Client decryption optimization method and system for privacy protection verifiable outsourcing calculation
By introducing a combination of outsourcing decryption obfuscated circuit solution and fully homomorphic encryption, the problem of inefficient computing efficiency in the client's online decryption stage is solved, and significant reduction in computing overhead and system efficiency is achieved.
Patent Information
- Application Number
- CN202510243738.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-06-10
AI Technical Summary
In the prior art, the client has a high computing burden during the online decryption stage of privacy protection verification outsourcing computing, resulting in inefficient system.
The outsourcing decrypted obfuscation circuit scheme (ODGS) was introduced, which converts it into an adaptive and secure obfuscation circuit scheme through a series of converters, and combines the fully homomorphic encryption scheme to construct an efficient verifiable outsourcing computing protocol.
The calculation overhead is significantly reduced during the client online decryption phase, improves system efficiency, and maintains the same security. Specifically, when the security parameter value is 128, the client computing overhead is only about 0.0078 times that of the traditional solution.
Smart Images

Figure CN120128310A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of information security and cryptography, and in particular, to a client decryption optimization method and system for privacy-preserving verifiable outsourced computing. Background Art
[0002] In the field of privacy-preserving verifiable outsourced computing, ensuring the correctness of the computation result and the privacy of the input data is crucial. Traditional secure outsourced computing protocols include the garbled circuit scheme (GS) and fully homomorphic encryption (FHE) technology. However, these methods usually require a large amount of message decryption work during the client online phase, which not only increases the computational burden on the client but also reduces the efficiency of the entire system.
[0003] Regarding the privacy security of verifiable computing, the work of Gennaro et al. pointed out that the definitions of output privacy and input privacy in verifiable computing are similar, while the work of Fiore et al. further pointed out that the output privacy of verifiable computing can be directly derived from the input privacy.
[0004] The present invention aims to introduce a new cryptographic primitive - the outsourceable decryption garbled circuit scheme (ODGS), and use this primitive to construct a verifiable computing protocol that conforms to a stronger privacy definition and a UC-secure multi-client verifiable outsourced computing protocol, respectively. Compared with existing schemes, both of these two schemes have higher computational efficiency during the client online decryption phase in the corresponding scenarios. Summary of the Invention
[0005] Aiming at the deficiencies in the prior art, the purpose of the present invention is to provide a client decryption optimization method and system for privacy-preserving verifiable outsourced computing.
[0006] According to a client decryption optimization method for privacy-preserving verifiable outsourced computing provided by the present invention, it includes:
[0007] Step S1: Construct a non-adaptive secure outsourceable decryption garbled circuit scheme;
[0008] Step S2: Use the converter ODGS-to-GS to convert the non-adaptive secure outsourceable decryption garbled circuit scheme into a non-adaptive secure garbled circuit scheme;
[0009] Step S3: Use the converter rom-all-to-all1 to convert the non-adaptive secure garbled circuit scheme into an adaptive secure garbled circuit scheme;
[0010] Step S4: Use the converter GS-to-ODGS to convert the adaptively secure garbled circuit scheme into an adaptively secure outsourceable decryption garbled circuit scheme;
[0011] Step S5: Combine the adaptively secure outsourceable decryption garbled circuit scheme with the fully homomorphic encryption scheme to obtain a secure and verifiable outsourced computing scheme.
[0012] Preferably, the non-adaptively secure outsourceable decryption garbled circuit scheme includes a garbling algorithm Gb, an encoding algorithm En, a verification algorithm Ve, a computing algorithm Ev, and an auxiliary algorithm ev.
[0013] Preferably, the garbling algorithm Gb takes as input a security parameter κ and a function f to be computed, and generates a garbled circuit F, an encoding mapping e, and a verification function v; the encoding algorithm En takes as input the encoding mapping e and a preimage x, and generates a garbled output X; the computing algorithm Ev takes as input the garbled circuit F and the garbled output X, and outputs a function value y and verification information π; the verification algorithm Ve takes as input the verification function v, the function value y, and the verification information π, and outputs a verification result ψ; the auxiliary algorithm ev takes as input the function f and the preimage x, and outputs an image y.
