A method and device for processing floating point data in ciphertext calculation
By converting the ciphertext of floating-point data into an integer type for processing, and mapping it according to the positive and negative conditions of the processing results, the ciphertext of floating-point type is finally restored, which solves the problem that floating-point type data cannot be processed in the existing technology, and improves the efficiency and accuracy of ciphertext inference.
Patent Information
- Application Number
- CN202510545524.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-04-28
AI Technical Summary
The existing ciphertext inference scheme cannot support the processing of floating-point data, resulting in inefficient ciphertext inference.
By converting the ciphertext of floating-point number data into information of integer type for nonlinear processing, the calculation is completed using the ciphertext inference protocol of integer type, and mapping is performed based on the positive and negative conditions of the processing results, and finally recovering the ciphertext of floating-point number type.
The ciphertext inference of floating-point number type data is realized, which improves the efficiency and accuracy of ciphertext inference.
Smart Images

Figure CN120105461B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cryptography technology, and in particular to a method and device for processing floating-point data in ciphertext calculations. Background Art
[0002] Ciphertext reasoning schemes that combine homomorphic encryption and secure multi-party computation (SMC) technologies can protect the privacy of both the model and data providers while improving reasoning efficiency compared to ciphertext reasoning based solely on homomorphic encryption. Due to limitations in converting homomorphic ciphertext to SMC secret shares, current solutions often use the Brakerski-Van-Vercauteren (BFV) algorithm or the Brakerski-Gentry-Vaikuntanathan (BGV) algorithm combined with secure multi-party computation (MPC). However, these methods only support ciphertext reasoning for integer data and lack support for floating-point numbers. Therefore, implementing ciphertext reasoning for floating-point data is a pressing technical challenge. Summary of the Invention
[0003] The embodiments of the present application provide a method and device for processing floating-point data in ciphertext calculations, which can implement ciphertext reasoning of floating-point type data.
[0004] The technical solution of the embodiment of the present application is implemented as follows:
[0005] In a first aspect, an embodiment of the present application provides a method for processing floating-point data in ciphertext calculation, which is applied to a terminal device, and the method includes:
[0006] Obtaining a first ciphertext sent by the service device; wherein the first ciphertext represents a ciphertext generated based on floating-point data;
[0007] Determining first information of integer type according to the first ciphertext, and performing nonlinear processing on the first information to obtain a processing result;
[0008] Determining a first result based on the processing result and the first value; wherein the first result represents a result of mapping based on the positive or negative condition of the processing result;
[0009] Determine a second ciphertext of a floating-point number type according to the first result, the first value, and a preset constant;
[0010] A first secret share is determined based on the second ciphertext, and the first secret share is sent to the service device, so that the service device determines a target ciphertext according to the local second secret share and the first secret share.
[0011] In a second aspect, an embodiment of the present application provides a method for processing floating-point data in ciphertext calculation, which is applied to a service device, and the method includes:
[0012] Generate a first ciphertext based on the ciphertext to be processed, and send the first ciphertext to the terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data;
[0013] In response to a first secret share sent by a terminal device, a target ciphertext is obtained based on a local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines a first result based on the obtained processing result and the first numerical value, determines a second ciphertext of a floating-point type based on the first result, the first numerical value and a preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive or negative situation of the processing result.
[0014] In a third aspect, an embodiment of the present application provides a terminal device, including a first acquiring unit, a first determining unit, and a first generating unit;
[0015] A first acquiring unit is configured to acquire a first ciphertext sent by the service device; wherein the first ciphertext represents ciphertext generated based on floating-point data;
[0016] a first determining unit, configured to determine first information of an integer type according to the first ciphertext, and perform nonlinear processing on the first information to obtain a processing result;
[0017] The first generating unit is configured to determine a first result based on the processing result and the first numerical value; determine a second ciphertext of a floating-point type based on the first result, the first numerical value, and a preset constant; determine a first secret share based on the second ciphertext, and send the first secret share to a service device, so that the service device determines a target ciphertext based on the local second secret share and the first secret share; wherein the first result represents a result of mapping based on the positive or negative condition of the processing result.
[0018] In a fourth aspect, an embodiment of the present application provides a service device, including a second generating unit and a second determining unit;
[0019] A second generating unit is configured to generate a first ciphertext based on the ciphertext to be processed, and send the first ciphertext to a terminal device; wherein the ciphertext to be processed is a ciphertext corresponding to the floating-point data;
[0020] The second determination unit is used to respond to the first secret share sent by the terminal device and obtain the target ciphertext based on the local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines a first result based on the obtained and first numerical values, determines the second ciphertext of a floating-point type based on the first result, the first numerical value and a preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive and negative conditions of the processing result.
[0021] An embodiment of the present application provides a method and device for processing floating-point data in ciphertext calculation, wherein a terminal device obtains a first ciphertext sent by a service device; wherein the first ciphertext represents a ciphertext generated based on the floating-point data; first information of an integer type is determined based on the first ciphertext, and nonlinear processing is performed based on the first information to obtain a processing result; a first result is determined based on the processing result and a first numerical value; wherein the first result represents a result of mapping based on the positive or negative situation of the processing result; a second ciphertext of a floating-point type is determined based on the first result, the first numerical value, and a preset constant; a first secret share is determined based on the second ciphertext, and the first secret share is sent to the service device, so that the service device determines a target ciphertext based on the local second secret share and the first secret share. The service device generates a first ciphertext based on the ciphertext to be processed and sends the first ciphertext to the terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data; in response to the first secret share sent by the terminal device, the target ciphertext is obtained according to the local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines a first result based on the obtained processing result and the first numerical value, determines a second ciphertext of a floating-point type according to the first result, the first numerical value and a preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive or negative situation of the processing result. It can be seen that when the service device and the terminal device calculate and exchange secret shares of the floating-point data type, the terminal device can, after receiving the first ciphertext of the floating-point data type sent by the service device, first process the first ciphertext into first information of the integer type, so that the relevant protocol that can support integer type data can be used to complete nonlinear processing to obtain the processing result, and then obtain the first result that can map the positive and negative conditions of the processing result based on the processing result and the first numerical value, and then use the first result, the first numerical value and the preset constant to obtain the second ciphertext of the floating-point data type, and obtain the first secret share of the floating-point data type based on the second ciphertext, thereby completing the generation of the secret share of the floating-point data type, and then sending the first secret share to the service device, and the service device obtains the completed target ciphertext based on its local second secret share and the first secret share, effectively realizing ciphertext reasoning that supports floating-point type data and improving the efficiency of ciphertext reasoning. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Various other advantages and benefits will become apparent to those skilled in the art by reading the detailed description of the preferred embodiment below.The accompanying drawings are only for the purpose of illustrating the preferred embodiment and are not to be considered as limiting the present application.
