Secret calculation method for range and extreme value sum of distributed data set, storage medium and equipment

By using the NTRU encryption scheme and segmentation-selecting method in a distributed data set, both parties calculate the extreme difference and extreme value sum without leaking private data, solving the problem of leaking intermediate results in the calculation method in the prior art, and achieving high security and privacy protection calculation effect.

CN120128316AInactive Publication Date: 2025-06-10天津仁爱学院
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510254628.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-06-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing calculation methods of calculating extreme differences and extreme values ​​have the problem of leaking intermediate results.

Method used

Using the confidential calculation method of distributed data sets, through the NTRU encryption scheme and the segmentation-select method, both parties calculate the sum of extreme differences and extreme values ​​without leaking private data.

Benefits of technology

It realizes the calculation of extreme differences and extreme values ​​without leaking intermediate results, has high security and privacy protection capabilities, and is suitable for various application scenarios, especially in malicious models.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128316A_ABST
    Figure CN120128316A_ABST
Patent Text Reader

Abstract

The invention discloses a secrecy calculation method of a range and extreme value sum of a distributed data set, a storage medium and equipment, and belongs to the technical field of secrecy calculation of the range and extreme value sum. In order to solve the problem that an intermediate result is leaked in a current calculation mode of calculating range and extreme value sum, the method comprises the following steps of: coding by using a maximum value and a minimum value of a private set and a complete set in which the private sets of two confidential calculation parties are located, performing NTRU encryption, and sending the encrypted data to the opposite party; one or both parties select the vector of the bit sequence corresponding to the sending data of the opposite party to perform encryption calculation based on the bit sequence of the maximum value and the minimum value of the own private set in the complete set, the corresponding random permutation result is sent to the opposite party based on the encryption calculation result of the coding characteristic, and the opposite party performs the bit addition calculation and returns the bit addition calculation; and one or two parties receiving the returned result perform decryption based on the NTRU encryption mode, so that the confidential calculation of the range and extreme value sum of the distributed data set under the semi-honest model or the malicious model is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for securely calculating the sum of range and extreme values, as well as a corresponding storage medium and device. Background Art

[0002] Secure Multiparty Computation (MPC) is an effective means of protecting privacy. It can perform calculations without revealing any information, thereby protecting the privacy of users. The earliest MPC problems originated in the 1980s and aimed to solve how multiple participants can securely calculate a certain function and protect their respective privacies without the participation of a trusted third party. Subsequently, Goldreich proposed a security model based on passive attackers and a limited communication model, that is, to achieve secure multiparty computation in an environment where a passive attacker exists and the communication volume between participants is restricted. With the development of computer technology and cryptography, MPC has been widely applied and studied, including problems such as securely calculating the sum of range and extreme values, securely data mining problems, and securely scientific computing problems, effectively solving many practical problems.

[0003] In the field of financial data processing, the range and the sum of extreme values play a crucial role. They are widely used in multiple aspects such as risk assessment, tender evaluation, fraud detection, trading prediction, and portfolio optimization. For investors, disclosing their trading strategies, especially those involving the calculation of price fluctuation ranges, may bring unnecessary risks. Therefore, secure computing technology has become an important tool for calculating the range and the sum of extreme values in a data set to ensure the security and privacy of the evaluation process. Investors may not want to disclose their trading strategies, especially those involving the calculation of price fluctuation ranges, so it is necessary to securely calculate the range and the sum of extreme values in the data set for evaluation. The range represents the difference value between the maximum and minimum values in a set of data. Suppose we want to evaluate the risk of a stock market. Then, by collecting historical stock price data and calculating the range between the daily closing price and the historical average price. Suppose the daily closing price of a stock is a 1 ,…,a q , which can be represented as the set A = {a 1 ,…,a q}, and the average price for the past month is b 1 ,…,b w , which can be represented as the set B = {b 1 ,…,b w}. In the stock market, calculating the range of these two sets can be used to describe the fluctuation range of stock prices and reflect the risk level of the market. That is, the larger the range, the greater the risk. By understanding the volatility of the data range, it helps to evaluate the risk of investment portfolios. The extreme value sum represents the sum of the maximum and minimum values in a set of data. Investors can discover abnormal situations in market price fluctuations by observing the extreme value sum of stock prices, thereby better grasping the bottom and top of the market. Similarly, calculate the extreme value sum between the closing price of each day and the average price of the past month. Then, a relatively reasonable threshold can be calculated based on historical data, such as 3 times the standard deviation or 2 times the standard deviation, etc. If the extreme value sum of a certain stock's price on a certain day exceeds the defined abnormal threshold and drops by 5% or rises by more than 10% in a short period of time, then these data points can be marked as outliers.

[0004] The application of secure computing technology in financial data processing also deserves attention. Take the bidding for a smart city project as an example. Companies from multiple industries participate in the bidding and each has its own private data. These data are crucial for evaluating the feasibility and cost-effectiveness of the bidding proposals. However, to ensure the fairness and transparency of the bidding while protecting the data privacy of each company, secure computing technology has emerged. Through secure computing, the tenderer and bidders can jointly calculate important indicators such as the range and extreme value sum of the data without revealing their respective data. This technology not only effectively protects the data privacy of all parties but also promotes fair competition and cooperation, making the project bidding process more efficient and reliable.

