Multi-party secure computing method and device
By keeping the ciphertext in the Montgomery state in multi-party security computing and using Montgomery subtraction technology, the problem of low homomorphic encryption computing performance is solved, and the ciphertext computing performance is significantly improved.
Patent Information
- Application Number
- CN202510111779.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-12
- Publication Date
- 2025-05-16
AI Technical Summary
Homomorphic encryption has low computing performance in multi-party secure computing, and it is difficult to effectively improve it to meet the needs of multi-party joint data processing for privacy protection.
By keeping the ciphertext in the Montgomery state, use Montgomery reduction technology to improve computing performance. Specific methods include mapping operations and homomorphic encryption of plaintext data, forming a converted ciphertext in Montgomery state, and performing homomorphic operations in this state, including modular multiplication operations.
It significantly improves the computing performance in the ciphertext computing stage and improves the application efficiency of homomorphic encryption in multi-party secure computing.
Smart Images

Figure CN120017243A_ABST
Abstract
Description
[0001] This application is a divisional application of the invention patent application with application number 202210380969.0 filed on April 12, 2022, and entitled “Method and Device for Multi-Party Secure Computing”. Technical Field
[0002] One or more embodiments of the present specification relate to joint data processing, and more particularly, to a method and apparatus for multi-party secure computing based on privacy protection. Background Art
[0003] With the development of computer technology, joint data processing has been applied to various technical fields for analyzing and processing various business data. A typical example is federated machine learning, which requires data that often involves multiple fields. For example, in the merchant classification analysis scenario based on machine learning, the electronic payment platform has the merchant's transaction flow data, the e-commerce platform stores the merchant's sales data, and the banking institution has the merchant's loan data. Data often exists in the form of isolated islands. Due to issues such as data security and user privacy, data integration faces great resistance, and it is difficult to integrate data scattered across various platforms to train machine learning models. Therefore, it is proposed that multiple parties jointly conduct data processing and model training under the premise of protecting privacy, so that data can be available but not visible.
[0004] In order to achieve data privacy protection in the process of joint data processing, a variety of secure multi-party computation (MPC) methods have been proposed, and homomorphic encryption is one of the most widely used methods. However, due to its computational complexity, the computing performance of homomorphic encryption needs to be further improved.
[0005] Therefore, we hope to have an improved solution to enhance the computing performance of the homomorphic encryption computing process so that it can be better applied to multi-party joint data processing to protect privacy. Summary of the invention
[0006] One or more embodiments of the present specification describe a method and apparatus for multi-party secure computing, which can improve computing performance by using Montgomery reduction during the ciphertext computing stage of homomorphic encryption.
[0007] According to a first aspect, a method for multi-party secure computing is provided, comprising:
[0008] The first party performs a first mapping operation and homomorphic encryption on the first plaintext data to obtain a first converted ciphertext in a Montgomery state; the first mapping operation is used to convert the data from an integer ring to a Montgomery state;
[0009] The first party sends the first converted ciphertext to the second party;
[0010] The second party performs a first homomorphic operation based on the first conversion ciphertext in the Montgomery state to obtain a first result ciphertext in the Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation.
[0011] According to one implementation, the method further includes: the second party sending the first result ciphertext to the first party; and the first party performing Montgomery reduction and decryption operations on the first result ciphertext to obtain a first result plaintext.
[0012] According to another embodiment, the method further includes: the second party sends the first result ciphertext to a third party; the third party performs a second homomorphic operation based on the first result ciphertext in a Montgomery state to obtain a second result ciphertext.
[0013] In one embodiment, the first party performs a first mapping operation and homomorphic encryption on the first data to obtain a first converted ciphertext in a Montgomery state, specifically including: the first party performs homomorphic encryption on the first plaintext data to obtain a first original ciphertext; using the first mapping operation, converting the first ciphertext to a Montgomery state to obtain the first converted ciphertext.
[0014] In another embodiment, the first party performs a first mapping operation and homomorphic encryption on the first data to obtain a first converted ciphertext in a Montgomery state, specifically including: the first party uses the first mapping operation to convert the first plaintext data to the Montgomery state to obtain a first converted plaintext; and performs an encryption operation on the first converted plaintext in the Montgomery state to obtain the first converted ciphertext.
[0015] According to one implementation, the method further includes: the second party obtains a second conversion ciphertext in a Montgomery state; and obtaining a first result ciphertext in a Montgomery state specifically includes: performing the first homomorphic operation on the first conversion ciphertext and the second conversion ciphertext to obtain the first result ciphertext.
[0016] In one embodiment of the above implementation, the second party receives the second converted ciphertext from the first party.
[0017] In another embodiment of the above implementation, the second party performs the first mapping operation and homomorphic encryption on its local second plaintext data to obtain the second converted ciphertext.
[0018] According to one implementation, the first plaintext data is parameter data of a business prediction model, and the second plaintext data is feature data of a business object.
