Multi-party data processing method capable of protecting privacy and computing equipment
Through homomorphic encryption technology and the use of RLWE ciphertext, the problem of complex and high cost of sparse matrix multiplication calculation in the prior art is solved, and efficient and low-cost privacy-protected data processing is achieved.
Patent Information
- Application Number
- CN202510122539.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-06
AI Technical Summary
When the prior art calculates the multiplication of sparse matrix and matrix while protecting privacy, the calculation is complex and the calculation is large, resulting in high cost.
Through homomorphic encryption technology, the first party encrypts the first matrix, generates multiple RLWE ciphertexts, and sends them to the second party. According to the Boolean vector, the second party extracts the corresponding ciphertext from the received ciphertext and performs homomorphism and calculation to obtain the ciphertext of the matrix multiplication result.
It reduces the amount of calculation in the data processing process, reduces the cost of calculation, and improves the computing efficiency.
Smart Images

Figure CN119939667A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification belong to the field of data processing technology, and more particularly, to a privacy-protecting multi-party data processing method and computing device. Background Art
[0002] Computing sparse matrices or sparse vector-matrix multiplication in a privacy-preserving manner is one of the basic operators and building blocks of privacy computing. For example, in a multi-party secure computing (MPC) scenario, the first party has sensitive information that needs to be protected, and the second party has a plaintext matrix. It can encrypt the sensitive information into ciphertext and execute a two-party protocol to obtain the ciphertext of matrix-matrix multiplication. In a fully homomorphic encryption (FHE) computing scenario, a user generates a matrix ciphertext encrypted with his own private key, sends the matrix ciphertext to the cloud server to perform plaintext-cipher matrix multiplication, and the cloud server sends the ciphertext result back to the user after completing the multiplication calculation.
[0003] Sparse matrix multiplication is a commonly used calculation, such as tree model training in machine learning, graph neural network training and reasoning, and binary neural network reasoning. Currently, in order to protect privacy, sparse matrix multiplication is usually performed based on LWE and RLWE algorithms. Specifically, it is achieved by converting LWE and RLWE ciphertexts to each other and converting matrix multiplication into homomorphic addition of LWE and RLWE ciphertexts. This solution is computationally complex and requires a large amount of calculation. Summary of the invention
[0004] The purpose of the present invention is to provide a privacy-protecting multi-party data processing method to reduce the amount of calculation in the data processing process.
[0005] In a first aspect, the present specification provides a multi-party data processing method for protecting privacy, wherein the multi-party includes a first party and a second party, wherein the first party has a first matrix including n rows, and the second party has a Boolean vector, and the method includes:
[0006] The first party homomorphically encrypts the data in the first matrix to obtain m first RLWE ciphertexts corresponding to n row vectors of the first matrix, where m is less than or equal to n; and sends the m first RLWE ciphertexts to the second party;
[0007] The second party obtains t second ciphertexts corresponding to t row vectors of the first matrix respectively based on the Boolean vector and the m first RLWE ciphertexts, and calculates the homomorphic sum of the t second ciphertexts as the ciphertext of the multiplication result of the Boolean vector and the first matrix.
[0008] A second aspect of the present specification provides a privacy-preserving multi-party data processing method, wherein the multi-party includes a first party and a second party, the first party has a first matrix including n rows, the second party has a Boolean vector, and the method is performed by the first party, including:
[0009] Perform homomorphic encryption on the data in the first matrix to obtain m first RLWE ciphertexts corresponding to n row vectors of the first matrix; and send the m first RLWE ciphertexts to the second party;
[0010] A ciphertext of a multiplication result of the Boolean vector and the first matrix is received from the second party, where the ciphertext of the multiplication result is obtained based on a homomorphic sum of t second ciphertexts, where the t second ciphertexts correspond to t row vectors of the first matrix, respectively, and are obtained based on the Boolean vector and the m first ciphertexts.
[0011] A third aspect of the present specification provides a privacy-preserving multi-party data processing method, wherein the multi-party includes a first party and a second party, the first party has a first matrix including n rows, the second party has a Boolean vector, and the method is performed by the second party, including:
[0012] receiving m first RLWE ciphertexts from the first party, the m first RLWE ciphertexts being homomorphically encrypted ciphertexts corresponding to n row vectors of the first matrix;
[0013] According to the Boolean vector, t second ciphertexts corresponding to the t row vectors of the first matrix are obtained based on the m first RLWE ciphertexts, and the homomorphic sum of the t second ciphertexts is calculated as the ciphertext of the multiplication result of the Boolean vector and the first matrix.