[0014] Preferably, given an input outsourceable decryption garbled circuit scheme ODGS = (Gb, En, Ve, Ev, ev), the converter ODGS-to-GS outputs a garbling scheme GS = (Gb, En, De, Ev, ev), where:
[0015] Gb(1 κ , f): Call ODGS.Gb(1 κ , f) to obtain (F, e, v), let d ← v, and then return (F, e, d) as the result;
[0016] En(e, x): Call ODGS.En(e, x) to obtain X, and return it as the result;
[0017] Ev(F, X): Call ODGS.Ev(F, X) to obtain (y, π), and return it as Y as a whole;
[0018] De(d, Y): Parse Y into (y, π), call ODGS.Ve(d, y, π) to obtain ψ; if ψ = 0, return ⊥; otherwise return y.
[0019] Preferably, given an input a garbling scheme GS = (Gb, En, De, Ev, ev), the converter GS-to-ODGS outputs an outsourceable decryption garbled circuit scheme ODGS = (Gb, En, Ve, Ev, ev), where:
[0020] Gb(1 κ , f): Call GS.Gb(1κ , f) Obtain (F, e, d), set v ← d, and return (F, e, v) as the result;
[0021] En(e, x): Call GS.En(e, x) to obtain X and return it as the result;
[0022] Ev(F, X): Call GS.Ev(F, X) to obtain Y, and parse it as (y, π) and then return;
[0023] De(d, Y): Let Y ← (y, π), call GS.Ve(v, Y) to obtain y or ⊥; if ⊥ is obtained, set ψ = 0; otherwise set ψ = 1; finally return ψ as the function return value.
[0024] According to a client - side decryption optimization system for privacy - protected verifiable outsourced computing provided by the present invention, it includes:
[0025] Module M1: Construct a non - adaptive secure outsourcable decryption garbled circuit scheme;
[0026] Module M2: Use the converter ODGS - to - GS to convert the non - adaptive secure outsourcable decryption garbled circuit scheme into a non - adaptive secure garbled circuit scheme;
[0027] Module M3: Use the converter rom - all - to - all1 to convert the non - adaptive secure garbled circuit scheme into an adaptive secure garbled circuit scheme;
[0028] Module M4: Use the converter GS - to - ODGS to convert the adaptive secure garbled circuit scheme into an adaptive secure outsourcable decryption garbled circuit scheme;
[0029] Module M5: Combine the adaptive secure outsourcable decryption garbled circuit scheme with a fully homomorphic encryption scheme to obtain a secure verifiable outsourced computing scheme.
[0030] Preferably, the non - adaptive secure outsourcable decryption garbled circuit scheme includes a garbling algorithm Gb, an encoding algorithm En, a verification algorithm Ve, a computing algorithm Ev, and an auxiliary algorithm ev.
[0031] Preferably, the garbling algorithm Gb inputs a security parameter κ and a function f to be computed, and generates a garbled circuit F, an encoding mapping e, and a verification function v; the encoding algorithm En inputs the encoding mapping e and a pre - image x, and generates a garbled output X; the computing algorithm Ev inputs the garbled circuit F and the garbled output X, and outputs a function value y and verification information π; the verification algorithm Ve inputs the verification function v, the function value y, and the verification information π, and outputs a verification result ψ; the auxiliary algorithm ev inputs the function f and the pre - image x, and outputs an image y.
[0032] Preferably, given an outsourced decryption garbled circuit scheme ODGS = (Gb, En, Ve, Ev, ev), the converter ODGS-to-GS outputs a garbled scheme GS = (Gb, En, De, Ev, ev), where:
[0033] Gb(1 κ , f): Call ODGS.Gb(1 κ , f) to obtain (F, e, v), set d ← v, and then return (F, e, d) as the result;
[0034] En(e, x): Call ODGS.En(e, x) to obtain X, and return it as the result;
[0035] Ev(F, X): Call ODGS.Ev(F, X) to obtain (y, π), and return it as the whole Y;
[0036] De(d, Y): Parse Y into (y, π), call ODGS.Ve(d, y, π) to obtain ψ; if ψ = 0, return ⊥; otherwise return y.
