Method and apparatus for generating a multiplication quintet

By generating multiplicative quintuples through secure multi-party computation and RMFE encoding techniques, the problem of high overhead in generating multiplicative quintuples in existing technologies is solved, thereby improving generation efficiency and security.

CN119602950BActive Publication Date: 2025-11-11ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411666747.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-11-11
Estimated Expiration
2044-11-20

AI Technical Summary

Technical Problem

Existing technologies incur significant overhead when generating multiplication quintuples, impacting the efficiency of data computation among multiple participants.

Method used

Through secure multi-party computation among multiple participants, a secret share of triples in a specified domain space is generated. Based on these secret shares, the secret shares of the remaining elements of the quintuple are sampled from multiple equivalence classes in the specified domain space. The RMFE encoding technique is used for packaging and encoding to reduce the communication and computational overhead of the generation process.

Benefits of technology

It improves the generation efficiency of multiplication quintuples, reduces the computational overhead among multiple participants, and enhances the security and efficiency of data computation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119602950B_ABST
    Figure CN119602950B_ABST
Patent Text Reader

Abstract

This specification provides a method and apparatus for generating multiplicative quintuples. Multiple parties engage in a first data interaction based on secure multi-party computation, enabling each party to obtain a first secret share of the triples within a specified domain space. Next, through a second data interaction based on secure multi-party computation, for each element in the triples, based on the first secret share held by each party, samples are taken from multiple equivalence classes within the specified domain space. This results in each party obtaining an adopted secret share, which serves as a second secret share for the remaining elements in the quintuple to be generated. The second secret share and the first secret share constitute the secret share of the quintuple to be generated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to one or more embodiments in the field of computer technology, and more particularly to a method and apparatus for generating multiplication quintuples. Background Technology

[0002] Secure Multi-Party Computation (MPC) is a cryptographic technique that allows multiple participants to collaborate on computation and analysis while maintaining their individual data privacy. Its core idea is to use cryptographic techniques and algorithms to encrypt the data of each participant before computation, ensuring that each participant only obtains the data and computation results they need, and cannot access the original data of other participants. Many business scenarios involve data computation and interaction between multiple collaborating parties; however, none of the parties want to leak their private data. In such cases, secure multi-party computation based on secret sharing has become a widely deployed security solution. When performing data multiplication calculations based on secure multi-party computation, to ensure the security of the multiplication operation, multiple participants need to generate random quintuples to assist in the multiplication operation, thereby ensuring the correctness and security of the calculation while reducing communication and computational overhead. Currently, generating multiplication quintuples is relatively expensive.

[0003] Therefore, we hope to find an improved solution that can increase the generation efficiency of multiplication quintuples and reduce overhead. Summary of the Invention

[0004] This specification describes one or more embodiments of a method and apparatus for generating multiplicative quintuples. The specific technical solution is as follows.

[0005] In a first aspect, the embodiment provides a method for generating a multiplication quintuple, executed by multiple participants, including:

[0006] Through a first data interaction based on secure multi-party computation, multiple participants obtain, respectively, the first secret sharing of a triple in a specified domain space within that participant.

[0007] Multiple participants engage in a second data interaction based on secure multi-party computation. For the elements in the triplet, based on the first secret sharing held by each party, the elements are sampled from multiple equivalence classes in the specified domain space, so that each participant obtains: the second secret sharing of the remaining elements in the quintuple to be generated in that participant; the second secret sharing and the first secret sharing constitute the secret sharing of the quintuple to be generated.

[0008] In one implementation, the first data interaction includes:

[0009] Multiple participants generate their own k Boolean secret-sharing triples through first sub-data interaction based on secure multi-party computation;

[0010] Multiple participants exchange second sub-data based on secure multi-party computation to package and encode the k Boolean secret sharing triples owned by each party in the designated domain space, so that each participant obtains the corresponding first secret sharing.

[0011] In one implementation, any Boolean secret sharing triple includes a three-element Boolean secret sharing; the second sub-data interaction includes:

[0012] For any one of the three elements, each participant shares the k Boolean secrets of that element to form the Boolean secret sharing of the vector corresponding to that element.

[0013] Multiple participants exchange second sub-data based on secure multi-party computation, packaging and encoding the Boolean secrets of the vectors corresponding to the three elements owned by each party in the designated domain space, so that each participant obtains the first secret sharing corresponding to the three elements respectively.

[0014] In one implementation, the designated domain space is a space containing multiple m-bit binary domain elements, and the encoding includes operations based on the multiplication-friendly encoding RMFE.

[0015] In one implementation, the second data interaction includes:

[0016] Multiple participants interact through a second data exchange based on secure multi-party computation. Based on the secret sharing of the vectors corresponding to the elements owned by each party, the vectors are sampled from multiple preimages in the specified domain space, so that each participant obtains a new secret sharing. The new secret sharing serves as the second secret sharing of the remaining elements.

[0017] The secret share of the vector can be obtained by decoding the first secret share of the element.

[0018] In one implementation, the triplet includes a first element, a second element, and a third element, wherein the third element is equal to the product of the first element and the second element; the step of sampling the element from multiple equivalence classes in the specified domain space includes:

[0019] Sample the first element from multiple equivalence classes in the specified domain space to obtain the secret sharing of the fourth element in the five-tuple to be generated in multiple participating parties, which serves as the second secret sharing of the fourth element.

[0020] The second element is sampled from multiple equivalence classes in the specified domain space to obtain the secret sharing of the fifth element in the five-tuple to be generated in multiple participating parties, which serves as the second secret sharing of the fifth element.

[0021] Secondly, the embodiments provide a privacy-preserving data processing method, executed by multiple parties, including:

[0022] Multiple participants each obtain a quintuple secret share of the multiplication quintuple; the quintuple secret share is generated by the method described in the first aspect;

[0023] Multiple participants each use their own five-tuple secret sharing to hide their private data, obtain secret data sharing, and send it to other participants;

[0024] Multiple participants, based on their respective five-tuple secret sharing and the secret data sharing sent by other participants, determine the secret sharing of the product between the private data of the multiple participants.

[0025] Thirdly, the embodiment provides a method for generating a multiplication quintuple, which can be executed by any one of the participants, including:

[0026] Through the first data interaction based on secure multi-party computation with other participants, each participant obtains: the first secret sharing of the triple in the specified domain space within that participant;

[0027] Through a second data interaction based on secure multi-party computation between the participants, for the elements in the triplet, based on the first secret sharing held by each party, the elements are sampled from multiple equivalence classes in the specified domain space, so that the multiple participants respectively obtain: the second secret sharing of the remaining elements in the quintuple to be generated in the participant's second secret sharing; the second secret sharing and the first secret sharing constitute the secret sharing of the quintuple to be generated.

