Multi-party data processing method capable of protecting privacy and computing equipment

By using the MLWE encryption algorithm to encrypt vectors, the privacy protection problem in multi-party data processing is solved, the effect of reducing the amount of ciphertext data and communication data is achieved, and the efficiency and security of privacy protection are improved.

CN119939666APending Publication Date: 2025-05-06ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510122534.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art is difficult to effectively protect privacy in multi-party data processing, resulting in excessive amounts of ciphertext data and communication data, increasing the risk of privacy leakage.

Method used

The MLWE encryption algorithm is used to replace the RLWE algorithm, encrypt the vectors, and by encoding polynomials and performing homomorphic multiplication, the waste of polynomial space is reduced, and the amount of ciphertext data and communication data is reduced.

Benefits of technology

It effectively reduces the amount of ciphertext data and the amount of communication data between multiple parties, and improves the efficiency and security of privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939666A_ABST
    Figure CN119939666A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a privacy-protecting multi-party data processing method and computing equipment, and the method comprises the steps that a first party encodes a first vector into a first polynomial, and encrypts the first polynomial to obtain a first MLWE ciphertext; the first MLWE ciphertext is sent to a second party; the second party encodes the second vector into a second polynomial; homomorphic multiplication of a second polynomial and the first MLWE ciphertext is executed to obtain a second MLWE ciphertext, and the second polynomial enables a constant term of a plaintext polynomial corresponding to the second MLWE ciphertext to be an inner product of the first vector and the second vector; the second MLWE ciphertext is sent to the first party; and the first party obtains an inner product of the first vector and the second vector based on the second MLWE ciphertext and t first private key polynomials arranged in sequence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification belong to the field of data processing technology, and more particularly, to a privacy-protecting multi-party data processing method and computing device. Background Art

[0002] Computing the inner product of vectors in a privacy-preserving manner is one of the basic operators and building blocks of privacy computing. For example, in a scenario where multiple parties use tree models for model prediction, the first party has the prediction values ​​of multiple tree models. The second party has the weights of the multiple tree model In order not to disclose the private data of each party, the first party and the second party hope to calculate the vector in a privacy-preserving manner. With vector The inner product of The output value predicted by the model.

[0003] In a scenario of joint modeling by multiple parties, the first party is, for example, a model party that provides a model, and the vector held in the model party is, for example, a parameter vector in the model; the second party is, for example, a data party that provides feature data, and the vector held in the second party is, for example, a feature vector. The first party and the second party similarly wish to calculate the inner product of the parameter vector and the feature vector in a privacy-preserving manner to obtain the model output value. Summary of the invention

[0004] The object of the present invention is to provide a privacy-protecting multi-party data processing method to reduce the amount of ciphertext data and the amount of communication data between multiple parties.

[0005] In a first aspect, the present specification provides a multi-party data processing method for protecting privacy, wherein the multiple parties include a first party and a second party, the first party owns a first vector, and the second party owns a second vector with the same dimension as the first vector, and the method includes:

[0006] The first party encodes the first vector into a first polynomial, encrypts the first polynomial based on t random polynomials arranged in sequence and t first private key polynomials arranged in sequence, to obtain a first MLWE ciphertext corresponding to the first vector, wherein the first MLWE ciphertext includes the t random polynomials arranged in sequence; and sends the first MLWE ciphertext to the second party;

[0007] The second party encodes the second vector into a second polynomial; performs homomorphic multiplication of the second polynomial and the first MLWE ciphertext to obtain a second MLWE ciphertext, wherein the second polynomial makes the constant term of the plaintext polynomial corresponding to the second MLWE ciphertext the inner product of the first vector and the second vector; and sends the second MLWE ciphertext to the first party;

[0008] The first party obtains the inner product of the first vector and the second vector based on the second MLWE ciphertext and the sequentially arranged t first private key polynomials.

