Secure computation methods, media, devices, and software products based on homomorphic encryption

By performing number-theoretic transformations and homomorphic encryption on the second column vector in ring A, the problem of the modular prime number ring limitation in the prior art is solved, enabling secure computation on any modular number ring, improving computational efficiency and data protection capabilities, and enhancing the applicability and stability of the model.

CN119921942BActive Publication Date: 2025-10-31BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510112317.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-10-31
Estimated Expiration
2045-01-23

AI Technical Summary

Technical Problem

Existing homomorphic encryption mechanisms based on number theory transformation coding are only applicable to secure computation of matrix and vector products on the modular prime number ring, which has a limited scope of application and high computational complexity.

Method used

The method involves performing number theory transformations on the second column vector in ring A to generate N polynomials, and then generating ciphertext polynomials through homomorphic encryption. It utilizes the properties of operator rings for secure computation, and is applicable to matrix-vector multiplication on rings with arbitrary moduli, while reducing the computational complexity of the encoding.

Benefits of technology

It enables secure computation on any modular digital ring, improves the execution efficiency of data processing tasks, protects data security in model training scenarios, and enhances the applicability and stability of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119921942B_ABST
    Figure CN119921942B_ABST
Patent Text Reader

Abstract

A secure computation method, medium, device, and program product based on homomorphic encryption. The secure computation method is used for collaborative computation between a first participant and a second participant to compute the product of a first matrix and a first column vector. The method applied to the first participant includes: performing number-theoretic transformations on the second column vector over a ring A to obtain N polynomials, where the second column vector is (1, x, ..., x^2). N‑1 The first ciphertext polynomial is transposed by the product of the first matrix and the first column vector. In response to receiving the first ciphertext polynomial from the second participant, a second ciphertext polynomial is generated based on N polynomials and the first ciphertext polynomial. A first data processing task is then performed based on the second ciphertext polynomial. This allows for secure computation of the product of the first matrix and the first column vector by utilizing the properties of operator rings, making this scheme applicable to secure computation of matrix-vector products on rings of arbitrary moduli. Furthermore, this scheme can protect data security and improve applicability in model training scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of secure multi-party computation, and more specifically, to a secure computation method, medium, device, and program product based on homomorphic encryption. Background Technology

[0002] Secure multi-party computation (MPC), also known as secure multi-party computation, allows multiple parties to collaboratively compute the result of a function without disclosing the input data of each party. The result is then made public to one or more of the participating parties. Typical applications of secure MPC include joint statistical analysis of privacy-preserving multi-party data and machine learning. In particular, secure MPC techniques can be used to protect privacy data during the training phase of machine learning models, primarily involving the protection of model parameters and the protection of data from each participating party during training.

[0003] In machine learning model training, model loss is typically used to update model parameters. The calculation of model loss usually involves the secure computation of the product of a matrix and its column vectors. Currently, homomorphic encryption mechanisms based on Number Theoretic Transform (NTT) encoding are commonly used for secure computation of this product. However, since NTT encoding transforms a polynomial into the coefficient representation of another polynomial on the modular prime ring, and relies on specific properties of modular prime numbers, homomorphic encryption mechanisms based on NTT encoding are only suitable for secure computation of the product of a matrix and its vectors on the modular prime ring, thus limiting their applicability. Summary of the Invention

[0004] This summary section is provided to briefly introduce the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] In a first aspect, this disclosure provides a secure computation method based on homomorphic encryption. The secure computation method is used for a first participant and a second participant to collaboratively compute the product of an N*N first matrix and an N-dimensional first column vector. The first matrix is ​​held solely by the first participant, and the first column vector is held solely by the second participant. The method is applied to the first participant and includes:

[0006] Performing number-theoretic transformations on the second column vector over ring A yields N polynomials, where the second column vector is (1, x, ..., x). N-1 The transpose of the product of the first matrix and the first matrix, where the independent variable x is a 2N-degree primitive root of unity in the ring A. R is any commutative ring containing 1, and N is a power of 2;

[0007] In response to receiving the first ciphertext polynomial sent by the second participant, a second ciphertext polynomial is generated based on the N polynomials and the first ciphertext polynomial, wherein the first ciphertext polynomial is obtained by the second participant homomorphically encrypting the first plaintext polynomial, and the first plaintext polynomial uses the first column vector as the coefficient vector.

[0008] The first data processing task is performed based on the second ciphertext polynomial.

[0009] In a second aspect, this disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the secure computation method based on homomorphic encryption provided in the first aspect of this disclosure.

[0010] Thirdly, this disclosure provides an electronic device, including:

[0011] A storage device on which computer programs are stored;

[0012] A processing device is configured to execute the computer program in the storage device to implement the steps of the secure computation method based on homomorphic encryption provided in the first aspect of this disclosure.

[0013] Fourthly, this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the secure computation method based on homomorphic encryption provided in the first aspect of this disclosure.

[0014] In the above technical solution, when calculating the product of the first matrix and the first column vector, the first participant first performs a number-theoretic transformation on the second column vector on ring A to obtain N polynomials, where the second column vector is (1, x, ..., x). N-1The transpose of the product of the first matrix and the first column vector is obtained. Simultaneously, the second participant homomorphically encrypts the first plaintext polynomial to obtain the first ciphertext polynomial, which is then sent to the first participant. The first plaintext polynomial uses the first column vector as its coefficient vector. After receiving the first ciphertext polynomial from the second participant, the first participant generates the second ciphertext polynomial based on N polynomials and the first ciphertext polynomial, and performs the first data processing task based on the second ciphertext polynomial. This utilizes the properties of operator rings to securely compute the product of the first matrix and the first column vector, thus avoiding the problem that secure computation methods for matrix-vector products using number-theoretic transformations are only applicable to rings with modulo prime numbers. Therefore, this scheme is applicable to secure computation of matrix-vector products on rings with any modulus. Furthermore, performing a number-theoretic transformation on the second column vector on ring A, i.e., encoding the first matrix through number-theoretic transformation, reduces the computational complexity of the encoding, thereby improving the execution efficiency of the first data processing task. Furthermore, this solution can protect data security during model training and enable the trained model to exhibit good performance and stability under different data, tasks, environments, and scenarios, thereby improving the applicability of the model.

[0015] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description

[0016] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale. In the drawings:

[0017] Figure 1 This is a flowchart illustrating a secure computation method based on homomorphic encryption applied to a first participant, according to an exemplary embodiment.

[0018] Figure 2 This is a flowchart illustrating a method for performing number-theoretic transformations on a second column vector over a ring A, according to an exemplary embodiment.

[0019] Figure 3 This is a flowchart illustrating a secure computation method based on homomorphic encryption applied to a second participant, according to an exemplary embodiment.

[0020] Figure 4 This is a block diagram illustrating a secure computing device based on homomorphic encryption applied to a first participant, according to an exemplary embodiment.

[0021] Figure 5This is a block diagram illustrating a secure computing device based on homomorphic encryption applied to a second participant, according to an exemplary embodiment.

[0022] Figure 6 This is a schematic diagram of the structure of an electronic device according to an exemplary embodiment. Detailed Implementation

[0023] Before introducing specific embodiments of this disclosure, the specific application scenarios of multi-party secure computation and the terms involved in this disclosure will be explained.