[0028] Fourthly, the embodiment provides a system for generating multiplication quintuples, the system comprising multiple participants;

[0029] Among multiple participants, a first data interaction based on secure multi-party computation is used to enable each participant to obtain: a triplet of a specified domain space and a first secret sharing within that participant;

[0030] Among multiple participants, through a second data interaction based on secure multi-party computation, for the elements in the triple, based on a first secret share held by each party, the elements are sampled from multiple equivalence classes in the specified domain space, such that each participant obtains: the second secret share of the remaining elements in the quintuple to be generated in that participant; the second secret share and the first secret share constitute the secret share of the quintuple to be generated.

[0031] Fifthly, the embodiments provide a privacy-protecting data processing system, the system comprising multiple participating parties;

[0032] Multiple parties are involved in obtaining the quintuple secret share of the multiplication quintuple; the quintuple secret share is generated by the method described in the first aspect.

[0033] Multiple participants use their respective quintuple secret sharing to hide their private data, obtain secret data sharing, and send it to other participants;

[0034] Multiple parties are involved in determining the secret sharing of the product between their private data based on their respective quintuple secret sharing and the secret data sharing sent by other parties.

[0035] Sixthly, the embodiment provides a multiplication quintuple generation apparatus, deployed in any participating party, comprising:

[0036] The triplet determination module is configured to enable multiple participants to obtain, through a first data interaction based on secure multi-party computation with other participants, the first secret sharing of triples in a specified domain space within that participant.

[0037] The quintuple determination module is configured to, through a second data interaction based on secure multi-party computation with the participating parties, sample the elements in the triple from multiple equivalence classes in the specified domain space based on the first secret sharing held by each party, so that the multiple participating parties respectively obtain: the second secret sharing of the remaining elements in the quintuple to be generated in that participating party; the second secret sharing and the first secret sharing constitute the secret sharing of the quintuple to be generated.

[0038] In a seventh aspect, an embodiment provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method described in any one of the first to third aspects.

[0039] Eighthly, an embodiment provides a computing device including a memory and a processor, wherein the memory stores executable code, and the processor, when executing the executable code, implements the method described in any one of the first to third aspects.

[0040] In the methods and apparatus provided in the embodiments of this specification, multiple participants interact through data exchange based on secure multi-party computation to generate a secret share of the remaining two elements of a specified domain space based on a triplet. The secret share of the triplet and the secret share of the two elements constitute a secret share of a quintet. This quintet generation method can call the bucketing technique only once, which has lower overhead than existing methods and can improve the generation efficiency of multiplicative quintuples. Attached Figure Description

[0041] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.

[0042] Figure 1 This is a schematic diagram illustrating an implementation scenario of one embodiment disclosed in this specification;

[0043] Figure 2 A flowchart illustrating a method for generating a multiplicative quintuple is provided for an embodiment.

[0044] Figure 3 This is a diagram comparing the bucketing costs of two different schemes.

[0045] Figure 4 A schematic flowchart illustrating a privacy-protecting data processing method provided in this embodiment;

[0046] Figure 5 A schematic block diagram of a multiplication quintuple generation system provided for an embodiment;

[0047] Figure 6 A schematic block diagram of a data processing system provided for an embodiment;

[0048] Figure 7 This is a schematic block diagram of a device for generating a multiplication quintuple, provided as an embodiment. Detailed Implementation

[0049] The solution provided in this specification will now be described with reference to the accompanying drawings.

[0050] Figure 1This is a schematic diagram illustrating an implementation scenario of one embodiment disclosed in this specification. It includes multiple participants, such as participant A, participant B, and participant C. These participants can interact with each other based on MPC (Multiplication Protocol), generating multiplicative quintuples through this data interaction. Based on data interaction, each participant can generate a secret share of triples in a specified domain space. The secret shares of triples from multiple participants can reconstruct a complete triple. Based on data interaction, multiple participants can generate a secret share of quintuples based on the secret shares of triples. The secret shares of quintuples from multiple participants can reconstruct a complete quintuple. The reconstruction operation can include operations such as addition. Figure 1 The multiple participants shown are merely an example. In practical applications, the number of participants can be two or more.

[0051] Multiple parties can communicate via the Internet and jointly execute a pre-negotiated software protocol, MPC. The MPC described in this specification may include algorithms such as homomorphic encryption, secret sharing, zero-knowledge proofs, accidental transmission, and obfuscated circuits. Secret sharing, also known as secret sharing, divides confidential information into multiple random fragments, each stored and managed by a different party. The original secret can only be recovered when a certain number of parties cooperate. This can be achieved using... <x>Let represent the secret sharing of x. Secret sharing is a fundamental algorithm in MPC, providing a method for secure information exchange without revealing each other's inputs. This algorithmic mechanism is the cornerstone for building more complex secure multi-party computation protocols, and other secure multi-party computation algorithms can be executed based on the secret sharing algorithm.

[0052] In business processing, multiple parties need to perform data computations based on Multi-Party Computation (MPC). Furthermore, these parties often rely on randomly generated quintuples to assist in data multiplication operations, thereby ensuring the security of the computation process. A quintuple is a secret-shared combination containing five secret-shared values, used to assist in secure multi-party computation multiplication operations. The computation process involves numerous multiplication operations, requiring a large number of randomly generated quintuples. Therefore, the efficiency of quintuple generation significantly impacts the efficiency of data computation among multiple parties.

[0053] To improve the efficiency of generating quintuples and reduce the computational overhead among multiple participants, this specification provides a method for generating quintuples. It should be noted that multiple participants perform data computation operations through their respective computing devices. The computing devices of the multiple participants (i.e., participant devices) are connected via network communication. Each computing device can be implemented using any device, equipment, platform, device cluster, etc., with computing and processing capabilities.

[0054] The following is combined with Figure 2 The method of this embodiment will be described in detail.

[0055] Figure 2 This is a flowchart illustrating a method for generating a multiplicative quintuple, provided as an example. The method is executed by multiple participants. For ease of understanding, this example uses participant A and participant B as illustrations. This embodiment specifically includes the following steps.

[0056] In step S210, multiple participants exchange data based on secure multi-party computation, thereby enabling each participant to obtain a first secret sharing of a triple (a, b, c) in a specified domain space within that participant.

[0057] The triple (a, b, c) contains the first element a, the second element b, and the third element c, and the third element c is equal to the product of the first element a and the second element b, i.e., c = ab.

[0058] A specified domain space can be a defined numerical domain space, which is a finite field. A specified domain space contains multiple elements. The specified domain space involves corresponding encoding and decoding processes. A specified domain space satisfies the following condition: after encoding two vectors X and Y into elements M and N in the specified domain space respectively, if a multiplication Z = MN is performed on M and N, and Z is decoded back into a vector C, then it is guaranteed that C is equal to the point-wise multiplication result of X and Y, that is, for any i-th bit, C[i] = X[i] * Y[i]. Here, C[i], X[i], and Y[i] represent the i-th data in C, X, and Y respectively. In other words, this encoding and decoding process is used to embed elements from a smaller finite field into a larger finite field while maintaining a certain degree of homomorphism. Multiplication operations based on this encoding and decoding process often utilize randomly generated quintuples to implement this process.