[0005] In summary, the range and extreme value sum play a crucial role in financial data processing. The introduction of secure computing technology further enhances the security and efficiency of data processing, providing strong support for risk management, bidding evaluation, fraud detection, trading prediction, and portfolio optimization in the financial field. The wide application of this technology not only helps investors make more informed decisions but also promotes the sustainable and healthy development of the financial industry. Although there is currently no secure computing research on the extreme value sum and range problems, solutions such as "Private substitution and its applications in private scientific computation" and "Private maximum and minimum computation" can only obtain the plaintext of the maximum and minimum values. If used to calculate the range and extreme value sum, the intermediate results will be leaked. While the solution in "Secure multi-party computation for minimum and its applications" can obtain the ciphertext of the maximum and minimum values, but it needs to be decrypted to calculate the ciphertext of the range and extreme value sum. Summary of the Invention

[0006] The present invention aims to solve the problem that the existing calculation methods of range, extreme value and sum disclose intermediate results.

[0007] A secure calculation method for the range and sum of extreme values of a distributed dataset. Denote the two parties that need to perform secure calculation as Alice and Bob. Alice has a private set A = {a 1 , …, a q}, and the maximum and minimum values are a max and a min ; Bob has a private set B = {b 1 , …, b w}, and the maximum and minimum values are b max and b min ; where u 1 < u 2 < … < u m and the cardinality of the universal set |U| = m. The two parties perform secure calculation without disclosing their respective private data, including the following steps:

[0008] Alice and Bob run the NTRU encryption scheme to generate public key / private key pairs, namely pk 1 / sk 1 , and pk 2 / sk 2 , and respectively publish the public keys pk 1 = h 1 and pk 2 = h 2 ;

[0009] Alice initializes the row vectors x' = {x max ', …, x' min} and x” = {x 1 ”, …, x” m} according to a 1 and a m where: Then, the vectors x' and x” are encrypted by NTRU to obtain C' and C”, and sent to Bob; Bob initializes the row vectors y' = {y max ', …, y' min} and y” = {y 1 ”, …, y” m} in the same way according to b 1 and b m , and then encrypt the vectors y' and y” by NTRU to obtain H' and H”, and send them to Alice;

[0010] Alice determines the ordinal index of a max in the universal set U1 , select the index in vector H' 1 Dimensional vector And record it as calculate According to a min The index of the position in the universal set U 2 , select the index in vector H" 2 Dimensional vector And record it as calculate Then Random permutation Will Random permutation and will After random permutation, they are sent to Bob; where E(·) represents NTRU encryption;

[0011] Bob based on b max The index of the position in the universal set U 3 , select the index in vector C' 3 Dimensional vector And record it as calculate According to b min The index of the position in the universal set U 4 , select the index in vector C" 4 Dimensional vector And record it as calculate Then Random permutation Will Random permutation and will After random replacement, they are sent to Alice;

[0012] Alice Calculation Then (D 1 ,D 1 ') and (D 2 ,D 2 ') is sent to Bob; Bob calculates Then (D 3 ,D 3 ') and (D 4 ,D' 4 ) is sent to Alice;

[0013] Alice Calculation And calculate G 1 =X max +(-X min ), G2 = X max + X min Denote them as g 1 、g 3 ; Bob calculates and calculates G 1 = X max + (-X min )、G 2 = X max + X min Denote them as g 2 、g 4 ;

[0014] For g 1 and g 2 , Alice and Bob respectively select m random polynomials r ai 、r bi , i = 1, …, m, and respectively calculate and announce Alice selects m / 2 groups arbitrarily from the m groups and requests Bob to announce the corresponding r bi + (g 2 / 2h 2 ), then uses Bob's public key h 2 to verify If the verification fails, stop; otherwise, continue; at the same time, Bob selects m / 2 groups arbitrarily from the m groups and requests Alice to announce the corresponding r ai + (g 1 / 2h 1 ), then uses Alice's public key h 1 to verify If the verification fails, stop; otherwise, continue; Alice and Bob respectively randomly select one and from the remaining and Then Alice uses Bob's public key h 2 to calculate c 1 ' a = (r a ' 1 * h 2 ) + (g 1 / 2)(mod q), calculate Denote it as A; Bob uses Alice's public key h 1 to calculate c 1 ' b = (r b ' 1*h 1 )+(g 2 / 2)(modq), calculate Recorded as B; finally, the two parties exchange A and B;

[0015] For g 3 and g 4 , using the same 1 , g 2 With the same process, Alice and Bob obtain B' and A' respectively;

[0016] Alice uses the private key sk 1 Decrypt B to get the extreme difference, decrypt B' to get the extreme sum, and / or, Bob uses the private key sk 2 Decrypting A gives the extreme value, and decrypting A' gives the extreme value sum.

[0017] A computer storage medium stores a computer program, which is loaded and executed by a processor to implement a confidential calculation method for the extreme difference and extreme value sum of a distributed data set.

[0018] A confidential computing device for the range and sum of extreme values ​​of a distributed data set, the device comprising a processor and a memory, the memory storing a computer program, the computer program being loaded and executed by the processor to implement the confidential computing method for the range and sum of extreme values ​​of a distributed data set.

[0019] The present invention proposes a new encoding method, combines it with an efficient NTRU encryption scheme, analyzes possible malicious behaviors, and uses cryptographic tools such as the split-selection method to design a confidential calculation method for the extreme difference and extreme value sum of distributed data sets under a malicious model. The security of the protocol is proved by an ideal-actual example, which not only solves the problem of leaking intermediate results in the current calculation method of the extreme difference and extreme value sum, but also has very high security.

