Method and device for encryption based on homomorphic encryption matrix-vector plaintext mixed multiplication

Through the homomorphic encryption matrix-vector ciphertext mixed multiplication method, the problem of ciphertext data needing to be decrypted in deep learning model training is solved, safe and efficient model training and data protection are achieved, and the generalization ability and data security of the model are improved.

CN119420466BActive Publication Date: 2025-05-09BEIJING YINSUAN QUANTITY TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510024141.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-09
Estimated Expiration
2045-01-07

AI Technical Summary

Technical Problem

In the training of deep learning model, the existing homomorphic encryption technology has the problem of ciphertext data that needs to be decrypted before it can be calculated, resulting in large calculation overhead, high risk of data leakage, and poor generalization capabilities of the model.

Method used

The matrix-vector ciphertext hybrid multiplication method based on homomorphic encryption is adopted. By packing the plaintext matrix column by column, filling and rotating the ciphertext vectors, fast and efficient calculation of ciphertext data is achieved, and security training is used using the cloud computing platform.

Benefits of technology

It realizes security training of deep learning models without decryption, reduces computing overhead, improves the generalization ability and data security of the model, and ensures that data is not leaked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420466B_ABST
    Figure CN119420466B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of ciphertext data processing, and in particular to a method and device for encrypting a mixed plaintext and ciphertext based on homomorphic encryption matrix-vector multiplication, the method comprising: S1, obtaining a target training set, packing its plaintext matrix elements column by column along the diagonal, obtaining a packing vector of multiple plaintext data, and automatically filling the empty slots with 0; S2, filling the ciphertext vector, and filling the empty slots in sequence according to the ciphertext vector elements; S3, rotating the ciphertext vector to the correct position in sequence; S4, multiplying the rotated ciphertext vector with the obtained plaintext data vector; S5, adding the elements of the corresponding slots of the multiplied plaintext and ciphertext mixed vector to obtain the final output vector as the ciphertext data of the deep learning model training set. The method can quickly and efficiently obtain the ciphertext data in the target training set, greatly reducing the computational overhead. The ciphertext data output by the device is decrypted to obtain the same result as the multiplication of the original matrix and the plaintext vector, and the output reliability is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of ciphertext data processing, and more specifically to a method and device for encryption based on homomorphic encryption matrix-vector plaintext mixed multiplication. Background Art

[0002] At present, with the rapid development of information technology, data privacy and security issues are increasingly concerned, especially in areas involving personal sensitive information, such as medical, financial and social networks. Traditional data processing methods usually rely on plaintext data, which makes data vulnerable to various attacks and leakage risks during storage and transmission. In this context, homomorphic encryption technology has gradually become an effective means to protect data privacy. Homomorphic encryption is a technology that allows calculations to be performed directly on ciphertext, and the decryption of the calculation result is the same as the result of the same operation on the plaintext. This feature allows users to use cloud computing or other third-party services to perform complex data processing and analysis without decrypting the data, thereby effectively protecting data privacy.

[0003] However, although homomorphic encryption technology has great potential in theory, its efficiency and feasibility in practical applications still face many challenges. For example, in the field of deep learning, model training usually requires a large amount of plaintext data for calculation, and traditional methods require data to be decrypted during training, which not only increases the risk of data leakage, but may also lead to compliance issues.

[0004] Therefore, how to achieve effective training and inference of deep learning models while protecting data privacy is an urgent problem that technicians in this field need to solve. Summary of the invention

[0005] In view of this, the present invention provides a matrix-vector plaintext ciphertext hybrid multiplication encryption method and device based on homomorphic encryption, which solves the problem that ciphertext data needs to be decrypted before training when a deep learning model is trained securely, solves the problem of excessive computational overhead when encrypting and decrypting ciphertext data, and solves the problem of poor generalization ability of deep learning models.