[0059] In information theory, cryptography, and communication systems, the binary field is an important numerical field and algebraic operation field. The following explanation uses the binary field as an example to illustrate a specific field space. In a binary field, the elements are m-bit binary numbers. This type of field space is often called a binary finite field, also known as a Galois field (GF(2)). m In this field, element operations are modulo 2, meaning they mainly involve addition and multiplication without carry.

[0060] Through the aforementioned first data exchange, participants A and B respectively obtained the first secret sharing of the triple (a, b, c). , , <c> ).in,< / c> This is the first secret shared by the first element of the triplet. It is the first secret shared by the second element in the triplet. <c>It is the first secret shared by the third element in the triplet.

[0061] When multiple parties perform various data interactions based on MPC (including the first data interaction and subsequent data interactions), the functions and status of each party are the same, the operations performed and the types of data obtained are the same, but the values ​​of the data themselves are random and different; that is, the value of the first secret shared by the triple (a, b, c) is different among the multiple parties. For example, the first secret shared by the triple (a, b, c) in party A is (< / c> , , <c>) A Sharing the first secret with participant B (< / c> , , <c>) B The values ​​are different, and the specific values ​​are randomly generated. Furthermore, the first secret sharing among multiple participants can reconstruct the complete triple (a, b, c). It should be noted that although multiple secret sharing can reconstruct the complete data, in general, it is not necessary to reconstruct the complete data during data processing; instead, data processing is based on the secret sharing.

[0062] The technique for generating secret sharing of triples is an existing technology in the field of MPC applications. Therefore, for the step of obtaining the first secret sharing of triples (a, b, c) in a specified domain space among multiple participants through the first data interaction based on secure multi-party computation, various existing technologies can be used.

[0063] In one application scenario, when it is necessary to compute a "comparison" operation between two numbers, a common MPC approach is to describe the comparison operation as a Boolean logic circuit (composed of an XOR gate and an AND gate), and then use Boolean secret sharing techniques for computation. Currently, an efficient approach is to use multiplication-friendly encoding RMFE packaging technology to package multiple Boolean secret shares into an arithmetic secret share, and perform secure computation on the arithmetic secret share.

[0064] RMFE (Reverse Multiplication-Friendly Embedding) is a technique used in cryptography and MPC that allows multiple numerical values ​​to be encoded as polynomials, enabling multiplication without revealing the original values. RMFE is an encoding method applied in binary domain space. Its input is a k-bit vector (each element is either 0 or 1), and through an encoding function, the output is an m-bit binary domain element. When two k-bit vectors X and Y are encoded into binary domain elements M and N respectively, if a multiplication Z = MN is performed on M and N, and Z is decoded back into a vector C, then C is guaranteed to be equal to the bitwise product of X and Y, i.e., for all i (1 ≤ i ≤ k), C[i] = X[i] * Y[i]. Here, C[i], X[i], and Y[i] represent the i-th bit of C, X, and Y, respectively. The following text uses E to represent the RMFE encoding algorithm and D to represent the RMFE decoding algorithm. The space containing the k-bit vector is a k-bit vector space. RMFE can convert elements between vector space and binary field space. Furthermore, for increased security, m is typically set to be greater than k, meaning the number of bits in the binary field space is greater than the dimension of the vector space. For example, you could use the following settings: k = 12, m = 48. Setting k and m to other values ​​is also possible.

[0065] In this embodiment, the first data interaction may include a first sub-data interaction and a second sub-data interaction. That is, step S210 can be performed using steps 1 and 2.

[0066] Step 1: Multiple participants generate their own k Boolean secret sharing triples through the first sub-data interaction based on MPC.

[0067] Any Boolean secret-sharing triplet can be understood as a secret share of the corresponding Boolean triplet. A Boolean triplet contains three elements, and the product of any two of these elements equals the third element. After the first sub-data interaction based on MPC, each participant obtains k secret shares of Boolean triples. Boolean triples and Boolean secret-sharing triplets are not triples and their secret shares defined in a specific domain space.

[0068] Each participant's Boolean secret sharing triple is not a complete Boolean triple, but rather a secret share of Boolean triples. Boolean Secret Sharing is a secret-sharing scheme based on Boolean operations, i.e., logical operations such as AND, OR, and NOT. In this scheme, the secret is represented as a binary value, either 0 or 1, and shares are also binary values. That is, each element in a Boolean triple has a value of 0 or 1, and each element in a Boolean Secret Sharing triple also has a value of 0 or 1. Boolean Secret Sharing is characterized by its simplicity and high computational efficiency.

[0069] For any participant, its k Boolean secret-sharing triples can be represented as:

[0070] ( <x1> , <y1> , <z1> )、( <x2> , <y2> , <z2>), ..., ( <x k >, <y k >, <z k >) (1)

[0071] Wherein, the i-th Boolean secret sharing triplet can be represented as ( <x i >, <y i >, <z i >), i∈[1,k]. <x i >、 <y i >and <z i Both are either 0 or 1.

[0072] The corresponding elements in the i-th Boolean secret-sharing triplet of multiple participants can form the complete elements of the Boolean triplet. For example, the i-th Boolean secret-sharing triplet of participant A ( <x i >, <y i >, <z i >) A Share the triplet with participant B's i-th Boolean secret ( <x i >, <y i >, <z i >) B Elements at the same position in the array correspond to each other and can be reconstructed to form a complete Boolean triplet (x, y, z), where z = xy. Multiple participants each possess k Boolean secret-sharing triplets, which can be used to reconstruct k complete Boolean triplets.

[0073] The step of multiple participants generating their own k Boolean secret sharing triples through the first sub-data interaction based on MPC can be implemented in various existing ways. For example, TinyOT technology can be used to generate the k Boolean secret sharing triples owned by each participant; the specific process will not be elaborated here.

[0074] Step 2: Through the second sub-data interaction based on secure multi-party computation, multiple participants package and encode the k Boolean secret sharing triples owned by each party in a designated domain space, so that each participant obtains the corresponding first secret sharing.

[0075] The k Boolean secret sharing triples held by each participant are not elements of the specified domain space. Furthermore, the k Boolean secret shares held by any participant are independent k Boolean secret shares, not vectors in a k-dimensional vector space. Step 2 ensures that the k Boolean secret shares of each element in the Boolean triples are packaged into a vector, and this vector is encoded into the specified domain space.

[0076] Any Boolean secret sharing triplet consists of a Boolean secret sharing of three elements, therefore the second sub-data interaction can be performed using the following steps 2-1 and 2-2.

[0077] Step 2-1: Any participant A, for any element x among the three elements (x, y, z), shares the k Boolean secrets of element x. <x1> , <x2>,…,as well as <x k >The Boolean secret sharing of the vector corresponding to the constituent element x.

