Calculation Method for Multiplication of Plaintext Matrix and Ciphertext Tensor Based on Homomorphic Encryption

Through the homomorphic encryption method that encodes tensors, the client encrypts the plaintext matrix and ciphertext tensor multiplication is calculated on the server side, which solves the problem of high overhead of ciphertext matrix multiplication in the existing technology, realizes efficient data processing and privacy protection, and is suitable for computing optimization of large model inference.

CN119519920BActive Publication Date: 2025-07-08CHONGQING INST OF GREEN & INTELLIGENT TECH CHINESE ACAD OF SCI
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411528012.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-07-08
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

In the large-model inference of existing homomorphic encryption, ciphertext matrix multiplication calculation has high overhead problems, especially when processing batch data, which leads to increased computing delays and memory requirements, and the existing solutions fail to effectively utilize tensor operations to improve efficiency.

Method used

The calculation method of multiplication of plaintext matrix and ciphertext tensor based on homomorphic encryption is adopted. By encoding the tensor, the client encrypts it and performs calculations on the server side to avoid ciphertext rotation operations, and the multiplication of plaintext matrix and ciphertext tensor is directly completed. Combined with the bias vector in linear transformation, the calculation efficiency is improved.

Benefits of technology

On the premise of ensuring data privacy, the computing efficiency of large-scale model inference is significantly improved, the computing delay and memory requirements are reduced, the calculation of any dimension is supported, and the coding consistency of the results is maintained. It is suitable for the privacy protection model inference framework involving both parties.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119519920B_ABST
    Figure CN119519920B_ABST
Patent Text Reader

Abstract

The present invention is a calculation method for the multiplication of a plaintext matrix and a ciphertext tensor based on homomorphic encryption, belonging to the field of information security. For the situation where the client has the plaintext tensor X data, the server has the plaintext matrix W and the plaintext vector b, and performs ciphertext tensor operations on the server, the method includes the following steps: S1: Set the homomorphic encryption scheme and parameters; S2: The client generates a public-private key pair and an operation key; S3: The client encodes the tensor, encrypts it with the public key, and sends the ciphertext vector, the public key, and the operation key to the server; S4: The server calculates the ciphertext result of the model according to the weight matrix and the bias vector of the deep learning model; S5: The client decrypts it with the private key to obtain the plaintext; S6: The client decodes the plaintext to obtain the plaintext tensor. The method of the present invention directly encodes the tensor, and can complete the multiplication of the plaintext matrix and the ciphertext tensor without performing ciphertext rotation, greatly improving the calculation efficiency of the linear transformation in the model and having strong generalization ability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a calculation method for multiplying a plaintext matrix by a ciphertext tensor based on homomorphic encryption, belonging to the field of information security, and is particularly applicable to the calculation of multiplying a plaintext matrix by a ciphertext tensor based on homomorphic encryption. Background Art

[0002] In the context of the widespread application of current large language models (such as GPT and BERT), they play a crucial role in promoting social productivity and technological progress. However, the large amounts of data used in the training and inference processes of these models often contain sensitive information, highlighting the importance of data privacy protection. By introducing homomorphic encryption technology, effective data processing and analysis can be carried out while ensuring data privacy, improving the security and robustness of the model. At the same time, when homomorphic encryption is combined with large model inference, the operations of ciphertext matrices and tensors are core components. Especially in large models involving two-party calculations, such as the attention mechanism and linear transformation γ = X·W + b under the Transformer architecture, which involve a large number of multiplications of plaintext matrix W and ciphertext tensor X. Therefore, optimizing the multiplication calculation efficiency of the plaintext matrix and the ciphertext tensor can effectively improve the overall performance of the model, laying a foundation for the better service of homomorphic encryption technology in various fields.

[0003] Homomorphic encryption allows calculations to be directly performed on encrypted data, and the data remains encrypted throughout the entire calculation cycle, thus minimizing the risk of data leakage during transmission and processing. Its decryption result matches the result of the corresponding operation on the plaintext and can provide quantum-resistant security, enabling effective data analysis and processing while protecting data privacy. Currently, homomorphic encryption technology has become an important approach to solving privacy and security in fields such as outsourced computing, bioinformatics, vehicle networking, and machine learning. In the inference of large models based on homomorphic encryption, references [1]-[6] all simplify tensor calculations into matrix calculations to accelerate the model inference speed by improving the ciphertext matrix multiplication calculation speed. However, in homomorphic schemes (BGV, BFV, CKKS) based on SIMD technology, even the latest ciphertext matrix multiplication methods still inevitably involve a large number of high-overhead ciphertext rotation operations. In actual situations, the inference of large models mainly performs a large number of matrix operations on batch data, and the inference speed of batch data can be effectively improved through tensor operations. Therefore, in order to improve the practicality of ciphertext large model inference, batch ciphertext data inference is essential. Therefore, there is an urgent need to design an encoding method applicable to ciphertext tensor calculations that can efficiently complete the calculation of multiplying a plaintext matrix by a tensor when two parties participate in the calculation, optimizing the calculation latency and memory requirements of batch ciphertext data large model inference.