[0023] Figure 1 Schematic diagram of the implementation process of the method for processing floating point data in ciphertext calculation proposed in this application embodiment Figure 1 ;
[0024] Figure 2 Schematic diagram of the implementation process of the method for processing floating point data in ciphertext calculation proposed in this application embodiment Figure 2 ;
[0025] Figure 3 Schematic diagram of the implementation process of the method for processing floating point data in ciphertext calculation proposed in this application embodiment Figure 3 ;
[0026] Figure 4 A schematic diagram of an application scenario of ciphertext reasoning proposed in an embodiment of this application;
[0027] Figure 5 Schematic diagram of the implementation process of the method for processing floating point data in ciphertext calculation proposed in this application embodiment Figure 4 ;
[0028] Figure 6 Schematic diagram of the implementation process of the method for processing floating point data in ciphertext calculation proposed in this application embodiment Figure 5 ;
[0029] Figure 7 Schematic diagram of the structure of the terminal device proposed in this embodiment of the application Figure 1 ;
[0030] Figure 8 Schematic diagram of the structure of the terminal device proposed in this embodiment of the application Figure 2 ;
[0031] Figure 9 Schematic diagram of the composition structure of the service equipment proposed in this embodiment Figure 1 ;
[0032] Figure 10 Schematic diagram of the composition structure of the service equipment proposed in this embodiment Figure 2 . DETAILED DESCRIPTION
[0033] The following will be combined with the accompanying drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. It should be understood that the specific embodiments described herein are only used to explain the related applications and are not intended to limit the applications. It should also be noted that for ease of description, only the portions relevant to the related applications are shown in the drawings.
[0034] Currently, due to the limitations of converting homomorphic ciphertext to secure multi-party computing secret shares, related ciphertext reasoning schemes mostly use the BFV or BGV algorithms that support integers in combination with MPC, but lack related methods for converting the Cheon-Kim-Kim-Song Algorithm (CKKS) algorithm that supports floating-point numbers to MPC secret shares.
[0035] For example, for the ciphertext reasoning related methods of the BFV or BGV algorithm, in the process of converting homomorphic ciphertext to MPC secret share (Enc_to_share), the model reasoning can be completed by the server and the client together, where the homomorphic calculation is performed on the server and the MPC protocol is completed by the interaction and collaboration of both parties. The conversion process of ciphertext and secret share involved in the reasoning process can be: for the server, it can be in the algebraic loop. Select a random number r as the random mask, add the random mask to the ciphertext to be processed and encrypt it, the secret share ct_share obtained can be expressed as Add(ct, Encrypt(r)), and the secret share ct_share is sent to the client; assuming that the client generates a secret share of client_share=x+r after decryption and nonlinear calculation based on the secret share ct_share, and the local secret share of the server is expressed as server_share=-r, then the secret shares of the two parties satisfy server_share+client_share mod p=x, where x represents the plaintext corresponding to the ciphertext to be processed, and p is the plaintext modulus, which is also the modulus used by the MPC protocol; because the random mask is , so this split is secure. During the MPC secret share to homomorphic ciphertext conversion (Share_to_Enc) process, the client can send the secret share a to the server. The server can add the received secret share a to the local secret share b to obtain the converted ciphertext. According to the additive secret sharing property, the secret shares of both parties satisfy a+b mod p=c. The properties of homomorphic computation ensure that the encoded and encrypted enc(a) +enc(b) = enc(a+b) = enc(c), so this conversion is secure and correct.
[0036] The CKKS ciphertext inference scheme, because it supports floating-point operations, is well suited for model reasoning. However, the method proposed above cannot be directly used to convert CKKS ciphertext into secret shares. CKKS ciphertext encodes and encrypts plaintext in the complex domain, but it is impossible to find a uniformly distributed random number r in the complex domain, making x and x + r indistinguishable. Simply adding a random mask cannot guarantee security, and x may be leaked. Furthermore, in the Share_to_enc phase, if the share values of both parties are a + b = c + p mod p, the CKKS encrypted sum is enc(c + p), and the corresponding plaintext is c + p instead of c, which can lead to significant errors.
[0037] In order to solve the current problem, the embodiment of the present application proposes a method and device for processing floating-point data in ciphertext calculation. The embodiment of the present application provides a method and device for processing floating-point data in ciphertext calculation, wherein the terminal device obtains a first ciphertext sent by a service device; wherein the first ciphertext represents a ciphertext generated based on floating-point data; first information of an integer type is determined according to the first ciphertext, and nonlinear processing is performed according to the first information to obtain a processing result; a first result is determined according to the processing result and the first numerical value; wherein the first result represents a result of mapping according to the positive and negative situation of the processing result; a second ciphertext of a floating-point type is determined according to the first result, the first numerical value and a preset constant; a first secret share is determined based on the second ciphertext, and the first secret share is sent to the service device, so that the service device determines the target ciphertext based on the local second secret share and the first secret share. The service device generates a first ciphertext based on the ciphertext to be processed and sends the first ciphertext to the terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data; in response to the first secret share sent by the terminal device, the target ciphertext is obtained according to the local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines a first result based on the obtained processing result and the first numerical value, determines a second ciphertext of a floating-point type according to the first result, the first numerical value and a preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive and negative conditions of the processing result, thereby enabling ciphertext reasoning of floating-point type data.
[0038] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application.
[0039] An embodiment of the present application provides a method for processing floating-point data in ciphertext calculation, which is applied to a terminal device; Figure 1 As shown, the method for processing floating-point data in ciphertext calculation of a terminal device may include the following steps:
[0040] Step 101: Obtain a first ciphertext sent by a service device; wherein the first ciphertext represents a ciphertext generated based on floating-point data.
[0041] In an embodiment of the present application, the terminal device may obtain a first ciphertext sent by the service device; wherein the first ciphertext represents a ciphertext generated based on floating-point data.
[0042] In an embodiment of the present application, the terminal device may be a device that can communicate with the service device, receive ciphertext sent by the service device and perform related calculations; for example, the terminal device may be a computer, mobile phone, tablet computer or other device with communication and computing functions.
[0043] In an embodiment of the present application, the service device may be the provider of the model, where the model refers to a machine learning model, such as a neural network, a decision tree, a support vector machine, etc., and its parameters are stored in encrypted or plain text form in the service device; the service device can complete the core calculation of the model reasoning in a ciphertext state; correspondingly, the terminal device may be the user of the model, and the terminal device may participate in key calculation steps through the MPC protocol and output plain text or decrypted ciphertext related to the processing results.
[0044] In the embodiments of the present application, a floating-point number is a data format for representing real numbers, which can flexibly represent very large or very small values while allowing a certain degree of precision loss.
[0045] In an embodiment of the present application, the first ciphertext may be a ciphertext obtained by adding a random mask to the ciphertext to be processed after the service device performs homomorphic calculation on floating-point data and obtains the ciphertext to be processed by encoding and encrypting it.
[0046] For example, the service device has floating point data to be processed. By performing homomorphic calculation on the floating point data to be processed and then encoding and encrypting the result of the homomorphic calculation, the ciphertext to be processed can be obtained. ,in, , Express To encode, Indicates encryption using the public key, N is the number of homomorphic ciphertext slots, which is a preset value; then the service device can generate a bit width of Random mask of , for example, the bit width can be N / 2 Random numbers to form a random mask , ; Then, the first ciphertext can be obtained based on the random mask and the ciphertext to be processed.
[0047] In some embodiments of the present application, when the service device adds a random mask to the ciphertext to be processed to obtain the first ciphertext, it can perform a division operation on the random mask and a preset constant, and then encode and encrypt the result of the division operation to obtain the encrypted mask, thereby obtaining the first ciphertext based on the encrypted mask and the ciphertext to be processed.
[0048] For example, the encrypted mask can be expressed as ,in, represents a preset constant, so the first ciphertext can be expressed as , that is, the first ciphertext may be the result of adding the encrypted mask and the ciphertext to be processed.
[0049] Step 102: Determine first information of integer type according to the first ciphertext, and perform nonlinear processing on the first information to obtain a processing result.
[0050] In an embodiment of the present application, after obtaining the first ciphertext sent by the service device, the terminal device can determine the first information of integer type according to the first ciphertext, and perform nonlinear processing according to the first information to obtain a processing result.
