Lightweight distributed data encryption sharing and comparison function construction method

By adopting lightweight distributed data encryption sharing and comparison function construction methods with 0/1 encoding and early interrupt technology in the secure comparison protocol, the problems of high communication overhead and computing complexity in the existing technology are solved, and a more efficient key generation and execution process is achieved.

CN120017256AActive Publication Date: 2025-05-16SHENZHEN YUANWANGGU INTELLIGENT TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510102752.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-16
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

The existing security comparison protocol is based on obfuscated circuits or arithmetic secret sharing, resulting in high communication overhead and computational complexity, which is difficult to apply in actual network environments.

Method used

The lightweight distributed data encryption sharing and comparison function construction method is adopted, and the key generation algorithm is optimized using 0/1 encoding and early interrupt technology, and the comparison process is divided into two parts to reduce the key length and calculation complexity.

Benefits of technology

It significantly reduces the key length and space overhead, optimizes the key generation and execution process, reduces the computational complexity of online execution, and improves computing efficiency and resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017256A_ABST
    Figure CN120017256A_ABST
Patent Text Reader

Abstract

The invention discloses a lightweight distributed data encryption sharing and comparison function construction method, which comprises the following steps: in a key generation stage, giving a security parameter 1 lambda and a comparison function f (x) = {xlt; the preprocessing trusted third-party server generates a pair of keys # imgabs0 # corresponding to the comparison function by using a DCF key generation algorithm, and the keys are respectively fed back to the two independent servers; in a secret key execution section, giving a secret key and an input value x, based on 0 / 1 coding and an early interruption technology, outputting secret output parts beta 0 and beta 1 of one addition of a comparison function by the server, when and only when xlt; when alpha is greater than alpha, the # imgabs1 # is not greater than 0, and f (x) is equal to 0. According to the method, the memory occupation is greatly reduced, the calculation complexity of online execution is reduced, the calculation efficiency is improved, the calculation cost is reduced, and safe comparison operation can be efficiently and flexibly realized in a distributed system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of network security and relates to a lightweight distributed data encryption sharing and comparison function construction method. Background Art

[0002] Secure comparison protocols are core components in the field of secure multi-party computation and are widely used in privacy-preserving machine learning tasks. Their goal is to achieve privacy-preserving data size comparison without leaking the private data of the participants. Research in this field first introduced the method of using obfuscated circuits for integer comparison, laying the foundation for secure multi-party computation. Obfuscated circuits achieve privacy protection by encoding computational tasks as Boolean circuits and having the participants perform the computations layer by layer. However, protocols based on obfuscated circuits have significant communication overhead because each circuit gate requires the exchange of a one-time key between the two parties, which is particularly evident in large-scale computations.

[0003] In order to overcome the limitations of obfuscated circuits, researchers proposed arithmetic secret sharing technology. Arithmetic secret sharing divides data into multiple shares and distributes them to different participants, so that a single participant cannot obtain complete information, thereby achieving calculation while ensuring privacy. In the study of secure comparison protocols, the introduction of Function Secret Sharing (FSS) marks a major breakthrough. FSS shares the function secret with multiple participants, so that each participant only holds part of the function's information, thereby achieving efficient calculation while ensuring privacy. FSS has become the basis of the Distributed Point Function (DPF) and Distributed Comparison Function (DCF) schemes, providing a new direction for subsequent research. Based on FSS, researchers have proposed a variety of improvement schemes. For example, the distributed interval inclusion function further optimizes the computational efficiency by converting the comparison problem into an interval judgment problem. The DCF based on the half tree and the DCF based on the GGM tree reduce the computational and communication overhead by introducing a tree structure. However, these schemes still face some challenges in practical applications, such as they require longer random number generation (RNG) keys and require additional operations to solve the wraparound problem during online execution. In order to further improve performance, Grotto et al. proposed a DCF scheme based on parity segment tree to reduce the use of RNG, but this scheme needs to traverse each layer of parity segment tree during the DCF execution stage, which introduces additional computational costs.