[0004] [1] Meng Hao, Hongwei Li, Hanxiao Chen, Pengzhi Xing, Guowen Xu, and Tianwei Zhang. Iron: Private inference on transformers. In NeurIPS, 2022.

[0005] [2] Zheng, Mengxin, Qian Lou, and Lei Jiang. "Primer: Fast private transformer inference on encrypted data." 2023 60th ACM / IEEE Design Automation Conference (DAC). IEEE, 2023.

[0006] [3] Meng Tong, Kejiang Chen, Jie Zhang, Yuang Qi, Weiming Zhang, Nenghai Yu, Tianwei Zhang, Zhikun Zhang. InferDPT: Privacy-preserving Inference for Black-box Large Language Models.

[0007] [4] Xiaoyang Hou, Jian Liu, Jingyu Li, Yuhan Li, Wen-jie Lu, Cheng Hong, and Kui Ren. 2023. Ciphergpt: Secure two-party gpt inference. Cryptology ePrint Archive (2023).

[0008] [5] Pang, Q., et al. BOLT: Privacy-Preserving, Accurate and Efficient Inference for Transformers. IEEE S&P, 2024.

[0009] [6] HUANG Z, HONG C, WENG C, et al. More Efficient Secure Matrix Multiplication for Unbalanced Recommender Systems[J]. 2023, 20(01): 551 - 62.

[0010] [7] Brakerski, Z., Gentry, C., Vaikuntanathan, V.: (Leveled) fully homomorphic encryption without bootstrapping. ACM Transactions on Computation Theory 6(3), 13:1–13:36 (2014).

[0011] [8] Junfeng Fan and Frederik Vercauteren. Somewhat Practical Fully Homomorphic Encryption. Cryptology ePrint Archive, Report 2012 / 144, 2012.

[0012] [9] CHEON J H, KIM A, KIM M, et al. Homomorphic encryption for arithmetic of approximate numbers;proceedings of the Advances in Cryptology–ASIACRYPT 2017: 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3 - 7, 2017, Proceedings, Part I 23, F, 2017[C]. Springer. SUMMARY OF THE INVENTION

[0013] In view of this, for Figure 1 the model inference framework for privacy protection involving two parties as shown where the client has a plaintext data tensor as and the server has a plaintext matrix and a plaintext vector After the client encrypts the tensor X, the server calculates the ciphertext of the tensor to obtain Y = X·W + b, and outputs the ciphertext of the tensor Figure 2 to the client, as Denote the n-dimensional real vector space, where l, n, m, t, and p are positive integers. The present invention provides a calculation method for multiplying a plaintext matrix by a ciphertext tensor based on homomorphic encryption, which is applied to a system composed of two computer devices, namely a server and a client, connected through a network. The ciphertext is encoded into m ciphertexts, and the multiplication of the ciphertext tensor and the plaintext matrix can be completed without rotation operations, efficiently realizing the multiplication calculation of batch ciphertexts. Combining with the bias vector in linear transformation can greatly improve the calculation efficiency of linear transformation in large model architectures.

[0014] To achieve the above object, in combination with the attached Figure 3 As shown, first, the symbols involved in the present invention are defined as follows:

[0015] (1) Let the plaintext space be The ciphertext space is Use Enc to represent the encryption algorithm operation, and Dec to represent the decryption algorithm operation; use Encode to represent the tensor encoding operation, and Encode to represent the tensor decoding operation, where represents the element at the (k, i, j) position in the tensor X, and use x j,i-1 to represent the vector x j The i-th element in, and use [] k to represent the non-negative residue obtained by taking the modulus k of the calculated value, represents the largest integer not exceeding the calculated value, ⊙ represents the Hadamard Product of vectors, and ← represents assignment.