[0037] Preferably, given an input of a garbled scheme GS = (Gb, En, De, Ev, ev), the converter GS-to-ODGS outputs an outsourced decryption garbled circuit scheme ODGS = (Gb, En, Ve, Ev, ev), where:
[0038] Gb(1 κ , f): Call GS.Gb(1 κ , f) to obtain (F, e, d), set v ← d, and then return (F, e, v) as the result;
[0039] En(e, x): Call GS.En(e, x) to obtain X, and return it as the result;
[0040] Ev(F, X): Call GS.Ev(F, X) to obtain Y, and then parse it into (y, π) and return;
[0041] De(d, Y): Set Y ← (y, π), call GS.Ve(v, Y) to obtain y or ⊥; if ⊥ is obtained, set ψ = 0; otherwise set ψ = 1; finally, return ψ as the function return value.
[0042] Compared with the prior art, the present invention has the following beneficial effects:
[0043] 1. The present invention constructs a non-adaptively secure outsourced decryption garbled circuit scheme through tools such as double-key encryption, then obtains a non-adaptively secure garbled circuit scheme through the newly constructed converter ODGS-to-GS, then obtains an adaptively secure garbled circuit scheme through the existing converter rom-all-to-all1, obtains an adaptively secure outsourced decryption garbled circuit scheme ODGC through the newly constructed converter GS-to-ODGS, and finally combines with a fully homomorphic encryption scheme to obtain a secure and verifiable outsourced computing scheme, achieving an improvement in the computing efficiency of the client during the online phase.
[0044] 2. The optimization scheme proposed by the present invention is based on an improved garbled circuit scheme, which can effectively reduce the computing overhead of the client during the online decryption phase of the outsourced computing protocol, and has the same security as the existing scheme. This optimization allows the server to decode the garbled result on the homomorphic ciphertext of the computing result, sharing the computing overhead of the client, thus reducing the computing amount of the client; when the security parameter of the garbled circuit scheme takes a value of 128, the computing overhead of the client is about 0.0078 times that of the existing scheme.
[0045] 3. The present invention constructs a new outsourced decryption garbled circuit scheme to replace the traditional garbled circuit scheme, solving the problem of low efficiency in the online decryption phase of the existing outsourced computing scheme, and reducing its computational complexity from O(dlκ) to O(dl + κ), where d represents the computational complexity expansion rate of the fully homomorphic encryption algorithm, l is the output scale, and κ represents the security parameter.
[0046] Other beneficial effects of the present invention will be elaborated in the specific implementation manner through the introduction of specific technical features and technical solutions. Those skilled in the art should be able to understand the beneficial technical effects brought by the said technical features and technical solutions through these introductions. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives, and advantages of the present invention will become more apparent:
[0048] Figure 1 It is a flowchart of the privacy-protected verifiable outsourced computing scheme for client decryption optimization in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0049] The present invention will be described in detail below with reference to specific embodiments. The following embodiments will help those skilled in the art to further understand the present invention, but do not limit the present invention in any form. It should be noted that those of ordinary skill in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the protection scope of the present invention.
[0050] The present invention provides an optimized solution for the decryption algorithm of privacy - protected verifiable outsourced computing on the client side. This optimized solution is based on an improved garbled circuit scheme, which can effectively reduce the computational overhead of the client in the online decryption phase of the outsourced computing protocol, and has the same security as existing solutions. This optimization allows the server to decode the garbled results on the homomorphic ciphertext of the calculation results, sharing the computational overhead of the client, thereby reducing the computational amount of the client. Specifically, when the security parameter of the garbled circuit scheme takes a value of 128, the computational overhead of the client is approximately 0.0078 times that of the existing solution.
[0051] Refer to Figure 1 As shown, it is the flowchart of the privacy - protected verifiable outsourced computing scheme optimized for client - side decryption. The green boxes in the figure represent the contributions of the improved scheme, and the black boxes represent existing tools. The arrows represent the flowchart of the scheme construction, and the line segments represent the associations between the same kind of schemes. It can be seen that starting from constructing a non - adaptively secure outsourced decryption garbled circuit scheme ODGS, a non - adaptively secure garbled circuit scheme is obtained by using the newly constructed converter ODGS - to - GS. Then, an adaptively secure garbled circuit scheme is obtained by using the existing converter rom - all - to - all1. Next, an adaptively secure outsourced decryption garbled circuit scheme ODGC is obtained by using the newly constructed converter GS - to - ODGS, and ODGC is used to replace the traditional adaptively secure garbled circuit scheme. Combining with the fully homomorphic encryption scheme, a secure verifiable outsourced computing scheme is finally obtained.