[0020] A method for calculating the range and sum of extreme values ​​of a distributed data set in a confidential manner. The two parties who need to perform confidential calculations are denoted as Alice and Bob. Alice has a private set A = {a 1 ,…,a q}, the maximum and minimum values ​​are a max and a min ; Bob has a private set B = {b 1 ,…,b w}, the maximum and minimum values ​​are b max and b min ; where u 1 <u 2 <…<u mAnd the cardinality of the universal set |U| = m; The two parties perform secure computations without revealing their respective private data, including the following steps:

[0021] Alice runs the NTRU cryptosystem to generate a public key / private key pair, i.e., pk / sk, and publishes the public key pk = h;

[0022] Alice initializes the row vectors x' = {x max ', …, x' min} and x” = {x 1 ”, …, x” m} according to a 1 and a m where: Then, encrypt the vectors x' and x” using NTRU to obtain C' and C”, and send them to Bob;

[0023] Bob selects the vector max at the 1 index 1 in the universal set U according to b and denote it as Calculate Bob selects the vector min at the 2 index 2 in the universal set U according to b and denote it as Calculate Then, randomly permute it to obtain Randomly permute to obtain And send after random permutation to Alice respectively;

[0024] Alice calculates Then, send (D 1 , D 1 ') and (D 2 , D 2 ') to Bob;

[0025] Bob calculates and G 1 = X max + (-X min ), G 2 = X max + X min ; Then, send G 1 , G 2 to Alice;

[0026] Alice performs an operation on G1 , G 2 Decryption obtains the range, extreme value sum.

[0027] A computer storage medium stores a computer program, which is loaded and executed by a processor to implement the above-mentioned secure computing method for the range and extreme value sum of a distributed data set.

[0028] A secure computing device for the range and extreme value sum of a distributed data set, the device includes a processor and a memory, the memory stores a computer program, and the computer program is loaded and executed by the processor to implement the above-mentioned secure computing method for the range and extreme value sum of a distributed data set.

[0029] The present invention first proposes a new coding method, and combines it with an efficient NTRU encryption scheme to design a secure computing method for the range and extreme value sum of a distributed data set under a semi-honest model, which solves the problem of leaking intermediate results in the current calculation methods for the range, extreme value sum.

[0030] In short, the present invention is not only applicable to the case of a small data set range, but also can solve the secure calculation of the range, extreme value sum on a distributed sparse set in the case of a large data range, with a wide application range and no leakage of intermediate results; especially the secure computing protocol for the range and extreme value sum of a distributed data set under a malicious model can resist the attacks of malicious adversaries. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 It is a flowchart of the secure calculation of the range and extreme value sum of a distributed data set under a semi-honest model. DETAILED DESCRIPTION OF THE INVENTION

[0032] Aiming at the problems in the background technology, the solution designed by the present invention can securely calculate the range, extreme value sum without leaking any intermediate results, has higher security and privacy protection capabilities, can better protect the sensitive data and calculation results of users, and can be applicable to various different application scenarios. Before specifically describing the specific implementation manners, the cryptographic knowledge required by the present invention is first described.

[0033] NTRU Encryption Scheme:

[0034] The NTRU encryption algorithm is a lattice-based public key encryption system. Compared with other encryption algorithms, it has the advantages of high security, fast speed, small storage space occupation, and resistance to quantum attacks. The specific protocol is as follows.

[0035] Key Generation: First, in the polynomial ring R = Z[X] / (X N-1), two polynomials f and g are randomly selected, and the polynomials satisfy: the degree is N - 1, the coefficients p and q are integers, N is a prime number, gcd(p, q) = 1, gcd(p, q) = 1 and q >> p. The polynomial f has inverses modulo p and modulo q, which are F p and F q , that is, F p * f = 1 mod p, F q * f = 1 mod q. Calculate pk = h = p·F q * g (mod q) to obtain the public key, and calculate sk = (f, F p ) to obtain the private key.

[0036] Encryption: Randomly select a polynomial r, and at the same time represent the plaintext information to be encrypted as a polynomial M (the degree of the polynomial is N - 1 and the coefficients are integers), and then calculate C = E(M) = r * h + M (mod q).

[0037] Decryption: Calculate d = f * C (mod q), where the coefficients of d belong to the set Then calculate M = D(C) = F p * d (mod p), and the plaintext m can be obtained according to the plaintext encoding rule.

[0038] Additive homomorphicity:

[0039]

[0040] Cut-and-choose method:

[0041] The cut-and-choose method is a commonly used strategy in cryptography. One party (usually called the sender) generates or constructs a large amount of data, and the other party (usually called the receiver) randomly selects half of the data and asks the other party to provide a commitment value for verification. If the verification is correct, further confidential calculations will be performed on the other half of the data. The main purpose of this method is to improve the data transmission and processing speed while ensuring data security, and it has the following advantages:

[0042] (1) Improve security and computational efficiency: The receiver adopts a strategy of only verifying half of the data to detect whether the data has been tampered with, thereby improving the security of the data. The effectiveness of this method lies in that any tampering with the data will be discovered during the verification process, thus preventing data leakage or damage. Moreover, since only half of the data is verified, even if the data is stolen during the verification process, not all of the data will be exposed. This strategy not only improves the security of the data but also improves the processing speed while maintaining security, showing extremely high efficiency and flexibility.

[0043] (2) Flexibility: The amount of data generated and verified can be adjusted according to specific security requirements, making the method more suitable for different scenarios and needs. This flexibility enables the method to play its advantages in different environments and conditions.