[0014] A fourth aspect of the present specification provides a privacy-preserving multi-party data processing method, wherein the multiple parties include a first party and a second party, the first party has a first matrix including n columns, and the second party has a Boolean vector, and the method includes:
[0015] The first party homomorphically encrypts the data in the first matrix to obtain m first RLWE ciphertexts corresponding to n column vectors of the first matrix, where m is less than or equal to n; and sends the m first RLWE ciphertexts to the second party;
[0016] The second party obtains t second ciphertexts corresponding to t column vectors of the first matrix respectively based on the m first RLWE ciphertexts according to the Boolean vector, and calculates the homomorphic sum of the t second ciphertexts as the ciphertext of the multiplication result of the first matrix and the Boolean vector.
[0017] A fifth aspect of the present specification provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method described in the first aspect, the second aspect, the third aspect or the fourth aspect.
[0018] A sixth aspect of the present specification provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method described in the first aspect, the second aspect, the third aspect or the fourth aspect is implemented.
[0019] A seventh aspect of the present specification provides a computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the method described in the first aspect, the second aspect, the third aspect or the fourth aspect.
[0020] In the data processing scheme of the embodiment of the present specification, the first party may generate multiple RLWE ciphertexts corresponding to the row vectors of the matrix V, and send the multiple RLWE ciphertexts to the second party. The second party may extract n ciphertexts corresponding to the n row vectors of the matrix V from the multiple RLWE ciphertexts, obtain t ciphertexts from the n ciphertexts based on the Boolean vector, and add the t ciphertexts to obtain the ciphertext of the multiplication result of the Boolean vector and the matrix V, with a small amount of calculation and a low calculation cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0022] Figure 1 A schematic diagram of calculating the multiplication of a matrix M and a matrix V in a privacy-preserving manner in an embodiment of this specification;
[0023] Figure 2 This is a flow chart of a multi-party data processing method for protecting privacy in an embodiment of this specification;
[0024] Figure 3 This is a schematic diagram of the data processing process in the embodiments of this specification;
[0025] Figure 4 Schematic diagram of the process of extracting t MLWE ciphertexts and performing homomorphic addition on them in the embodiment of this specification;
[0026] Figure 5 is another schematic diagram of a data processing process in an embodiment of this specification;
[0027] Figure 6 This is a flow chart of a method for packaging multiple MLWE ciphertexts in an embodiment of this specification;
[0028] Figure 7 It is a schematic diagram of the process of packaging MLWE ciphertext in an embodiment of this specification;
[0029] Figure 8 is another schematic diagram of a data processing process in an embodiment of this specification;
[0030] Fig. 9 This is a flow chart of a multi-party data processing method for protecting privacy in another embodiment of this specification;
[0031] Fig.10 This is a schematic diagram of the data processing process in the embodiments of this specification;
[0032] Fig.11 Schematic diagram of the process of extracting t MLWE ciphertexts and performing homomorphic addition on them in the embodiment of this specification. DETAILED DESCRIPTION
[0033] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.
[0034] Fully homomorphic encryption (FHE) is a technology that allows arbitrary computing operations to be performed on ciphertext without decrypting the data, where the result of the homomorphic calculation corresponds to the calculation result of the original plaintext after being decrypted. This means that even in an encrypted state, the data can still be processed and manipulated without leaking the original data. Specifically, in homomorphic addition, for plaintext polynomial m and plaintext polynomial t, E(m+t)=E(m)+E(t), where plaintext polynomial m and plaintext polynomial t are polynomials in the same polynomial space, and E() represents the ciphertext obtained by homomorphically encrypting the ciphertext polynomial; in homomorphic multiplication, E(t*m)=t*E(m), and in a homomorphic multiplication, E(x i *m)=x i *E(m); In homomorphic substitution, assuming that the ciphertext of polynomial m(x) is ct(x), then ct(x t )=E(m(x t )).
[0035] At present, most FHE schemes can be based on the learning with errors assumption (LEW), the ring learning with errors assumption (RLWE), and the modulo learning with errors assumption (MLWE). Correspondingly, the FHE scheme can include the following ciphertexts (where bold letters represent vectors or polynomials):
[0036] LWE ciphertext: Given two positive integers n and q, the LWE ciphertext of plaintext m (m is an integer) is defined as in, Represents n+1 dimensions space, The space represents the set of integers modulo q, ranging from {0,1,2,…,q-1}, a is a randomly obtained vector in the n-dimensional vector space, s is the homomorphic encryption private key, s∈{0,1} n , b = a·s+m+e mod q, where the error e is obtained by sampling from the error distribution.