[0004] Most of the existing secure comparison schemes are designed based on obfuscated circuits or arithmetic secret sharing, which leads to high communication overhead and communication rounds, making them difficult to apply in actual network environments. Distributed Comparison Function (DCF) is a FSS primitive that can be applied to the field of secure multi-party computing to implement secure calculation of comparison functions in single-round communication. However, when implementing secure comparison operations, existing DCFs usually need to generate a large number of pseudo-random numbers, resulting in high computational complexity and low operating efficiency. Secondly, existing DCF schemes require a large amount of memory space during key generation and execution, which limits their application in resource-constrained environments. Summary of the invention

[0005] The purpose of the present invention is to provide a lightweight distributed data encryption sharing and comparison function construction method, the technical solution adopted is:

[0006] A lightweight distributed data encryption sharing and comparison function construction method comprises the following steps:

[0007] S1: During the key generation phase:

[0008] Given security parameter 1 λ and comparison function f(x)={x<α}, the pre-processing trusted third-party server generates two pairs of keys corresponding to the comparison function using the DCF key generation algorithm Key Feedback is sent to two independent servers P0 and P1 respectively;

[0009] S2: In the key execution segment:

[0010] Given the key and input value x, based on 0 / 1 encoding and early interruption technology, the server P0 and the server P1 output an added secret output of the comparison function f(x) β0=f0(x) and β1=f1(x), if and only if x<α, Otherwise f(x)=0.

[0011] In one embodiment of the present invention, step S1 comprises:

[0012] Assume that the input value x is a binary string of length l, represented as x0x1…x l-1 , x l-1 is the least significant bit, x0 is the most significant bit, and the 0-encoding and 1-encoding rules of the binary string x are defined as:

[0013] In one embodiment of the present invention, step S1 comprises:

[0014] The input values ​​x and α are divided into two parts α0, ..., α v ||α v+1 , ..., α l-1 and x0, ..., x v ||x v+1 , ..., x l-1 , where v∈[0,l-1], are compared respectively;

[0015] When x0…x v ≠α0…α v When , only the first (v+1) bits of the string need to be compared;

[0016] When x0…x v =α0…α v , continue to compare the remaining (lv-1) bits of string length.

[0017] In one embodiment of the present invention, step S1 comprises:

[0018] For the first v bits of length α0, ..., α v Construct a virtual tree, where the left and right child nodes of each node represent 0 and 1 respectively, and compare the node value with each bit of the number layer by layer from the top to the bottom of the tree. The path that matches α is called a special path;

[0019] Each node stores a label to indicate whether it is on a special path. If so, the label is 1, otherwise it is 0;

[0020] For the remaining bit length α v+1 , ..., α l-1 , construct a query table for it If the encoding method is to use a lookup table, Then the kth element ω of the encoding table ω is (k) is 1 if the value is true, otherwise it is 0.

[0021] In one embodiment of the present invention, in step S1, the DCF key generation algorithm includes the following steps:

[0022] S11: Initialization:

[0023] Enter security parameters 1 λ and special paths α = α0, α1, ..., α l-1 , set the optimal layer number of early interruption to v = l-1-log2λ, where l is the bit length of α, and initialize the seed of the server PP0 and the seed of the server P1 and the label of the server P0 and the tag of the server P1

[0024] S12: Generate correction words:

[0025] For the first v+1 bits of α, the string α0,...,α v , generate the correction words CW of the first v+1 layers layer by layer (0) ||…||||CW (v) ;

[0026] For the remaining string α v+1 ,…,α l-1 , encoded using the lookup table method, which is if Then set the kth element ω (k) =1, otherwise ω (k) =0, then use random seed and Construct the correction word at position v+1

[0027] S13: Generate key:

[0028] Output the key of the server P0 The key The initial random seed and v+1 correction words CW;

[0029] Output the key of the server P1 The key The initial random seed And v+1 correction words CW.