[0016] (2) The encoding operation of the tensor is Input the tensor Output m vector groups {x j} 0≤j<m ; where, for any x j = [x j,s 0≤s<l·n , the assignment process of x j,s is: traverse 0 ≤ k < l and 0 ≤ i < n in sequence, select the element where k·n + i = s from the tensor X and assign it to x j,s , to obtain

[0017] (3) The decoding operation of the vector group is Input the vector group {x j} 0≤j<m with length m, and the output tensor is Among them, for any j-th vector x j = [x j,s 0≤s<l·n , the corresponding element in the tensor X can be constructed

[0018] (4) The addition operation of the ciphertext c and the real number r is Input a ciphertext c = (c0, …, c n-1 ); Output a ciphertext c' such that c' = (c0 + r, …, c n-1 + r).

[0019] (5) The multiplication operation of the ciphertext c and the real number r is Input a ciphertext c = (c0, …, c n-1 ); Output a ciphertext c' such that c' = (r·c0, …, r·c n-1 ).

[0020] (6) The addition operation of k ciphertexts is Input k ciphertexts c i for i = 0, …, k - 1, and output the ciphertext

[0021] The present invention provides the following technical solutions:

[0022] A calculation method for multiplying a plaintext matrix and a ciphertext tensor based on homomorphic encryption, comprising the following steps:

[0023] S1: Set the security parameter λ of the homomorphic encryption scheme ε = (Enc, Dec), and generate the relevant encryption and decryption parameters of the homomorphic encryption scheme according to the security parameter λ;

[0024] S2: The client generates a private key sk, a public key pk, and an operation key ek according to the encryption and decryption parameters;

[0025] S3: The client encodes the tensor X into m vector groups {x j}, 0≤j<m and encrypts the vector group into ciphertext vectors {c x,j} 0≤j<m using the public key pk, and finally packs and sends the ciphertext vectors, the public key pk, and the operation key ek to the server;

[0026] S4: The server calculates c j,i = CAdd(Add_all(CMult(c 0≤j<m,0≤i<t ), w i ))), b 0≤i<t according to the weight matrix W = [w y,i = CAdd(Add_all(CMult(c x,j , w j,i )), b i ) to obtain the ciphertext c y,i , and traverses i to obtain the ciphertext vectors {c y,i}0≤i<t ;

[0027] S5: The server sends the ciphertext vector group {c y,i} 0≤i<t to the client, and the client decrypts it with the private key sk to obtain the plaintext vector group {y i} 0≤i<t ;

[0028] S6: The client decodes the plaintext vector {y i} 0≤i<t and calculates the plaintext tensor Y = Decode({y i} 0≤i<t );

[0029] Furthermore, step S1 is specifically as follows:

[0030] S101: Determine the security parameter λ, that is, it can resist at least an adversary with 2 λ times of bit operation computing power;

[0031] S102: The client selects an integer p according to the sample data, and its value size will not exceed p / 2 during the ciphertext calculation process;

[0032] S103: The user selects parameters m and q according to the security parameter λ and in accordance with the suggestions in the Homomorphic Encryption Security Standard ( http: / / homomorphicencryption.org / ), and determines that the plaintext space of the homomorphic encryption scheme is That is, the residue class ring obtained by taking the integer coefficient polynomial ring modulo the ideal generated by the m-th cyclotomic polynomial φ m (X) and the integer p, and the ciphertext space is

[0033] Furthermore, step S2 is specifically as follows:

[0034] S201: The client generates a random polynomial f with coefficients randomly selected from the set {-1, 0, 1} with the degree of the indeterminate X not exceeding , where represents the number of elements in the set {1, 2,..., m} that are relatively prime to m, then the private key sk = (1, f);

[0035] S202: The client randomly selects a polynomial a of the indeterminate X from the uniform distribution of R q , and randomly selects a noise polynomial e about the indeterminate X from the error distribution χ, then the public key pk = (-[(a·f + e)] q ​, a), where [...] q represents the polynomial obtained by taking the coefficients of the polynomial in the square brackets modulo q;

[0036] S203: The client generates the operation key ek required for noise control during the ciphertext operation according to the selected homomorphic encryption scheme.

[0037] Furthermore, step S3 is specifically as follows:

[0038] S301: The client encodes the tensor to obtain m groups of plaintext vectors {x j} 0≤j<m = Encode(X), where the length of each vector is l·n;

[0039] S302: The client encrypts each plaintext vector x j one by one using the public key pk to obtain the corresponding ciphertext c x,j = Enc pk (x j ); where j = 0,..., m - 1;

[0040] S303: The client packs and sends the ciphertext vectors {c x,j} 0≤j<m , the public key pk, and the operation key ek to the server.

