Method and device for executing encryption matrix multiplication among multiple parties

By encoding the subpolynomials in the matrix into large polynomials and using dense state multiplication between the large polynomials, the problem of high cost in multiplication in multiple parties in the era of encrypted matrix multiplication is solved, and the computing performance is improved.

CN119960725APending Publication Date: 2025-05-09ALIPAY (HANGZHOU) INFORMATION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411834143.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

In secure multi-party computing, multi-party execution of encryption matrix multiplication is relatively expensive in the era, affecting the computing performance.

Method used

By dividing the subpolynomials in the matrix into groups and encoding the subpolynomials of each group into large polynomials, the dense multiplication between the majority polynomials is used instead of multiplication between multiple subpolynomials.

Benefits of technology

It significantly reduces the cost of multi-party execution of encrypted matrix multiplication and improves the performance of encrypted matrix multiplication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119960725A_ABST
    Figure CN119960725A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method and device for executing encryption matrix multiplication among multiple parties. Wherein elements in the first matrix owned by the first party and the first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding a plurality of numerical elements. The first party divides a plurality of sub-polynomials contained in the first matrix into a plurality of groups, so that the sub-polynomials in any first group meet the following conditions: no addition relationship exists in matrix multiplication, and a corresponding multiplication relationship exists between the sub-polynomials and the sub-polynomials in the first vector. Next, the first party encodes the plurality of sub-polynomials of the first group into a first large polynomial. Meanwhile, the second party encodes a plurality of sub-polynomials contained in the first vector into a second large polynomial; and executing multiplication between the first large polynomial and the second large polynomial between the first party and the second party through data interaction based on secure multi-party calculation to obtain a first sub-result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present specification relate to the field of computer technology, and more particularly, to a method and apparatus for performing encrypted matrix multiplication between multiple parties. Background Art

[0002] Secure Multi-Party Computation (MPC) is a cryptographic technology that allows multiple parties to jointly perform calculations and analyses while maintaining the privacy of their respective data. The core idea is to use cryptographic technology and algorithms to encrypt the data of each participant and then perform model calculations to ensure that each participant can only obtain the data and calculation results they need, and cannot obtain the original data of other participants. In the relevant calculations of neural networks, matrix multiplication is a high-frequency operation when multiple parties jointly perform model calculations, and its cost is relatively high.

[0003] Therefore, it is hoped that there will be an improved scheme that can reduce the cost of performing encrypted matrix multiplication by multiple parties. Summary of the invention

[0004] One or more embodiments of this specification describe a method and device for performing encrypted matrix multiplication between multiple parties to reduce the cost of performing encrypted matrix multiplication between multiple parties and improve the performance of encrypted matrix multiplication. The specific technical solution is as follows.

[0005] In a first aspect, an embodiment provides a method for performing encrypted matrix multiplication between multiple parties, wherein elements in a first matrix owned by a first party and a first vector owned by a second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; the method comprises:

[0006] The first party divides the multiple sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively; encodes the multiple sub-polynomials in the first group into a first large polynomial;

[0007] The second party encodes a plurality of sub-polynomials included in the first vector into a second large polynomial;

[0008] The first party and the second party perform multiplication between the first large polynomial and the second large polynomial through data interaction based on secure multi-party computing to obtain a first sub-result.

[0009] In a second aspect, an embodiment provides a method for performing encrypted matrix multiplication between multiple parties, wherein elements in a first matrix owned by a first party and a first vector owned by a second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; the method is performed by the first party, and includes:

[0010] Divide the multiple sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between each of the sub-polynomials in the first vector;

[0011] encoding the plurality of sub-polynomials of the first group into a first large polynomial;

[0012] Through data interaction with the second party based on secure multi-party computing, multiplication between the first large polynomial and the second large polynomial is performed to obtain a first sub-result; wherein the second large polynomial is obtained by the second party encoding several sub-polynomials contained in the first vector.

[0013] In one implementation, the step of dividing the plurality of sub-polynomials included in the first matrix into a plurality of groups comprises:

[0014] Based on the number of rows and columns corresponding to any sub-polynomial in the first matrix, and in accordance with a preset rule of the number of rows and columns for each group, a sub-polynomial is selected from each row and each column to form a group.

[0015] In one implementation, the plurality of subpolynomials in the first group are obtained by encoding with different moduli; and the first matrix is ​​obtained by:

[0016] For a block circulant matrix containing multiple sub-blocks, multiple sub-blocks in the row are respectively encoded into corresponding sub-polynomials using the modulus corresponding to each row, and the moduli of different rows are different.

[0017] In one embodiment, the step of encoding the plurality of sub-polynomials of the first group into a first large polynomial includes: multiplying the moduli of the plurality of sub-polynomials of the first group to obtain the modulus of the first large polynomial to be encoded;

[0018] Based on the modulus of the first large polynomial and in combination with the Chinese remainder theorem, multiple sub-polynomials of the first group are encoded to obtain the first large polynomial.

[0019] In one embodiment, the moduli of the several sub-polynomials included in the first vector are respectively the same as the moduli of the corresponding sub-polynomials in the first group. When there is a multiplication relationship between the sub-polynomials in the first vector and the sub-polynomials in the first group, the two correspond to each other.

[0020] In one implementation, the first vector is obtained by encoding the sub-blocks in the first sub-block vector that are in a multiplication relationship with the sub-polynomial using the modulus of the sub-polynomial included in the first group; the plurality of groups also include a second group; and the method further includes:

[0021] encoding the plurality of subpolynomials included in the second group into a third largest polynomial;

[0022] By performing data interaction with the second party based on secure multi-party computing, multiplication between the third large polynomial and the fourth large polynomial is obtained to obtain a second sub-result;

[0023] Among them, the fourth large polynomial is obtained by the second party encoding several sub-polynomials contained in the second vector, and the second vector is obtained by using the modulus of the sub-polynomial contained in the second group to encode the sub-block in the first sub-block vector that has a multiplication relationship with the sub-polynomial.

[0024] In one embodiment, the method further comprises:

[0025] Decrypting the encrypted large polynomial sum of the first sub-result and the second sub-result to obtain the large polynomial sum;

[0026] Decoding the large polynomial and value to obtain a plurality of sub-polynomials;

[0027] The obtained multiple sub-polynomials are decoded respectively, and a product result between the block circulant matrix and the first sub-block vector is determined based on the decoding results.

[0028] In a third aspect, an embodiment provides a method for performing encrypted matrix multiplication between multiple parties, wherein elements in a first matrix owned by a first party and a first vector owned by a second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; the method is performed by the second party, and includes:

[0029] Encoding a plurality of sub-polynomials included in the first vector into a second large polynomial;

[0030] By performing data interaction with the first party based on secure multi-party computing, multiplication between the first large polynomial and the second large polynomial is obtained to obtain a first sub-result;

[0031] Among them, the first large polynomial is obtained by the first party encoding multiple sub-polynomials of any first group among several groups, and the several groups are obtained by the first party dividing multiple sub-polynomials contained in the first matrix, and the sub-polynomials in the first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively.

[0032] In one embodiment, the plurality of subpolynomials in the first group are obtained by encoding with different moduli, and the first matrix is ​​obtained by encoding a subblock in a block circulant matrix including a plurality of subblocks;

[0033] The moduli of the several sub-polynomials included in the first vector are respectively the same as the moduli of the corresponding sub-polynomials in the first group. When there is a multiplication relationship between the sub-polynomials in the first vector and the sub-polynomials in the first group, the two correspond to each other.

[0034] In one implementation, the first vector is obtained in the following manner:

[0035] Based on the sub-block partitioning method of the block circulant matrix, the second original matrix is ​​correspondingly divided into a plurality of sub-blocks;

[0036] Taking out a first sub-block vector including a plurality of sub-blocks from the second original matrix;

[0037] Using the modulus of the sub-polynomial included in the first group, encoding the sub-blocks in the first sub-block vector that are in a multiplication relationship with the sub-polynomial into a sub-polynomial to obtain a first vector;

[0038] The plurality of groups also include a second group, and the method further includes:

[0039] Using the modulus of the sub-polynomial included in the second group, the sub-blocks in the first sub-block vector that are in a multiplication relationship with the sub-polynomial are encoded as sub-polynomials to obtain a second vector.