[0051] In some embodiments of the present application, when the terminal device determines the first information of the integer type based on the first ciphertext, it can determine the integer information based on the product of the first ciphertext and a preset constant; then perform a modulo operation on the integer information and the second value to obtain the first information.
[0052] In some embodiments of the present application, when the terminal device determines integer information based on the product of the first ciphertext and a preset constant, it can first decrypt the first ciphertext to obtain floating-point data, and then determine the integer information based on the product of the floating-point data and the preset constant.
[0053] In some embodiments of the present application, when the terminal device determines integer information based on the product of floating-point data and a preset constant, it can round the product of the floating-point data and the preset constant, thereby converting the floating-point data into an integer; thereby, the rounding of the floating-point number can be achieved to provide conditions for subsequent nonlinear processing based on the MPC protocol.
[0054] For example, the terminal device processes the first ciphertext After decryption, we can get , the terminal device can determine the integer information based on the product of the floating point data and the preset constant. and preset constants Perform multiplication and rounding, for example, , to complete the operation of converting floating-point numbers into integers.
[0055] In some embodiments of the present application, the terminal device performs a modulo operation on the integer information and the second value to obtain the first information, using the second value as the modulus, thereby performing a modulo operation on the integer information and the second value to obtain the first information.
[0056] For example, the second value is ,in, is the number of bits used by the MPC protocol; the first information can be expressed as .
[0057] It can be understood that in the embodiments of the present application, the processing result represents the result obtained by the terminal device performing nonlinear processing based on the first information; wherein, the nonlinear processing is not limited in this application, for example, it can be the calculation processing of some nonlinear functions.
[0058] In an embodiment of the present application, the terminal device converts floating-point data into integers, thereby being able to perform nonlinear processing under the MPC protocol, thereby ensuring efficient computing while maintaining the privacy and security of all parties' devices.
[0059] Step 103 : Determine a first result based on the processing result and the first value; wherein the first result represents a result of mapping based on the positive or negative condition of the processing result.
[0060] In an embodiment of the present application, after the terminal device determines the first information of an integer type based on the first ciphertext and performs nonlinear processing based on the first information to obtain the processing result, it can determine the first result based on the processing result and the first numerical value; wherein the first result represents the result of mapping based on the positive or negative situation of the processing result.
[0061] In the embodiments of the present application, the specific value of the first value is not limited in this application. For example, the first value can be .
[0062] In some embodiments of the present application, when the terminal device determines the first result based on the first numerical value and the processing result, if the processing result is a negative number, the terminal device may perform a value mapping process of a modulo operation on the processing result to obtain a mapping value; wherein the mapping value is equal to the result of the modulo operation of the processing result and the second numerical value; then determine the first sum between the mapping value and the first numerical value, perform a modulo operation on the first sum and the second numerical value, and obtain the first result; if the processing result is not a negative number, determine the second sum between the processing result and the first numerical value, perform a modulo operation on the second sum and the second numerical value, and obtain the first result.
[0063] In an embodiment of the present application, in the case where the processing result is a negative number, in order to ensure that the negative number can be correctly processed so that the secret share finally obtained based on the processing result is also a negative number without affecting the accuracy of the final ciphertext inference, the embodiment of the present application performs mapping according to the positive and negative conditions of the processing result to obtain the first result, thereby ensuring the accuracy and reliability of the first secret share obtained by performing subsequent operations based on the first result.
[0064] For example, due to the requirements of the protocol, when the terminal device determines the first secret share based on the processing result, it is necessary to make the value of the processing result a positive number, such as the value of the processing result must meet Therefore, when the processing result is a negative number, you can first perform a modulo operation on the processing result to obtain the mapping value. Assume =3, the second value , processing results , the mapping value can be taken as 7, this is because .
[0065] In some embodiments of the present application, a method for determining a first sum between a mapped value and a first numerical value, and performing a modulo operation on the first sum and the second numerical value to obtain a first result can be expressed as follows: ,in, Indicates the first result, represents the first value, represents the second value, Indicates the processing result The corresponding mapping value.
[0066] For example, =3, then the second value , the first value =4, processing result , the mapping value of the processing result is 7; then according to the above The calculation method is calculated 3, that is is 3.
[0067] In an embodiment of the present application, when the first result is greater than or equal to 0 and less than the first value, the calculation result can be considered to be a negative number; when the first result is greater than or equal to the first value and less than the second value, the calculation result can be considered to be a positive number.
[0068] For example, assuming =3, the second value , the first value , processing results , Corresponding mapping value is 7, then the first result can be calculated , the first result is in [0, ), it can be considered that the original processing result corresponding to the first result is a negative number.
[0069] For example, assuming =3, the second value , the first value , processing results , you can directly use Calculate the first result , the first result is in [ , ), it can be considered that the original processing result corresponding to the first result is a positive number.
[0070] In an embodiment of the present application, by calculating the first result in the above manner, a "potential" negative number can be represented by the first result, so that when the processing result is a negative number, the final secret share is also a negative number, thereby improving the reliability of ciphertext reasoning.
[0071] Step 104: Determine a second ciphertext of a floating-point type according to the first result, the first value, and a preset constant.
[0072] In an embodiment of the present application, after determining the first result according to the first numerical value and the processing result, the terminal device can determine a second ciphertext of a floating-point type according to the first result, the first numerical value and a preset constant.
[0073] In the embodiment of the present application, since a rounding operation of multiplication is performed using a preset constant in the process of determining the first information, the preset constant can be used to perform corresponding processing on the first result to restore the data type of the floating-point number.
[0074] In some embodiments of the present application, when the terminal device determines the second ciphertext of the floating-point type based on the first result, the first numerical value and the preset constant, it can determine the first difference between the first result and the first numerical value; then determine the first ratio between the first difference and the preset constant; then encode the first ratio to obtain the first plaintext information; finally, encrypt the first plaintext information to obtain the second ciphertext.
[0075] In an embodiment of the present application, the first difference is obtained by subtracting the first value from the first result in order to offset the portion of the first value added to the processed result when calculating the first result; and the first ratio is obtained by dividing the first difference by a preset constant in order to offset the portion of the floating-point number multiplied by the preset constant to restore the data type of the floating-point number.
[0076] For example, when determining the second ciphertext, the first result may be determined first. With the first value The first difference between , then determine the first difference and the preset constant The first ratio between , so that the second ciphertext can be obtained after encoding and encrypting the first ratio. The second ciphertext can be expressed as .
[0077] For example, assuming the processing result , first result , preset constant =1, , then the second ciphertext is .
[0078] In the embodiment of the present application, the above-mentioned calculation method of the second ciphertext allows the processing result, whether positive or negative, to be correctly represented by the second ciphertext.
[0079] Step 105: Determine a first secret share based on the second ciphertext, and send the first secret share to the service device, so that the service device determines a target ciphertext based on the local second secret share and the first secret share.
[0080] In an embodiment of the present application, after the terminal device determines the second ciphertext of the floating-point type based on the first result, the first numerical value and the preset constant, it can determine the first secret share based on the second ciphertext and send the first secret share to the service device, so that the service device determines the target ciphertext based on the local second secret share and the first secret share.
[0081] In some embodiments of the present application, after completing nonlinear processing based on the first information of integer type, the terminal device can convert the first secret share of floating point type based on the obtained processing result, thereby completing the ciphertext reasoning of the floating point type data.
[0082] In some embodiments of the present application, the terminal device may determine the third ciphertext, thereby determining the first secret share based on the second ciphertext and the third ciphertext.
