Outsourcing multi-party computing method, device and system capable of identifying malicious behaviors
By using vector space secret sharing and multiplication triple verification methods in outsourcing computing scenarios, malicious computing parties are identified and eliminated, and the problem of malicious computing parties identification in the existing technology is solved, and the robustness and security of the computing system are achieved.
Patent Information
- Application Number
- CN202510112239.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art is difficult to effectively identify and deal with malicious computing parties in outsourcing computing scenarios, resulting in privacy leakage and robustness of computing systems.
A n-party calculation scheme that can identify malicious behavior is proposed. Through vector space secret sharing and multiplication triple verification, malicious calculators are identified and excluded, ensuring the robustness and security of the calculation results.
Implementation of identification of malicious behavior in most semi-honest scenarios ensures robustness, security and high availability of computing systems, and avoids privacy breaches and denial of service attacks.
Smart Images

Figure CN119995854A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an outsourced multi-party computing method, device and system capable of identifying malicious behavior. Background Art
[0002] In addition to running the computation protocol directly between data owners, secure multi-party computation can also be used in outsourcing scenarios, where the data owner distributes the original data to n non-colluding computation parties, which execute the secure multi-party computation protocol without knowing the original data and return the output share to the recipient to reconstruct the computation results. Usually, these computation parties are servers with powerful computing power. In practice, the number of computation parties can be appropriately selected based on performance, cost, and security requirements.
[0003] However, once the computation is outsourced, the data owner loses actual control, resulting in serious privacy leakage. Most applications want to ensure that sensitive information is hidden from the computing party, and once the computing party performs malicious behavior, the scheme can identify and exclude the party. Then, the computation should continue to run, thereby guaranteeing output delivery (also known as output reachability or robustness) and preventing denial of service attacks. It should be noted that not all computing parties will maliciously deviate from the protocol. On the contrary, most of them will execute the protocol as agreed to obtain rewards. Due to the heterogeneity of computing parties and differences in confidence, this asymmetric corruption model is suitable for many real-world applications. Compared with the static symmetric security model, the scheme does not need to verify the correctness of the behavior of all computing parties, and can use the property of semi-honest parties following the protocol to speed up the computation.
[0004] At present, the research on outsourced computing to achieve robustness mainly considers the honest majority setting, that is, most of the computing parties are honest and only a few are malicious. Taking the three-party scenario as an example, the honest majority setting assumes that there is only one malicious party and the other two parties are honest. These works focus on traditional robustness, that is, identifying the honest party and allowing it to obtain all sensitive information so that the calculation is completed in plain text. In addition, these schemes cannot be extended to n-party scenarios, and it is unrealistic to require the computing parties (usually cloud servers) to be completely honest during the protocol execution. They are more likely to follow the protocol but try to infer additional sensitive data. Summary of the invention
[0005] The present invention proposes an n-party computing scheme (n≥3) that can identify malicious behavior for most semi-honest scenarios. The scheme overcomes the above limitations and aims to obtain a robust, secure and highly available computing system. The reason for setting n=3 is that after excluding the malicious party, the scheme can still be regarded as a two-party calculation. The present invention assumes that one party can perform malicious behavior and the other n-1 parties are semi-honest. The computing party either honestly executes the protocol and gets rewarded, or deviates from the protocol and is caught. In the latter case, the malicious party will be blacklisted or punished.
[0006] The technical solution adopted by the present invention is as follows:
[0007] A first aspect provides an outsourced multi-party computing method capable of identifying malicious behavior, including:
[0008] Receive the secret sharing share of the original data sent by the data owner, wherein the secret sharing share of the original data is obtained by the data owner after performing vector space secret sharing on the original data;
[0009] Verify the multiplication triples;
[0010] For addition and constant multiplication operations, the addition and constant multiplication calculations are performed locally based on the received secret sharing shares and constants. For multiplication, the multiplication calculations are performed based on the received secret sharing shares and the verified triples.
[0011] When the intermediate data needs to be reconstructed, random numbers are first used for blinding, and the blinded results are reconstructed using the received secret sharing shares, and the malicious computing party is identified based on the reconstructed results.
[0012] In one implementation, the computing party verifies the multiplication triplet, including:
[0013] Input victim triplet
[0014] Calculation Square P j ,j∈{0,1,2} uses pseudo-random functions to jointly generate random numbers calculate <v>Indicates the share , The result obtained by doing linear operation;
[0015] P j Call the reconstruction protocol that can identify malicious behavior to calculate v. If P1 is malicious, P2 sends Give P0; P0 calculation If P2 is malicious, P1 sends Give P0, P0 calculate Among them, the reconstruction protocol that can identify malicious behavior allows P0 to perform reconstruction first and assist in identifying malicious computing parties, and then exclude and avoid malicious parties from reconstructing intermediate results. <w>Represents the intermediate result of reconstruction, represents the reconstruction coefficient, <w> 0、 <w> 1、 <w>3 represents the shares held by the computing parties P0, P1, and P3 respectively. <c>1 indicates the share of the tuple held by P1;
[0016] If w=0, the verification succeeds, otherwise the verification fails.