[0078] Each of the k Boolean secret shares of element x is an independent value. However, when constructing the vector corresponding to element x from these k Boolean secret shares, we are actually building a single vector from the k Boolean secret shares of element x. The vector corresponding to element x can be constructed as (x1, x2, ..., x...). k The secret sharing of this vector among participant A is called Boolean secret sharing, which can be represented as ( <x1> , <x2>, ..., <x k Similarly, participant A can construct a vector of element y as (y1, y2, ..., y). k The Boolean secret sharing of this vector in participant A can be represented as ( <y1> , <y2>, ..., <y k >). Participant A can construct a vector of elements z as (z1, z2, ..., z). k The Boolean secret sharing of this vector in participant A can be represented as ( <z1> , <z2>, ..., <z k >).

[0079] For other participants, such as participant B, they can also share the k Boolean secrets of each of the three elements (x, y, z) to form the Boolean secret share of the vector corresponding to that element. The expression of the vector and the Boolean secret share of the vector is the same as that of participant A, and will not be listed in detail here.

[0080] Multiple participants can independently share the k Boolean secrets of an element to form the Boolean secret sharing of the vector corresponding to that element x.

[0081] In a vector formed by k Boolean secret shares, the vector is k-dimensional, and each element of the vector takes the value 0 or 1, hence it is called a Boolean secret share of the vector.

[0082] After the data processing in step 2-1, each of the three elements (x, y, z) in the Boolean secret sharing triplet corresponds to a vector, thus obtaining three vectors corresponding to the three elements. Multiple participants then share these three vectors in a Boolean secret sharing process.

[0083] ( <x1> , <x2> ,…,<x k >)、( <y1> , <y2>, ..., <y k >) and ( <z1> , <z2>, ..., <z k >) (2)

[0085] Step 2-2: Through a second sub-data exchange based on secure multi-party computation, multiple participants package and encode the Boolean secret sharing of the vectors corresponding to the three elements (x, y, z) held by each party in a specified domain space, so that each participant obtains the first secret sharing corresponding to these three elements (a, b, c) respectively. < / z1> < / y1> < / x2> < / x1> < / z1> < / y1> < / x1> < / x1> < / y2> < / x2> < / z1> < / y1> < / x1> < / c> 、 、 <c>).

[0086] The vectors corresponding to the three elements (x, y, z) are vectors in a k-dimensional vector space, and the k elements in each vector are independent of each other. During packing and encoding, the k elements in each vector are packed and encoded, transforming each k element into an element in the specified domain space. Thus, the three vectors corresponding to the three elements (x, y, z) can each be transformed into an element in the specified domain space, resulting in three elements represented as (a, b, c). This represents the Boolean secret sharing of the first vector (vector 1) among multiple participants. <x1> , <x2>, ..., <x k >) is transformed into the first secret share of element a in the triple (a, b, c), and the Boolean secret share of the second vector (vector 2) among multiple participants. <y1> , <y2>, ..., <y k >) is transformed into the first secret sharing of element b in the triple (a, b, c), and the Boolean secret sharing of the third vector (vector 3) among multiple participants. <z1> , <z2>, ..., <z k >) is transformed into the first secret share of element c in the triple (a, b, c).

[0087] In the specific implementation of step 2-2 above, the specified field space can be a space containing multiple m-bit binary field elements, and the encoding algorithm is RMFE. RMFE packing technology can be used to achieve RMFE secretsharing conversion, that is, converting k boolean secret shares into one RMFE secret share.

[0088] This transformation is equivalent to sharing the k Boolean secrets held by multiple participants. <x1> , <x2>, ..., <x k >) Packaged in RMFE as a single arithmetic secret for sharing. < / x1> < / z1> < / y1> < / x1> < / c> And the decoding result of a is D(a) = (x1, x2, ..., x k ), and a=E(x1, x2, …, x k ), where 'a' is a secret shared by multiple parties. The complete data after reconstruction.

[0089] This transformation is also equivalent to sharing the k Boolean secrets held by multiple participants. <y1> , <y2>, ..., <y k >) Packaged in RMFE as a single arithmetic secret for sharing. And the decoding result of b is D(b) = (y1, y2, ..., y k ), and b = E(y1, y2, ..., y k b is a secret shared by multiple parties. The complete data after reconstruction.

[0090] This transformation is also equivalent to sharing the k Boolean secrets held by multiple participants. <z1> , <z2>, ..., <z k >) Packaged in RMFE as a single arithmetic secret for sharing. <c>And the decoding result of c is D(c) = (z1, z2, ..., z k ), and c = E(z1, z2, ..., z k ), c is a secret shared by multiple participants. <c>The complete data after reconstruction.

[0091] Table 1 shows various data related to the first secret sharing of k Boolean secret-sharing triples and triples in the transformed specified domain space for any participant.

[0092]

[0093] The left column contains various secrets shared by a participant, while the right column contains the corresponding complete data and the relationships between the data.< / c> < / c> < / z1> < / y1> 、 and <c>All are m-bit binary field elements.

[0094] It should be noted that numerical values ​​without angle brackets typically represent complete values, not secret shares. In the embodiments described in this specification, the relationships between complete values ​​are for theoretical analysis only and will not be used in actual data processing. Actual data processing utilizes corresponding secret shares.

[0095] For step S210, the specified domain space can be any of several finite fields. Furthermore, the first data interaction can be implemented in various ways, as long as it allows multiple participants to obtain the first secret sharing of the triples (a, b, c) in the specified domain space. Steps 1 and 2 are one implementation of the first data interaction in a Boolean logic circuit-related scenario. In practical applications, similar implementations to steps 1 and 2 can also be used to execute step S210 in other scenarios, which will not be detailed further.

[0096] When executing step 2, steps 2-1 and 2-2 are one way to implement step 2. In practical applications, through MPC-based data interaction, the k Boolean secret sharing triples held by each party are packaged and encoded in a specified domain space, so that multiple participating parties each obtain the first secret share. This can be implemented using a black box, and step 2 is the function of this black box. The input of the black box is the k Boolean secret sharing triples from multiple participating parties, and the output is the first secret share of the triples in the specified domain space. The internal implementation of the black box can include many methods.

[0097] In step S220, multiple participants engage in a second data interaction based on secure multi-party computation. For each element in the triple (a, b, c), based on a shared first secret held by each party, samples are taken from multiple equivalence classes within a specified domain space. This ensures that each participant receives a second secret share of the remaining elements in the to-be-generated quintuple within that participant. The elements can be any one of the triples (a, b, c). Sampling can be random sampling or sampling in a specific order.

[0098] In this process, the second secret share and the first secret share constitute the secret share of the quintuple to be generated. Multiple participants already have the first secret share of three elements (a, b, c), and are missing the secret shares of two elements (d, e), which can then form the quintuple to be generated (a, b, c, d, e). Next, two elements can be selected from the triple (a, b, c), and for each element, based on the first secret share held by each party, samples can be taken from multiple equivalence classes of that element in a specified domain space, thereby obtaining the secret shares of the two missing elements (d, e).