[0006] In order to achieve the above object, the present invention adopts the following technical solution:

[0007] A matrix-vector plaintext hybrid multiplication encryption method based on homomorphic encryption includes the following steps:

[0008] S1. Obtain the target training set, pack the plaintext matrix elements of the training set column by column along the diagonal, obtain the packing vectors of multiple plaintext data, and automatically fill the empty slots with 0;

[0009] S2, fill the ciphertext vector, and fill the remaining slots in sequence according to the elements of the initial ciphertext vector;

[0010] S3, rotate the filled ciphertext vectors in sequence and rotate them to the correct position;

[0011] S4, multiplying the rotated ciphertext vector by the obtained plaintext data vector;

[0012] S5. Add the elements of the corresponding slots of the multiplied plaintext and ciphertext mixed vector to obtain the final output vector as the ciphertext data of the deep learning model training set.

[0013] Furthermore, in S1, the number of rows of the plaintext matrix is ​​n, and the number of columns is m, which can be expressed as ,in, , ;

[0014] The plaintext matrix elements are packed column by column along the diagonal to obtain m plaintext data packing vectors, each of which includes n non-zero elements. The first element of the column is used as the first element to pack diagonally. The packing vector of plaintext data is expressed as:

[0015] ;

[0016] in, For the The nth non-zero element of the packed vector is packed into the The first element of the column is the first diagonal packing. After the number of columns is exhausted, the diagonal packing continues from the first column of the next row to the last element packed.

[0017] Furthermore, in S1, the length of the plaintext data packing vector is the number of slots M, the number of slots M is a power of 2, and needs to satisfy ,definition .

[0018] Furthermore, in S2, the specific process of filling the ciphertext vector includes:

[0019] S21. According to the number of columns of the plaintext matrix, the initial ciphertext vector is obtained, which is expressed as:

[0020] ;

[0021] S22, fill the initial ciphertext vector into a ciphertext vector with the same length as the plaintext data packing vector, which is expressed as:

[0022] .

[0023] Furthermore, in S3, the filled ciphertext vector is rotated m times in sequence to obtain m different rotated ciphertext vectors. The rotated ciphertext vector is expressed as: or ;

[0024] in, represents the ciphertext vector, Indicates The rotation is performed one time with a step length of one step, and positive or negative indicates rotation to the left or right.

[0025] Furthermore, in S3, the rotation to the correct position is: each time the ciphertext vector is rotated, the ciphertext vector element sequence number in its slot is consistent with the element column number of the same slot of the plaintext data packing vector multiplied by it.

[0026] Furthermore, in S4, the rotated m ciphertext vectors are homomorphically multiplied with the m plaintext data packing vectors obtained in S1 to obtain m plaintext and ciphertext mixed vectors, where The plaintext and ciphertext mixed vector is expressed as: ;

[0027] in, For the A packing vector of plaintext data, To fill the ciphertext vector Rotate Left The ciphertext vector after the step.

[0028] Furthermore, in S5, the m plaintext and ciphertext mixed vectors are accumulated according to the row structure of the matrix, that is, the plaintext and ciphertext mixed elements of the same slot are superimposed to obtain the final output vector as the ciphertext data for training the deep learning model, where the final output vector is expressed as , and its calculation formula is:

[0029] ;

[0030] Furthermore, a homomorphic encryption matrix-vector plain ciphertext hybrid multiplication encryption device is disclosed, which is applicable to the above homomorphic encryption matrix-vector plain ciphertext hybrid multiplication encryption method, including:

[0031] A plaintext data acquisition module is used to pack the plaintext matrix elements column by column along the diagonal to obtain m plaintext data packing vectors, whose length is the number of slots M, and the empty slots are automatically filled with 0;

[0032] The ciphertext vector filling module is used to obtain the initial ciphertext vector according to the number of columns of the plaintext matrix, fill it into a ciphertext vector with the same length as the plaintext data packaging vector, and fill the remaining slots in sequence according to the initial ciphertext vector elements;

[0033] The ciphertext vector rotation module is used to rotate the filled ciphertext vectors in sequence to obtain m different rotated ciphertext vectors. After the rotation, the ciphertext vector element sequence number of each slot is consistent with the element column number of the plaintext data packing vector multiplied by it in the same slot;

[0034] A homomorphic multiplication operation module is used to perform homomorphic multiplication operations on the rotated m ciphertext vectors and the m plaintext data packing vectors obtained by S1 to obtain m plaintext and ciphertext mixed vectors;

[0035] The homomorphic addition operation module is used to superimpose the plaintext and ciphertext mixed elements in the same slot of the m plaintext and ciphertext mixed vectors to obtain the final ciphertext data result vector.