[0017] In one embodiment, for addition and constant multiplication operations, the computing party performs the addition and constant multiplication calculations locally according to the received secret sharing share and the constant, including:
[0018] The computing party inputs the secret sharing share <x> , <y>and constants c1, c2, calculated locally<c1·x+c2·y> = <c1> ·x+ <c2>·y.
[0019] In one embodiment, for multiplication, a multiplication calculation is performed based on the received secret sharing share and the verified triplet, including:
[0020] For multiplication, enter the share <x> , <y>and the verified triples (< / y> < / x> < / c1> < / y> < / x> < / c> < / w> < / w> < / w> < / w> , , <c>), calculation method P j ,j∈{0,1,2} local calculation <h> j = <x> j +< / x> < / h> < / c> j , <v> j = <y> j + j , P0 additional calculation <h> 3= <x> 3+< / x> < / h> < / y> < / v> 3, <h> 4= <x> 4+< / x> < / h> 4, <v> 3= <y> 3+ 3, <v> 4= <y> 4+ 4, <h>Indicates the share <x> ,< / x> < / h> < / y> < / v> < / y> < / v> The result of adding together is <h> j Indicates that the jth computing party will share <x> j and< / x> < / h> j The result of adding together is <h> 3、 <h> 4、 <v> 3、 <v>4 represents the additional calculated share of P0;
[0021] P j ,j∈{0,1,2} calls the reconstruction protocol that can identify malicious behavior to calculate h,v. If P1 is malicious, P h ,j∈{0,2} local calculation <z> h = <x> j ·v- j ·h+ <c> j , P0 additional calculation <z> 3= <x> 3·v- 3·h+ <c> 3, <z> 4= <x> 4·v- 3·h+ <c>4; If P2 is malicious, P j ,j∈{0,1} local calculation <z> j = <x> j ·v- j ·h+ <c> j , P0 additional calculation <z> 3= <x> 3·v- 3·h+ <c> 3, <z> 4= <x>4. The input of the multiplication protocol is the share <x> , <y>, the output is the share of the product <z>, satisfying z = xy, <z> h Indicates P j The product share of <z> 3、 <z>4 indicates the share of reconstruction results calculated additionally by P0.
[0022] In one implementation, when the intermediate data needs to be reconstructed, random numbers are first used for blinding, and the blinded results are reconstructed using the received secret sharing shares, and malicious computing parties are identified based on the reconstructed results, including:
[0023] The computing party P0 calculates x0, x1, x2, x3, x4 based on the received shares and formulas (1)-(5);
[0024] x0=a 00 · <x> 0+a 01 · <x> 1+a 02 · <x>2#(1)
[0025]
[0026] x0~x4 represent the reconstruction results, a 00 、a 01 、a 02 , is the reconstruction coefficient;
[0027] If x2=x4,x0≠x1≠x3, P1 is malicious, P0 sends <x> 0, <x>3 gives P2, output x = x2; P2 calculates
[0028] If x1=x3,x0≠x2≠x4, P2 is malicious; P0 sends <x> 0, <x>3 gives P1, output x = x1; P1 calculates
[0029] Based on the same inventive concept, the second aspect of the present invention provides an outsourced multi-party computing device capable of identifying malicious behavior, comprising:
[0030] A receiving module, used for receiving the secret sharing shares of the original data sent by the data owner, wherein the secret sharing shares of the original data are obtained by the data owner after performing vector space secret sharing on the original data;
[0031] A triple verification module, used to verify the multiplication triples;
[0032] A secure computing module, for performing addition and constant multiplication operations locally according to the received secret sharing shares and constants, and for multiplication, performing multiplication according to the received secret sharing shares and the verified triplet;
[0033] The reconstruction module is used to first use random numbers to blind the intermediate data when it is necessary to reconstruct the intermediate data, and then use the received secret sharing shares to reconstruct the blinded results, and identify the malicious computing party based on the reconstruction results.
[0034] Based on the same inventive concept, the third aspect of the present invention provides an outsourced multi-party computing system that can identify malicious behavior, comprising: the outsourced multi-party computing device that can identify malicious behavior as described in the second aspect and the data owner, wherein the data owner performs vector space secret sharing on the original data and sends the calculated secret sharing share of the original data to each computing party.
[0035] In one implementation, the data owner is specifically used to:
[0036] For the original data x, select two random values We get u=(x,u1,u2) T , is a prime field, u is a constructed vector;
[0037] Calculate separately <x> j =Ψ j u,j∈{0,1,2} and sent to the computing parties P0,P1,P2, and additionally send a share to P0 <x>3=Ψ3·u, <x>4=Ψ4·u, <x> j P is the calculation square j The secret sharing share, Ψ j P is the calculation square j Holds vector.
[0038] Based on the same inventive concept, the fourth aspect of the present invention provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the outsourced multi-party computing method capable of identifying malicious behavior described in the first aspect is implemented.