[0030] In one embodiment of the present invention, step S12 includes:

[0031] For each layer (i∈[0,v]), use a pseudo-random generator (G:{0,1} λ →{0,1} 2(λ+1) ) Generate a seed extension string;

[0032] Divide the extended string into its left half (s L ||t L ) and the right half (s R ||t R ), where s L and R is a random seed of length λ bits, t L and t Ris 1 label;

[0033] According to α i The value of selects the keep part (Keep) and the discard part (Lose): If α i = 0, then keep the left part (Keep = L) and lose the right part (Lose = R); if α i =1, then keep the right part (Keep=R) and lose the right part (Lose=L);

[0034] Calculate Correction Words in

[0035] Calculate the next layer of seeds and tags

[0036] The loop stops at the vth layer, and the correction word CW of the previous v+1th layer is obtained. (0) ||…||||CW (v) .

[0037] In one embodiment of the present invention, step S2 comprises:

[0038] For the first v bits of length x0…x v , according to the 0 / 1 coding rule test comparison, when x0…x v <α0…α v According to the 0 / 1 encoding rule, we can get and and

[0039] If x0…x v <α0…α v , then x0…x v There is only one x i =0 satisfies x0…x i-1 1=α0…α i , get the current x0…x v <α0…α v The comparison result β;

[0040] For x v+1 ,…,x l-1 <α v+1 ,…,α l-1 Compare the results, perform a security query based on the query table, and select the first Value Update β to The final comparison result β of x<α is obtained.

[0041] In one embodiment of the present invention, in step S2, the key execution includes the following steps:

[0042] S21: Initialization:

[0043] Server P b Enter the key and the public x=x0,α1,…,α l-1 , from the key Parsing initial seed and the correction word CW of each layer (i) , set the optimal layer number of early interruption v = l-1-log2λ;

[0044] S22: Layered execution:

[0045] For the first v+1 bits of x, the string x0,…,x v , analyze layer by layer Get x0,…,x of the first v+1 layers v <α0,…,α v Safety comparison results of β b , where (b∈{0,1});

[0046] For the remaining strings of x According to the random seed of layer v+1 Status Tags and correction words Parsing Output Then select the query table ω b No. Update β b , that is: in

[0047] S23: Return result:

[0048] The server P0 outputs the result β0, the server P1 outputs the result β1, and the final result of the lightweight distributed data encryption sharing and comparison function is If β=1, then x<α, otherwise, x≥α.

[0049] In one embodiment of the present invention, step S22 includes:

[0050] For the first v+1 bits of x, the string x0,…,x v , for each layer (i∈[0,v]), use a pseudo-random generator (G:{0,1} λ →{0,1} 2(λ+1) ) and seeds Generate an extended string (τ b), and parse the extended string into s′ L ||t′ L ||s′ R ||t′ R , where s′ L The current left random temporary seed uses the seed of the pseudo-random generator at each layer, s′ R The current right random temporary seed uses the seed of the pseudo-random generator at each layer, t′ L Indicates the state of selecting the left half, t′ R Indicates the state of selecting the right half;

[0051] According to x i Update the seed and label with the value of i = 0, then update And update the right sibling node status If x i =1, then update Until the loop stops at the v layer, obtain x0,...,x of the previous v+1 layers v <α0, ..., α v Safety comparison results of β b .

[0052] In one embodiment of the present invention, the lightweight distributed data encryption sharing and comparison function is deployed in a preprocessing model based on two-party secure computing, and the preprocessing model includes two independent servers P0 and P1 that are not collusive and a preprocessing trusted third-party server P T , the pre-processing trusted third-party server P T Keys are pre-generated and cached for the server P0 and the server P1.