[0037] RLWE ciphertext: RLWE ciphertext is LWE ciphertext in polynomial space The ring form in polynomial space The degree of the polynomial space is less than N, where N is a power of 2, such as 4096, 8192, etc. The RLWE ciphertext is defined as: Where b = a·s+m+emodQ, where In this article, bold letters are used to represent vectors or polynomials.
[0038] MLWE ciphertext: MLWE ciphertext consists of t+1 polynomials Polynomial Space The degree of the polynomial space is less than k, k is a power of 2, and all polynomials a 0 ,...,a t-1 are all uniformly selected, b = -∑a i ·s i +m+e.
[0039] In the related art, when calculating the matrix multiplication of a plaintext matrix M (i.e., a Boolean matrix) (s rows × n columns) with a [0,1] distribution and a matrix V (n rows × k columns) to be privacy protected, assuming that the first party has the matrix V and the second party has the matrix M, the first party and the second party usually perform the following steps to obtain M*V:
[0040] The first party encrypts each column of the matrix V to obtain k RLWE ciphertexts corresponding to the k column vectors, and sends the k RLWE ciphertexts to the second party;
[0041] The second party performs the following processing on each row of the matrix M: Based on a row of the matrix M, t LWE ciphertexts are selected from the k RLWE ciphertexts through the RLWE sample extraction algorithm, where t is the number of elements with a value of 1 in the row vector, and for the column vector of the matrix V corresponding to each RLWE ciphertext, the t LWE ciphertexts are added using the addition of the LWE ciphertext to obtain the LWE ciphertext of the inner product of the row of the matrix M and a column of the matrix V, that is, a total of k LWE ciphertexts are obtained, and the k LWE ciphertexts constitute a row of the ciphertext corresponding to M*V. The second party can obtain s groups of ciphertexts based on s rows of the matrix M, each group of ciphertexts includes k LWE ciphertexts, and then the second party can package multiple LWE ciphertexts into RLWE ciphertexts.
[0042] Afterwards, the second party may send the RLWE ciphertext to the first party so that the first party can obtain M*V through decryption, or may send the ciphertext difference E(b1) between the RLWE ciphertext and the random polynomial b0 to the first party, where E(b1) represents the RLWE ciphertext corresponding to the polymorphic b1, so that the first party can obtain a plaintext fragment of M*V based on b1, and the second party can obtain another plaintext fragment of M*V based on b0.
[0043] In the above calculation process, the second party needs to calculate k RLWE ciphertexts based on each row of the matrix M, and the calculation process of selecting t LWE ciphertexts from each RLWE ciphertext is more complicated and the amount of calculation is large. In addition, the performance of homomorphic calculation and packaging of LWE ciphertexts is poor, resulting in a high calculation cost.
[0044] Figure 1 Schematic diagram of calculating the multiplication of matrix M and matrix V in a privacy-preserving manner in an embodiment of this specification. Figure 1As shown, in the first-party device 101, an \(n\times k\) matrix \(V\) is stored, and in the second-party device 102, an \(s\times n\) matrix \(M\) is stored. The first party can generate a plurality of RLWE ciphertexts corresponding to the row vectors of the matrix \(V\) and send the plurality of RLWE ciphertexts to the second party. The second party can extract \(n\) MLWE ciphertexts corresponding to the \(n\) row vectors of the matrix \(V\) from the plurality of RLWE ciphertexts, obtain \(t\) MLWE ciphertexts from the \(n\) MLWE ciphertexts based on each row of the matrix \(M\), and add the \(t\) MLWE ciphertexts to obtain the multiplication result of one row of the matrix \(M\) and the matrix \(V\). Additionally, in this process, extracting MLWE ciphertexts from RLWE ciphertexts essentially involves rearranging and combining the coefficients of the ciphertext polynomials, without expensive polynomial and NTT operations, and the computational cost is relatively low.
[0045] It can be understood that in Figure 1 the example shown, when the number of rows of the matrix \(M\) is 1 row, that is, it is equivalent that the second party includes a row vector. In the case where the second party includes a row vector, the solution in the embodiments of this specification can still be applied. In the following, the cases where the matrix \(M\) is a vector and a non-vector are described through different examples respectively.
[0046] Figure 2 It is a flowchart of a privacy-preserving multi-party data processing method in the embodiments of this specification. This method can be executed by Figure 1 the first-party device (hereinafter simply referred to as the first party) and the second-party device (hereinafter simply referred to as the second party) in. Among them, the first party includes the matrix \(V\) that needs privacy protection, and the second party includes the boolean vector \(M\) or the boolean matrix \(M\).
