A Construction Method of Function Secret Sharing for Comparison Functions

By adopting a function secret sharing construction method for comparison functions in a dual-cloud distributed computing system, using DPF key and prefix parity query algorithm, the problem of large communication overhead of existing privacy protection comparison solutions is solved, and efficient privacy protection comparison operations are achieved.

CN119483918BActive Publication Date: 2025-06-10XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410540817.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-30
Publication Date
2025-06-10
Estimated Expiration
2044-04-30

AI Technical Summary

Technical Problem

The existing privacy protection comparison scheme is based on obfuscated circuits or arithmetic secret sharing design, resulting in higher communication overhead and communication rounds, making it difficult to apply to actual network environments.

Method used

The function secret sharing construction method for comparison functions is adopted, and the DPF keys of servers S0 and S1 are generated through the DPF key generation algorithm, and the prefix parity query algorithm is used to realize the secure calculation of nonlinear functions in a dual-cloud distributed computing system.

Benefits of technology

While protecting user data privacy, it reduces computing complexity and memory usage, improves computing efficiency, and is suitable for scenarios with high overall computing complexity and large data volume.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119483918B_ABST
    Figure CN119483918B_ABST
Patent Text Reader

Abstract

The present invention provides a construction method for function secret sharing for comparison functions, including: in the key generation stage: a trusted third party uses the DPF key generation algorithm to generate DPF keys corresponding to two servers; in the key evaluation stage, two servers S0 and S1 use the DPF keys held by each of them and the prefix parity query algorithm to query the input data, and feed the query results back to the system user; the system user performs an exclusive OR operation on the two query results to obtain the DCF result. Since the parameters of the function are distributedly hidden in the key, any single key cannot be resolved; and during the encrypted state calculation process, the server cannot peek at the plaintext value of the DCF result and only obtains the encrypted state query result; at the same time, the present invention also designs an algorithm that is more lightweight than the existing distributed comparison function scheme, effectively reducing the computational complexity. Therefore, the present invention can provide high computational efficiency while protecting the privacy of user data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a construction method of function secret sharing for comparison functions. Background Art

[0002] For computationally intensive tasks that require privacy protection through secure multi-party computing technology, such as the performance bottleneck of deep neural network inference lies in non-linear operations, especially comparison operations. With the rise of big data and large models, users' demand for privacy protection is also increasing. There is an urgent need to design an efficient secure computing method for comparison functions that can perform non-linear comparison operations efficiently while protecting data privacy.

[0003] Secret sharing technology provides a feasible approach to solve the above problems. Most existing solutions are designed based on garbled circuits or arithmetic secret sharing, resulting in high communication overhead and communication rounds, making it difficult to be applied in actual network environments. Function secret sharing is a new type of cryptographic primitive, first proposed by Boyle et al. at the Eurocrypt conference in 2015, see reference 1 ((BOYLE E, GILBOA N, ISHAI Y. Function secret sharing[C] / / Annual international conference on the theory and applications of cryptographic techniques. Springer, 2015:337-367), which can be applied to the field of secure multi-party computation to achieve secure computation of non-linear functions with single-round communication, and can effectively solve the communication bottleneck of secure multi-party non-linear operations under the semi-honest model. Based on the above article and an improved scheme in 2016 (BOYLE E, GILBOA N, ISHAI Y. Function secret sharing: Improvements and extensions[C] / / Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. 2016:1292-1303), Boyle et al. further improved the distributed comparison function scheme (BOYLE E, CHANDRAN N, GILBOA N, et al. Function secret sharing for mixed-mode and fixed-point secure computation[C] / / Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, 2021:871-900) at the Eurocrypt conference in 2021.

[0004] Most existing privacy protection comparison schemes are designed based on garbled circuits or arithmetic secret sharing, resulting in high communication overhead and communication rounds, and it is difficult to apply them to the actual network environment. The Function Secret Sharing (FSS) proposed by Boyle et al. is a new type of cryptographic primitive that can be applied to the field of secure multi-party computation to achieve secure computation of non-linear functions with single-round communication. It can effectively solve the communication bottleneck of non-linear operations in secure multi-party computation tasks in the semi-honest model. However, the corresponding memory overhead and local computational complexity have increased compared with previous schemes, making it difficult to be practically applied in scenarios with high overall computational complexity and large amounts of data. Summary of the Invention

[0005] To solve the above problems existing in the prior art, the present invention provides a method for constructing function secret sharing for comparison functions. The technical problems to be solved by the present invention are realized through the following technical solutions:

[0006] The present invention provides a method for constructing function secret sharing for comparison functions, including:

[0007] In the key generation stage:

[0008] A trusted third party uses the DPF key generation algorithm to generate DPF keys corresponding to server S0 and server S1. The DPF key corresponding to each server includes shares of input parameters; and the DPF keys are fed back to server S0 and server S1.