[0039] Based on the same inventive concept, the fifth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the outsourced multi-party computing method capable of identifying malicious behavior as described in the first aspect is implemented.
[0040] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows:
[0041] 1. Consider an n-party secure computation scheme with output reachability in the presence of malicious adversaries, and focus on the asymmetric corruption setting, where n-1 parties are semi-honest and one party is malicious. The identification process of the malicious party can be regarded as a Byzantine problem, and the scheme completes the agreement between the semi-honest computing parties by excluding the party.
[0042] 2. Traditional secure computing scenarios allow the adversary to choose any computing party to corrupt (as long as it is below a threshold value). This approach requires verifying the correctness of the behavior of all computing parties, which is very costly. The present invention focuses on a specific scenario, where the adversary corrupts a computing party within a predetermined range. The solution does not require complex zero-knowledge proof and other technologies, and can speed up computing based on the property that semi-honest parties honestly follow the protocol. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0044] < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / z> < / z> < / z> < / z> < / y> < / x> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / v> < / v> < / h> < / h> Figure 1 A flow chart of an outsourced multi-party computing method capable of identifying malicious behavior provided by an embodiment of the present invention;
[0045] Figure 2 A schematic diagram of a tuple sacrifice protocol for three parties to identify malicious behavior provided by an embodiment of the present invention;
[0046] Figure 3 A schematic diagram of a multiplication protocol for three parties to identify malicious behavior provided by an embodiment of the present invention;
[0047] Figure 4 A schematic diagram of a reconstruction protocol that allows three parties to identify malicious behavior is provided for an embodiment of the present invention;
[0048] Figure 5 A structural diagram of an outsourced multi-party computing device capable of identifying malicious behavior provided by an embodiment of the present invention;
[0049] Figure 6 A structural diagram of an outsourced multi-party computing system capable of identifying malicious behavior provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0050] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0051] Embodiment 1
[0052] The present invention discloses an outsourced multi-party computing method capable of identifying malicious behavior, see Figure 1 ,include:
[0053] S1: Receive the secret sharing share of the original data sent by the data owner, where the secret sharing share of the original data is obtained by the data owner after performing vector space secret sharing on the original data;
[0054] S2: Verify the multiplication triples;
[0055] S3: For addition and constant multiplication operations, perform addition and constant multiplication calculations locally based on the received secret sharing share and constant. For multiplication, perform multiplication calculations based on the received secret sharing share and the verified triplet.
[0056] S4: When the intermediate data needs to be reconstructed, first use random numbers to blind it, use the received secret sharing shares to reconstruct the blinded results, and identify the malicious computing party based on the reconstruction results.
[0057] Specifically, the execution subject of the method of this embodiment is the computing party, which includes three or more computing parties, and specifically involves four stages: data reception, triple verification, multi-party secure computing, and reconstruction.
[0058] For this solution, the data owner is responsible for sharing the collected data secrets with the computing party, which is usually a cloud server with powerful computing and storage capabilities. They jointly perform secure calculations based on the received secret shares, including addition, constant multiplication, and multiplication operations. In practical applications, the computing party may also perform secret reconstruction to recover the intermediate results. In order to protect data privacy, the reconstructed intermediate results are generally blinded data. The specific steps are as follows:
[0059] Data distribution or reception phase
[0060] 1) For data x, the data owner selects two random values We get u=(x,u1,u2) T ;
[0061] 2) Calculation by data owner <x> j =Ψ j u,j∈{0,1,2} and sent to the computing parties P0,P1,P2. In addition, an additional share is sent to P0 <x>3=Ψ3·u, <x>4=Ψ4·u.
[0062] Triple( , , <c>) verification phase:
[0063] 1) Input the victim triplet
[0064] 2) Calculate square P j ,j∈{0,1,2} uses pseudo-random functions to jointly generate random numbers calculate
[0065] 3) P j Call the reconstruction protocol that can identify malicious behavior to calculate v. If P1 is malicious, P2 sends Give P0; P0 calculation If P2 is malicious, P1 sends Give P0, P0 calculate
[0066] 4) If w=0, the verification succeeds, otherwise the verification fails.
[0067] The secure computing phase includes:
[0068] For addition and constant multiplication operations, enter the share <x> , <y>And constants c1, c2, the calculation side is calculated locally<c1·x+c2·y> =c1· <x> +c2· <y>.
[0069] For multiplication, enter the share <x> , <y> and the verified triples (< / y> < / x> < / y> < / x> < / y> < / x> < / c> , , <c>), calculation method P j ,j∈{0,1,2} local calculation <h> j = <x> j +< / x> < / h> < / c> j , <v> j = <y> j + j , P0 additional calculation <h> 3= <x> 3+< / x> < / h> < / y> < / v> 3, <h> 4= <x> 4+< / x> < / h> 4, <v> 3= <y> 3+ 3, <v> 4= <y> 4+ 4;P j ,j∈{0,1,2} calls the reconstruction protocol that can identify malicious behavior to calculate h,v. If P1 is malicious, P j ,j∈{0,2} local calculation <z> j = <x> j ·v- j ·h+ <c> j , P0 additional calculation <z> 3= <x> 3·v- 3·h+ <c> 3, <z> 4= <x> 4·v- 3·h+ <c>4; If P2 is malicious, P j ,j∈{0,1} local calculation <z> j = <x> j ·v- j ·h+ <c> j , P0 additional calculation <z> 3= <x> 3·v- 3·h+ <c> 3, <z> 4= <x>4.