[0019] According to a second aspect, a method for multi-party secure computing is provided, which is performed by a first party and includes:
[0020] Performing a first mapping operation and homomorphic encryption on the first plaintext data to obtain a first converted ciphertext in a Montgomery state; the first mapping operation is used to convert the data from an integer ring to a Montgomery state;
[0021] sending the first transformed ciphertext to a second party;
[0022] receiving a result ciphertext from a third party, wherein the result ciphertext is obtained by performing a homomorphic operation based on the first transformed ciphertext in a Montgomery state, wherein the homomorphic operation includes a modular multiplication operation;
[0023] Performing Montgomery reduction and decryption operations on the result ciphertext to obtain a result plaintext.
[0024] According to a third aspect, a method for multi-party secure computing is provided, which is performed by a second party and includes:
[0025] receiving a first converted ciphertext in a Montgomery state from a first party, wherein the first converted ciphertext is obtained by the first party performing a first mapping operation and homomorphic encryption on first plaintext data; the first mapping operation is used to convert data from an integer ring to a Montgomery state;
[0026] In the Montgomery state, performing a first homomorphic operation based on the first conversion ciphertext to obtain a first result ciphertext in the Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation;
[0027] The first result ciphertext is sent.
[0028] According to a fourth aspect, a system for multi-party secure computing is provided, comprising a first party and a second party, wherein:
[0029] The first party is used to perform a first mapping operation and homomorphic encryption on the first plaintext data to obtain a first converted ciphertext in a Montgomery state; the first mapping operation is used to convert the data from an integer ring to a Montgomery state;
[0030] The first party is further configured to send the first converted ciphertext to the second party;
[0031] The second party is used to perform a first homomorphic operation based on the first conversion ciphertext in the Montgomery state to obtain a first result ciphertext in the Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation.
[0032] According to a fifth aspect, a multi-party secure computing apparatus is provided, which is deployed in a first party and includes:
[0033] An encryption conversion unit is configured to perform a first mapping operation and homomorphic encryption on the first plaintext data to obtain a first converted ciphertext in a Montgomery state; the first mapping operation is used to convert the data from an integer ring to a Montgomery state;
[0034] a sending unit, configured to send the first converted ciphertext to a second party;
[0035] a receiving unit configured to receive a result ciphertext from a third party, wherein the result ciphertext is obtained by performing a homomorphic operation based on the first transformed ciphertext in a Montgomery state, wherein the homomorphic operation includes a modular multiplication operation;
[0036] The decryption conversion unit is configured to perform Montgomery reduction and decryption operations on the result ciphertext to obtain a result plaintext.
[0037] According to a sixth aspect, a multi-party secure computing apparatus is provided, which is deployed in a second party and includes:
[0038] A receiving unit is configured to receive a first converted ciphertext in a Montgomery state from a first party, wherein the first converted ciphertext is obtained by the first party performing a first mapping operation and homomorphic encryption on first plaintext data; the first mapping operation is used to convert data from an integer ring to a Montgomery state;
[0039] an operation unit configured to perform a first homomorphic operation based on the first conversion ciphertext in a Montgomery state to obtain a first result ciphertext in a Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation;
[0040] A sending unit is configured to send the first result ciphertext.
[0041] According to the seventh aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the method of any one of the first to third aspects above.
[0042] According to a fourth aspect, a computing device is provided, including a memory and a processor, wherein an executable code is stored in the memory, and when the processor executes the executable code, the method of any one of the first to third aspects described above is implemented.
[0043] In the multi-party secure computing solution provided in the embodiments of this specification, by keeping the ciphertext in the Montgomery state, Montgomery reduction can be used to improve the computing performance of the ciphertext computing stage. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0045] Figure 1 A schematic diagram showing a modular multiplication operation using Montgomery reduction is shown;
[0046] Figure 2 A schematic diagram showing modular exponentiation using Montgomery reduction;
[0047] Figure 3 A schematic diagram showing a calculation process of multi-party secure calculation according to an embodiment;
[0048] Figure 4 A schematic diagram showing a calculation process of multi-party secure calculation according to an embodiment;
[0049] Figure 5 Show the correspondence between plaintext space, ciphertext space and Montgomery space;
[0050] Figure 6 A schematic diagram showing the structure of a multi-party secure computing device deployed in a first party according to an embodiment;
[0051] Figure 7 A schematic diagram showing the structure of a multi-party secure computing device deployed in a second party according to one embodiment. DETAILED DESCRIPTION
[0052] The solution provided in this specification is described below in conjunction with the accompanying drawings.
[0053] As mentioned above, in scenarios where multiple parties jointly perform data operations, homomorphic encryption is a cryptographic technology that can both protect data privacy and implement data computing. It allows the computing party to perform operations on ciphertext and obtain a result that is still encrypted, and the result obtained by decrypting it is the same as the result of the same operation on the plaintext.
[0054] Specifically, a homomorphic encryption algorithm is an encryption function that performs operations on plaintext before encryption, and performs the same operations on the ciphertext after encryption, and the results are equivalent. For example, encrypting v1 and v2 with the same public key PK yields E PK (v1) and E PK (v2), if:
[0055] E PK (v1+v2)=E PK (v1)⊕E PK (v2) (1)
[0056] Then it is considered that the encryption algorithm satisfies additive homomorphism, where ⊕ is the corresponding homomorphic addition operation.
