Fast Calculation Method for Multiplication of Ciphertext Matrices Based on Homomorphic Encryption

By performing rotation preprocessing of diagonal vector ciphertext under the rotation-encoded matrix multiplication framework, and using the ciphertext rotation multiplication method, the calculation of multiple ciphertext matrix multiplication is optimized, which solves the problem of unsatisfactory calculation efficiency in the prior art, and realizes efficient ciphertext matrix multiplication.

CN119519919BActive Publication Date: 2025-06-20CHONGQING INST OF GREEN & INTELLIGENT TECH CHINESE ACAD OF SCI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411528002.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-06-20
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

In the prior art, when performing multiplication of multiple ciphertext matrixes, the computing efficiency is not ideal, especially in the dense state computing scenario of large language models, it is necessary to perform multiplication of multiple ciphertext matrixes.

Method used

Under the matrix multiplication framework of rotation encoding, preprocessing of the diagonal vector ciphertext is realized through preprocessing. In response to the multiplication of multiple ciphertext matrices, the diagonal element ciphertext vector is constructed for optimization calculations.

Benefits of technology

It greatly reduces computing time and improves computing efficiency. It is suitable for ciphertext calculations in transformer neural networks. There is no need to decrypt the intermediate links, which significantly improves computing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119519919B_ABST
    Figure CN119519919B_ABST
Patent Text Reader

Abstract

The present invention is a fast calculation method for multiplying ciphertext matrices based on homomorphic encryption, belonging to the field of information security. The method includes the following steps: S1: Set a homomorphic encryption scheme and parameters; S2: The client generates a public-private key pair and an operation key; S3: The client factorizes the multiplication formula of the plaintext matrix; S4: The client encrypts each factor one by one to obtain ciphertext vectors; S5: The server performs ciphertext matrix multiplication on all factors to obtain the ciphertext result matrix of all factors; S6: Repeat steps S3 to S5 until the ciphertext result matrix of the multiplication formula of the plaintext matrix is calculated; S7: The server sends the ciphertext result matrix to the client; S8: The client decrypts the ciphertext result matrix. The method of the present invention constructs a diagonal element ciphertext vector by means of ciphertext rotation multiplication, greatly reducing the calculation complexity; when applied to the ciphertext calculation of the transformer network, it can directly realize the ciphertext prediction of the transformer network, greatly improving the calculation efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a fast calculation method for multiplying encrypted matrices based on homomorphic encryption, belonging to the field of information security, and is particularly applicable to the fast calculation of multiplying encrypted matrices based on homomorphic encryption. Background Art

[0002] With the booming development of the field of machine learning, it has been widely applied in many fields such as computers, information security, and data analysis. Although machine learning has made great progress in improving social productivity, a large number of shared data sets have also brought serious privacy and security problems. Therefore, privacy computing technology has been proposed, aiming to better serve various fields under the condition of protecting data privacy. At the same time, the field of machine learning involves a large number of matrix multiplication calculations, and the efficiency of matrix multiplication directly affects the performance of the overall model. Therefore, in the field of privacy computing, the importance of optimizing matrix multiplication operations has been significantly improved, especially optimizing the encrypted matrix multiplication operation after being encrypted by homomorphic encryption technology, which has gradually become a research hotspot.

[0003] Homomorphic encryption is an encryption scheme that allows direct calculation on ciphertexts, and the decrypted result matches the result of the corresponding operation on the plaintext. It can perform effective data analysis and processing while protecting data privacy, and can provide quantum-resistant security. Therefore, it is considered to be one of the most promising privacy protection solutions. Currently, homomorphic encryption technology has become an important way to solve privacy and security in fields such as outsourced computing, bioinformatics, vehicle networking, and machine learning. Among the many applications of privacy protection computing based on homomorphic encryption, matrix operation is the most basic operation. Therefore, improving the efficiency of encrypted matrix operations can promote the application of homomorphic encryption in various fields. In the calculation of plaintext matrix - encrypted matrix multiplication, in order to improve the efficiency of the homomorphic scheme, Reference [1] proposed to introduce a batch processing technology of single instruction multiple data (SIMD) in homomorphic encryption to process data in parallel, but this also led to difficulties in calculating the inner product of vectors and reduced the calculation efficiency of encrypted matrix multiplication. For this reason, Reference [2] performed a linear transformation on the encrypted vectors in Reference [1] to achieve efficient matrix multiplication.