[0040] In one embodiment, the method further comprises:

[0041] Encoding a plurality of sub-polynomials included in the second vector into a fourth polynomial;

[0042] By exchanging data with the first party based on secure multi-party computing, multiplication between the third large polynomial and the fourth large polynomial is performed to obtain a second sub-result; wherein the third large polynomial is obtained by the first party encoding several sub-polynomials included in the second group.

[0043] In one embodiment, the method further comprises:

[0044] Decrypting the secret state large polynomial sum of the first sub-result and the second sub-result to obtain the large polynomial sum;

[0045] Decoding the large polynomial and value to obtain a plurality of sub-polynomials;

[0046] The plurality of sub-polynomials are decoded respectively, and a product result between the block circulant matrix and the first sub-block vector is determined based on the decoding results.

[0047] In a fourth aspect, an embodiment provides a system for performing encrypted matrix multiplication between multiple parties, including a first party and a second party, wherein elements in a first matrix owned by the first party and a first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements;

[0048] The first side is used to divide the multiple sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively; encode the multiple sub-polynomials in the first group into a first large polynomial;

[0049] The second party is used to encode the plurality of sub-polynomials included in the first vector into a second large polynomial;

[0050] The first party and the second party are configured to perform multiplication between the first large polynomial and the second large polynomial through data interaction based on secure multi-party computing to obtain a first sub-result.

[0051] In a fifth aspect, an embodiment provides a device for performing encrypted matrix multiplication between multiple parties, wherein elements in a first matrix owned by a first party and a first vector owned by a second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; the device is deployed in the first party, and includes:

[0052] A first grouping module is configured to divide the plurality of sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between each of the sub-polynomials in the first vector;

[0053] A first encoding module, configured to encode the plurality of sub-polynomials of the first group into a first large polynomial;

[0054] The first multiplication module is configured to perform multiplication between the first large polynomial and the second large polynomial through data interaction with the second party based on secure multi-party computing to obtain a first sub-result; wherein the second large polynomial is obtained by the second party encoding several sub-polynomials contained in the first vector.

[0055] In a sixth aspect, an embodiment provides a device for performing encrypted matrix multiplication between multiple parties, wherein the elements in a first matrix owned by a first party and a first vector owned by a second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; the device is deployed in the second party, and includes:

[0056] A second encoding module, configured to encode a plurality of sub-polynomials included in the first vector into a second large polynomial;

[0057] a second multiplication module, configured to perform multiplication between the first large polynomial and the second large polynomial through data interaction with the first party based on secure multi-party computing to obtain a first sub-result;

[0058] Among them, the first large polynomial is obtained by the first party encoding multiple sub-polynomials of any first group among several groups, and the several groups are obtained by the first party dividing multiple sub-polynomials contained in the first matrix, and the sub-polynomials in the first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively.

[0059] In a seventh aspect, an embodiment provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute any one of the methods in the first to third aspects.

[0060] In an eighth aspect, an embodiment provides a computing device, comprising a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method described in any one of the first to third aspects is implemented.

[0061] In the method and device provided in the embodiments of this specification, the first party divides multiple sub-polynomials in the first matrix into several groups, encodes multiple sub-polynomials in any first group into a first large polynomial, and the second party encodes multiple sub-polynomials contained in the first vector into a second large polynomial. Through data interaction between the two parties based on secure multi-party computing, a single secret multiplication between the first large polynomial and the second large polynomial is used to replace multiple multiplications between multiple sub-polynomials in the first group and multiple sub-polynomials in the first vector, thereby reducing the cost when multiple parties perform encrypted matrix multiplication and improving the performance of encrypted matrix multiplication. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0063] Figure 1 A schematic diagram of an implementation scenario of an embodiment disclosed in this specification;

[0064] Figure 2 is the circulant matrix w 11 With the matrix x 1 A schematic diagram of a process for encoding and multiplying;

[0065] Figure 3 is the matrix W 1 With the matrix X 1 A schematic diagram of matrix multiplication between vectors in ;

[0066] Figure 4 The block circulant matrix Q provided in the embodiment 1 and the first sub-block vector H 1 A schematic diagram of a principle when encoding the sub-blocks in;

[0067] Figure 5 A flowchart of a method for performing encrypted matrix multiplication between multiple parties provided in an embodiment;

[0068] Figure 6 The first matrix provided for the implementation example With the first sub-block vector H 1 A flowchart of dense matrix multiplication between ;

[0069] Figure 7 A schematic block diagram of a system for performing encrypted matrix multiplication between multiple parties is provided for an embodiment;

[0070] Figure 8 A schematic block diagram of an apparatus for performing encrypted matrix multiplication between multiple parties provided in an embodiment;

[0071] Fig. 9 A schematic block diagram of an apparatus for performing encrypted matrix multiplication between multiple parties is provided in accordance with an embodiment. DETAILED DESCRIPTION

[0072] The solution provided in this specification is described below in conjunction with the accompanying drawings.

[0073] Figure 1The present invention is a schematic diagram of an implementation scenario of an embodiment disclosed in this specification. It includes a first party A, a second party B and a third party C. Multiple parties need to perform secret matrix multiplication based on MPC. Multiple parties encode and encrypt their own matrices respectively, that is, encode the elements in the matrix into multiple sub-polynomials, encode the multiple sub-polynomials into a large polynomial, and homomorphically encrypt the large polynomial. In this way, multiple parties can perform matrix multiplication based on the secret large polynomial. Encoding multiple sub-polynomials into a large polynomial can reduce the number of multiplications, thereby reducing the cost of secret matrix multiplication. Figure 1 The multiple participants are just an example. In actual applications, the number of participants can be 2 or more.

[0074] The first party, the second party, and the third party can perform secret matrix multiplication through their respective computing devices. Secret matrix multiplication means that when each party sends private data such as matrices to other parties, they are all sent in the form of secret matrices to protect data privacy from being leaked. The computing device can be implemented by any device, equipment, platform, device cluster, etc. with computing and processing capabilities.

[0075] Matrix multiplication performed jointly by multiple parties can occur in model calculation, sample data processing, and other processes. The following uses model calculation as an example to illustrate. In one application scenario, one party owns the model and one party owns the data, and multiple parties need to jointly calculate the product of the model parameter matrix and the data matrix. In other application scenarios, at least one party owns private data and part of the model, and one party owns the remaining part of the model, and multiple parties need to jointly perform matrix calculations between multiple computing layers in the model.

[0076] The following example uses the joint execution of model calculation by two parties, where the first party A has a weight matrix W and the second party B has a data matrix X. The elements in these two matrices are all numerical values, that is, the matrices contain numerical elements. For a linear layer in a neural network model, the linear layer can be a convolutional layer or a fully connected layer. Taking the fully connected layer as an example, the linear layer needs to calculate the weight matrix W*data matrix X. In order to protect the privacy data from being leaked, the first party A and the second party B cannot send the plaintext W or the plaintext X to each other, so the two parties can use MPC to jointly perform dense matrix multiplication.

[0077] MPC can include algorithms such as homomorphic encryption, secret sharing, zero-knowledge proof, oblivious transfer, and obfuscated circuits. Among them, homomorphic encryption and secret sharing can be applied to perform secret matrix multiplication. The following uses the homomorphic encryption algorithm as an example to illustrate an implementation process of joint secret matrix multiplication between multiple parties.

[0078] The homomorphic encryption algorithm here can be a fully homomorphic encryption algorithm. Fully homomorphic encryption is a new type of encryption algorithm. The decryption result of the sum (or product) of two ciphertexts is equal to the sum (or product) of the plaintexts. The plaintext domain of fully homomorphic encryption is mod x n +1 polynomial, and each coefficient mod t. That is, in the fully homomorphic encryption algorithm, each data needs to be encoded into the specified domain space corresponding to the plaintext domain. For example, n = 8, t = 7, Encrypt(x 2 +8)+Encrypt(x 3 +1)=Encrypt(x 3 +x 2 +2), that is, the polynomial x 2 +8 ciphertext and polynomial x 3 +1 is equal to the encryption of the plaintext and the two polynomials. In the calculation process, the multiplication and addition between polynomials must be modulo x. n +1, coefficient mod t.