[0057] For example, the Paillier algorithm is a commonly used encryption algorithm that satisfies additive homomorphism. Specifically, the Paillier algorithm uses an asymmetric encryption method that uses public key encryption and private key decryption. Its public key can be represented by (N, g), where N is a natural number and can be represented as the product of two large prime numbers p and q: N = p*q; g is less than N. 2 And a natural number that satisfies certain mathematical conditions. In practice, g=N+1 can be taken. According to the Paillier encryption algorithm, when the public key PK is used to encrypt the message m, the ciphertext c can be expressed as:
[0058] c=g m *r N =(N+1) m *r N (modN 2 ) (2)
[0059] Among them, r is the random number used for encryption, and mod is the modulus operation.
[0060] Based on the ciphertext form shown in formula (2), it is easy to verify that the Paillier algorithm satisfies:
[0061] E PK (v1+v2)=E PK (v1) E PK (v2) (3)
[0062] Then the multiplication of the ciphertext E PK (v1) E PK (v2) corresponds to the homomorphic addition operation.
[0063] Based on the Pailiier algorithm, a variety of improved algorithms have been proposed, such as the OU (Okamoto-Uchiyama) algorithm, the DJ The encryption and operation rules are similar to those of Paillier. The encryption process involves power operations and modulus operations, and the ciphertext operation stage involves ciphertext multiplication.
[0064] Since homomorphic encryption algorithms can perform calculations on ciphertext, which is an ideal feature for privacy-preserving data processing, they are commonly used as a multi-party secure computing method in joint computing scenarios. However, the computing performance of homomorphic encryption is several orders of magnitude slower than plaintext computing, which has become a constraint on its further promotion and application.
[0065] Analysis shows that no matter Pailler, OU, or other homomorphic encryption algorithms, their calculation process is performed in the modulo space, which involves a large number of modulo operations, which is the main factor leading to the low performance of homomorphic encryption operations. As those skilled in the art know, modulo operations involve division, and division calculations on the CPU are relatively slow. Specifically, the calculation process of amodm is shown in the following formula (4):
[0066]
[0067] in, It indicates rounding down. From formula (4), it can be seen that the calculation of amodm involves one division, one multiplication and one subtraction. Multiplication and subtraction are relatively fast on the CPU, while division takes a long time.
[0068] In order to avoid the division operation in the modulo process and speed up the modulo calculation, Montgomery reduction, or Montgomery reduction, was proposed. The purpose of Montgomery reduction is to calculate the value of a mod m without using division.
[0069] Specifically, Montgomery reduction can be described as follows: let m be an integer representing the modulo space; R is an integer related to m and taken according to the base number, R>m, and m and R are relatively prime; then for a given integer T, the calculation result of its Montgomery reduction is: TR -1 mod m. When R is chosen appropriately, Montgomery reduction can quickly calculate TR -1 mod m. This calculation process achieves fast modulo operation by replacing traditional division with simple shift operations.
[0070] Montgomery reduction cannot be applied directly, and requires that the numbers conform to a certain form. For example, to calculate a mod m, first calculate R based on m (as described above, a value related to m), and then if a happens to satisfy TR -1 In the form of TR -1 mod m can be calculated quickly. Therefore, the key step in using Montgomery reduction is to construct TR -1 The following is a practical example of how to use Montgomery reduction to speed up modulo-related operations.
[0071] Figure 1 Figure 2 shows a schematic diagram of modular multiplication using Montgomery reduction. Figure 1 In the example, assuming that a and b are integers in the integer ring Z and m is a positive integer, the example attempts to calculate a*b mod m, that is, the modular multiplication of a and b.
[0072] like Figure 1As shown, in order to apply Montgomery reduction to perform modular multiplication operations, the operation process mainly includes the following steps.
[0073] First, the mapping function f(x) is used to transform a and b from the integer ring (hereinafter referred to as Z ring) to the Montgomery ring (hereinafter referred to as M ring) to obtain the Montgomery state results aR and bR. Figure 1 As shown, the mapping function f(x)=xR modm is used to map the input integer x to the Montgomery ring, and xR is recorded as the mapping result of x in the Montgomery state.
[0074] Then, T = aR*bR is calculated in the Montgomery state (one ordinary multiplication), and then a Montgomery reduction is applied to obtain aR*bR*R^-1mod m = abR mod m. This result is the result in the M ring or Montgomery state.
[0075] Finally, by applying Montgomery reduction again, the result abR mod m in the M ring is mapped back to the Z ring to obtain abmod m, which is the desired target calculation result.
[0076] Figure 2 Figure 2 shows a schematic diagram of modular exponentiation using Montgomery reduction. Figure 2 In the example, assuming that g is an integer in the integer ring Z, and e and m are positive integers, the example attempts to calculate g^e mod m, that is, the modular power of g.
[0077] like Figure 2 As shown, in order to apply Montgomery reduction to perform modular exponentiation operation, the operation process mainly includes the following steps.
[0078] First, use the mapping function f(x) to convert g from the integer ring to the Montgomery ring, and get the Montgomery state result gR. Then, in the Montgomery state, decompose the e-th power of gR into multiple modular multiplications, and apply a Montgomery reduction to each modular multiplication, and finally get the M state result (g) e R mod m. Finally, by applying Montgomery reduction again, the result in the M ring is mapped back to the Z ring to obtain g e mod m is the target calculation result.