[0004] Regarding the multiplication calculation of ciphertext matrices, current research is limited to the case of multiplying two matrices. The multiplication calculation of multiple ciphertext matrices is also implemented by splitting it into the form of multiplying two matrices layer by layer. For example, when performing ciphertext calculation in the widely used neural network structure Transformer, in the multi-head attention part of Transformer, the continuous multiplication of three matrices Q, K, and V needs to be calculated. The algorithms in references [1, 2] can be directly applied to this scenario, but the calculation efficiency is not very ideal. Especially in scenarios such as the encrypted state calculation of large language models, a large number of continuous multiplications of multiple ciphertext matrices are required.

[0005] In summary, for the scenario where the sender needs to perform data encryption protection and the calculator has a model for calculation, there is an urgent need to improve the fast calculation method for the continuous multiplication of ciphertext matrices.

[0006] [1] HALEVI S,SHOUP V.Algorithms in helib;proceedings of the Advancesin Cryptology–CRYPTO 2014:34th Annual Cryptology Conference,Santa Barbara,CA,USA,August 17-21,2014,Proceedings,Part I 34,F,2014.

[0007] [2] Halevi,S.,Shoup,V.(2015).Bootstrapping for HElib.In:Oswald,E.,Fischlin,M.(eds)Advances in Cryptology--EUROCRYPT 2015.EUROCRYPT 2015.LectureNotes in Computer Science(),vol 9056.Springer,Berlin,Heidelberg.

[0008] [3] Brakerski,Z.,Gentry,C.,Vaikuntanathan,V.:(Leveled)fullyhomomorphic encryption without bootstrapping.ACM Transactions on ComputationTheory 6(3),13:1–13:36(2014).https: / / doi.org / 10.1145 / 2633600.

[0009] [4] Junfeng Fan and Frederik Vercauteren. Somewhat Practical Fully Homomorphic Encryption. Cryptology ePrint Archive, Report 2012 / 144, 2012. https: / / eprint.iacr.org / 2012 / 144.

[0010] [5] CHEON J H, KIM A, KIM M, et al. Homomorphic encryption for arithmetic of approximate numbers;proceedings of the Advances in Cryptology–ASIACRYPT 2017: 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3 - 7, 2017, Proceedings, Part I23, F, 2017[C]. Springer. https: / / doi.org / 10.1007 / 978-3-319-70694-8_15.

[0011] [6] Xiaoqian Jiang, Miran Kim, Kristin Lauter, and Yongsoo Song. Secure outsourced matrix computation and application to neural networks. In David Lie, Mohammad Mannan, Michael Backes, and XiaoFeng Wang, editors, Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (October 15–19, 2018, Toronto, Canada), pages 1209–1222. ACM, New York, 2018. Summary of the Invention

[0012] In view of this, for the case of continuously multiplying multiple ciphertext matrices in the computing party, the present invention proposes a fast calculation method for multiplying ciphertext matrices based on homomorphic encryption. Under the framework of matrix multiplication with rotation encoding, through preprocessing, the rotation preprocessing of diagonal vector ciphertext can be realized, which can greatly reduce the calculation time and improve the calculation efficiency.

[0013] To achieve the above object, first, the symbols involved in the present invention are defined as follows:

[0014] (1) Let the plaintext space be and the ciphertext space be Use Enc to represent the encryption algorithm operation, Dec to represent the decryption algorithm operation; use Encode to represent the data encoding operation, Decode to represent the data decoding operation; use k to represent taking the non - negative residue modulo k for calculating a numerical value, and ⊙ to represent the Hadamard Product of vectors; to represent rounding up, to represent rounding down.

[0015] (2) The addition operation of d ciphertexts is The output ciphertext c satisfies Dec(c1)+Dec(c2)+…+Dec(c d ) = Dec(c), where d is a positive integer.

[0016] (3) The multiplication operation of ciphertext c1 and c2 is The output ciphertext c satisfies Dec(c1)⊙Dec(c2) = Dec(c).

[0017] (4) The rotation operation of ciphertext c is Input ciphertext c=(c0,c1,…,c n-1 ) and an integer The output ciphertext is That is, a new plaintext obtained by rotating each component of c to the left by ciphertext slots. If is negative, it means rotating to the right; where each component of c is called a ciphertext slot, and there are a total of n ciphertext slots.