[0024] A ring is a set that defines two operations: addition and multiplication. It forms an abelian group for addition and a semigroup for multiplication for all elements except zero. Multiplication satisfies the distributive property of addition.

[0025] In the field of secure computing, particularly in multi-party computation (MPC), an operator ring typically refers to a set of operators that support secure computation between multiple parties. These operators can include basic arithmetic operations (such as addition and multiplication), logical operations, comparison operations, etc., and they form the basis for building more complex secure computing protocols.

[0026] The ring consisting of addition and multiplication is defined above. It is an integer ring. Addition is defined as integer addition modulo N, and multiplication is defined as integer multiplication modulo N, where N is an integer greater than 1.

[0027] It is a ring consisting of equivalence classes obtained by taking the modulo of integers with respect to 2N, namely {0, 1, 2, ..., 2N-1}.

[0028] It is a modulo 2N multiplicative group. The set of all elements coprime to 2N, i.e., these elements have multiplicative inverses modulo 2N, i.e., {1, 3, ..., 2N-1}.

[0029] Secret sharing, also known as secret partitioning or secret sharing, works by dividing a secret (such as a key or private data) into multiple shares, each held by a different data holder. The secret can only be recovered when more than a certain number of parties merge their shares; shares obtained from fewer than the threshold cannot recover any information from the secret. In multi-party secure computation, the threshold number is usually the same as the number of participating parties, and the shares into which the secret is divided can be called fragments. The private data refers to the data that the parties do not want to know in a multi-party secure computation.

[0030] Homomorphic encryption is a technique that allows computation on encrypted data (i.e., ciphertext) and then decryption to obtain the result. The result of homomorphic encryption is the same as the result of direct computation on the original data (i.e., plaintext), but the entire computation process is performed on the encrypted data.

[0031] NTT (Nearest Fourier Transform) is a method in number theory for efficiently computing convolutions, similar to the Discrete Fourier Transform (DFT). NTT primarily operates on finite fields, avoiding the precision issues associated with floating-point operations in the DFT, and is widely used in digital signal processing and cryptography. Like the Fast Fourier Transform (FFT), NTT achieves fast computation through a divide-and-conquer strategy. Specifically, the sequence to be transformed is divided into "even parts" and "odd parts," and the transform is recursively applied until the length of the sequence to be transformed is 1, at which point the results are combined.

[0032] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0033] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0034] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0035] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0036] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0037] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0038] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.

[0039] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.

[0040] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0041] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0042] Meanwhile, it is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0043] Figure 1 This is a flowchart illustrating a secure computation method based on homomorphic encryption applied to a first participant, according to an exemplary embodiment. Figure 1 As shown, the method may include S101 to S103.

[0044] In S101, a number-theoretic transformation is performed on the second column vector over ring A to obtain N polynomials, where the second column vector is (1, x, ..., x). N-1 The transpose of the product of the first matrix and the first matrix, where the independent variable x is a primitive root of unity of degree 2N in the ring A.

[0045] In this disclosure, a secure computation method is used by a first participant and a second participant to collaboratively compute the product of an N*N first matrix and an N-dimensional first column vector. It is understood that the first matrix and the first column vector in this disclosure can be any data that the holder does not wish to disclose.

[0046] The first matrix is ​​held solely by the first participant, and the first column vector is held solely by the second participant. Wherein, the first matrix M∈M N,N (R), meaning the first matrix M is an N-dimensional square matrix on the ring R, and the first column vector α∈R. (N) That is, the first column vector is an N-dimensional column vector on the ring R, where R is any commutative ring containing 1s. Ring A is the quotient ring of univariate polynomial rings on ring R, and the ring... N is a power of 2.

[0047] The first matrix is ​​a square matrix. If the matrix used for safe computation was not initially a square matrix, it can be reconstructed into a square matrix by padding with zeros or cutting it.

[0048] The second column vector is (1, x, ..., x). N-1 The transpose of the product of the first matrix M and the second column vector U = (1, x, ..., x) is the second column vector U = (1, x, ..., x) N-1 )·M=(m0(x),m1(x),…,m N-1 (x)) T ,in, n i,j Let m be the element in the i-th row and j-th column of the first matrix M. j (x) is the polynomial in the i-th row of the second column vector U, i = 0, 1, ..., N-1, j = 0, 1, ..., N-1.

[0049] The first participant performs a number-theoretic transformation on the second column vector in ring A to encode the first matrix, resulting in N polynomials. The number-theoretic transformation NTT, like the Fast Fourier Transform, can be rapidly computed using a divide-and-conquer strategy, specifically achieving O(N^2) computation time. 2 Encoding the first matrix efficiently with a time complexity of logN.

[0050] In S102, in response to receiving the first ciphertext polynomial sent by the second participant, a second ciphertext polynomial is generated based on N polynomials and the first ciphertext polynomial.

[0051] In this disclosure, the first ciphertext polynomial is obtained by the second participant through homomorphic encryption of the first plaintext polynomial. The first plaintext polynomial uses the first column vector as the coefficient vector, that is, the first column vector is the coefficient vector of the first plaintext polynomial corresponding to the first ciphertext polynomial.

[0052] Specifically, when calculating the product of the first matrix and the first column vector, the first participant performs a number theory transformation on the second column vector on ring A to encode the first matrix, obtaining N polynomials. Simultaneously, the second participant uses its own first column vector as the coefficient vector to generate a first plaintext polynomial. Then, the second participant uses a homomorphic encryption public key to homomorphically encrypt the first plaintext polynomial and sends the homomorphically encrypted first ciphertext polynomial to the first participant. After receiving the first ciphertext polynomial, the first participant generates a second ciphertext polynomial based on the N polynomials encoded from the first matrix and the first ciphertext polynomial.

[0053] The second participant can use its first column vector as the coefficient vector to generate the first plaintext polynomial m1 through the following equation (1):

[0054] m1=(1,x,...,x N-1 )α (1)

[0055] In S103, the first data processing task is performed based on the second ciphertext polynomial.

[0056] In one implementation, the first data processing task can be performed based on the second ciphertext polynomial through the following steps (c1) and (c2).

[0057] Step (c1): Generate an N-dimensional random column vector, use the random column vector to mask the second ciphertext polynomial to obtain a masked polynomial, and send the masked polynomial to the second participant so that the second participant can generate the first slice of the product of the first matrix and the first column vector based on the masked polynomial.

[0058] Step (c2): Use the random column vector as the second slice of the first matrix and the first column vector, and perform the first data processing task based on the second slice.

[0059] Wherein, the random column vector β0∈R (N) That is, the random column vector is an N-dimensional column vector on a randomly generated R-ring.

[0060] After generating a random column vector, the first participant can use it as a slice of the product of the first matrix and the first column vector, i.e., the second slice. Simultaneously, the first participant uses the random column vector to mask the second ciphertext polynomial and sends the masked polynomial to the second participant. Upon receiving the masked polynomial, the second participant generates another slice of the product of the first matrix and the first column vector based on it, i.e., the first slice. Then, the first and second participants can share their respective slices of the product result and merge them to obtain the final calculation result (i.e., the product of the first matrix and the first column vector). The result of the product of the first matrix and the first column vector includes the first slice and the second slice, i.e., first matrix * first column vector = first slice + second slice.

