A method and device for implementing Paillier homomorphic calculation by using cryptographic hardware

By leveraging specialized hardware for Paillier computations, the method addresses inefficiencies in software implementations and dedicated hardware limitations, enhancing speed, security, and flexibility in Paillier operations across diverse platforms.

CN117955630BActive Publication Date: 2025-07-15HARBIN UNIV OF SCI & TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410107944.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-26
Publication Date
2025-07-15
Estimated Expiration
2044-01-26

AI Technical Summary

Technical Problem

In the prior art, the software implementation of Paillier homomorphic encryption algorithm has problems such as low computing efficiency, fragile security, large resource utilization and poor flexibility, while the dedicated cryptographic chip has problems such as high design cost, unscalable functions and insufficient flexibility.

Method used

Password hardware is used, including password chips and microcontrollers that do not support the Paillier algorithm. By installing password hardware on the sender and receiver host computers, the microcontroller and password chips are used to realize Paillier key pair generation, encryption, decryption and homomorphic computing processes, and Paillier homomorphic computing is supported.

Benefits of technology

Significantly improves the speed and throughput of Paillier homomorphic computing, enhances security, reduces host burden, provides flexibility and scalability, reduces development and production costs, and supports multi-platform use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117955630B_ABST
    Figure CN117955630B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for implementing Paillier homomorphic calculation by using cryptographic hardware, which relates to the technical field of information security, and aims to solve the problems brought by the existing software implementation of the Paillier algorithm and the use of dedicated hardware to solely implement the Paillier algorithm. The technical key points of the present invention include: the cryptographic hardware includes a cryptographic chip that does not support the Paillier algorithm and a microcontroller. The sending-party cryptographic hardware generates a Paillier key pair according to the number of bits of the Paillier key pair, and sends the public key part thereof to the receiving-party cryptographic hardware, encrypts the plaintext data according to the Paillier key pair to obtain ciphertext data; sends the ciphertext data and the name of the homomorphic algorithm to the receiving-party cryptographic hardware; the receiving-party cryptographic hardware calls the homomorphic calculation process to perform homomorphic calculation, and sends the obtained ciphertext of the homomorphic calculation result to the sending-party cryptographic hardware; the sending-party cryptographic hardware decrypts the ciphertext of the homomorphic calculation result by using the Paillier key pair to obtain the corresponding plaintext data. The present invention can improve the speed and throughput of Paillier homomorphic calculation and has strong security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a method and device for implementing Paillier homomorphic calculation by using cryptographic hardware. Background Art

[0002] Homomorphic encryption is a cryptographic technique that allows computational operations to be performed on encrypted data without decrypting it. It provides the ability to perform meaningful computations on encrypted data without exposing sensitive raw data. Homomorphic encryption is of great significance in the fields of secure computing, privacy protection, and secure cloud computing. Homomorphic encryption has many advantages, but some limitations and challenges also need to be considered. The computational efficiency of homomorphic encryption algorithms is usually low, and the encryption and decryption overheads are large, occupying a large amount of processor resources, memory resources, storage resources, network resources, etc.

[0003] The Paillier technique is a public-key encryption algorithm proposed by Pascal Paillier in 1999. It is an encryption scheme based on integer residues and has additive homomorphic properties, allowing addition operations to be performed on ciphertexts in the encrypted state without decrypting the data. The Paillier encryption algorithm has advantages in supporting additive homomorphicity, public verification, randomness, and uncertainty. It has a wide range of applications in the fields of privacy protection, secure computing, and secure cloud computing, providing an effective solution for protecting data privacy and performing secure computations.

[0004] Currently, most of the Paillier implementations are software-based Paillier, which has the following disadvantages: Software implementations usually rely on the processing power of general-purpose computers, and the processing speed and parallel performance of general-purpose computers are lower than those of dedicated hardware devices; The software-based Paillier encryption scheme may be threatened by security risks at the software level, and factors such as malware, malicious code, or operating system vulnerabilities may have an adverse impact on the security of software implementations; The software-based Paillier encryption scheme may be restricted by computer resources such as processors, memory, and storage, which may limit the flexibility and scalability of software implementations, especially when dealing with large-scale data or high-concurrency computations; The software-based Paillier encryption scheme requires specialized development and maintenance work, which includes writing and optimizing the code of the encryption algorithm, handling security vulnerabilities and updates, and performing performance tuning, etc.

[0005] If the Paillier algorithm is implemented solely using specialized hardware, the following problems exist: Specialized cryptographic chips are usually designed for specific cryptographic algorithms or application scenarios, and thus lack flexibility in other algorithms or applications. If multiple algorithms or applications need to be supported, additional chips or updates are required. The specialized design and manufacturing of cryptographic chips involve substantial R & D and production costs, which usually makes them expensive, limiting their popularity and adoption in certain application scenarios. Since cryptographic chips are usually custom-designed, once produced, their functions and performance cannot be directly upgraded. If updates or upgrades are needed, new chips need to be redesigned and produced. Summary of the Invention

[0006] In view of the above problems, the present invention proposes a method and device for implementing Paillier homomorphic calculation using cryptographic hardware, aiming to solve the problems brought about by the existing software implementation of the Paillier algorithm and the sole implementation of the Paillier algorithm using specialized hardware.