[0018] Combined with Figure 1 , for the case where the client encrypts data and sends it to the computing party for continuously multiplying multiple ciphertext matrices, the present invention provides a "fast calculation method for multiplying ciphertext matrices based on homomorphic encryption", including the following steps:

[0019] S1: The user sets the security parameter λ of the homomorphic encryption scheme ε = (Enc, Dec) on the client side, and generates the relevant encryption and decryption parameters of the homomorphic encryption scheme according to the security parameter λ;

[0020] S2: The client generates the private key sk, the public key pk and the operation key ek according to the encryption and decryption parameters;

[0021] S3: The client factorizes the consecutive multiplication formula of the plaintext matrix, and extracts the factors of the consecutive multiplication of three matrices and the factors of the multiplication of two matrices therein;

[0022] S4: The client uses the public key pk to encrypt the plaintext matrix in the factor by vector one by one to obtain the ciphertext vector; and packs and sends the ciphertext matrix, the public key pk and the operation key ek to the server;

[0023] S5: The server performs ciphertext matrix multiplication calculations on all factors using parallel computing, obtains the ciphertext result matrices of all factors, and uses them to replace the factors in the consecutive multiplication formula of the corresponding plaintext matrix;

[0024] S6: Repeat steps S3 - S5 until the ciphertext result matrix of the consecutive multiplication formula of the plaintext matrix is calculated;

[0025] S7: The server sends the ciphertext result matrix of the consecutive multiplication formula of the plaintext matrix to the client;

[0026] S8: The client decrypts the ciphertext result matrix of the consecutive multiplication formula of the plaintext matrix using the private key sk.

[0027] Furthermore, the specific steps of step S1 are as follows:

[0028] S101: Determine the security parameter λ, that is, it can resist at least an adversary with the computing power of 2 λ bit operations;

[0029] S102: The client selects the SIMD homomorphic encryption method according to the requirements, and determines the size q of the ciphertext slots in the ciphertext homomorphic scheme;

[0030] S103: The client selects an integer p according to the sample data, and the numerical size will not exceed p / 2 during the ciphertext calculation process;

[0031] S104: The user selects the parameters m and q according to the security parameter λ and in accordance with the suggestions in the Homomorphic Encryption Security Standard, and determines that the plaintext space of the homomorphic encryption scheme is that is, the ring of polynomials with integer coefficients modulo the m - th cyclotomic polynomial φ mThe residue class ring obtained after generating the ideal by (X) and the integer p, and the ciphertext space is

[0032] Preferably, the homomorphic encryption scheme described in step S1 can be all schemes using SIMD technology, including: BGV scheme [3], B / FV scheme [4], and CKKS scheme [5].

[0033] Preferably, for the security parameter λ, take λ = 128 or 256; and the error distribution χ is taken as the discrete Gaussian distribution.

[0034] Furthermore, the specific step S2 is as follows:

[0035] S201: The client generates a random polynomial f whose coefficients are randomly selected from the set {-1, 0, 1} with equal probability and the number of indeterminates X does not exceed where represents the number of elements in the set {1, 2,..., m} that are relatively prime to m, then the private key sk = (1, f);

[0036] S202: The client randomly selects a polynomial a of the indeterminate X from the uniform distribution of R q , and randomly selects a noise polynomial e of the indeterminate X from the error distribution χ of , then the public key pk = (-[(a·f + e)] q , a), where [·] q represents the polynomial obtained by taking the coefficients of the polynomial in the square brackets modulo q;

[0037] S203: The client generates the operation key ek required for noise control during the generation of ciphertext according to the selected homomorphic encryption scheme.

[0038] Furthermore, the factorization described in step S3 is specifically: For the consecutive multiplication formula of the plaintext matrix, take every three matrices as a factor in sequence, and preferentially extract several factors of the consecutive multiplication of three matrices, leaving a factor of the multiplication of two matrices or a single matrix.

[0039] Furthermore, for the factor of the multiplication of two matrices, encrypt the two matrices column by column in the manner described in reference [6].

[0040] Furthermore, for the factor Q·K·V of the consecutive multiplication of three matrices, the specific step S4 is as follows:

[0041] S401: The client respectively adds a 0 column vector to matrix K and a 0 row vector to matrix V, so that

[0042] S402: The client separately arranges Q by columns, K by rows, and V by columns, and uses the public key pk to encrypt their plaintext vectors q j , k j , v j respectively to obtain the corresponding ciphertexts c q,j = Enc pk (q j ), c k,j = Enc pk (k j ), c v,j = Enc pk (v j ); where Q = [q j 0≤j≤m-1 , V = [v j 0≤j≤m-1 , j = 0, …, m - 1;

[0043] S403: The client packs and sends the ciphertext vectors {c q,j}, {c 0≤j<m}, {c k,j}, the public key pk, and the operation key ek to the server. 0≤j<m v,j 0≤j<m}, {c 0≤j<m}, the public key pk, and the operation key ek to the server.

[0044] Furthermore, the factors for multiplying the two matrices directly adopt the method in Reference [6] to implement the ciphertext matrix multiplication calculation in step S5, obtaining the ciphertext result matrix of the factors, and replacing the factors for multiplying the two matrices in the continuous multiplication formula of the plaintext matrix with the ciphertext result matrix of the factors.