[0041] Furthermore, step S4 is specifically as follows:

[0042] S401: The server calculates the ciphertext vectors {c xw,i} x,j according to the formula c j,i = Add_all(CMult(c j,i ), w xw,i ), where w 0≤i<t is an element of the weight matrix W; traversing i = 0,..., t - 1;

[0043] S402: The server calculates the ciphertext vectors {c y,i} xw,i according to the formula c i = CAdd(c i ), b y,i ), where b 0≤i<t is an element of the bias vector b; traversing i = 0,..., t - 1.

[0044] Furthermore, step S5 is specifically as follows:

[0045] S501: The server sends the ciphertext vectors {c y,i} 0≤i<t to the client;

[0046] S502: The client decrypts the ciphertext c one by one using the private key sk respectively y,i to obtain the corresponding plaintext vector y i = Dec sk (c y,i ); where i = 0, …, t - 1.

[0047] Preferably, the homomorphic encryption scheme described in step S1 can be one of all the schemes using the SIMD technology, such as the BGV scheme, the B / FV scheme, and the CKKS scheme. The references for the BGV scheme are as follows: Brakerski, Z., Gentry, C., Vaikuntanathan, V.: (Leveled) fully homomorphic encryption without bootstrapping. ACM Transactions on Computation Theory 6(3), 13:1–13:36 (2014). https: / / doi.org / 10.1145 / 2633600 ; The references for the B / FV scheme are as follows: Junfeng Fan and Frederik Vercauteren. Somewhat Practical Fully Homomorphic Encryption. Cryptology ePrint Archive, Report 2012 / 144, 2012. https: / / eprint.iacr.org / 2012 / 144 ; The references for the CKKS scheme are as follows: CHEON J H, KIM A, KIM M, et al. Homomorphic encryption for arithmetic of approximate numbers; proceedings of the Advances in Cryptology–ASIACRYPT 2017: 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3 - 7, 2017, Proceedings, Part I 23, F, 2017[C]. Springer. ht tps: / / doi.org / 10.1007 / 978-3-319-70694-8_15 .

[0048] Preferably, for the security parameter λ, take λ = 128 or 256; the error distribution χ is taken as the discrete Gaussian distribution.

[0049] Preferably, the CAdd and CMult calculation operations described in step S4 can be calculated using a parallel computing system with vectorized operations, which can improve the calculation efficiency.

[0050] Preferably, the plaintext data tensor and the weight matrix When m > n, perform a transpose operation on the tensor X and the weight matrix W as a preprocessing, that is and adjust the corresponding indices, and calculate At this time, the corresponding number of ciphertexts is n, achieving the function of reducing the number of ciphertexts.

[0051] The beneficial effects of the present invention are as follows: The present invention provides a calculation method for the multiplication of a plaintext matrix and a ciphertext tensor based on homomorphic encryption. Under the model inference framework based on two-party participation in privacy protection, the client only encrypts the tensor data, and the server only processes the ciphertext data and does not come into contact with any client data, thus ensuring the security of both the server and client data at the same time; compared with other solutions that regard the tensor as multiple matrices and perform matrix multiplication separately, the present invention can complete the multiplication of the plaintext matrix and the ciphertext tensor without ciphertext rotation by directly encoding the tensor, greatly improving the calculation efficiency of the linear transformation in large model inference; secondly, the encoding method of the present invention supports calculations for any dimension, effectively solving the dimension transformation of the tensor after the linear transformation, and the encoding method of the result is consistent with the input, and the result can be directly used as the input for the next calculation, with strong generalization ability. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] To illustrate the purpose and technical solutions of the present invention, the following drawings are provided for illustration:

[0053] Figure 1 It is a framework diagram of a model inference based on two-party participation in privacy protection;

[0054] Figure 2 It is a framework diagram of the linear transformation of a ciphertext tensor based on homomorphic encryption;

[0055] Figure 3 It is a schematic diagram of the tensor encoding of the present invention;

[0056] Figure 4 It is a flowchart of Embodiment 1 of the present invention;

[0057] Figure 5 It is a comparison diagram of the experimental results of Embodiment 2 of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0058] Embodiment 1: As Figure 1As shown, in the model inference framework for privacy protection involving two parties, to achieve the purpose of privacy protection, the client encrypts the tensor data it owns and sends the ciphertext to the server. The server performs calculations in combination with the model data and sends the result back to the client after completion. The client decrypts the ciphertext to obtain the prediction result, such as Figure 2 As shown. In the privacy-preserving large model inference based on homomorphic encryption, linear transformation is one of the most basic operations, and its efficiency is mainly affected by matrix and tensor multiplication. Therefore, the present invention provides a "computing method for multiplying a plaintext matrix by a ciphertext tensor based on homomorphic encryption".