[0036] Furthermore, it also includes a result decryption and output module, which uses a private key to perform the same decryption operation on the ciphertext data result vector to obtain the final plaintext result vector, which is used to verify whether it is consistent with the correct output result after multiplying the original matrix and the plaintext vector.

[0037] It can be seen from the above technical solutions that, compared with the prior art, the present invention has the following beneficial effects:

[0038] (1) The present invention utilizes a matrix-vector plaintext-ciphertext mixed multiplication device based on homomorphic encryption to obtain plaintext-ciphertext mixed ciphertext data for use in the security training of deep learning models. The device can quickly and efficiently obtain ciphertext data, and the obtained ciphertext data can be directly used for the security training of deep learning models without decryption, which is as reliable as the plaintext data obtained after decryption for model training.

[0039] (2) The present invention makes full use of the computing power of the cloud computing platform, reduces the computing overhead of packaging, rotation, homomorphic operations, etc. when acquiring ciphertext data, and improves the efficiency of encryption and decryption of ciphertext data. It is very suitable for secure training of complex deep learning models in an encrypted state without sacrificing data security.

[0040] (3) Although the data input into the deep learning model is encrypted, the structure and weights of the model remain in plain text, allowing researchers to analyze the behavior of the deep learning model without worrying about the leakage of the input data.

[0041] (4) Users can verify the correctness of deep learning model calculations by decrypting the final results, ensuring the credibility of the model output.

[0042] (5) Different organizations can collaborate to train deep learning models without leaking their respective data, thereby improving the generalization ability of deep learning models and reducing overfitting.

[0043] (6) Through encryption technology, organizations can share data and deep learning models without worrying about competitors gaining access to sensitive information. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0045] Figure 1 It is a flow chart of the matrix-vector plaintext mixed homomorphic multiplication encryption method of the present invention;

[0046] Figure 2 A flowchart of an embodiment of homomorphic multiplication of a plaintext matrix with a greater number of columns than rows and a ciphertext vector;

[0047] Figure 3 A flowchart of an embodiment of homomorphic multiplication of a plaintext matrix with a greater number of rows than columns and a ciphertext vector;

[0048] Figure 4 It is a structural diagram of a matrix-vector plaintext hybrid homomorphic multiplication encryption device;

[0049] Figure 5 Another structural diagram of a matrix-vector plaintext mixed homomorphic multiplication encryption device. DETAILED DESCRIPTION

[0050] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0051] The embodiment of the present invention discloses a homomorphic encryption matrix-vector plaintext hybrid multiplication encryption method, comprising the following steps:

[0052] S1. Obtain the target training set, pack the plaintext matrix elements of the training set column by column along the diagonal, obtain the packing vectors of multiple plaintext data, and automatically fill the empty slots with 0;

[0053] S2, fill the ciphertext vector, and fill the remaining slots in sequence according to the elements of the initial ciphertext vector;

[0054] S3, rotate the filled ciphertext vectors in sequence and rotate them to the correct position;

[0055] S4, multiplying the rotated ciphertext vector by the obtained plaintext data vector;

[0056] S5. Add the elements of the corresponding slots of the multiplied plaintext and ciphertext mixed vector to obtain the final output vector as the ciphertext data of the deep learning model training set.