[0083] In some embodiments of the present application, Figure 2 As shown, when the terminal device determines the first secret share based on the second ciphertext, the following steps may be included:
[0084] Step 201: Verify the first result based on a comparison protocol to obtain a first reference value; wherein the first reference value is used to determine whether the sum of the first result and the second secret share is greater than a second value.
[0085] In an embodiment of the present application, when the terminal device determines the first secret share based on the second ciphertext, it can verify the first result based on the comparison protocol to obtain a first reference value; wherein the first reference value is used to determine whether the sum of the first result and the second secret share is greater than the second value.
[0086] In some embodiments of the present application, when determining the third ciphertext, the terminal device can verify the size of the first result based on the comparison protocol in the MPC protocol; the comparison protocol can be used to compare whether the sum of the first result and the second secret share local to the service device is greater than or equal to the second value; after inputting the first result into the comparison protocol, the terminal device can obtain the first reference value.
[0087] Exemplarily, the comparison protocol can be expressed as ,in Represents the second secret share of the service device, that is, the comparison protocol can compare the first result With the second secret share Is the sum greater than or equal to Compare and feed back the first reference value to the terminal device , feedback to the service device the second reference value ; Among them, if ,but ,otherwise , and The specific value of is not limited, for example , ,but ; , ,but .
[0088] Step 202: Determine a third ciphertext according to the first reference value, the preset constant, and the second value.
[0089] In an embodiment of the present application, after the terminal device verifies the first result based on the comparison protocol and obtains the first reference value, it can determine the third ciphertext according to the first reference value, the preset constant and the second value.
[0090] In some embodiments of the present application, when the terminal device determines the third ciphertext based on the first reference value, the preset constant and the second numerical value, it can determine the first product of the second numerical value and the first reference value; then determine the second ratio of the first product and the preset constant; and then encode the second ratio to obtain the second plaintext information; finally, the second plaintext information can be encrypted to obtain the third ciphertext.
[0091] For example, when determining the third ciphertext, the terminal device may first determine the second value With the first reference value The first product of , and then determine the second ratio of the first product to the preset constant , and then the second ratio is encoded and encrypted to obtain the third ciphertext .
[0092] Step 203: Determine the first secret share according to the second ciphertext and the third ciphertext.
[0093] In an embodiment of the present application, after determining the third ciphertext according to the first reference value, the preset constant and the second numerical value, the terminal device may determine the first secret share according to the second ciphertext and the third ciphertext.
[0094] Exemplarily, the first secret share may include the second ciphertext and the third ciphertext .
[0095] In the embodiments of the present application, the order of determining the third ciphertext and determining the second ciphertext is not limited in this application. For example, the third ciphertext can be determined at the same time as the second ciphertext is determined; the third ciphertext determination process can also be executed after the second ciphertext is determined; or the third ciphertext can be determined first and then the second ciphertext is determined, and it is only necessary to finally obtain the first secret share based on the second ciphertext and the third ciphertext.
[0096] An embodiment of the present application provides a method for processing floating-point data in ciphertext calculation, where a terminal device obtains a first ciphertext sent by a service device; wherein the first ciphertext represents a ciphertext generated based on the floating-point data; first information of an integer type is determined based on the first ciphertext, and nonlinear processing is performed based on the first information to obtain a processing result; a first result is determined based on the processing result according to the processing result and a first numerical value; wherein the first result represents a result of mapping according to the positive or negative situation of the processing result; a second ciphertext of a floating-point type is determined based on the first result, the first numerical value, and a preset constant; a first secret share is determined based on the second ciphertext, and the first secret share is sent to the service device, so that the service device determines a target ciphertext based on the local second secret share and the first secret share. It can be seen that when the service device and the terminal device calculate and exchange secret shares of the floating-point data type, the terminal device can, after receiving the first ciphertext of the floating-point data type sent by the service device, first process the first ciphertext into first information of the integer type, so that the relevant protocol that can support integer type data can be used to complete nonlinear processing to obtain the processing result, and then obtain the first result that can map the positive and negative conditions of the processing result based on the processing result and the first numerical value, and then use the first result, the first numerical value and the preset constant to obtain the second ciphertext of the floating-point data type, and obtain the first secret share of the floating-point data type based on the second ciphertext, thereby completing the generation of the secret share of the floating-point data type, and then sending the first secret share to the service device, and the service device obtains the completed target ciphertext based on its local second secret share and the first secret share, effectively realizing ciphertext reasoning that supports floating-point type data and improving the efficiency of ciphertext reasoning.
[0097] Based on the above embodiment, in another embodiment of the present application, a method for processing floating point data in ciphertext calculation is provided, which is applied to a service device such as Figure 3 As shown, the method for processing floating-point data in ciphertext calculation of the service device may include the following steps:
[0098] Step 301: Generate a first ciphertext based on the ciphertext to be processed, and send the first ciphertext to a terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data.
[0099] In an embodiment of the present application, the service device may generate a first ciphertext based on the ciphertext to be processed, and send the first ciphertext to the terminal device; wherein the ciphertext to be processed is a ciphertext corresponding to floating-point data.
[0100] In some embodiments of the present application, the ciphertext to be processed is the ciphertext obtained after the service device performs homomorphic calculations on floating-point data and then encodes and encrypts the data.
[0101] In some embodiments of the present application, when the service device generates the first ciphertext according to the ciphertext to be processed, it may add a random mask to the ciphertext to be processed to obtain the first ciphertext.
[0102] Step 302: In response to the first secret share sent by the terminal device, a target ciphertext is obtained based on the local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, determines a first result based on the obtained processing result and the first numerical value, determines a second ciphertext of a floating-point type based on the first result, the first numerical value, and a preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive or negative situation of the processing result.
[0103] In an embodiment of the present application, after the service device generates a first ciphertext based on the ciphertext to be processed and sends the first ciphertext to the terminal device, it can respond to the first secret share sent by the terminal device and obtain the target ciphertext based on the local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines the first result based on the obtained processing result and the first numerical value, determines the second ciphertext of a floating-point type based on the first result, the first numerical value and the preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive and negative situation of the processing result.
[0104] In some embodiments of the present application, when the service device obtains the target ciphertext according to the local second secret share and the first secret share, it can determine the target ciphertext according to the second reference value, the first secret share, and the second secret share.
[0105] In an embodiment of the present application, the second reference value represents a reference value obtained by the service device based on a comparison protocol and used to determine whether the sum of the first result and the second secret share is greater than a second value.
[0106] For example, the service device sends the second secret share Enter the comparison protocol to get the second reference value , the process can be expressed as , that is, the comparison protocol can be used to compare the first result With the second secret share Is the sum greater than or equal to Compare and feed back the first reference value to the terminal device , feedback to the service device the second reference value ; Among them, if ,but ,otherwise , and The specific value of is not limited.
[0107] In some embodiments of the present application, the service device determines the target ciphertext according to the second reference value, the first secret share and the second secret share. The method can be expressed as the following formula:
[0108] (1)
[0109] It can be seen that the target ciphertext can be directly calculated from the second ciphertext, the third ciphertext, the second reference value and the second numerical value in the first secret share through transformation.
