Method and system for jointly computing privacy data of two parties based on linear secret sharing

Through a joint computing method based on linear secret sharing, the complexity and efficiency of the existing multi-party security computing protocol during the cooperation of the private data between the two parties is solved, and a safe, efficient and reliable acquisition of calculation results is achieved.

CN119961957APending Publication Date: 2025-05-09TIANJIN UNIVERSITY OF TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510057222.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

When the existing multi-party security computing protocol cooperates to calculate the privacy data of the two parties, there are problems such as complex circuit design, low flexibility, large communication overhead and complex implementation process.

Method used

A joint calculation method based on linear secret sharing is adopted to achieve secure, efficient and reliable calculation of the private data of both parties through sharing algorithms, reconstruction algorithms and opening algorithms. The specific steps include two participants holding private data running the corresponding algorithm as the sharers, and multiple participants performing the calculation as the calculator to perform the calculation of the arithmetic gate, and finally the sharers decrypt and obtain the calculation results.

Benefits of technology

Reduces time overhead, improves efficiency, increases flexibility, reduces communication costs, and achieves safe and efficient multi-party security computing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961957A_ABST
    Figure CN119961957A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for jointly calculating privacy data of two parties based on linear secret sharing. The method comprises the following steps that two participants with private data serve as sharing parties, and a sharing algorithm, a reconstruction algorithm and an opening algorithm are operated; a plurality of participants executing calculation serve as calculation parties, and calculation of an arithmetic gate is carried out; calculating the fragment of the result value by each calculation party, judging whether the fragment is the fragment of the final output result or not according to a calculation rule, and if the fragment is the fragment of the final output result; each calculation party sends the data fragments of the final output result to the sharing party requesting the calculation result; and requesting the sharing party of the calculation result to decrypt the fragment of the final output result to obtain the final output result. According to the method, a preprocessing stage is not needed, and the sharing party is responsible for generating the random number and distributing the random number fragments to the calculation party, so that the time overhead is reduced, and the efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of multi-party data security computing, and in particular to a method and system for jointly computing private data of two parties based on linear secret sharing. Background Art

[0002] In the era of big data, the problem of data silos has seriously restricted the flow and use of data. Data owned by different organizations and institutions cannot be shared and integrated with each other due to interests, privacy, security and other reasons. The use of big data can make predictions more accurate, decisions more optimized, and statistics more precise. Therefore, it is particularly important to promote information sharing. However, in practice, multi-party data sets often belong to different stakeholders, and data leakage will cause considerable losses to data owners. At the same time, data users usually only want to obtain the results calculated based on these private data, and do not care about the private data itself in the calculation process. This leads to a very natural question: Can we get the calculation results based on multi-party data without leaking the private data of each party? Multi-party secure computing (MPC) technology provides a solution and has made a great contribution to the controllable sharing of data.

[0003] Multi-party secure computing can be divided into two-party computing and multi-party computing. Two-party computing aims to allow two participants to jointly calculate the result of a function without disclosing their input data. The mainstream implementation methods are Yao obfuscation circuits based on Boolean circuits and GMW protocols. Multi-party computing aims to allow multiple participants to collaboratively calculate the result of a function without disclosing their input data. The mainstream implementation methods are BGW protocols and DN protocols based on arithmetic circuits.

[0004] When two privacy data holders need to perform collaborative computing, if the mainstream two-party computing protocol is adopted, there will be problems such as complex circuit design and low flexibility; if the mainstream multi-party computing protocol is adopted, there will be problems such as high communication overhead and complex implementation process.

[0005] Therefore, it is necessary to develop an MPC protocol based on linear secret sharing to jointly calculate the private data of two parties. Summary of the invention

[0006] The purpose of the present invention is to construct a safe, efficient and reliable multi-party secure computing protocol based on linear secret sharing when two parties need to jointly calculate private data. In order to achieve the above purpose, this patent provides a method and system for jointly calculating the private data of two parties based on linear secret sharing.