[0057] In this embodiment, in S1, the number of rows in the plaintext matrix is ​​n, and the number of columns is m, which is expressed as ,in, , ;

[0058] The plaintext matrix elements are packed column by column along the diagonal to obtain m plaintext data packing vectors, each of which includes n non-zero elements. The first element of the column is used as the first element to pack diagonally. The packing vector of plaintext data is expressed as:

[0059] ;

[0060] in, For the first The first element of the column is used for diagonal packing. After the number of columns is exhausted, the diagonal packing starts from the first column of the next row. The last element packed is also the first The nth non-zero element of the packed vectors.

[0061] In this embodiment, in S1, the length of the plaintext data packing vector is the number of slots M, the number of slots M is a power of 2, and needs to satisfy ,definition .

[0062] In this embodiment, in S2, the specific process of filling the ciphertext vector includes:

[0063] S21. According to the number of columns of the plaintext matrix, the initial ciphertext vector is obtained, which is expressed as:

[0064] ;

[0065] S22, fill the initial ciphertext vector into a ciphertext vector with the same length as the plaintext data packing vector, which is expressed as:

[0066] .

[0067] In this embodiment, in S3, the filled ciphertext vector is rotated m times in sequence to obtain m different rotated ciphertext vectors. The rotated ciphertext vector is expressed as: or ,

[0068] in, represents the ciphertext vector, Indicates The rotation is performed one time with a step length of one step, and positive or negative indicates rotation to the left or right.

[0069] In this embodiment, in S3, the rotation to the correct position means that the ciphertext vector element sequence number in the slot of each rotated ciphertext vector is consistent with the element column number of the same slot of the plaintext data packing vector multiplied by it.

[0070] In this embodiment, in S4, the rotated m ciphertext vectors are homomorphically multiplied with the m plaintext data packing vectors obtained in S1 to obtain m plaintext and ciphertext mixed vectors, where The plaintext and ciphertext mixed vector is expressed as:

[0071] ;

[0072] in, For the A packing vector of plaintext data, To fill the ciphertext vector Rotate Left The ciphertext vector after the step.

[0073] In this embodiment, in S5, the m plaintext and ciphertext mixed vectors are accumulated according to the row structure of the matrix, that is, the plaintext and ciphertext mixed elements of the same slot are superimposed to obtain the final output vector as the ciphertext data for training the deep learning model, where the final output vector is expressed as , and its calculation formula is:

[0074] .

[0075] In this embodiment, a homomorphic encryption matrix-vector plain ciphertext hybrid multiplication encryption device is disclosed, which is applicable to the above homomorphic encryption matrix-vector plain ciphertext hybrid multiplication encryption method, specifically including: a plaintext data acquisition module, a ciphertext vector filling module, a ciphertext vector rotation module, a homomorphic multiplication operation module, and a homomorphic addition operation module;

[0076] A plaintext data acquisition module is used to pack the plaintext matrix elements column by column along the diagonal to obtain m plaintext data packing vectors, whose length is the number of slots M, and the empty slots are automatically filled with 0;

[0077] The ciphertext vector filling module is used to obtain the initial ciphertext vector according to the number of columns of the plaintext matrix, fill it into a ciphertext vector with the same length as the plaintext data packaging vector, and fill the remaining slots in sequence according to the initial ciphertext vector elements;

[0078] The ciphertext vector rotation module is used to rotate the filled ciphertext vectors in sequence to obtain m different rotated ciphertext vectors. After the rotation, the ciphertext vector element sequence number of each slot is consistent with the element column number of the plaintext data packing vector multiplied by it in the same slot;

[0079] A homomorphic multiplication operation module is used to perform homomorphic multiplication operations on the rotated m ciphertext vectors and the m plaintext data packing vectors obtained by S1 to obtain m plaintext and ciphertext mixed vectors;

[0080] The homomorphic addition operation module is used to superimpose the plaintext and ciphertext mixed elements in the same slot of the m plaintext and ciphertext mixed vectors to obtain the final ciphertext data result vector.

[0081] In this embodiment, a result decryption and output module is also included, which uses the corresponding private key to perform the same decryption operation on the ciphertext data in the ciphertext data result vector to obtain the final plaintext result vector, which is used to verify whether it is consistent with the correct output result after multiplying the original matrix and the plaintext vector.