[0047] As Figure 1 shown, first, in step S201, the first party homomorphically encrypts the data in the matrix \(V\) to obtain \(m\) RLWE ciphertexts corresponding to \(n\) row vectors.
[0048] In one implementation, when the number of columns \(k = N\) of the matrix \(V\), that is, the above polynomial space and are the same space, the first party can perform RLWE encryption on each row vector of the matrix \(V\) to obtain \(n\) RLWE ciphertexts corresponding to the \(n\) row vectors respectively.
[0049] In one implementation, when the number of columns \(k\lt N\) of the matrix \(V\), and \(N\) is an integer multiple of \(k\), the first party can sequentially splice \(N / k\) row vectors in the matrix \(V\) into \(N\)-dimensional row vectors, so as to obtain \(m\) \(N\)-dimensional row vectors, where \(m=n / (N / k)\). Then, the first party performs RLWE homomorphic encryption on the \(m\) \(N\)-dimensional row vectors respectively to obtain \(m\) RLWE ciphertexts, and the RLWE ciphertexts correspond to the polynomial space of degree \(N - 1\).
[0050] Figure 3 Figure 1 is a schematic diagram of the data processing process in this manual. Figure 3 As shown on the left side of the figure, assume that the matrix V is a 4-row × 2-column matrix as shown on the left side, and assume that N = 4. In the case of N = 4, the plaintext polynomial includes 4 coefficients, and a 4-dimensional vector can be encrypted. In order not to waste polynomial space, every two rows of the matrix V can be concatenated into a 4-dimensional vector for encryption. Specifically, Figure 3 As shown in the middle part of the figure, the first and second rows of the matrix V are concatenated into a row vector (1,2,3,4), which is converted into a polynomial 1+2x+3x 2 +4x 3 , and then encrypt the polynomial based on the RLWE algorithm to obtain RLWE1( Figure 3 As shown in the figure, the ciphertext is represented by a rounded rectangle with a shadow, and the multiple numbers in the rounded rectangle represent the plaintext corresponding to the ciphertext. As mentioned above, RLWE1 includes two ciphertext polynomials (a, b). For example, it can be assumed that a=a 0 +a 1 x+a 2 x 2 +a 3 x 3 , b=b 0 +b 1 x+b 2 x 2 +b 3 x 3 Similarly, by concatenating the third and fourth rows of matrix V into a row vector (5,6,7,8), the row vector is converted to the polynomial 5+6x+7x 2 +8x 3 , and then encrypt the polynomial based on the RLWE algorithm to obtain RLWE2. That is, in this example, the first party can obtain 2 RLWE ciphertexts corresponding to 4 row vectors, that is, n=4, m=2.
[0051] In step S203, the first party sends m RLWE ciphertexts to the second party.
[0052] In step S205, the second party obtains t target ciphertexts based on the Boolean vector and the m RLWE ciphertexts, and calculates the homomorphic sum of the t target ciphertexts.
[0053] In one implementation, when m RLWE ciphertexts are n RLWE ciphertexts, the second party may directly obtain t RLWE ciphertexts corresponding to t row vectors of the matrix V from the n RLWE ciphertexts according to the Boolean vector.
[0054] In another implementation, when m < n, the second party can extract n MLWE ciphertexts corresponding to the n row vectors of matrix V from m RLWE ciphertexts, and then can obtain t MLWE ciphertexts corresponding to the t row vectors of matrix V from the n MLWE ciphertexts based on the values of the respective elements in the Boolean vector.
[0055] Specifically, when extracting the MLWE ciphertexts, the second party can extract N / k MLWE ciphertexts from each RLWE ciphertext. As Figure 3 shown, when N = 4 and k = 2, the second party can extract 4 / 2 = 2 MLWE ciphertexts from each RLWE ciphertext. For example, the second party can extract the ciphertext MLWE1 corresponding to the first row of matrix V and the ciphertext MLWE2 corresponding to the second row of matrix V from RLWE1, and extract the ciphertext MLWE3 corresponding to the third row of matrix V and the ciphertext MLWE4 corresponding to the fourth row of matrix V from RLWE2. Among them, Figure 3 the MLWE ciphertexts extracted from RLWE1 and the MLWE ciphertexts extracted from RLWE2 are respectively represented by rounded rectangular blocks with two colors of shading. Among them, the two numbers in the shaded rounded rectangular block represent the row vectors in matrix V corresponding to the MLWE ciphertext.