[0110] An embodiment of the present application provides a method for processing floating-point data in ciphertext calculation, where a service device can generate a first ciphertext based on a ciphertext to be processed and send the first ciphertext to a terminal device; wherein the ciphertext to be processed is a ciphertext corresponding to the floating-point data; in response to a first secret share sent by the terminal device, a target ciphertext is obtained based on a local second secret share and a first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines a first result based on the obtained processing result and the first numerical value, determines a second ciphertext of a floating-point type based on the first result, the first numerical value and a preset constant, and determines a secret share based on the second ciphertext; the first result represents a result of mapping according to the positive or negative situation of the processing result. It can be seen that the service device can send the first ciphertext of the floating-point data type to the terminal device, so that the terminal device converts the first ciphertext into integer type data, and completes subsequent nonlinear processing and obtains the first secret share of the floating-point data type based on the processing result. When the service device receives the first secret share of the floating-point data type sent by the terminal device, it can obtain the target ciphertext based on the first secret share and the local second secret share, thereby completing the ciphertext reasoning for the floating-point data type and improving the ciphertext reasoning efficiency of the floating-point data type.
[0111] Based on the above embodiment, in another embodiment of the present application, illustratively, as Figure 4 As shown, in an application scenario of encrypted reasoning, the model provider 200 can provide a encrypted reasoning service 2002 based on a trained neural network model 2001, and the service device needs to protect the parameter information of the model; the model user 300 can send model reasoning request data 3001 to the model provider, and the model provider can send the reasoning result 2003 to the model user after responding to the model reasoning request. The model user needs to protect the model reasoning request data and the reasoning result.
[0112] In an embodiment of the present application, the service device may be the provider of the model, where the model refers to a trained machine learning model, such as a neural network, a decision tree, a support vector machine, etc., and its parameters are stored in encrypted or plain text form in the service device; the service device can complete the core calculation of the model reasoning in a ciphertext state; correspondingly, the terminal device may be the user of the model, and the terminal device may participate in key calculation steps through the MPC protocol and output plain text or decrypted ciphertext related to the processing results.
[0113] In an embodiment of the present application, MPC is used to solve the problem of a group of mutually distrustful participants, each holding secret data, collaboratively calculating a given function. While ensuring that the participants obtain the correct processing results, MPC cannot obtain any information other than the processing results. Throughout the calculation process, the participants always have absolute control over the data they own. Additive secret sharing is a commonly used technology in MPC. It splits the secret in the form of addition on an algebraic ring or an algebraic field. Each share after the split is managed by a different participant. A single participant cannot recover the secret information. Only when several participants work together can the secret message be recovered. The recovery method is to perform an addition operation on multiple shares, so it is called additive secret sharing. Participants holding secret shares of data can execute a given protocol. During the execution of the protocol, the participants jointly calculate a function of the original data through several rounds of data interaction. The final processing result is still retained in the form of a secret share, and each participant only holds a part of it.
[0114] In some embodiments of the present application, the method for processing floating-point data in ciphertext calculation can be applied to ciphertext reasoning scenarios, and the privacy computing node performs the homomorphic ciphertext to MPC secret share process and the MPC secret share to homomorphic ciphertext process in homomorphic computing and MPC calculation; in the above-mentioned ciphertext reasoning scenario, the service device can perform homomorphic ciphertext calculation to obtain homomorphic ciphertext, and convert it into MPC secret share. After that, the terminal device can perform nonlinear processing on the MPC secret share, and convert the calculated result into homomorphic ciphertext for subsequent calculations.
[0115] In some embodiments of the present application, the processing method of floating-point data in ciphertext calculation can be used to support ciphertext reasoning of floating-point numbers. The service device can use the CKKS homomorphic algorithm for efficient calculation in the linear calculation part; in the nonlinear processing part, the terminal device can use the MPC algorithm for precise calculation to reduce the error caused by approximate fitting; thereby, the conversion between CKKS ciphertext and MPC secret share can be achieved without leaking data.
[0116] In some embodiments of the present application, the CKKS homomorphic algorithm is an encryption and decryption algorithm that supports arbitrary calculations on floating-point data. The CKKS homomorphic algorithm supports the following operators:
[0117] Key generation KeyGen(lambda)->(sk,pk,rlk,glk): Input security parameter lambda, output private key sk, encrypted public key pk, relinearized public key rlk, rotated public key glk;
[0118] Encode(msg)->pt: Input a message data msg containing n_slot numbers and output a plaintext pt;
[0119] Decode(pt)->msg: Input a plaintext pt and output a message data msg containing n_slot numbers;
[0120] Encrypt(pk,pt)->ct: Input the encryption public key pk and a plaintext pt, and output a ciphertext ct;
[0121] Decryption Decrypt(sk,ct)->pt: input private key sk, a ciphertext ct, and output a plaintext pt;
[0122] Ciphertext + plaintext AddPlain(ct0,pt)->ct1: Input a ciphertext ct0 and a plaintext pt, and output a ciphertext ct1, satisfying Decode(Decrypt(sk,ct0))+Decode(pt)=Decode(Decrypt(sk,ct1))+e, where sk is the private key and e is a small error term;
[0123] Ciphertext + Ciphertext Add(ct0,ct1)->ct2: Input two ciphertexts ct0 and ct1, and output a ciphertext ct2, satisfying Decode(Decrypt(sk,ct0))+Decode(Decrypt(sk,ct1))=Decode(Decrypt(sk,ct2))+e, where sk is the private key and e is a small error term;
[0124] Ciphertext × Plaintext MultPlain(ct0,pt)->ct1: Input the relinearized public key rlk, a ciphertext ct0, and a plaintext pt, and output a ciphertext ct1. This satisfies Decode(Decrypt(sk,ct0))×Decode(pt)=Decode(Decrypt(sk,ct1))+e, where sk is the private key and e is a small error term.
[0125] Ciphertext × Ciphertext Mult(rlk,ct0,ct1)->ct2: Input two ciphertexts ct0 and ct1, and output a ciphertext ct2, satisfying Decode(Decrypt(sk,ct0))×Decode(Decrypt(sk,ct1))=Decode(Decrypt(sk,ct2))+e, where sk is the private key and e is a small error term;
[0126] Rotate(glk,ct0,n_step)->ct1: Input the rotated public key glk, a ciphertext ct0 and the number of rotation steps n_step, and output a ciphertext ct1 that satisfies Decode(Decrypt(sk,ct0))=RotateMessage(Decode(Decrypt(sk,ct1)),n_step)+e, where sk is the private key, e is a small error term, and RotateMessage(,) is some kind of circular shift of the message data array.
[0127] In an embodiment of the present application, a process in which a service device generates a first ciphertext, a terminal device receives the first ciphertext sent by the service device, and determines the first information can be regarded as a process of converting homomorphic ciphertext into an MPC secret share; a process in which the terminal device performs nonlinear processing on the first information to obtain a processing result, and determines the first secret share based on the processing result and sends it to the service device, so that the service device can determine the target ciphertext based on the first secret share and the local second secret share can be regarded as a process of converting the MPC secret share into homomorphic ciphertext.
[0128] In some embodiments of the present application, a floating point number is converted into an integer by multiplying the floating point number by a constant and rounding it up. Assume that the service device performs homomorphic calculations on the floating point data to obtain the plaintext x, given a preset constant The value range of x satisfies For the convenience of explanation , Express To encode, Indicates encryption using the public key; takes the statistical security value of the MPC protocol =40.
[0129] For example, Figure 5 As shown, the method for processing floating-point data in ciphertext calculation may include the following steps:
[0130] Step 401: Determine the ciphertext to be processed.
[0131] The service device can perform homomorphic calculations on the floating-point data to be processed, and then encode and encrypt the results of the homomorphic calculations to obtain the ciphertext to be processed. .
[0132] Step 402: Generate a random mask, determine the first ciphertext based on the random mask, and send it to the terminal device.