[0009] In the key evaluation stage:

[0010] The users of the dual-cloud distributed computing system send input data to server S0 and server S1.

[0011] Server S0 and server S1 both obtain a parity check tree from their respective corresponding DPF keys, then use the prefix parity query algorithm to query the input data and the parity check tree to obtain query results, and feed back the query results to the system users.

[0012] The users of the dual-cloud distributed computing system perform an exclusive OR operation on the query results respectively fed back by server S0 and server S1 to obtain the DCF result.

[0013] Advantageous Effects:

[0014] The present invention provides a function secret sharing construction method for comparison function, including: in the key generation stage: a trusted third party generates DPF keys corresponding to two servers using a DPF key generation algorithm; and feeds back the DPF keys to the two servers S0 and S1; in the key evaluation stage: a system user sends input data to the server S0 and the server S1, and the server S0 and the server S1 both obtain parity check trees from their respective corresponding DPF keys, and then use a prefix parity query algorithm to query the input data and the parity check tree to obtain a query result, and feeds back the query result to the system user; the dual-cloud distributed computing system user performs an XOR operation on the query results fed back by the server S0 and the server S1 to obtain a DCF result. Since the input parameters in the key generation stage are all distributedly hidden in the DPF key, any single DPF key cannot be parsed out; and the server uses the secret state share of the parameters in the DPF key to perform secret state calculations, and cannot spy on the plain text values ​​of the parameters and the DCF results, and finally outputs a result of performing a prefix parity query on the input data using a parity check tree constructed by the DPF key. At the same time, the present invention designs a more lightweight algorithm than the existing solution, effectively reducing the computational complexity and memory usage. Therefore, the present invention can provide higher computational efficiency while protecting user data privacy.

[0015] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a process schematic diagram of a function secret sharing construction method for comparison function provided by the present invention;

[0017] Figure 2 It is a schematic diagram of a DPF binary tree sample provided by the present invention;

[0018] Figure 3 It is a schematic diagram of the tree structure actually contained in the DPF key provided by the present invention;

[0019] Figure 4 This is a schematic diagram of a parity check tree sample provided by the present invention. DETAILED DESCRIPTION

[0020] The present invention is further described in detail below with reference to specific embodiments, but the embodiments of the present invention are not limited thereto.

[0021] Before introducing the present invention, a brief introduction to the field knowledge involved in the present invention is first given.

[0022] Unless otherwise specified, the present invention and the protocols are all run on a dual-cloud distributed outsourcing computing model, with the cloud server being S 0 , S 1. All data operations are performed in the ring , where l represents the number of binary digits of a number.

[0023] Double-cloud distributed outsourcing computing model: The data owner encrypts the data locally and uploads it to two independent cloud servers. The cloud servers execute a series of secure computing protocols according to specific tasks and finally send the encrypted result to the designated user.

[0024] Semi-honest threat model: That is, the server will faithfully execute all operations according to the protocol regulations, but will try to spy on or infer the privacy information related to the original data.

[0025] The present invention relates to function secret sharing. Function secret sharing (FSS) divides a function into two additive or XOR sharing shares f (x) and f 0 (x). Each share hides the specific content of f and ensures that for all inputs x ∈ G 1 , there is f in (x)+f 0 (x) = f(x) or 1 This means that the value of f(x) corresponding to any input x can be reconstructed through its two secret sharing shares. Its formal definition is as follows:

[0026] Definition 1. A two-party function secret sharing (FSS) scheme consists of a pair of probabilistic polynomial-time algorithms, namely Gen(·) and Eval(·). This pair of algorithms has the following characteristics:

[0027] · Gen(1 λ , f) is a key generation algorithm. Given the security parameter λ and the description of the function f, this algorithm outputs a pair of functional keys (k 0 , k 1 ), also known as function secret sharing shares. Each key can effectively describe f 0 and f 1 , while not revealing the specific information of f.