[0059] In this embodiment, it is assumed that the server holds the plaintext matrix W 3×2 and the plaintext vector b 2 ; it is assumed that the client owns the tensor X 2×2×3 ; it is necessary to complete a linear transformation Y 2×2×2 = X·W + b on the server side while protecting the plaintext data. The specific values are as follows:

[0060] b 2 = [0.1 0.2];

[0061]

[0062] Next, the preferred application examples of the present invention will be described in detail with reference to the accompanying drawings.

[0063] As Figure 4 shown, it specifically includes the following steps:

[0064] Step 1: The client sets the parameters of the CKKS homomorphic encryption scheme.

[0065] (1) The client sets the security parameter λ = 128 according to the selected homomorphic encryption scheme;

[0066] (2) Select the prime number p = 40;

[0067] (3) According to the homomorphic encryption standard, select the parameter q as a product of 4 randomly selected odd prime numbers with bit lengths between 40 and 60, and the bit length of q is about 200;

[0068] Step 2: The client generates the key according to the security parameter.

[0069] (1) Uniformly and randomly select a polynomial f from the set of univariate polynomials with coefficients {-1, 0, 1} and degrees not exceeding , and let the private key sk = (1, f);

[0070] (2) Randomly and uniformly select a polynomial \(a\) from the set of univariate polynomials with coefficients \(\{0, 1, 2, \ldots, q - 1\}\) and degree not exceeding 8192, and select a noise polynomial \(e\) from the discrete Gaussian distribution with standard deviation 3.2 over the set of integer - coefficient polynomials of degree not exceeding 8192. Let the public key \(pk = ( - [(a\cdot f+e)] q ,a)\);

[0071] (3) Generate an operation key \(ek\) for ciphertext operation noise control according to the private key \(sk\) and the public key \(ps\).

[0072] Step 3: The client encodes the tensor \(X\) into 3 groups of plaintext vectors \(\{x j \}\) 0≤j<3 , and encrypts the vector group with the public key \(pk\) to obtain ciphertext vectors \(\{c x,j \}\) 0≤j<3 . Finally, the client sends the ciphertext vectors, the public key \(pk\), and the operation key \(ek\) to the server.

[0073] (1) The client encodes the \(X 2×2×3 \) tensor to obtain 3 groups of plaintext vectors \(\{x j \}\) 0≤j<3 = Encode(X), where the length of each vector is 4; the 3 vectors are \(x0=(0.1, 0.7, 0.4, 1.0)\), \(x1=(0.2, 0.8, 0.5, 1.1)\) and \(x2=(0.3, 0.9, 0.6, 1.2)\);

[0074] (2) The client encrypts each plaintext vector \(x j \) with the public key \(pk\) respectively to obtain the corresponding ciphertext \(c x,j = Enc pk (x j ); the 3 ciphertexts are \(c x,0 = Enc(0.1, 0.7, 0.4, 1.0)\), \(c x,1 = Enc(0.2, 0.8, 0.5, 1.1)\) and \(c x,2 = Enc(0.3, 0.9, 0.6, 1.2)\);

[0075] (3) The client packs and sends the encrypted data \(\{c x,j \}\) 0≤j<3 , the public key \(pk\), and the operation key \(ek\) to the server.

[0076] Step 4: The server calculates \(c j,i = CAdd(Add_all(CMult(c 0≤j<3,0≤i<2 and the bias vector \(b = [b i 0≤i<2 according to the weight matrix \(W = [w y,i = CAdd(Add_all(CMult(c​x,j , w j,i ))), b i ) Obtain the ciphertext c y,i , traverse i to obtain the ciphertext vector {c y,i} 0≤i<2 .