[0070] The reconstruction phase includes:
[0071] Taking the reconstruction of x as an example, the computing party P0 calculates x0, x1, x2, x3, x4 based on the received shares and formulas 1 to 5;
[0072] If x2=x4,x0≠x1≠x3, P1 is malicious. P0 sends <x> 0, <x>3 gives P2, output x = x2; P2 calculates
[0073] If x1=x3,x0≠x2≠x4, P2 is malicious; P0 sends <x> 0, <x>3 gives P1, output x = x1; P1 calculates
[0074] The specific value of the reconstruction coefficient needs to be determined according to actual conditions. For the convenience of this implementation, it is represented by variables, and the wavy lines and hats are added to distinguish different coefficients.
[0075] In a specific implementation, data is encoded into a ring. Taking the above example, x represents data in scalar form; x represents data in vector form; ψ represents the public matrix of vector space secret sharing; <x>represents the vector space secret sharing share of data x; [n] represents the set {0,…,n-1}; the calculation method Vector space secret sharing allows specifying which parties can reconstruct the secret and which parties cannot reconstruct the secret even if they collude. Access Structure Defined as The set of subsets of Each element in is an authorized set, and only the computing parties in the authorized set can jointly reconstruct the secret value. Assume that the vector space is in Prime field, p is a large prime number, ζ ≥ 2 is an integer, then there exists a function satisfy where a i YesP i The reconstruction coefficients of , j∈{0,…,m-1}. All vectors ψ(P i ) is denoted as Ψ. Assume that Dealer holds a secret value Vector Space Secret Sharing Algorithm Dealer selects ζ-1 random values Construct vector u=(s,u i ,u2,…,u ζ-1 ) T , calculate and send P i ,i∈{0,…,n-1}’s share <s> i =ψ(P i )·u. Since s=(1,0,…,0)·u, the reconstruction algorithm is composed of the participants P i Co-computing The vector space secret sharing shares have a linear property, that is, given the shares <s1> , <s2>and constants c1, c2, the calculation party can obtain locally<c1·s1+c2·s2> =c1· <s1> +c2· <s2>.
[0076] In the following description of the present invention, the data owner uses the input sharing protocol to share the original data. To perform vector space secret sharing, in order to calculate multiplication in the online phase, the computing party needs to obtain the vector share of the multiplication triple ( < / s1> < / s1> < / s> < / x> < / x> < / x> < / x> < / x> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / y> < / v> < / y> < / v> <s> , , <c>), satisfying c=a·b. Triples can be generated in batches by the data owner and sent to the computing party after random shuffle, or they can be jointly generated by the computing party in a distributed manner. The outsourced computing scheme constructed by the present invention includes two types of entities: data owners and computing parties. The data owners are entities that hold the data. They are responsible for sharing the original data secretly with the computing party without participating in the computing process. The computing party is a cloud server with powerful computing and storage capabilities. They jointly perform secure calculations based on the received secret shares, including addition, constant multiplication and multiplication operations. The scheme takes three parties as an example to give a detailed structure, including input sharing, secure calculation and output reconstruction, and then extends it to n parties. In order to simplify the description, the scheme omits the modulus 2 k .
[0077] <·> represents the data share held by the computing party, and the jth computing party holds <·> j ,therefore< / c> The multiplication triple satisfies c = ab, where the computing party only knows the element share, so it is recorded as ( , , <c>).
[0078] 1. Secure third-party outsourcing computing
[0079] 1. Enter sharing
[0080] Define a 5×3 public matrix Ψ, the element Ψ in the jth row j , j∈{0,1,2} corresponds to the calculation parties P0, P1, P2 respectively, where P0 additionally holds the vectors Ψ3=α·Ψ1+β·Ψ2, Ψ4=α′·Ψ1+β′·Ψ2, α, β, α′, β′ are constants not equal to 0. Obviously, there are the following public reconstruction coefficients satisfying:
[0081]
[0082] Since the computing party outside the access structure cannot recover the secret, {Ψ0,Ψ3,Ψ4} and {Ψ1,Ψ2} cannot calculate (1,0,0). When the data owner performs secret sharing on data x, it is necessary to set the vector u and calculate the secret share <x>, including the following steps:
[0083] 1) The data owner selects two random values We get u=(x,u1,u2) T ;
[0084] 2) Calculation by data owner <x> j =Ψ j u,j∈{0,1,2} and sent to the computing parties P0,P1,P2. In addition, an additional share is sent to P0 <x>3=Ψ3·u, <x>4=Ψ4·u.