[0053] Beneficial effects of the present invention:

[0054] The lightweight distributed data encryption sharing and comparison function construction method of the present invention is based on the optimized key generation algorithm of 0 / 1 coding and early interruption technology, introduces early interruption technology, divides the comparison process into two parts, and constructs the first v+1 correction words CW of the key based on the 0 / 1 coding technology in the first half (0) ||...|||CW (v) In the second half, the obfuscated lookup table is constructed to form the last correction word of the key, and then the initialization seed is combined to combine the correction words of the two layers to form the key. Finally, the keys of the two servers are output, which significantly reduces the key length, reduces the space overhead, optimizes the key generation and execution process, and reduces the computational complexity of online execution. During the execution process, combined with the early interruption technology, the security comparison results x0,...,x0 of the first v+1 layer are obtained based on the 0 / 1 encoding principle in the first half.v <α0, ..., α v , then compare the remaining parts based on the obfuscated lookup table, and finally use the comparison results of the remaining layers to update the comparison results of the previous v+1 layers, and obtain and output the final secure comparison results. In the multi-layer structure, the computational cost is significantly reduced. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 It is a process schematic diagram of a lightweight distributed data encryption sharing and comparison function construction method provided by an embodiment of the present invention;

[0056] Figure 2 It is a schematic diagram of a virtual tree construction of a lightweight distributed data encryption sharing and comparison function provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0057] The present invention is described in detail below with reference to the accompanying drawings and specific embodiments.

[0058] The present invention provides a lightweight distributed data encryption sharing and comparison function construction method, which combines 0 / 1 encoding and early interruption technology to significantly reduce key length, reduce space overhead, optimize key generation and execution process, and reduce the computational complexity of online execution, especially in a multi-layer structure, significantly reducing the computational cost.

[0059] Unless otherwise specified, the lightweight distributed data encryption sharing and comparison function proposed in the present invention is deployed in a preprocessing model based on two-party secure computing. The preprocessing model includes two independent servers P0 and P1 that are not collusive and a preprocessing trusted third-party server P T , where the preprocessing trusted third-party server P T Ability to pre-generate and cache keys for server P0 and server P1.

[0060] The protocol of the present invention follows the standard simulation paradigm for semi-honest probabilistic polynomial time (PPT) security threat adversaries. In this paradigm, the threat adversary can only destroy one of P0 and P1, and it will execute according to the protocol provisions and try to obtain the private information of P0 or P1 by analyzing the protocol.

[0061] In the lightweight distributed data encryption sharing and comparison function construction method of the present invention, the DCF protocol based on 0 / 1 encoding is an example of Function Secret Sharing (FSS). Given a comparison function cluster and a common input x∈G in , the DCF protocol converts a function It is divided into two arithmetic shares f0(x) and f1(x). Each share hides the specific content of the function f(x), ensuring that for input x, f0(x)+f1(x)=f(x). This means that the function value f(x) can be reconstructed by the sum of its two arithmetic shares. DCF includes a pair of algorithms: key generation algorithm Gen(1 λ , α) and execute the algorithm

[0062] See attached Figure 1 The lightweight distributed data encryption sharing and comparison function construction method of the present invention comprises the following steps:

[0063] S1: During the key generation phase:

[0064] Given security parameter 1 λ and comparison function f(x) = {x < α}, the pre-processing trusted third-party server uses the DCF key generation algorithm to generate two pairs of keys corresponding to the comparison function Key Feedback is sent to two independent servers P0 and P1 respectively;

[0065] S2: In the key execution segment:

[0066] Given a key and input value x, based on 0 / 1 encoding and early interruption technology, server P0 and server P1 output a secret output of the comparison function f(x) β0=f0(x) and β1=f1(x) if and only if x<α, Otherwise f(x)=0.

[0067] The present invention uses a 0 / 1 encoding method to convert the comparison problem into an equality problem. Assume that the input value x is a binary string of length l, represented by x0x1...x l-1 , x l-1 is the least significant bit, x0 is the most significant bit, and the 0-encoding and 1-encoding rules of the binary string x are defined as: The present invention uses 0 / 1 encoding technology to convert the security comparison problem into a string equal value matching problem, thereby reducing the size and construction complexity of the key.

[0068] Assuming that there is a guess z>y, to verify whether this guess is correct, the present invention encodes the larger value z and the smaller value y by 1-encoding and 0-encoding respectively, that is, and Then check Is it true? If it is true, then z>y is true; otherwise, Then z≤y. On the contrary, assuming there is a guess y>z, encode y and z respectively as and Then check Is it true? For example: Assume z = 10 = 10102, y = 3 = 00112, l = 4. According to the 0 / 1 encoding method rules, we can get and because So z>y.