[0099] When selecting an element from the triple (a, b, c), which includes the first element a, the second element b, and the third element c, you can choose the first element a and the second element b, or you can choose the first element a and the third element c, or the second element b and the third element c. The following example of selecting the first element a and the second element b illustrates how to sample from the equivalence class of elements. Other selection methods are similar and will not be elaborated further.

[0100] Multiple participants can share a first secret based on the first element 'a' possessed by each participant through a second data interaction based on secure multi-party computation.< / c> By sampling from multiple equivalence classes of the first element 'a' in a specified domain space, the secret sharing of the fourth element 'd' in the to-be-generated quintuple (a, b, c, d, e) is obtained among the multiple participating parties. <d>The second secret sharing as the fourth element d <d>.

[0101] Multiple participants can share a first secret based on the second element b, which is owned by each participant, through a second data interaction based on secure multi-party computation. By sampling from multiple equivalence classes of the second element b in a specified domain space, the secret sharing of the fifth element e in the quintuple to be generated (a, b, c, d, e) is obtained among the multiple participating parties. <e>The second secret shared as the fifth element e <e>.

[0102] An equivalence class is a set of multiple elements in a given domain space that, when decoded, yield the same vector. In other words, multiple binary elements in a given domain space that can be decoded into the same vector can be called an equivalence class. This implies the existence of a relation.

[0103] D(d) = D(a), D(e) = D(b) (3)

[0104] As discussed above, RMFE encoding allows a k-bit vector to be encoded into m-bit binary field elements. In RMFE, the encoded field space is much larger than the original vector space, therefore different binary field elements can be decoded into the same vector. In other words, multiple elements in a specified field space correspond to a single vector in the vector space. Through the RMFE encoding function, each vector can be uniquely encoded into a binary field element. Through the RMFE decoding function, a binary field element can be uniquely decoded into a vector.

[0105] When the encoding and decoding functions corresponding to a specified domain space are known, given the first secret sharing of an element by multiple participants, it is possible to determine multiple equivalence classes of that element in the specified domain space. Step S220 can be implemented in the following ways:

[0106] Multiple participants exchange data based on MPC, and each party samples from multiple preimages in a specified domain space based on the secret sharing of the vector corresponding to the element owned by each party. This results in each participant obtaining a new secret sharing, which serves as the second secret sharing for the remaining elements.

[0107] This includes cases where the element is the first element a, the second element b, or the third element c in the triple (a, b, c). Let's continue with the example of choosing the first element a and the second element b.

[0108] Multiple participants can exchange data through a second data interaction based on secure multi-party computation, and can share the secret of the vector corresponding to the first element 'a' held by each participant. <x1> , <x2>, ..., <x k >), sampling is performed from multiple preimages of the vector in the specified domain space, so that multiple participants obtain new secret shares, which serve as the second secret shares corresponding to the fourth element d in the to-be-generated quintuple (a, b, c, d, e) among the multiple participants respectively. <d>.

[0109] Multiple participants can exchange data through a second data interaction based on secure multi-party computation, and can secretly share the vector corresponding to the second element b held by each participant. <y1> , <y2>, ..., <y k >), sampling is performed from multiple preimages of the vector in the specified domain space, so that multiple participants each obtain a new secret share, which serves as the second secret share corresponding to the fifth element e in the to-be-generated quintuple (a, b, c, d, e) among the multiple participants. <e>.

[0110] Specifically, the secret share of a vector can be obtained by decoding the first secret share of an element. The first secret share of an element is encoded data, and by decoding the first secret share of an element, the secret share of the vector corresponding to that element can be obtained. For example, the first secret share of the first element 'a'...< / e> < / y1> < / d> < / x1> < / e> < / e> < / d> < / d> Decoding reveals the secret share of the vector. <x1> , <x2>, ..., <x k >); Sharing the first secret of the second element b Decoding reveals the secret share of the vector. <y1> , <y2>, ..., <y k Multiple participants can independently decode the first secret share of the elements to obtain the secret share of the vector.

[0111] It should be noted that the secret share of the vector can be obtained by decoding the first secret share of the element, or it can be obtained directly from step S210 without decoding. In one embodiment of step S210, the participants can construct the Boolean secret share of the vector corresponding to the element using the k Boolean secret shares of the element they generate.

[0112] Through an encoding function, a vector can be encoded into a specified domain space to obtain the first secret share of the elements. Through a decoding function, multiple first secret shares (i.e., binary domain elements) of the elements can be decoded into a vector space to obtain the secret shares of the vectors of multiple participants. In decoding, the vector belongs to the "image," and the binary domain elements in the specified domain space belong to the "pre-image."

[0113] When performing step S220, sampling from multiple preimages of the vector corresponding to the element held by each party is only one feasible implementation. Step S220 can also be implemented in other ways, such as by mathematically solving for the element directly from multiple equivalence classes of the element held by each party based on the first secret sharing of the element.

[0114] The sampling process will be explained below from the perspective of the principles of encoding and decoding.

[0115] In RMFE, the specified field space is an m-bit binary field space, and the vector space is a k-bit binary number space. There is a mapping relationship between the elements of the two spaces, which can be represented as:

[0116] f→(f(β1), f(β2),…, f(β k (4)

[0117] In the above equation, f on the left side is a binary field element, which can be represented as a polynomial including variables and 2k-1 coefficients. The right side of the equation is a k-dimensional vector, where f(β1), f(β2), etc., are elements of the vector, and → represents a mapping function (including decoding and encoding functions). β1 and β2 are fixed parameters in the mapping function.

[0118] When the variables in the polynomial take k elements of a vector, and the vector on the right side is determined, the k elements of the vector are the k evaluations of f. These k evaluations are the values ​​of the variables when they take values ​​from β1 to β2. k The value of f is obtained by taking the k estimated values. Based on these k estimates, k coefficients of f can be randomly fixed, and the remaining k-1 coefficients can be determined by interpolation or other methods, thus obtaining f, which is equivalent to obtaining a sample.

[0119] Next, let's explain the concept of data interaction. First data interaction, second data interaction, and so on, refer to the data interaction methods between multiple participants. When the input data is different, using the same data interaction method can achieve the same function. Therefore, first data interaction and second data interaction can be understood as corresponding to different functions, respectively.

[0120] For the quintuplet to be generated (a, b, c, d, e), elements a, b, and c are obtained through step S210, meaning elements a, b, and c are elements of the triplet (a, b, c), where c = ab. Elements d and e are obtained through step S220. The secret sharing of elements d and e is obtained by sampling the equivalence classes of the elements in the triplet, and elements d and e have relationships with the elements in the triplet. For example, the elements in the quintuplet to be generated have the following relationships:

[0121] a=E(D(a)), b=E(D(b)), c=E(D(a) * D(b)), D(d)=D(a), D(e)=D(b)(5)

[0122] The following example illustrates the implementation.

