Secure computing system based on threshold homomorphic encryption technology in floating-point number cloud environment
By adopting a secure computing system with threshold homomorphic encryption technology in a floating-point cloud environment, the problem that the existing technology cannot effectively handle floating-point operation is solved, efficient and secure floating-point calculation is achieved, and computing efficiency and data processing capabilities are improved.
Patent Information
- Application Number
- CN202510596897.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-06-17
AI Technical Summary
The existing homomorphic encryption scheme cannot directly process floating-point number operations, has low computing efficiency, and cannot support large-scale data calculation and processing, and its application scenarios are limited.
A secure computing system based on threshold homomorphic encryption technology in a floating-point cloud environment uses the data owner node to encode and encrypt the original data. The cloud platform node performs secure computing operations based on threshold homomorphic encryption rules to ensure data security and computing efficiency.
It realizes efficient and high-precision floating-point number calculation while protecting data security, improves safe computing efficiency, and supports large-scale data calculation and processing.
Smart Images

Figure CN120165835A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and particularly to a secure computing system based on threshold homomorphic encryption technology in a floating-point cloud environment. Background Art
[0002] With the rapid development of cloud computing technology, more and more enterprises and individuals choose to outsource computing tasks to the cloud to reduce local computing resource overhead and improve efficiency. When data is processed in the cloud, it often faces certain data leakage risks, and the security and confidentiality of data are crucial in fields such as finance, healthcare, and power systems.
[0003] Current secure outsourced computation (SOC) mainly relies on homomorphic encryption and secure multi-party computation technologies. However, most existing homomorphic encryption schemes (such as Paillier, RSA) only support addition and multiplication in the integer domain, and cannot directly handle floating-point operations. Moreover, homomorphic encryption involves complex mathematical operations, requires a large amount of computing resources, and has low computing efficiency. At the same time, due to the large computing overhead, homomorphic encryption cannot support large-scale data computing and processing, and its application scenarios are limited to a certain extent.
[0004] Therefore, there is a problem of low efficiency in secure computing in traditional technologies. Summary of the Invention
[0005] Based on this, it is necessary to provide a secure computing system based on threshold homomorphic encryption technology in a floating-point cloud environment that can improve the efficiency of secure computing for the above technical problems.
[0006] A secure computing system based on threshold homomorphic encryption technology in a floating-point cloud environment, the system includes: a data owner node and a cloud platform node; where:
[0007] The data owner node is used to obtain the original data of the secure computing task, and encrypt the original data using a floating-point encoder to obtain the encrypted data corresponding to the secure computing task, and upload the encrypted data to the cloud platform node;
[0008] The cloud platform node is used to receive multiple encrypted data uploaded by the data owner node, and perform secure computing operations on the multiple encrypted data based on the secure computing protocol determined by the threshold homomorphic encryption rule to obtain the encrypted computing result, and return the encrypted computing result to the data owner node;
[0009] The data owner node is used to decrypt the encrypted computing result to obtain the data computing result of the secure computing task.
[0010] In one embodiment, a data owner node is configured to:
[0011] Obtain security parameters for a secure computing task; the security parameters characterize the security level of the system;
[0012] Generate a key based on the security parameters;
[0013] Encrypt the original data based on the key to obtain encrypted data corresponding to the original data.
[0014] In one embodiment, the system further includes a computing service node; the key includes a public key, a first private key, and a second private key;
[0015] The data owner node is configured to upload the public key and the first private key to the cloud platform node, and upload the second private key to the computing service node.
[0016] In one embodiment, a data owner node is configured to:
[0017] Determine the target floating-point type to which the original data belongs;
[0018] Encode the original data according to the encoding method corresponding to the target floating-point type to obtain an encoded array corresponding to the original data;
[0019] Obtain a random number, and encrypt the mantissa in the encoded array corresponding to the original data based on the random number and the public key to obtain encrypted data corresponding to the original data.
[0020] In one embodiment, a data owner node is configured to:
[0021] In the case where the target floating-point type is a preset floating-point type, encode the original data using a floating-point encoder to obtain an initial encoded array corresponding to the original data; the initial encoded array includes an initial mantissa, an initial exponent, and an initial sign bit;
[0022] Based on the public key, determine a mantissa threshold, and in the case where the initial mantissa in the initial encoded array corresponding to the floating-point number is greater than or equal to the mantissa threshold, return to the step of encoding the original data using the floating-point encoder until the initial mantissa in the initial encoded array corresponding to the original data is less than the mantissa threshold;
[0023] Use the initial encoded array corresponding to the original data as the encoded array corresponding to the original data.