[0077] (1) The server calculates the ciphertext vector {c xw,i = Add_all(CMult(c x,j , w j,i )) 0≤j<3 ) According to the formula. When i = 0, calculate c xw,i = Add_all(1×Enc(0.1, 0.7, 0.4, 1.0), 3×Enc(0.2, 0.8, 0.5, 1.1), 5×Enc(0.3, 0.9, 0.6, 1.2)) = Enc(2.2, 7.6, 4.9, 10.3); When i = 1, c 0≤i<2 = Add_all(2×Enc(0.1, 0.7, 0.4, 1.0), 4×Enc(0.2, 0.8, 0.5, 1.1), 6×Enc(0.3, 0.9, 0.6, 1.2)) = Enc(2.8, 10.0, 6.4, 13.6); xw,0 = Add_all(1×Enc(0.1, 0.7, 0.4, 1.0), 3×Enc(0.2, 0.8, 0.5, 1.1), 5×Enc(0.3, 0.9, 0.6, 1.2)) = Enc(2.2, 7.6, 4.9, 10.3); When i = 1, c xw,1 = Add_all(2×Enc(0.1, 0.7, 0.4, 1.0), 4×Enc(0.2, 0.8, 0.5, 1.1), 6×Enc(0.3, 0.9, 0.6, 1.2)) = Enc(2.8, 10.0, 6.4, 13.6);

[0078] (2) The server calculates the ciphertext vector {c y,i = CAdd(c xw,i , b i ) According to the formula. When i = 0, calculate c y,i = Enc(2.3, 7.7, 5.0, 10.4) according to the formula; When i = 1, calculate c 0≤i<2 . When i = 0, calculate c y,0 = Enc(2.3, 7.7, 5.0, 10.4) according to the formula; When i = 1, calculate c y,1 = Enc(3.0, 10.2, 6.6, 13.8) according to the formula.

[0079] Step Five: The server sends the ciphertext vector {c y,i} 0≤i<2 to the client, and the client decrypts it with the private key sk to obtain the plaintext vector group {y i} 0≤i<2 .

[0080] (1) The server side sends the ciphertext vector {c k,i} 0≤i<2 to the client;

[0081] (2) The client uses the private key sk to decrypt each ciphertext c y,i one by one to obtain the corresponding plaintext vector yi = Dec sk (c y,i ) Quantity; the two plaintext vectors are y0 = (2.3, 7.7, 5.0, 10.4) and y1 = (3.0, 10.2, 6.6, 13.8) respectively.

[0082] Step Six: The client decodes the plaintext vector group {y i} 0≤i<2 and calculates the tensor Y = Decode({y i} 0≤i<2 ):

[0083]

[0084] It can be seen that the calculation result of the method of the present invention is consistent with the plaintext calculation result.

[0085] Example 2: Considering that in practical applications, the model calculation amount is large. For the calculation of one layer in an MLP neural network, assuming that the weight matrix W 64×32 and the bias vector b 32 are initialized randomly, and the inference is performed on this network. The input data dimension used is X 100×32×64 . For the encrypted calculation of this neural network, the method of the present invention provides a "calculation method for multiplying a plaintext matrix and a ciphertext tensor based on homomorphic encryption". The specific steps are exactly the same as those in Example 1, and the details will not be elaborated here. The specific process is as follows:

[0086] Step One: The client sets the parameters of the CKKS homomorphic encryption scheme.

[0087] Step Two: The client generates keys according to the security parameters.

[0088] Step Three: The client encodes the tensor X into a plaintext vector group {x j} 0≤j<3 , and encrypts the vector group into ciphertext vectors {c x,j} 0≤j<3 through the public key pk, and finally sends the ciphertext vectors, the public key pk, and the operation key ek to the server.

[0089] Step Four: The server calculates c j,i = CAdd(Add_all(CMult(c 0≤j<64,0≤i<32 , w i ))), b 0≤i<32 according to the weight matrix W = [w y,i x,j and the bias vector b = [b j,i i to obtain the ciphertext c y,i ​​, traverse \(i\) to obtain the ciphertext vector \(\{c y,i \}\ 0≤i<64 .

[0090] Step Five: The server sends the ciphertext vector \(\{c y,i \}\ 0≤i<64 to the client, and the client decrypts it with the private key \(sk\) to obtain the plaintext vector group \(\{y i \}\ 0≤i<64 .

[0091] Step Six: The client decodes the plaintext vector group \(\{y i \}\ 0≤i<64 and calculates to obtain the tensor \(Y = Decode(\{y i \}\ 0≤i<64 ).