[0061] Furthermore, the aforementioned first data processing task can be a machine learning model training task, where the machine learning model can be, for example, a neural network model, a logistic regression model, etc. The first participant can train the machine learning model using MPC based on its own first matrix, and the second participant can train it based on its own first column vector, to obtain a slice of the product of the first matrix and the first column vector, respectively. Then, based on the slices of the product held by each participant, the model loss is calculated, and the model parameters of the machine learning model are updated according to the model loss. Here, the first matrix can be a feature matrix, and the first column vector can be a vector composed of model parameters.

[0062] In the above technical solution, when calculating the product of the first matrix and the first column vector, the first participant first performs a number-theoretic transformation on the second column vector on ring A to obtain N polynomials, where the second column vector is (1, x, ..., x). N-1The transpose of the product of the first matrix and the first column vector is obtained. Simultaneously, the second participant homomorphically encrypts the first plaintext polynomial to obtain the first ciphertext polynomial, which is then sent to the first participant. The first plaintext polynomial uses the first column vector as its coefficient vector. After receiving the first ciphertext polynomial from the second participant, the first participant generates the second ciphertext polynomial based on N polynomials and the first ciphertext polynomial, and performs the first data processing task based on the second ciphertext polynomial. This utilizes the properties of operator rings to securely compute the product of the first matrix and the first column vector, thus avoiding the problem that secure computation methods for matrix-vector products using number-theoretic transformations are only applicable to rings with modulo prime numbers. Therefore, this scheme is applicable to secure computation of matrix-vector products on rings with any modulus. Furthermore, performing a number-theoretic transformation on the second column vector on ring A, i.e., encoding the first matrix through number-theoretic transformation, reduces the computational complexity of the encoding, thereby improving the execution efficiency of the first data processing task. Furthermore, this solution can protect data security during model training and enable the trained model to exhibit good performance and stability under different data, tasks, environments, and scenarios, thereby improving the applicability of the model.

[0063] The following is a detailed explanation of the specific implementation method for performing number theory transformations on the second column vector on ring A to obtain N polynomials in S101 above. Specifically, it can be achieved through the following steps (a1) to (a4).

[0064] Step (a1): Calculate (1, x, ..., x) N-1 The product of the first matrix and the first matrix is ​​used to obtain the first row vector.

[0065] Step (a2): Transpose the first row vector to obtain the second column vector.

[0066] Step (a3): Use multi-level recursive operations to perform number theory transformation on the second column vector of ring A to obtain the third column vector.

[0067] Step (a4): Determine each row of the third column vector as N polynomials.

[0068] Specifically, multi-level recursive operations can be used, through... Figure 2 The S201 to S207 shown in the diagram implement the number theory transformation of the second column vector on ring A to obtain the third column vector.

[0069] In S201, the second column vector is used as the input data for the l-th level recursive operation.

[0070] In this disclosure, l is initially set to 1.

[0071] In S202, the operation factors of the l-th level recursive operation are calculated.

[0072] In this disclosure, the operand of the l-th level recursive operation is For ring A The fundamental unit root, and The operands of the l-th level recursive operation are A diagonal matrix of dimension 1.

[0073] For example, the operand of the first-level recursive operation is ξ 2N Let ξ be a primitive root of unity of degree 2N in ring A, and ξ 2N =x -1 .

[0074] Wherein, the third column vector V = NTT N (U)=NTT N ·U, NTT N (U) Characterization using NTT N Perform a number-theoretic transformation on U, where NTT N Let be the number-theoretic transformation matrix of the first-order recursive operation, and be NTT. N

[0075]

[0076] In S203, the input data is split into a fourth column vector and a fifth column vector according to the parity of the index. The fourth column vector consists of even rows of the input data, and the fifth column vector consists of odd rows of the input data.

[0077] For example, if l = 1, then the input data is the second column vector U = (m0(x), m1(x), ..., m N-1 (x)) T At this point, the second column vector is split according to the parity of the indices to obtain the fourth column vector U. even =(m0(x),m2(x),m4(x),…,m N-2 (x)) T The fifth column vector U odd =(m1(x),m3(x),m5(x),…,m N-1 (x)) T .

[0078] In S204, based on the factors of the l-th recursive operation and the input data of the l-th recursive operation, two output data of the l-th recursive operation are obtained. The two output data include the sum of the number theory transformation result of the fourth column vector and the first product, and the difference between the number theory transformation result of the fourth column vector and the first product. The first product is the product of the factors of the l-th recursive operation and the number theory transformation result of the fifth column vector.

[0079] In this disclosure, the two output data of the l-th recursive operation include: the number-theoretical transformation result of the fourth column vector + the operation factor of the l-th recursive operation * the number-theoretical transformation result of the fifth column vector, and the number-theoretical transformation result of the fourth column vector - the operation factor of the l-th recursive operation * the number-theoretical transformation result of the fifth column vector. The calculation results of these two output data are respectively the first part of the number-theoretical transformation result of the input data of the l-th recursive operation. The result of the number-theoretical transformation of the input data of the l-th level recursive operation. The number-theoretical transformation of the fourth column vector is equal to the product of the number-theoretical transformation matrix of the (l+1)th level recursive operation and the fourth column vector. The number-theoretical transformation of the fifth column vector is equal to the product of the number-theoretical transformation matrix of the (l+1)th level recursive operation and the fifth column vector.

[0080] For example, if l = 1, then the input data is the second column vector, and the two output data of the first level of recursion include: V up and V down , where V up It is a column vector, specifically the first N / 2 rows of the third column vector, V down Let be a column vector, specifically the last N / 2 rows of the third column vector, and:

[0081]

[0082] Among them, NTT N / 2 This is the number theory transformation matrix for the second-order recursive operation.

[0083] In S205, determine whether the dimension of the fourth or fifth column vector is 1.

[0084] In this disclosure, the dimensions of the fourth column vector and the fifth column vector are the same. It can be determined whether the dimension of the fourth column vector is 1, and also whether the dimension of the fifth column vector is 1. If the dimension of either the fourth or fifth column vector is not 1, then increment l by 1, and use the fourth and fifth column vectors as input data for the l-th level recursive operation. Then, execute S206, and return to S202 above to perform the l-th level recursive operation on the fourth and fifth column vectors respectively. If the dimension of either the fourth or fifth column vector is 1, it indicates that the length of the sequence to be transformed is 1. At this point, the recursive transformation can end, and execute S207.

[0085] In S206, let l be incremented by 1, and use the fourth column vector and the fifth column vector as the input data for the l-th level recursive operation.

[0086] In S207, the output data of each level of recursive operation are merged to obtain the third column vector.