[0028] · Eval(b, k b , x) is a polynomial-time evaluation algorithm. Given the index b ∈ {0, 1} of the participating party, the key k b and the input value x, it can output a secret sharing share f b (x) such that f 0 (x)+f 1 (x) = f(x) or

[0029] ​The technical concept of the present invention will be briefly introduced below.

[0030] Most existing privacy protection comparison schemes are designed based on garbled circuits or arithmetic secret sharing, resulting in high communication overhead and communication rounds, and it is difficult to apply them to the actual network environment. Function Secret Sharing (FSS) is a new type of cryptographic primitive that can be applied to the field of secure multi-party computing to achieve secure computation of non-linear functions with single-round communication. It can effectively solve the communication bottleneck of non-linear operations in secure multi-party computing tasks under the semi-honest model. However, the corresponding memory overhead and local computing complexity have increased compared with the previous schemes, making it difficult to be practically applied in scenarios with high overall computing complexity and large data volume.

[0031] The present invention proposes a construction method of function secret sharing for comparison functions, namely a distributed comparison function (DCF) based on prefix parity query (PPQ), which can implement privacy-protected comparison operations in a distributed system. Based on the implementation method of the distributed comparison function of the present invention, provable security under the semi-honest threat model can be achieved, that is, it is ensured that the comparison operation protocol can be correctly carried out on a distributed cloud server, and the plaintext information of the data participating in the comparison will not be leaked to any cloud server. At the same time, compared with the existing schemes, the memory overhead and local computing complexity during calculation have also been greatly improved.

[0032] The technical solution details of the present invention will be introduced in detail below.

[0033] As Figure 1 shown, the present invention provides a construction method of function secret sharing for comparison functions, including:

[0034] In the key generation stage:

[0035] A trusted third party uses the DPF key generation algorithm to generate the DPF keys corresponding to server S0 and server S1. The DPF key corresponding to each server includes the share of the input parameter; and the DPF key is fed back to the server S0 and the server SI;

[0036] Distributed Point Function (DPF) is an FSS scheme for point functions. A point function outputs a non-zero value at an exact index within its domain, and the specific definition is as follows:

[0037]

[0038] The function of the distributed point function can be viewed as traversing a binary tree of depth l, where l is the bit length of the input data (usually 32 or 64 bits). Among all the paths in the binary tree, there is a unique path from the root node to the α-node, called the 1-path. Among the nodes in the binary tree, only the α-node has a value of 1, and the values ​​of other nodes are all 0.

[0039] refer to Figure 2 , describes a binary tree where each node stores a value that is the XOR result of its child node values. The edges at level i show α i The left side represents 0 and the right side represents 1. The above 1-path is highlighted in red, which ends with a unique α-node. During the evaluation process, each evaluator receives a different initial random state (s, t) ∈ {0, 1} λ ×{0, 1}. Starting from the root node, each evaluator traverses the tree toward the root node and updates its state according to the value of x[i] at each level. This update uses the correction word CW in the function key. (i) As long as x[i] = α[i], we will continue along the special path. If a position x[i] ≠ α[i] appears, the evaluator will immediately deviate from the special path, causing the output to become 0. If we can follow this path all the way to the root node, this indicates that x = α, and the function outputs β.

[0040] The DPF keys held by the servers S0 and S1 contain the data structure of a parity check tree. There are n nodes in the parity check tree. The nodes corresponding to the server S0 are respectively denoted as The node corresponding to server S1 is recorded as refer to Figure 3 , Figure 3 The DPF key actually contains the tree structure, such as Figure 3 Shown in the shaded area.

[0041] In a specific implementation of the present invention, the generation of the DPF keys corresponding to the server S0 and the server S1 by using the DPF key generation algorithm includes:

[0042] S11, receiving security parameters 1λ, parameter α, parameter β, parameter

[0043] S12, using its own pseudo-random number generator, using a binary string of length λ as a pseudo-random number generation seed to generate a 2(λ+1)-bit pseudo-random binary string {0, 1} 2(λ+1) ;

[0044] S13, decompose the parameter α into a binary string α 1 , …, α n∈ {0, 1} n ;

[0045] S14, Generate a 1-bit random number denoted as and denote the result as

[0046] S15, Use a loop block to loop multiple times from i = 1 to n to obtain parameters and

[0047] S16, Use the addition defined on the Abelian group to calculate Denote the result as CW (n+1) ;

[0048] S17, For b = 0, 1, combine CW (1) ,..., CW (n+1) , denoted as k b to obtain the key pair (k 0 , k 1 ); where k 0 is the DPF key of server S0, and k 1 is the DPF key of server S1.