[0007] To achieve the above purpose, the technical solution provided by the present invention is as follows:

[0008] First aspect

[0009] The present invention provides a method for jointly calculating private data of two parties based on linear secret sharing, comprising the following steps:

[0010] Step 1: Two parties holding private data act as sharing parties and run the sharing algorithm, reconstruction algorithm, and opening algorithm;

[0011] Step 2: Multiple participants who perform calculations act as computing parties and perform calculations of arithmetic gates;

[0012] Step 3: Each computing party calculates the shard of the result value, and determines whether it is the shard of the final output result according to the calculation rules. If it is the shard of the final output result, proceed to step 4, otherwise return to step 2;

[0013] Step 4: Each computing party sends the data shards of the final output results to the sharing party that requested the calculation results;

[0014] Step 5: The party requesting the sharing of the calculation result decrypts the shard of the final output result to obtain the final output result.

[0015] Furthermore, in step 1, the sharing algorithm used by the sharing party is Shamir secret sharing.

[0016] Furthermore, in step 1, the reconstruction algorithm used by the sharing party is the Lagrange interpolation method.

[0017] Furthermore, in step 1, the opening algorithm used by the sharing party is the same as the reconstruction algorithm, the difference being that after the sharing party recovers the secret value, it sends the secret value to all computing parties.

[0018] Furthermore, the step 2 specifically includes:

[0019] When a linear gate calculation is performed, it is performed locally, and no communication is required between the calculation party and the sharing party;

[0020] When performing a nonlinear multiplication gate calculation, the multiplication sub-protocol is run, and communication is required between the computing party and the sharing party.

[0021] Furthermore, when a nonlinear multiplication gate calculation is performed, the multiplication sub-protocol is run, and communication is required between the calculation party and the sharing party, which specifically includes the following steps:

[0022] Step 2.2.1: The two sharing parties each generate a random value known only to themselves, and run the sharing algorithm on the random value;

[0023] Step 2.2.2: Calculate each square P i According to the received random value shards, the corresponding results are calculated in sequence through PRF and saved as the second random value shard;

[0024] Step 2.2.3: Each of the two sharing parties randomly selects 2t computing parties, and calculates 2t second random value slices using the pseudo-random function PRF based on the random value slices sent to the selected computing parties. Then, combined with the random values ​​known only to themselves, the 2t-order polynomial f'(x) is reconstructed, and the second random value slices of the unselected computing parties are calculated based on their numbers, and sent to the unselected computing parties.

[0025] Step 2.2.4: The computing party that receives the second random value shard overwrites the second random value shard saved in step 2.2.2 with the second random value shard received;

[0026] Step 2.2.5: Each computing party performs a multiplication operation on the secret data shard that needs to be multiplied, and adds it to the second random value shard to obtain an intermediate value shard;

[0027] Step 2.2.6: At least 2t+1 computing parties send the intermediate value shards of the above results to the same sharing party;

[0028] Step 2.2.7: The above-mentioned sharing parties run the opening algorithm based on the received intermediate value shards, so that all computing parties obtain the intermediate value;

[0029] Step 2.2.8: Each computing party performs local calculation: the intermediate value minus the first random value shard, and the calculation result is the shard of the secret data product.

[0030] Second aspect

[0031] The present invention provides a system for jointly calculating private data of two parties based on linear secret sharing, including a sharing party and a calculating party;

[0032] The sharing party and the computing party perform the following:

[0033] Step 1: Two parties holding private data act as sharing parties and run the sharing algorithm, reconstruction algorithm, and opening algorithm;

[0034] Step 2: Multiple participants who perform calculations act as computing parties and perform calculations of arithmetic gates;

[0035] Step 3: Each computing party calculates the shard of the result value, and determines whether it is the shard of the final output result according to the calculation rules. If it is the shard of the final output result, proceed to step 4, otherwise return to step 2;

[0036] Step 4: Each computing party sends the data shards of the final output results to the sharing party that requested the calculation results;

[0037] Step 5: The party requesting the sharing of the calculation result decrypts the shard of the final output result to obtain the final output result.

[0038] Furthermore, the sharing algorithm used by the sharing party is Shamir secret sharing.

[0039] Furthermore, the reconstruction algorithm used by the sharing party is Lagrange interpolation method.