[0044] Security definition under the malicious model:

[0045] The malicious model is an MPC security computing model that is closer to reality. In the malicious model, participants may take malicious actions for their own interests or other reasons in an attempt to undermine the security of the system. Therefore, protocols that are secure under the malicious model are usually more practical and universal. The security proof of the malicious model is generally proved through the ideal-practical paradigm, as follows:

[0046] Ideal protocol: Alice has x, Bob has y, and both parties want to jointly calculate the function f(x, y) = (f 1 (x,y),f 2 (x,y)), and after the agreement is completed, both parties will obtain f 1 (x,y) and f 2 (x,y).

[0047] (1) The honest party will send its real data to the TTP, while the malicious party will choose false data x', y' or refuse to execute the protocol.

[0048] (2) TTP calculation f(x,y) = (f 1 (x,y),f 2 (x,y)), it will send f to Alice 1 (x,y), otherwise, send the symbol ⊥ to Alice.

[0049] (3) If Alice behaves maliciously, then she will receive message f 1 (x,y), may refuse to execute the protocol, in which case Bob will receive ⊥. Otherwise, Bob will receive f 2 (x,y).

[0050] The security of an ideal protocol means that both parties can only obtain their own results in the protocol and cannot obtain other information. Under a malicious model, if the result of the executed protocol is the same as the result obtained under the ideal model, it can be proved that the protocol under the malicious model is secure. However, it should be noted that at least one party should be honest when executing the protocol under the malicious model, otherwise the security and feasibility of the protocol cannot be guaranteed.

[0051] Definition 1: If there are acceptable strategy pairs under the ideal protocol and the actual protocol respectively and such that then the protocol is secure. Among them, It shows that in the ideal case, with the help of the auxiliary input information z, the process of calculating the function F(x, y) through the strategy B.

[0052] Specific implementation method 1: Combining Figure 1 to illustrate this implementation method,

[0053] This implementation method is a secure calculation method for the range and sum of extreme values of a distributed dataset, which is a secure calculation method for the range and sum of extreme values of a distributed dataset under the semi-honest model. Denote the two parties that need to perform secure calculations as Alice and Bob. Alice has the private set A = {a 1 , …, a q}, and Bob has the private set B = {b 1 , …, b w}, where u 1 < u 2 < … < u m and the cardinality of the universal set |U| = m. The two parties hope to calculate the range g 1 (A ∪ B) = max(A ∪ B) - min(A ∪ B) and the sum of extreme values g 2 (A ∪ B) = max(A ∪ B) + min(A ∪ B) without revealing their respective private data, denoted as g 1 and g 2 respectively.

[0054] Coding method: Assume a max = max(A), a min = min(A), b max = max(B), b min = min(B), x max = max(A ∪ B), x min = min(A ∪ B). The specific content is as follows:

[0055] (1) Alice initializes the encoding as row vectors x′ = {x max ′, …, x′ min} and x″ = {x 1 ″, …, x′ m} according to a 1 and a m ′, where and sends the vectors x′ and x″ to Bob.

[0056] (2) Bob, according to his own data b max and b minPerform the following operations:

[0057] (2.1) According to the rank (position) index of b max in the universal set U 1 (1 ≤ index 1 ≤ m), select the index-th 1 dimensional component in the vector x' and denote it as Calculate

[0058] (2.2) According to the rank (position) index of b min in the universal set U 2 (1 ≤ index 2 ≤ m), select the index-th 2 dimensional component in the vector x″ and denote it as Calculate

[0059] (2.3) Randomly permute (shuffle the order) to get Randomly permute (shuffle the order) to get Randomly permute (shuffle the order) to get and send and to Alice.

[0060] (3) Alice calculates d 1 = α · a max , and d 2 = β · a min , Then send (d 1 , d 1 '), (d 2 , d 2 ') to Bob.

[0061] (4) Bob calculates x max = α · a max + (1 - α) · b max = d 1 + (1 - α) · b max , x min = (1 - β) · a min + β · b min = d 2 '+ β · b min .

[0062] Obviously, the range of the distributed set A ∪ B is:

[0063] g 1(A ∪ B) = max(A ∪ B) - min(A ∪ B) = max(a max , b max ) - min(a min , b min ) = x max - x min 。

[0064] From the encoding method, it can be known that:

[0065] When α = 1, at this time x max = α·a max + (1 - α)·b max = a max ; when α = 0, at this time x max = α·a max + (1 - α)·b max = b max ; in either case, x max must be max(A ∪ B).

[0066] When β = 1, at this time x min = (1 - β)·a min + β·b min = b min ; when β = 0, at this time x min = (1 - β)·a min + β·b min = a min ; in either case, x min must be x min = min(A ∪ B).

[0067] According to x max = α·a max + (1 - α)·b max = d 1 + (1 - α)·b max , x min = (1 - β)·a min + β·b min = d 2 ' + β·b min , there is: x max - x min = α·a max + (1 - α)·b max - ((1 - β)·a min + β·b min ) = (d 1 + (1 - α)·b max ) - (d 2 ' + β·b min ), that is, g 1 is obtained.

[0068] The principle is as above. The extreme value sum of the distributed set A ∪ B is:

[0069] g 2 (A ∪ B) = x max +x min =(α·a max +(1 - α)·b max )+((1 - β)·a min +β·b min ).

[0070] The specific calculation process is shown in Table 1.