[0085] 2. Secure computing that can identify malicious behavior
[0086] Assume that the computing party P0 is semi-honest and one of P1 and P2 is malicious. For addition and constant multiplication operations, the input share <x> , <y>and constants c1, c2, the computing party can calculate locally<c1·x+c2·y> =c1· <x> +c2· <y> For multiplication, the scheme first constructs a tuple sacrificial protocol to verify the multiplication triplet (< / y> < / x> < / y> < / x> < / x> < / x> < / x> < / x> < / c> , , <c>) and then design a multiplication method that can identify malicious behavior. The tuple sacrifice protocol that can identify malicious behavior can use batch processing technology to improve verification efficiency, that is, the computing party non-interactively selects random numbers The same r is used for the triples verified in the same batch, and then a reconstruction protocol that can identify malicious behavior is called to restore the intermediate results. The reconstructed result is randomized data, so privacy will not be leaked. If a malicious party does something bad in the process of generating random numbers, the scheme will identify the party and exclude it, but the calculation of the semi-honest party will not be affected. Tuple sacrifice protocol (such as< / c> Figure 2 The method includes the following steps:
[0087] 1) Input verification triplet ( , , <c>) and the sacrificial triplet
[0088] 2) Calculate square P j ,j∈{0,1,2} uses pseudo-random functions to jointly generate random numbers calculate
[0089] 3) P j ,j∈{0,1,2} calls the reconstruction protocol that can identify malicious behavior to calculate v, and then P0 calculates If P1 is malicious, P2 sends <w>2 to P0; P0 calculation If P2 is malicious, P1 sends <w>1 is given to P0, P0 calculates
[0090] 4) If w=0, the verification succeeds, otherwise the verification fails.
[0091] It should be noted that (< / w> < / w> < / c> , , <c>)and represents two non-identical triples, with only the second element b being the same, satisfying c = ab, The wavy line is for< / c> distinguish, The wavy line is for <c>The first triplet is used in subsequent calculations, so its correctness needs to be verified. The second triplet is sacrificed in the verification process and cannot be used later. <v> Indicates the share< / v> < / c> , The result of the linear operation is also the share, so it is recorded as <v>For all shares <v>Performing reconstruction can restore v. <w>Similarly, <w> 1、 <w>3 represents the shares held by the calculation parties P1 and P3 respectively.
[0092] So far, the correctness of the multiplication triple has been verified. Next, we need to build a multiplication protocol that can identify malicious behavior by three parties (such as< / w> < / w> < / w> < / v> < / v> Figure 3 As shown), realize <z>=<x·y> , including the following steps:
[0093] 1) Input share <x> , <y>and the verified triples ( , , <c>), calculation method P j ,j∈{0,1,2} local calculation <h> j = <x> j +< / x> < / h> < / c> j , <v> j = <y> j + j , P0 additional calculation <h> 3= <x> 3+< / x> < / h> < / y> < / v> 3, <h> 4= <x> 4+< / x> < / h> 4, <v> 3= <y> 3+ 3, <v> 4= <y> 4+ 4;
[0094] 2) P j ,j∈{0,1,2} calls the reconstruction protocol that can identify malicious behavior to calculate h,v. If P1 is malicious, P j ,j∈{0,2} local calculation <z> j = <x> j ·v- j ·h+ <c> j , P0 additional calculation <z> 3= <x> 3·v- 3·h+ <c> 3, <z> 4= <x> 4·v- 3·h+ <c>4; If P2 is malicious, P j ,j∈{0,1} local calculation <z> j = <x> j ·v- j ·h+ <c> j , P0 additional calculation <z> 3= <x> 3·v- 3·h+ <c> 3, <z> 4= <x>4.
[0095] The input of the multiplication protocol is the share <x> , <y>, the output is the share of the product <z>, satisfying z=xy. <h>Indicates the share <x> ,< / x> < / h> < / z> < / y> < / x> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / y> < / v> < / y> < / v> The result of adding them together is also the share, so it is recorded as <h>Specifically, the jth computing party will share <x> j and< / x> < / h> j Add together to get <h> j , and similarly we get <v> j 、 <y> j 、 j 。 <h> 3、 <x>3 represents the case where j=3, <h> 4、 <x>4 indicates the case where j=4.
[0096] 3. Reconstruction protocol that can identify malicious behavior
[0097] Since P0 is semi-honest, the reconstruction protocol (such as< / x> < / h> < / x> < / h> < / y> < / v> < / h> Figure 4 As shown in the figure, P0 is allowed to perform reconstruction first and assist in identifying the malicious computing party, and then exclude and avoid the malicious party from reconstructing the intermediate result. Taking the reconstruction of x as an example, secret reconstruction is performed using formulas (1) to (5) respectively. If P1 performs malicious behavior, the reconstruction result of formula (3) is equal to formula (5). If P2 is malicious, only the reconstruction result of formula (2) is equal to formula (4). In order to simplify the description, the results of formulas (1) to (5) are expressed as x0, x1, x2, x3, and x4 respectively.