[0056] In the process of extracting MLWE ciphertexts from RLWE ciphertexts, assuming that the RLWE ciphertext includes a first polynomial and a second polynomial, the second party can use every N / k coefficients in the coefficients of the first polynomial as the coefficients of N / k third polynomials respectively to obtain N / k third polynomials; use every N / k coefficients in the coefficients of the second polynomial as the coefficients of N / k fourth polynomials respectively to obtain N / k fourth polynomials; combine the N / k third polynomials with the respective fourth polynomials to obtain N / k first MLWE ciphertexts.
[0057] Taking the extraction of MLWE1 and MLWE2 from RLWE1 as an example, for RLWE1 = (a, b), where a = a 0 + a 1 x + a 2 x 2 + a 3 x 3 , b = b 0 + b 1 x + b 2 x 2 + b 3 x 3 , N / k = 2. Therefore, every two coefficients in polynomial a can be used as the coefficients of one polynomial in MLWE1 and ciphertext MLWE2 respectively, that is, a 0 and a 2As the polynomial a in the ciphertext MLWE1 and MLWE2 1 The coefficient of a 1 =a 0 +a 2 x, a 1 and a 3 As the polynomial a in the ciphertext MLWE1 and MLWE2 2 The coefficient of a 2 =a 1 +a 3 x. Similarly, the coefficients of each two terms in the polynomial b can be used as the coefficients of a polynomial in MLWE1 or ciphertext MLWE2, that is, 0 and b 2 The polynomial b as the ciphertext MLWE1 1 The coefficient of b 1 =b 0 +b 2 x, b 1 and b 3 As the polynomial b in MLWE2 2 The coefficient of b 2 =b 1 +b 3 x. Thus we can get:
[0058] MLWE1=(a 1 ,a 2 ,b 1 )
[0059] MLWE2=(a 1 ,a 2 ,b 2 )
[0060] The second party can extract the ciphertexts MLWE3 and MLWE4 corresponding to the third and fourth rows of the matrix V respectively from RLWE2 in the same manner.
[0061] After the second party extracts m MLWE ciphertexts corresponding to n rows of the matrix V from the m RLWE ciphertexts, based on the t elements with a value of 1 included in the Boolean vector, it extracts t MLWE ciphertexts corresponding to the positions of the t elements from the m MLWE ciphertexts, performs homomorphic addition on the t MLWE ciphertexts, and obtains the homomorphic sum of the t MLWE ciphertexts.
[0062] For example, assuming MLWE1 = (a 1 ,a 2 ,b 1 ), MLWE2=(a 1 ,a 2 ,b 2 ), MLWE3=(a3 ,a 4 ,b 3 ), MLWE4=(a 3 ,a 4 ,b 4 ), assuming the Boolean vector is (1,0,1,1) T , then we can extract three MLWE from the four MLWE ciphertexts, MLWE1, MLWE3 and MLWE4, and calculate their homomorphic sum as (a 1 +a 3 +a 3 ,a 2 +a 4 +a 4 ,b 1 +b 3 +b 4 ), where a 1 +a 3 +a 3 Calculate the addition of three polynomials.
[0063] Figure 4 The example shows a schematic diagram of the process of extracting t MLWE ciphertexts and performing homomorphic addition on them.
[0064] like Figure 4 As shown, according to the position of the "1" element in the Boolean vector, MLWE1, MLWE3 and MLWE4 are selected from the four MLWE ciphertexts arranged in sequence, and homomorphic addition is performed on them to obtain the ciphertext MLWE5, which is the ciphertext of the multiplication result of the Boolean vector (1,0,1,1) and the matrix V. According to the additive homomorphism of MLWE encryption, it can be concluded that the plaintext corresponding to the ciphertext MLWE5 is the vector obtained by adding the three row vectors corresponding to MLWE1, MLWE3 and MLWE4, that is, (1+5+7,2+6+8)=(13,16), which is also the multiplication result of (1,0,1,1) and the matrix V. Among them, 13 is also the Boolean vector (1,0,1,1) T and the column vector (1,3,5,7) of matrix V T The inner product result, 16 is the Boolean vector (1,0,1,1) T and the column vector (2,4,6,8) of matrix V T That is to say, by homomorphically adding t MLWE ciphertexts, the inner product of the Boolean vector and the two column vectors of the matrix V is obtained at the same time.