[0092] To better demonstrate the beneficial effects of the method of the present invention, a comparative experiment was conducted on this embodiment using the invention patent "Matrix Multiplication Calculation Method for Plaintext and Ciphertext Based on Homomorphic Encryption" (Application No.: 202311195584.8) and the method of the present invention. After 100 repeated experiments, the average value was obtained, and the experimental results are as Figure 5 shown. It can be seen that the method of the present invention is much more efficient than the matrix multiplication calculation method for plaintext and ciphertext based on homomorphic encryption.

[0093] Furthermore, in terms of computational complexity, the number of ciphertexts of the method of the present invention is \(m\) pieces, and the number of plaintext-ciphertext multiplications is \(m\cdot t 2 , and the depth of CMult required in one calculation is 1; while the number of ciphertexts of the matrix multiplication calculation method for plaintext and ciphertext based on homomorphic encryption is \(l\) pieces, and the number of plaintext-ciphertext multiplications is \(l(m + m\cdot t 2 ), and the depth of CMult required in one calculation is 2. It can be seen that in theory, as the multiplication scale increases, the computational efficiency of the method of the present invention will be more superior to the matrix multiplication calculation method for plaintext and ciphertext based on homomorphic encryption.

[0094] Finally, it should be noted that the above preferred embodiments are only used to illustrate the technical solutions of the present invention and are not restrictive. Although the present invention has been described in detail through the above preferred embodiments, those skilled in the art should understand that various changes can be made in form and details without departing from the scope defined by the claims of the present invention.