[0133] The service device can generate a bit width of Random mask of , to get the first ciphertext And send it to the terminal device.
[0134] For example, the bit width can be N / 2. Random numbers to form a random mask , .
[0135] This ensures The statistical security of the bit makes it impossible for the terminal device to obtain the value of the original floating-point data, and the secret share is safely split to perform subsequent processing.
[0136] Step 403: The terminal device decrypts and calculates the received first ciphertext to obtain the first information.
[0137] The terminal device decrypts and performs related calculations on the received first ciphertext, including After decryption, we get ,right and preset constants Perform multiplication and rounding to get , complete the operation of converting the floating point number into an integer, and then compare the obtained integer information with the second value Perform modulo operation to obtain the first information .
[0138] in, Is the number of bits used by the MPC protocol. To ensure the calculation reliability of the MPC protocol, Need to be greater than ; Assume that the secret share of the service device is local , then it satisfies .
[0139] For example, Figure 6 As shown, after the terminal device obtains the first information, it may include the following steps:
[0140] Step 404: The terminal device performs nonlinear processing according to the first information to obtain a processing result, and determines a first result according to the processing result.
[0141] For example, the first result is determined according to the processing result. When the processing result is a negative number, you can first perform a modulo operation on the processing result to obtain the mapping value, and then map the processing result to interval; assuming =3, the second value , processing results , since -1 mod 8=7, the processing result is Corresponding mapping value is 7; then the first result is determined using the mapping value, the first value and the second value, for example, the first result ,in, Indicates the first result, represents the first value, represents the second value, Indicates the processing result The corresponding mapping value can be calculated to get the first result .
[0142] Step 405: Determine a second ciphertext based on the first result, obtain a first reference value based on the comparison protocol, and determine a third ciphertext based on the first reference value. Send the second ciphertext and the third ciphertext as the first secret share to the service device.
[0143] The terminal device can determine the second ciphertext based on the first result , based on the comparison protocol, a first reference value is obtained, and a third ciphertext is determined based on the first reference value .
[0144] Step 406: The service device obtains a second reference value based on the comparison protocol.
[0145] Step 407: The service device obtains the target ciphertext based on the second reference value, the first secret share, and the local second secret share.
[0146] The terminal device can be based on the comparison protocol Get the first reference value , the service device can also obtain a second reference value based on the comparison protocol ,if ,but ,otherwise , and The specific value of is not limited; the terminal device obtains the second ciphertext by calculation and the third ciphertext , the second ciphertext and the third ciphertext Sent to the service device as the first secret share; the service device can obtain the second reference value based on the obtained , Second ciphertext , the third ciphertext and the second value Substitute into the above formula (1) to get the target ciphertext .
[0147] It can be understood that by comparing the protocols, the problem of the sum of the secret shares of both parties exceeding the modulus can be handled, so that the result is rather than , after the above steps, the conversion between secret share and CKKS ciphertext can be completed correctly.
[0148] In summary, the embodiments of the present application provide a method for processing floating-point data in ciphertext calculations, so that ciphertext reasoning can adopt the CKKS encryption algorithm that supports floating-point numbers, which is more suitable for ciphertext reasoning scenarios of floating-point data, improves the applicability of ciphertext reasoning, and at the same time improves the accuracy and reliability of ciphertext reasoning of floating-point data.
[0149] An embodiment of the present application provides a method and device for processing floating-point data in ciphertext calculation, wherein a terminal device obtains a first ciphertext sent by a service device; wherein the first ciphertext represents a ciphertext generated based on the floating-point data; first information of an integer type is determined based on the first ciphertext, and nonlinear processing is performed based on the first information to obtain a processing result; a first result is determined based on the processing result and a first numerical value; wherein the first result represents a result of mapping based on the positive or negative situation of the processing result; a second ciphertext of a floating-point type is determined based on the first result, the first numerical value, and a preset constant; a first secret share is determined based on the second ciphertext, and the first secret share is sent to the service device, so that the service device determines a target ciphertext based on the local second secret share and the first secret share. The service device generates a first ciphertext based on the ciphertext to be processed and sends the first ciphertext to the terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data; in response to the first secret share sent by the terminal device, the target ciphertext is obtained according to the local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines a first result based on the obtained processing result and the first numerical value, determines a second ciphertext of a floating-point type according to the first result, the first numerical value and a preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive or negative situation of the processing result. It can be seen that when the service device and the terminal device calculate and exchange secret shares of the floating-point data type, the terminal device can, after receiving the first ciphertext of the floating-point data type sent by the service device, first process the first ciphertext into first information of the integer type, so that the relevant protocol that can support integer type data can be used to complete nonlinear processing to obtain the processing result, and then obtain the first result that can map the positive and negative conditions of the processing result based on the processing result and the first numerical value, and then use the first result, the first numerical value and the preset constant to obtain the second ciphertext of the floating-point data type, and obtain the first secret share of the floating-point data type based on the second ciphertext, thereby completing the generation of the secret share of the floating-point data type, and then sending the first secret share to the service device, and the service device obtains the completed target ciphertext based on its local second secret share and the first secret share, effectively realizing ciphertext reasoning that supports floating-point type data and improving the efficiency of ciphertext reasoning.
[0150] Based on the above embodiment, in another embodiment of the present application, a terminal device is provided, such as Figure 7 As shown, the terminal device 1 may include a first acquiring unit 11 , a first determining unit 12 , and a first generating unit 13 .
[0151] The first acquiring unit 11 may be configured to acquire a first ciphertext sent by the service device; wherein the first ciphertext represents a ciphertext generated based on floating-point data.
[0152] The first determining unit 12 may be configured to determine first information of an integer type according to the first ciphertext, and perform nonlinear processing on the first information to obtain a processing result.
[0153] The first generating unit 13 can be used to determine a first result based on the processing result and the first numerical value; wherein the first result represents a result of mapping according to the positive or negative situation of the processing result; determine a second ciphertext of a floating-point type based on the first result, the first numerical value, and a preset constant; determine a first secret share based on the second ciphertext, and send the first secret share to the service device, so that the service device determines a target ciphertext based on the local second secret share and the first secret share.
[0154] In some embodiments of the present application, the first generation unit 13 can also be used to verify the first result based on a comparison protocol to obtain a first reference value; wherein the first reference value is used to determine whether the sum of the first result and the second secret share is greater than the second value; and determine the third ciphertext based on the first reference value, the preset constant and the second value; and determine the first secret share based on the second ciphertext and the third ciphertext.
[0155] In some embodiments of the present application, the first generation unit 13 can also be used to, when the processing result is a negative number, perform a value mapping process of a modulo operation on the processing result to obtain a mapping value; wherein the mapping value is equal to the result of the modulo operation of the processing result and the second numerical value; and determine a first sum between the mapping value and the first numerical value, perform a modulo operation on the first sum and the second numerical value to obtain a first result; and when the processing result is not a negative number, determine a second sum between the processing result and the first numerical value, perform a modulo operation on the second sum and the second numerical value to obtain the first result.
[0156] In some embodiments of the present application, the first generation unit 13 can also be used to determine a first difference between the first result and the first numerical value; and determine a first ratio between the first difference and a preset constant; and encode the first ratio to obtain first plaintext information; and encrypt the first plaintext information to obtain a second ciphertext.
[0157] In some embodiments of the present application, the first generation unit 13 can also be used to determine a first product of a second numerical value and a first reference value; and determine a second ratio of the first product to a preset constant; and encode the second ratio to obtain second plaintext information; and encrypt the second plaintext information to obtain a third ciphertext.