[0065] In the second party include Figure 1In the case of the Boolean matrix M (s rows*n columns) shown in , the process in step S205 can be performed on the s row vectors of the matrix M respectively, so as to obtain s multiplication result ciphertexts (MLWE ciphertexts) arranged in sequence as the ciphertext of the product MV of the Boolean matrix M and the matrix V. For example, Figure 5 As shown, in the case where the matrix M is 2 rows * 4 columns, the two row vectors (1,0,1,1) and (1,1,0,0) in the Boolean matrix M can be respectively executed Figure 4 The process shown in can obtain MLWE5 and MLWE6 arranged in sequence, which correspond to the multiplication results of the row vector (1,0,1,1) and the matrix V, and the multiplication results of the row vector and the matrix V, respectively. For the s MLWE ciphertexts, they can be packaged into RLWE ciphertexts to reduce the communication volume with the first party.
[0066] Figure 6 This is a flow chart of the method for packaging multiple MLWE ciphertexts in this specification.
[0067] like Figure 6 As shown, in step S601, multiple multiplication result ciphertexts corresponding to multiple Boolean vectors in the matrix M are packaged into a second RLWE ciphertext.
[0068] Figure 7 Schematic diagram of the process of packing MLWE ciphertexts. For s MLWE ciphertexts, each N / k MLWE ciphertexts can be packed into one RLWE ciphertext, so as to obtain one or more second RLWE ciphertexts. The packing process can be the reverse process of the aforementioned process of extracting N / k MLWE from RLWE ciphertexts. Specifically, Figure 7 As shown, assuming
[0069] MLWE5=(c 1 ,c 2 ,d 1 )
[0070] MLWE6=(c 1 ,c 2 ,d 2 ),
[0071] Among them, c 1 =c 0 +c 2 x,c 2 =c 1 +c 3 x,d 1 =d 0 +d 2 x,d 2 =d 1 +d 3 x
[0072] Then the ciphertext RLWE3 obtained by packing MLWE5 and MLWE6 is (c, d),
[0073] Where c = c 0 +c 1 x+c 2 x 2 +c 3 x 3 , d = d 0 +d 1 x+d 2 x 2 +d 3 x 3 .
[0074] refer to Figure 7 , the ciphertext RLWE3 corresponds to the plaintext vector (13,16,4,6).
[0075] In step S603, the second party sends the second RLWE ciphertext or the fragmented ciphertext to the first party.
[0076] In one embodiment, after obtaining one or more second RLWE ciphertexts, the second party may send the one or more second RLWE ciphertexts directly to the first party, so that the first party can decrypt the one or more second RLWE ciphertexts in step S605, and obtain the product MV of the matrix M and the matrix V by rearranging the elements in the decrypted vector.
[0077] For example, refer to Figure 8 After the first party decrypts RLWE3 to obtain the plaintext vector (13,16,4,6), it can be rearranged as as the product MV.
[0078] In another embodiment, after obtaining one or more second RLWE ciphertexts, the second party may randomly generate a polynomial space corresponding to The second party can use the homomorphic encryption public key received in advance from the first party to encrypt the polynomial f, and then calculate RLWE3-E(f)=RLWE4, and send RLWE4 to the first party. The first party decrypts RLWE4 to obtain vector g, and vector f and vector g can be used as two plaintext fragments of the product MV. In other words, in this way, the first party and the second party each obtain a plaintext fragment of the product MV.
[0079] Fig. 9 This is a flow chart of a privacy-protecting multi-party data processing method in another embodiment of this specification. The method includes the following steps:
[0080] In step S901, the first party homomorphically encrypts the data in the matrix V to obtain m RLWE ciphertexts corresponding to n column vectors;
[0081] In step S903, the first party sends m RLWE ciphertexts to the second party;
[0082] In step S905, the second party obtains t target ciphertexts based on the m RLWE ciphertexts according to the Boolean vector, and calculates the sum of the t target ciphertexts as the multiplication result ciphertext of the matrix V and the Boolean vector M.
[0083] This method and Figure 2 The method shown is different in that Figure 2 In the method shown, the first party and the second party calculate the multiplication result MV of the Boolean vector M and the matrix V in a privacy-preserving manner, that is, the Boolean vector is on the left side of the multiplication, so each row vector of the matrix V needs to be encrypted, while in this embodiment, the first party and the second party calculate the multiplication result VM of the matrix V and the Boolean vector M in a privacy-preserving manner, that is, the Boolean vector M is on the right side of the multiplication, so each column vector of the matrix V needs to be encrypted.