[0069] In order to optimize the existing solution, the present invention also adopts early termination technology. The input value x and α are divided into two parts α0, ..., α v ||α v+1 , ..., α l-1 and x0, ..., x v ||x v+1 , ..., x l-1 , where v∈[0,l-1], are compared respectively; when x0…x v ≠α0…α v When x0…x v =α0…α v , continue to compare the remaining (lv-1) bits of string length.

[0070] In the key generation phase, for the first v bits of length α0,...,α v Build a virtual tree, refer to the attached Figure 2 , the left and right child nodes of each node represent 0 and 1 respectively, and the node value is compared with each bit of the number layer by layer from the top to the bottom of the tree, where the path that matches α is called a special path. Each node saves a label to indicate whether it is on a special path, if so, the label is 1, otherwise it is 0; for the remaining bit length α v+1 , ..., α l-1 , encoded using the lookup table method, which is if Then the kth element ω of the encoding table ω is (k) is 1 if the value is true, otherwise it is 0.

[0071] Referring to Table 1, the DCF key generation algorithm includes the following steps:

[0072] S11: Initialization:

[0073] Enter security parameters 1 λ and special paths α=α0,α1,…,α l-1 , set the optimal layer number of early interruption to v = l-1-log2λ, where l is the bit length of α, and initialize the seed of the server P0 and the seed of the server P1 and the label of the server P0 and the tag of the server P1

[0074] S12: Generate correction words:

[0075] For the first v+1 bits of α, the string α0,…,α v , generate the correction words CW of the first v+1 layers layer by layer (0) ||…||||CW (v) For each layer (i∈[0,v]), use a pseudo-random generator (G:{0,1} λ →{0,1} 2(λ+1) ) Generate a seed extension string. Divide the extension string into the left half (s L ||t L ) and the right half ((s R ||t R ), where s L and R is a random seed of length λ bits, t L and t R is 1 label. According to α i The value of selects the keep part (Keep) and the discard part (Lose): If α i = 0, then keep the left part (Keep = L) and lose the right part (Lose = R); if α i =1, then keep the right part (Keep=R), lose the right part (Lose=L). Calculate the correction word in Next, calculate the next layer of seeds and tags The loop stops at the vth layer, and the correction word CW of the previous v+1th layer is obtained. (0) ||…||||CW (v) .

[0076] For the remaining string α v+1 ,…,α l-1 , construct a query table for it if Then set the kth element ω (k) =1 otherwise ω (k) =0, then use random seed and Construct the correction word at position v+1 This is an obfuscated query table, which is used by the server to execute Prevent the leakage of query results when performing queries.

[0077] S13: Generate key:

[0078] Output the key of server P0 Key The initial random seed and v+1 correction words CW; output server P1's key Key The initial random seed And v+1 correction words CW.

[0079] Table 1

[0080]

[0081] The lightweight distributed data encryption sharing and comparison function construction method of the present invention is based on the optimized key generation algorithm of 0 / 1 coding and early interruption technology, introduces early interruption technology, divides the comparison process into two parts, and constructs the first v+1 correction words CW of the key based on the 0 / 1 coding technology in the first half (0) ||…||||CW (v) In the second half, the obfuscated lookup table is constructed to generate the last correction layer of the key, and then the initialization seed is combined to combine the correction words of the two layers to form the key. Finally, the keys of the two servers are output. This significantly reduces the key length, reduces the space overhead, optimizes the key generation and execution process, and reduces the computational complexity of online execution.