[0087] For example, if N = 4, then first define the second column vector U = (m0(x), m1(x), m2(x), m3(x)). T As the input data for the first-level recursive operation, the operation factor for the first-level recursive operation is: Next, the second column vector U = (m0(x), m1(x), m2(x), m3(x)) T Split into a fourth column vector U based on the parity of the index. even =(m0(x),m2(x)) T and the fifth column vector U odd =(m1(x),m3(x)) T Next, based on the operands of the first level of recursive operation... The input data for the l-th level recursive operation, namely the second column vector, yields the following two output data for the first level recursive operation:

[0088]

[0089] At this point, the dimensions of both the fourth and fifth column vectors are 2. We can increment l by 1, making l equal to 2, and then set the fourth column vector U... even =(m0(x),m2(x)) T The fifth column vector U odd =(m1(x),m3(x)) T These are respectively used as input data for the second-level recursive operation, based on the operation factor diag(ξ) of the second-level recursive operation. N For the fourth column vector U even =(m0(x),m2(x)) T The fifth column vector U odd =(m1(x),m3(x)) T Perform the second level of recursive operations respectively.

[0090] Specifically, when the input data is the fourth column vector U even =(m0(x),m2(x)) T When this happens, the fourth column vector can be split into a new fourth column vector U according to the parity of the index. even-even =(m0(x)) T and the new fifth column vector U even-odd =(m1(x)) T Next, based on the operational factor diag(ξ) of the second-level recursive operation... N The input data for the second-level recursive operation, namely the fourth column vector U. even =(m0(x),m2(x)) T The following two output data V are obtained from the second level of recursive operation.up1 and V down1 :

[0091] V up1 =NTT N / 4 U even-even +diag(ξ N NTT N / 4 U evben-odd (4)

[0092] V down1 =NTT N / 4 U even-even -diag(ξ N NTT N / 4 U even-odd (5)

[0093] Among them, NTT N / 4 This is the number theory transformation matrix for the third level of recursive operations.

[0094] At this point, both the new fourth and fifth column vectors have a dimension of 1, so the iteration can stop. Then, calculate the NTT. N / 4 U even-even NTT N / 4 U even-odd Therefore, diag(ξ) is calculated. N NTT N / 4 U even-odd Substituting these values ​​into equations (4) and (5) above, we obtain V. up1 and V down1 Among them, V up1 For NTT N / 2 U even The first row of the vector (two-dimensional column vector) represented by V down1 NTT N / 2 U even The second row of the vector represents the NTT. N / 2 U even The vector that represents.

[0095] The input data is the fifth column vector U. odd =(m1(x), m3(x)) T At that time, the fifth column vector can be split into a new fourth column vector U according to the parity of the index. odd-even =(m1(x)) T and the new fifth column vector U odd-odd =(m3(x)) T Next, based on the operational factor diag(ξ) of the second-level recursive operation... N The input data for the second-level recursive operation, namely the fifth column vector U. odd=(m1(x), m3(x)) T The following two output data V are obtained from the second level of recursive operation. up2 and V down2 :

[0096] V up2 =TTT N / 4 U odd-even +diag(ξ N NTT N / 4 U odd-odd (6)

[0097] V down2 =TTT N / 4 U odd-even -diag(ξ N TTT N / 4 U odd-odd (7)

[0098] At this point, both the new fourth and fifth column vectors have a dimension of 1, so the iteration can stop. Then, calculate the NTT. N / 4 U odd-even NTT N / 4 U odd-odd Therefore, diag(ξ) is calculated. N NTT N / 4 U odd-odd Then, by substituting into equations (6) and (7) above, we can obtain V. up2 and V down2 Among them, V up2 For NTT N / 2 U odd The first row of the vector (two-dimensional column vector) represented by V down2 NTT N / 2 U odd The second row of the vector represents the NTT. N / 2 U odd The vector that represents.

[0099] Next, you can use NTT N / 2 U even The vector represented by NTT N / 2 U odd Substituting the vector represented into equations (2) and (3) above, we obtain V. up and V down V up V represents the first two rows of the third column vector (a four-dimensional column vector). down The last two rows of the third column vector are used to obtain the third column vector.

[0100] In the above implementation, a total of logN recursive iterations were performed. Each iteration involved N / 2 multiplications of monomials and polynomials over ring A. Here, the monomial refers to the data in the operands, and the polynomial refers to the number-theoretical transformations of the fourth and fifth column vectors. Thus, the computational complexity of encoding the first matrix is ​​O(N^2). 2 logN), where the computational complexity of multiplying a monomial by a polynomial is N.

[0101] The following is a detailed description of the specific implementation method for generating the second ciphertext polynomial based on N polynomials and the first ciphertext polynomial in S102 above. Specifically, it can be achieved through the following steps (b1) and (b2).

[0102] Step (b1): Perform N rotation operations on the first ciphertext polynomial to obtain N third ciphertext polynomials;

[0103] In one implementation, step (b1) may include the following steps:

[0104] Step (b11): Receive the Galois key sent by the second participant, wherein the Galois key is generated by the second participant based on the homomorphic encryption private key.

[0105] In this disclosure, the second participant can generate a Galois key based on the homomorphic encryption private key and send it to the first participant. The Galois key is usually an element in the Galois group and is used to perform rotation transformations on the ciphertext. After receiving the Galois key, the first participant uses the Galois key to perform rotation operations on the corresponding ciphertext polynomial.

[0106] It should be noted that the specific method of generating a Galois key using a homomorphic encryption private key is well known to those skilled in the art, and will not be elaborated upon in this disclosure.

[0107] Step (b12): For each element of the modulo 2N multiplicative group, perform a rotation operation on the first ciphertext polynomial using that element and the Galois key to obtain the third ciphertext polynomial.

[0108] In this disclosure, the modular 2N multiplication group elements in That is, k = 1, 3, ..., 2N-1. The Galois key does not directly affect the transformation formula; its role is to ensure that the first participant can perform transformations on the ciphertext (i.e., the first ciphertext polynomial) so that the plaintext polynomial obtained after subsequent decryption (i.e., a0 + a1x) is... k +…+a N-1 x k(N-1) mod(x N+1)) is equal to the polynomial obtained by performing a k-transformation directly on the first plaintext polynomial m1, that is:

[0109] Dec(sk,σ k (ct))=σ k (m1)=a0+a1x k +…+a N-1 x k(N-1) mod(x N +1)

[0110] Where, σ k (ct) is the (k+1) / 2th ciphertext polynomial among N third ciphertext polynomials; the first ciphertext polynomial ct = Enc(a0 + a1x + ... + a N-1 x N-1 Enc represents encryption, that is, ct is the first plaintext polynomial m1 = a0 + a1x + ... + a N- 1x N-1 The ciphertext; the first column vector is Dec represents decryption, and sk is the homomorphic encryption private key.

[0111] Here, performing the k-transformation means applying k to the power of the first ciphertext polynomial.

[0112] Step (b2): Generate the second ciphertext polynomial based on the N polynomials and the N third ciphertext polynomials.

[0113] For example, the second ciphertext polynomial can be generated from N polynomials and N third ciphertext polynomials using the following equation (8):

[0114]

[0115] Wherein, ct(β) is the second ciphertext polynomial; v k (x) is the (k+1) / 2th polynomial among the N polynomials.

[0116] The following is a detailed explanation of the specific implementation method for masking the second ciphertext polynomial using a random column vector in step (c1) to obtain the masked polynomial. Specifically, this can be achieved through the following steps (c11) to (c13):

[0117] Step (c11): Generate the second plaintext polynomial using a random column vector as the coefficient vector.