[0079] Encoding the circulant matrix into a polynomial can simplify matrix multiplication. For example, the domain space is specified with n=8 and t=7. Figure 2 is the circulant matrix w 11 With the matrix x 1 A schematic diagram of the process of encoding and multiplication. Among them, the matrix w 11 and x 1 The numerical elements in Figure 2 As shown in the numbers in the box in , the result of directly multiplying the two matrices is Figure 2 As shown in the upper part. 11 is a b-order circulant matrix, whose elements 1 and 2 are symmetrically used as coefficients of x from 0 to 7 powers, that is, as x 0 and x 4 The coefficients of Change b to d 1 The matrix x of columns 1 Each element of is used as the coefficient of each power x in turn, and the encoded Multiply the two encoded polynomials and mod x n +1, get

[0080]

[0081] The polynomial in the above formula is the result after taking the modulus. After decoding, we can get y 11 , that is, y 11 =w 11 × 1 .right The decoding process is from Read the corresponding coefficients from the polynomial as the circulant matrix w 11 With the matrix x 1 The elements in the product matrix of .

[0082] When the polynomial After homomorphically encrypting them separately and then multiplying them, it is equivalent to multiplying the plaintexts of the two and then encrypting them. Figure 2 The method is applied in dense matrix multiplication, that is, the circulant matrix is ​​encoded as a polynomial. There is no need to do complex matrix multiplication, only a polynomial multiplication is needed to get the result.

[0083] For a weight matrix W with e rows and f columns, the first party A can split the weight matrix W into multiple sub-blocks with b rows and b columns based on the modulus n during encoding, that is, it can be split into (e / b)*(f / b) sub-blocks. It is assumed here that e and f are divisible by b. If e and f are not divisible by b, the weight matrix W can be filled with 0. In addition, b should be divisible by mod x n +1, and is smaller than n. Generally speaking, n is a multiple of b. The weight matrix W after block division is fine-tuned into a block circulant matrix, that is, the sub-block w 11 It is a circulant matrix. Specifically, the weight matrix W can be fine-tuned during the training of the neural network model, so that it is called a block circulant matrix. The block circulant matrix contains multiple sub-blocks, each of which is a circulant matrix, and the elements in each sub-block are still numerical elements. In other words, the block circulant matrix is ​​still a matrix containing numerical elements.

[0084] For a data matrix X with f rows and g columns, it can be split into multiple sub-blocks according to the dimension of b*d1, including sub-block x 1 It is b*d1 dimensional, where b*d1=n. The data matrix X contains multiple sub-blocks, and the elements in each sub-block are still numerical elements. In other words, the data matrix X containing multiple sub-blocks is still a matrix of numerical elements.

[0085] After the above processing, the sub-blocks in the block circulant matrix and the block-divided data matrix X can be Figure 2 The matrix W with polynomials as elements is obtained. 1 and the matrix X 1 , and calculate the matrix W 1 and the matrix X 1 Dense matrix multiplication between .

[0086] Figure 3 is the matrix W 1 With the matrix X 1 A schematic diagram of matrix multiplication between vectors in . Among them, the matrix W 1is a 3*3 dimensional matrix with polynomials as elements owned by the first party A, and vector is a 3*1 dimensional column vector with polynomials as elements owned by the second party B. Nine multiplications need to be performed between the first party A and the second party B, that is, multiplications between nine groups of polynomials.

[0087] When the matrix W 1 When the order of is higher, the number of multiplications between polynomial elements becomes large, and the cost of dense matrix multiplication is high.

[0088] In order to reduce the cost of performing encrypted matrix multiplication between multiple parties, the present specification provides a method for performing encrypted matrix multiplication between multiple parties. The method uses the Chinese remainder theorem to encode sub-blocks in a block circulant matrix into sub-polynomials, and divides multiple sub-polynomials into several groups according to certain requirements, encodes multiple sub-polynomials in the group into large polynomials, and uses encrypted multiplication between large polynomials to replace multiplication between multiple sub-polynomials, thereby reducing the number of multiplications and reducing the cost of encrypted matrix multiplication.

[0089] The above content is explained using the weight matrix W and the data matrix X as examples. In practical applications, the first party A and the second party B can calculate the dense matrix multiplication between any first original matrix Q and second original matrix H. Among them, the first party A has the first original matrix Q (e*f dimension), and the second party B has the second original matrix H (f*g dimension). The first original matrix Q and the second original matrix H are matrices that can be multiplied, and there is a relationship between the matrix dimensions. The elements in the first original matrix Q and the second original matrix H are numerical elements (that is, the elements are numerical values), not polynomial elements. n=8 and t=7 in the above plaintext domain are also examples, and other values ​​can be taken in practical applications.

[0090] The method of this embodiment may include a process of encoding matrix elements and a process of dense matrix multiplication. The following first describes the process of encoding matrix elements.

[0091] The first party A may divide the first original matrix Q into a plurality of sub-blocks according to the selected order b, and fine-tune the first original matrix Q including the plurality of sub-blocks to obtain a block circulant matrix Q 1 . Among them, the block circulant matrix Q 1 It contains multiple sub-blocks, each of which is a circulant matrix, and the elements in each sub-block are numerical elements. Block circulant matrix Q 1 is a matrix of numerical elements of dimension i*j, where i=e / b and j=f / b.

[0092] A circulant matrix is ​​a square matrix with the same number of rows and columns. A circulant matrix is ​​a special form of matrix in which each row is a cyclic shift of the previous row. Specifically, if the first row of a matrix is ​​[a 0 ,a 1,a 2 ,…,a b-1 ], then the second line is [a b-1 ,a 0 ,a 1 ,…,a b-2 ], the third line is [a b-2 ,a b-1 ,a 0 ,…,a b-3 ], and so on.

[0093] For example, the matrix shown in Table 1 is a 4*4 circulant matrix.

[0094] Table 1

[0095] -1.39 0.06 1.56 0.36 0.36 -1.39 0.06 1.56 1.56 0.36 -1.39 0.06 0.06 1.56 0.36 -1.39

[0096] The second party B is based on the block circulant matrix Q 1 The sub-block division method is based on b*d 1 The dimension (b*d 1 = n) the second original matrix H is correspondingly divided into a number of sub-blocks, and the first sub-block vector H containing the sub-blocks is taken out from the second original matrix H 1 (The dimension is j*1). The second original matrix H containing multiple sub-blocks may contain one or more sub-block vectors. The first sub-block vector H 1 Is any one of them. The first sub-block vector H 1 The elements in are numerical values, that is, they are numerical element vectors. b, d 1 and n are public data, not private data, and are shared by both parties. n can be a relatively large integer.

[0097] Next, we need to treat the block circulant matrix Q to be multiplied 1 and the first sub-block vector H 1 When performing matrix multiplication, according to the definition of matrix multiplication, the block circulant matrix Q 1 There is an additive relationship between each row of sub-blocks in the first sub-block vector H 1 The sub-blocks and block circulant matrix Q in 1 There is a multiplication relationship between the corresponding sub-blocks.

[0098] Figure 4 The block circulant matrix Q provided in the embodiment 1 and the first sub-block vector H 1 A schematic diagram of the principle of encoding the sub-blocks in . The numbers in the boxes represent the sub-block numbers, and the block circulant matrix Q 1 Each sub-block in is a b*b dimensional circulant matrix of numerical elements. The first sub-block vector H 1 Each sub-block in is b*d1 There is an additive relationship between sub-blocks 1, 2, and 3, an additive relationship between sub-blocks 4, 5, and 6, and an additive relationship between sub-blocks 7, 8, and 9, that is, the block circulant matrix Q 1 There is an additive relationship between sub-blocks in the same row. There is a multiplication relationship between sub-block 10 and sub-blocks 1, 4 and 7, there is a multiplication relationship between sub-block 11 and sub-blocks 2, 5 and 8, and there is a multiplication relationship between sub-block 12 and sub-blocks 3, 6 and 9, that is, the block circulant matrix Q 1 The sub-block in and the first sub-block vector H 1 There is a multiplication relationship between the corresponding sub-blocks in . The addition relationship and the multiplication relationship are based on the definition of matrix multiplication.