[0082] exist Figure 2 In this paper, an example of multiplying a matrix with more columns than rows with a ciphertext is given. The input is The plaintext matrix, The number of slots M is a power of 2, so .

[0083] According to the column-by-column diagonal packing principle, four plaintext data vectors are packed. Each packed vector contains two non-zero matrix elements, both in the first two slots, and the remaining slots are filled with 0;

[0084] In the device, the initial length of the input ciphertext vector is slot 2, and the number of ciphertext elements is 2. To perform homomorphic multiplication with the packed plaintext data vector, the slots need to be expanded to 8, and the expanded 6 slots are filled with the elements of the initial ciphertext vector in sequence;

[0085] Since the number of elements in the initial ciphertext vector is the same as the number of columns in the input plaintext matrix, the initial ciphertext vector needs to be expanded by four slots to be consistent with the length of the packed vector; the expanded four slots are filled in the order of the elements of the initial ciphertext to obtain a filled ciphertext vector;

[0086] The filled ciphertext vectors are rotated left one step in sequence to obtain 4 rotated ciphertext vectors. The 4 rotated ciphertext vectors are homomorphically multiplied with the 4 diagonally packed plaintext data vectors to obtain four plaintext and ciphertext mixed vectors. The homomorphic addition operation is performed, that is, the elements of the corresponding slots are accumulated according to the row structure of the matrix to obtain the final encrypted result vector as the output of the device. The encrypted result vector output by the device is the ciphertext data, which is used for the security training of the deep learning model.

[0087] exist Figure 3 , input to the device The plaintext matrix has more rows than columns, , , since the number of slots M is a power of 2, the number of slots M is still 8.

[0088] According to the column-by-column diagonal packing principle, a total of 2 plaintext data vectors are packed. Each plaintext data contains 3 matrix elements, which are filled in the first 3 slots of the vector, and the remaining slots are filled with 0;

[0089] In this embodiment, after the number of columns is exhausted, diagonal packing is continued starting from the first column element of the next row, so the number of non-zero elements in each plaintext data packing vector is the same, which is 3; in other embodiments, the number of non-zero elements in the packing vector can be the same as the number of rows of the plaintext matrix.

[0090] Since the number of columns of the plaintext matrix is ​​2, the number of elements in the input ciphertext vector is 2 at the beginning. Then, the slots are expanded by 6, and the expanded slots are filled in the order of the initial ciphertext vector elements. Finally, the filled eight-slot ciphertext vector is obtained, as shown in the following figure: Figure 3 shown.

[0091] The filled ciphertext vectors are rotated left one step in turn to obtain two rotated ciphertext vectors, which are homomorphically multiplied with the two diagonally packed plaintext data vectors to obtain two plaintext and ciphertext mixed vectors, which can also be called ciphertext result vectors. The two ciphertext result vectors are accumulated according to the row structure of the matrix to obtain the final encryption result vector as the output of the device.

[0092] In an embodiment of the present invention, the multiplication operation of the plaintext vector and the ciphertext vector has a homomorphic property, and the result after the multiplication is then summed to obtain the calculation result of the matrix-vector plaintext and ciphertext mixed multiplication, which is the ciphertext data vector for training the deep learning model. After the same decryption operation, the same result as the multiplication of the original matrix and the plaintext vector is obtained.

[0093] In the embodiment, homomorphic operations are performed in an encrypted state so that the user's original data (such as personal information, medical records, etc.) will not be exposed, thereby effectively protecting data privacy;

[0094] Take full advantage of the computing power of cloud computing platforms to train complex deep learning models without sacrificing data security;

[0095] Although the input data is encrypted, the structure and weights of the deep learning model are still in plain text, allowing researchers to analyze the behavior of deep learning models without worrying about data leakage;

[0096] Users can verify the correctness of the calculation by decrypting the final result, ensuring the credibility of the deep learning model output.

[0097] Different organizations can collaborate to train deep learning models without leaking their respective data, thereby improving the generalization capabilities of deep learning models and reducing overfitting.