[0123] Generate TinyOT multiplication triples. In practical applications, to improve security and reduce computational overhead, each party generates (N+s)*k TinyOT triples (i.e., Boolean secret-sharing triples) through step 1. <x i >, <y i >, <z i ), where i = 1, 2, ..., (N+s)*k. The elements in the triplet are either 0 or 1. N is the number of quintuples to be generated, which can be a large number, such as 100,000. s is a security-related parameter, typically 40. s sets of quintuples act as noise, thus protecting the real quintuples. Each participant generates the following series of triplets ( <x1> , <y1> , <z1> )、( <x2> , <y2> , <z2>), ..., ( <x (N+s)*k >, <y (N+s)*k >, <z (N+s)*k >).

[0124] Perform the RMFE secret sharing transformation. Multiple participants divide the above series of triples into segments of k triplets each, with each segment consisting of k Boolean secret sharing triples. For each segment, each party generates an RMFE triple through step 2. i >, i >, <c i >), which is a triplet in the specified domain space, where i = 1, ..., N+s.

[0125] Randomly sample the preimages of RMFE secret sharing a and b. Multiple participants execute step S220, inputting the obtained elements. i >, the secret sharing of outputting the corresponding random preimage <d i >, so that D(d i )=D(a i ); Input the obtained elements i >, the secret sharing of outputting the corresponding random preimage <e i >, making D(e i )=D(b i ).element <d i >and <e i >and i >、 i >and <c i This forms the quintuples to be generated. For each i from 1 to N+s, N+s quintuples can be obtained, and N quintuples can be selected from the N+s quintuples.

[0126] Output N quintuples ( i >, i >, <c i >, <d i >, <e i >), where i = 1, ..., N.

[0127] It should be noted that the most expensive part of the above process is step 1 in step S210, where multiple participants jointly generate k Boolean secret sharing triples through the first sub-data interaction based on MPC. This step can be executed using existing methods. Typically, the execution of step 1 introduces an overhead inflation factor B due to bucketing technology. Bucketing is a data partitioning technique that randomly distributes n*B elements into n buckets, with each bucket containing B elements.

[0128] ​​​​​​​​Furthermore, steps 2 and S220, performed based on this triple, do not require the use of bucketing technology. Therefore, the solution in this embodiment invokes bucketing technology at most once, reducing the overhead caused by bucketing.

[0129] < / y2> < / x2> < / z1> < / y1> < / x1> < / y1> < / x1> Figure 3 This is a schematic diagram comparing the bucketing overhead of two schemes. The flowchart on the left includes steps such as generating TinyOT multiplication triples, performing RMFE secret-sharing transformation, and randomly sampling the preimage of the RMFE secret-sharing. Bucketing is only introduced once in this process when generating TinyOT multiplication triples. Figure 3 The symbol is represented by ×B.

[0130] In a similar scheme, multiple participants can jointly generate RMFE secret-sharing tuples ( , <c>)and( , <d>), where c = E(D(a)) and d = E(D(b)). Based on this tuple, by invoking a complex "multiplication" protocol, the following is calculated: <e>And e = c * d. In this scheme, calculate... <e> The overhead is huge, requiring three calls to the bucketing technique. For example...< / e> < / e> < / d> < / c> Figure 3 The flowchart on the right shows steps including constructing binary pairs, sacrificing buckets, combining buckets (a), and combining buckets (b). The latter three steps all involve calculating... <e>The bucketing technique was invoked three times in total.

[0131] Assuming the bucket size parameter for each bucketing is B, if N quintuples need to be generated, then a similar approach would require approximately 2*N*B quintuples to be generated. 3 There are 2 pairs of binary tuples. In other words, each bucketing operation is equivalent to multiplying the cost of this algorithm by a factor of B. In practical systems, B typically takes values ​​of 3, 4, or 5, therefore B... 3 It is equivalent to 27 or 64.

[0132] The solution in this embodiment only requires one bucketing technique, which can divide B... 3 The overhead factor is reduced to B, resulting in a performance improvement of about an order of magnitude.

[0133] The above describes the method for generating multiplication quintuples in MPC. The following section explains how to use these multiplication quintuples for data processing, specifically the process of performing multiplication operations across multiple devices.

[0134] Figure 4 This is a flowchart illustrating a privacy-protecting data processing method provided in this embodiment. The method is executed by multiple parties. For ease of understanding, this embodiment uses party A and party B as examples. The method specifically includes the following steps.

[0135] Step S410: Multiple participants each obtain the quintuple secret sharing of the multiplication quintuple. For example, participant A obtains the multiplication quintuple secret sharing as ( A , A , <c> A , <d> A , <e> A The secret of the multiplication quintuple obtained by participant B is (< / e> < / d> < / c> B , B , <c> B , <d> B , <e> B Among them, the relationships between the elements a to e are shown in equation (5).

[0136] Secret sharing of the five-element group by multiple participants< / e> < / d> < / c> Figure 2 The method for generating the example can be found in the following documentation for the specific generation process. Figure 2 The relevant explanations will not be repeated here.

[0137] In step S420, multiple participants each use their own quintuple secret sharing to hide their private data, obtain secret data sharing, and send the secret data sharing to other participants.

[0138] For example, participant A's private data includes <x> A and <y> A Participant B's private data includes <x> B and <y> B .

[0139] When using a quintuple secret sharing method to hide individual private data, methods such as performing pre-defined operations or overlaying the quintuple secret sharing with the private data can be employed. For example, participant A can calculate... <m> A = <x> A - A , <n> A = <y> A - A To enable access to private data <x> A and <y> A The concealment; participant A can calculate <m> B = <x> B -< / x> < / m> < / y> < / x> < / y> < / n> B , <n> B = <y> B - B To enable access to private data <x> B and <y> B The hidden.

[0140] Secret data sharing refers to data that has been hidden and is not considered private data; it can be sent to other participants. Participant A can share secret data. <m> A and <n> A Send to participant B, who can then share the secret data. <m> B and <n> B It is sent to participant A without disclosing private data.

[0141] In step S430, multiple participants, based on their respective quintuple secret sharing and the secret data sharing sent by other participants, determine the secret sharing of the product between the private data of the multiple participants.

[0142] Specifically, during this step, the secret sharing of the product between the private data of multiple participants can be determined by combining the inferred and verified formula. Inference verification can be performed based on the relationships between the elements of the quintuple.

[0143] For example, participant A can calculate m = <m> A - <m> B ,n= <n> A - <n> B ,as well as <z> A =E(D(m)) <e> A +E(D(n)) <d> A +E(D(m))E(D(n))+ <c> A .

[0144] Participant B can calculate m = <m> A - <m> B ,n= <n> A - <n> B ,as well as <z> B =E(D(m)) <e> B +E(D(n)) <d> B +E(D(m))E(D(n))+ <c> B ...

[0145] in, <z> A + <z> B = x * y. x is <x> A and <x> B The reconstructed complete data, y is <y> A and <y> B The complete data after reconstruction.

[0146] In this embodiment, step S410 can generate quintuples more efficiently, thereby reducing the time required for the entire data processing process and improving the overall data processing efficiency.