[0118] For example, the second plaintext polynomial m2 can be generated using a random column vector as the coefficient vector through the following equation (9):

[0119] m2=(1,x,…,x N-1)β0 (9)

[0120] Where β0 is a random column vector.

[0121] Step (c12): Homomorphically encrypt the second plaintext polynomial to obtain the fourth ciphertext polynomial.

[0122] Step (c13): Determine the difference between the second ciphertext polynomial and the fourth ciphertext polynomial as the masking polynomial, i.e., the masking polynomial ct(β1) = ct(β) - ct(β0), where ct(β0) is the fourth ciphertext polynomial.

[0123] The following explanation addresses the correctness of the above equation, where the first matrix * first column vector = first segment + second segment, i.e., Mα = β = β0 + β1, and β1 is the second segment.

[0124] If β = Mα, where β ∈ R (N) ,but

[0125]

[0126] The above equation (10) can be derived through the following process:

[0127] make

[0128]

[0129] in,

[0130] This is a compound operation, where the transpose of B is B. T This is the number theory transformation matrix NTT of the first-level recursive operation. N ;tr A / R For the mapping from ring A to ring R, tr A / R =1 + σ³ + ... + σ 2N-1 ,σ3,…,σ 2N-1 Let tr be an element in the Galois group, where each element in the Galois group is a mapping from the ring A to itself. A / R Both P and P are operators.

[0131] because And (1,x,…,x) N-1 M = (m0(x), ..., m) N-1 (x)), then we have:

[0132]

[0133] Because the second column vector U = (m0(x),…,m N-1 (x)) TThe third column vector V = NTT N (U)=NTT N U, then:

[0134]

[0135] Therefore, we can conclude that:

[0136] (1,x,…,x N-1 )β=P(1,x,…,x N-1 )α

[0137]

[0138] Among them, U T V is the transpose of the second column vector U. T The transpose of the third column vector, (NTT) N ) T For NTT N transpose; u j The element in the j-th row of the second column vector; u 2j The element in the 2j-th row of the second column vector; u 2j+1 ξ is the element in the (2j+1)th row of the second column vector; N Let ξ be an Nth-degree primitive root of unity in ring A, and ξ N =x -2 .

[0139] Among them, in the above equation (8)

[0140]

[0141] Figure 3 This is a flowchart illustrating a secure computation method based on homomorphic encryption applied to a second participant, according to an exemplary embodiment. Figure 3 As shown, the method may include S301 to S305.

[0142] In S301, the first plaintext polynomial is generated using the first column vector as the coefficient vector.

[0143] In this disclosure, a secure computation method is used for a first participant and a second participant to collaboratively compute the product of an N*N first matrix and an N-dimensional first column vector.

[0144] In S302, the first plaintext polynomial is homomorphically encrypted to obtain the first ciphertext polynomial.

[0145] In S303, the first ciphertext polynomial is sent to the first participant, who then generates a masking polynomial based on the first ciphertext polynomial and the first matrix, and sends the masking polynomial to the second participant.

[0146] In S304, the first slice of the product is generated based on the masking polynomial sent by the first participant.

[0147] In S305, the first data processing task is executed based on the first slice.

[0148] In this disclosure, the aforementioned first data processing task can be a machine learning model training task. The machine learning model can be, for example, a neural network model, a logistic regression model, etc. The first participant can train the machine learning model using MPC based on its own first matrix, and the second participant can train it based on its own first column vector, to obtain a slice of the product of the first matrix and the first column vector, respectively. Then, based on the slices of the product held by each participant, the model loss is calculated, and the model parameters of the machine learning model are updated according to the model loss. The first matrix can be a feature matrix, and the first column vector can be a vector composed of model parameters.

[0149] The following is a detailed description of the specific implementation scheme for the first fragment of the product generated based on the masked polynomial sent by the first participant in S304 above. Specifically, it can be achieved through the following steps (d1) and (d2):

[0150] Step (d1): Homomorphically decrypt the masking polynomial to obtain the third plaintext polynomial.

[0151] Step (d2): Determine the coefficient vector of the third plaintext polynomial as the first slice.

[0152] After receiving the masking polynomial sent by the first participant, the second participant uses its local homomorphic encryption private key to homomorphically decrypt the masking polynomial to obtain the third plaintext polynomial. Then, the coefficient vector (column vector) of the third plaintext polynomial is determined as the first slice of the product of the first matrix and the first column vector.

[0153] In one possible implementation, the above-described secure computation method based on homomorphic encryption applied to the second participant may further include:

[0154] Generate a Galois key based on a homomorphic encryption private key;

[0155] Send the Galois key to the first participant.

[0156] The specific implementation of each step in the secure computation method based on homomorphic encryption applied to the second participant according to the embodiments of this disclosure has been described in detail in the secure computation method based on homomorphic encryption applied to the first participant according to the embodiments of this disclosure, and will not be repeated here.

[0157] Figure 4 This is a block diagram illustrating a secure computing device based on homomorphic encryption applied to a first participant, according to an exemplary embodiment. The secure computing method is used for the first and second participants to collaboratively compute the product of an N*N first matrix and an N-dimensional first column vector. The first matrix is ​​held solely by the first participant, and the first column vector is held solely by the second participant. The method is applied to the first participant. Figure 4 As shown, the secure computing device 400 based on homomorphic encryption applied to the first participant includes:

[0158] Number theory transformation module 401 is used to perform number theory transformations on the second column vector over the ring A to obtain N polynomials, where the second column vector is (1, x, ..., x). N-1 The transpose of the product of the first matrix and the first matrix, where the independent variable x is a 2N-degree primitive root of unity in the ring A. R is any commutative ring containing 1, and N is a power of 2;

[0159] The first generation module 402 is configured to, in response to receiving a first ciphertext polynomial sent by the second participant, generate a second ciphertext polynomial based on the N polynomials and the first ciphertext polynomial, wherein the first ciphertext polynomial is obtained by the second participant homomorphically encrypting the first plaintext polynomial, and the first plaintext polynomial uses the first column vector as the coefficient vector.

[0160] The first task execution module 403 is used to execute the first data processing task based on the second ciphertext polynomial.

[0161] In the above technical solution, when calculating the product of the first matrix and the first column vector, the first participant first performs a number-theoretic transformation on the second column vector on ring A to obtain N polynomials, where the second column vector is (1, x, ..., x). N-1The transpose of the product of the first matrix and the first column vector is obtained. Simultaneously, the second participant homomorphically encrypts the first plaintext polynomial to obtain the first ciphertext polynomial, which is then sent to the first participant. The first plaintext polynomial uses the first column vector as its coefficient vector. After receiving the first ciphertext polynomial from the second participant, the first participant generates the second ciphertext polynomial based on N polynomials and the first ciphertext polynomial, and performs the first data processing task based on the second ciphertext polynomial. This utilizes the properties of operator rings to securely compute the product of the first matrix and the first column vector, thus avoiding the problem that secure computation methods for matrix-vector products using number-theoretic transformations are only applicable to rings with modulo prime numbers. Therefore, this scheme is applicable to secure computation of matrix-vector products on rings with any modulus. Furthermore, performing a number-theoretic transformation on the second column vector on ring A, i.e., encoding the first matrix through number-theoretic transformation, reduces the computational complexity of the encoding, thereby improving the execution efficiency of the first data processing task. Furthermore, this solution can protect data security during model training and enable the trained model to exhibit good performance and stability under different data, tasks, environments, and scenarios, thereby improving the applicability of the model.