[0007] According to one aspect of the present invention, a method for implementing Paillier homomorphic calculation using cryptographic hardware is proposed. The cryptographic hardware includes a cryptographic chip that does not support the Paillier algorithm and a microcontroller. The cryptographic hardware is installed on the sender host computer and the receiver host computer where Paillier homomorphic calculation is to be implemented. The method for the sender host computer and the receiver host computer to implement Paillier homomorphic calculation using the cryptographic hardware includes:

[0008] S1. The sender cryptographic hardware generates a Paillier key pair according to the number of bits of the Paillier key pair, and sends the public key part to the receiver cryptographic hardware;

[0009] S2. The sender cryptographic hardware encrypts the plaintext data according to the Paillier key pair to obtain ciphertext data; and sends the ciphertext data and the name of the homomorphic algorithm to be executed to the receiver cryptographic hardware;

[0010] S3. After receiving the ciphertext data and the name of the homomorphic algorithm to be executed, the receiver cryptographic hardware calls the homomorphic calculation process to perform homomorphic calculation to obtain the homomorphic calculation result ciphertext; and sends the homomorphic calculation result ciphertext to the sender cryptographic hardware;

[0011] S4. After receiving the homomorphic calculation result ciphertext, the sender cryptographic hardware decrypts it using the Paillier key pair to obtain the corresponding plaintext data.

[0012] Further, the process in S1 where the sender's cryptographic hardware generates a Paillier key pair according to the number of bits of the Paillier key pair includes: The microcontroller generates a Paillier key pair by calling the hardware true random number in the cryptographic chip and the large number operation function integrated in the microcontroller itself, and stores it in the microcontroller.

[0013] Further, the plaintext data includes fixed-point decimal data and negative data; the process in S2 where the sender's cryptographic hardware encrypts the plaintext data according to the Paillier key pair to obtain ciphertext data includes: The microcontroller performs Paillier encryption on the plaintext data by calling the hardware true random number in the cryptographic chip, the large number operation function integrated in itself, and the stored Paillier key pair to obtain ciphertext data; among them, when the plaintext data includes fixed-point decimal data, the cryptographic hardware records the number of fixed-point decimal digits; when the plaintext data includes negative data, the microcontroller takes the modulus of the negative number by calling the large number operation function integrated in itself.

[0014] Further, the process in S3 where the receiver's cryptographic hardware performs homomorphic calculation by calling the homomorphic calculation process after receiving the ciphertext data and the name of the homomorphic algorithm to be executed includes: The microcontroller performs Paillier homomorphic calculation on the ciphertext data by calling the hardware true random number in the cryptographic chip, the large number operation function integrated in itself, and the stored Paillier public key to obtain the homomorphic calculation result ciphertext.

[0015] Further, the homomorphic algorithms to be executed include homomorphic addition and homomorphic multiplication, where homomorphic addition is the addition of two original plaintexts, and homomorphic multiplication is the multiplication of a specified number and an original plaintext.

[0016] Further, the process in S4 where the sender's cryptographic hardware decrypts the homomorphic calculation result ciphertext using the Paillier key pair includes: The microcontroller performs Paillier decryption on the homomorphic calculation result ciphertext by calling the hardware true random number in the cryptographic chip, the large number operation function integrated in itself, and the stored Paillier key pair to obtain plaintext data; among them, when the homomorphic calculation result ciphertext includes negative data to be restored, the microcontroller maps and restores positive and negative numbers by calling the large number operation interface; when the homomorphic calculation result ciphertext includes decimal data to be restored, the microcontroller restores the recorded decimal point position to its original position.

[0017] According to another aspect of the present invention, a device for implementing Paillier homomorphic calculation using cryptographic hardware is proposed. The device includes a sender cryptographic hardware and a receiver cryptographic hardware; the sender cryptographic hardware includes a first cryptographic chip that does not support the Paillier algorithm and a first microcontroller, and the receiver cryptographic hardware includes a second cryptographic chip that does not support the Paillier algorithm and a second microcontroller; wherein,

[0018] The sender cryptographic hardware is used to generate a Paillier key pair according to the number of bits of the Paillier key pair, and send the public key part to the receiver cryptographic hardware; encrypt the plaintext data according to the Paillier key pair to obtain ciphertext data, and send the ciphertext data and the name of the homomorphic algorithm to be executed to the receiver cryptographic hardware; decrypt the homomorphic calculation result ciphertext using the Paillier key pair after receiving it to obtain the corresponding plaintext data;

[0019] After receiving the ciphertext data and the name of the homomorphic algorithm to be executed, the receiver cryptographic hardware calls the homomorphic calculation process to perform homomorphic calculation to obtain the homomorphic calculation result ciphertext; and sends the homomorphic calculation result ciphertext to the sender cryptographic hardware.