[0009] A second aspect of the present specification provides a privacy-preserving multi-party data processing method, wherein the multi-party includes a first party and a second party, the first party has a first vector, and the second party has a second vector with the same dimension as the first vector, and the method is performed by the first party, including:

[0010] encoding the first vector into a first polynomial;

[0011] Encrypting the first polynomial based on t random polynomials arranged in sequence and t first private key polynomials arranged in sequence to obtain a first MLWE ciphertext corresponding to the first vector, wherein the first MLWE ciphertext includes the t random polynomials arranged in sequence;

[0012] sending the first MLWE ciphertext to the second party;

[0013] receiving a second MLWE ciphertext from the second party, the second MLWE ciphertext being obtained by homomorphically multiplying a second polynomial by the first MLWE ciphertext, the second polynomial being a polynomial corresponding to the second vector, the second polynomial being such that a constant term of a plaintext polynomial corresponding to the second MLWE ciphertext is an inner product of the first vector and the second vector;

[0014] Based on the second MLWE ciphertext and the sequentially arranged t first private key polynomials, an inner product of the first vector and the second vector is obtained.

[0015] A third aspect of the present specification provides a multi-party data processing method for protecting privacy, wherein the multi-party includes a first party and a second party, the first party has a first vector, the second party has a second vector with the same dimension as the first vector, and the method is performed by the second party, including:

[0016] receiving a first MLWE ciphertext from the first party, the first MLWE ciphertext being obtained by encrypting a first polynomial based on t sequentially arranged random polynomials and t sequentially arranged first private key polynomials, the first polynomial being obtained by encoding a first vector;

[0017] encoding the second vector as a second polynomial;

[0018] Perform homomorphic multiplication of the second polynomial and the first MLWE ciphertext to obtain a second MLWE ciphertext, wherein the second polynomial makes a constant term of a plaintext polynomial corresponding to the second MLWE ciphertext be an inner product of the first vector and the second vector;

[0019] The second MLWE ciphertext is sent to the first party.

[0020] A fourth aspect of the present specification provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method described in the first aspect, the second aspect, or the third aspect.

[0021] A fifth aspect of the specification provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method described in the first aspect, the second aspect, or the third aspect is implemented.

[0022] A sixth aspect of the present specification provides a computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the method described in the first aspect, the second aspect or the third aspect.

[0023] In the data processing scheme of the embodiment of this specification, by using the MLWE encryption algorithm to replace the RLWE algorithm to encrypt the vector, the waste of polynomial space can be reduced and the amount of ciphertext data can be reduced, thereby reducing the amount of communication data between the first party and the second party. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0025] Figure 1 To calculate the vector in a privacy-preserving manner in the embodiments of this specification With vector Schematic diagram of the inner product of ;

[0026] Figure 2 This is a flow chart of a multi-party data processing method for protecting privacy in an embodiment of this specification;

[0027] Figure 3 Schematic diagram of the data processing process in the embodiment of this specification. DETAILED DESCRIPTION

[0028] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.

[0029] Fully homomorphic encryption (FHE) is a technology that allows arbitrary computing operations to be performed on ciphertext without decrypting the data, where the result of the homomorphic calculation corresponds to the calculation result of the original plaintext after being decrypted. This means that even in an encrypted state, the data can still be processed and manipulated without leaking the original data. Specifically, in homomorphic addition, for plaintext polynomial m and plaintext polynomial t, E(m+t)=E(m)+E(t), where plaintext polynomial m and plaintext polynomial t are polynomials in the same polynomial space, and E() represents the ciphertext obtained by homomorphically encrypting the ciphertext polynomial; in homomorphic multiplication, E(t*m)=t*E(m), and in a homomorphic multiplication, E(x i *m)=x i *E(m); In homomorphic substitution, assuming that the ciphertext of polynomial m(x) is ct(x), then ct(x t )=E(m(x t )).

[0030] At present, most FHE schemes can be based on the learning with errors assumption (LEW), the ring learning with errors assumption (RLWE), and the modulo learning with errors assumption (MLWE). Correspondingly, the FHE scheme can include the following ciphertexts (where bold letters represent vectors or polynomials):

[0031] LWE ciphertext: Given two positive integers N and q, the LWE ciphertext of plaintext m (m is an integer) is defined as in, Represents N+1 dimensions space, The space represents the set of integers modulo q, ranging from {0,1,2,…,q-1}, a is a randomly obtained vector in the N-dimensional vector space, s is the homomorphic encryption private key, s∈{0,1} N, b = a·s+m+e mod q, where the error e is obtained by sampling from the error distribution.