[0024] In one embodiment, a data owner node is configured to:
[0025] In the case where the target floating-point type is not the preset floating-point type, encode the original data into a preset encoding array; the preset encoding array includes a preset mantissa, a preset exponent, and a preset sign bit;
[0026] Use the preset encoding array as the encoding array corresponding to the original data.
[0027] In one embodiment, the data owner node is used to combine the first private key and the second private key to decrypt the encrypted calculation result to obtain the data calculation result of the secure calculation task.
[0028] In one embodiment, the cloud platform node is used for:
[0029] Based on the secure calculation protocol, perform secure calculation operations on each encrypted data involved in the first secure calculation subtask to obtain a first encrypted calculation result, and the collaborative calculation service node performs secure calculation operations on each encrypted data involved in the second secure calculation subtask based on the secure calculation protocol to obtain a second encrypted calculation result; the first secure calculation subtask is a subtask in the secure calculation task with an operation complexity less than the preset complexity; the second secure calculation subtask is a subtask in the secure calculation task with an operation complexity greater than or equal to the preset complexity;
[0030] Aggregate the first encrypted calculation result and the second encrypted calculation result to obtain an encrypted calculation result.
[0031] In one embodiment, the cloud platform node is used to send a collaborative calculation request to the calculation service node to request the calculation service node to perform a secure calculation operation;
[0032] The calculation service node is used to perform secure calculation operations on each encrypted data involved in the second secure calculation subtask in response to the collaborative calculation request to obtain a second encrypted calculation result.
[0033] In one embodiment, the cloud platform node adopts a dual-channel communication architecture during deployment; the dual-channel communication architecture includes a control channel and a data channel; the control channel is used to transmit the parameters of the secure calculation protocol; the data channel is used to transmit the encrypted calculation result.
[0034] The above-mentioned secure computing system based on threshold homomorphic encryption technology in a floating-point cloud environment. The data owner node obtains the original data of the secure computing task, encrypts the original data using a floating-point encoder to obtain the encrypted data corresponding to the secure computing task, and uploads the encrypted data to the cloud platform node. The cloud platform node receives multiple encrypted data uploaded by the data owner node, and based on the secure computing protocol determined by the threshold homomorphic encryption rule, performs secure computing operations on the multiple encrypted data to obtain the encrypted computing result, and returns the encrypted computing result to the data owner node. The data owner node decrypts the encrypted computing result to obtain the data computing result of the secure computing task. In this way, the data owner node can use the floating-point coding technology to encode floating-point numbers, and by outsourcing the secure computing task to the cloud platform node, the cloud platform node can perform secure computing based on the secure computing protocol generated by the threshold homomorphic encryption rule, achieving efficient and high-precision floating-point operations while protecting the data security of all parties and improving the secure computing efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0036] Figure 1 It is a schematic diagram of a secure computing system based on threshold homomorphic encryption technology in a floating-point cloud environment in one embodiment;
[0037] Figure 2 It is a schematic diagram of data interaction between nodes in a secure computing system in one embodiment;
[0038] Figure 3 It is a schematic flowchart of a secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment in one embodiment;
[0039] Figure 4 It is a structural block diagram of a secure computing device based on threshold homomorphic encryption technology in a floating-point cloud environment in one embodiment;
[0040] Figure 5 It is an internal structure diagram of a computer device in one embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0042] In an exemplary embodiment, Figure 1 As shown, a secure computing system based on threshold homomorphic encryption technology in a floating point cloud environment is provided, the system includes a data owner node 102 and a cloud platform node 104, wherein the data owner node 102 communicates with the cloud platform node 104, wherein:
[0043] The data owner node 102 is used to obtain the original data of the secure computing task, and encrypt the original data using a floating point encoder to obtain the encrypted data corresponding to the secure computing task, and upload the encrypted data to the cloud platform node 104;
[0044] The cloud platform node 104 is used to receive multiple encrypted data uploaded by the data owner node, and perform a secure computing operation on the multiple encrypted data based on a secure computing protocol determined by a threshold homomorphic encryption rule to obtain an encrypted computing result, and return the encrypted computing result to the data owner node 102;
[0045] The data owner node 102 is used to decrypt the encrypted calculation result to obtain the data calculation result of the security calculation task.
[0046] Among them, the data owner node can refer to the data owner (DO for short), that is, the individual or entity that owns and manages a specific data set or data domain. The data owner DO is responsible for ensuring the quality, legal and compliant use, security, and lifecycle management of the data.
[0047] Among them, the cloud platform node can refer to a cloud service provider (CP), that is, a supplier of cloud computing services. The cloud service provider CP is responsible for managing the cloud infrastructure, including computing resources, networks, and storage, and providing services and security guarantees to customers.