[0098] With encryption, organizations can share data and deep learning models without worrying about competitors gaining access to sensitive information.

[0099] The method for obtaining ciphertext data mentioned in the embodiment of the present invention uses the multiplication of plaintext matrix and ciphertext vector to realize the secure training of deep learning model through homomorphic encryption technology. This method combines matrix diagonal packing, ciphertext vector filling and rotation, ciphertext multiplication and accumulation, and finally obtains ciphertext data that can be used for secure training of deep learning model, ensuring efficient data processing in an encrypted state. Through this technology, users can perform model training and inference without exposing the original data, thereby enhancing data security and privacy protection.

[0100] The innovation of this technology lies in: improving the efficiency of homomorphic encryption in the application of deep learning model training, and providing new solutions for multi-party cooperation and data sharing. With the increasingly stringent data protection regulations and the increasing public awareness of privacy protection, the potential value and market demand of this technology in practical applications will continue to grow.

[0101] In the ciphertext multiplication and accumulation stage, the rotated ciphertext vector and the diagonally packed plaintext data vector are subjected to homomorphic multiplication operations respectively. At this time, the ciphertext operation is always kept in an encrypted state, and all encrypted multiplications are completed in the homomorphic encryption domain without exposing any plaintext data.

[0102] After the ciphertext vector and the packed vector are multiplied term by term, multiple ciphertext result vectors will be obtained. In order to obtain the final result, all ciphertext result vectors must be accumulated according to the row structure of the matrix, that is, the operation results of each row are superimposed through homomorphic addition to obtain the final encrypted result vector.

[0103] The key points of the technical solution of the present invention are:

[0104] An arbitrary matrix-vector packing calculation scheme based on homomorphic encryption is proposed, which performs ciphertext rotation and padding under homomorphic properties, reduces the computational complexity, and effectively reduces the number of ciphertext rotations.

[0105] A plaintext matrix packing scheme and a ciphertext padding and rotation scheme are presented, by filling the entire slot with ciphertext and rotating them one by one to reach a position that matches the diagonally packed matrix vector.

[0106] The protection points of the technical solution of the present invention are: a matrix diagonal packing and filling scheme based on homomorphic encryption and a ciphertext vector filling and rotation scheme based on homomorphic encryption.

[0107] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0108] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A homomorphic encryption matrix-vector plaintext hybrid multiplication encryption method, characterized in that: The following steps are involved: S1. Obtain the target training set, pack the plaintext matrix elements of the target training set column by column along the diagonal, obtain the packing vectors of multiple plaintext data, and automatically fill the empty slots with 0; The number of rows in the plaintext matrix is ​​n, and the number of columns is m; In S1, the length of the plaintext data packing vector is the number of slots M, which is a power of 2 and needs to satisfy M ≥ 2k, and k = max(n, m); S2, fill the ciphertext vector, and fill the remaining slots in sequence according to the elements of the initial ciphertext vector; S2 includes: S21. According to the number of columns of the plaintext matrix, the initial ciphertext vector is obtained, which is expressed as: b=[x0,x1,…,x m-1 ]; S22, fill the initial ciphertext vector into a ciphertext vector with the same length as the plaintext data packing vector, which is expressed as: b=[x0,x1,…,x m-1 ,x0,x1,…x m-1 ,…]; S3, rotate the filled ciphertext vectors in sequence and rotate them to the correct position; S4, homomorphically multiplying the rotated ciphertext vector with the obtained plaintext data packing vector; S5. Add the elements of the corresponding slots of the multiplied plaintext and ciphertext mixed vector to obtain the final output vector as the ciphertext data of the deep learning model training set.