[0032] RLWE ciphertext: RLWE ciphertext is LWE ciphertext in polynomial space The ring form in polynomial space The degree of the polynomial space is less than N, where N is a power of 2, such as 4096, 8192, etc., and x is set N =-1, polynomial The RLWE ciphertext is defined as: Where b = a·s+m+emodQ, where In this article, bold letters are used to represent vectors or polynomials.

[0033] MLWE ciphertext: MLWE ciphertext consists of t+1 polynomials Polynomial Space The degree of the polynomial space is less than k, k is a power of 2, and all polynomials a0,...,a t-1 are all uniformly selected, b = -∑a i ·s i +m+e.

[0034] In the related art, it is assumed that the first party has the vector The second party has the vector That is, the vector and vector Both are k-dimensional vectors. The first and second parties usually perform the following steps to obtain their inner product

[0035] In order to In the homomorphic operation, the first party randomly selects a random polynomial a(X) of length N and a private key polynomial s(X), where N>k and N is an integer multiple of k. Encoded as a polynomial:

[0036] U(X)=u0+u1X+…+u k-1 X k-1 +0X k +…+0X N-1 .

[0037] Then, the first party calculates b(X)=U(X)+a(X)*s(X), thus obtaining (a(X),b(X)) as a vector The first party then sends the RLWE ciphertext RLWE(U(X)) to the second party.

[0038] After receiving RLWE(U(X)), the second party first converts the vector The encoding is the following polynomial:

[0039] V(X)=v0+0X+…0X N-k -v k-1 X N-k+1 -v k-2 X N-k+2 -…-v1X N-1 .

[0040] Then, the second party performs homomorphic multiplication V(X)*(a(X), b(X)) to obtain the RLWE ciphertext (c(X), d(X)), and sends the RLWE ciphertext (c(X), d(X)) to the first party, where c(X)=V(X)*a(X), d(X)=V(X)*b(X).

[0041] According to the multiplication homomorphism of the RLWE algorithm, V(X)*(a(X),b(X)) is V(X)*E(U(X))=E(U(X)*V(X)). In, X N =-1, according to the above calculation of U(X)*V(X) from U(X) and V(X), it can be seen that the constant term of U(X)*V(X) can include

[0042]

[0043] That is, by transforming the vector and vector Encoded as a polynomial, so that the constant term of the plaintext corresponding to the above RLWE ciphertext (c(X), d(X)) is its inner product

[0044] Therefore, after receiving the RLWE ciphertext (c(X), d(X)), the first party can decrypt the RLWE ciphertext (c(X), d(X)) to obtain the plaintext polynomial and the constant term of the plaintext polynomial, i.e., the inner product

[0045] In one embodiment, after receiving the RLWE ciphertext (c(X), d(X)), the first party may extract the LWE ciphertext corresponding to the constant term of the plaintext polynomial from the RLWE ciphertext, so that the inner product can be obtained by decrypting the LWE ciphertext. Among them, the LWE ciphertext is the above The ciphertext of the space, that is, the LWE ciphertext corresponds to the N+1-dimensional space.

[0046] In the above calculation process, the RLWE ciphertext (a(X), b(X)) is calculated based on U(X), and U(X) is filled with multiple items with coefficients of 0, which wastes the polynomial space and makes the amount of data of the RLWE ciphertext (a(X), b(X)) sent by the first party to the second party larger. Similarly, the second party calculates the RLWE ciphertext (c(X), d(X)) based on (a(X), b(X)) and V(X), and V(X) is also filled with multiple items with coefficients of 0, which wastes the polynomial space and makes the amount of data of the RLWE ciphertext (c(X), d(X)) sent by the second party to the first party larger.

[0047] To this end, in the embodiments of this specification, the MLWE encryption algorithm is used to replace the RLWE algorithm to encrypt the vector, which can reduce the waste of polynomial space and reduce the amount of ciphertext data, thereby reducing the amount of communication data between the first party and the second party.