[0079] pass Figure 1 and Figure 2 From the example, we can see that if we want to use Montgomery reduction to perform modulo operations, we must first use the mapping function f(x) to map the value x to be calculated from the integer ring Z ring to the M ring. However, the calculation of xR mod m in f(x) itself involves division, and the performance is relatively low. Therefore, the conversion speed from the Z ring to the M ring is relatively slow.
[0080] Therefore, in Figure 1In the example, although the modular multiplication can be performed using Montgomery reduction, the performance is not as good as directly calculating the multiplication and modulo on the Z ring, given the time-consuming conversion from the Z ring to the M ring. Figure 2 In the example, because g^e is decomposed into a very large number of modular multiplications, the benefits of multiple modular multiplications are enough to offset the overhead of converting the Z ring to the M ring. Therefore, using Montgomery reduction in modular exponentiation can speed up the calculation.
[0081] The encryption process of the homomorphic encryption algorithm generally involves a large number of modular exponentiation operations, for example, see the encryption process of the Paillier algorithm shown in formula (2). Therefore, the encryption phase of the homomorphic encryption algorithm can be accelerated using Montgomery reduction. However, the ciphertext operation phase of the homomorphic encryption algorithm, such as the homomorphic addition shown in formula (3), generally involves modular multiplication operations. As mentioned above, in modular multiplication operations, the performance of using Montgomery reduction is not higher than direct calculation. Therefore, in conventional technology, Montgomery reduction cannot be used to accelerate the homomorphic operation of ciphertext.
[0082] In view of this, the inventor proposes a new scheme architecture, in which the encryption party keeps the encrypted ciphertext in the Montgomery state, so that the calculation party can use Montgomery reduction to perform homomorphic operations on the ciphertext in the Montgomery state, including modular multiplication operations, which greatly improves the calculation performance of the ciphertext operation stage. The implementation method of the above scheme architecture is described in detail below.
[0083] Figure 3 A schematic diagram of a calculation process of a multi-party secure calculation according to an embodiment is shown. Figure 3 In the example, multi-party secure computing involves a first party and a second party, wherein the first party acts as an encryptor / decryptor and the second party acts as a ciphertext calculator. The first party and the second party may be specifically implemented as any server, device, platform, equipment or equipment cluster with computing and processing capabilities, which is not limited here. In different business scenarios of different embodiments, the first party and the second party may have different business roles. In one embodiment, the first party may be a model owner, who has a pre-trained business prediction model that requires privacy protection, and the second party may be a model user, who has some feature data of the business object to be tested. In another embodiment, the first party may be a model user and the second party may be a model owner. In yet another embodiment, the first party is the owner of the privacy data and the second party is a computing platform.
[0084] In the preparatory stage before multi-party secure computing, the first party first generates a key pair of the homomorphic encryption algorithm, namely the public key PK and the private key SK. The public key PK is open to the public, and the private key SK is held by the party. The homomorphic encryption algorithm can be the Paillier algorithm, OU algorithm, DJ algorithm, etc. These homomorphic encryption algorithms use modular exponentiation in the encryption stage and involve modular multiplication in the ciphertext operation stage.
[0085] After preparing the public and private key pairs, the two parties can perform multi-party secure computing.
[0086] In the multi-party secure computation process, in step 31, the first party performs a mapping operation and homomorphic encryption on the first plaintext data to obtain a first converted ciphertext in a Montgomery state. Specifically, the first plaintext data, denoted as p1, is private data held by the first party and is also the target data to be encrypted. The above-mentioned mapping operation is a mapping function for converting data from an integer ring to a Montgomery state, such as the aforementioned mapping function f(x) = xR mod m. If the ciphertext obtained by homomorphic encryption of the first plaintext data p1 is denoted as c1, the first converted ciphertext in the Montgomery state obtained in step 31 can be denoted as c1R.
[0087] To obtain the above-mentioned first converted ciphertext, in one embodiment, the first party first performs homomorphic encryption on the first plaintext data p1 in a conventional manner to obtain the first original ciphertext c1; then uses the above-mentioned mapping operation to convert the first original ciphertext c1 into a Montgomery state to obtain the first converted ciphertext c1R.
[0088] As mentioned above, Montgomery reduction can be used to accelerate modular exponentiation in the encryption stage. Therefore, in another embodiment, more advantageously, the first party can use the above-mentioned mapping operation f(x) to convert the first plaintext data p1 into the Montgomery state to obtain the first converted plaintext p1R; then, the first converted plaintext p1R is encrypted in the Montgomery state to obtain the first converted ciphertext c1R. The process of encrypting the first converted plaintext p1R in the Montgomery state involves Figure 2 The modular exponentiation operation in the M ring is shown. However, unlike Figure 2 The result in the M ring is converted back to the integer ring. In step 31, the first party directly outputs the result in the M ring, that is, the result of the Montgomery state, as the first conversion ciphertext c1R.
[0089] Next, in step 32, the first party sends the first converted ciphertext c1R to the second party.