[0049] In a specific embodiment of the present invention, S15 includes:

[0050] S151, Set the loop count i = 1 to n;

[0051] S152, Set as the seed of the pseudo-random number generator G, generate a 2(λ + 1)-bit pseudo-random number, and parse the pseudo-random number into four parts with lengths of λ, 1, λ, and 1 respectively, denoted as where b = 0, 1;

[0052] S153, Execute the first judgment process of the branch block within the loop block to re-label as or

[0053] In this step, execute the first judgment process of the branch block within the loop block. If α i = 0, then denote the variable with superscript L in S152 as as and denote the variable with superscript R as as If α i ≠ 0, denote the variable in S152 as and the variable Denote as

[0054] S154, calculate Denote the result as s CW ;

[0055] S155, calculate Denote the result as Synchronous calculation Denote the result as

[0056] S156, combine s CW 、 Denote as CW (i) ;

[0057] S157, for b = 0, 1, calculate Denote the result as

[0058] S158, for b = 0, 1, calculate Denote the result as

[0059] In the key generation phase, the key generation algorithm of the distributed point function used in this scheme is as shown in Algorithm 1:

[0060]

[0061]

[0062] The detailed analysis of the algorithm is as follows:

[0063] Algorithm parameters: 1 λ : Security parameter, α, β: The meanings refer to the definition of the point function,[[]] The Abelian group to which β belongs

[0064] It should be noted that the random number generation, pseudo-random number generation in the algorithm process and the input and output string lengths of the process are related to λ and are in the form of 1 λ This is a general writing method in cryptography to represent the string length, {0, 1} n represents a binary string of 0s and 1s with length n. Note the distinction from the superscript of letter variables.

[0065] The algorithm executor holds a pseudo-random number generator G. G accepts a binary string of length λ as the pseudo-random number generation seed and generates a pseudo-random binary string of 2(λ + 1) bits.

[0066] is an arbitrary mapping method that converts a binary string of length λ to the Abelian group above.

[0067] Algorithm process:

[0068] 1. Decompose the input α into its binary string representation α 1 ,…,α n ∈{0,1} n

[0069] 2. Generate two random numbers with a binary length of λ, denoted as

[0070] 3. Generate a 1-bit random number, denoted as Let The result of be denoted as

[0071] 4. Start of the loop block: For i = 1 to n:

[0072] 5. Set As the seed of the pseudo-random number generator G, generate a pseudo-random number with a length of 2(λ + 1) bits, and parse it into four parts with lengths of λ, 1, λ, and 1 respectively, denoted as where b = 0,1.

[0073] 6. Start of the branch block: If α i = 0, then denote the variable with superscript L generated in step 5 as Denote as The variable with superscript R Denote as where b = 0,1.

[0074] 7. Otherwise: Contrary to step 6, denote the variable Denote as The variable Denote as where b = 0,1.

[0075] 8. End of the branch block

[0076] 9. Calculate Denote the result as s CW

[0077] 10. Calculate Denote the result as Calculate Denote the result as

[0078] 11. Combine s CW 、 Denote as CW (i)

[0079] 12. For b = 0,1, calculate Denote the result as

[0080] 13. For b = 0, 1, calculate Denote the result as

[0081] 14. End of the loop block

[0082] 15. Use the addition defined on to calculate Denote the result as CW (n+1)

[0083] 16. For b = 0, 1, combine CW (1) ,..., CW (n+1) , and denote it as k b

[0084] 17. Return the key pair (k 0 , k 1 )

[0085] In the above algorithm process, the information of α and β is distributedly hidden in k 0 , k 1 The two keys, and the plaintext values of α and β cannot be parsed and restored from any single key.

[0086] In the key evaluation stage:

[0087] The users of the dual-cloud distributed computing system send the input data to the server S0 and server S1;

[0088] Both the server S0 and server S1 obtain the parity check tree from their respective DPF keys, then use the prefix parity query algorithm to query the input data and the parity check tree to get the query result, and feedback the query result to the system user;

[0089] The users of the dual-cloud distributed computing system perform an exclusive OR operation on the query results respectively feedback by the server S0 and server S1 to obtain the DCF result.