[0099] When encoding, multiple sub-blocks select different moduli (mod). For example, for the block circulant matrix Q 1 For example, the sub-blocks in the same row are encoded with the same modulus, and the sub-blocks in different rows are encoded with different moduli. The modulus corresponding to each row is used to encode the multiple sub-blocks in the row into corresponding sub-polynomials. Moreover, the moduli of different rows are different, and a total of i moduli are required. In this way, the block circulant matrix Q 1 After encoding the sub-blocks in The first matrix is ​​an i*j dimensional matrix, the elements of which are subpolynomials.

[0100] For the first sub-block vector H 1 For example, it needs to be encoded into i sets. Since the block circulant matrix Q 1 Different rows of sub-blocks in the byte array use different modulus codes. When the first sub-block vector H 1 The sub-blocks and block circulant matrix Q in 1 When there is a multiplication relationship between the sub-blocks in , the same modulus encoding is required, so the first sub-block vector H 1 The sub-blocks in are encoded into i sets.

[0101] by Figure 4 For example, the block circulant matrix Q 1 Different rows of sub-blocks are encoded using moduli mod1, mod2 and mod3 respectively. The first sub-block vector H 1 Each sub-block in is encoded using mod1, mod2, and mod3. In order to facilitate the correspondence, the block circulant matrix Q 1 The sub-blocks in the first sub-block are divided into different groups, and the sub-blocks in each group are encoded using different moduli. That is, the first group includes sub-blocks 1, 5, and 9, the second group includes sub-blocks 2, 6, and 7, and the third group includes sub-blocks 3, 4, and 8. At the same time, the first sub-block vector H 1 The sub-blocks in are divided into different groups accordingly, and each group is encoded using a different modulus.

[0102] After encoding the sub-blocks using the corresponding modulus, the block circulant matrix Q 1 The first matrix is ​​obtained First Matrix The dimension is i*j, and each element is a subpolynomial. From the first sub-block vector H 1 The corresponding different groups get the first vector Second vector and the third vector The dimension of each vector is a column vector of size j*1, and the elements are subpolynomials. Block circulant matrix Q 1 are respectively able to be related to the first vector Second vector and the third vector There is a relationship between the matrices and the dimensions of the matrices to be multiplied. Moreover, any sub-polynomial is obtained by encoding the corresponding sub-block, and specifically, the sub-polynomial is obtained by encoding the numerical elements in the sub-block.

[0103] The modulus can be x n -1,x n +1, x n +2, etc. For example, when n=4, multiple moduli can be 4 -1,x 4 +1, x 4 +2, multiple moduli use the same n value. In practical applications, n can be a large integer, such as 32768. Multiple moduli are plain text data and can be obtained by all parties.

[0104] The above is the encoding process of matrix elements. The dense matrix multiplication process is explained below.

[0105] To compute the dense matrix multiplication between the first original matrix Q owned by the first party A and the second original matrix H owned by the second party B, it can be converted to compute the block circulant matrix Q 1 Dense matrix multiplication with a second original matrix H containing multiple sub-blocks, including computing the block circulant matrix Q 1 With the first sub-block vector H 1 Dense matrix multiplication of . Calculate Q 1 With H 1 The dense matrix multiplication of Respectively with the first vector Second vector and the third vector The core calculation is to perform the first matrix With any vector (with the first vector For example, the dense matrix multiplication between Figure 5 The embodiments are described in detail.

[0106] Figure 5 A flowchart of a method for performing encrypted matrix multiplication between multiple parties is provided in an embodiment. In which, the first party A has a first matrix The second party B has the first vector The elements are all sub-polynomials obtained by encoding numerical elements. Sub-polynomials can also be called small polynomials, where sub or small is relative to the subsequent large polynomial. The method includes the following steps.

[0107] Step S510: The first party A converts the first matrix The multiple sub-polynomials contained are divided into several groups, so that the sub-polynomials in any first group satisfy the following conditions: there is no additive relationship in matrix multiplication, and they are respectively related to the first vector There is a corresponding multiplication relationship between the sub-polynomials in .

[0108] As mentioned earlier, the first matrix The multiple sub-polynomials in the same row are encoded by the same modulus, and the moduli in different rows are different. When selecting between the multiple sub-polynomials according to the above conditions, it can be known that the multiple sub-polynomials in any first group are encoded by different moduli. In other words, the multiple sub-polynomials in the same group have different corresponding moduli.

[0109] exist Figure 4 As mentioned in the previous section, the block circulant matrix Q 1 There is an additive relationship between each row of sub-blocks in the first sub-block vector H 1 The sub-blocks and block circulant matrix Q in 1 There is a multiplication relationship between the corresponding sub-blocks. After encoding, the first matrix There is an additive relationship between the subpolynomials in each row of , and the first vector The polynomial and the first matrix in There is a multiplication relationship between the corresponding sub-polynomials of . In the above conditions, there is no addition relationship between the sub-polynomials in the first group, that is, it is required that the multiple sub-polynomials in the first group belong to the first matrix The multiplication relationship in the above conditions refers to the multiplication relationship in the definition of matrix multiplication.

[0110] When the first matrix When is a square matrix, multiple sub-polynomials can be divided into i groups, where is the number of rows or columns of the square matrix, and each group contains i sub-polynomials. Figure 4 Here, we take a 3*3 polynomial matrix as an example to illustrate the grouping method, see Table 2.

[0111] Table 2

[0112]

[0113] Among them, the second column on the left in Table 2 lists the first matrix in tabular form The position of each polynomial element in, such as Q 11 represents the polynomial in the first row and first column of the matrix. The first column on the left is the modulus used by each row of the matrix. It can be seen that the three polynomials in each group are selected from two rows respectively, and the multiple polynomials in each group are arranged in the order of the number of rows. Of course, this arrangement order is not unique, as long as it is consistent with the first vector The polynomials in the corresponding multiplication relationship can be used. The first column on the right is the first vector Contains multiple subpolynomials H 11 , H 21 and H 31 .

[0114] Here, the first matrix The case of a square matrix (i.e., i=j) is used as an example. When it is not a square matrix, that is, i is not equal to j, the number of subpolynomials in the first group can be equal to the smaller of the number of rows i and the number of columns j.

[0115] In this step S510, based on the first matrix The number of rows and columns corresponding to any sub-polynomial in the matrix is ​​determined by selecting a sub-polynomial from each row and column to form a group according to the preset number of rows and columns for each group. Or, for the first matrix The multiple sub-polynomials in the first group are judged respectively whether the sub-polynomial to be added to the first group meets the above conditions. If it meets the conditions, it is added to the first group. If it does not meet the conditions, it is not added. That is, each sub-polynomial is added to each group one by one by judging.

[0116] In step S520, the first party A encodes the first group of multiple sub-polynomials into a first large polynomial.

[0117] When this step is executed, multiple sub-polynomials can be encoded into a large polynomial, i.e., the first large polynomial, in a variety of ways. In one embodiment, the moduli of the multiple sub-polynomials of the first group can be multiplied to obtain the modulus of the first large polynomial to be encoded, and based on the modulus of the first large polynomial, combined with the Chinese remainder theorem, the multiple sub-polynomials of the first group are encoded to obtain the first large polynomial. Alternatively, based on the modulus of the first large polynomial, combined with the extended Chinese remainder theorem, the multiple sub-polynomials of the first group can be encoded to obtain the first large polynomial. The specific implementation process can refer to the existing methods, which will not be repeated here.

[0118] By using the moduli of the multiple sub-polynomials of the first group and taking the moduli of the first large polynomial respectively, the corresponding sub-polynomials can be obtained respectively.