[0098] x0=a 00 · <x> 0+a 01 · <x> 1+a 02 · <x>2#(1)
[0099]
[0100] 1) The computing party P0 calculates x0, x1, x2, x3, x4 according to the received shares and formulas (1) to (5);
[0101] 2) If x2=x4, x0≠x1≠x3, P1 is malicious. P0 sends <x> 0, <x>3 gives P2, output x = x2; P2 calculates
[0102] 3) If x1=x3, x0≠x2≠x4, P2 is malicious; P0 sends <x> 0, <x>3 gives P1, output x = x1; P1 calculates
[0103] Since malicious parties may do evil, the reconstruction results may be wrong. In order to distinguish them, we record the reconstruction results as x0, x1, x2, x3, and x4 respectively.
[0104] 2. Secure n-party outsourced computing
[0105] 1. Enter sharing
[0106] Define a (n+2)×n public matrix Ψ, the element Ψ in the jth row j ,j∈{0,…,n-1} respectively correspond to the calculation squares P0,…,P n-1 , where P0 additionally holds the vector Ψ n ,Ψ n+1 , whose value is equal to Ψ0,…,Ψ n-1 Obviously, there are the following public reconstruction coefficients that satisfy
[0107]
[0108] When the data owner performs secret sharing on data x, he needs to set the vector u and calculate the secret share <x>, specifically including the following steps:
[0109] 1) For input x, the data owner chooses a random value We get u=(x,u1,…,u n-1 ) T ;
[0110] 2) Calculation by data owner <x> j =Ψ j u,j∈{0,1,…,n-1} and sent to the computing party P j In addition, additional shares are sent to P0 <x> n =ψ n ·u, <x> n+1 =Ψ n+1 ·u.
[0111] 2. Secure computing that can identify malicious behavior
[0112] For n-square addition and constant multiplication operations, enter the share <x> , <y>and constants c1, c2, the computing party can calculate locally<c1·x+c2·y> = <c1> ·x+ <c2>·y. For the n-way multiplication and reconstruction protocol, the calculation process is similar to the three-way protocol. The multiplication is blinded using triples and then reconstructed. n-1 Collusion, no information can be leaked even if the P0 share is missing.
[0113] 3. Reconstruction protocol that can identify malicious behavior
[0114] Computational Protocol with Malicious Parties Assume that P0 is semi-honest, P1,…,P n-1 One of the parties can perform malicious behavior. Addition and constant multiplication operations are completed locally. For multiplication, the scheme uses a tuple sacrifice technique that allows n parties to identify malicious behavior to verify the correctness of the triple. This process is similar to the three-party protocol. The core component of multiplication is a reconstruction protocol that can identify malicious behavior and thereby identify and exclude malicious parties. The identification process is also based on the equivalence of the reconstruction results, which is due to the fact that reconstruction is the only step in the multiplication calculation that requires interaction. Once the computing party commits a malicious act, the secret reconstruction performed with the malicious party's share as input will definitely not be equivalent, while the secret reconstruction performed with the semi-honest party's share as input will definitely be equivalent. Since the input of the reconstruction protocol is data blinded with random numbers, sensitive information will not be leaked. In addition, the scheme allows P0 to perform secret reconstruction first, and P1,…,P n-1 Either the protocol is executed as agreed upon, or it deviates from the protocol and is caught, with that party excluded and the computation completed by the semi-honest party.
[0115] In general, an n-party computing scheme (n≥3) is designed that can identify malicious behavior in most semi-honest scenarios. The identification process of malicious parties can be regarded as a Byzantine problem. The scheme assumes that one party can perform malicious behavior and the other n-1 parties are semi-honest. The computing party either honestly executes the protocol and gets paid, or deviates from the protocol and is caught. In the latter case, the malicious party will be blacklisted or punished. Compared with most schemes that consider symmetric corruption settings, the computing scheme of the present invention does not need to verify the behavior of all computing parties, nor does it require complex zero-knowledge proof and other technologies.
[0116] Embodiment 2
[0117] Based on the same inventive concept, this embodiment discloses an outsourced multi-party computing device capable of identifying malicious behavior, see Figure 5 ,include:
[0118] A receiving module 201 is used to receive the secret sharing shares of the original data sent by the data owner, wherein the secret sharing shares of the original data are obtained by the data owner after performing vector space secret sharing on the original data;
[0119] A triplet verification module 202, for verifying the multiplication triplet;
[0120] The secure computing module 203 is used to perform addition and constant multiplication operations locally according to the received secret sharing shares and constants, and for multiplication, perform multiplication according to the received secret sharing shares and the verified triplet;
[0121] The reconstruction module 204 is used to first use random numbers to blind the intermediate data when it is necessary to reconstruct the intermediate data, reconstruct the blinded result using the received secret sharing share, and identify the malicious computing party based on the reconstruction result.