[0020] Further, the process of generating a Paillier key pair according to the number of bits of the Paillier key pair in the sender cryptographic hardware includes: the first microcontroller generates a Paillier key pair by calling the hardware true random number in the cryptographic chip and the large number operation function integrated in the microcontroller itself and stores it in the first microcontroller; the plaintext data includes fixed-point decimal data and negative data; the process of encrypting the plaintext data according to the Paillier key pair to obtain ciphertext data includes: the first microcontroller performs Paillier encryption on the plaintext data by calling the hardware true random number in the first cryptographic chip, the large number operation function integrated in itself and the saved Paillier key pair to obtain ciphertext data; wherein, when the plaintext data includes fixed-point decimal data, the sender cryptographic hardware records the number of fixed-point decimal bits; when the plaintext data includes negative data, the first microcontroller takes the modulus of the negative number by calling the large number operation function integrated in itself.

[0021] Further, the process of the receiving - party cryptographic hardware invoking the homomorphic - computing process for homomorphic computing after receiving the ciphertext data and the name of the homomorphic algorithm to be executed includes: The second microcontroller performs Paillier homomorphic computing on the ciphertext data by invoking the hardware true random number in the second cryptographic chip, its own integrated large - number operation function, and the saved Paillier public key to obtain the ciphertext of the homomorphic - computing result; The homomorphic algorithm to be executed includes homomorphic addition and homomorphic multiplication. Among them, homomorphic addition is the addition of two original plaintexts, and homomorphic multiplication is the multiplication of a specified number and an original plaintext.

[0022] Further, the process of the sending - party cryptographic hardware decrypting the ciphertext of the homomorphic - computing result using the Paillier key pair includes: The first microcontroller performs Paillier decryption on the ciphertext of the homomorphic - computing result by invoking the hardware true random number in the first cryptographic chip, its own integrated large - number operation function, and the saved Paillier key pair to obtain the plaintext data; Among them, when the ciphertext of the homomorphic - computing result includes negative data to be restored, the microcontroller maps and restores positive and negative numbers by invoking the large - number operation interface; When the ciphertext of the homomorphic - computing result includes decimal data to be restored, the microcontroller restores the recorded decimal - point position to its original position.

[0023] The beneficial technical effects of the present invention are:

[0024] The present invention provides a method and apparatus for implementing Paillier homomorphic calculation using cryptographic hardware. The proposed cryptographic hardware can significantly improve the speed and throughput of Paillier homomorphic calculation when implementing Paillier homomorphic calculation, especially bringing faster calculation results in the case of large-scale data sets or complex calculation tasks; since the Paillier function is integrated into dedicated cryptographic hardware, the security of implementing Paillier homomorphic calculation in the present invention is significantly enhanced, and the cryptographic chip and the microcontroller have security functions such as physical isolation, protection measures, and hardware encryption engines, which can protect sensitive data and keys, and this hardware-level security can better resist side-channel attacks and physical attacks; further, the present invention can reduce the burden on the host. Using cryptographic hardware can transfer the load of Paillier calculation from the host computer to dedicated hardware, which can free up the processing power of the host computer, improve the performance and response speed of the overall system, and enable the host to focus on other calculation tasks without being affected by Paillier homomorphic calculation; further, the present invention has scalability and flexibility. By externalizing the Paillier function to an independent cryptographic board, the board can be easily inserted or removed from different computer systems without large-scale modification or redeployment of the software, which provides greater flexibility and scalability, and enables Paillier homomorphic calculation to be used on multiple computing platforms.

[0025] The present invention constitutes the cryptographic hardware in a more economical and efficient manner. Developing and producing a separate Paillier cryptographic chip may require more resources and costs, including design, manufacturing, and verification. While using a cryptographic board, existing microcontrollers and general-purpose cryptographic chips can be utilized, reducing the cost of independent chip development. Implementing Paillier homomorphic calculation using cryptographic hardware in the present invention can provide greater flexibility and customizability. By selecting microcontrollers and general-purpose cryptographic chips with suitable performance and functions, different requirement scenarios can be adapted. In addition, since the cryptographic hardware is pluggable, it can be easily replaced or upgraded when needed. The present invention has fast development and iterability. Using existing microcontrollers and general-purpose cryptographic chips can accelerate the development and iteration speed. There is no need to design and verify a separate Paillier cryptographic chip from scratch, and existing hardware and software resources can be utilized to implement the function faster and perform iteration and improvement. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The present invention can be better understood by referring to the description given below in conjunction with the accompanying drawings, which are included in and form a part of this specification together with the following detailed description, and are used to further illustrate the preferred embodiments of the present invention and explain the principles and advantages of the present invention.

[0027] Figure 1 It is a flowchart of a method for implementing Paillier homomorphic calculation using cryptographic hardware according to an embodiment of the present invention.

[0028] Figure 2 It is a schematic diagram of communication between cryptographic hardware and a host computer in an embodiment of the present invention.