[0048] The secure computing task may refer to a computing task that may occupy more local computing resources of the data owner node when computing in the data owner node. The secure computing task may include relatively simple computing tasks and relatively complex computing tasks.
[0049] The floating point number encoder may be an encoder for encoding floating point numbers.
[0050] Among them, the original data of the secure computing task may include unprocessed data required for the secure computing task.
[0051] Among them, the encrypted data of the secure computing task may refer to the data formed after encrypting the original data required for the secure computing task.
[0052] Among them, the secure computing protocol may be a computing protocol determined based on the threshold homomorphic encryption rule, which can ensure data security.
[0053] Among them, the encrypted calculation result may be the result obtained after operating on the original data of the secure computing task in the encrypted state.
[0054] Among them, the data calculation result may refer to the calculation result required for the secure computing task. In fact, the data calculation result obtained after the data owner node executes the secure computing task using the original data is the same as the data calculation result obtained after the cloud platform node executes the secure computing task in the form of data encryption. Since executing the computing task at the data owner node often consumes more local resources, therefore, the computing task of the data owner node can be outsourced to the cloud platform node through the technical solution of the present application to achieve efficient computing.
[0055] For the above secure computing system based on the threshold homomorphic encryption technology in the floating-point cloud environment, the data owner node obtains the original data of the secure computing task, and uses a floating-point encoder to encrypt the original data to obtain the encrypted data corresponding to the secure computing task, and uploads the encrypted data to the cloud platform node; the cloud platform node receives multiple encrypted data uploaded by the data owner node, and based on the secure computing protocol determined by the threshold homomorphic encryption rule, performs a secure computing operation on the multiple encrypted data to obtain an encrypted calculation result, and returns the encrypted calculation result to the data owner node; the data owner node decrypts the encrypted calculation result to obtain the data calculation result of the secure computing task; in this way, the data owner node can use the floating-point coding technology to encode the floating-point numbers, and by outsourcing the secure computing task to the cloud platform node, the cloud platform node can perform secure computing based on the secure computing protocol generated by the threshold homomorphic encryption rule, realizing high-efficiency and high-precision floating-point arithmetic while protecting the data security of all parties, and improving the secure computing efficiency.
[0056] In an exemplary embodiment, the data owner node is configured to: obtain a security parameter for the secure computing task; the security parameter characterizes the security level of the system; generate a key based on the security parameter; encrypt the original data based on the key to obtain the encrypted data corresponding to the original data.
[0057] Among them, the security parameter characterizes the security level of the secure computing system, and the security parameter can be used representation
[0058] Among them, the secret key can be used to encrypt and decrypt the original data.
[0059] Optionally, when the data owner node of the secure computing system encrypts the original data using a floating-point encoder to obtain the encrypted data corresponding to the secure computing task, specifically, it first obtains the security parameters for the secure computing task, generates a secret key based on the security parameters, and then encrypts the original data based on the secret key to obtain the encrypted data corresponding to the original data.
[0060] In this embodiment, the data owner node of the secure computing system obtains the security parameters for the secure computing task; the security parameters characterize the security level of the system; generates a secret key based on the security parameters; encrypts the original data based on the secret key to obtain the encrypted data corresponding to the original data; in this way, a secret key that matches the security level of the secure computing system can be generated, thereby realizing the encryption of the original data.
[0061] In an exemplary embodiment, the system further includes a computing service node; the secret key includes a public key, a first private key, and a second private key; the data owner node is configured to upload the public key and the first private key to the cloud platform node, and upload the second private key to the computing service node.
[0062] Among them, as Figure 1 shown, the secure computing system further includes a computing service node 106. The computing service node 106 may refer to a cloud service provider (CSP), that is, an enterprise or platform that provides cloud computing services. The cloud service provider CSP provides more diverse cloud computing resources and services for users through the Internet, and users do not need to build expensive hardware devices by themselves.
[0063] Among them, the secret key includes a public key, a first private key, and a second private key. The public key can be represented by The first private key can be represented by The second private key can be represented by representation.
[0064] In practical applications, when generating the secret key, by inputting the security parameter , generate two large prime numbers , calculate the modulus and the Carmichael function , construct the public key and the master private key , and then generate the shard private key through the Chinese Remainder Theorem, satisfying and 。
[0065] Optionally, the data owner node of the secure computing system uploads the public key and the first private key to the cloud platform node, and uploads the second private key to the computing service node.