[0071] Table 1

[0072]

[0073]

[0074]

[0075] For example: The universal set U = (10, 50, 70, 100, 843, 1000, 8888, 9999), m = 8, Alice inputs the set A = {70, 100, 843, 8888}, and Bob inputs the set B = {50, 70, 100, 1000}. For the convenience of explanation, the relevant description of the ciphertext E(·) obtained by NTRU encryption is omitted. Therefore, the calculation can be directly performed using α·a max without expressing it in the form of The operations are as follows:

[0076] (1) Alice initializes the row vectors according to a max = 8888 and a min = 70, and after obtaining x' = {1, 1, 1, 1, 1, 1, 1, 0} and x'' = {1, 1, 1, 0, 0, 0, 0, 0}, sends them to Bob.

[0077] (2) Bob selects the 6th - dimensional vector in x' = {1, 1, 1, 1, 1, 1, 1, 0} according to the position order 6 of b max = 1000 in the universal set, and denotes it as α = 1. Then, according to the position order 2 of b = 50 in the universal set, selects the 2nd - dimensional vector in b min and denotes it as β = 1. Then, min Finally, sends the randomly permuted (1, 0) and (1, 0) to Alice.

[0078] (3) Alice calculates α·a max ​= 8888, β·a min = 70, Send (8888, 0) and (70, 0) to the other party.

[0079] (4) Bob calculates x max = α·a max +(1 - α)·b max = 8888; x min = (1 - β)·a min +β·b min = 50, and then obtains the range as 8838 and the sum of extreme values as 8938.

[0080] Correctness analysis:

[0081] (1) Alice and Bob each have two elements a max 、a min and b max 、b min , and calculate the range and the sum of extreme values of the distributed set D composed of these four elements. Assume a set D = {a max , a min , b max , b min}. According to the properties of the set, max(A ∪ B) - min(A ∪ B) = maxD - minD, max(A ∪ B) + min(A ∪ B) = maxD + minD.

[0082] (2) In step 2, Bob sends E α and E β . At this time, Alice can use the private key to decrypt it, thus leaking the size relationship between a max and a min , b max and b min . Therefore, after randomly permuting and sending them to Alice respectively, even if Alice has malicious behavior, the size relationship between the data will not be leaked.

[0083] (3) Through the additive homomorphism of the NTRU encryption algorithm, Bob calculates

[0084]

[0085] After sending it to Alice, Alice calculates X max + (-X min ) and X max + X min and then decrypts them with the private key to obtain the range and the sum of extreme values respectively.

[0086] Through the above protocol, the calculation of the range and the sum of extreme values can be achieved, and on the premise of protecting data privacy, it can provide strong support for fields such as risk assessment, fraud detection, transaction prediction, and portfolio optimization. However, in practical applications, participants may have malicious behaviors, so it is very necessary to design a secure computing protocol under the malicious model. Specific Embodiment 2:

[0088] This embodiment is a computer storage medium, in which a computer program is stored. The computer program is loaded and executed by a processor to implement the secure computing method for the range and the sum of extreme values of a distributed data set described in Specific Embodiment 1, that is, the secure computing protocol for the range and the sum of extreme values of a distributed data set under the semi-honest model.

[0089] It should be understood that the storage medium described in this embodiment includes but is not limited to magnetic storage media and optical storage media; the magnetic storage media includes but is not limited to RAM, ROM, and other storage media such as hard disks and USB flash drives. Specific Embodiment 3:

[0091] This embodiment is a secure computing device for the range and the sum of extreme values of a distributed data set. The device includes a processor and a memory, and a computer program is stored in the memory. The computer program is loaded and executed by the processor to implement the secure computing method for the range and the sum of extreme values of a distributed data set described in Specific Embodiment 1, that is, the secure computing protocol for the range and the sum of extreme values of a distributed data set under the semi-honest model.

[0092] It should be understood that the device described in this embodiment includes but is not limited to devices including a processor and a memory, and may also include devices corresponding to other units or modules with information acquisition, information interaction, and control functions. For example, the device may also include a signal acquisition device, etc. The device includes but is not limited to a PC, a workstation, a mobile device, etc. Specific Embodiment 4:

[0094] This embodiment is a secure computing method for the range and the sum of extreme values of a distributed dataset, which is a secure computing method for the range and the sum of extreme values of a distributed dataset under a malicious model. When designing a secure multi-party computing protocol under a malicious model, it is necessary to analyze the possible attacks by participants in a semi-honest protocol, and design preventive measures against these attacks to prevent these attacks from occurring, so that the malicious behavior of an adversary cannot be implemented or will be detected once implemented. The secure multi-party computing protocol under a malicious model must have the same security level as the ideal model protocol to ensure that malicious behavior cannot be implemented. In addition to the unstoppable behaviors such as refusing to participate, providing false inputs, or stopping halfway, other malicious behaviors may be taken when executing the protocol. The following are the possible malicious behaviors when executing Protocol 1: At the last step of executing Protocol 1, Alice needs to decrypt G 1 (G 2 ) to obtain the range g 1 (A ∪ B) and the sum of extreme values g 2 (A ∪ B) of the distributed set A ∪ B, and tell the other party the final result. In this process, Alice may deliberately tamper with her calculation result and tell Bob a wrong result.

[0095] To avoid the occurrence of the above malicious behavior, the present invention also designs a secure computing protocol for the range and the sum of extreme values of a distributed dataset under a malicious model. The solution idea is to let both parties execute Protocol 1 once each and output the final results respectively, and finally verify whether the obtained results are consistent by means of the cut-and-choose method.