[0090] Given a binary bit string x = x 0 x 1 , ···, x l-1 , assume there exists a substring x a x a+1 , ···, x b-1 , denoted as x[a, b), where 0 ≤ a < b ≤ l. The parity check query for x[a, b) is defined as follows:

[0091]

[0092] This solution uses a data structure called a parity check tree to perform parity check queries, and the computational complexity of this process is O(l). In the parity check tree, the value of each node is the parity check result of its two child nodes. The parity check tree is constructed bottom-up. First, x is split into 2 k substrings, each substring containing λ bits, where it is assumed that l / λ = 2 k . Next, for each substring, a leaf node is generated and the substring is linked to the node. The parity value of the substring is stored within the leaf node. Then, for each pair of adjacent leaf nodes, a parent node is inserted and the parity value of its two child nodes is stored therein. This process is repeated for each pair of adjacent parent nodes until a single root node is formed. At this point, the parity bit held by any given node is equal to the parity of the concatenation of the substrings of x associated with all the descendant leaf nodes of that node.

[0093] Figure 4 Figure 8 shows an example of a parity check tree, in which the binary bit string is x = 0010110010111011 2 . It can be stipulated that the traversal of the substrings is always to the left, and at this time the substrings can be regarded as the left child nodes of the leaf nodes (in fact, this relationship does not exist, so it is represented by a dotted line). The specific steps for traversing the parity check tree are further given as follows:

[0094] · Initialize the output r to 0 and set the path direction to the left;

[0095] · Starting from the root node, traverse to the leaf node associated with the binary bit a;

[0096] · When the traversal path direction changes, update the output r by XORing the parity value stored at the changing node;

[0097] · XOR all the prefix binary bits in the substring associated with the leaf node and output r.

[0098] Furthermore, in order to obtain x[a,b), it is only necessary to sequentially traverse the parity check tree to obtain parity(x[0,a)) and parity(x[0,b)) respectively. Subsequently, through the equivalent transformation of the following formula, the parity value of x[a,b) is further obtained:

[0099]

[0100] The correctness of the above formula stems from the idempotency of the exclusive OR calculation (XOR). Therefore, calculating the prefix parity of binary bits a and b can obtain the correct parity of x[a,b). Figure 2The green arrow in [ ] indicates the traversal process of parity(x[0,a)). The green dots are used to mark the nodes where the direction changes. Based on this traversal process, the following can be obtained:

[0101]

[0102] Through a similar traversal, parity(x[0,b)) = 1 can be obtained (marked with blue arrows and nodes). According to the defined formula, the parity check query of x[a,b) can be calculated as follows:

[0103]

[0104] In a specific embodiment of the present invention, the reuse prefix parity check query algorithm queries the input data and the parity check tree to obtain the query result, including:

[0105] S21, taking the security parameter 1 λ , the input data x, and the DPF key k of the dot function b as the input;

[0106] S22, for b ∈ {0, 1}, decomposing the input data x into binary strings, denoted as x 1 , …, x l ∈ {0, 1} l ;

[0107] S23, parsing the DPF key k b to obtain s (0) , t (0) , CW (1) , …, CW (l+1) ;

[0108] S24, initializing the variable pv b = 0, d = 0;

[0109] S25, using a loop block to loop multiple times from i = 1 to l to update or to obtain the prefix parity check result pv b .

[0110] In a specific embodiment of the present invention, S25 includes:

[0111] S251, for i ∈ [1, l], using a loop block to parse CW (i) to obtain s CW ,

[0112] S252, calculating and denoting the result as τ (i) ;

[0113] S253, Parse τ (i) Obtain s L , t L , s R , t R ∈ {0, 1} 2(λ+1) ;

[0114] S254, Execute the second judgment process of the branch block within the loop block to record s L , t L as s (i) , t (i) or record s R , t R as s (i) , t (i) ;

[0115] In this step, execute the second judgment process of the branch block within the loop block. If x i = 0, then record s L as s (i) , and record t L as t (i) ; if x i ≠ 0, then record s R as s (i) , and record t R as t (i) .

[0116] S255, Execute the third judgment process of the branch block within the loop block to update or Obtain the prefix parity query result pv b .

[0117] In this step, execute the third judgment process of the branch block within the loop block. If d ≠ x i , then update d = x i , If d = 1, then update Obtain the prefix parity query result pv b .