[0119] For example, the two subpolynomials are -x 3 and x 3 When the modulus is x 4 +1 and x 4 -1, after encoding these two polynomials, we get the large polynomial x 7 At the same time, use x 4 +1 to x 7 Modulo, we can get -x 3 , that is, x 7 mod x 4 +1 = -x 3 . Use x 4 -1 pair x 7 Modulo, we can get x 3 , that is, x 7 mod x 4 -1 = x 3 .

[0120] The moduli of multiple sub-polynomials in the same group (for example, the first group) are different. This is required to encode multiple sub-polynomials in the same group into a large polynomial, which is also required by the Chinese remainder theorem. The first matrix The multiple sub-polynomials in the same row are encoded by the same modulus because there is an additive relationship between the multiple sub-polynomials in the same row. The sub-polynomials encoded by the same modulus can be added.

[0121] Step S530: The second party B converts the first vector The contained sub-polynomials are encoded as the second largest polynomial.

[0122] First Vector The multiple sub-polynomials in are respectively multiplied with the multiple sub-polynomials in the first group. However, in this embodiment, the first vector in is not The multiple sub-polynomials in the first group are correspondingly multiplied, or encrypted and correspondingly multiplied.

[0123] First Vector The moduli of the sub-polynomials contained in are the same as the moduli of the corresponding sub-polynomials in the first group. The correspondence here means that when the first vector When there is a multiplication relationship between the sub-polynomials in and the sub-polynomials in the first group, the two correspond to each other. And the first vector The moduli of the sub-polynomials are different. For example, the sub-polynomials of the first group are Q 11 , Q 22 and Q 33 , whose moduli are mod1, mod2 and mod3 respectively. The corresponding first vector The sub-polynomials included are H 11 , H 21 and H 31 , whose moduli are mod1, mod2 and mod3 respectively.

[0124] When this step is executed, the first vector The modulus of the second largest polynomial to be encoded is obtained by multiplying the moduli of the multiple sub-polynomials in the first vector. Based on the modulus of the second largest polynomial and the Chinese remainder theorem, Alternatively, the first vector can be encoded by combining the modulus of the second largest polynomial and the extended Chinese remainder theorem. The multiple sub-polynomials in are encoded to obtain the second largest polynomial. The specific implementation process can refer to the existing method and will not be repeated here.

[0125] The above steps S530 and S520 are performed in no particular order.

[0126] Step S540: The first party A and the second party B perform multiplication between the first large polynomial and the second large polynomial through MPC-based data interaction to obtain a first sub-result.

[0127] The modulus of the first and second largest polynomials is the same, so the two can be densely matrix multiplied.

[0128] Here, the data interaction based on MPC can be data interaction based on homomorphic encryption algorithm or secret sharing. Taking the use of homomorphic encryption algorithm as an example, this step can include multiple implementation methods.

[0129] For example, the first party A may homomorphically encrypt the first large polynomial, and send the encrypted first large polynomial to the second party B. The second party B may multiply the encrypted first large polynomial by the second large polynomial to obtain a first sub-result, or may homomorphically encrypt the second large polynomial to obtain an encrypted second large polynomial, and multiply the encrypted first large polynomial by the encrypted second large polynomial to obtain a first sub-result.

[0130] Alternatively, the second party B homomorphically encrypts the second large polynomial, and sends the encrypted second large polynomial to the first party A. The process of the first party A performing the dense matrix multiplication is similar to the above implementation, and will not be repeated.

[0131] In this embodiment, each party encodes multiple sub-polynomials into a large polynomial, and replaces the secret multiplication between multiple sub-polynomials with the secret multiplication between the large polynomials, which can significantly reduce the number of multiplications and reduce the cost.

[0132] The first sub-result is a large polynomial whose modulus is the same as the modulus of the first large polynomial or the second large polynomial. By decoding the first sub-result with the modulus, multiple sub-polynomials can be obtained. These multiple sub-polynomials are similar to directly adding multiple sub-polynomials in the first group to the first vector The results of dense matrix multiplication of several subpolynomials are the same. The following is some proof and property description of this.

[0133] Assume that the first group contains 2 subpolynomials - x 3 and x 3 , the moduli are x 4 +1 and x 4 -1. The first vector contains 2 subpolynomials -x 2 and x 2 When the modulus is x 4 +1 and x 4 -1. Subpolynomial -x 3 and x 3 can be encoded as a large polynomial x 7 , subpolynomial-x 2 and x 2 can be encoded as a large polynomial x 6 , where x 6 mod x 4 +1 = -x 2 , x 6 mod x 4 -1 = x 2 The encoded modulus is (x 4 +1)(x 4 -1) = x 8 -1. Multiplying two large polynomials gives x 7 x6 =x 13 =x 5 (mod x 8 -1), by computing the large polynomial x 7 With x 6 The product between them completes the subpolynomial -x 3 With -x 2 The product of 3 With x 2 The product between . Obviously, the following relationship exists

[0134] x 7 x 6 mod x 4 +1 = x 5 , x 7 x 6 mod x 4 -1 = x 5 (2)

[0135] x 7 +x 6 mod x 4 +1 = -x 3 -x 2 , x 7 +x 6 mod x 4 -1 = x 3 +x 2 (3)

[0136] The result of multiplying the sub-polynomials is (-x 3 )(-x 2 )=x 5 , x 3 x 2 =x 5 According to formula (2), the multiplication of a large polynomial is equivalent to the multiplication of its sub-polynomials.

[0137] The result of adding the sub-polynomials is (-x 3 )+(-x 2 ) and x 3 +x 2 According to formula (3), the addition of large polynomials is equivalent to the addition of sub-polynomials.

[0138] The above is explained with parameters in non-confidential form. After homomorphic encryption of large polynomials, the above relationship still holds.

[0139] The above steps S520 to S540 are executed by the first group of sub-polynomials and the first vector The dense multiplication between the sub-polynomials in the first sub-result is only the first matrix With the first sub-block vector H 1 For a 3*3 matrix, the first sub-result is one of the three sub-results. With the first sub-block vector H 1 The complete result of the dense matrix multiplication between the two can be continued in the same way to perform the second group of sub-polynomials and the second vector The dense matrix multiplication between and the third group of subpolynomials and the third vector Dense matrix multiplication between them, etc.

[0140] Among them, the first vector Second vector and the third vector is obtained by transforming the first sub-block vector H 1 The first group and the first vector There is a multiplication relationship between the second group and the second vector There is a multiplication relationship between the third group and the third vector There is a multiplicative relationship between them.

[0141] In the matrix encoding stage, the first party A uses the modulus of the sub-polynomial contained in the first group to convert the first sub-block vector H 1 The sub-blocks in the multiplication relationship with the sub-polynomial are encoded as sub-polynomials to obtain the first vector At the same time, the first party A uses the modulus of the sub-polynomial contained in the second group to convert the first sub-block vector H 1 The sub-blocks in the multiplication relationship with the sub-polynomial are encoded as sub-polynomials to obtain the second vector The first party A also uses the modulus of the sub-polynomial contained in the third group to convert the first sub-block vector H 1 The sub-blocks in the multiplication relationship with the sub-polynomial are encoded as sub-polynomials to obtain the third vector

[0142] First Vector is the modulus of the first set of neutron polynomials on the first sub-block vector H 1 The second vector is obtained by encoding the corresponding sub-block in is the modulus of the second set of neutron polynomials on the first sub-block vector H 1 The third vector is obtained by encoding the corresponding sub-block in is the modulus of the third group of neutron polynomials on the first sub-block vector H 1 The corresponding sub-block in is encoded.

[0143] exist Figure 5Based on the embodiment, the method provided in another embodiment of this specification may further include the following steps 1, 2 and 3.

[0144] Step 1: The first party A encodes several sub-polynomials included in the second group into a third polynomial. The second group is a group other than the first group among the several groups. The specific encoding method can be referred to step S520, which will not be described here.