[0096] In a secure computing method for the range and the sum of extreme values of a distributed dataset according to this embodiment, the two parties that need to perform secure computing are denoted as Alice and Bob. Alice has a private set A = {a 1 , …, a q}, and Bob has a private set B = {b 1 , …, b w}, where u 1 < u 2 < … < u m and the cardinality of the universal set |U| = m. The two parties hope to calculate the range g 1 (A ∪ B) = max(A ∪ B) - min(A ∪ B) and the sum of extreme values g 2 (A ∪ B) = max(A ∪ B) + min(A ∪ B) without revealing their respective private data, denoted as g 1 and g 2 respectively. The specific calculation process is shown in Table 2.

[0097] Table 2

[0098]

[0099]

[0100]

[0101] Correctness analysis:

[0102] The status, operation and security status of both parties in this protocol are completely symmetrical. The following is an analysis of the malicious behavior that Alice may carry out:

[0103] (1) In step 8, Alice may deliberately enter an incorrect value for g. 1 , which was not discovered during the verification in step (10), but this situation cannot be avoided under rational circumstances and is not considered.

[0104] (2) In step 10, Alice uses Bob’s public key h 2 Calculation: c 1 ' a =(r a ' 1 *h 2 )+(g 1 / 2)(modq), then calculate It is recorded as A. At this time, there is In this process, not only was no information leaked, but the correct extreme value was also obtained.

[0105] (3) In steps 9-12, both parties use the split-select method to detect malicious behavior in the protocol. If malicious behavior is detected, the protocol is terminated. Bob Randomly select one And do the following: Bob uses Alice's public key h 1 Perform the calculation and send the result to Alice, who uses the private key sk 1 Decryption. If Alice cannot decrypt the final result, Bob’s malicious behavior will be detected in time.

[0106] (4) In this process, the only malicious behavior that Alice can successfully carry out is: the false ciphertext provided by Alice is not selected by Bob in step 9, but is selected by chance in step 10, resulting in an incorrect result. If there is one group in m groups that does not meet the requirements, the maximum probability of Alice's successful deception is 1 / m; if Alice provides n groups of wrong data (n<m / 2), the probability of successful deception is As the value of m increases, the probability of cheating approaches 0.

[0107] Safety Proof:

[0108] In Protocol 2, Alice calculates \(g\) for confidentiality. 1 and \(g\) 3 , and Bob calculates \(g\) for confidentiality. 2 and \(g\) 4 . Next, \(g\) 1 and \(g\) 2 are used as input data for verification. Therefore, the problem can be transformed into judging whether \(g\) 1 and \(g\) 2 are equal as the criterion for judging security. The security of the protocol under the malicious model is widely proved using the ideal-real paradigm method.

[0109] Theorem 1 Protocol 2 (denoted as \(\Pi\)) is secure under the malicious model.

[0110] Proof: To prove that Protocol 2 is secure, it is necessary to prove that the strategy pair found jointly by the two parties is indistinguishable from the strategy pair in the protocol under the ideal model. Here, the strategy pair refers to the set of actions or steps taken by both parties when executing the protocol.

[0111] In the protocol, it must be ensured that at least one party is honest to guarantee the feasibility and security of the protocol. If both parties are dishonest, then the protocol may not be executed properly or there may be security risks. Specifically, it is divided into two cases:

[0112] (1) A 1 is honest, A 2 is dishonest, A 1 always operates according to the rules of the protocol, while A 2 may try to deceive or disrupt the execution of the protocol. That is, there exists:

[0113] S is the message sequence received by A 2 during the execution process.

[0114] When A 1 is honest, it is necessary to prove that A 2 in the actual protocol is indistinguishable from B 2 under the ideal model to ensure the correctness and security of the protocol. Therefore, during the proof process, it is necessary to verify the security of the protocol according to the behavior of A 2 .

[0115] In the actual situation, the honest B 1 will send the real information \(g\) 1 to the TTP, and the dishonest B 2 will send information to the TTP depending on the strategy of A 2 , that is, A 2 \((g\) 2), finally TTP outputs F(g 1 , A 2 (g 2 ))。

[0116] B 2 Utilize F(g 1 , A 2 (g 2 )) to try to obtain one that is indistinguishable from what A gets when actually executing the protocol 2 obtained and use it as the output of A and regard it as A 2 's output.

[0117] B 2 Randomly select g 1 ', such that the equation F(g 1 ', A 2 (g 2 )) = F(g 1 , A 2 (g 2 )) holds, and simulate the entire process of executing Protocol 2. Eventually, obtain

[0118] Because the same encryption method is adopted, so

[0119] (2) A 2 is honest, A 1 is dishonest:

[0120] A 1 Ignores TTP after getting the result, and Bob gets ⊥:

[0121] A 1 Executes the protocol normally:

[0122] B 2 is deterministic and will output the required data as per the regulations. Just convert A 1 to the ideal model B 1 and that's it. In the actual situation, B 1 will send A 1 (q 1 ) to TTP. Similarly, B 2 sends q 2 , and TTP calculates F(A 1 (q 1 ), q 2 ). If A 1 executes the protocol normally in the actual situation, then in the ideal situation, TTP will also output F(A 1 (q1 ),q 2 ) Send to B 2 . If in the actual situation A 1 Ignores the TTP after getting the result. Ideally, the TTP will send ⊥ to B 2 .

[0123] B 1 Utilizes A 1 And tries to obtain What it gets when actually executing the protocol Indistinguishable. That is, B 1 Randomly selects g' 2 , B 1 Disguises as A 2 And executes the protocol with A 1 Satisfying Generates the entire process of executing Protocol 2 S', and finally outputs Specifically determined according to whether A 1 Announces the final result after decrypting the information, as follows:

[0124] A 1 Ignores the TTP after getting the result:

[0125] A 1 Normally executes the protocol:

[0126] The encryption methods adopted by the present invention are all the same, so

[0127] Obviously, both of these existing situations meet the security definition, and Protocol 2 is secure.