[0048] Figure 1 To calculate the vector in a privacy-preserving manner in the embodiments of this specification With vector Schematic diagram of the inner product of . Figure 1 As shown, the first party device 101 stores a k-dimensional vector The second device 102 stores a k-dimensional vector The first party can generate vectors of The second party can generate MLWE ciphertexts of the vector A specific encoding is performed to obtain a polynomial V(X) of length k, so that by calculating the polynomial V(X) and the vector Homomorphic multiplication of the MLWE ciphertext yields the inner product with the vector The corresponding MLWE ciphertext is obtained and the MLWE ciphertext is sent to the first party. In this scheme, when encoding the vector into a polynomial, it is not necessary to fill the polynomial with terms with coefficients of 0 or fewer terms with coefficients of 0 may be included, thereby wasting less polynomial space and reducing the amount of data in the MLWE ciphertext.

[0049] Figure 2 is a flow chart of a multi-party data processing method for protecting privacy in an embodiment of this specification. The method can be performed by Figure 1 The first party device (hereinafter referred to as the first party) and the second party device (hereinafter referred to as the second party) in the embodiment are executed. The first party includes the vector that needs to be protected for privacy. The second party includes the vector that needs to be protected for privacy

[0050] like Figure 1 As shown, first, in step S201, the first party converts the vector Encrypted into MLWE ciphertext MLWE1(U(X)).

[0051] The first party may first determine the parameters in the MLWE algorithm, including the dimension M of the polynomial space (i.e., the number of terms in the polynomial) and the modulus q. The dimension M of the polynomial space may be set to k, for example. It is understood that the dimension M of the polynomial space is not limited to being set to k, and may be set to a number less than N, where N is the vector dimension corresponding to the LWE ciphertext. For example, when k=4 and N=16, the dimension M of the polynomial space may be set to 8, which may also reduce the waste of the polynomial space and the amount of ciphertext data.

[0052] Afterwards, the first party may randomly select t polynomials of length M, such as a0(X) and a1(X), from the polynomial space of dimension M, and determine t private key polynomials of length M, such as s0(X) and s1(X). The number of t may be determined based on the lengths of M and N. For example, when M=4 and N=8, t may be set to 2, so that the final LWE ciphertext may include an 8-dimensional vector.

[0053] In the case of M = k, the first party can Encoded as the following polynomial U(X):

[0054] U(X)=u0+u1X+…+u k-1 X k-1 (1)

[0055] In the case of M>k, the first party can convert the vector Encoded as the following polynomial U(X):

[0056] U(X)=u0+u1X+…+u k-1 X k-1 +0X k +…+0X M-1 (2)

[0057] Then, the first party can calculate b1(X) based on the MLWE algorithm:

[0058] b1(X)=U(X)+a0(X)*s0(X)+a1(X)*s1(X)

[0059] Thus, we can get the ciphertext MLWE1(U(X))=(a0(X),a1(X),b1(X))

[0060] Figure 3Schematic diagram of the data processing process in the embodiment of this specification. Figure 3 As shown, assuming that the vector is (1,2,3,4), and the vector is When encoding, we can get U(X)=1+2X+3X 2 +4X 3 , by encrypting U(X) based on the MLWE algorithm, we can get Figure 3 The MLWE ciphertext MLWE1(U(X)) shown in FIG. The numbers 1, 2, 3, and 4 in the MLWE1(U(X)) in sequence represent the multiple coefficients in the plaintext polynomial corresponding to the ciphertext in sequence. This encoding method does not waste the polynomial space, and, taking M=k=4 and N=8 as an example, since MLWE1(U(X)) includes three 4-dimensional polynomials, a total of 12 coefficients, and the above The RLWE ciphertext in space includes 2 polynomials and a total of 16 coefficients. Obviously, the MLWE1(U(X)) ciphertext has a smaller data volume than the RLWE(U(X)) in the above text, thereby reducing the amount of communication data between the first party and the second party.

[0061] By using the above formula (2) for the vector In the case of encoding, taking M=8, N=16 as an example, it can be similarly concluded that the MLWE1(U(X)) ciphertext has a smaller amount of data than the RLWE(U(X)) in the above text.