[0162] In the above technical solution, when calculating the product of the first matrix and the first column vector, the first participant first performs a number-theoretic transformation on the second column vector on ring A to obtain N polynomials, where the second column vector is (1, x, ..., x). N-1 The transpose of the product of the first matrix and the first column vector is obtained. Simultaneously, the second participant homomorphically encrypts the first plaintext polynomial to obtain the first ciphertext polynomial, which is then sent to the first participant. The first plaintext polynomial uses the first column vector as its coefficient vector. After receiving the first ciphertext polynomial from the second participant, the first participant generates the second ciphertext polynomial based on N polynomials and the first ciphertext polynomial, and performs the first data processing task based on the second ciphertext polynomial. This utilizes the properties of operator rings to securely compute the product of the first matrix and the first column vector, thus avoiding the problem that secure computation methods for matrix-vector products using number-theoretic transformations are only applicable to rings with modulo prime numbers. Therefore, this scheme is applicable to secure computation of matrix-vector products on rings with any modulus. Furthermore, performing a number-theoretic transformation on the second column vector on ring A, i.e., encoding the first matrix through number-theoretic transformation, reduces the computational complexity of the encoding, thereby improving the execution efficiency of the first data processing task. Furthermore, this solution can protect data security during model training and enable the trained model to exhibit good performance and stability under different data, tasks, environments, and scenarios, thereby improving the applicability of the model.

[0163] Optionally, the number theory transformation module 401 includes:

[0164] The first calculation submodule is used to calculate (1, x, ..., x). N-1 The product of the first matrix and the first row vector is obtained.

[0165] The transpose submodule is used to transpose the first row vector to obtain the second column vector.

[0166] The number theory transformation submodule is used to implement the number theory transformation of the second column vector on ring A using multi-level recursive operations to obtain the third column vector;

[0167] The first determining submodule is used to determine each row of the third column vector as the N polynomials.

[0168] Optionally, the number theory transformation submodule includes:

[0169] The second determining submodule is used to take the second column vector as the input data for the l-th level recursive operation, where l is initially 1;

[0170] The second calculation submodule is used to calculate the operation factor of the l-th level recursive operation, wherein the operation factor of the l-th level recursive operation is: For ring A The fundamental unit root, and

[0171] The splitting submodule is used to split the input data into a fourth column vector and a fifth column vector according to the parity of the index, wherein the fourth column vector consists of the even rows of the input data, and the fifth column vector consists of the odd rows of the input data;

[0172] The recursive operation submodule is used to obtain two output data of the l-th level recursive operation based on the operation factor of the l-th level recursive operation and the input data of the l-th level recursive operation. The two output data include the sum of the number theory transformation result of the fourth column vector and the first product, and the difference between the number theory transformation result of the fourth column vector and the first product. The first product is the product of the operation factor of the l-th level recursive operation and the number theory transformation result of the fifth column vector.

[0173] The third determining submodule is used to determine whether the dimension of the fourth column vector or the fifth column vector is 1; the first triggering submodule is used to, if the dimension of the fourth column vector or the fifth column vector is not 1, trigger the third triggering submodule to increment 1, and use the fourth column vector and the fifth column vector as input data for the l-th level recursive operation, trigger the second calculation submodule to calculate the operation factor of the l-th level recursive operation, so as to perform the l-th level recursive operation on the fourth column vector and the fifth column vector respectively; the second triggering submodule is used to, if the dimension of the fourth column vector or the fifth column vector is 1, trigger the merging submodule to merge the output data of each level of recursive operation to obtain the third column vector.

[0174] The third triggering submodule is used to increment l by 1 and use the fourth column vector and the fifth column vector as input data for the l-th level recursive operation, respectively, to trigger the second calculation submodule to calculate the operation factor of the l-th level recursive operation, so as to perform the l-th level recursive operation on the fourth column vector and the fifth column vector respectively.

[0175] The merging submodule merges the output data of each level of recursive operation to obtain the third column vector.

[0176] Optionally, the first task execution module 403 includes:

[0177] The first generation submodule is used to generate an N-dimensional random column vector, use the random column vector to mask the second ciphertext polynomial to obtain a masked polynomial, and send the masked polynomial to the second participant so that the second participant can generate the first slice of the product based on the masked polynomial.

[0178] The fourth determining submodule is used to take the random column vector as the second slice of the product and perform the first data processing task based on the second slice.

[0179] Optionally, the first generation submodule includes:

[0180] The second generation submodule is used to generate a second plaintext polynomial using the random column vector as the coefficient vector;

[0181] The first homomorphic encryption submodule is used to homomorphically encrypt the second plaintext polynomial to obtain the fourth ciphertext polynomial.

[0182] The fifth determining submodule is used to determine the difference between the second ciphertext polynomial and the fourth ciphertext polynomial as the masking polynomial.

[0183] Optionally, the first generation module 402 includes:

[0184] The first rotation submodule is used to perform N rotation operations on the first ciphertext polynomial to obtain N third ciphertext polynomials;

[0185] The third generation submodule is used to generate the second ciphertext polynomial based on the N polynomials and the N third ciphertext polynomials.

[0186] Optionally, the first rotating submodule includes:

[0187] The receiving submodule is used to receive the Galois key sent by the second participant, wherein the Galois key is generated by the second participant based on the homomorphic encryption private key;

[0188] The second rotation submodule is used to perform a rotation operation on the first ciphertext polynomial for each element of the modulo 2N multiplication group, using that element and the Galois key, to obtain the third ciphertext polynomial.

[0189] Optionally, the third generation submodule is used to generate a second ciphertext polynomial based on the N polynomials and the N third ciphertext polynomials using the following formula:

[0190]

[0191] Where ct(β) is the second ciphertext polynomial; v k (x) is the (k+1) / 2th polynomial among the N polynomials. It is an integer ring; σ k (ct) is the (k+1) / 2th ciphertext polynomial among the N third ciphertext polynomials.

[0192] Optionally, the first data processing task is a machine learning model training task.

[0193] Figure 5 This is a block diagram illustrating a secure computing device based on homomorphic encryption applied to a second participant, according to an exemplary embodiment. The secure computing method is used for the first and second participants to collaboratively compute the product of an N*N first matrix and an N-dimensional first column vector, where the first matrix is ​​held solely by the first participant, and the first column vector is held solely by the second participant. Figure 5 As shown, the secure computing device 500 based on homomorphic encryption applied to the second participant includes:

[0194] The second generation module 501 is used to generate a first plaintext polynomial using the first column vector as the coefficient vector;

[0195] Encryption module 502 is used to perform homomorphic encryption on the first plaintext polynomial to obtain the first ciphertext polynomial;

[0196] The sending module 503 is used to send the first ciphertext polynomial to the first participant, so that the first participant can generate a masking polynomial based on the first ciphertext polynomial and the first matrix, and send the masking polynomial to the second participant;

[0197] The third generation module 504 is used to generate the first fragment of the product based on the masking polynomial sent by the first participant.