[0128] (A) Computational complexity:

[0129] "Private substitution and its applications in private scientific computation" (Document 1 in Table 3), "Private maximum and minimum computation" (Document 2 in Table 3), and Protocol 1 of the present invention are all protocols under the semi-honest model. "Private substitution and its applications in private scientific computation" uses the 0-1 coding method to calculate the maximum and minimum values through the secure substitution method, which requires an average of 5nm + 2n modular exponentiation operations. "Private maximum and minimum computation" utilizes the additive homomorphism of the ElGamal public key algorithm. Generating the public key requires n operations, and encryption and decryption together require 3nm + n operations (where n represents the number of participants and the cardinality of the universal set U is m). Obtaining the minimum value requires ni modular exponentiation operations, and obtaining the maximum value requires n(m - j) modular exponentiation operations, with a total of 5n(i + m - j) + 4m modular exponentiation operations. Protocol 1 of the present invention applies the NTRU encryption scheme, which requires a total of 2m + 17 convolution operations for calculating the range, and 2m + 16 convolution operations for calculating the sum of extreme values. Since the schemes in the two documents can only obtain the plaintext of the maximum and minimum values, if used to calculate other values such as the range, sum of extreme values, etc., they will mark the positions in the universal set U, thus leaking the intermediate results, and the security of these two schemes is extremely low and they cannot resist the attacks of malicious adversaries.

[0130] "Secure maximum(minimum)computation in malicious model" (Document 3 in Table 3) constructs a maximum (minimum) value calculation protocol that resists active attacks using the ElGamal public key cryptosystem. Generating the public key requires n modular exponentiation operations, with a total of 2(m + 1)n + 5n(i + m - j) + 4m modular exponentiation operations. Although this scheme can resist the attacks of malicious adversaries, if used to calculate extreme values, it will also leak the intermediate results and has low efficiency. Protocol 2 of the present invention uses the efficient NTRU encryption scheme. When Alice encrypts the data, 2m convolution operations are performed. During the calculation process, 4 convolution operations are carried out. When calculating the range, 11 convolution operations are performed. When calculating the sum of extreme values, 10 convolution operations are carried out. When decrypting, 2 convolution operations are required (ignoring the verification stage). Alice and Bob are symmetric, so a total of 4m + 34 convolution operations are required for calculating the range, and 4m + 32 convolution operations are required for calculating the sum of extreme values.

[0131] Communication complexity:

[0132] The communication complexity is usually measured by the number of communication rounds, which reflects the communication time and data transmission volume required in the communication protocol. The number of communication rounds in "Private substitution and its applications in private scientific computation" is (n - 1)(m + 4) rounds, the number of communication rounds in "Private maximum and minimum computation" is (0.75m + 2)(n - 1) rounds, the number of communication rounds in "Secure maximum (minimum) computation in malicious model" is 3n rounds (the verification phase is only a simple multiplication operation and can be ignored), the number of communication rounds of Protocol 1 of the present invention is 2 rounds, and the number of communication rounds of Protocol 2 of the present invention is 8 rounds.

[0133] Table 3 Performance Comparison

[0134]

[0135]

[0136] As can be seen from Table 3, for Protocol 2, whether calculating the range or the sum of extreme values, both the computational overhead and the communication overhead are lower than those in the existing literature. Although Document 3 can resist attacks from malicious adversaries, it will also leak intermediate results and cannot perform secure computations for the range and the sum of extreme values. Compared with these solutions, the protocol of the present invention has advantages in all aspects.

[0137] The present invention can be applied to project bidding involving multiple industries, requiring different types of companies to form teams to bid. In order to decide whether to form a team to bid without disclosing the expected price, each company needs to perform a secure computation of the range of the expected price as a reference. By securely computing the range, the change range of the expected prices of each company can be measured, thereby helping them decide whether to form a team to bid and ensuring the smooth progress of the project bidding. Specific Embodiment 5:

[0139] This embodiment is a computer storage medium, in which a computer program is stored. The computer program is loaded and executed by a processor to implement the secure computation method for the range and the sum of extreme values of a distributed dataset described in Specific Embodiment 4, that is, the secure computation protocol for the range and the sum of extreme values of a distributed dataset under a malicious model.

[0140] It should be understood that the storage medium described in this embodiment includes but is not limited to magnetic storage media and optical storage media; the magnetic storage media include but are not limited to RAM, ROM, and other storage media such as hard disks and USB flash drives. Specific Embodiment 6:

[0142] This embodiment is a secure computing device for the sum of the range and extreme values of a distributed dataset. The device includes a processor and a memory. A computer program is stored in the memory and loaded and executed by the processor to implement a secure computing method for the sum of the range and extreme values of a distributed dataset described in Embodiment 4, that is, a secure computing protocol for the sum of the range and extreme values of a distributed dataset under a malicious model.

[0143] The present invention can also have many other embodiments. Without departing from the spirit and essence of the present invention, those skilled in the art can make various corresponding changes and deformations according to the present invention. However, these corresponding changes and deformations should all fall within the protection scope of the appended claims of the present invention.