[0029] Figure 3 It is a flowchart of generating a Paillier key pair using cryptographic hardware in an embodiment of the present invention.

[0030] Figure 4 It is a flowchart of encrypting using cryptographic hardware in an embodiment of the present invention.

[0031] Figure 5 It is a flowchart of performing homomorphic calculation using cryptographic hardware in an embodiment of the present invention.

[0032] Figure 6 It is a flowchart of decrypting using cryptographic hardware in an embodiment of the present invention. Detailed implementation manners

[0033] In order to enable those skilled in the art to better understand the solution of the present invention, the exemplary embodiments or examples of the present invention will be described below in conjunction with the accompanying drawings. Obviously, the described embodiments or examples are only part of the embodiments or examples of the present invention, rather than all of them. All other embodiments or examples obtained by those of ordinary skill in the art based on the embodiments or examples of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0034] An embodiment of the present invention provides a method for implementing Paillier homomorphic calculation using cryptographic hardware. The cryptographic hardware includes a cryptographic chip that does not support the Paillier algorithm and a microcontroller, and the cryptographic hardware is respectively installed on the sending host computer and the receiving host computer where Paillier homomorphic calculation is to be implemented. As Figure 1 shown, the method for the sending host computer and the receiving host computer to implement Paillier homomorphic calculation using the cryptographic hardware includes:

[0035] S1. The sending cryptographic hardware generates a Paillier key pair according to the number of bits of the Paillier key pair, and sends the public key part to the receiving cryptographic hardware;

[0036] S2. The sending cryptographic hardware encrypts the plaintext data according to the Paillier key pair to obtain ciphertext data; and sends the ciphertext data and the name of the homomorphic algorithm to be executed to the receiving cryptographic hardware;

[0037] S3. After receiving the ciphertext data and the name of the homomorphic algorithm to be executed, the receiving - party cryptographic hardware calls the homomorphic calculation process to perform homomorphic calculation, obtaining the homomorphic calculation result ciphertext; and sends the homomorphic calculation result ciphertext to the sending - party cryptographic hardware.

[0038] S4. After receiving the homomorphic calculation result ciphertext, the sending - party cryptographic hardware decrypts it using the Paillier key pair to obtain the corresponding plaintext data.

[0039] According to the embodiments of the present invention, as Figure 2 shown, the cryptographic hardware specifically includes a micro - controller M1 and a cryptographic chip E1. M1 is responsible for calling the algorithm interface of E1 to complete the key generation, encryption, decryption, and homomorphic calculation processes of Paillier. At the same time, M1 is responsible for interacting with the host computer through PCIe CMDQ and storing the Paillier key pair. Both the sending party and the receiving party perform the homomorphic calculation process based on this structure.

[0040] An existing cryptographic chip needs to be used in the cryptographic hardware. This chip does not directly support Paillier, but supports other cryptographic algorithms such as RSA, ECC, AES, SM1, SM2, and EIP154, etc. And for the large - number algorithms such as large - number calculation, modular exponentiation, modular multiplication, modular inversion, etc. in these algorithms, there are external interfaces. Then, the Paillier homomorphic calculation function is completed by the interaction between the host computer and the lower - level machine of the cryptographic hardware.

[0041] The process of the sending party and the receiving party using the above - mentioned cryptographic hardware to implement Paillier homomorphic calculation is as follows:

[0042] First, the sending party selects the number of bits Keybits of the Paillier key pair and the number of bits mbits of the plaintext, and uses the cryptographic hardware to call the key - generation process to generate the Paillier key pair. This key pair is stored in the local cryptographic hardware; after the key pair is generated, the sending party sends the public - key part to the receiving party through a secure communication protocol for the receiving party to use in the subsequent homomorphic calculation process; after receiving the Paillier public key, the receiving party stores it in the cryptographic hardware; the receiving - party cryptographic hardware is the same as the sending - party cryptographic hardware.

[0043] Second, the sending party specifies and records the homomorphic algorithm f(x) and the fixed - point decimal number of bits Mbits for this calculation, and then calls the encryption process of the cryptographic hardware to encrypt the plaintext data M using the Paillier key pair to obtain the ciphertext data C. After the Paillier encryption is completed, the sending party sends the encrypted ciphertext data C and the homomorphic algorithm to be executed to the receiving party through a secure communication protocol for the receiving party to perform homomorphic calculation.

[0044] Again, after receiving the ciphertext data C and the specified homomorphic algorithm f(x), the receiver uses the same cryptographic hardware as the sender to call the corresponding homomorphic computing process to obtain the homomorphic computing result ciphertext Chomo; then the receiver sends the calculation result ciphertext Chomo to the receiver through a secure communication protocol, and the receiver's calculation task is completed.

[0045] Finally, after receiving the ciphertext Chomo of the homomorphic computing result, the sender uses the cryptographic hardware to call the decryption process and uses the Paillier key to decrypt Chomo to obtain the plaintext Mhomo; then Mhomo is restored to a decimal according to the recorded Mbits.