[0052] The present invention first provides a non - adaptively secure outsourced decryption garbled circuit scheme ODGS. This scheme includes five algorithms, and the algorithms run as follows:
[0053] Algorithm 1: Garbling algorithm Gb: Given the security parameter κ and the function f to be computed, generate the garbled circuit F, the encoding mapping e, and the verification function v.
[0054] 1. Parse the specific parameters corresponding to the function (n, m, q, A, B, G) ← f;
[0055] Among them, n represents the input length of the function f, m represents the output length of the function f, q represents the number of logic gates in the circuit representation of the function f, A represents the mapping from the logic gate index to the input wire index of the logic gate, B represents the mapping from the logic gate index to the output wire index of the logic gate, and G represents a mapping that maps the Cartesian product of the logic gate index and two binary inputs {0, 1} to a binary output {0, 1}.
[0056] 2. Generate the garbled tags corresponding to the input and intermediate parameters:
[0057]
[0058] where ← $ denotes a random selection from the set, t denotes a certain intermediate parameter, denotes the garbled label encoding corresponding to the circuit with index i when taking the value j, and the length is the security parameter κ.
[0059] 3. Generate the final garbled circuit
[0060]
[0061]
[0062] where g, i, j are loop variables, specifically representing the index of a certain logic gate, the value of the first input of the logic gate, and the value of the second input of the logic gate respectively. a represents the index of the first input wire of the logic gate with index g (hereinafter referred to as this logic gate), b represents the index of the second input wire of this logic gate, denotes the value of the garbled label encoding of the first input wire of this logic gate, denotes the value of the garbled label encoding of the second input wire of this logic gate, lsb(·) represents the function of extracting the least significant bit of a string, denotes the least significant bit of denotes the least significant bit of. T is an intermediate parameter, representing the concatenated string of the logic gate index g and , with a length of κ + 1. P represents a mapping that maps the Cartesian product of the logic gate index and two garbled label encoding inputs {0, 1} to a garbled label encoding output {0, 1}. denotes the double-key encryption function used, denotes two keys, T represents the parameter adjustment permutation, is the message to be encrypted. Among them, G g (i, j) represents the garbled circuit mapping G g outputs the garbled result when the input is i, j.
[0063] 4. Return (F, e, v).
[0064] Algorithm 2: Encoding algorithm En: Given the encoding mapping e and the preimage x, generate the garbled output X.
[0065] 1. Parse the decoding mapping
[0066]
[0067] 2. Parse the input
[0068] x 1 …x n ←x;
[0069] 3. Output the obfuscated input
[0070]
[0071] 4. Return X
[0072] Algorithm 3: Computation algorithm Ev: Given the obfuscated circuit F and the obfuscated input X, output the function value y and the verification information π.
[0073] 1. Parse the obfuscated circuit
[0074] (n, m, q, A, B, P) ← F;
[0075] 2. Evaluate the obfuscated circuit
[0076]
[0077] 3. Output the obfuscated output
[0078] (Y 1 , …, Y m ) ← (X n+q-m+1 , …, X n+q );
[0079] 4. Compute the verification information
[0080] π ← 0 κ ;
[0081] for i ∈ [m] do
[0082] y i ← lsb(Y i );
[0083] π ← π ⊕ Y i ;
[0084] y ← y 1 …y m ;
[0085] where m represents the output length of the function f, i is the loop variable, Y i represents the i-th obfuscated output value in the obfuscated output, y i represents the least significant bit of the string Y i , and y represents the string concatenated by y 1 to y m .
[0086] 5. Return the result (y, π)
[0087] Algorithm 4: Verification Algorithm Ve: Given a verification function v, a function value y, and a verification message π, output a verification result ψ.
[0088] 1. Parse the verification function
[0089]
[0090] 2. Verification result
[0091]
[0092] 3. Return the verification result
[0093] if π = 0 κ then
[0094] Return 1
[0095] else
[0096] Return 0
[0097] Algorithm 5: Auxiliary Algorithm ev: Given a function f and a preimage x, output an image y.