Claims

1. A method for calculating the confidentiality of the extreme difference and the sum of extreme values ​​of a distributed data set, characterized by: The two parties who need to perform confidential computing are Alice and Bob. Alice has a private set A = {a1,…,a q }, the maximum and minimum values ​​are a max and a min ; Bob has a private set B = {b1,…,b w }, the maximum and minimum values ​​are b max and b min ; where u1<u2<…<u m And the cardinality of the whole set |U|=m; The two parties perform confidential computing without disclosing their respective private data, including the following steps: Alice and Bob run the NTRU encryption scheme to generate public / private key pairs, pk1 / sk1 and pk2 / sk2, respectively, and publish public keys pk1=h1 and pk2=h2, respectively. Alice based on a max and a min Initialize the row vector x'={x1',…,x' m } and x”={x1”,…,x” m },in: Then perform NTRU encryption on vectors x' and x'' to get C' and C'', and send them to Bob; Bob uses b max and b min Initialize the row vector y'={y1',...,y' in the same way m } and y”={y1”,…,y” m }, then perform NTRU encryption on the vectors y' and y'' to obtain H' and H'', and send them to Alice; Alice based on a max At position index1 in the set U, select the vector of dimension index1 in vector H' And record it as calculate According to a min At position index2 in the universal set U, select the vector with dimension index2 in vector H' And record it as calculate Then Random permutation Will Random permutation and will After random permutation, they are sent to Bob; where E(·) represents NTRU encryption; Bob based on b max At position index3 in the universal set U, select the vector of dimension index3 in vector C' And record it as calculate According to b min At position index4 in the universal set U, select the vector of dimension index4 in vector C' And record it as calculate Then Random permutation Will Random permutation and will After random replacement, they are sent to Alice; Alice Calculation Then (D1, D1') and (D2, D2') are sent to Bob; Bob calculates Then send (D3,D3') and (D4,D'4) to Alice; Alice Calculation And calculate G1 = X max +(-X min ), G2=X max +X min They are denoted as g1 and g3 respectively; Bob calculates And calculate G1 = X max +(-X min ), G2=X max +X min They are denoted as g2 and g4 respectively; For g1 and g2, Alice and Bob select m random polynomials r respectively. ai 、r bi , i=1,…,m, and calculate and publish them separately Alice from group m Randomly select m / 2 groups And ask Bob to publish the corresponding r bi +(g2 / 2h2), and then verify using Bob’s public key h2 If the verification fails, stop, otherwise continue; at the same time, Bob Randomly select m / 2 groups And ask Alice to publish the corresponding r ai +(g1 / 2h1), and then verify using Alice’s public key h1 If the verification fails, stop, otherwise continue; Alice and Bob each take and Randomly select one and Alice then uses Bob's public key h2 to calculate c1' a =(r a '1*h2)+(g1 / 2)(modq), calculate Recorded as A; Bob uses Alice's public key h1 to calculate c1' b =(r b '1*h1)+(g2 / 2)(modq), calculate Recorded as B; finally, the two parties exchange A and B; For g3 and g4, the same treatment as g1 and g2 is adopted, and Alice and Bob obtain B' and A' respectively; Alice uses the private key sk1 to decrypt B to obtain the extreme difference, and decrypts B' to obtain the extreme value sum, and / or Bob uses the private key sk2 to decrypt A to obtain the extreme difference, and decrypts A' to obtain the extreme value sum.

2. A computer storage medium, characterized in that: The storage medium stores a computer program, which is loaded and executed by a processor to implement the confidentiality calculation method of the range and extreme value sum of a distributed data set as described in claim 1.

3. A confidential computing device for the extreme difference and extreme value sum of a distributed data set, characterized by: The device includes a processor and a memory, wherein a computer program is stored in the memory, and the computer program is loaded and executed by the processor to implement the confidentiality calculation method of the range and extreme value sum of a distributed data set as described in claim 1.

4. A method for calculating the confidentiality of the extreme difference and the sum of extreme values ​​of a distributed data set, characterized by: The two parties who need to perform confidential computing are Alice and Bob. Alice has a private set A = {a1,…,a q }, the maximum and minimum values ​​are a max and a min ; Bob has a private set B = {b1,…,b w }, the maximum and minimum values ​​are b max and b min ; where u1<u2<…<u m And the cardinality of the whole set |U|=m; The two parties perform confidential computing without disclosing their respective private data, including the following steps: Alice runs the NTRU cryptosystem to generate a public / private key pair, pk / sk, and publishes the public key pk=h; Alice based on a max and a min Initialize the row vector x'={x1',…,x' m } and x”={x1”,…,x” m },in: Then perform NTRU encryption on vectors x' and x'' to get C' and C'', and send them to Bob; Bob based on b max At position index1 in the set U, select the vector of dimension index1 in vector C' And record it as calculate According to b min At position index2 in the universal set U, select the vector of dimension index2 in vector C' And record it as calculate Then Random permutation Will Random permutation and will After random replacement, they are sent to Alice; Alice Calculation Then send (D1,D1') and (D2,D'2) to Bob; Bob calculates and G1 = X max +(-X min ), G2=X max +X min ; Then send G1 and G2 to Alice; Alice decrypts G1 and G2 to obtain the extreme difference, extreme value and sum.

5. A computer storage medium, characterized in that: The storage medium stores a computer program, which is loaded and executed by a processor to implement the confidentiality calculation method of the range and the sum of extreme values ​​of a distributed data set as described in claim 4.

6. A confidential computing device for the extreme difference and extreme value sum of a distributed data set, characterized by: The device includes a processor and a memory, wherein a computer program is stored in the memory, and the computer program is loaded and executed by the processor to implement the confidentiality calculation method of the range and extreme value sum of a distributed data set as described in claim 4.