[0118] The Distributed Comparison Function (DCF) is an FSS scheme for comparison functions. The comparison function has a boundary at a specific index within its domain. The distributed comparison function defined in this scheme outputs 0 when the input is less than or equal to this value, and outputs a non-zero value β when it is greater than this value. The specific definition is as follows:

[0119]

[0120] In the key evaluation execution phase, the distributed comparison function evaluation algorithm based on prefix parity query designed in this scheme performs prefix parity query on the distributed dot function key generated by Algorithm 1, as shown in Algorithm 2. In this algorithm, pv b and d respectively represent the continuously updated parity check value and the traversal direction of the current tree. Finally, the results of the parity checks of the two parties, pv b are XORed to obtain the execution result of the distributed comparison function.

[0121]

[0122]

[0123] The following is a detailed analysis of the above Algorithm 2:

[0124] Algorithm parameters: Security parameter 1 λ , input x, dot function DPF key k of b

[0125] Note: The lengths of the input and output strings of the following random number generation, pseudorandom number generation, and processes are related to λ and are in the form of 1 λ which is a common cryptographic notation for representing string lengths, and {0, 1} l represents a binary string of length l consisting of 0s and 1s. Note the distinction from the superscripts of letter variables.

[0126] The algorithm executor holds a pseudorandom number generator G that accepts a binary string of length λ as a seed and generates a pseudorandom binary string of 2(λ + 1) bits. Denote the pseudorandom number obtained by setting x as the seed for pseudorandom number generation as G(x).

[0127] is an arbitrary mapping method that converts a binary string of length λ to an Abelian group . a||b||c||d represents the combination of a, b, c, and d.

[0128] Algorithm process:

[0129] 1. For b ∈ {0, 1}, do the following:

[0130] 2. Decompose x into its binary string representation x 1 , …, x l ∈ {0, 1} l

[0131] 3. Parse k b to obtain s (0) , t (0) , CW (1) , …, CW (l+1)

[0132] 4. Initialize the variable pv b = 0, d = 0

[0133] 5. Start of loop block: For i ∈ [1, l]:

[0134] 6. Parse CW (i) Get S CW 、

[0135] 7. Calculate Record the result as τ (i)

[0136] 8. Parse τ (i) Get s L 、t L 、s R 、t R ∈ {0, 1} 2(λ+1)

[0137] 9. Start of branch block: If x i = 0 then:

[0138] 10. Record s L as s (i) and record t L as t (i)

[0139] 11. Otherwise:

[0140] 12. Record s R as s (i) and record t R as t (i)

[0141] 13. End of branch block

[0142] 14. Start of branch block: If d ≠ x i then:

[0143] 15. Update d = x i

[0144] 16. Update

[0145] 17. End of branch block

[0146] 18. End of loop block

[0147] 19. Start of branch block: If d = 1 then:

[0148] 20. Update

[0149] 21. End of branch block

[0150] 22. Return the prefix parity query result pv b

[0151] In the above algorithm process, the algorithm executor uses the encrypted state share of α existing in the DPF key for encrypted state calculation. During the calculation process, the algorithm executor can never peek at the plaintext value of α, and finally outputs a result of performing a prefix parity query on the input x using the parity check tree constructed by the key k b That is, the result in the form of an exclusive-or sharing of the distributed comparison function of the result.

[0152] The present invention realizes a distributed comparison function calculation that occupies less system resources and runs more efficiently on the premise of protecting data privacy. Compared with the existing work, this solution occupies less memory space, and because the number of pseudo-random numbers generated during the algorithm process is nearly halved compared to the original DCF scheme, it has higher computing efficiency. Simple experimental evaluations were carried out on the key technologies involved in the present invention, where the element bit width l of the input vector is 64, the test machine CPU is i7-11800H, and the GPU is NVIDIA GeForce RTX3060 Laptop. The test code is written in the Python language, and the specific experimental data is as follows:

[0153]

[0154]

[0155] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality" means two or more, unless otherwise specifically defined.

[0156] Although the present application has been described in conjunction with various embodiments herein, however, in implementing the claimed present application, those skilled in the art can understand and realize other variations of the disclosed embodiments by viewing the accompanying drawings, the disclosed content, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality of cases.