[0045] Furthermore, for any three matrix continuous multiplication factors Q·K·V, step S5 is specifically as follows:

[0046] S501: The server determines the outer loop number l and the inner loop number k according to the number of columns m of matrix K, and requires that m ≤ l·k, where l and k are positive integers;

[0047] S502: The server calculates the diagonal element ciphertext vector of Q·K where 0 ≤ i < l, 0 ≤ j < k;

[0048] S503: The server calculates the ciphertext result column vector of Q·K·v s where 0 ≤ s < d;

[0049]

[0049] S504: Repeat step S503, traverse all column vectors of V, calculate the ciphertext result matrix [c s 0≤s<m of Q·K·V, and use [c​​​s 0≤s<m Replace Q·K·V in the consecutive multiplication formula of the plaintext matrix.

[0050] Preferably, in order to reduce the computational complexity, the smaller the distance |l - k| between the outer loop number l and the inner loop number k described in step S501, the better.

[0051] Preferably, in order to improve the computational efficiency, the calculation of the diagonal element ciphertext vectors of Q·K described in step S502 is independent of each other, and parallel computing can be used to achieve it.

[0052] Preferably, during the replacement process of the consecutive multiplication formula of the plaintext matrix in step S504, the middle matrix K of the three-matrix consecutive multiplication factor Q·K·V that appears in the next round of calculation needs to be transposed.

[0053] A transformer neural network for homomorphic ciphertext data applied to the fast calculation method of consecutive multiplication of ciphertext matrices based on homomorphic encryption, characterized in that the transformer neural network for homomorphic ciphertext data is a multi-layer transformer neural network trained with a plaintext data set, the input is ciphertext data, the output is ciphertext prediction data, and no decryption is required in the middle link; each layer of the transformer neural network is composed of a multi-head attention mechanism, an Add&Norm layer, a feed-forward neural network layer (Feed Forward), a pooling layer (Pooling), and a Softmax layer; the multi-head attention mechanism processes the factors of three-matrix consecutive multiplication.

[0054] The beneficial effects of the present invention are as follows: The present invention provides a fast calculation method for consecutive multiplication of ciphertext matrices based on homomorphic encryption. For the factors of three-matrix consecutive multiplication, the method of rotating and multiplying ciphertexts is adopted, and the optimization of consecutive multiplication of ciphertext matrices is realized by constructing diagonal element ciphertext vectors, greatly reducing the computational complexity; it can naturally fit into the ciphertext calculation of the transformer neural network, no decryption is required in the middle link, and the ciphertext prediction of the transformer neural network can be directly realized, greatly improving the computational efficiency. Description of the Drawings

[0055] In order to illustrate the purpose and technical solutions of the present invention, the following drawings are provided for illustration:

[0056] Figure 1 It is a framework diagram of model inference for privacy protection involving two parties;

[0057] Figure 2 It is a flowchart of Embodiment 1 of the present invention;

[0058] Figure 3 ​This is the architecture diagram of the single-layer transformer neural network for Embodiment 2 of the present invention. Detailed implementation manners

[0059] Embodiment 1: The client needs to calculate a matrix multiplication formula, but due to insufficient computing power of its own, it needs to rely on the server side for calculation. In order to achieve the purpose of data privacy protection, under the model inference framework for privacy protection involving two parties, the client encrypts the matrix, sends the ciphertext to the server of the computing service party, and the server completes the calculation and sends it back to the client. The client decrypts the ciphertext to obtain the calculation result. For this scenario, the present invention provides a "fast calculation method for ciphertext matrix multiplication based on homomorphic encryption".

[0060] In this embodiment, to better demonstrate the method of the present invention, it is assumed that the client needs to calculate Y = Q·K·V·A·B, where the plaintext matrix needs to be calculated on the server side while protecting the plaintext data.

[0061] Next, the preferred application examples of the present invention will be described in detail with reference to the accompanying drawings.

[0062] As Figure 2 shown, it specifically includes the following steps:

[0063] Step 1: The user sets the security parameter λ of the CKKS homomorphic encryption scheme ε = (Enc, Dec) on the client side, and generates the relevant encryption and decryption parameters of the homomorphic encryption scheme according to the security parameter λ.

[0064] (1) The client sets the security parameter λ = 128 according to the selected homomorphic encryption scheme;

[0065] (2) Determine the size q of the ciphertext slots in the ciphertext homomorphic scheme to be 4;

[0066] (2) Select the prime number p = 40;

[0067] (3) According to the homomorphic encryption standard, select the parameter q as a product of randomly selected 4 odd prime numbers with bit lengths between 40 and 60, and the bit length of q is about 200.