2. The method for encryption based on homomorphic encryption matrix-vector plaintext hybrid multiplication according to claim 1 is characterized in that: In S1, the plaintext matrix is ​​represented by A = [a i,j ], where i∈{0,1,2…,n-1}, j∈{0,1,2…,m-1}; The plaintext matrix elements are packed column by column along the diagonal to obtain the packed vectors of m plaintext data, each of which includes n non-zero elements. The packed vector of the i-th plaintext data obtained by diagonally packing the first element of the i-th column is expressed as: w i =[a 0,i ,a 1,i+1 ,…,a n-1+imodm,(i+n)modm ,0,0,…]; Among them, i∈{0,1,2…,m-1}, a n-1+imodm,(i+n)modm It is the nth non-zero element packed diagonally in the ith column, and is the last non-zero element packed diagonally starting from the first column of the next row after the number of columns is exhausted.

3. The method for encryption based on homomorphic encryption matrix-vector plaintext hybrid multiplication according to claim 1 is characterized in that: In S3, the filled ciphertext vector is rotated m times in sequence to obtain m different rotated ciphertext vectors, which are represented by rot(b,i) or rot(b,-i). Among them, b represents the ciphertext vector, i represents the i-th rotation, each rotation step is one step, and positive or negative represents left or right rotation.

4. The method for encryption based on homomorphic encryption matrix-vector plaintext hybrid multiplication according to claim 3 is characterized in that: In S3, the rotation to the correct position is: each time the ciphertext vector is rotated, the ciphertext vector element number in its slot is consistent with the element column number of the same slot of the plaintext data packing vector multiplied with it.

5. The method for encryption based on homomorphic encryption matrix-vector plaintext hybrid multiplication according to claim 4 is characterized in that: In S4, the rotated m ciphertext vectors are homomorphically multiplied with the m plaintext data packing vectors obtained in S1 to obtain m plaintext and ciphertext mixed vectors, where the i-th plaintext and ciphertext mixed vector is expressed as: w i ×rot(b,i); Among them, i∈{0,1,2…,m-1}, w i is the packing vector of the i-th plaintext data, and rot(b,i) is the ciphertext vector after rotating the filled ciphertext vector b to the left i steps.

6. The method for encryption based on homomorphic encryption matrix-vector plaintext hybrid multiplication according to claim 5 is characterized in that: In S5, the m plaintext and ciphertext mixed vectors are accumulated according to the row structure of the matrix to obtain the final output vector as the ciphertext data for training the deep learning model. The final output vector is represented by c, and its calculation formula is:

7. A homomorphic encryption matrix-vector plaintext hybrid multiplication encryption device, characterized in that: It is applicable to the homomorphic encryption matrix-vector plaintext hybrid multiplication encryption method according to any one of claims 1 to 6, including: A plaintext data acquisition module is used to pack the plaintext matrix elements column by column along the diagonal to obtain a packing vector of m plaintext data, whose length is the number of slots M, and the empty slots are automatically filled with 0; The ciphertext vector filling module is used to obtain the initial ciphertext vector according to the number of columns of the plaintext matrix, fill it into a ciphertext vector with the same length as the plaintext data packaging vector, and fill the remaining slots in sequence according to the initial ciphertext vector elements; The ciphertext vector rotation module is used to rotate the filled ciphertext vectors in sequence to obtain m different rotated ciphertext vectors. After the rotation, the ciphertext vector element number of each slot is consistent with the element column number of the same slot of the plaintext data packing vector multiplied by it. A homomorphic multiplication operation module is used to perform homomorphic multiplication operations on the rotated m ciphertext vectors and the m plaintext data packing vectors obtained by S1 to obtain m plaintext and ciphertext mixed vectors; The homomorphic addition operation module is used to superimpose the plaintext and ciphertext mixed elements in the same slot of the m plaintext and ciphertext mixed vectors to obtain the final ciphertext data result vector.

8. The homomorphic encryption matrix-vector plaintext hybrid multiplication encryption device according to claim 7 is characterized in that: It also includes a result decryption and output module, which uses the corresponding private key to perform the same decryption operation on the final ciphertext data result vector to obtain the final plaintext result vector, which is used to verify whether it is consistent with the correct output result after multiplying the original matrix and the plaintext vector.

Citation Information

Patent Citations

  • Privacy protection machine learning method and device based on homomorphic encryption and secure outsourcing matrix

    CN118249980A