[0157] The above content is a further detailed description of the present invention in combination with specific preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A method for constructing a function secret sharing for comparison functions, characterized in that: include: During the key generation phase: The trusted third party generates DPF keys corresponding to server S0 and server S1 using the DPF key generation algorithm. The DPF key corresponding to each server includes a share of the input parameters. And feed back the DPF key to the server S0 and server S1; During the key evaluation phase: The user of the dual-cloud distributed computing system sends input data to the server S0 and the server S1; The server S0 and the server S1 both obtain the parity check tree from their respective corresponding DPF keys, and then use the prefix parity query algorithm to query the input data and the parity check tree to obtain the query result, and feed back the query result to the system user; The dual-cloud distributed computing system user performs an XOR operation on the query results fed back by the server S0 and the server S1 to obtain a DCF result; The step of querying the input data and the parity check tree using the prefix parity query algorithm to obtain the query result comprises: S21, set the safety parameter 1 λ , input data x, point function The DPF key k b As input; S22, for b∈{0,1}, decompose the input data x into a binary string, represented as S23, parse DPF key k b get S24, initialize variable pv b =0,d=0; S25, using the loop block from i = 1 to Repeat multiple times to update or Get the prefix parity query result pv b .

2. The method for constructing a function secret sharing for comparison functions according to claim 1, characterized in that: The DPF keys of the servers S0 and S1 contain the data structure of a parity check tree. There are n nodes in the parity check tree. The nodes corresponding to the server S0 are respectively denoted as The node corresponding to server S1 is recorded as 3. The method for constructing a function secret sharing for comparison functions according to claim 2, characterized in that: The method of using the DPF key generation algorithm to generate the DPF keys corresponding to the server S0 and the server S1 includes: S11, receiving security parameters 1 λ , parameter α, parameter β, parameter S12, using its own pseudo-random number generator, uses a binary string of length λ as a pseudo-random number generation seed to generate a 2(λ+1)-bit pseudo-random binary string {0,1} 2(λ+1) ; S13, decompose the parameter α into binary strings α1,…,α n ∈{0,1} n ; S14, generate a 1-bit random number and record it as and will The result is recorded as S15, use the loop block to loop from i=1 to n multiple times to obtain the parameters and S16, using the definition in the Abelian group Addition calculation on The result is recorded as CW (n+1) ; S17, for b = 0, 1, combination Denoted as k b A key pair (k0, k1) is obtained; wherein k0 is the DPF key of server S0, and k1 is the DPF key of server S1.

4. The method for constructing a function secret sharing for comparison functions according to claim 3, characterized in that: S15 includes: S151, setting the number of cycles i=1 to n; S152, Set as the seed of the pseudo-random number generator G, generate a 2(λ+1)-bit pseudo-random number, and parse the pseudo-random number into four parts with lengths of λ, 1, λ, and 1, respectively, denoted as Where b = 0, 1; S153, executing the first judgment process of the branch block in the loop block to Re-labeled as or S154, calculation Let the result be s CW ; S155, calculation Record the result as Synchronous calculation Record the result as S156, Combination S CW , CW (i) ; S157, for b = 0, 1, calculate Record the result as S158, for b = 0, 1, calculate Record the result as 5. The method for constructing a function secret sharing for comparison functions according to claim 4, characterized in that: S153 includes: Execute the first judgment process of the branch block in the loop block. If α i = 0, then the variable superscripted with L in S152 Recorded as Variables with superscript R Recorded as If α i ≠0, the variable in S152 Recorded as variable Recorded as 6. The method for constructing a function secret sharing for comparison functions according to claim 1, characterized in that: S25 includes: S251, for Parsing CW using loop blocks (i) Get CW , S252, calculation Let τ be the result. (i) ; S253, Analytical τ (i) Get L ,t L 、s R ,t R ∈{0,1} 2(λ+1) S254, executing the second judgment process of the branch block in the loop block to convert s L ,t L Denoted as s (i) ,t (i) Or R ,t R Denoted as s (i) ,t (i) ; S255, executing the third judgment process of the branch block in the loop block to update or Get the prefix parity query result pv b .

7. The method for constructing a function secret sharing for comparison functions according to claim 6, characterized in that: S254 includes: Execute the second judgment process of the branch block in the loop block. If x i = 0, then s L Note: s (i) , t L Denoted as t (i) ; if x i ≠0, then s R Note: s (i) , t R Denoted as t (i) .

8. The method for constructing a function secret sharing for comparison functions according to claim 6, characterized in that: S255 includes: executing the third judgment process of the branch block in the loop block, if d≠x i , then update d = x i , If d = 1, update Get the prefix parity query result pv b .

Citation Information

Patent Citations

  • Two-party function secret sharing method

    CN115065462A

  • Multi-party database query method and system for privacy protection

    CN117827892A