[0098] (n, m, q, A, B, G) ← f;
[0099] for g ← n + 1 to n + q do
[0100] a ← A(g), b ← B(g);
[0101] x g ← G g (x a , x b );
[0102] Return x n+q-m+1 …x n+q
[0103] where a and b represent the indices of the input wires of the first and second inputs corresponding to the function logic gate with index g, x a and x b represent the values of these two inputs respectively, and x g represents the value of the output of this logic gate.
[0104] Next, define the converter ODGS-to-GS. Given an input outsourcable decryption garbled circuit scheme ODGS = (Gb, En, Ve, Ev, ev), the converter outputs a garbled scheme GS = (Gb, En, De, Ev, ev), where:
[0105] 1. Gb(1 κ , f): Call ODGS.Gb(1 κ, f) obtain (F, e, v), set d ← v and return (F, e, d) as the result.
[0106] 2. En(e, x): Call ODGS.En(e, x) to obtain X and return it as the result.
[0107] 3. Ev(F, X): Call ODGS.Ev(F, X) to obtain (y, π) and return it as Y as a whole.
[0108] 4. De(d, Y): Parse Y into (y, π), call ODGS.Ve(d, y, π) to obtain ψ. If ψ = 0, return ⊥; otherwise return y.
[0109] Next, define the converter GS-to-ODGS. Given an input of a garbling scheme GS = (Gb, En, De, Ev, ev), the converter outputs an outsourcable decryption garbled circuit scheme ODGS = (Gb, En, Ve, Ev, ev), where:
[0110] 1. Gb(1 κ , f): Call GS.Gb(1 κ , f) to obtain (F, e, d), set v ← d and return (F, e, v) as the result.
[0111] 2. En(e, x): Call GS.En(e, x) to obtain X and return it as the result.
[0112] 3. Ev(F, X): Call GS.Ev(F, X) to obtain Y, parse it into (y, π) and then return.
[0113] 4. De(d, Y): Set Y ← (y, π), call GS.Ve(v, Y) to obtain y or ⊥. If ⊥ is obtained, set ψ = 0; otherwise set ψ = 1. Finally, return ψ as the function return value.
[0114] Combining the outsourcable decryption garbled circuit scheme ODGS with non-adaptive security, the converter ODGS-to-GS, the converter rom-all-to-all1, and the converter GS-to-ODGS, an adaptively secure outsourcable decryption garbled circuit scheme can be obtained, constructed as GS-to-ODGS[rom-all-to-all1[ODGS-to-GS[ODGS]]]. Denote this construction as ODGC.
[0115] Finally, based on ODGC, an efficient verifiable outsourced computing protocol is given. Compared with the traditional verifiable outsourced computing protocol, this protocol uses ODGC to replace the traditional garbled circuit algorithm. The specific construction is as follows:
[0116] Algorithm 1: Offline Phase KeyGen(f, κ): Given a function f and a security parameter κ, output a public key PK and a private key SK. 1. Generate a garbled circuit using the ODGC protocol
[0117] (F, e, v) ← ODGC(1 κ , f);
[0118] 2. Return the public and private keys
[0119] PK ← F;
[0120] SK ← (e, v);
[0121] 3. Return (PK, SK)
[0122] Algorithm 2: Online Encryption Phase ProbGen(SK, x): Given a private key SK and an input x, output a ciphertext input σ x and a decryption information τ x .
[0123] 1. Parse the private key
[0124] (e, v) ← SK;
[0125] 2. Compute the garbled input
[0126] X ← ODGC.En(e, x);
[0127] 3. Obtain a fully homomorphic public and private key pair
[0128] (pk FHE , sk FHE ) ← FHE.KeyGen(1 κ );
[0129] 4. Compute the ciphertext input σ x and the decryption information τ x
[0130] σ x ← FHE.Enc(pk FHE , x);
[0131] τ x ← sk FHE ;
[0132] 5. Return (σ x , τ x )
[0133] Algorithm 3: Online Computation Phase Compute(PK, σ x ): Given a public key PK and a ciphertext input σ x , output a ciphertext output σ y .