[0147] In this specification, the terms "first," "first secret sharing," and "first element," as well as the corresponding "second" (if any), are used merely for ease of distinction and description and do not have any limiting meaning.

[0148] The foregoing description describes specific embodiments of this specification; other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than those shown in the embodiments, and the desired result may still be achieved. Furthermore, the processes depicted in the drawings do not necessarily need to follow the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0149] < / y> < / y> < / x> < / x> < / z> < / z> < / c> < / d> < / e> < / z> < / n> < / n> < / m> < / m> < / c> < / d> < / e> < / z> < / n> < / n> < / m> < / m> < / n> < / m> < / n> < / m> < / y> < / x> < / y> < / n> Figure 5 This is a schematic block diagram of a multiplication quintuple generation system provided for an embodiment. The system 500 includes multiple participants, such as participant 510, participant 520, and participant 530. The system 500 and... Figure 2 The method embodiments shown are relative.

[0150] Among multiple participants, a first data interaction based on secure multi-party computation is used to enable each participant to obtain: a triplet of a specified domain space and a first secret sharing within that participant;

[0151] Among multiple participants, through a second data interaction based on secure multi-party computation, for the elements in the triple, based on a first secret share held by each party, the elements are sampled from multiple equivalence classes in the specified domain space, such that each participant obtains: the second secret share of the remaining elements in the quintuple to be generated in that participant; the second secret share and the first secret share constitute the secret share of the quintuple to be generated.

[0152] In one implementation, the first data interaction includes: multiple participants generating their own k Boolean secret sharing triples through a first sub-data interaction based on secure multi-party computation; and multiple participants packaging and encoding their own k Boolean secret sharing triples in the designated domain space through a second sub-data interaction based on secure multi-party computation, so that each participant obtains its corresponding first secret share.

[0153] In one implementation, any Boolean secret sharing triple includes a Boolean secret sharing of three elements. The second sub-data interaction includes: any participating party, for any one of the three elements, constructing a Boolean secret sharing of the vector corresponding to that element from k Boolean secret sharings of that element; multiple participating parties, through a second sub-data interaction based on secure multi-party computation, package and encode the Boolean secret sharing of the vectors corresponding to the three elements held by each party in the designated domain space, so that each participating party obtains a first secret sharing corresponding to each of the three elements.

[0154] In one implementation, the designated domain space is a space containing multiple m-bit binary domain elements, and the encoding includes operations based on the multiplication-friendly encoding RMFE.

[0155] In one implementation, the second data interaction includes: multiple participants engaging in a second data interaction based on secure multi-party computation, each sampling from multiple preimages of the vectors corresponding to the elements held by each party, based on a secret sharing of the vectors, such that each participant obtains a new secret sharing, which serves as the second secret sharing of the remaining elements. The secret sharing of the vectors can be obtained by decoding the first secret sharing of the elements.

[0156] In one implementation, the triplet includes a first element, a second element, and a third element, wherein the third element is equal to the product of the first element and the second element. The second data interaction includes: sampling from the first element across multiple equivalence classes in the specified domain space to obtain the secret shares corresponding to the fourth element of the to-be-generated quintuple among multiple participating parties, serving as the second secret share of the fourth element; and sampling from the second element across multiple equivalence classes in the specified domain space to obtain the secret shares corresponding to the fifth element of the to-be-generated quintuple among multiple participating parties, serving as the second secret share of the fifth element.

[0157] Figure 6 This is a schematic block diagram of a data processing system provided for an embodiment. The system 600 includes multiple participants, such as participant 610, participant 620, and participant 630. The system 600 and... Figure 4 The method embodiments shown are relative.

[0158] Multiple participants are involved in obtaining the quintuple secret sharing of the multiplication quintuple. The quintuple secret sharing is achieved through… Figure 2 The method of the illustrated embodiment generates the data;

[0159] Multiple participants use their respective quintuple secret sharing to hide their private data, obtain secret data sharing, and send it to other participants;

[0160] Multiple parties are involved in determining the secret sharing of the product between their private data based on their respective quintuple secret sharing and the secret data sharing sent by other parties.

[0161] The above system embodiments correspond to the method embodiments, and detailed descriptions can be found in the method embodiment section, which will not be repeated here. The system embodiments and their corresponding method embodiments have the same technical effects, and detailed descriptions can be found in the corresponding method embodiments.

[0162] Figure 7 This is a schematic block diagram of a device for generating a multiplication quintuple, provided as an embodiment. This device embodiment is related to... Figure 2 The method embodiment shown corresponds to this. The device 700 is deployed in any of the participating parties, including:

[0163] The triplet determination module 710 is configured to enable multiple participants to obtain, respectively, the first secret sharing of triples in a specified domain space within that participant through a first data interaction based on secure multi-party computation with other participants.

[0164] The quintuple determination module 720 is configured to, through a second data interaction based on secure multi-party computation with the participating parties, sample the elements in the triple from multiple equivalence classes in the specified domain space based on the first secret sharing held by each party, so that the multiple participating parties respectively obtain: the second secret sharing of the remaining elements in the quintuple to be generated in that participating party; the second secret sharing and the first secret sharing constitute the secret sharing of the quintuple to be generated.

[0165] In one implementation, the triplet determination module 710 includes:

[0166] The first interaction submodule 711 is configured to generate k Boolean secret sharing triples respectively among multiple participants through the first sub-data interaction based on secure multi-party computation;

[0167] The second interaction submodule 712 is configured to package and encode the k Boolean secret sharing triples owned by each party in the specified domain space through a second sub-data interaction based on secure multi-party computation, so that the multiple parties can obtain the corresponding first secret sharing.

[0168] In one implementation, any Boolean secret sharing triple includes a Boolean secret sharing of three elements. The second interaction submodule 712 is specifically configured as follows: any participating party, for any one of the three elements, constructs a Boolean secret sharing of the vector corresponding to that element from k Boolean secret sharings of that element; multiple participating parties, through a second sub-data interaction based on secure multi-party computation, package and encode the Boolean secret sharing of the vectors corresponding to the three elements held by each party in the designated domain space, so that each participating party obtains a first secret sharing corresponding to each of the three elements.

[0169] In one implementation, the designated domain space is a space containing multiple m-bit binary domain elements, and the encoding includes operations based on the multiplication-friendly encoding RMFE.

[0170] In one implementation, the quintuple determination module 720 is specifically configured as follows: multiple participants engage in a second data interaction based on secure multi-party computation, and each participant samples from multiple preimages of the vectors corresponding to the elements in the specified domain space based on the secret sharing of the vectors held by each party, thereby obtaining new secret sharing for each participant. This new secret sharing serves as the second secret sharing for the remaining elements. The secret sharing of the vectors can be obtained by decoding the first secret sharing of the elements.