[0122] Since the device introduced in the second embodiment of the present invention is a device used to implement the outsourced multi-party computing method for identifying malicious behavior in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, the person skilled in the art can understand the specific structure and deformation of the device, so it is not repeated here. All devices used in the method in the first embodiment of the present invention belong to the scope of protection of the present invention.
[0123] Embodiment 3
[0124] Based on the same inventive concept, this embodiment discloses an outsourced multi-party computing system capable of identifying malicious behavior. Figure 6 , including: the outsourced multi-party computing device 20 (computing party) capable of identifying malicious behavior in the second embodiment and the data owner 10, wherein the data owner 10 performs vector space secret sharing on the original data and sends the calculated secret sharing shares of the original data to each computing party.
[0125] In one implementation, the data owner is specifically used to:
[0126] For the original data x, select two random values We get u=(x,u1,u2) T , is a prime field, u is a constructed vector;
[0127] Calculate separately <x> j =Ψ j u,j∈{0,1,2} and sent to the computing parties P0,P1,P2, and additionally send a share to P0 <x>3=Ψ3·u, <x>4=Ψ4·u, <x> j P is the calculation square j The secret sharing share, Ψ j P is the calculation square j Holds vector.
[0128] Since the system introduced in the third embodiment of the present invention is a system used to implement the outsourced multi-party computing method capable of identifying malicious behavior in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and deformation of the system, so it is not described here in detail. All systems used in the method in the first embodiment of the present invention belong to the scope of protection of the present invention.
[0129] Embodiment 4
[0130] Based on the same inventive concept, the present invention further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the method described in the first embodiment is implemented.
[0131] Since the computer-readable storage medium introduced in the fourth embodiment of the present invention is the computer-readable storage medium used to implement the outsourced multi-party computing method capable of identifying malicious behavior in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and deformation of the computer-readable storage medium, so it is not repeated here. All computer-readable storage media used in the method of the first embodiment of the present invention belong to the scope of protection of the present invention.
[0132] Embodiment 5
[0133] The present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in Embodiment 1 when executing the program.
[0134] Since the computer device introduced in the fifth embodiment of the present invention is a computer device used to implement the outsourced multi-party computing method capable of identifying malicious behavior in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, the person skilled in the art can understand the specific structure and deformation of the computer device, so it is not repeated here. All computer devices used in the method of the first embodiment of the present invention belong to the scope of protection of the present invention.
[0135] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0136] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0137] Although preferred embodiments of the present invention have been described, additional changes and modifications may be made to these embodiments by those skilled in the art once the basic creative concepts are known. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention. Obviously, those skilled in the art may make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if these modifications and variations of the embodiments of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.< / x> < / x> < / x> < / x> < / c1> < / y> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / x> < / y> < / x> < / z> < / s> < / x> < / x> < / x> < / v>
Claims
1. An outsourced multi-party computing method capable of identifying malicious behavior, characterized in that: include: Receive the secret sharing share of the original data sent by the data owner, wherein the secret sharing share of the original data is obtained by the data owner after performing vector space secret sharing on the original data; Verify the multiplication triples; For addition and constant multiplication operations, the addition and constant multiplication calculations are performed locally based on the received secret sharing shares and constants. For multiplication, the multiplication calculations are performed based on the received secret sharing shares and the verified triples. When the intermediate data needs to be reconstructed, random numbers are first used for blinding, and the blinded results are reconstructed using the received secret sharing shares, and the malicious computing party is identified based on the reconstructed results.
2. The outsourced multi-party computing method capable of identifying malicious behavior as claimed in claim 1, characterized in that: The computing party verifies the multiplication triplet, including: Input victim triplet Calculation Square P j , j∈{0, 1, 2} uses a pseudo-random function to jointly generate random numbers calculate <v>Indicates the share , The result obtained by doing linear operation; < / v> P j Call the reconstruction protocol that can identify malicious behavior to calculate v. If P1 is malicious, P2 sends Give P0; P0 calculation If P2 is malicious, P1 sends Give P0, P0 calculate Among them, the reconstruction protocol that can identify malicious behavior allows P0 to perform reconstruction first and assist in identifying malicious computing parties, and then exclude and avoid malicious parties from reconstructing intermediate results. <w>Represents the intermediate result of reconstruction, represents the reconstruction coefficient, <w> 0、 <w> 1、 <w>3 represents the shares held by the computing parties P0, P1, and P3 respectively, <c> 1 indicates the share of the tuple held by P1;< / c> < / w> < / w> < / w> < / w> If w=0, the verification succeeds, otherwise the verification fails.