[0090] Afterwards, in step 33, the second party performs a homomorphic operation in the Montgomery state based on the first conversion ciphertext c1R to obtain a first result ciphertext c'R in the Montgomery state, wherein the above homomorphic operation includes a modular multiplication operation, such as a homomorphic addition operation in the Pailler algorithm or the OU algorithm (corresponding to ciphertext multiplication).
[0091] According to one embodiment, the homomorphic operation includes performing a homomorphic operation, such as homomorphic addition, on the first transformed ciphertext c1R and another ciphertext data. In order to perform the homomorphic operation in the Montgomery state, the second party needs to ensure that the other ciphertext data is also in the Montgomery state.
[0092] To this end, in one embodiment, the second party obtains a second transformed ciphertext c2R in a Montgomery state. In one example, the second transformed ciphertext may come from the first party, that is, the first party encrypts and transforms the second plaintext data p2 in a manner similar to the first transformed ciphertext to obtain the second transformed ciphertext c2R, and then sends it to the second party. In another example, the second transformed ciphertext may come from the second party itself, that is, the second party reads its local second plaintext data p2, performs the aforementioned mapping operation and homomorphic encryption on the data, and obtains the second transformed ciphertext c2R. It should be understood that the homomorphic encryption process uses a public key PK for encryption, and the public key PK is public, so the second party can also encrypt and map the second plaintext data in a manner similar to the first party to obtain the first transformed ciphertext, and obtain the second transformed ciphertext c2R.
[0093] Then, the second party performs a homomorphic operation on the first transformed ciphertext c1R and the second transformed ciphertext c2R in the Montgomery state. For example, when the homomorphic operation corresponds to ciphertext multiplication, the homomorphic operation of the first transformed ciphertext c1R and the second transformed ciphertext c2R corresponds to Figure 1 The modular multiplication operation in the M ring is shown in .
[0094] Although the homomorphic operation performed by the second party is described above in conjunction with the second converted ciphertext, it should be understood that the homomorphic operation performed by the second party may involve more data, for example, also involve a third ciphertext, and the homomorphic operation may also include more complex operations, such as multiple modular multiplications, and combinations of modular multiplication results, etc., which are not limited here.
[0095] In this way, the second party performs homomorphic operation in the Montgomery state based on the first conversion ciphertext to obtain a first result ciphertext c'R in the Montgomery state. Then, in step 34, the second party sends the first result ciphertext c'R to the first party.
[0096] Therefore, in step 35, the first party performs Montgomery reduction and decryption operations on the first result ciphertext c'R to obtain the first result plaintext. Specifically, the first party can first perform Montgomery reduction on the first result ciphertext c'R to obtain a ciphertext c' in a normal form (in an integer ring); then use the private key SK held by the first party to decrypt the ciphertext c' to obtain the first result plaintext.
[0097] It can be understood that the above multi-party secure computing can be applied to a variety of different business scenarios. In different business scenarios, the data transmitted between the first party and the second party can have different business meanings. For example, when the first party is the model owner and the second party is the model user, the first plaintext data can be the model parameters of the business prediction model owned by the first party, and the first party encrypts it and sends it to the second party; the second plaintext data can be the feature data of the business object owned by the second party, and the second party performs homomorphic operations based on the secret model parameters and feature data, and the first result ciphertext obtained can correspond to the prediction result or intermediate result of the business prediction model. When the first party is the model user and the second party is the model owner, the first plaintext data can be the feature data of the business object owned by the first party, and the second plaintext data is the model parameter. When the first party is the data holder and the second party is the computing platform, the first plaintext data and the second plaintext data are both the private data of the first party, such as user personal information of different projects; the first party encrypts it and sends it to the second party; the second party performs homomorphic operations on the secret private data based on its confidential algorithm or model to obtain the first result ciphertext, which corresponds to the processing result for the private data. In addition to the above examples, Figure 3 Multi-party secure computing can also be applied to other business scenarios, which are not listed here one by one.
[0098] It should be emphasized that no matter what the specific scenario is, in the above process, it can be seen that in the entire ciphertext operation stage, the data has always been kept in the Montgomery state, that is, in the form of xR, so that the homomorphic operation of the ciphertext can continue in the Montgomery state, which is convenient for using Montgomery reduction to accelerate the calculation. For example, two Montgomery state data aR and bR are modularly multiplied to obtain (ab)R. The data form before and after the modular multiplication does not change. abR can regard ab as x as a whole, so abR can continue to multiply with other xR to obtain abxR, until the final result is needed, R can be eliminated to obtain the real result abx. In this way, the use of Montgomery reduction to accelerate the calculation and improve the calculation performance is achieved throughout the ciphertext operation stage.
[0099] Experiments have shown that when the OU encryption algorithm is used, the performance of the homomorphic addition operation between ciphertexts can be improved by 3.75 times by performing operations in the Montgomery state according to the above scheme compared to conventional ciphertext modular multiplication. For the "ciphertext + plaintext" operation, the above scheme also has a 2-fold performance improvement compared to conventional technologies. Therefore, the above scheme significantly improves the computing performance of the ciphertext operation stage.