[0046] In this embodiment, the sender selects the required Paillier key pair number Keybits and the number of plaintext bits mbits, such as Figure 3 As shown, the process of using cryptographic hardware to call the key generation process to generate a Paillier key pair is as follows:

[0047] S11. The sender calls the Paillier key generation API on the host computer equipped with cryptographic hardware to start the key generation process.

[0048] S12. The API initiates the Paillier key generation process of the cryptographic hardware through PCIe CMDQ, and transmits the Paillier key pair number Keybits to the cryptographic hardware. The subsequent process is dominated by the microcontroller M1.

[0049] S13, M1 generates a Paillier key pair by calling the hardware true random number and large number operation interface in the cryptographic chip E1 and stores it in M1.

[0050] S14 and M1 return the Paillier key pair to the API via PCIe CMDQ.

[0051] In this embodiment, the plaintext data to be encrypted in the cryptographic hardware encryption process supports fixed-point decimals and negative numbers. The number of decimal places of the fixed-point decimal is determined by the sender when initiating a homomorphic calculation. The number of decimal places ranges from 0 to mbits, and the number of decimal places can be different for each complete homomorphic calculation. The support method for negative numbers is modulo operation. Figure 4 As shown in the figure, the specific steps of the encryption process are as follows:

[0052] S21. The sender selects and records the homomorphic algorithm and the number of fixed-point decimal places, and then calls the encryption API to start the Paillier encryption process.

[0053] S22. The API initiates the Paillier encryption process of the cryptographic hardware through PCIe CMDQ and sends the plaintext M to the cryptographic hardware.

[0054] S23. If M is negative, M1 takes the modulo Mod of the negative number by calling the large number operation in the cryptographic chip E1, while positive numbers remain unchanged, and Mod is not less than the maximum value that can be represented by a binary number of 4 times m bits.

[0055] S24. M1 performs Paillier encryption on the data by calling the hardware true random number and large number operation interface in the cryptographic chip E1 and the key stored in M1 to obtain the ciphertext C.

[0056] S25. M1 returns the encrypted ciphertext C to the API through PCIe CMDQ.

[0057] In this embodiment, there are two homomorphic algorithms in the homomorphic calculation process, namely homomorphic addition and homomorphic multiplication. The calculation effect of homomorphic addition is the addition of two original plaintexts; the calculation effect of homomorphic multiplication is the multiplication of a specified number k and an original plaintext. As Figure 5 shown, the specific steps of the homomorphic calculation process are as follows:

[0058] S31. The receiver calls the homomorphic calculation API on the host computer equipped with cryptographic hardware to initiate the corresponding homomorphic calculation process.

[0059] S32. The API initiates the Paillier homomorphic calculation process of the cryptographic hardware through PCIe CMDQ and sends the corresponding ciphertext to the cryptographic hardware.

[0060] S33. M1 performs Paillier homomorphic calculation on the data by calling the hardware true random number and large number operation interface in the cryptographic chip E1 and the public key stored in M1 to obtain the homomorphic calculation result Chomo.

[0061] S34. M1 returns Chomo to the API through PCIe CMDQ.

[0062] In this embodiment, the reduction of decimals and negative numbers is involved in the decryption process. The reduction of negative numbers uses subtraction modulo operation; the reduction of decimals is achieved by restoring the recorded decimal point position to its original position. As Figure 6 shown, the specific steps of the decryption process are as follows:

[0063] S41. The sender calls the Paillier decryption API to initiate the corresponding decryption process.

[0064] S42. The API initiates the Paillier decryption process of the cryptographic hardware through PCIe CMDQ and sends the homomorphic calculation result Chomo to the cryptographic hardware.

[0065] S43, M1 performs Paillier decryption on the data by calling the hardware true random number and large number operation interface in the cryptographic chip E1 and the Paillier key stored in M1.

[0066] S44, M1 calls the large number operation interface in the cryptographic chip E1 to map and restore the positive and negative numbers and restore the decimal places to obtain the plain text Mhomo.

[0067] S45 and M1 return the plain text Mhomo to the API through PCIe CMDQ.

[0068] As an example, taking a machine learning scenario as an example, in a method of implementing Paillier homomorphic computing using cryptographic hardware, the sender is the data owner, and the receiver is a third party for model training. Then, the process of using the present invention to perform model training is as follows.

[0069] Step 1: The sender selects the required number of Paillier key pairs Keybits and the number of plaintext bits of training data mbits, and then uses the cryptographic hardware to call the key generation process to generate a Paillier key pair. The key pair is stored in the microcontroller M1 of the sender's local cryptographic hardware. After the key is generated, the sender sends the public key part of the key pair to the receiver through the SSL protocol for the subsequent homomorphic computing process. After receiving the public key part of the Paillier key pair, the receiver stores it in the receiver's microcontroller M1 in the local cryptographic hardware.