[0145] Step 2, the second square B, the second vector The included sub-polynomials are encoded as the fourth largest polynomial. The specific encoding method can be referred to in step S530 and will not be described in detail here.

[0146] Step 3: The first party A and the second party B perform multiplication between the third large polynomial and the fourth large polynomial through data exchange based on secure multi-party computing to obtain a second sub-result. The specific implementation of this step can be referred to step S540, which will not be repeated here.

[0147] In the same way, we can encode a large polynomial based on the third group and the third vector The third sub-result is obtained. The first sub-result, the second sub-result and the third sub-result are all encrypted data.

[0148] Figure 6 The first matrix provided for the implementation example With the first sub-block vector H 1 A flowchart of the dense matrix multiplication between . Among them, the first matrix The elements in are sub-polynomials, each with a sharp corner. The 9 polynomials are divided into 3 groups. The same box color represents the same group. The box color of the first group is white, the box color of the second group is gray, and the box color of the third group is black. The moduli of the 3 rows are mod1, mod2, and mod3 respectively. The first sub-block vector H 1 The elements in are sub-blocks, which are encoded for different groups of moduli, and three sets of vectors are obtained, namely the first vector (white box), the second vector (gray box) and the third vector (black box). The dotted box represents the encoded large polynomial. The first party and the second party perform three large polynomial dense multiplications, and the first sub-result, the second sub-result and the third sub-result can be obtained respectively.

[0149] The first sub-result, the second sub-result, and the third sub-result are summed to obtain the secret state large polynomial sum value. When the calculation task is completed, the secret state large polynomial sum value after homomorphic encryption should be decrypted first and then decoded into sub-polynomials.

[0150] By comparison Figure 6 and Figure 3It can be found that when performing a dense matrix multiplication of a 3*3-dimensional matrix and a 3*1-dimensional column vector, the method of this embodiment can reduce the number of dense matrix multiplications from 9 to 3. For matrix multiplication encrypted using a homomorphic encryption algorithm, according to the existing homomorphic encryption matrix multiplication, in order to protect data privacy, each time a dense matrix multiplication is performed between multiple parties, multiple multiplications of full slots are actually required. For example, when the slot is 1000, Figure 3 The 9 multiplications in require 9000 slot multiplications. Figure 6 When performing 3 multiplications in , only 3000 slot multiplications need to be performed, and the number of multiplications is significantly reduced.

[0151] Based on the above embodiment, another embodiment method of the present specification may further include the following steps 4 to 6, and steps 4 to 6 may be performed by the first party A or the second party B.

[0152] Step 4, decrypt the secret state large polynomial sum of the first sub-result, the second sub-result, and the third sub-result to obtain the large polynomial sum. For example, a homomorphic encryption algorithm can be used to decrypt the secret state large polynomial sum. The specific process can be referred to the existing method, which will not be repeated here.

[0153] Step 5: Decode the obtained large polynomial and value to obtain multiple sub-polynomials.

[0154] During decoding, the modulus of the large polynomial (referred to as the large modulus), such as the modulus of the first large polynomial, and the moduli of multiple sub-polynomials (referred to as small moduli) can be used to decode the large polynomial and value, and obtain sub-polynomials corresponding to multiple small moduli respectively. The small modulus, for example, includes mod1, mod2 and mod3 mentioned above. The moduli of the first large polynomial to the fourth large polynomial are the same. The decoding process can be carried out in conjunction with the Chinese remainder theorem or the extended Chinese remainder theorem, and the specific process can adopt existing technology, which will not be repeated here.

[0155] Step 6: Decode multiple sub-polynomials respectively, and determine the block circulant matrix Q based on the decoding results. 1 With the first sub-block vector H 1 The product result between .

[0156] The multiple sub-polynomials obtained by decoding correspond to multiple sub-blocks respectively. For example, when the 3*3 block circulant matrix Q 1 With the first 3*1 sub-block vector H 1 When multiplied, the resulting matrix is ​​a 3*1 column vector, that is, it contains 3 sub-blocks. Through step 5 decoding, 3 sub-polynomials are obtained, which correspond to the 3 sub-blocks respectively. Figure 2The encoding method shown corresponds to a method in which numerical values ​​are read from the coefficients of the multiple sub-polynomials as elements in the product result matrix.

[0157] In this specification, the word "first" in terms such as first party, first matrix, first vector, first group, first large polynomial, etc., and the corresponding "second" (if any) in the text, etc., are merely for the convenience of distinction and description and do not have any limiting meaning.

[0158] The foregoing describes certain embodiments of the present specification, and other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims may be performed in an order different from that in the embodiments, and the desired results may still be achieved. In addition, the processes depicted in the accompanying drawings do not necessarily have to be performed in the specific order or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0159] Figure 7 A schematic block diagram of a system for performing encrypted matrix multiplication between multiple parties is provided in an embodiment. The system 700 includes a first party 710 and a second party 720. Figure 5 The elements in the first matrix owned by the first party 710 and the first vector owned by the second party 720 are sub-polynomials, and the sub-polynomials are obtained by encoding the numerical elements.

[0160] The first side 710 is used to divide the multiple sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any of the first groups satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector; encode the multiple sub-polynomials in the first group into a first large polynomial;

[0161] The second party 720 is used to encode the plurality of sub-polynomials included in the first vector into a second large polynomial;

[0162] The first party 710 and the second party 720 are used to perform multiplication between the first large polynomial and the second large polynomial through data interaction based on secure multi-party computing to obtain a first sub-result.

[0163] In one embodiment, when the first party 710 divides the multiple sub-polynomials contained in the first matrix into several groups, it is specifically used to: based on the number of rows and columns corresponding to any sub-polynomial in the first matrix, according to the preset row and column number rule for each group, select a sub-polynomial from each row and each column to form a group.

[0164] In one embodiment, multiple sub-polynomials in the first group are obtained by encoding with different moduli; the first party 710 is also used to obtain the first matrix in the following manner: for a block circulant matrix containing multiple sub-blocks, the multiple sub-blocks in the row are respectively encoded into corresponding sub-polynomials using the modulus corresponding to each row, and the moduli of different rows are different.

[0165] In one embodiment, the first party 710, when encoding multiple sub-polynomials of the first group into a first large polynomial, is specifically used to: multiply the moduli of the multiple sub-polynomials of the first group to obtain the modulus of the first large polynomial to be encoded; based on the modulus of the first large polynomial, in combination with the Chinese remainder theorem, encode the multiple sub-polynomials of the first group to obtain the first large polynomial.

[0166] In one implementation, the moduli of the several sub-polynomials included in the first vector are respectively the same as the moduli of the corresponding sub-polynomials in the first group. When there is a multiplication relationship between the sub-polynomials in the first vector and the sub-polynomials in the first group, the two correspond to each other.

[0167] In one implementation, the second side 720 is further configured to obtain the first vector in the following manner: based on the sub-block partitioning method of the block circulant matrix, the second original matrix is ​​correspondingly divided into a plurality of sub-blocks, and a first sub-block vector containing the plurality of sub-blocks is extracted from the second original matrix; using the modulus of the sub-polynomial contained in the first group, a sub-block in the first sub-block vector that has a multiplication relationship with the sub-polynomial is encoded into a sub-polynomial to obtain the first vector;

[0168] When the plurality of groups further includes a second group, the second party 720 is further configured to: use the modulus of the sub-polynomial included in the second group to encode the sub-blocks in the first sub-block vector that are in a multiplication relationship with the sub-polynomial into a sub-polynomial to obtain a second vector.

[0169] In one embodiment, the first party 710 is further used to encode the several sub-polynomials included in the second group into a third large polynomial; the second party 720 is further used to encode the several sub-polynomials included in the second vector into a fourth large polynomial;

[0170] The first party 710 and the second party 720 are also used to perform multiplication between the third large polynomial and the fourth large polynomial through data interaction based on secure multi-party computing to obtain a second sub-result.

[0171] In one embodiment, the first party 710 or the second party 720 is further used to decrypt the secret large polynomial sum of the first sub-result and the second sub-result to obtain the large polynomial sum; decode the large polynomial sum to obtain multiple sub-polynomials; decode the multiple sub-polynomials respectively, and determine the product result between the block circulant matrix and the first sub-block vector based on the decoding result.