[0084] Specifically, reference Fig.10 For example, the matrix V is a matrix of 2 rows and 4 columns. The first party can concatenate the first column and the second column of the matrix V into a 4-dimensional vector, encrypt the vector, and obtain the ciphertext RLWE1, concatenate the third column and the fourth column of the matrix V into a 4-dimensional vector, encrypt the vector, and obtain the ciphertext RLWE2, and send the ciphertexts RLWE1 and RLWE2 to the second party.
[0085] After receiving the ciphertexts RLWE1 and RLWE2, the second party can extract the ciphertexts MLWE1, MLWE2, MLWE3 and MLWE4 corresponding to the columns of the matrix V from the ciphertexts RLWE1 and RLWE2, respectively, similarly to the above. Fig.11 , the second party can add the ciphertexts MLWE1, MLWE2, and MLWE4 according to the Boolean vector to obtain the ciphertext MLWE5 of the multiplication result VM of the matrix V and the Boolean vector M.
[0086] The embodiment of the present specification also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed in a computer, the computer is caused to execute the following Figure 2 , Figure 6 or Fig. 9 The method shown.
[0087] The embodiment of the present specification also provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the following is implemented: Figure 2 , Figure 6or Fig. 9 The method shown.
[0088] The embodiments of the present specification also provide a computer program product, including a computer program / instruction, which is executed by a processor to implement the following Figure 2 , Figure 6 or Fig. 9 The steps of the method shown.
[0089] In the data processing scheme of the embodiment of the present specification, the first party may generate multiple RLWE ciphertexts corresponding to the row vectors of the matrix V, and send the multiple RLWE ciphertexts to the second party. The second party may extract n ciphertexts corresponding to the n row vectors of the matrix V from the multiple RLWE ciphertexts, obtain t ciphertexts from the n ciphertexts based on the Boolean vector, and add the t ciphertexts to obtain the ciphertext of the multiplication result of the Boolean vector and the matrix V, with a small amount of calculation and a low calculation cost.
[0090] In the 1990s, improvements to a technology could be clearly distinguished as hardware improvements (for example, improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the method flow). However, with the development of technology, many improvements to the method flow today can be regarded as direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.
[0091] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.
[0092] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a server system. Of course, the present application does not exclude that with the development of computer technology in the future, the computer that implements the functions of the above embodiments may be, for example, a personal computer, a laptop computer, a vehicle-mounted human-computer interaction device, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0093] Although one or more embodiments of the present specification provide method operation steps as described in the embodiments or flow charts, more or less operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way of executing the order of many steps, and does not represent the only execution order. When the device or terminal product in practice is executed, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings (for example, a parallel processor or a multi-threaded processing environment, or even a distributed data processing environment). The term "include", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, product or equipment including a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such a process, method, product or equipment. In the absence of more restrictions, it is not excluded that there are other identical or equivalent elements in the process, method, product or equipment including the elements. For example, if the words first, second, etc. are used to represent the name, they do not represent any specific order.
[0094] For the convenience of description, the above devices are described in various modules according to their functions. Of course, when implementing one or more of the present specification, the functions of each module can be implemented in the same or more software and / or hardware, or the module implementing the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0095] The present invention is described with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0096] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0097] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0098] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0099] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0100] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage, graphene storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0101] It should be understood by those skilled in the art that one or more embodiments of the present specification may be provided as a method, system or computer program product. Therefore, one or more embodiments of the present specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, one or more embodiments of the present specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0102] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0103] Each embodiment in this specification is described in a progressive manner, and the same and similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. In the description of this specification, the description of the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic representation of the above terms does not necessarily target the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples without contradiction.
[0104] The above description is only an example of one or more embodiments of the present specification and is not intended to limit one or more embodiments of the present specification. For those skilled in the art, one or more embodiments of the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims.
Claims
1. A privacy-preserving multi-party data processing method, wherein the multi-party comprises a first party and a second party, wherein the first party has a first matrix comprising n rows, and the second party has a Boolean vector, wherein the method comprises: The first party homomorphically encrypts the data in the first matrix to obtain m first RLWE ciphertexts corresponding to n row vectors of the first matrix, where m is less than or equal to n; and sends the m first RLWE ciphertexts to the second party; The second party obtains t second ciphertexts corresponding to t row vectors of the first matrix respectively based on the Boolean vector and the m first RLWE ciphertexts, and calculates the homomorphic sum of the t second ciphertexts as the ciphertext of the multiplication result of the Boolean vector and the first matrix.