[0134] 1. Parse the public key
[0135] F ← PK;
[0136] 2. Calculate the ciphertext output
[0137]
[0138] 3. Return σ y
[0139] Algorithm 4: Online decryption phase Verify(SK, τ x , σ y ): Input the private key SK, decryption information τ x and the ciphertext output σ y , and output the plaintext result y or the termination symbol ⊥.
[0140] 1. Parse the input private key SK
[0141] (e, v) ← SK;
[0142] 2. Parse the decryption information τ x
[0143] sk FHE ← τ x ;
[0144] 3. Parse the ciphertext output σ y
[0145]
[0146] 4. Fully homomorphic decryption
[0147]
[0148] 5. Verify the result
[0149] ψ ← ODGC.Ve(v, y, π);
[0150] 6. If ψ = 0, return y; otherwise, return ⊥.
[0151] The present invention constructs a new outsourced decryption garbled circuit scheme to replace the traditional garbled circuit scheme, solves the problem of low efficiency in the online decryption phase of the client in the existing outsourced computing scheme, and reduces its computational complexity from O(dlκ) to O(dl + κ).
[0152] The present invention also provides a client decryption optimization system for privacy-preserving verifiable outsourced computing. The client decryption optimization system for privacy-preserving verifiable outsourced computing can be implemented by executing the process steps of the client decryption optimization method for privacy-preserving verifiable outsourced computing. That is, those skilled in the art can understand the client decryption optimization method for privacy-preserving verifiable outsourced computing as a preferred implementation manner of the client decryption optimization system for privacy-preserving verifiable outsourced computing.
[0153] Specifically, a client decryption optimization system for privacy-preserving verifiable outsourced computing includes:
[0154] Module M1: Construct a non-adaptive secure outsourced decryption garbled circuit scheme;
[0155] Module M2: Use the converter ODGS-to-GS to convert the non-adaptive secure outsourced decryption garbled circuit scheme into a non-adaptive secure garbled circuit scheme;
[0156] Module M3: Use the converter rom-all-to-all1 to convert the non-adaptive secure garbled circuit scheme into an adaptive secure garbled circuit scheme;
[0157] Module M4: Use the converter GS-to-ODGS to convert the adaptive secure garbled circuit scheme into an adaptive secure outsourced decryption garbled circuit scheme;
[0158] Module M5: Combine the adaptive secure outsourced decryption garbled circuit scheme with a fully homomorphic encryption scheme to obtain a secure verifiable outsourced computing scheme.
[0159] The non-adaptive secure outsourced decryption garbled circuit scheme includes a garbling algorithm Gb, an encoding algorithm En, a verification algorithm Ve, a computing algorithm Ev, and an auxiliary algorithm ev.
[0160] The garbling algorithm Gb takes as input a security parameter κ and a function f to be computed, and generates a garbled circuit F, an encoding mapping e, and a verification function v; the encoding algorithm En takes as input the encoding mapping e and a preimage x, and generates a garbled output X; the computing algorithm Ev takes as input the garbled circuit F and the garbled output X, and outputs a function value y and verification information π; the verification algorithm Ve takes as input the verification function v, the function value y, and the verification information π, and outputs a verification result ψ; the auxiliary algorithm ev takes as input the function f and the preimage x, and outputs an image y.
[0161] Given an input outsourced decryption garbled circuit scheme ODGS = (Gb, En, Ve, Ev, ev), the converter ODGS-to-GS outputs a garbling scheme GS = (Gb, En, De, Ev, ev), where:
[0162] Gb(1 κ, f): Call ODGS.Gb(1 κ , f) to obtain (F, e, v), set d ← v, and then return (F, e, d) as the result;
[0163] En(e, x): Call ODGS.En(e, x) to obtain X and return it as the result;
[0164] Ev(F, X): Call ODGS.Ev(F, X) to obtain (y, π) and return it as Y as a whole;
[0165] De(d, Y): Parse Y into (y, π), call ODGS.Ve(d, y, π) to obtain ψ; if ψ = 0, return ⊥; otherwise return y.