[0100] The above solution architecture and technical concept can also be applied to multi-party secure computing with more than two parties. Figure 4 A schematic diagram of a calculation process of a multi-party secure calculation according to an embodiment is shown. Figure 4In the example, multi-party secure computing involves a first party, a second party, and a third party, wherein the first party acts as an encryptor / decryptor, and the second and third parties act as ciphertext calculators. Each party can be specifically implemented as any server, device, platform, equipment, or equipment cluster with computing and processing capabilities, which is not limited here. In one embodiment, the first party may be the model owner, who has a pre-trained business prediction model that requires privacy protection, and the second and third parties are both model users, each of whom owns a portion of the feature data (privacy data) of the business object to be tested. In another embodiment, the first party is the data owner, and the second and third parties each own a distributedly deployed model portion. In other embodiments, the architecture can also be applied to other business scenarios.
[0101] During the multi-party secure computation, in step 41, the first party performs a mapping operation and homomorphic encryption on the first plaintext data to obtain a first transformed ciphertext c1R in a Montgomery state.
[0102] Next, in step 42, the first party sends the first transformed ciphertext c1R to the second party.
[0103] Afterwards, in step 43, the second party performs a first homomorphic operation in the Montgomery state based on the first conversion ciphertext c1R to obtain a first result ciphertext c'R in the Montgomery state.
[0104] The specific execution process of the above steps 41-43 is the same as Figure 3 Similar, no need to repeat.
[0105] Then, in step 44, the second party sends the first result ciphertext c'R to the third party.
[0106] In step 45, the third party performs a second homomorphic operation based on the first result ciphertext c'R in the Montgomery state to obtain a second result ciphertext. Specifically, the second homomorphic operation may include performing a homomorphic operation on the first result ciphertext and another converted ciphertext data, referred to as a third converted ciphertext. In one example, the third converted ciphertext is obtained by the third party performing a mapping conversion and encryption on the third plaintext data locally owned by the third party. In another example, the third converted ciphertext is provided by the first party to the third party. In yet another example, the third converted ciphertext is an intermediate result ciphertext that is homomorphically operated based on the converted ciphertext provided by the first party and the converted ciphertext locally of the third party. In addition, the operation mode of the second homomorphic operation may be the same as or different from the first homomorphic operation performed by the second party, which is not limited here.
[0107] Afterwards, in step 46, the third party sends the second result ciphertext to the first party.
[0108] Then, in step 47, the first party performs Montgomery reduction and decryption operations on the second result ciphertext to obtain a second result plaintext.
[0109] The above describes the process of multi-party secure computation using Montgomery reduction in combination with the scenario of two computing parties (the second party and the third party). It can be understood that the computation process can be extended to the case of more computing parties, for example, including a fourth party, and the third party sends its result ciphertext to the fourth party, so that it can continue to perform homomorphic operations based on the result ciphertext. That is, after obtaining the result ciphertext, each computing party sends it to the subsequent computing party, which continues the computation. Finally, a computing party sends the final result ciphertext to the first party, which decrypts it to obtain the result plaintext.
[0110] It should be noted that in the calculation process of the above multiple computing parties, during the entire ciphertext operation stage, no matter how many computing parties it passes through, the data still remains in the Montgomery state, so that the homomorphic operation of the ciphertext can continue in the Montgomery state, thereby using Montgomery reduction to accelerate the calculation and improve the computing performance.
[0111] The security of the ciphertext in the Montgomery state is proved below.
[0112] Figure 5 The correspondence between the plaintext space, ciphertext space and Montgomery space is shown. As shown in the figure, the plaintext space corresponds to the integer ring Z, the ciphertext space corresponds to another integer ring C, and the Montgomery space corresponds to the integer ring M. Homomorphism means that the plaintext to ciphertext is a one-to-many mapping, and isomorphism means that the ciphertext to the Montgomery state ciphertext is a one-to-one mapping. Since the C ring and the M ring are a one-to-one mapping relationship, the security of the M state ciphertext is consistent with the original ciphertext. Assuming that the ciphertext cR can be cracked, the attacker can also convert the original ciphertext c into plaintext p in O(1) time (because the conversion from c to cR can be completed in O(1) time), and then crack the homomorphic encryption algorithm. It is known that the original homomorphic encryption algorithm is secure, so the assumption does not hold, that is, the ciphertext cR in the Montgomery state is also secure.
[0113] In summary, the solution architecture proposed in the embodiments of this specification can use Montgomery reduction to improve computing performance during the ciphertext calculation stage of multi-party secure computing, while ensuring the security of the computing process.
[0114] On the other hand, corresponding to the above-mentioned multi-party secure computing process, an embodiment of this specification also discloses a multi-party secure computing device, which is deployed in a first party. The first party can be implemented as any computing unit, platform, server, device, etc. with computing and processing capabilities. Figure 6 A schematic diagram showing the structure of a multi-party secure computing device deployed in a first party according to an embodiment is shown. Figure 6 As shown, the device 600 includes:
[0115] The encryption conversion unit 61 is configured to perform a first mapping operation and homomorphic encryption on the first plaintext data to obtain a first converted ciphertext in a Montgomery state; the first mapping operation is used to convert the data from an integer ring to a Montgomery state;
[0116] A sending unit 62, configured to send the first converted ciphertext to a second party;
[0117] A receiving unit 63 is configured to receive a result ciphertext from a third party, where the result ciphertext is obtained by performing a homomorphic operation based on the first transformed ciphertext in a Montgomery state, where the homomorphic operation includes a modular multiplication operation;
[0118] The decryption conversion unit 64 is configured to perform Montgomery reduction and decryption operations on the result ciphertext to obtain a result plaintext.