[0040] Compared with the prior art, the present invention has the following beneficial effects:

[0041] (1) In terms of efficiency, in the prior art, when running the multiplication sub-protocol, a preprocessing stage is required, that is, all participants jointly participate in generating batches of random number shards, which requires a lot of communication interaction and time cost. However, the present invention does not require a preprocessing stage, and the sharing party is responsible for generating random numbers and distributing random number shards to the computing party, which reduces time overhead and improves efficiency;

[0042] (2) In terms of flexibility, in the prior art, if a participant needs to be added or replaced, all participants need to re-execute the preprocessing stage to generate batches of random value shards for executing the multiplication sub-protocol. However, when the multiplication sub-protocol is run, the random value shards are distributed by the sharing party, so when the computing party is added or replaced, it will not be affected, which is more flexible.

[0043] (3) In terms of communication cost, when running the multiplication sub-protocol, the existing technology can theoretically achieve an average communication cost of 6 elements per multiplication gate per party. However, in practice, the random values ​​generated in the preprocessing stage are often left over, resulting in an actual communication cost greater than 6 elements. The present invention generates random values ​​according to demand and does not waste random values. The communication cost is fixed at 4 elements per multiplication gate per party. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 A flowchart of the steps of a method for jointly calculating private data of two parties based on linear secret sharing provided in an embodiment of the present invention;

[0045] Figure 2 is a schematic diagram of a sharing algorithm used in an embodiment of the present invention;

[0046] Figure 3 is a flowchart of the steps of the multiplication sub-protocol used in an embodiment of the present invention;

[0047] Figure 4 is a flowchart of steps using a pseudo-random function PRF in an embodiment of the present invention;

[0048] Figure 5is a schematic diagram of an opening algorithm used in an embodiment of the present invention;

[0049] Figure 6 Schematic diagram of the reconstruction algorithm used in the embodiment of the present invention. DETAILED DESCRIPTION

[0050] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0051] like Figure 1 As shown, an embodiment of the present invention provides a method for jointly calculating private data of two parties based on linear secret sharing, comprising the following steps:

[0052] Step 1: As the holder of private data, the sharing party runs the sharing algorithm on the private data.

[0053] It should be noted that the sharing algorithm used by the sharing party adopts Shamir secret sharing, which is a (t,n) threshold scheme, in which the secret value is divided into n data slices and sent to each computing party. Any t data slices cannot obtain any information about the secret value. At least t+1 or more data slices can restore the secret value, where t is the number of dishonest computing parties. The dishonest party will strictly abide by the MPC protocol described in the present invention, but try to use the output of the protocol or the intermediate information during the operation process to obtain the private data of other private data holders. In this process, the sharing party first selects a large prime number p to ensure that all calculations are in the finite field Z. p Then a random t-order polynomial f(x) is selected so that f(0) = s, where s is the secret value. This polynomial can be expressed as:

[0054] f(x)=s+a1x+a2x 2 +...+a t x t

[0055] Among them, a1, a2, ..., a t From Z p The coefficients randomly selected in ;

[0056] Then, according to the unique number x of the calculation party i i Calculate the corresponding slice value y i =f(x i ) and split the data into (x i ,y i) is sent to the corresponding computing party i.

[0057] like Figure 2 As shown, the specific implementation method of the sharing algorithm includes the following:

[0058] Step 1.1: Set a total of n computing parties, of which there are at most t dishonest computing parties, and select a large prime number p so that all calculations are in the finite field Z p in;

[0059] Step 1.2: Sharer 1 has private data set A, and Sharer 2 has private data set B (taking sharing of private data a and b as an example, where );

[0060] Step 1.3: Sharer 1 selects a random t-degree polynomial f1(x) satisfying f1(0) = a, and Sharer 2 selects a random t-degree polynomial f2(x) satisfying f2(0) = b;

[0061] The polynomial can be expressed as:

[0062] f1(x)=a+p1x+p2x 2 +...+p t x t

[0063] f2(x)=b+q1x+q2x 2 +...+q t x t

[0064] Among them, p1, p2, ..., p t and q1,q2,...,q t From Z p The coefficients randomly selected in ;

[0065] Step 1.4: Sharer 1 calculates f1(x i ) to obtain the slice (x) of computing party i i ,f1(x i )) is recorded as (x i ,[a] i ), Share 2 calculates f2(x i ) to obtain the slice (x) of computing party i i ,f2(x i )) is recorded as (x i ,[b] i ), where x i is a number unique to the computing party i;

[0066] Step 1.5: Share 1 will share the shard (x i ,[a] i) is sent to computing party i; sharing party 2 sends the shard (x i ,[b] i ) is sent to computing party i;

[0067] Step 2: Each computing party performs arithmetic gate calculations on the private data shards according to the calculation rules.