[0070] Step 2: The sender specifies and records the number of fixed-point decimal places Mbits, and then calls the cryptographic hardware encryption process to use the Paillier key pair to encrypt the original view data plaintext M to obtain the original view data ciphertext C. After the Paillier encryption is completed, the sender sends the original view data ciphertext C and to the receiver through the SSL protocol so that the receiver can perform model training.

[0071] Step 3: After receiving the original visual data ciphertext C, the receiver uses the same cryptographic hardware as the sender to call the corresponding homomorphic computing process to continuously train the data and obtain the training result ciphertext Chomo. The receiver then sends the training result ciphertext Chomo to the receiver through the SSL protocol.

[0072] Step 4: After receiving the training result ciphertext Chomo, the sender calls the cryptographic hardware decryption process and uses the Paillier key to decrypt Chomo to obtain the training result plaintext Mhomo. Then, Mhomo is restored to a decimal according to the recorded Mbits. At this point, the model training is completed.

[0073] The present invention provides that hardware acceleration can significantly improve the speed and throughput of Paillier homomorphic computing, especially bringing faster computing results in the case of large-scale data sets or complex computing tasks.

[0074] The security of the present invention is significantly enhanced. Since the Paillier function is integrated into dedicated cryptographic hardware, higher security can be provided. Moreover, the cryptographic chip and the microcontroller have security functions such as physical isolation, protection measures, and a hardware encryption engine, which can protect sensitive data and keys. This hardware-level security can better resist side-channel attacks and physical attacks.

[0075] The present invention can relieve the burden on the host. Using cryptographic hardware can transfer the load of Paillier computing from the host computer to dedicated hardware. This can free up the processing power of the host computer, improve the performance and response speed of the overall system. The host can focus on other computing tasks without being affected by Paillier homomorphic computing.

[0076] The present invention has scalability and flexibility. By externalizing the Paillier function to an independent cryptographic board, the board can be easily inserted or removed from different computer systems without large-scale software modification or redeployment. This provides greater flexibility and scalability, enabling Paillier homomorphic computing to be used on multiple computing platforms.

[0077] The way the present invention constitutes the cryptographic hardware is more economical and efficient. Developing and producing a separate Paillier cryptographic chip may require more resources and costs, including design, manufacturing, and verification. While using a cryptographic board, existing microcontrollers and general-purpose cryptographic chips can be utilized, reducing the cost of independent chip development.

[0078] The present invention using cryptographic hardware to implement Paillier homomorphic computing can provide greater flexibility and customizability. By selecting microcontrollers and general-purpose cryptographic chips with suitable performance and functions, different requirements can be met. In addition, since the cryptographic hardware is pluggable, it can be easily replaced or upgraded when needed.

[0079] The present invention has fast development and iterativeness. Using existing microcontrollers and general-purpose cryptographic chips can accelerate the development and iteration speed. There is no need to design and verify a separate Paillier cryptographic chip from scratch. Existing hardware and software resources can be utilized to implement functions faster and perform iteration and improvement.

[0080] Another embodiment of the present invention proposes a device for implementing Paillier homomorphic calculation using cryptographic hardware, which includes a sender cryptographic hardware and a receiver cryptographic hardware; the sender cryptographic hardware includes a first cryptographic chip and a first microcontroller that do not support the Paillier algorithm, and the receiver cryptographic hardware includes a second cryptographic chip and a second microcontroller that do not support the Paillier algorithm; wherein,

[0081] The sender cryptographic hardware is used to generate a Paillier key pair according to the number of bits of the Paillier key, and send the public key part to the receiver cryptographic hardware; encrypt the plaintext data according to the Paillier key pair to obtain ciphertext data, and send the ciphertext data and the name of the homomorphic algorithm to be executed to the receiver cryptographic hardware; decrypt the homomorphic calculation result ciphertext using the Paillier key pair after receiving it to obtain plaintext data;

[0082] After receiving the ciphertext data and the name of the homomorphic algorithm to be executed, the receiver cryptographic hardware calls the homomorphic calculation process to perform homomorphic calculation to obtain the homomorphic calculation result ciphertext; and sends the homomorphic calculation result ciphertext to the sender cryptographic hardware.

[0083] According to the embodiment of the present invention, the cryptographic hardware is a cryptographic hardware board installed on the PCIe interface of the host computer, and the board is composed of a cryptographic chip and a microcontroller; as an example, the cryptographic hardware board is installed on the server through the PCIe interface, and the hardware driver and API are written on the server.

[0084] The cryptographic chip E1 is used for hardware true random numbers, which is an existing general cryptographic chip. This chip does not directly support Paillier but supports other cryptographic algorithms such as RSA, ECC, AES, SM1, SM2, and EIP, etc. And there are external interfaces for large number calculations or algorithms such as modular exponentiation, modular multiplication, and modular inversion in these algorithms, so the support for Paillier can be realized under the control of the microcontroller.

[0085] The microcontroller M1 is used to control the cryptographic chip E1 to implement the Paillier function and store the Paillier key in the chip. The corresponding firmware for implementing the Paillier process by calling E1 is written in M1, and at the same time, this firmware supports key storage.