3. The outsourced multi-party computing method capable of identifying malicious behavior as claimed in claim 1, characterized in that: For addition and constant multiplication operations, the computing party performs addition and constant multiplication calculations locally based on the received secret sharing shares and constants, including: The computing party inputs the secret sharing share <x> , <y>and constants c1, c2, calculated locally<c1·x+c2·y> = <c1> ·x+ <c2> ·y。< / c2> < / c1> < / y> < / x> 4. The outsourced multi-party computing method capable of identifying malicious behavior as claimed in claim 2, characterized in that: For multiplication, multiplication is performed based on the received secret sharing share and the verified triplet, including: For multiplication, enter the share <x> , <y>and the verified triples ( <a), , <c>), calculation method P j , j∈{0, 1, 2} local calculation <h> j = <x> j +< / x> < / h> < / c> < / y> < / x> j , <v> j = <y> j + j , P0 additional calculation <h> 3= <x> 3+< / x> < / h> < / y> < / v> 3, <h> 4= <x> 4+< / x> < / h> 4, <v> 3= <y> 3+ 3, <v> 4= <y> 4+ 4, <h>Indicates the share <x> ,< / x> < / h> < / y> < / v> < / y> < / v> The result of adding together is <h> j Indicates that the jth computing party will share <x> j and< / x> < / h> j The result of adding together is <h> 3、 <h> 4、 <v> 3、 <v> 4 represents the additional calculated share of P0;< / v> < / v> < / h> < / h> P j , j∈{0, 1, 2} calls the reconstruction protocol that can identify malicious behavior to calculate h, v. If P1 is malicious, P j , j∈{0,2} local calculation <z> j = <x> j ·v- j ·h+ <c> j , P0 additional calculation <z> 3= <x> 3·v- 3·h+ <c> 3, <z> 4= <x> 4·v- 3·h+ <c>4; If P2 is malicious, P j , j∈{0,1} local calculation <z> j = <x> j ·v- j ·h+ <c> j , P0 additional calculation <z> 3= <x> 3·v- 3·h+ <c> 3, <z> 4= <x>4. The input of the multiplication protocol is the share <x> , <y>, the output is the share of the product <z>, satisfying z = xy, <z> j Indicates P j The product share of <z> 3、 <z> 4 indicates the share of reconstruction results calculated additionally by P0.< / z> < / z> < / z> < / z> < / y> < / x> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> < / c> < / x> < / z> 5. The outsourced multi-party computing method capable of identifying malicious behavior as claimed in claim 1, characterized in that: When the intermediate data needs to be reconstructed, first use random numbers to blind the data, and then use the received secret sharing shares to reconstruct the blinded results. The malicious computing party is identified based on the reconstructed results, including: The computing party P0 calculates x0, x1, x2, x3, x4 based on the received shares and formulas (1)-(5); x0=a 00 · <x> 0+a 01 · <x> 1+a 02 · <x> 2#(1)< / x> < / x> < / x> x0~x4 represent the reconstruction results, a 00 、a 01 、a 02 , is the reconstruction coefficient; If x2=x4, x0≠x1≠x3, P1 is malicious, P0 sends <x> 0, <x>3 gives P2, output x = x2; P2 calculates < / x> < / x> If x1=x3, x0≠x2≠x4, P2 is malicious; P0 sends <x> 0, <x>3 gives P1, output x = x1; P1 calculates < / x> < / x> 6. An outsourced multi-party computing device capable of identifying malicious behavior, characterized in that: include: A receiving module, used for receiving the secret sharing shares of the original data sent by the data owner, wherein the secret sharing shares of the original data are obtained by the data owner after performing vector space secret sharing on the original data; A triple verification module, used to verify the multiplication triples; A secure computing module, for performing addition and constant multiplication operations locally according to the received secret sharing shares and constants, and for multiplication, performing multiplication according to the received secret sharing shares and the verified triplet; The reconstruction module is used to first use random numbers to blind the intermediate data when it is necessary to reconstruct the intermediate data, and then use the received secret sharing shares to reconstruct the blinded results, and identify the malicious computing party based on the reconstruction results.
7. An outsourced multi-party computing system capable of identifying malicious behavior, characterized in that: include: The outsourced multi-party computing device capable of identifying malicious behavior and the data owner as described in claim 6, wherein the data owner performs vector space secret sharing on the original data and sends the calculated secret sharing shares of the original data to each computing party.
8. The outsourced multi-party computing system capable of identifying malicious behavior as claimed in claim 7, characterized in that: The data owner is specifically used to: For the original data x, select two random values We get u = (x, u1, u2) T , is a prime field, u is a constructed vector; Calculate separately <x> j =ψ j u, j∈{0, 1, 2} and sent to the computing parties P0, P1, P2, and additionally send a share to P0 <x>3=Ψ3·u, <x>4=Ψ4·u, <x> j P is the calculation square j The secret sharing share, Ψ j P is the calculation square j Holds vector.< / x> < / x> < / x> < / x> 9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the outsourced multi-party computing method capable of identifying malicious behavior as claimed in any one of claims 1 to 5 is implemented.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the outsourced multi-party computing method capable of identifying malicious behavior as claimed in any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Mobile secure multi-party computing method and system based on copy secret sharing
CN117614684A
Method and System for Fault Tolerant and Secure Multiparty Computation with SPDZ
US20190372760A1
Cited By
Recommendation method based on cross-platform user behavior analysis
CN121437104A