[0068] Step 2: The client generates a key according to the security parameter.

[0069] (1) Uniformly and randomly select a polynomial f from the set of univariate polynomials with coefficients {-1, 0, 1} and degrees not exceeding and let the private key sk = (1, f);

[0070] (2) Randomly and uniformly select a polynomial \(a\) from the set of univariate polynomials with coefficients \(\{0, 1, 2, \ldots, q - 1\}\) and degree not exceeding 8192, and select a noise polynomial \(e\) from the discrete Gaussian distribution with standard deviation 3.2 on the set of polynomials with integer coefficients and degree not exceeding 8192. Let the public key \(pk = ( - [(a\cdot f + e)] q , a)\);

[0071] (3) Generate an operation key \(ek\) for ciphertext operation noise control according to the private key \(sk\) and the public key \(pk\).

[0072] Step 3: The client factorizes the product formula of the plaintext matrices \(Y = Q\cdot K\cdot V\cdot A\cdot B\), and extracts the factor \(Y1 = Q\cdot K\cdot V\) of the product of three matrices and the factor \(Y2 = A\cdot B\) of the product of two matrices.

[0073] Step 4: For the factor \(Y2 = A\cdot B\) of the product of two matrices, the client encrypts it column by column and directly sends it to the server. The server uses the method in [6] to implement the ciphertext matrix multiplication calculation, obtains the ciphertext result matrix \(C\) of the factor, and replaces the factor \(A\cdot B\) of the product of two matrices in the product formula of the plaintext matrix with the ciphertext result matrix \(C\) of the factor.

[0074] Step 5: For the factor \(Y1 = Q\cdot K\cdot V\) of the product of three matrices, the client encrypts the plaintext matrix vector by vector using the public key \(pk\) to obtain a ciphertext vector; and packs and sends the ciphertext matrix, the public key \(pk\), and the operation key \(ek\) to the server. Specifically:

[0075] (1) The client respectively adds a column vector of 0 after the last column of matrix \(K\) and a row vector of 0 after the last row of matrix \(V\) so that

[0076] (2) The client respectively encrypts \(Q\) column by column, \(K\) row by row, and \(V\) column by column, and uses the public key \(pk\) to encrypt the plaintext vectors \(q j , k j , v j respectively to obtain the corresponding ciphertexts \(c q,j = Enc pk (q j ), \(c k,j = Enc pk (k j ), \(c v,j = Enc pk (v j ); where \(Q = [q j 0≤j≤5 , V = [v j 0≤j≤5 , j = 0, \ldots, 5;

[0077] ​​(3) The client packs and sends the ciphertext vectors {c q,j}, 0≤j<m {c k,j}, 0≤j<m {c v,j}, 0≤j<m the public key pk, and the operation key ek to the server.

[0078] To demonstrate the specific calculation process of the method of the present invention, in this embodiment, it is assumed that the ciphertext vectors are:

[0079]

[0080] Step Five: The server performs ciphertext matrix multiplication on the factors Y1 = Q·K·V of the three matrix multiplications to obtain the ciphertext result matrix of all factors. Specifically:

[0081] (1) The server determines the outer loop number l = 3 and the inner loop number k = 2 according to the number of columns 6 of the matrix K.

[0082] (2) The server calculates the diagonal element ciphertext vectors of Q·K in parallel where 0 ≤ i < 3, 0 ≤ j < 2;

[0083] where D 1,1 = [3, 4, 2, 7, 2, 4] ⊙ [2, 5, 1, 3, 6, 3] + [5, 1, 3, 4, 4, 3] ⊙ [6, 7, 2, 2, 1, 2] + [6, 5, 1, 3, 6, 7] ⊙ [2, 2, 1, 6, 7, 3] + [4, 3, 6, 1, 3, 1] ⊙ [6, 3, 2, 7, 2, 4] + [1, 6, 4, 2, 2, 3] ⊙ [7, 2, 3, 1, 2, 3] = [50, 67, 76, 35, 64, 73], D 1,2 = [72, 64, 30, 71, 42, 48], D 2,1 = [51, 64, 63, 28, 84, 78], D 2,2 = [88, 76, 28, 70, 75, 59], D 3,1 = [56, 84, 59, 26, 73, 84], D 3,2 = [79, 58, 33, 56, 68, 52].