[0082] In the key execution section, for the first v bits of length x0…x v , according to the 0 / 1 coding rule test comparison, when x0…x v <α0…α v According to the 0 / 1 encoding rule, we can get and and If x0…x v <α0…α v , then x0…x v There is only one x i =0 satisfies x0...x i-1 1=α0...α i This means that in the tree structure, there is a path matching x (the blue path in the figure) such that x0...x i-1 1=α0...α i This means that the first i-1 bits of x are on a special path, and x i= 0 is on a special path. Therefore, in the key execution of the function, we only need to check which bits of x are 0, get the labels of its right siblings, and check whether their sum is 1. Figure 2 As shown, assume x = 5 = 01012 and α = 10 = 10102. It is known that x0 = x2 = 0, but only x0's right sibling node Node2 is on the special path. Due to the structure of the tree, for any x there is at most one x. i = 0, its right sibling node is located on a special path. Therefore, we can get the current x0…x v <α0…α v The comparison result β. For x v+1 , ..., x l-1 <α v+1 , ..., α l-1 Compare the two, perform a security query based on the encoded query table, and select the first Value Update β to The final comparison result β of x<α is obtained.

[0083] Referring to Table 2, key execution includes the following steps:

[0084] S21: Initialization:

[0085] The key entered by server P0 and server P1 and the public x=x0,x1,...,x l-1 , from the key Parsing initial seed and the correction word CW of each layer (i) , set the optimal layer number of early interruption v = l-1-log2λ.

[0086] S22: Layered execution:

[0087] For the first v+1 bits of x, the string x0,...,x v , analyze layer by layer Get x0,...,x of the first v+1 layers v <α0, ..., α v Safety comparison results of β b , where (b∈{0,1});

[0088] For each layer (i∈[0,v]), a pseudo-random generator (G: {0,1} λ →{0,1} 2(λ+1) ) and seeds Generate an extended string (τ b ), and analyze τ b s′L ||t′ L ||s′ R ||t′ R , where s′ L The current left random temporary seed uses the seed of the pseudo-random generator at each layer, s′ R The current right random temporary seed uses the seed of the pseudo-random generator at each layer, t′ L Indicates the state of selecting the left half, t′ R Indicates the state of selecting the right half. i Update the seed and label with the value of i = 0, then update And update the right sibling node status If x i =1, then update Until the loop stops at the v layer, obtain x0,…,x of the previous v+1 layer v <α0,…,α v Safety comparison results of β b .

[0089] For the remaining strings of x According to the random seed of layer v+1 Status Tags and correction words Parsing Output Then select the query table ω b No. Update β b , that is: in

[0090] S23: Return result:

[0091] Server P0 outputs the result β0, and server P1 outputs the result β1. The final result of the lightweight distributed data encryption sharing and comparison function is If β=1, then x<α, otherwise, x≥α.

[0092] Table 2

[0093]

[0094] The lightweight distributed data encryption sharing and comparison function construction method of the present invention combines the early interruption technology during the execution process to obtain the security comparison results x0,…,x0 of the first v+1 layer based on the 0 / 1 coding principle in the first half. v <α0,…,α v, then compare the remaining parts based on the obfuscated lookup table, and finally use the comparison results of the remaining layers to update the comparison results of the previous v+1 layers, and obtain and output the final comparison results. In a multi-layer structure, the computational cost is significantly reduced.

[0095] While ensuring data privacy and security, the present invention significantly reduces the occupation of system resources and realizes more efficient distributed comparison function calculation. Compared with the prior art, this solution greatly reduces the memory usage, and because the number of pseudo-random numbers generated during the algorithm is reduced by nearly half compared with the traditional DCF solution, the calculation efficiency is significantly improved.

[0096] In order to verify the technical advantages of the present invention, the key technologies were experimentally evaluated. The experiment used an input vector element width of 64 bits, the test environment was a CPU i7-11800H and a GPU NVIDIA GeForce RTX 3060Laptop, and the test code was written in Python. The specific experimental data is shown in Table 3:

[0097] Table 3

[0098]

[0099] The lightweight distributed data encryption sharing and comparison function construction method of the present invention significantly reduces the number of pseudo-random numbers generated by optimizing the algorithm, thereby improving the computing efficiency. Secondly, the existing DCF scheme requires a large amount of memory space during key generation and execution, which limits its application in resource-constrained environments. The present invention significantly reduces memory usage by introducing the 0 / 1 encoding principle and early interrupt technology, so that the algorithm can run efficiently in a resource-constrained environment, and can efficiently and flexibly implement secure comparison operations in a distributed system. Moreover, the present invention can improve the efficiency of secure comparison operations while ensuring security, and is suitable for privacy-preserving decision tree training, reasoning, secure multi-party computing, and other privacy computing tasks involving comparison operations.