Claims

1. A calculation method for multiplying a plaintext matrix and a ciphertext tensor based on homomorphic encryption, for the case where the client has a plaintext data tensor as the server has a plaintext matrix and a plaintext vector After the client encrypts the tensor X, the server calculates the ciphertext tensor to obtain Y = X·W + b, and outputs the ciphertext of the tensor to the client, characterized in that This method is applied to a system composed of two computer devices, namely a server and a client, which are connected through a network. The method includes the following steps: S1: Set the security parameter λ of the homomorphic encryption scheme ε = (Enc, Dec), and generate the relevant encryption and decryption parameters of the homomorphic encryption scheme according to the security parameter λ; S2: The client generates a private key sk, a public key pk, and an operation key ek according to the encryption and decryption parameters; S3: The client encodes the tensor X into m vector groups {x j } 0≤j<m , and encrypt the vector group into a ciphertext vector {c x,j } 0≤j<m , and finally package the ciphertext vector, public key pk and operation key ek and send them to the server; S4: The server calculates c j,i 0≤j<m,0≤i<t according to the weight matrix W = [w i 0≤i<t and the bias vector b = [b y,i x,j as c j,i = CAdd(Add_all(CMult(c i ), b y,i )) to obtain the ciphertext c y,i}, and traverses i to obtain the ciphertext vector {c 0≤i<t};​​​ S5: The server sends the ciphertext vector group {c y,i} 0≤i<t to the client, and the client decrypts it with the private key sk to obtain the plaintext vector group {y i} 0≤i<t ; S6: The client decodes the plaintext vector {y i}, 0≤i<t and calculates the plaintext tensor Y = Decode({y i}) 0≤i<t ; Among them, represents the n-dimensional real vector space, where l, n, m, t, and p are positive integers; let the plaintext space be The ciphertext space is Use Enc to represent the encryption algorithm operation, and Dec to represent the decryption algorithm operation; use Encode to represent the tensor encoding operation, and Decode to represent the tensor decoding operation. Among them, represents the element at the (k, i, j) position in the tensor X, and use x j,i-1 to represent the vector x j the i-th element in, and use [] k to represent the non-negative residue obtained by taking the modulus k when calculating the numerical value, represents the largest integer not exceeding the calculated numerical value, ⊙ represents the Hadamard Product of vectors, and ← represents assignment; Tensor The encoding operation of Input tensor Output m sets of vectors {x j} 0≤h<m ; where, for any x j = [x j,s 0≤s<l·n , the assignment process of x j,s is: traverse 0 ≤ kk < l and 0 ≤ i < n in sequence, select the element with k·n + i = s from tensor X and assign it to x j,s , obtaining ​ Vector group The decoding operation of Input a vector group {x j} 0≤j<m with length m, and the output tensor is where, for any j-th vector x j = [x j,s 0≤ s <l·n , the corresponding element in tensor X can be constructed ​ The addition operation of the ciphertext c and the real number r is Input a ciphertext c = (c0, …, c n-1 ); Output a ciphertext c′ such that c′ = (c0 + r, …, c n-1 + r); The multiplication operation of the ciphertext c and the real number r is Input a ciphertext c = (c0, …, c n-1 ); Output a ciphertext c' such that c' = (r·c0, …, r·c n-1 ); The addition operation of k ciphertexts is Input k ciphertexts c for i = 0, …, k - 1 i , and output the ciphertext Furthermore, step S1 is specifically as follows: S101: Determine the security parameter λ, i.e., it can resist at least an adversary with the computing power of 2 λ bit operations; S102: The client selects an integer p according to the sample data, and the numerical size will not exceed p / 2 during the ciphertext calculation process; S103: According to the security parameter λ and following the suggestions in the Homomorphic Encryption Security Standard, the user selects parameters m and q, and determines that the plaintext space of the homomorphic encryption scheme is That is, the ring of polynomials with integer coefficients Modulo the ideal generated by the m-th cyclotomic polynomial φ m (X) and the integer p, the resulting residue class ring, and the ciphertext space is Furthermore, step S2 is specifically as follows: S201: The client generates a random polynomial f with the number of indeterminates X randomly selected from the set {-1, 0, 1} with equal probability not exceeding , where represents the number of elements in the set {1, 2,..., m} that are relatively prime to m, and the private key sk = (1, f); S202: The client randomly selects a polynomial a of an indeterminate X from a uniform distribution of R q and randomly selects a noise polynomial e of the indeterminate X from an error distribution χ of . Then the public key pk = (-[(a·f + e)] q , a), where [·] q denotes the polynomial obtained by taking the coefficients of the polynomial in the square brackets modulo q; S203: The client generates the operation key ek required for noise control during the ciphertext operation process according to the selected homomorphic encryption scheme; Furthermore, step S3 is specifically as follows: S301: The client encodes the tensor to obtain m groups of plaintext vectors {x j} 0≤j<m = Encode(X), where the length of each vector is l·n; S302: The client encrypts the plaintext vector x one by one using the public key pk j to obtain the corresponding ciphertext c x,j = Enc pk (x j ); where j = 0, …, m - 1; S303: The client packs and sends the ciphertext vector {c x,j}, 0≤j<m the public key pk, and the operation key ek to the server; Furthermore, step S4 is specifically as follows: S401: The server side calculates according to the formula c xw,i = Add_all(CMult(c x,j , w j,i )) where w j,i is an element of the weight matrix W; traverse i = 0,..., t - 1 to calculate the ciphertext vectors {c xw,i} 0≤i<t ; S402: The server calculates according to the formula c y,i = CAdd(c xw,i , b i ), where b i is an element of the bias vector b; traverse i = 0, …, t - 1 to calculate the ciphertext vectors {c y,i} 0≤i<t ; Furthermore, step S5 is specifically as follows: S501: The server sends the ciphertext vector {c y,i} 0≤i<t to the client; S502: The client uses the private key sk to decrypt the ciphertext c one by one y,i to obtain the corresponding plaintext vector y i = Dec sk (c y,i ); where i = 0, …, t - 1.

2. The calculation method of plaintext matrix and ciphertext tensor multiplication based on homomorphic encryption according to claim 1, wherein For the security parameter λ described in step S101, take λ = 128 or 256.

3. The calculation method of plaintext matrix and ciphertext tensor multiplication based on homomorphic encryption according to claim 1, characterized in that The error distribution χ described in step S202 is taken as a discrete Gaussian distribution.

4. The calculation method of plaintext matrix and ciphertext tensor multiplication based on homomorphic encryption according to claim 1, wherein The CAdd and CMult calculation operations described in step S4 can be calculated using a parallel computing system with vectorized operations, which can improve the calculation efficiency.

5. The calculation method of the multiplication of the plaintext matrix and the ciphertext tensor based on homomorphic encryption according to claim 1, characterized in that The plaintext data tensor and the weight matrix When m > n, perform a transpose operation on the tensor X and the weight matrix W as a preprocessing, that is and adjust the corresponding indices, and calculate At this time, the corresponding number of ciphertexts is n, achieving the function of reducing the number of ciphertexts.

Citation Information

Patent Citations

  • Plaintext and ciphertext matrix multiplication calculation method based on homomorphic encryption

    CN117200972A

  • Operating device and method using multivariate packing

    US20220029783A1

  • Method of Designing of Multi-Party System in QAP-Based Homomorphic Encryption

    US20230188343A1