[0084] (3) The server calculates the ciphertext result column vector of Q·K·v s where 0 ≤ s < 1;

[0085] ​Among them, c0 = [582, 530, 272, 495, 362, 217] + [238, 462, 495, 255, 681, 536] + [433, 240, 642, 620, 250, 384] = [1253, 1232, 1409, 1370, 1293, 1137].

[0086] (4) Since V has only one column vector, the ciphertext result of Q·K·V is the one-dimensional column vector c0 at this time.

[0087] Step Six: Repeat Step Three to Step Five, and use the method in [6] to calculate the ciphertext result matrix c = c0·C of the product formula of the plaintext matrix. Among them, for 3 columns of 0 elements need to be filled in to make

[0088] Step Seven: The server sends c to the client.

[0089] Step Eight: The client decrypts c using the private key sk; and replaces the factors of the product formula of the corresponding plaintext matrix. Specifically: The client uses the private key sk to decrypt the first three columns of ciphertext c in the ciphertext result matrix c of the product formula of the plaintext matrix column by column to obtain the corresponding plaintext column vector y i and gets the corresponding plaintext column vector y i = Dec sk (c i ), where i = 1, 2, 3.

[0090] It can be seen that the calculation result of the method of the present invention is consistent with the plaintext calculation result.

[0091] Embodiment 2: When a user needs to use the transformer model that has been trained under the plaintext data set owned by the server to predict its own data Considering the privacy protection of the data, the user hopes to encrypt it on the local client and then send it to the server to complete the homomorphic ciphertext calculation, and then return the ciphertext to the client for decryption.

[0092] The method of the present invention provides a "transformer neural network for homomorphic ciphertext data". As Figure 3As shown, the transformer neural network for the homomorphic ciphertext data is a multi-layer transformer neural network trained with a plaintext dataset. The input is ciphertext data, and the output is ciphertext prediction data, without the need for decryption in the intermediate process. In this embodiment, DASHformer is taken as an example for illustration. This transformer neural network only has an encoder, and it should be noted that other types of transformer neural networks are similar. Each layer of the transformer neural network is successively composed of an embedding layer (Embedding), a positional encoding (Positional Encoding), a four-head attention mechanism, a linear layer, an Add&Norm layer, a feed-forward neural network layer (Feed Forward), an Add&Norm layer, a pooling layer (Pooling), and a Softmax layer; here, the multi-head attention mechanism needs to be processed as a factor of the product of three matrices.

[0093] The method of the present invention provides a "fast calculation method for matrix multiplication of ciphertext based on homomorphic encryption".

[0094] The specific parameter settings are exactly the same as those in Embodiment 1, and the details will not be elaborated here. The specific process is as follows:

[0095] Step 1: The user sets the security parameter λ of the CKKS homomorphic encryption scheme ε = (Enc, Dec) on the client side, and generates the relevant encryption and decryption parameters of the homomorphic encryption scheme according to the security parameter λ.

[0096] Step 2: The client generates a key according to the security parameter.

[0097] Step 3: The client factorizes the calculation formula of a transformer neural network for a kind of homomorphic ciphertext data, and extracts the factors of the product of three matrices and the factors of the product of two matrices therein.

[0098] The specific analysis is as follows: The ciphertext matrix data after encrypting the plaintext matrix data is denoted as and is successively input into the embedding layer, the positional encoding, the four-layer multi-head attention mechanism, the linear layer, the first Add&Norm layer, the feed-forward neural network layer, the second Add&Norm layer, the pooling layer, and the Softmax layer.

[0099] Among them, the calculation of the embedding layer and the positional encoding is: Among them, is the trained plaintext weight matrix, is the plaintext positional encoding matrix.

[0100] The calculation of the four-head attention mechanism is: where h = 1, 2, 3, 4, the input is the pre - trained plaintext weight matrix; is the pre - trained plaintext bias vector.

[0101] The calculation of the linear layer is: where W c is the pre - trained plaintext weight matrix; b c is the pre - trained plaintext bias vector.

[0102] The calculation of the first Add&Norm layer is:

[0103] The calculation of the feed - forward neural network layer is: where W1, W2 are the pre - trained plaintext weight matrices; b1, b2 are the pre - trained plaintext bias vectors.

[0104] The calculation of the second Add&Norm layer is:

[0105] The calculation of the pooling layer is: where W d is the pre - trained plaintext weight matrix; b d is the pre - trained plaintext bias vector.

[0106] The calculation of the Softmax layer is: y = softmax(x).

[0107] Among them, the continuous multiplication formula of the plaintext matrix involved is mainly the factor of multiplying two matrices. In this embodiment, only the four - head attention mechanism is regarded as the factor of multiplying three matrices

[0108] Step 4: For the factor of multiplying two matrices, after the client encrypts it, it is packaged and sent to the server together with the public key pk and the operation key ek. The server uses the method in [6] to implement the ciphertext matrix multiplication calculation and obtains the ciphertext result matrix of the factor.