[0172] The above system embodiment corresponds to the method embodiment, and the specific description can refer to the description of the method embodiment part, which will not be repeated here. The system embodiment has the same technical effect as the corresponding method embodiment, and the specific description can refer to the corresponding method embodiment.

[0173] Figure 8 A schematic block diagram of an apparatus for performing encrypted matrix multiplication between multiple parties is provided in an embodiment. Figure 5 The method embodiment shown corresponds to the method performed by the first party. The elements in the first matrix owned by the first party and the first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding the numerical elements. The device 800 is deployed in the first party, and includes:

[0174] A first grouping module 810 is configured to group the plurality of sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between each of the sub-polynomials in the first vector;

[0175] A first encoding module 820, configured to encode the plurality of sub-polynomials of the first group into a first large polynomial;

[0176] The first multiplication module 830 is configured to perform multiplication between the first large polynomial and the second large polynomial through data interaction with the second party based on secure multi-party computing to obtain a first sub-result; wherein the second large polynomial is obtained by the second party encoding several sub-polynomials contained in the first vector.

[0177] In one implementation, the first grouping module 810 is specifically configured as follows:

[0178] Based on the number of rows and columns corresponding to any sub-polynomial in the first matrix, and in accordance with a preset rule of the number of rows and columns for each group, a sub-polynomial is selected from each row and each column to form a group.

[0179] In one embodiment, the multiple sub-polynomials in the first group are obtained by encoding with different moduli; the device 800 also includes a first determination module (not shown in the figure), which is configured to obtain the first matrix in the following manner: for a block circulant matrix containing multiple sub-blocks, use the modulus corresponding to each row to encode the multiple sub-blocks in the row into corresponding sub-polynomials, and the moduli of different rows are different.

[0180] In one embodiment, the first encoding module 820 is specifically configured as follows: multiplying the moduli of multiple sub-polynomials of the first group to obtain the modulus of the first large polynomial to be encoded; based on the modulus of the first large polynomial, combined with the Chinese remainder theorem, encoding the multiple sub-polynomials of the first group to obtain the first large polynomial.

[0181] In one embodiment, the moduli of the several sub-polynomials included in the first vector are respectively the same as the moduli of the corresponding sub-polynomials in the first group. When there is a multiplication relationship between the sub-polynomials in the first vector and the sub-polynomials in the first group, the two correspond to each other.

[0182] In one embodiment, the first vector is obtained by encoding the sub-blocks in the first sub-block vector that have a multiplication relationship with the sub-polynomial contained in the first group using the modulus of the sub-polynomial contained in the first group; the several groups also include the second group. The first encoding module 820 is also configured to encode the several sub-polynomials contained in the second group into a third large polynomial. The first multiplication module 830 is also configured to perform multiplication between the third large polynomial and the fourth large polynomial through data interaction based on secure multi-party computing with the second party to obtain a second sub-result. The fourth large polynomial is obtained by the second party encoding the several sub-polynomials contained in the second vector, and the second vector is obtained by encoding the sub-blocks in the first sub-block vector that have a multiplication relationship with the sub-polynomial using the modulus of the sub-polynomial contained in the second group.

[0183] In one embodiment, the device 800 further includes: a sum decryption module, a first decoding module, and a second decoding module (not shown in the figure). The sum decryption module is configured to decrypt the secret state large polynomial sum of the first sub-result and the second sub-result to obtain the large polynomial sum. The first decoding module is configured to decode the large polynomial sum to obtain a plurality of sub-polynomials. The second decoding module is configured to decode the obtained plurality of sub-polynomials respectively, and determine the product result between the block circulant matrix and the first sub-block vector based on the decoding result.

[0184] Fig. 9 A schematic block diagram of an apparatus for performing encrypted matrix multiplication between multiple parties is provided in an embodiment. Figure 5 The method embodiment shown corresponds to the method performed by the second party. The elements in the first matrix owned by the first party and the first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding the numerical elements. The device 900 is deployed in the second party, and includes:

[0185] A second encoding module 910 is configured to encode a plurality of sub-polynomials included in the first vector into a second large polynomial;

[0186] A second multiplication module 920 is configured to perform multiplication between the first large polynomial and the second large polynomial through data interaction with the first party based on secure multi-party computing to obtain a first sub-result;

[0187] Among them, the first large polynomial is obtained by the first party encoding multiple sub-polynomials of any first group among several groups, and the several groups are obtained by the first party dividing multiple sub-polynomials contained in the first matrix, and the sub-polynomials in the first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively.

[0188] In one embodiment, the plurality of subpolynomials in the first group are obtained by encoding with different moduli, and the first matrix is ​​obtained by encoding a subblock in a block circulant matrix including a plurality of subblocks;

[0189] The moduli of the several sub-polynomials included in the first vector are respectively the same as the moduli of the corresponding sub-polynomials in the first group. When there is a multiplication relationship between the sub-polynomials in the first vector and the sub-polynomials in the first group, the two correspond to each other.

[0190] In one embodiment, the device 900 also includes a third encoding module (not shown in the figure), which is used to determine the first vector in the following manner: based on the sub-block division method of the block circulant matrix, the second original matrix is ​​correspondingly divided into a plurality of sub-blocks, and a first sub-block vector containing the plurality of sub-blocks is taken out from the second original matrix, and the modulus of the sub-polynomial contained in the first group is used to encode the sub-blocks in the first sub-block vector that have a multiplication relationship with the sub-polynomial into a sub-polynomial to obtain the first vector.

[0191] The several groups also include a second group, and the third encoding module is further used to: use the modulus of the sub-polynomial included in the second group to encode the sub-blocks in the first sub-block vector that have a multiplication relationship with the sub-polynomial into a sub-polynomial to obtain a second vector.

[0192] In one embodiment, the device 900 further includes: a fourth encoding module and a third multiplication module (not shown in the figure). The fourth encoding module is used to encode the several sub-polynomials contained in the second vector into a fourth large polynomial. The third multiplication module is configured to perform multiplication between the third large polynomial and the fourth large polynomial through data interaction based on secure multi-party computing with the first party to obtain a second sub-result. The third large polynomial is obtained by the first party encoding the several sub-polynomials contained in the second group.

[0193] In one embodiment, the device 900 further includes: a sum decryption module, a first decoding module, and a second decoding module (not shown in the figure). The sum decryption module is configured to decrypt the secret state large polynomial sum of the first sub-result and the second sub-result to obtain the large polynomial sum. The first decoding module is configured to decode the large polynomial sum to obtain a plurality of sub-polynomials. The second decoding module is configured to decode the obtained plurality of sub-polynomials respectively, and determine the product result between the block circulant matrix and the first sub-block vector based on the decoding result.

[0194] The above-mentioned device embodiments correspond to the method embodiments. For specific descriptions, please refer to the description of the method embodiments, which will not be repeated here. The device embodiments are obtained based on the corresponding method embodiments and have the same technical effects as the corresponding method embodiments. For specific descriptions, please refer to the corresponding method embodiments.

[0195] The present specification also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed in a computer, the computer is caused to execute Figures 1 to 6 Any of the methods described above.

[0196] The embodiment of the present specification also provides a computing device, including a memory and a processor, wherein the memory stores an executable code, and when the processor executes the executable code, Figures 1 to 6 Any of the methods described above.

[0197] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the storage medium and computing device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.

[0198] Those skilled in the art should be aware that in one or more of the above examples, the functions described in the embodiments of the present invention may be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions may be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0199] The specific implementation methods described above further describe the purpose, technical solutions and beneficial effects of the embodiments of the present invention in detail. It should be understood that the above description is only a specific implementation method of the embodiments of the present invention and is not intended to limit the scope of protection of the present invention. Any modification, equivalent replacement, improvement, etc. made on the basis of the technical solution of the present invention shall be included in the scope of protection of the present invention.