[0198] The second task execution module 505 is used to execute the first data processing task based on the first slice.

[0199] Optionally, the third generation module 504 includes:

[0200] The decryption submodule is used to perform homomorphic decryption on the masking polynomial to obtain the third plaintext polynomial;

[0201] The sixth determining submodule is used to determine the coefficient vector of the third plaintext polynomial as the first slice.

[0202] Optionally, the secure computing device 500 based on homomorphic encryption applied to the second participant further includes:

[0203] The fourth generation module is used to generate a Galois key based on a homomorphic encryption private key;

[0204] The sending module 503 is also used to send the Galois key to the first participant.

[0205] Optionally, the first data processing task is a machine learning model training task.

[0206] The following is for reference. Figure 6 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 600 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0207] like Figure 6As shown, electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 601, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 602 or a program loaded from storage device 608 into random access memory (RAM) 603. RAM 603 also stores various programs and data required for the operation of electronic device 600. Processing device 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.

[0208] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 608 including, for example, magnetic tapes, hard disks, etc.; and communication devices 609. Communication device 609 allows electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 6 An electronic device 600 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0209] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a storage device 608, or installed from a ROM 602. When the computer program is executed by the processing device 601, it performs the functions defined in the methods of embodiments of this disclosure.

[0210] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0211] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0212] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0213] The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: perform number-theoretic transformations on the second column vector over ring A to obtain N polynomials, wherein the second column vector is (1, x, ..., x...).N-1 The transpose of the product of the first matrix and the first matrix, where the independent variable x is a 2N-degree primitive root of unity in the ring A. R is any commutative ring containing 1, and N is a power of 2. The secure computation method is used for the first participant and the second participant to collaboratively compute the product of an N*N first matrix and an N-dimensional first column vector. The first matrix is ​​held solely by the first participant, and the first column vector is held solely by the second participant. In response to receiving a first ciphertext polynomial sent by the second participant, a second ciphertext polynomial is generated based on the N polynomials and the first ciphertext polynomial. The first ciphertext polynomial is obtained by the second participant through homomorphic encryption of the first plaintext polynomial, and the first plaintext polynomial uses the first column vector as its coefficient vector. A first data processing task is executed based on the second ciphertext polynomial.

[0214] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0215] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0216] The modules described in the embodiments of this disclosure can be implemented in software or in hardware. The names of the modules do not necessarily limit the module itself; for example, a number theory transformation module can also be described as "a module that performs number theory transformations on a second column vector on ring A to obtain N polynomials".

[0217] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0218] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0219] According to one or more embodiments of this disclosure, Example 1 provides a secure computation method based on homomorphic encryption. The secure computation method is used for a first participant and a second participant to collaboratively compute the product of an N*N first matrix and an N-dimensional first column vector. The first matrix is ​​held solely by the first participant, and the first column vector is held solely by the second participant. The method is applied to the first participant and includes:

[0220] Performing number-theoretic transformations on the second column vector over ring A yields N polynomials, where the second column vector is (1, x, ..., x). N-1 The transpose of the product of the first matrix and the first matrix, where the independent variable x is a 2N-degree primitive root of unity in the ring A. R is any commutative ring containing 1, and N is a power of 2;

[0221] In response to receiving the first ciphertext polynomial sent by the second participant, a second ciphertext polynomial is generated based on the N polynomials and the first ciphertext polynomial, wherein the first ciphertext polynomial is obtained by the second participant homomorphically encrypting the first plaintext polynomial, and the first plaintext polynomial uses the first column vector as the coefficient vector.

[0222] The first data processing task is performed based on the second ciphertext polynomial.

[0223] According to one or more embodiments of this disclosure, Example 2 provides the method of Example 1, wherein performing a number-theoretic transformation on a second column vector on ring A to obtain N polynomials includes:

[0224] Calculate (1, x, ..., x) N-1 The product of the first matrix and the first row vector is obtained.

[0225] Transpose the first row vector to obtain the second column vector;

[0226] A number-theoretical transformation of the second column vector on ring A is performed using multi-level recursive operations to obtain the third column vector;

[0227] Each row of the third column vector is determined as one of the N polynomials.

[0228] According to one or more embodiments of this disclosure, Example 3 provides the method of Example 2, wherein the number-theoretic transformation of the second column vector on ring A is performed using multi-level recursive operations to obtain the third column vector, including:

[0229] S201, use the second column vector as the input data for the l-th level recursive operation, where l is initially 1;

[0230] S202, calculate the operation factor of the l-th level recursive operation, wherein the operation factor of the l-th level recursive operation is: For ring A The fundamental unit root, and

[0231] S203, the input data is split into a fourth column vector and a fifth column vector according to the parity of the index, wherein the fourth column vector consists of the even rows of the input data and the fifth column vector consists of the odd rows of the input data;

[0232] S204, based on the operation factor of the l-th level recursive operation and the input data of the l-th level recursive operation, two output data of the l-th level recursive operation are obtained, wherein the two output data include the sum of the number theory transformation result of the fourth column vector and the first product, and the difference between the number theory transformation result of the fourth column vector and the first product, wherein the first product is the product of the operation factor of the l-th level recursive operation and the number theory transformation result of the fifth column vector;

[0233] S205, determine whether the dimension of the fourth column vector or the fifth column vector is 1; if not, proceed to S206; if yes, proceed to S207.

[0234] S206, increment l by 1, and use the fourth column vector and the fifth column vector as input data for the l-th level recursive operation, respectively, and return to S202 to perform the l-th level recursive operation on the fourth column vector and the fifth column vector respectively;

[0235] S207, merge the output data of each level of recursive operation to obtain the third column vector.

[0236] According to one or more embodiments of this disclosure, Example 4 provides the method of Example 1, wherein performing the first data processing task based on the second ciphertext polynomial includes:

[0237] An N-dimensional random column vector is generated, and the second ciphertext polynomial is masked using the random column vector to obtain a masked polynomial. The masked polynomial is then sent to the second participant, who generates the first slice of the product based on the masked polynomial.

[0238] The random column vector is used as the second slice of the product, and the first data processing task is performed based on the second slice.

[0239] According to one or more embodiments of this disclosure, Example 5 provides the method of Example 4, wherein the second ciphertext polynomial is masked using the random column vector to obtain a masked polynomial, comprising:

[0240] Using the random column vector as the coefficient vector, a second plaintext polynomial is generated;

[0241] The second plaintext polynomial is homomorphically encrypted to obtain the fourth ciphertext polynomial.

[0242] The difference between the second ciphertext polynomial and the fourth ciphertext polynomial is determined as the masking polynomial.

[0243] According to one or more embodiments of this disclosure, Example 6 provides the method of Example 1, wherein generating a second ciphertext polynomial based on the N polynomials and the first ciphertext polynomial includes:

[0244] Perform N rotation operations on the first ciphertext polynomial to obtain N third ciphertext polynomials;

[0245] Generate the second ciphertext polynomial based on the N polynomials and the N third ciphertext polynomials.