[0086] As an example, the microcontroller M1 selects an Arm Cortex M3 core microcontroller, and the cryptographic chip E1 selects a chip that supports the EIP protocol. Thus, a cryptographic hardware board is formed and installed on the server through the PCIe interface, and the hardware driver and API are written on the server. The corresponding firmware for implementing the Paillier process by calling E1 is written in M1, and at the same time, this firmware supports key storage.

[0087] In this embodiment, optionally, the process of generating a Paillier key pair according to the number of bits of the Paillier key pair in the sender's cryptographic hardware includes: the first microcontroller generates a Paillier key pair by calling the hardware true random number in the cryptographic chip and the large number operation function integrated in the microcontroller itself, and stores it in the first microcontroller; the plaintext data includes fixed-point decimal data and negative data; the process of encrypting the plaintext data with the Paillier key pair to obtain ciphertext data includes: the first microcontroller performs Paillier encryption on the plaintext data by calling the hardware true random number in the first cryptographic chip, the large number operation function integrated in itself, and the saved Paillier key pair to obtain ciphertext data; wherein, when the plaintext data includes fixed-point decimal data, the sender's cryptographic hardware records the number of fixed-point decimal digits; when the plaintext data includes negative data, the first microcontroller takes the modulus of the negative number by calling the large number operation function integrated in itself.

[0088] In this embodiment, optionally, the process of the receiver's cryptographic hardware performing homomorphic calculation by calling the homomorphic calculation process after receiving the ciphertext data and the name of the homomorphic algorithm to be executed includes: the second microcontroller performs Paillier homomorphic calculation on the ciphertext data by calling the hardware true random number in the second cryptographic chip, the large number operation function integrated in itself, and the saved Paillier public key to obtain the homomorphic calculation result ciphertext; the homomorphic algorithms to be executed include homomorphic addition and homomorphic multiplication, where homomorphic addition is the addition of two original plaintexts, and homomorphic multiplication is the multiplication of a specified number and an original plaintext.

[0089] In this embodiment, optionally, the process of the sender's cryptographic hardware decrypting the homomorphic calculation result ciphertext with the Paillier key pair includes: the first microcontroller performs Paillier decryption on the homomorphic calculation result ciphertext by calling the hardware true random number in the first cryptographic chip, the large number operation function integrated in itself, and the saved Paillier key pair to obtain the corresponding plaintext data; wherein, when the homomorphic calculation result ciphertext includes negative data to be restored, the microcontroller maps and restores positive and negative numbers by calling the large number operation interface; when the homomorphic calculation result ciphertext includes decimal data to be restored, the microcontroller restores the recorded decimal point position to its original position.

[0090] The function of the device for implementing Paillier homomorphic calculation using cryptographic hardware in an embodiment of the present invention can be illustrated by the aforementioned method for implementing Paillier homomorphic calculation using cryptographic hardware. Therefore, for the parts not described in detail in the device embodiment, reference can be made to the above method embodiment, and details will not be repeated here.

[0091] Although the present invention has been described in terms of a limited number of embodiments, those skilled in the art, having the benefit of the foregoing description, will appreciate that other embodiments can be contemplated within the scope of the invention as thus described. The disclosure of the invention is illustrative, not restrictive, with respect to the scope of the invention, which is defined by the appended claims.

Claims

1. A method for implementing Paillier homomorphic calculation using cryptographic hardware, characterized in that, The cryptographic hardware includes a cryptographic chip that does not support the Paillier algorithm and a microcontroller. The cryptographic hardware is installed on the sender host computer and the receiver host computer that are to implement Paillier homomorphic computation. The method for the sender host computer and the receiver host computer to implement Paillier homomorphic computation using the cryptographic hardware includes: S1. The sender cryptographic hardware generates a Paillier key pair according to the number of bits of the Paillier key pair, and sends the public key part to the receiver cryptographic hardware; S2. The sender cryptographic hardware encrypts the plaintext data according to the Paillier key pair to obtain ciphertext data. The plaintext data includes fixed-point decimal data and negative data. The process includes: The microcontroller performs Paillier encryption on the plaintext data by calling the hardware true random number in the cryptographic chip, the large number operation function integrated in itself, and the saved Paillier key pair to obtain ciphertext data. Among them, when the plaintext data includes fixed-point decimal data, the cryptographic hardware records the number of fixed-point decimal digits; when the plaintext data includes negative data, the microcontroller takes the modulus of the negative number by calling the large number operation function integrated in itself; and sends the ciphertext data and the name of the homomorphic algorithm to be executed to the receiver cryptographic hardware; S3. After receiving the ciphertext data and the name of the homomorphic algorithm to be executed, the receiver cryptographic hardware calls the homomorphic computation process to perform homomorphic computation to obtain the homomorphic computation result ciphertext; and sends the homomorphic computation result ciphertext to the sender cryptographic hardware; S4. After receiving the homomorphic computation result ciphertext, the sender cryptographic hardware decrypts it using the Paillier key pair to obtain the corresponding plaintext data, including: The microcontroller performs Paillier decryption on the homomorphic computation result ciphertext by calling the hardware true random number in the cryptographic chip, the large number operation function integrated in itself, and the saved Paillier key pair to obtain the plaintext data. Among them, when the homomorphic computation result ciphertext includes negative data to be restored, the microcontroller maps and restores positive and negative numbers by calling the large number operation interface; when the homomorphic computation result ciphertext includes decimal data to be restored, the microcontroller restores the recorded decimal point position to its original position.