[0109] Step 5: For the factor of multiplying three matrices, the client encrypts the plaintext matrix by vector using the public key pk to obtain the ciphertext vector; and directly sends the ciphertext matrix to the server.

[0110] It should be noted that the plaintext data is encrypted by the client and then input into a transformer neural network of homomorphic ciphertext data for calculation. Due to the natural structure of the multi - head attention mechanism, the output ciphertext column vector can be directly used by the next - head attention mechanism, so there is no need to return for decryption and re - encryption in the middle.

[0111] Step 6: The server sends the ciphertext of the prediction result of a transformer neural network for a homomorphic ciphertext data to the client.

[0112] Step 7: The client decrypts the ciphertext of the prediction result using the private key sk.

[0113] To better demonstrate the beneficial effects of the method of the present invention, a comparative experiment is conducted here. 163 plaintext data are input into the transformer neural network for processing, and the calculation efficiency is tested. The results of the comparative experiment are shown in Table 1.

[0114] Table 1 Results of the comparative experiment (unit: second)

[0115]

[0116] It can be seen that the method of the present invention can effectively improve the efficiency of multiplying multiple ciphertext matrices and is very suitable for application in the transformer neural network.

[0117] Finally, it should be noted that the above preferred embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail through the above preferred embodiments, those skilled in the art should understand that various changes can be made in form and details without departing from the scope defined by the claims of the present invention.

Claims

1. A fast calculation method for ciphertext matrix multiplication based on homomorphic encryption, characterized in that: The method comprises the following steps: S1: The user sets the security parameter λ of the homomorphic encryption scheme ε=(Enc,Dec) on the client, and generates the relevant encryption and decryption parameters of the homomorphic encryption scheme according to the security parameter λ; S2: The client generates a private key sk, a public key pk and an operation key ek based on the encryption and decryption parameters; S3: The client factors the plaintext matrix multiplication formula and extracts the factors of the three matrix multiplications and the factors of the two matrix multiplications. S4: The client uses the public key pk to encrypt the plaintext matrix in the factor one by one according to the vector to obtain the ciphertext vector; and packages the ciphertext matrix, the public key pk and the operation key ek and sends them to the server; S5: The server uses parallel computing to perform ciphertext matrix multiplication on all factors to obtain the ciphertext result matrix of all factors, and uses it to replace the factors of the corresponding plaintext matrix multiplication formula; S6: Repeat steps S3 to S5 until the ciphertext result matrix of the continuous multiplication formula of the plaintext matrix is ​​calculated; S7: The server sends the ciphertext result matrix of the continuous multiplication formula of the plaintext matrix to the client; S8: The client uses the private key sk to decrypt the ciphertext result matrix of the continuous multiplication formula of the plaintext matrix; Among them, let the plaintext space be The ciphertext space is Enc is used to represent encryption algorithm operation, Dec is used to represent decryption algorithm operation; Encode is used to represent data encoding operation, Decode is used to represent data decoding operation; [] k Indicates that the calculation value needs to be a non-negative remainder modulo k, ⊙ represents the Hadamard Product of the vector; Indicates rounding up. Indicates rounding down; Among them, d ciphertexts The addition operation is The output ciphertext c satisfies Dec(c1)+Dec(c2)+…+Dec(c d )=Dec(c), where d is a positive integer; Among them, the multiplication operation of ciphertext c1 and c2 is The output ciphertext c satisfies Dec(c1)⊙Dec(c2)=Dec(c); Among them, the rotation operation of the ciphertext c is Input ciphertext c=(c0,c1,…,c n-1 ) and an integer ℓ, the output secret 𝒄′=(𝑐 ℓ ,...,𝑐 𝑛−1 ,𝑐0,...,𝑐 ℓ−1 ); that is, the new plaintext is obtained by rotating each component of c to the left by ℓ ciphertext slots in turn. If ℓ is a negative number, it means rotating to the right. Each component of c is called a ciphertext slot, and there are n ciphertext slots in total. Further, step S1 is specifically as follows: S101: Determine the security parameter λ, which can at least defend against 2 λ Adversaries with sub-bit computing power; S102: The client selects a SIMD homomorphic encryption method and determines the size q of the number of ciphertext slots in the ciphertext homomorphic scheme; S103: The client selects an integer p based on the sample data, and the value will not exceed p / 2 during the ciphertext calculation process; S104: The user uses the security parameter λ and the Homomorphic Encryption Security Standard. According to the recommendations in the Standard, we select parameters m and q and determine the plaintext space of the homomorphic encryption scheme as The ring of polynomials with integer coefficients Modulo the m-th degree cyclotomic polynomial φ m (X) and the integer p generate the ideal to obtain the residual class ring, the ciphertext space is Further, step S2 is specifically as follows: S201: The client generates a coefficient and randomly selects an undetermined element X from the set {-1, 0, 1} with a probability no greater than A random polynomial f, where represents the number of elements in the set {1,2,...,m} that are relatively prime to m, then the private key sk=(1,f); S202: Client from R q A polynomial a with an indeterminate variable X is randomly selected from a uniform distribution. A noise polynomial e about the indeterminate variable X is randomly selected from the error distribution χ, then the public key pk=(-[(a·f+e)] q ,a), where [·] q It represents the polynomial obtained by applying the coefficients of the polynomial in square brackets to q; S203: The client generates a computation key ek required for noise control during the ciphertext computation according to the selected homomorphic encryption scheme; Further, the factorization described in step S3 is specifically as follows: extracting a number of factors of three-matrix multiplications from the plaintext matrix multiplication formula in sequence, with each of three matrices as one factor, and leaving a factor of two-matrix multiplication or a single matrix; Further, for the factors Q·K·V of the three matrix multiplications, the step S4 is specifically as follows: S401: The client adds 0 column vectors to matrix K and 0 row vectors to matrix V, respectively, so that S402: The client uses the public key pk to sort the plaintext vectors q by column, K by row, and V by column. j , k j 、v j Encrypt to get the corresponding ciphertext c q,j =Enc pk (q j ),c k,j =Enc pk (k j ),c v,j =Enc pk (v j ); where Q = [q j ] 0≤j≤m-1 ,K= V=[v j ] 0≤j≤m-1 , j = 0, ..., m-1; S403: The client sends the ciphertext vector {c q,j } 0≤j<m 、{c k,j } 0≤j<m 、{c v,j } 0≤j<m , public key pk and operation key ek are packaged and sent to the server; Further, for any three matrix multiplication factors Q·K·V, step S5 is specifically as follows: S501: The server determines the outer loop number l and the inner loop number k according to the column number m of the matrix K, and requires that m≤l·k, where l and k are positive integers; S502: The server calculates the diagonal element ciphertext vector of Q·K Where 0≤i <l,0≤j<k; S503: Server calculates Q·K·v s The ciphertext result column vector Where 0≤s <d; S504: Repeat step S503, traverse all column vectors of V, and calculate the ciphertext result matrix [c s ] 0≤s<m , and use [c s ] 0≤s<m Replace Q·K·V in the multiplication formula of the plaintext matrix.