[0246] According to one or more embodiments of this disclosure, Example 7 provides the method of Example 6, wherein performing N rotation operations on the first ciphertext polynomial to obtain N third ciphertext polynomials includes:

[0247] Receive the Galois key sent by the second participant, wherein the Galois key is generated by the second participant based on the homomorphic encryption private key;

[0248] For each element of the modulo-2N multiplication group, the first ciphertext polynomial is rotated using that element and the Galois key to obtain the third ciphertext polynomial.

[0249] According to one or more embodiments of this disclosure, Example 8 provides the method of Example 6, wherein generating a second ciphertext polynomial based on the N polynomials and the N third ciphertext polynomials includes:

[0250] Based on the N polynomials and the N third ciphertext polynomials, the second ciphertext polynomial is generated using the following formula:

[0251]

[0252] Where ct(β) is the second ciphertext polynomial; v k (x) is the (k+1) / 2th polynomial among the N polynomials. It is an integer ring; σ k (ct) is the (k+1) / 2th ciphertext polynomial among the N third ciphertext polynomials.

[0253] According to one or more embodiments of this disclosure, Example 9 provides a method as described in any one of Examples 1-8, wherein the first data processing task is a machine learning model training task.

[0254] According to one or more embodiments of the present disclosure, Example 10 provides a computer-readable medium having a computer program stored thereon that, when executed by a processing device, implements the steps of the method described in any one of Examples 1-9.

[0255] According to one or more embodiments of this disclosure, Example 11 provides an electronic device, including:

[0256] A storage device on which computer programs are stored;

[0257] A processing device for executing the computer program in the storage device to implement the steps of any one of the methods in Examples 1-9.

[0258] According to one or more embodiments of the present disclosure, Example 12 provides a computer program product including a computer program that, when executed by a processor, implements the steps of the method described in any one of Examples 1-9.

[0259] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0260] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0261] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative forms of implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which the various modules perform their operations has been described in detail in the embodiments relating to the method, and will not be elaborated upon here.

Claims

1. A secure computation method based on homomorphic encryption, characterized in that, The secure computation method is used by a first participant and a second participant to collaboratively calculate the product of an N*N first matrix and an N-dimensional first column vector. The first matrix is ​​held solely by the first participant, and the first column vector is held solely by the second participant. The method is applied to the first participant and includes: Performing number-theoretic transformations on the second column vector over ring A yields N polynomials, where the second column vector is (1, x, ..., x). N-1 The transpose of the product of the first matrix and the first matrix, where the independent variable x is a 2N-degree primitive root of unity in the ring A. R is any commutative ring containing 1, and N is a power of 2; In response to receiving the first ciphertext polynomial sent by the second participant, a second ciphertext polynomial is generated based on the N polynomials and the first ciphertext polynomial, wherein the first ciphertext polynomial is obtained by the second participant homomorphically encrypting the first plaintext polynomial, and the first plaintext polynomial uses the first column vector as the coefficient vector. The first data processing task is performed based on the second ciphertext polynomial.

2. The method according to claim 1, characterized in that, The number-theoretic transformation of the second column vector on ring A yields N polynomials, including: Calculate (1, x, ..., x) N-1 The product of the first matrix and the first row vector is obtained. Transpose the first row vector to obtain the second column vector; A number-theoretical transformation of the second column vector on ring A is performed using multi-level recursive operations to obtain the third column vector; Each row of the third column vector is determined as one of the N polynomials.

3. The method according to claim 2, characterized in that, The method employs multi-level recursive operations to perform number-theoretic transformations on the second column vector of ring A to obtain the third column vector, including: S201, use the second column vector as the input data for the l-th level recursive operation, where l is initially 1; S202, calculate the operation factor of the l-th level recursive operation, wherein the operation factor of the l-th level recursive operation is: For ring A The fundamental unit root, and S203, the input data is split into a fourth column vector and a fifth column vector according to the parity of the index, wherein the fourth column vector consists of the even rows of the input data and the fifth column vector consists of the odd rows of the input data; S204, based on the recursive factor of the first-level recursive operation and the input data of the first-level recursive operation, two output data of the first-level recursive operation are obtained, wherein the two output data include the sum of the number theory transformation result of the fourth column vector and the first product, and the difference between the number theory transformation result of the fourth column vector and the first product, wherein the first product is the product of the operation factor of the first-level recursive operation and the number theory transformation result of the fifth column vector; S205, determine whether the dimension of the fourth column vector or the fifth column vector is 1; if not, execute S206; if yes, execute S207. S206, increment l by 1, and use the fourth column vector and the fifth column vector as input data for the l-th level recursive operation, respectively, and return to S202 to perform the l-th level recursive operation on the fourth column vector and the fifth column vector respectively; S207, merge the output data of each level of recursive operation to obtain the third column vector.

4. The method according to claim 1, characterized in that, The execution of the first data processing task based on the second ciphertext polynomial includes: An N-dimensional random column vector is generated, and the second ciphertext polynomial is masked using the random column vector to obtain a masked polynomial. The masked polynomial is then sent to the second participant, who generates the first slice of the product based on the masked polynomial. The random column vector is used as the second slice of the product, and the first data processing task is performed based on the second slice.

5. The method according to claim 4, characterized in that, The step of masking the second ciphertext polynomial using the random column vector to obtain the masked polynomial includes: Using the random column vector as the coefficient vector, a second plaintext polynomial is generated; The second plaintext polynomial is homomorphically encrypted to obtain the fourth ciphertext polynomial. The difference between the second ciphertext polynomial and the fourth ciphertext polynomial is determined as the masking polynomial.

6. The method according to claim 1, characterized in that, The step of generating the second ciphertext polynomial based on the N polynomials and the first ciphertext polynomial includes: Perform N rotation operations on the first ciphertext polynomial to obtain N third ciphertext polynomials; Generate the second ciphertext polynomial based on the N polynomials and the N third ciphertext polynomials.

7. The method according to claim 6, characterized in that, The step of performing N rotation operations on the first ciphertext polynomial to obtain N third ciphertext polynomials includes: Receive the Galois key sent by the second participant, wherein the Galois key is generated by the second participant based on the homomorphic encryption private key; For each element of the modulo-2N multiplication group, the first ciphertext polynomial is rotated using that element and the Galois key to obtain the third ciphertext polynomial.

8. The method according to claim 6, characterized in that, The step of generating the second ciphertext polynomial based on the N polynomials and the N third ciphertext polynomials includes: Based on the N polynomials and the N third ciphertext polynomials, the second ciphertext polynomial is generated using the following formula: Where ct(β) is the second ciphertext polynomial; v k (x) is the (k+1) / 2th polynomial among the N polynomials. It is an integer ring; σ k (ct) is the (k+1) / 2th ciphertext polynomial among the N third ciphertext polynomials.

9. The method according to any one of claims 1-8, characterized in that, The first data processing task is a machine learning model training task.

10. A computer-readable medium having a computer program stored thereon, characterized in that, When executed by a processing device, the computer program performs the steps of the method according to any one of claims 1-9.

11. An electronic device, characterized in that, include: A storage device on which computer programs are stored; A processing device for executing the computer program in the storage device to implement the steps of the method according to any one of claims 1-9.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Data transmission and processing method and system

    CN106100831A

  • Method and device for executing matrix security multiplication

    CN116702232A