[0166] Given an input of a garbling scheme GS = (Gb, En, De, Ev, ev), the converter GS-to-ODGS outputs an outsourcable decryption garbled circuit scheme ODGS = (Gb, En, Ve, Ev, ev), where:
[0167] Gb(1 κ , f): Call GS.Gb(1 κ , f) to obtain (F, e, d), set v ← d, and then return (F, e, v) as the result;
[0168] En(e, x): Call GS.En(e, x) to obtain X and return it as the result;
[0169] Ev(F, X): Call GS.Ev(F, X) to obtain Y, parse it into (y, π), and then return;
[0170] De(d, Y): Set Y ← (y, π), call GS.Ve(v, Y) to obtain y or ⊥; if ⊥ is obtained, set ψ = 0; otherwise set ψ = 1; finally, return ψ as the function return value.
[0171] Those skilled in the art know that in addition to implementing the system and its various devices, modules, and units provided by the present invention in the form of pure computer-readable program code, the method steps can be logically programmed to enable the system and its various devices, modules, and units provided by the present invention to be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers, etc. to achieve the same functions. Therefore, the system and its various devices, modules, and units provided by the present invention can be considered as a kind of hardware component, and the devices, modules, and units included therein for implementing various functions can also be regarded as the structures within the hardware component; the devices, modules, and units for implementing various functions can also be regarded as both software modules for implementing the method and the structures within the hardware component.
[0172] The specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the above specific embodiments, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other arbitrarily.
Claims
1. A client-side decryption optimization method for privacy-preserving verifiable outsourced computing, characterized in that: include: Step S1: construct a non-adaptive secure outsourced decryption obfuscation circuit scheme; Step S2: using a converter ODGS-to-GS to convert the non-adaptive secure outsourced decryption obfuscation circuit scheme into a non-adaptive secure obfuscation circuit scheme; Step S3: using a converter rom-all-to-all1 to convert the non-adaptive security obfuscation circuit scheme into an adaptive security obfuscation circuit scheme; Step S4: using a converter GS-to-ODGS to convert the adaptive security obfuscation circuit scheme into an adaptive security outsourced decryption obfuscation circuit scheme; Step S5: Combine the adaptive secure outsourced decryption obfuscation circuit scheme with the fully homomorphic encryption scheme to obtain a secure and verifiable outsourced computing scheme.
2. The client-side decryption optimization method for privacy-preserving verifiable outsourced computing according to claim 1, characterized in that: The non-adaptive secure outsourced decryption obfuscation circuit solution includes an obfuscation algorithm Gb, an encoding algorithm En, a verification algorithm Ve, a calculation algorithm Ev and an auxiliary algorithm ev.
3. The client-side decryption optimization method for privacy-preserving verifiable outsourced computing according to claim 2 is characterized in that: The obfuscation algorithm Gb inputs the security parameter κ and the function to be calculated f, generates the obfuscation circuit F, the encoding map e and the verification function v; the encoding algorithm En inputs the encoding map e and the original image x, generates the obfuscation output X; the calculation algorithm Ev inputs the obfuscation circuit F and the obfuscation output X, outputs the function value y and the verification information π; the verification algorithm Ve inputs the verification function v, the function value y and the verification information π, and outputs the verification result ψ; the auxiliary algorithm ev inputs the function f and the original image x, and outputs the image y.
4. The client-side decryption optimization method for privacy-preserving verifiable outsourced computing according to claim 2, characterized in that: Given an input outsourced decryption obfuscation scheme ODGS = (Gb, En, Ve, Ev, ev), the converter ODGS-to-GS outputs an obfuscation scheme GS = (Gb, En, De, Ev, ev), where: Gb(1 κ ,f): Call ODGS.Gb(1 κ ,f) get (F,e,v), set d←v and return (F,e,d) as the result; En(e,x): Calls ODGS.En(e,x) to get X and returns it as the result; Ev(F,X): Call ODGS.Ev(F,X) to get (y,π) and return it as Y as a whole; De(d,Y): Parse Y as (y,π), call ODGS.Ve(d,y,π) to get ψ; if ψ=0, return ⊥; otherwise return y.