Claims

1. A method for performing encrypted matrix multiplication between multiple parties, wherein: Elements in a first matrix owned by the first party and a first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; the method comprises: The first party divides the multiple sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively; encodes the multiple sub-polynomials in the first group into a first large polynomial; The second party encodes a plurality of sub-polynomials included in the first vector into a second large polynomial; The first party and the second party perform multiplication between the first large polynomial and the second large polynomial through data interaction based on secure multi-party computing to obtain a first sub-result.

2. A method for performing encrypted matrix multiplication between multiple parties, wherein: Elements in a first matrix owned by the first party and a first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; The method is performed by the first party and includes: Divide the multiple sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between each of the sub-polynomials in the first vector; encoding the plurality of sub-polynomials of the first group into a first large polynomial; Through data interaction with the second party based on secure multi-party computing, multiplication between the first large polynomial and the second large polynomial is performed to obtain a first sub-result; wherein the second large polynomial is obtained by the second party encoding several sub-polynomials contained in the first vector.

3. The method according to claim 2, wherein the step of dividing the plurality of sub-polynomials contained in the first matrix into a plurality of groups comprises: Based on the number of rows and columns corresponding to any sub-polynomial in the first matrix, and in accordance with a preset rule of the number of rows and columns for each group, a sub-polynomial is selected from each row and each column to form a group.

4. The method according to claim 2, wherein the plurality of sub-polynomials in the first group are obtained by encoding with different moduli; and the first matrix is ​​obtained by: For a block circulant matrix containing multiple sub-blocks, multiple sub-blocks in the row are respectively encoded into corresponding sub-polynomials using the modulus corresponding to each row, and the moduli of different rows are different.

5. The method according to claim 4, wherein the step of encoding the first group of multiple sub-polynomials into a first large polynomial comprises: multiplying the moduli of the plurality of sub-polynomials of the first group to obtain the modulus of the first large polynomial to be encoded; Based on the modulus of the first large polynomial and in combination with the Chinese remainder theorem, multiple sub-polynomials of the first group are encoded to obtain the first large polynomial.

6. According to the method of claim 4, the moduli of the several sub-polynomials contained in the first vector are respectively the same as the moduli of the corresponding sub-polynomials in the first group, and when there is a multiplication relationship between the sub-polynomials in the first vector and the sub-polynomials in the first group, the two correspond to each other.

7. The method according to claim 6, wherein the first vector is obtained by encoding the sub-blocks in the first sub-block vector that have a multiplication relationship with the sub-polynomial using the modulus of the sub-polynomial included in the first group; the plurality of groups further includes a second group; the method further includes: encoding the plurality of subpolynomials included in the second group into a third largest polynomial; By performing data interaction with the second party based on secure multi-party computing, multiplication between the third large polynomial and the fourth large polynomial is obtained to obtain a second sub-result; Among them, the fourth large polynomial is obtained by the second party encoding several sub-polynomials contained in the second vector, and the second vector is obtained by using the modulus of the sub-polynomial contained in the second group to encode the sub-block in the first sub-block vector that has a multiplication relationship with the sub-polynomial.

8. The method according to claim 7, further comprising: Decrypting the encrypted large polynomial sum of the first sub-result and the second sub-result to obtain a large polynomial sum; Decoding the large polynomial and value to obtain a plurality of sub-polynomials; The obtained multiple sub-polynomials are decoded respectively, and a product result between the block circulant matrix and the first sub-block vector is determined based on the decoding results.

9. A method for performing encrypted matrix multiplication between multiple parties, wherein: Elements in a first matrix owned by the first party and a first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; The method is performed by the second party and includes: Encoding a plurality of sub-polynomials included in the first vector into a second large polynomial; By performing data interaction with the first party based on secure multi-party computing, multiplication between the first large polynomial and the second large polynomial is obtained to obtain a first sub-result; Among them, the first large polynomial is obtained by the first party encoding multiple sub-polynomials of any first group among several groups, and the several groups are obtained by the first party dividing multiple sub-polynomials contained in the first matrix, and the sub-polynomials in the first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively.

10. The method according to claim 9, wherein the plurality of sub-polynomials in the first group are obtained by encoding with different moduli, and the first matrix is ​​obtained by encoding a sub-block in a block circulant matrix containing a plurality of sub-blocks; The moduli of the several sub-polynomials included in the first vector are respectively the same as the moduli of the corresponding sub-polynomials in the first group. When there is a multiplication relationship between the sub-polynomials in the first vector and the sub-polynomials in the first group, the two correspond to each other.

11. The method according to claim 10, wherein the first vector is obtained in the following manner: Based on the sub-block partitioning method of the block circulant matrix, the second original matrix is ​​correspondingly divided into a plurality of sub-blocks; Taking out a first sub-block vector including a plurality of sub-blocks from the second original matrix; Using the modulus of the sub-polynomial included in the first group, encoding the sub-blocks in the first sub-block vector that are in a multiplication relationship with the sub-polynomial into a sub-polynomial to obtain a first vector; The plurality of groups also include a second group, and the method further includes: Using the modulus of the sub-polynomial included in the second group, the sub-blocks in the first sub-block vector that are in a multiplication relationship with the sub-polynomial are encoded as sub-polynomials to obtain a second vector.

12. The method according to claim 11, further comprising: Encoding a plurality of sub-polynomials included in the second vector into a fourth polynomial; By exchanging data with the first party based on secure multi-party computing, multiplication between the third large polynomial and the fourth large polynomial is performed to obtain a second sub-result; wherein the third large polynomial is obtained by the first party encoding several sub-polynomials included in the second group.

13. The method according to claim 12, further comprising: Decrypting the encrypted large polynomial sum of the first sub-result and the second sub-result to obtain a large polynomial sum; Decoding the large polynomial and value to obtain a plurality of sub-polynomials; The plurality of sub-polynomials are decoded respectively, and a product result between the block circulant matrix and the first sub-block vector is determined based on the decoding results.

14. A system for performing encrypted matrix multiplication between multiple parties, comprising a first party and a second party, wherein the elements in a first matrix owned by the first party and a first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; The first side is used to divide the multiple sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively; encode the multiple sub-polynomials in the first group into a first large polynomial; The second party is used to encode the plurality of sub-polynomials included in the first vector into a second large polynomial; The first party and the second party are configured to perform multiplication between the first large polynomial and the second large polynomial through data interaction based on secure multi-party computing to obtain a first sub-result.

15. An apparatus for performing encrypted matrix multiplication between multiple parties, wherein: Elements in a first matrix owned by the first party and a first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; The device is deployed in a first party and includes: A first grouping module is configured to divide the plurality of sub-polynomials included in the first matrix into a plurality of groups, so that the sub-polynomials in any first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between each of the sub-polynomials in the first vector; A first encoding module, configured to encode the plurality of sub-polynomials of the first group into a first large polynomial; The first multiplication module is configured to perform multiplication between the first large polynomial and the second large polynomial through data interaction with the second party based on secure multi-party computing to obtain a first sub-result; wherein the second large polynomial is obtained by the second party encoding several sub-polynomials contained in the first vector.

16. An apparatus for performing encrypted matrix multiplication between multiple parties, wherein: Elements in a first matrix owned by the first party and a first vector owned by the second party are sub-polynomials, and the sub-polynomials are obtained by encoding numerical elements; The device is deployed in the second party and includes: A second encoding module, configured to encode a plurality of sub-polynomials included in the first vector into a second large polynomial; a second multiplication module, configured to perform multiplication between the first large polynomial and the second large polynomial through data interaction with the first party based on secure multi-party computing to obtain a first sub-result; Among them, the first large polynomial is obtained by the first party encoding multiple sub-polynomials of any first group among several groups, and the several groups are obtained by the first party dividing multiple sub-polynomials contained in the first matrix, and the sub-polynomials in the first group satisfy: there is no additive relationship in matrix multiplication, and there is a corresponding multiplication relationship between the sub-polynomials in the first vector respectively.

17. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method according to any one of claims 1 to 13.

18. A computing device, comprising a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method according to any one of claims 1 to 13 is implemented.