[0068] When performing a linear gate calculation such as addition or multiplication, it can be calculated locally without the need for communication between the calculating party and the sharing party, because after the linear gate calculation, the maximum degree of the polynomial with the secret value as the constant term is still t, and the (t,n) threshold scheme is still valid.

[0069] When performing a nonlinear multiplication gate calculation, the multiplication sub-protocol requires communication between the computing party and the sharing party, because the product of the two secret shard values ​​will increase the highest degree of the polynomial whose secret product value is a constant term to 2t, thus making the (t,n) threshold scheme invalid. Therefore, it is necessary to run the multiplication sub-protocol to reduce the polynomial to t. i ,[a] i ) and (x i ,[b] i ) as an example:

[0070] Among them, [s] i represents a t-degree polynomial with s as a constant term. When x is x i The function value when , that is, the computing party i obtains the data shard about the secret s with a threshold value of t; [s] i ' represents a 2t-degree polynomial with s as the constant term when x is x i The function value when , that is, the computing party i obtains the data shard about the secret s with a threshold of 2t.

[0071] like Figure 3 As shown in the figure, the specific implementation steps of the multiplication sub-protocol are:

[0072] Step 2.2.1: Sharer 1 generates a private random value r1, and Sharer 2 generates a private random value r2;

[0073] Step 2.2.2: Sharer 1 runs the sharing algorithm on r1 and saves the data shards (x i ,[r1] i ); Sharer 2 runs the sharing algorithm on r2 and saves the data shards sent to each computing party (x i ,[r2] i );

[0074] Step 2.2.3: Computing party i receives the data shard (x i ,[r1] i) and (x i ,[r2] i ), run the pseudo-random function PRF to calculate the data slice to obtain the data slice (x i ,[y1] i ) and (x i ,[y2] i ) and save.

[0075] like Figure 4 As shown, the specific implementation steps of the pseudo-random function PRF are:

[0076] Step 2.2.3.1: Input data shard (x, [r]);

[0077] Step 2.2.3.2: Use MD5 to calculate the hash value of the data fragment value [r] and use it as the key of the pseudo-random function HMAC-SHA256;

[0078] Step 2.2.3.3: Calculate PRF HMAC-SHA256 (key,[r]), get pseudo-random output y;

[0079] Step 2.2.3.4: Convert the pseudo-random output y into a value of the same type as the data shard value [r] and output it;

[0080] Step 2.2.4: Sharer 1 runs the pseudo-random function PRF on the data slices saved in step 2.2 in turn to obtain (x i ,[y1] i ); Sharer 2 performs the same operation and obtains (x i ,[y2] i );

[0081] Step 2.2.5: Sharing party 1 randomly selects 2t computing parties, and uses the new shards calculated in step 2.4 and the random value r1 to reconstruct the 2t-degree polynomial f1'(x) with r1 as the constant term; Sharing party 2 performs the same operation to reconstruct f2'(x). The specific process of reconstructing the polynomial is as follows:

[0082] Step 2.2.5.1: The sharing party collects 2t data shards (x i ,[y1] i ) and the secret value shard (0,r);

[0083] Step 2.2.5.2: For each shard (x i ,[y] i ), define the Lagrangian basis function L i (x), the Lagrangian basis function formula is as follows:

[0084]

[0085] Step 2.2.5.3: Construct the interpolation polynomial f'(x), which is expressed as:

[0086]

[0087] Step 2.2.6: Sharer 1 uses f1'(x) in step 2.5 to calculate the new data shard (x) of the unselected computing party. i ,[r1] i ') and send it to the corresponding computing party; sharing party 2 performs the same operation;

[0088] Step 2.2.7: Receive new data shard (x i ,[r1] i ') or (x i ,[r2] i ') overwrites the data shard saved in step 2.3, so that each computing party i has the data shard (x i ,[r1] i )、(x i ,[r2] i )、(x i ,[r1] i ') and (x i ,[r2] i '); (Note: The communication cost in this process is only constant and can be ignored)

[0089] Step 2.2.8: Each computing party performs a private data i ,[a] i ) and (x i ,[b] i ) and multiply to get (x i ,[ab] i '), and then with (x i ,[r1] i ') and (x i ,[r2] i ') add to get the intermediate value slice (x i ,[e] i '), where e = ab + r1 + r2;

[0090] Step 2.2.9: At least 2t+1 computing parties send the intermediate value shards in step 2.8 to the same sharing party;

[0091] Step 2.2.10: After the sharing party described in step 2.9 collects at least 2t+1 intermediate value shards, run the opening algorithm;

[0092] It should be noted that the opening algorithm used by the sharing party is the same as the reconstruction algorithm, but the difference is that after the sharing party recovers the secret value, it sends the secret value to all computing parties.