[0062] In step S203 , the first party sends the ciphertext MLWE1(U(X)) to the second party.

[0063] In step S205, the second party converts the vector Encoded as a polynomial V(X), the polynomial V(X) is homomorphically multiplied with MLWE1(U(X)) to obtain the MLWE ciphertext MLWE2(U(X)*V(X)).

[0064] In one embodiment, when M=k, the second party may Encoded as the following polynomial V(X):

[0065] V(X)=v0-v k-1 Xv k-2 X 2 -…-v1X k-1 (3)

[0066] In another embodiment, when M>k, the second party may convert the vector Encoded as the following polynomial V(X):

[0067] V(X)=v0+0X+…0X M-k -v k-1 X M-k+1 -v k-2 X M-k+2 -…-v1X M-1 (4)

[0068] Then, the second party homomorphically multiplies the polynomial V(X) with MLWE1(U(X)) to obtain the MLWE ciphertext MLWE2(U(X)*V(X)):

[0069] MLWE2(U(X)*V(X))

[0070] =V(x)*(a0(X),a1(X),b1(X))

[0071] =(V(x)*a0(X),V(x)*a1(X),V(x)*b1(X))

[0072] =(c0(X),c1(X),d1(X))

[0073] By using formula (1) for the vector Encode, and as shown in formula (3) the vector Encoding, the constant term of U(X)*V(X) may include u0v0+u1v1+…+u k-1 v k-1 ,Right now Thus, the constant term of the plaintext polynomial corresponding to MLWE2(U(X)*V(X)) can be made into

[0074] refer to Figure 3 , assuming the vector is (5,6,7,8), and the vector is Encoding, we can get V(X)=5-8X-7X 2 -6X 3 , multiplying the vector V(X) by the ciphertext MLWE1(U(X)) yields the ciphertext MLWE2(U(X)*V(X)). The constant term corresponding to the ciphertext is

[0075] By using formula (2) for the vector Encode, and as shown in formula (4) the vector Encoding, the same can be calculated, the constant term of U(X)*V(X) may include u0v0+u1v1+…+u k-1 v k-1 ,Right now Thus, the constant term of the plaintext polynomial corresponding to MLWE2(U(X)*V(X)) can be made into

[0076] In step S207 , the second party sends MLWE2(U(X)*V(X)) to the first party.

[0077] Similar to the above, the vector The encoding wastes less polynomial space, and the ciphertext MLWE2 (U (X) * V (X)) has a newer data amount compared to the aforementioned RLWE ciphertext (c (X), d (X)), reducing the amount of communication data between the second party and the first party.

[0078] In step S209 , the first party obtains the vector inner product based on MLWE2(U(X)*V(X)).

[0079] In one implementation, the first party may use the above s0(X) and s1(X) to decrypt MLWE2(U(X)*V(X)) to obtain the plaintext polynomial U(X)*V(X) corresponding to MLWE2(U(X)*V(X)), and obtain the constant term from the plaintext polynomial, which is the vector inner product.

[0080] In another embodiment, reference Figure 3 As shown in , the first party can extract the LWE ciphertext corresponding to the constant term of the plaintext polynomial from the ciphertext MLWE2(U(X)*V(X)), and obtain the vector inner product by decrypting the LWE ciphertext

[0081] Specifically, for MLWE2(U(X)*V(X))=(c0(X),c1(X),d1(X)), assume that:

[0082] c0(X)=c 0,0 +c 0,1 X+…+c 0,k-1 X k-1 ,

[0083] c1(X)=c 1,0 +c 1,1 X+…+c 1,k-1 X k-1 ,

[0084] d1(X)=d0+d1X+…+d k-1 X k-1 ,

[0085] According to the algorithm for extracting LWE ciphertext from MLWE ciphertext, the LWE ciphertext corresponding to the constant term of U(X)*V(X) is:

[0086] ((c 0,0 ,-c 0,k-1 ,…,-c 0,1 ,c 1,0 ,-c 1,k-1 ,…,c 1,1 ),d0)

[0087] Assume that the keys s0(X) and s1(X) mentioned above are:

[0088] s0(X)=s 0,0 +s 0,1 X+…+s 0,k-1 X k-1 ,

[0089] s1(X)=s 1,0 +s 1,1 X+…+s 1,k-1 X k-1

[0090] The first party can obtain the key s of the LWE ciphertext based on the polynomial coefficients of s0(X) and s1(X):

[0091] (s 0,0 ,s 0,1 ,…,s 0,k-1 ,s 1,0 ,s 1,1 ,…,s 1,k-1 )

[0092] The first party decrypts the above LWE ciphertext based on the key s and obtains the vector inner product

[0093] The embodiment of the present specification also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed in a computer, the computer is caused to execute the following Figure 2 The method shown.

[0094] The embodiment of the present specification also provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the following is implemented: Figure 2 The method shown.

[0095] The embodiments of the present specification also provide a computer program product, including a computer program / instruction, which is executed by a processor to implement the following Figure 2 The steps of the method are shown.

[0096] In the embodiments of this specification, the MLWE encryption algorithm is used to replace the RLWE algorithm to encrypt the vector, which can reduce the waste of polynomial space and reduce the amount of ciphertext data, thereby reducing the amount of communication data between the first party and the second party.

[0097] In the 1990s, improvements to a technology could be clearly distinguished as hardware improvements (for example, improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the method flow). However, with the development of technology, many improvements to the method flow today can be regarded as direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages ​​and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.

[0098] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.

[0099] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a server system. Of course, the present application does not exclude that with the development of computer technology in the future, the computer that implements the functions of the above embodiments may be, for example, a personal computer, a laptop computer, a vehicle-mounted human-computer interaction device, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0100] Although one or more embodiments of the present specification provide method operation steps as described in the embodiments or flow charts, more or less operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way of executing the order of many steps, and does not represent the only execution order. When the device or terminal product in practice is executed, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings (for example, a parallel processor or a multi-threaded processing environment, or even a distributed data processing environment). The term "include", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, product or equipment including a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such a process, method, product or equipment. In the absence of more restrictions, it is not excluded that there are other identical or equivalent elements in the process, method, product or equipment including the elements. For example, if the words first, second, etc. are used to represent the name, they do not represent any specific order.

[0101] For the convenience of description, the above devices are described in various modules according to their functions. Of course, when implementing one or more of the present specification, the functions of each module can be implemented in the same or more software and / or hardware, or the module implementing the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0102] The present invention is described with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0103] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0104] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0105] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0106] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0107] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage, graphene storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0108] It should be understood by those skilled in the art that one or more embodiments of the present specification may be provided as a method, system or computer program product. Therefore, one or more embodiments of the present specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, one or more embodiments of the present specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0109] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0110] Each embodiment in this specification is described in a progressive manner, and the same and similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. In the description of this specification, the description of the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic representation of the above terms does not necessarily target the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples without contradiction.

[0111] The above description is only an example of one or more embodiments of the present specification and is not intended to limit one or more embodiments of the present specification. For those skilled in the art, one or more embodiments of the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims.

Claims

1. A privacy-preserving multi-party data processing method, wherein the multi-party includes a first party and a second party, wherein the first party has a first vector, and the second party has a second vector with the same dimension as the first vector, and the method comprises: The first party encodes the first vector into a first polynomial, encrypts the first polynomial based on t random polynomials arranged in sequence and t first private key polynomials arranged in sequence, to obtain a first MLWE ciphertext corresponding to the first vector, wherein the first MLWE ciphertext includes the t random polynomials arranged in sequence; and sends the first MLWE ciphertext to the second party; The second party encodes the second vector into a second polynomial; performs homomorphic multiplication of the second polynomial and the first MLWE ciphertext to obtain a second MLWE ciphertext, wherein the second polynomial makes the constant term of the plaintext polynomial corresponding to the second MLWE ciphertext the inner product of the first vector and the second vector; and sends the second MLWE ciphertext to the first party; The first party obtains the inner product of the first vector and the second vector based on the second MLWE ciphertext and the sequentially arranged t first private key polynomials.