[0158] In some embodiments of the present application, the first determination unit 12 may also be configured to determine integer information based on the product of the first ciphertext and a preset constant; and perform a modulo operation on the integer information and the second value to obtain the first information.
[0159] In the embodiments of the present application, further, Figure 8 Schematic diagram of the structure of the terminal device proposed in this embodiment of the application Figure 2 ,like Figure 8 As shown, the terminal device 1 proposed in the embodiment of the present application may also include a first processor 14 and a first memory 15 storing executable instructions of the first processor 14; further, the service device 1 may also include a first communication interface 16, and a first bus 17 for connecting the first processor 14, the first memory 15 and the first communication interface 16.
[0160] In the embodiments of the present application, the first processor 14 may be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller, and a microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor functions may also be other, and the embodiments of the present application are not specifically limited. The service device 1 may also include a first memory 15, which may be connected to the first processor 14. The first memory 15 is used to store executable program code, which includes computer operating instructions. The first memory 15 may include high-speed RAM memory or non-volatile memory, such as at least two disk drives.
[0161] In the embodiment of the present application, the first bus 17 is used to connect the first communication interface 16, the first processor 14, and the first memory 15, and to facilitate mutual communication between these devices.
[0162] In the embodiment of the present application, the first memory 15 is used to store instructions and data.
[0163] Furthermore, in an embodiment of the present application, the above-mentioned first processor 14 is used to obtain a first ciphertext sent by a service device; wherein the first ciphertext represents a ciphertext generated based on floating-point data; determine first information of an integer type based on the first ciphertext, and perform nonlinear processing based on the first information to obtain a processing result; determine a first result based on the processing result and the first numerical value; wherein the first result represents a result of mapping based on the positive and negative conditions of the processing result; determine a second ciphertext of a floating-point type based on the first result, the first numerical value and a preset constant; determine a first secret share based on the second ciphertext, and send the first secret share to the service device, so that the service device determines the target ciphertext based on the local second secret share and the first secret share.
[0164] In practical applications, the first memory 15 may be a volatile memory, such as a random-access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the first processor 14.
[0165] An embodiment of the present application provides a terminal device for obtaining a first ciphertext sent by a service device; wherein the first ciphertext represents a ciphertext generated based on floating-point data; determining first information of an integer type based on the first ciphertext, and performing nonlinear processing based on the first information to obtain a processing result; determining a first result based on the processing result according to the processing result and the first numerical value; wherein the first result represents a result of mapping according to the positive or negative situation of the processing result; determining a second ciphertext of a floating-point type based on the first result, the first numerical value and a preset constant; determining a first secret share based on the second ciphertext, and sending the first secret share to the service device, so that the service device determines a target ciphertext based on the local second secret share and the first secret share. It can be seen that when the service device and the terminal device calculate and exchange secret shares of the floating-point data type, the terminal device can, after receiving the first ciphertext of the floating-point data type sent by the service device, first process the first ciphertext into first information of the integer type, so that the relevant protocol that can support integer type data can be used to complete nonlinear processing to obtain the processing result, and then obtain the first result that can map the positive and negative conditions of the processing result based on the processing result and the first numerical value, and then use the first result, the first numerical value and the preset constant to obtain the second ciphertext of the floating-point data type, and obtain the first secret share of the floating-point data type based on the second ciphertext, thereby completing the generation of the secret share of the floating-point data type, and then sending the first secret share to the service device, and the service device obtains the completed target ciphertext based on its local second secret share and the first secret share, effectively realizing ciphertext reasoning that supports floating-point type data and improving the efficiency of ciphertext reasoning.
[0166] Based on the above embodiment, in another embodiment of the present application, a service device is provided, such as Figure 9 As shown, the service device 2 may include a second generating unit 21 and a second determining unit 22 .
[0167] The second generating unit 21 can be used to generate a first ciphertext according to the ciphertext to be processed, and send the first ciphertext to the terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data.
[0168] The second determination unit 22 can be used to respond to the first secret share sent by the terminal device and obtain the target ciphertext based on the local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines the first result based on the obtained processing result and the first numerical value, determines the second ciphertext of the floating-point type based on the first result, the first numerical value and the preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive and negative situation of the processing result.
[0169] In some embodiments of the present application, the second determination unit 22 can also be used to determine the target ciphertext based on the second reference value, the first secret share and the second secret share; wherein the second reference value represents a reference value obtained by the service device based on the comparison protocol for determining whether the sum of the first result and the second secret share is greater than the second value.
[0170] Figure 10 Schematic diagram of the composition structure of the service equipment proposed in this embodiment Figure 2 ,like Figure 10 As shown, the service device 2 proposed in the embodiment of the present application may also include a second processor 23 and a second memory 24 storing executable instructions of the second processor 23; further, the terminal device 2 may also include a second communication interface 25, and a second bus 26 for connecting the second processor 23, the second memory 24 and the second communication interface 25.
[0171] In the embodiment of the present application, the second processor 23 may be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller, and a microprocessor. It is understood that for different devices, the electronic device used to implement the functions of the first processor may also be other, and the embodiment of the present application is not specifically limited. The terminal device 2 may also include a second memory 24, which may be connected to the second processor 23. The second memory 24 is used to store executable program code, which includes computer operating instructions. The second memory 24 may include high-speed RAM memory or non-volatile memory, such as at least two disk drives.
[0172] In the embodiment of the present application, the second bus 26 is used to connect the second communication interface 25, the second processor 23, and the second memory 24, and to facilitate mutual communication between these devices.
[0173] In the embodiment of the present application, the second memory 24 is used to store instructions and data.
[0174] Furthermore, in an embodiment of the present application, the above-mentioned second processor 23 is used to generate a first ciphertext based on the ciphertext to be processed and send the first ciphertext to the terminal device; wherein the ciphertext to be processed is a ciphertext corresponding to the floating-point data; in response to the first secret share sent by the terminal device, the target ciphertext is obtained according to the local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines the first result based on the obtained processing result and the first numerical value, determines the second ciphertext of the floating-point type according to the first result, the first numerical value and the preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive and negative situation of the processing result.
[0175] In practical applications, the second memory 24 may be a volatile memory, such as a random-access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the second processor 23.
[0176] An embodiment of the present application provides a service device that can generate a first ciphertext based on a ciphertext to be processed and send the first ciphertext to a terminal device; wherein the ciphertext to be processed is a ciphertext corresponding to floating-point data; in response to a first secret share sent by the terminal device, a target ciphertext is obtained based on a local second secret share and a first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines a first result based on the obtained processing result and the first numerical value, determines a second ciphertext of a floating-point type based on the first result, the first numerical value and a preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive or negative situation of the processing result. It can be seen that the service device can send the first ciphertext of the floating-point data type to the terminal device, so that the terminal device converts the first ciphertext into integer type data, and completes subsequent nonlinear processing and obtains the first secret share of the floating-point data type based on the processing result. When the service device receives the first secret share of the floating-point data type sent by the terminal device, it can obtain the target ciphertext based on the first secret share and the local second secret share, thereby completing the ciphertext reasoning for the floating-point data type and improving the ciphertext reasoning efficiency of the floating-point data type.