2. The method according to claim 1, wherein the first matrix comprises k columns, The first party homomorphically encrypts the first matrix to obtain m first RLWE ciphertexts corresponding to n row vectors of the first matrix, including: The first party sequentially concatenates each N / k row vectors in the first matrix into N-dimensional row vectors to obtain m N-dimensional row vectors; Perform RLWE homomorphic encryption on the m N-dimensional row vectors respectively to obtain m first RLWE ciphertexts, where the first RLWE ciphertexts correspond to a polynomial space of degree N-1.
3. The method according to claim 2, wherein the second party obtains t second ciphertexts corresponding to t row vectors of the first matrix respectively based on the m first RLWE ciphertexts according to the Boolean vector, comprising: The second party extracts N / k first MLWE ciphertexts from each first RLWE ciphertext to obtain n first MLWE ciphertexts corresponding to the n rows respectively, the first MLWE ciphertexts corresponding to a polynomial space of degree k-1; According to the Boolean vector, the t first MLWE ciphertexts are obtained from the n first MLWE ciphertexts as the t second ciphertexts.
4. The method according to claim 3, wherein the first RLWE ciphertext comprises a first polynomial and a second polynomial, and the second party extracting N / k first MLWE ciphertexts from each first RLWE ciphertext comprises: The second party uses each N / k coefficients of the coefficients of the first polynomial as coefficients of N / k third polynomials, respectively, to obtain N / k third polynomials; uses each N / k coefficients of the coefficients of the second polynomial as coefficients of N / k fourth polynomials, respectively, to obtain N / k fourth polynomials; The N / k third polynomials are respectively combined with each fourth polynomial to obtain N / k first MLWE ciphertexts.
5. The method according to claim 4, wherein the second party has a Boolean matrix, the Boolean vector is a row vector in the Boolean matrix, The calculating the homomorphic sum of the t second ciphertexts as the ciphertext of the multiplication result of the Boolean vector and the first matrix includes: For each Boolean vector in the plurality of Boolean vectors arranged sequentially in the Boolean matrix, calculate a homomorphic sum of t second ciphertexts to obtain a third ciphertext; The method further comprises: The second party packages each N / k third ciphertexts among the multiple third ciphertexts into an RLWE ciphertext to obtain one or more second RLWE ciphertexts, and sends the one or more second RLWE ciphertexts to the first party.
6. The method according to claim 5, further comprising: The first party decrypts the one or more second RLWE ciphertexts, and obtains a multiplication result of the Boolean matrix and the first matrix based on the decryption result.
7. A privacy-preserving multi-party data processing method, wherein the multi-party comprises a first party and a second party, wherein the first party has a first matrix comprising n rows, and the second party has a Boolean vector, wherein the method is performed by the first party, comprising: Performing homomorphic encryption on the data in the first matrix to obtain m first RLWE ciphertexts corresponding to the n row vectors of the first matrix; Sending the m first RLWE ciphertexts to the second party; A ciphertext of a multiplication result of the Boolean vector and the first matrix is received from the second party, where the ciphertext of the multiplication result is obtained based on a homomorphic sum of t second ciphertexts, where the t second ciphertexts correspond to t row vectors of the first matrix, respectively, and are obtained based on the Boolean vector and the m first ciphertexts.
8. A privacy-preserving multi-party data processing method, the multi-party comprising a first party and a second party, the first party having a first matrix comprising n rows, the second party having a Boolean vector, the method being performed by the second party, comprising: receiving m first RLWE ciphertexts from the first party, the m first RLWE ciphertexts being homomorphically encrypted ciphertexts corresponding to n row vectors of the first matrix; According to the Boolean vector, t second ciphertexts corresponding to the t row vectors of the first matrix are obtained based on the m first RLWE ciphertexts, and the homomorphic sum of the t second ciphertexts is calculated as the ciphertext of the multiplication result of the Boolean vector and the first matrix.
9. A privacy-preserving multi-party data processing method, wherein the multi-party comprises a first party and a second party, wherein the first party has a first matrix comprising n columns, and the second party has a Boolean vector, wherein the method comprises: The first party homomorphically encrypts the data in the first matrix to obtain m first RLWE ciphertexts corresponding to n column vectors of the first matrix, where m is less than or equal to n; and sends the m first RLWE ciphertexts to the second party; The second party obtains t second ciphertexts corresponding to t column vectors of the first matrix respectively based on the m first RLWE ciphertexts according to the Boolean vector, and calculates the homomorphic sum of the t second ciphertexts as the ciphertext of the multiplication result of the first matrix and the Boolean vector.
10. A computing device comprising a memory and a processor, wherein the memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 1 to 9 is implemented.
Citation Information
Cited By
Data hiding query method and system
CN120448431A