2. A method for implementing Paillier homomorphic computation using cryptographic hardware according to claim 1, wherein The process in S1 where the sender cryptographic hardware generates a Paillier key pair according to the number of bits of the Paillier key pair includes: The microcontroller generates a Paillier key pair by calling the hardware true random number in the cryptographic chip and the large number operation function integrated in the microcontroller itself, and stores it in the microcontroller.

3. A method for implementing Paillier homomorphic computation using cryptographic hardware according to claim 2, characterized in that, The process in S3 where the receiver cryptographic hardware calls the homomorphic computation process to perform homomorphic computation after receiving the ciphertext data and the name of the homomorphic algorithm to be executed includes: The microcontroller performs Paillier homomorphic computation on the ciphertext data by calling the hardware true random number in the cryptographic chip, the large number operation function integrated in itself, and the saved Paillier public key to obtain the homomorphic computation result ciphertext.

4. A method for implementing Paillier homomorphic computation using cryptographic hardware according to claim 3, wherein, The to-be-executed homomorphic algorithm includes homomorphic addition and homomorphic scalar multiplication. Among them, homomorphic addition is the addition of two original plaintexts, and homomorphic scalar multiplication is the multiplication of a specified number and an original plaintext.

5. A device for implementing Paillier homomorphic computation using cryptographic hardware, characterized in that, It includes a sender cryptographic hardware and a receiver cryptographic hardware; the sender cryptographic hardware includes a first cryptographic chip that does not support the Paillier algorithm and a first microcontroller, and the receiver cryptographic hardware includes a second cryptographic chip that does not support the Paillier algorithm and a second microcontroller; among them, The sender cryptographic hardware is used to generate a Paillier key pair according to the number of bits of the Paillier key pair and send the public key part to the receiver cryptographic hardware; encrypt the plaintext data according to the Paillier key pair to obtain ciphertext data. The plaintext data includes fixed-point decimal data and negative data. The process includes: the first microcontroller performs Paillier encryption on the plaintext data by calling the hardware true random number in the first cryptographic chip, the large number operation function integrated in itself, and the saved Paillier key pair to obtain ciphertext data; among them, when the plaintext data includes fixed-point decimal data, the sender cryptographic hardware records the number of fixed-point decimal digits; when the plaintext data includes negative data, the first microcontroller takes the modulus of the negative number by calling the large number operation function integrated in itself; send the ciphertext data and the name of the to-be-executed homomorphic algorithm to the receiver cryptographic hardware; decrypt the homomorphic calculation result ciphertext using the Paillier key pair to obtain the corresponding plaintext data, including: the first microcontroller performs Paillier decryption on the homomorphic calculation result ciphertext by calling the hardware true random number in the first cryptographic chip, the large number operation function integrated in itself, and the saved Paillier key pair to obtain plaintext data; among them, when the homomorphic calculation result ciphertext includes negative data to be restored, the microcontroller maps and restores positive and negative numbers by calling the large number operation interface; when the homomorphic calculation result ciphertext includes decimal data to be restored, the microcontroller restores the recorded decimal point position to its original position; After receiving the ciphertext data and the name of the to-be-executed homomorphic algorithm, the receiver cryptographic hardware calls the homomorphic calculation process to perform homomorphic calculation to obtain the homomorphic calculation result ciphertext; and sends the homomorphic calculation result ciphertext to the sender cryptographic hardware.

6. The device for implementing Paillier homomorphic calculation using cryptographic hardware according to claim 5, wherein The process of generating a Paillier key pair according to the number of bits of the Paillier key pair in the sender cryptographic hardware includes: the first microcontroller generates a Paillier key pair by calling the hardware true random number in the cryptographic chip and the large number operation function integrated in the microcontroller itself and stores it in the first microcontroller.

7. The apparatus for implementing Paillier homomorphic calculation using cryptographic hardware according to claim 6, wherein The process of the receiving party's cryptographic hardware calling the homomorphic computing process for homomorphic computing after receiving the ciphertext data and the name of the homomorphic algorithm to be executed includes: The second microcontroller performs Paillier homomorphic computing on the ciphertext data by calling the hardware true random number in the second cryptographic chip, the large number operation function integrated in itself, and the saved Paillier public key to obtain the homomorphic computing result ciphertext; The homomorphic algorithms to be executed include homomorphic addition and homomorphic multiplication, where homomorphic addition is the addition of two original plaintexts, and homomorphic multiplication is the multiplication of a specified number and an original plaintext.