2. According to the method of claim 1, the first MLWE ciphertext further includes a third polynomial, and the third polynomial is calculated based on the first polynomial, the t random polynomials and the t first private key polynomials. The performing homomorphic multiplication of the second polynomial and the first MLWE ciphertext includes: The second polynomial is multiplied by the t random polynomials arranged in sequence and the third polynomial respectively to obtain t+1 fourth polynomials arranged in sequence as the t+1 polynomials arranged in sequence included in the second MLWE ciphertext.

3. The method according to claim 1, wherein the first party obtains the inner product of the first vector and the second vector based on the second MLWE ciphertext and the sequentially arranged t first private key polynomials, comprising: The first party extracts, from the second MLWE ciphertext, an LWE ciphertext corresponding to a constant term of the plaintext polynomial; Obtaining a second private key vector corresponding to the LWE ciphertext based on the t first private key polynomials arranged in sequence; The LWE ciphertext is decrypted based on the second private key vector to obtain the constant term.

4. The method according to claim 3, wherein the second MLWE ciphertext comprises t fifth polynomials and sixth polynomials arranged in sequence, The first party extracts the LWE ciphertext corresponding to the constant term of the plaintext polynomial from the second MLWE ciphertext, including: The first party obtains a plurality of coefficients from the t second polynomials arranged in sequence, and obtains a first vector based on the plurality of coefficients; A constant term is obtained from the sixth polynomial, and the first vector and the constant term of the sixth polynomial are combined into the LWE ciphertext.

5. According to the method of claim 3, the step of obtaining the second private key polynomial corresponding to the LWE ciphertext based on the t first private key polynomials arranged in sequence comprises: The first coefficients of the t first private key polynomials are arranged in sequence to obtain the second private key vector.

6. According to the method of claim 3, the t is determined based on the dimension of the vector space corresponding to the LWE ciphertext and the dimension of the polynomial space corresponding to the first MLWE ciphertext.

7. The method according to claim 1, wherein the first party obtains the inner product of the first vector and the second vector based on the second MLWE ciphertext and the sequentially arranged t first private key polynomials, comprising: The first party decrypts the second MLWE ciphertext based on the t first private key polynomials to obtain the plaintext polynomial, and acquires the constant term in the plaintext polynomial.

8. A privacy-preserving multi-party data processing method, the multi-party comprising a first party and a second party, the first party having a first vector, the second party having a second vector having the same dimension as the first vector, the method being performed by the first party, comprising: encoding the first vector into a first polynomial; Encrypting the first polynomial based on t random polynomials arranged in sequence and t first private key polynomials arranged in sequence to obtain a first MLWE ciphertext corresponding to the first vector, wherein the first MLWE ciphertext includes the t random polynomials arranged in sequence; sending the first MLWE ciphertext to the second party; receiving a second MLWE ciphertext from the second party, the second MLWE ciphertext being obtained by homomorphically multiplying a second polynomial by the first MLWE ciphertext, the second polynomial being a polynomial corresponding to the second vector, the second polynomial being such that a constant term of a plaintext polynomial corresponding to the second MLWE ciphertext is an inner product of the first vector and the second vector; Based on the second MLWE ciphertext and the sequentially arranged t first private key polynomials, an inner product of the first vector and the second vector is obtained.

9. A privacy-preserving multi-party data processing method, the multi-party comprising a first party and a second party, the first party having a first vector, the second party having a second vector having the same dimension as the first vector, the method being performed by the second party, comprising: receiving a first MLWE ciphertext from the first party, the first MLWE ciphertext being obtained by encrypting a first polynomial based on t sequentially arranged random polynomials and t sequentially arranged first private key polynomials, the first polynomial being obtained by encoding a first vector; Encode the second vector into a second polynomial; perform homomorphic multiplication of the second polynomial and the first MLWE ciphertext to obtain a second MLWE ciphertext, wherein the second polynomial makes a constant term of a plaintext polynomial corresponding to the second MLWE ciphertext be an inner product of the first vector and the second vector; The second MLWE ciphertext is sent to the first party.

10. A computing device comprising a memory and a processor, wherein the memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 1 to 9 is implemented.

Citation Information

Cited By

  • Data encryption / decryption method, key generation method and electronic equipment

    CN120150952A