[0119] According to one embodiment, the second party and the third party are the same party. In another embodiment, the second party and the third party are different computing parties.
[0120] In one embodiment, the encryption conversion unit 61 is specifically configured to: perform homomorphic encryption on the first plaintext data to obtain a first original ciphertext; and use the first mapping operation to convert the first ciphertext into a Montgomery state to obtain the first converted ciphertext.
[0121] In another embodiment, the encryption conversion unit 61 is specifically configured as follows: using the first mapping operation to convert the first plaintext data into a Montgomery state to obtain a first converted plaintext; and performing an encryption operation on the first converted plaintext in the Montgomery state to obtain the first converted ciphertext.
[0122] According to another aspect, an embodiment of the present specification also discloses a multi-party secure computing apparatus, which is deployed in a second party, and the second party can be implemented as any computing unit, platform, server, device, etc. with computing and processing capabilities. Figure 7 A schematic diagram showing the structure of a multi-party secure computing device deployed in a second party according to an embodiment is shown. Figure 7 As shown, the device 700 includes:
[0123] A receiving unit 71 is configured to receive a first converted ciphertext in a Montgomery state from a first party, where the first converted ciphertext is obtained by the first party performing a first mapping operation and homomorphic encryption on first plaintext data; the first mapping operation is used to convert data from an integer ring to a Montgomery state;
[0124] An operation unit 72 is configured to perform a first homomorphic operation based on the first conversion ciphertext in a Montgomery state to obtain a first result ciphertext in a Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation;
[0125] The sending unit 73 is configured to send the first result ciphertext.
[0126] In one embodiment, the sending unit 73 is specifically configured to: send the first result ciphertext to the first party, so that the first party performs Montgomery reduction and decryption operations on the first result ciphertext to obtain a first result plaintext.
[0127] In another embodiment, the sending unit 73 is specifically configured to: send the first result ciphertext to a third party, so that the third party performs a second homomorphic operation based on the first result ciphertext in a Montgomery state to obtain a second result ciphertext.
[0128] According to one embodiment, the above-mentioned device also includes an acquisition unit (not shown), configured to obtain a second conversion ciphertext in a Montgomery state; accordingly, the operation unit 72 is configured to perform the first homomorphic operation on the first conversion ciphertext and the second conversion ciphertext to obtain the first result ciphertext.
[0129] Furthermore, in one embodiment, the acquisition unit is configured to: receive the second converted ciphertext from the first party.
[0130] In another embodiment, the acquisition unit is configured to: perform the first mapping operation and homomorphic encryption on the local second plaintext data to obtain the second converted ciphertext.
[0131] According to one implementation, the first plaintext data is parameter data of a business prediction model, and the second plaintext data is feature data of a business object.
[0132] According to another aspect, the present specification also discloses a system for multi-party secure computing, including a first party and a second party, wherein:
[0133] The first party is used to perform a first mapping operation and homomorphic encryption on the first plaintext data to obtain a first converted ciphertext in a Montgomery state; the first mapping operation is used to convert the data from an integer ring to a Montgomery state;
[0134] The first party is further configured to send the first converted ciphertext to the second party;
[0135] The second party is used to perform a first homomorphic operation based on the first conversion ciphertext in the Montgomery state to obtain a first result ciphertext in the Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation.
[0136] Through the above devices and systems, during the homomorphic ciphertext calculation stage of multi-party secure computing, the computing party can use Montgomery reduction to accelerate the calculation and improve the computing performance.
[0137] According to another aspect of the embodiment, a computer-readable storage medium is also provided, on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the method executed by each party in the aforementioned multi-party secure computing process.
[0138] According to yet another embodiment, a computing device is provided, including a memory and a processor, wherein an executable code is stored in the memory, and when the processor executes the executable code, the method executed by each party in the aforementioned multi-party secure computing process is implemented.
[0139] Those skilled in the art should be aware that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, firmware or any combination thereof. When implemented by software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.
[0140] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made on the basis of the technical solution of the present invention should be included in the scope of protection of the present invention.
Claims
1. A multi-party secure computing method, comprising: The first party sends a first transformed ciphertext to the second party, where the first transformed ciphertext is data in a Montgomery state and homomorphically encrypted; The second party performs a first homomorphic operation based on the first conversion ciphertext in the Montgomery state to obtain a first result ciphertext in the Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation.
2. The method according to claim 1, further comprising: The second party sends the first result ciphertext to the first party; The first party performs Montgomery reduction and decryption operations on the first result ciphertext to obtain a first result plaintext.
3. The method according to claim 1, further comprising: The second party sends the first result ciphertext to a third party; The third party performs a second homomorphic operation based on the first result ciphertext in the Montgomery state to obtain a second result ciphertext.