[0177] Specifically, the program instructions corresponding to the method for processing floating-point data in ciphertext calculation in this embodiment may be stored on a storage medium such as an optical disk, a hard disk, or a USB flash drive. When the program instructions corresponding to the method for processing floating-point data in ciphertext calculation in the storage medium are read or executed by the first processor, the following steps are included:
[0178] Obtaining a first ciphertext sent by the service device; wherein the first ciphertext represents ciphertext generated based on floating-point data;
[0179] Determining first information of integer type according to the first ciphertext, and performing nonlinear processing on the first information to obtain a processing result;
[0180] Determining a first result based on the processing result and the first value; wherein the first result represents a result of mapping based on the positive or negative condition of the processing result;
[0181] Determine a second ciphertext of a floating-point number type according to the first result, the first value, and a preset constant;
[0182] A first secret share is determined based on the second ciphertext, and the first secret share is sent to the service device, so that the service device determines a target ciphertext according to the local second secret share and the first secret share.
[0183] When a program instruction corresponding to a method for processing floating-point data in ciphertext calculation in a storage medium is read or executed by a second processor, the method includes the following steps:
[0184] Generate a first ciphertext based on the ciphertext to be processed, and send the first ciphertext to the terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data;
[0185] In response to a first secret share sent by a terminal device, a target ciphertext is obtained based on a local second secret share and the first secret share; wherein the first secret share represents that the terminal device converts the first ciphertext into first information of an integer type, performs nonlinear processing based on the first information, and determines a first result based on the obtained processing result and the first numerical value, determines a second ciphertext of a floating-point type based on the first result, the first numerical value and a preset constant, and determines the secret share based on the second ciphertext; the first result represents the result of mapping according to the positive or negative situation of the processing result.
[0186] In addition, the functional modules in this embodiment may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated units may be implemented in the form of hardware or software functional modules.
[0187] If the integrated unit is implemented as a software functional module and not sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this embodiment, or the portion that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the method of this embodiment. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0188] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage) containing computer-usable program code.
[0189] The present application is described with reference to the implementation flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the flowchart. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0190] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which is implemented in the implementation flow diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0191] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process described in the flowchart. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0192] The above embodiments are only preferred embodiments for fully illustrating the present invention, and the protection scope of the present invention is not limited thereto. Any equivalent substitution or modification made by those skilled in the art based on the present invention is within the protection scope of the present invention.
Claims
1. A method for processing floating point data in ciphertext calculation, characterized in that: Applied to a terminal device, the method includes: Obtaining a first ciphertext sent by the service device; wherein the first ciphertext represents a ciphertext generated based on floating-point data; Determining integer information according to the product of the first ciphertext and a preset constant; performing a modulo operation on the integer information and the second value to obtain first information, and performing nonlinear processing on the first information to obtain a processing result; wherein the second value is a power of 2; Determining a first result based on the processing result and the first value; wherein the first result represents a result of mapping based on the positive or negative condition of the processing result; and the first value is half of the second value; Determine a second ciphertext of a floating-point number type according to the first result, the first value, and a preset constant; A first secret share is determined based on the second ciphertext, and the first secret share is sent to the service device, so that the service device determines a target ciphertext according to the local second secret share and the first secret share.
2. The method according to claim 1, characterized in that The determining the first secret share based on the second ciphertext includes: Verify the first result based on a comparison protocol to obtain a first reference value; wherein the first reference value is used to determine whether the sum of the first result and the second secret share is greater than a second value; determining a third ciphertext based on the first reference value, the preset constant, and the second value; The first secret share is determined according to the second ciphertext and the third ciphertext.
3. The method according to claim 2, characterized in that Determining a first result according to the processing result and the first value includes: When the processing result is a negative number, performing a value mapping process of a modulo operation on the processing result to obtain a mapping value; wherein the mapping value is equal to the result of the modulo operation of the processing result and the second value; determining a first sum value between the mapped value and the first numerical value, and performing a modulo operation on the first sum value and the second numerical value to obtain the first result; When the processing result is not a negative number, a second sum value between the processing result and the first value is determined, and a modulo operation is performed on the second sum value and the second value to obtain the first result.
4. The method according to claim 2, characterized in that The determining of a second ciphertext of a floating-point type according to the first result, the first value, and a preset constant includes: determining a first difference between the first result and the first value; determining a first ratio between the first difference and the preset constant; Encoding the first ratio to obtain first plaintext information; The first plaintext information is encrypted to obtain the second ciphertext.
5. The method according to claim 4, characterized in that The determining the third ciphertext according to the first reference value, the preset constant, and the second value includes: determining a first product of the second value and the first reference value; determining a second ratio of the first product to the preset constant; Encoding the second ratio to obtain second plaintext information; The second plaintext information is encrypted to obtain the third ciphertext.
6. A method for processing floating point data in ciphertext calculation, characterized in that: Applied to service equipment; the method comprises: Generate a first ciphertext based on the ciphertext to be processed, and send the first ciphertext to the terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data; In response to a first secret share sent by the terminal device, a target ciphertext is obtained based on a local second secret share and the first secret share; wherein the first secret share represents that the terminal device determines integer information based on the product of the first ciphertext and a preset constant, performs a modulo operation on the integer information and the second value to obtain first information, performs nonlinear processing based on the first information, and determines a first result based on the obtained processing result and the first value, determines a second ciphertext of a floating-point type based on the first result, the first value and the preset constant, and determines the secret share based on the second ciphertext; the first result represents a result of mapping based on the positive or negative condition of the processing result; the second value is a power with a base of 2, and the first value is half of the second value.
7. The method according to claim 6, characterized in that Obtaining the target ciphertext according to the local second secret share and the first secret share includes: determining the target ciphertext according to a second reference value, the first secret share, and the second secret share; The second reference value represents a reference value obtained by the service device based on a comparison protocol and used to determine whether the sum of the first result and the second secret share is greater than a second value.
8. A terminal device, characterized in that: The terminal device includes a first acquiring unit, a first determining unit, and a first generating unit; The first acquiring unit is configured to acquire a first ciphertext sent by the service device; wherein the first ciphertext represents ciphertext generated based on floating-point data; The first determining unit is configured to determine integer information based on the product of the first ciphertext and a preset constant; perform a modulo operation on the integer information and a second value to obtain first information; and perform nonlinear processing on the first information to obtain a processing result; wherein the second value is a power of 2; The first generating unit is configured to determine a first result based on the processing result and the first numerical value; determine a second ciphertext of a floating-point type based on the first result, the first numerical value, and a preset constant; determine a first secret share based on the second ciphertext, and send the first secret share to the service device, so that the service device determines a target ciphertext based on the local second secret share and the first secret share; wherein the first result represents a result of mapping based on the positive or negative condition of the processing result; and the first numerical value is half of the second numerical value.
9. A service device, characterized in that: The service device includes a second generating unit and a second determining unit; The second generating unit is configured to generate a first ciphertext based on the ciphertext to be processed, and send the first ciphertext to the terminal device; wherein the ciphertext to be processed is the ciphertext corresponding to the floating-point data; The second determination unit is configured to obtain a target ciphertext based on a local second secret share and the first secret share in response to a first secret share sent by the terminal device; wherein the first secret share represents that the terminal device determines integer information based on the product of the first ciphertext and a preset constant, performs a modulo operation on the integer information and a second value to obtain first information, performs nonlinear processing based on the first information, determines a first result based on the obtained processing result and the first value, determines a second ciphertext of a floating-point type based on the first result, the first value, and the preset constant, and determines a secret share based on the second ciphertext; the first result represents a result of mapping based on the positive or negative condition of the processing result; the second value is a power of 2, and the first value is half of the second value.
Citation Information
Patent Citations
Multi-party computing method based on fully homomorphic encryption suitable for semi-honesty model
CN115001651A
Inference and conversion method for encrypted deep neural network model
US20250080320A1