5. The client-side decryption optimization method for privacy-preserving verifiable outsourced computing according to claim 2, characterized in that: Given an input obfuscation scheme GS = (Gb, En, De, Ev, ev), the converter GS-to-ODGS outputs an outsourced decryption obfuscation circuit scheme ODGS = (Gb, En, Ve, Ev, ev), where: Gb(1 κ ,f): call GS.Gb(1 κ ,f) get (F,e,d), set v←d and return (F,e,v) as the result; En(e,x): Call GS.En(e,x) to get X and return it as the result; Ev(F,X): Call GS.Ev(F,X) to get Y, parse it into (y,π) and return it; De(d,Y): Let Y←(y,π), call GS.Ve(v,Y) to get y or ⊥; if ⊥ is obtained, set ψ=0; otherwise set ψ=1; finally, use ψ as the function return value.
6. A client-side decryption optimization system for privacy-preserving verifiable outsourced computing, characterized in that: include: Module M1: Construct a non-adaptive secure outsourced decryption obfuscation circuit scheme; Module M2: Convert the non-adaptive secure outsourceable decryption obfuscated circuit scheme into a non-adaptive secure obfuscated circuit scheme using the converter ODGS-to-GS; Module M3: Convert the non-adaptive security obfuscation circuit scheme into an adaptive security obfuscation circuit scheme using a converter rom-all-to-all1; Module M4: Convert the adaptive secure obfuscated circuit scheme into an adaptive secure outsourced decryption obfuscated circuit scheme using the converter GS-to-ODGS; Module M5: Combine the adaptive secure outsourced decryption obfuscation circuit scheme with the fully homomorphic encryption scheme to obtain a secure and verifiable outsourced computing scheme.
7. The client-side decryption optimization system for privacy-preserving verifiable outsourced computing according to claim 6, characterized in that: The non-adaptive secure outsourced decryption obfuscation circuit solution includes an obfuscation algorithm Gb, an encoding algorithm En, a verification algorithm Ve, a calculation algorithm Ev and an auxiliary algorithm ev.
8. The client-side decryption optimization system for privacy-preserving verifiable outsourced computing according to claim 7, characterized in that: The obfuscation algorithm Gb inputs the security parameter κ and the function to be calculated f, generates the obfuscation circuit F, the encoding map e and the verification function v; the encoding algorithm En inputs the encoding map e and the original image x, generates the obfuscation output X; the calculation algorithm Ev inputs the obfuscation circuit F and the obfuscation output X, outputs the function value y and the verification information π; the verification algorithm Ve inputs the verification function v, the function value y and the verification information π, and outputs the verification result ψ; the auxiliary algorithm ev inputs the function f and the original image x, and outputs the image y.
9. The client-side decryption optimization system for privacy-preserving verifiable outsourced computing according to claim 7, characterized in that: Given an input outsourced decryption obfuscation scheme ODGS = (Gb, En, Ve, Ev, ev), the converter ODGS-to-GS outputs an obfuscation scheme GS = (Gb, En, De, Ev, ev), where: Gb(1 κ ,f): Call ODGS.Gb(1 κ ,f) get (F,e,v), set d←v and return (F,e,d) as the result; En(e,x): Calls ODGS.En(e,x) to get X and returns it as the result; Ev(F,X): Call ODGS.Ev(F,X) to get (y,π) and return it as Y as a whole; De(d,Y): Parse Y as (y,π), call ODGS.Ve(d,y,π) to get ψ; if ψ=0, return ⊥; otherwise return y.
10. The client-side decryption optimization system for privacy-preserving verifiable outsourced computing according to claim 7, characterized in that: Given an input obfuscation scheme GS = (Gb, En, De, Ev, ev), the converter GS-to-ODGS outputs an outsourced decryption obfuscation circuit scheme ODGS = (Gb, En, Ve, Ev, ev), where: Gb(1 κ ,f): Call GS.Gb(1 κ ,f) get (F,e,d), set v←d and return (F,e,v) as the result; En(e,x): Call GS.En(e,x) to get X and return it as the result; Ev(F,X): Call GS.Ev(F,X) to get Y, parse it into (y,π) and return it; De(d,Y): Let Y←(y,π), call GS.Ve(v,Y) to get y or ⊥; if ⊥ is obtained, set ψ=0; otherwise set ψ=1; finally, use ψ as the function return value.
Citation Information
Patent Citations
Homomorphic OU password-based outsourcing classifier encryption and decryption method
CN108833077A
Efficient and safe two-party computing system and computing method based on cooperation
CN113591146A
Ciphertext data outsourcing decryption system and method based on homomorphic encryption
CN115225250A