[0093] like Figure 5 As shown, the specific implementation process of the opening algorithm is as follows:

[0094] Step 2.2.10.1: The sharing party collects at least 2t+1 intermediate value shards (x i ,[e] i ');

[0095] Step 2.2.10.2: For each shard (x i ,[e] i ') Calculate the Lagrangian basis function L i (0), the formula is as follows:

[0096]

[0097] Step 2.2.10.3: Use the collected 2t+1 slices and the corresponding Lagrangian basis functions to recover the intermediate value e, as follows:

[0098]

[0099] Step 2.2.10.4: The sharing party sends the recovered intermediate value e to each computing party.

[0100] Step 2.2.11: Computing party i locally calculates: e-[r1] i -[r2] i , the result of the calculation is the shard of the product of the secret data (x i ,[c] i ), where c = ab.

[0101] Step 3: Each computing party calculates the shard of the result value and determines whether it is the shard of the final output result according to the calculation rules. If it is the shard of the final output result, proceed to step 4, otherwise return to step 2.

[0102] Step 4: Each computing party sends the data shards of the final output results to the sharing party that requested the calculation results.

[0103] Step 5: The party requesting the sharing of the calculation result runs the reconstruction algorithm to decrypt the shard of the final output result to obtain the final output result s.

[0104] It should be noted that the reconstruction algorithm used by the sharing party is the Lagrange interpolation method. After collecting at least t+1 data slices of the secret value, the Lagrange interpolation method is used to reconstruct the polynomial and calculate the value of the polynomial at x=0, which is the secret value. The Lagrange interpolation formula is as follows:

[0105]

[0106] Among them, (x j ,y j ) is the collected data slice, x j is a number unique to the computing party, y j It is the data shard value owned by the computing party.

[0107] like Figure 6 As shown in the figure, the specific implementation process of the reconstruction algorithm is as follows:

[0108] Step 5.1: The party requesting the calculation result to share collects at least t+1 shards of the final output result (x i ,[s] i );

[0109] Step 5.2: Calculate the Lagrangian basis function L for each slice i (x) The value L at x = 0 i (0), Lagrangian basis function L i (x) is defined as:

[0110]

[0111] Specific calculation

[0112]

[0113] Step 5.3: The party requesting the calculation result uses any t+1 slices and the corresponding Lagrangian basis function to calculate the final output result. The calculation formula is as follows:

[0114]

[0115] Corresponding to the above method, an embodiment of the present invention further provides a system for jointly calculating private data of two parties based on linear secret sharing, including a sharing party and a calculating party;

[0116] The sharing party and the computing party perform the following:

[0117] Step 1: Two parties holding private data act as sharing parties and run the sharing algorithm, reconstruction algorithm, and opening algorithm;

[0118] Step 2: Multiple participants who perform calculations act as computing parties and perform calculations of arithmetic gates;

[0119] Step 3: Each computing party calculates the shard of the result value, and determines whether it is the shard of the final output result according to the calculation rules. If it is the shard of the final output result, proceed to step 4, otherwise return to step 2;

[0120] Step 4: Each computing party sends the data shards of the final output results to the sharing party that requested the calculation results;

[0121] Step 5: The party requesting the sharing of the calculation result decrypts the shard of the final output result to obtain the final output result.

[0122] Furthermore, the sharing algorithm used by the sharing party is Shamir secret sharing.

[0123] Furthermore, the reconstruction algorithm used by the sharing party is Lagrange interpolation method.

[0124] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and descriptions are only preferred examples of the present invention and are not intended to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention. The scope of protection of the present invention is defined by the attached claims and their equivalents.