2. The fast calculation method for ciphertext matrix multiplication based on homomorphic encryption according to claim 1 is characterized in that: The security parameter λ in step S101 is λ=128 or 256.

3. The fast calculation method for ciphertext matrix multiplication based on homomorphic encryption according to claim 1 is characterized in that: The error distribution χ described in step S202 is taken as a discrete Gaussian distribution.

4. The fast calculation method for ciphertext matrix multiplication based on homomorphic encryption according to claim 1 is characterized in that: In order to improve the computational efficiency, the calculations of the diagonal element ciphertext vectors of Q·K described in step S502 are independent of each other and can be implemented by parallel computing.

5. The fast calculation method for ciphertext matrix multiplication based on homomorphic encryption according to claim 1 is characterized in that: In the process of replacing the plaintext matrix multiplication formula described in step S504, the intermediate matrix K of the factors Q·K·V of the three matrix multiplications appearing in the next round of calculation needs to be transposed.

6. A transformer neural network system applied to the fast calculation method of ciphertext matrix multiplication based on homomorphic encryption as described in any one of claims 1 to 5, characterized in that: It is implemented by a multi-layer transformer neural network trained with a plaintext data set; the input of the multi-layer transformer neural network is ciphertext data, and the output is ciphertext prediction data, and no decryption is required in the intermediate links; each layer of the transformer neural network is composed of a multi-head attention mechanism, an Add&Norm layer, a feedforward neural network layer (Feed Forward), a pooling layer (Pooling) and a Softmax layer; the multi-head attention mechanism is processed as a factor of three matrix multiplications, and is processed using a fast calculation method of ciphertext matrix multiplication based on homomorphic encryption.

Citation Information

Patent Citations

  • Personalized privacy information retrieval method based on block chain

    CN107454070A

  • Homomorphic encryption matrix continuous multiplication safety outsourcing method based on cloud computing

    CN111064558A