[0100] The above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any modifications, equivalent substitutions and improvements made by any technician familiar with the technical field within the technical scope disclosed by the present invention and within the spirit and principles of the present invention should be covered within the protection scope of the present invention.

Claims

1. A lightweight distributed data encryption sharing and comparison function construction method, characterized in that: The steps include: S1: During the key generation phase: Given security parameter 1 λ and comparison function f(x)={x<α}, the pre-processing trusted third-party server generates two pairs of keys corresponding to the comparison function using the DCF key generation algorithm Key Feedback is sent to two independent servers P0 and P1 respectively; S2: In the key execution segment: Given the key and input value x, based on 0 / 1 encoding and early interruption technology, the server P0 and the server P1 respectively output an additive secret output of the comparison function f(x) β0=f0(x) and β1=f1(x), if and only if x<α, otherwise 2. The lightweight distributed data encryption sharing and comparison function construction method according to claim 1, characterized in that: The step S1 comprises: Assume that the input value x is a binary string of length l, represented as x0x1…x l-1 , x l-1 is the least significant bit, x0 is the most significant bit, and the 0-encoding and 1-encoding rules of the binary string x are defined as:

3. The lightweight distributed data encryption sharing and comparison function construction method according to claim 2, characterized in that: The step S1 comprises: The input values ​​x and α are divided into two parts α0,…,α v ||α v+1 ,…,α l-1 and x0,…,x v ||x v+1 ,…,x l-1 , where v∈[0,l-1], are compared respectively; When x0…x v ≠α0…α v When , only the first (v+1) bits of the string need to be compared; When x0…x v =α0…α v , continue to compare the remaining (lv-1) bits of string length.

4. The lightweight distributed data encryption sharing and comparison function construction method according to claim 3, characterized in that: The step S1 comprises: For the first v bits of length α0,…,α v Construct a virtual tree, where the left and right child nodes of each node represent 0 and 1 respectively, and compare the node value with each bit of the number layer by layer from the top to the bottom of the tree. The path that matches α is called a special path; Each node stores a label to indicate whether it is on a special path. If so, the label is 1, otherwise it is 0. For the remaining bit lengths Construct a query table for it Using the lookup table method for encoding, if Then the kth element ω of the encoding table ω is (k) is 1 if the value is true, otherwise it is 0.

5. The lightweight distributed data encryption sharing and comparison function construction method according to claim 4, characterized in that: In step S1, the DCF key generation algorithm includes the following steps: S11: Initialization: Enter the security parameters 1 λ and the special path α=α0,α1,…,α l-1 , set the optimal layer number of early interruption to v = l-1-log2λ, where l is the bit length of α, and initialize the seed of the server P0 and the seed of the server P1 and the label of the server P0 and the tag of the server P1 S12: Generate correction words: For the first v+1 bits of α, the string α0,…,α v , generate the correction words CW of the first v+1 layer layer by layer (0) ||…||||CW (v) ; For the remaining string of α Encoding is done using the lookup table method, which is if Then set the kth element ω (k) =1, otherwise ω (k) =0, then use random seed and Construct the correction word at position v+1 S13: Generate key: Output the key of the server P0 Key The initial random seed and v+1 correction words CW; Output the key of the server P1 Key The initial random seed And v+1 correction words CW.