Claims

1. A method for jointly calculating private data of two parties based on linear secret sharing, characterized in that: The steps include: Step 1: Two parties holding private data act as sharing parties and run the sharing algorithm, reconstruction algorithm, and opening algorithm; Step 2: Multiple participants who perform calculations act as computing parties and perform calculations of arithmetic gates; Step 3: Each computing party calculates the shard of the result value, and determines whether it is the shard of the final output result according to the calculation rules. If it is the shard of the final output result, proceed to step 4, otherwise return to step 2; Step 4: Each computing party sends the data shards of the final output results to the sharing party that requested the calculation results; Step 5: The party requesting the sharing of the calculation result decrypts the shard of the final output result to obtain the final output result.

2. According to claim 1, a method for jointly calculating private data of two parties based on linear secret sharing is characterized in that: In step 1, the sharing algorithm used by the sharing party is Shamir secret sharing.

3. The method for jointly calculating two-party private data based on linear secret sharing according to claim 2, characterized in that: In step 1, the reconstruction algorithm used by the sharing party is the Lagrange interpolation method.

4. The method for jointly calculating two-party private data based on linear secret sharing according to claim 3, characterized in that: In step 1, the opening algorithm used by the sharing party is the same as the reconstruction algorithm, the difference is that after the sharing party recovers the secret value, it sends the secret value to all computing parties.

5. The method for jointly calculating two-party private data based on linear secret sharing according to claim 4, characterized in that: The step 2 specifically includes: When a linear gate calculation is performed, it is performed locally, and no communication is required between the calculation party and the sharing party; When performing a nonlinear multiplication gate calculation, the multiplication sub-protocol is run, and communication is required between the computing party and the sharing party.

6. The method for jointly calculating two-party private data based on linear secret sharing according to claim 5, characterized in that: When performing a nonlinear multiplication gate calculation, the multiplication sub-protocol is run, and communication is required between the calculation party and the sharing party, which includes the following steps: Step 2.2.1: The two sharing parties each generate a random value known only to themselves, and run the sharing algorithm on the random value; Step 2.2.2: Calculate the square P i According to the received random value shards, the corresponding results are calculated in sequence through PRF and saved as the second random value shard; Step 2.2.3: Each of the two sharing parties randomly selects 2t computing parties, and calculates 2t second random value slices using the pseudo-random function PRF based on the random value slices sent to the selected computing parties. Then, combined with the random values ​​known only to themselves, the 2t-order polynomial f'(x) is reconstructed, and the second random value slices of the unselected computing parties are calculated based on their numbers, and sent to the unselected computing parties. Step 2.2.4: The computing party that receives the second random value shard overwrites the second random value shard saved in step 2.2.2 with the second random value shard received; Step 2.2.5: Each computing party performs a multiplication operation on the secret data shard that needs to be multiplied, and adds it to the second random value shard to obtain an intermediate value shard; Step 2.2.6: At least 2t+1 computing parties send the intermediate value shards of the above results to the same sharing party; Step 2.2.7: The above-mentioned sharing parties run the opening algorithm based on the received intermediate value shards, so that all computing parties obtain the intermediate value; Step 2.2.8: Each computing party performs local calculation: the intermediate value minus the first random value shard, and the calculation result is the shard of the secret data product.

7. A system for jointly computing private data of two parties based on linear secret sharing, characterized in that: Including sharing parties and computing parties; The sharing party and the computing party perform the following: Step 1: Two parties holding private data act as sharing parties and run the sharing algorithm, reconstruction algorithm, and opening algorithm; Step 2: Multiple participants who perform calculations act as computing parties and perform calculations of arithmetic gates; Step 3: Each computing party calculates the shard of the result value, and determines whether it is the shard of the final output result according to the calculation rules. If it is the shard of the final output result, proceed to step 4, otherwise return to step 2; Step 4: Each computing party sends the data shards of the final output results to the sharing party that requested the calculation results; Step 5: The party requesting the sharing of the calculation result decrypts the shard of the final output result to obtain the final output result.

8. A system for jointly calculating two-party private data based on linear secret sharing according to claim 7, characterized in that: The sharing algorithm used by the sharing party is Shamir secret sharing.

9. The method for jointly calculating two-party private data based on linear secret sharing according to claim 8, characterized in that: The reconstruction algorithm used by the sharing party is the Lagrange interpolation method.