4. The method according to claim 1, further comprising: The second party obtains a second transformed ciphertext in a Montgomery state, where the second transformed ciphertext is homomorphically encrypted data; The obtaining of the first result ciphertext in the Montgomery state specifically includes: The first homomorphic operation is performed on the first converted ciphertext and the second converted ciphertext to obtain the first result ciphertext.
5. The method according to claim 4, wherein: The second party obtains the second converted ciphertext in the Montgomery state, specifically including: The second party receives the second transformed ciphertext from the first party.
6. The method according to claim 4, wherein: The second party obtains the second converted ciphertext in the Montgomery state, specifically including: The first mapping operation and homomorphic encryption are performed on the second plaintext data locally of the second party to obtain the second converted ciphertext.
7. The method according to claim 6, wherein: The first plaintext data is parameter data of a business prediction model, and the second plaintext data is feature data of a business object.
8. A method for multi-party secure computation, performed by a first party, comprising: Sending a first transformed ciphertext to a second party, wherein the first transformed ciphertext is data in a Montgomery state and homomorphically encrypted; receiving a result ciphertext from a third party, wherein the result ciphertext is obtained by performing a homomorphic operation based on the first transformed ciphertext in a Montgomery state, wherein the homomorphic operation includes a modular multiplication operation; Performing Montgomery reduction and decryption operations on the result ciphertext to obtain a result plaintext.
9. The method according to claim 8, wherein: The second party and the third party are the same party.
10. A method for multi-party secure computation, performed by a second party, comprising: receiving a first transformed ciphertext in a Montgomery state from a first party, wherein the first transformed ciphertext is homomorphically encrypted data; In the Montgomery state, performing a first homomorphic operation based on the first conversion ciphertext to obtain a first result ciphertext in the Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation; The first result ciphertext is sent.
11. The method according to claim 10, wherein: Sending the first result ciphertext includes: The first result ciphertext is sent to the first party, so that the first party performs Montgomery reduction and decryption operations on the first result ciphertext to obtain a first result plaintext.
12. The method according to claim 10, wherein: Sending the first result ciphertext includes: The first result ciphertext is sent to a third party, so that the third party performs a second homomorphic operation based on the first result ciphertext in a Montgomery state to obtain a second result ciphertext.
13. The method according to claim 10, further comprising: Obtaining a second transformed ciphertext in a Montgomery state, where the second transformed ciphertext is homomorphically encrypted data; The obtaining of the first result ciphertext in the Montgomery state specifically includes: The first homomorphic operation is performed on the first converted ciphertext and the second converted ciphertext to obtain the first result ciphertext.
14. The method according to claim 13, wherein: Obtain the second conversion ciphertext in the Montgomery state, including: The second transformed ciphertext is received from the first party.
15. The method according to claim 13, wherein: Obtain the second conversion ciphertext in the Montgomery state, including: Perform a first mapping operation and homomorphic encryption on the local second plaintext data to obtain the second converted ciphertext.
16. The method according to claim 15, wherein: The first plaintext data is parameter data of a business prediction model, and the second plaintext data is feature data of a business object.
17. A multi-party secure computing system, comprising a first party and a second party, wherein: The first party is used to send a first transformed ciphertext to the second party, where the first transformed ciphertext is data in a Montgomery state and homomorphically encrypted; The second party is used to perform a first homomorphic operation based on the first conversion ciphertext in the Montgomery state to obtain a first result ciphertext in the Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation.
18. A multi-party secure computing device, deployed in a first party, comprising: A sending unit, configured to send a first transformed ciphertext to a second party, wherein the first transformed ciphertext is data in a Montgomery state and homomorphically encrypted; a receiving unit configured to receive a result ciphertext from a third party, wherein the result ciphertext is obtained by performing a homomorphic operation based on the first transformed ciphertext in a Montgomery state, wherein the homomorphic operation includes a modular multiplication operation; The decryption conversion unit is configured to perform Montgomery reduction and decryption operations on the result ciphertext to obtain a result plaintext.
19. A multi-party secure computing device, deployed in a second party, comprising: A receiving unit configured to receive a first transformed ciphertext in a Montgomery state from a first party, wherein the first transformed ciphertext is homomorphically encrypted data; an operation unit configured to perform a first homomorphic operation based on the first conversion ciphertext in a Montgomery state to obtain a first result ciphertext in a Montgomery state, wherein the first homomorphic operation includes a modular multiplication operation; A sending unit is configured to send the first result ciphertext.
20. A computing device comprising a memory and a processor, characterized in that: The memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 1 to 16 is implemented.
Citation Information
Patent Citations
Processing architecture, accelerator and method for federated learning
CN112070222A
Data processing method, device and apparatus for homomorphic encryption
CN112199707A
Method, device and system for determining number of common data for protecting private data
CN114239019A
Systems and methods for implementing an efficient, scalable homomorphic transformation of encrypted data with minimal data expansion and improved processing efficiency
US20190036678A1
Cited By
High-performance data multi-domain transformation lattice-based homomorphic encryption and decryption method and system
CN121509119A