6. The lightweight distributed data encryption sharing and comparison function construction method according to claim 5, characterized in that: The step S12 comprises: For each layer (i∈[0,v]), use a pseudo-random generator (G:{0,1} λ →{0,1} 2(λ+1) ) Generate a seed extension string; Divide the extended string into its left half (s L ||t L ) and the right half (s R ||t R ), where s L and R is a random seed of length λ bits, t L and t R is 1 label; According to α i The value of selects the keep part (Keep) and the discard part (Lose): If α i = 0, then keep the left part (Keep = L) and lose the right part (Lose = R); if α i =1, then keep the right part (Keep=R) and lose the right part (Lose=L); Calculate Correction Words in Calculate the next layer of seeds and tags The loop stops at the vth layer, and the correction word CW of the previous v+1th layer is obtained. (0) ||…||||CW (v) .

7. The lightweight distributed data encryption sharing and comparison function construction method according to claim 6, characterized in that: The step S2 comprises: For the first v bits of length x0…x v , according to the 0 / 1 coding rule test comparison, when x0…x v <α0…α v According to the 0 / 1 encoding rule, we can get and and If x0…x v <α0…α v , then x0…x v There is only one x i =0 satisfies x0…x i-1 1=α0…α i , get the current x0…x v <α0…α v The comparison result β; For x v+1 ,…,x l-1 <α v+1 ,…,α l-1 , perform a security query based on the query table, and select the first Value Update β to The final comparison result β of x<α is obtained.

8. The lightweight distributed data encryption sharing and comparison function construction method according to claim 7, characterized in that: In step S2, key execution includes the following steps: S21: Initialization: The key input by the server P0 and server P1 and the public x=x0,x1,…,x l-1 , from the key Parsing initial seed and the correction word CW of each layer (i) , set the optimal layer number of early interruption v = l-1-log2λ; S22: Layered execution: For the first v+1 bits of x, the string x0,…,x v , analyze layer by layer Get x0,…,x of the first v+1 layers v <α0,…,α v Safety comparison results of β b , where (b∈{0,1}); For the remaining strings of x According to the random seed of layer v+1 Status Tags and correction words Parsing Output Then select the query table Update β b , that is: in S23: Return result: The server P0 outputs the result β0, the server P1 outputs the result β1, and the final result of the lightweight distributed data encryption sharing and comparison function is If β=1, then x<α, otherwise, x≥α.

9. The lightweight distributed data encryption sharing and comparison function construction method according to claim 8, characterized in that: Step S22 includes: For the first v+1 bits of x, the string x0,…,x v , for each layer (i∈[0,v]), use a pseudo-random generator (G:{0,1} λ →{0,1} 2(λ+1) ) and seeds Generate an extended string (τ b ), and parse the extended string into s ′L ||t ′L ||s ′R ||t ′R , where s ′L The pseudo-random generator seed of each layer is used as the temporary seed for the current left random, s ′R The current right random temporary seed uses the seed of the pseudo-random generator at each layer, t ′L Indicates the state of selecting the left half, t ′R Indicates the state of selecting the right half; According to x i Update the seed and label if x i = 0, then update And update the right sibling node status If x i =1, then update t ′R ; until the loop stops at the v layer, obtain x0,…,x of the previous v+1 layer v <α0,…,α v Safety comparison results of β b .

10. A lightweight distributed data encryption sharing and comparison function construction method according to any one of claims 1 to 9, characterized in that: The lightweight distributed data encryption sharing and comparison function is deployed in a preprocessing model based on two-party secure computing, which includes two independent servers P0 and P1 that are not collusive and a preprocessing trusted third-party server P T , the pre-processing trusted third-party server P T Keys are pre-generated and cached for the server P0 and the server P1.

Citation Information

Patent Citations

  • Efficient and safe linear rectification function operation method based on additive secret sharing technology

    CN113098840A

  • Distributed identity trust management method based on secure multi-party computing

    CN116094797A

  • Multi-party secret sharing data privacy comparison method based on efficient ciphertext confusion technology

    CN116743376A

  • Privacy protection neural network training method and device based on function secret sharing

    CN117592527A

  • Function secret sharing construction method for interval inclusion function

    CN118337381A

Cited By

  • Function secret sharing method of Boolean interval inclusion function

    CN121418095A