[0171] In one implementation, the triplet includes a first element, a second element, and a third element, where the third element is equal to the product of the first and second elements. The quintet determination module 720 is specifically configured to: sample from multiple equivalence classes of the first element in the specified domain space to obtain the secret shares corresponding to the fourth element in the quintet to be generated among multiple participating parties, which serve as the second secret share of the fourth element; and sample from multiple equivalence classes of the second element in the specified domain space to obtain the secret shares corresponding to the fifth element in the quintet to be generated among multiple participating parties, which serve as the second secret share of the fifth element.

[0172] The above-described apparatus embodiments correspond to the method embodiments, and detailed descriptions can be found in the description of the method embodiments section, which will not be repeated here. The apparatus embodiments are derived based on the corresponding method embodiments and have the same technical effects as the corresponding method embodiments; detailed descriptions can be found in the corresponding method embodiments.

[0173] This specification also provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform... Figures 1 to 4 Any one of the methods described.

[0174] This specification also provides a computing device, including a memory and a processor, wherein the memory stores executable code, and the processor executes the executable code to implement... Figures 1 to 4 Any one of the methods described.

[0175] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for storage media and computing devices are basically similar to the method embodiments, so they are described more simply; relevant parts can be referred to the descriptions of the method embodiments.

[0176] Those skilled in the art will recognize that the functions described in the embodiments of the present invention in one or more of the above examples can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.

[0177] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, or improvements made based on the technical solutions of the present invention should be included within the scope of protection of the present invention. < / x> < / m> < / y> < / x> < / y> < / x> < / e> < / x>

Claims

1. A method for generating a multiplication quintuple, executed by multiple participants, including: Through a first data interaction based on secure multi-party computation, multiple participants obtain, respectively, the first secret sharing of a triple in a specified domain space within that participant. Multiple participants engage in a second data interaction based on secure multi-party computation. For the elements in the triplet, based on the first secret sharing held by each party, the elements are sampled from multiple equivalence classes in the specified domain space, so that each participant obtains: the second secret sharing of the remaining elements in the quintuple to be generated in that participant; the second secret sharing and the first secret sharing constitute the secret sharing of the quintuple to be generated.

2. The method according to claim 1, wherein the first data interaction includes: Multiple participants generate their own k Boolean secret-sharing triples through first sub-data interaction based on secure multi-party computation; Multiple participants exchange second sub-data based on secure multi-party computation to package and encode the k Boolean secret sharing triples owned by each party in the designated domain space, so that each participant obtains the corresponding first secret sharing.

3. The method according to claim 2, wherein any Boolean secret sharing triple comprises a Boolean secret sharing of three elements; the second sub-data interaction comprises: For any one of the three elements, each participant shares the k Boolean secrets of that element to form the Boolean secret sharing of the vector corresponding to that element. Multiple participants exchange second sub-data based on secure multi-party computation, packaging and encoding the Boolean secrets of the vectors corresponding to the three elements owned by each party in the designated domain space, so that each participant obtains the first secret sharing corresponding to the three elements respectively.

4. The method according to claim 3, wherein the designated field space is a space containing a plurality of m-bit binary field elements, and the encoding includes operations based on multiplication-friendly encoding RMFE.

5. The method according to claim 1, wherein the second data interaction comprises: Multiple participants interact through a second data exchange based on secure multi-party computation. Based on the secret sharing of the vectors corresponding to the elements owned by each party, the vectors are sampled from multiple preimages in the specified domain space, so that each participant obtains a new secret sharing. The new secret sharing serves as the second secret sharing of the remaining elements. The secret share of the vector can be obtained by decoding the first secret share of the element.

6. The method according to claim 1, wherein the triplet comprises a first element, a second element, and a third element, the third element being equal to the product of the first element and the second element; the step of sampling the element from multiple equivalence classes in the specified domain space comprises: Sample the first element from multiple equivalence classes in the specified domain space to obtain the secret sharing of the fourth element in the five-tuple to be generated in multiple participating parties, which serves as the second secret sharing of the fourth element. The second element is sampled from multiple equivalence classes in the specified domain space to obtain the secret sharing of the fifth element in the five-tuple to be generated in multiple participating parties, which serves as the second secret sharing of the fifth element.

7. A privacy-preserving data processing method, performed by multiple parties, comprising: Multiple participants each obtain a quintuple secret share of the multiplication quintuple; the quintuple secret share is generated by the method described in claim 1. Multiple participants each use their own five-tuple secret sharing to hide their private data, obtain secret data sharing, and send it to other participants; Multiple participants, based on their respective five-tuple secret sharing and the secret data sharing sent by other participants, determine the secret sharing of the product between the private data of the multiple participants.

8. A method for generating a multiplication quintuple, executed by any one of the participants, comprising: Through the first data interaction based on secure multi-party computation with other participants, each participant obtains: the first secret sharing of the triple in the specified domain space within that participant; Through a second data interaction based on secure multi-party computation between the participants, for the elements in the triplet, based on the first secret sharing held by each party, the elements are sampled from multiple equivalence classes in the specified domain space, so that the multiple participants respectively obtain: the second secret sharing of the remaining elements in the quintuple to be generated in the participant's second secret sharing; the second secret sharing and the first secret sharing constitute the secret sharing of the quintuple to be generated.

9. A system for generating multiplicative quintuples, the system comprising multiple participants; Among multiple participants, a first data interaction based on secure multi-party computation is used to enable each participant to obtain: a triplet of a specified domain space and a first secret sharing within that participant; Among multiple participants, through a second data interaction based on secure multi-party computation, for the elements in the triple, based on a first secret share held by each party, the elements are sampled from multiple equivalence classes in the specified domain space, such that each participant obtains: the second secret share of the remaining elements in the quintuple to be generated in that participant; the second secret share and the first secret share constitute the secret share of the quintuple to be generated.

10. A privacy-protecting data processing system, the system comprising multiple parties; Multiple participants are involved in obtaining the quintuple secret share of the multiplication quintuple; the quintuple secret share is generated by the method described in claim 1. Multiple participants use their respective quintuple secret sharing to hide their private data, obtain secret data sharing, and send it to other participants; Multiple parties are involved in determining the secret sharing of the product between their private data based on their respective quintuple secret sharing and the secret data sharing sent by other parties.

11. A device for generating quintuples of multiplication, deployed in any participating party, comprising: The triplet determination module is configured to enable multiple participants to obtain, through a first data interaction based on secure multi-party computation with other participants, the first secret sharing of triples in a specified domain space within that participant. The quintuple determination module is configured to, through a second data interaction based on secure multi-party computation with the participating parties, sample the elements in the triple from multiple equivalence classes in the specified domain space based on the first secret sharing held by each party, so that the multiple participating parties respectively obtain: the second secret sharing of the remaining elements in the quintuple to be generated in that participating party; the second secret sharing and the first secret sharing constitute the secret sharing of the quintuple to be generated.

12. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of any one of claims 1-8.

13. A computing device comprising a memory and a processor, wherein the memory stores executable code, and the processor, when executing the executable code, implements the method of any one of claims 1-8.