[0066] In this embodiment, the secure computing system further includes a computing service node; the key includes a public key, a first private key, and a second private key; the data owner node of the secure computing system uploads the public key and the first private key to the cloud platform node, and uploads the second private key to the computing service node; in this way, the private key can be sharded so that the cloud platform node and the computing service node respectively hold part of the private key, which realizes distributed key management and reduces the risk of key leakage.
[0067] In an exemplary embodiment, the data owner node is configured to: determine the target floating-point type to which the original data belongs; encode the original data according to the encoding method corresponding to the target floating-point type to obtain an encoded array corresponding to the original data; obtain a random number, and encrypt the mantissa in the encoded array corresponding to the original data based on the random number and the public key to obtain the encrypted data corresponding to the original data.
[0068] Wherein, the target floating-point type may be the floating-point type of the original data. In the embodiments of the present application, the floating-point type of the original data includes ordinary floating-point numbers and special floating-point numbers.
[0069] Wherein, the encoding method corresponding to the target floating-point type may be the encoding method corresponding to the ordinary floating-point number or the encoding method corresponding to the special floating-point number.
[0070] Wherein, the encoded array corresponding to the original data may refer to the triple of the original data. By encoding the floating-point number , the triple corresponding to the floating-point number can be obtained , wherein, is the mantissa, is the exponent, is the sign bit.
[0071] Optionally, when the data owner node of the secure computing system encrypts the original data based on the key to obtain the encrypted data corresponding to the original data, specifically, it first determines the target floating-point type to which the original data belongs, encodes the original data according to the encoding method corresponding to the target floating-point type to obtain an encoded array corresponding to the original data, then obtains a random number, and encrypts the mantissa in the encoded array corresponding to the original data based on the random number and the public key to obtain the encrypted data corresponding to the original data.
[0072] In practical applications, the encryption method is represented as , where is a random number, thereby obtaining the encrypted data corresponding to the floating-point number . It can be seen that during encryption, it is necessary to encrypt based on the "N" in the public key and the random number .
[0073] In this embodiment, the data owner node of the secure computing system determines the target floating-point number type to which the original data belongs; encodes the original data according to the encoding method corresponding to the target floating-point number type to obtain the encoding array corresponding to the original data; obtains a random number, and encrypts the mantissa in the encoding array corresponding to the original data based on the random number and the public key to obtain the encrypted data corresponding to the original data; in this way, it is possible to flexibly encode the original data accurately according to the floating-point number type to which the original data belongs, ensuring the accuracy of data encoding, thereby improving the accuracy of data encryption.
[0074] In an exemplary embodiment, the data owner node is used to: when the target floating-point number type is a preset floating-point number type, encode the original data using a floating-point encoder to obtain the initial encoding array corresponding to the original data; the initial encoding array includes an initial mantissa, an initial exponent, and an initial sign bit; determine the mantissa threshold based on the public key, and when the initial mantissa in the initial encoding array corresponding to the floating-point number is greater than or equal to the mantissa threshold, return to the step of encoding the original data using the floating-point encoder until the initial mantissa in the initial encoding array corresponding to the original data is less than the mantissa threshold; use the initial encoding array corresponding to the original data as the encoding array corresponding to the original data.
[0075] Among them, the preset floating-point number type may refer to a normal floating-point number, that is, a floating-point number other than special floating-point values such as NaN and Inf.
[0076] Among them, the initial encoding array may refer to each encoding array before the final encoding array is determined.
[0077] Among them, the initial mantissa, the initial exponent, and the initial sign bit may refer to the mantissa, exponent, and sign bit corresponding to each encoding array before the final encoding array is determined.
[0078] Among them, the mantissa threshold can be set according to the actual situation.
[0079] Optionally, during the process of the data owner node encoding the original data according to the encoding method corresponding to the target floating-point number type to obtain the encoding array corresponding to the original data, specifically: when the floating-point number belongs to the preset floating-point number type, that is, a normal floating-point number, the data owner node uses a floating-point encoder to encode the floating-point number Perform encoding to obtain a floating-point number The corresponding initial encoding array , the initial encoding array includes an initial mantissa and an initial exponent , and an initial sign bit ; in the previous embodiment, a public key was constructed , and the data owner node can determine the mantissa threshold as based on the public key. In the floating-point number corresponding initial encoding array when the initial mantissa is greater than or equal to the mantissa threshold , return the step of encoding the floating-point number by the data owner node using a floating-point encoder until the floating-point number corresponding initial encoding array in the initial mantissa is less than the mantissa threshold , that is, through dynamic radix adjustment, when detecting , automatically trigger re-encoding , until the floating-point number corresponding initial encoding array in the initial mantissa is less than the mantissa threshold ; then at this time, use the initial encoding array corresponding to the floating-point number as the encoding array corresponding to the floating-point number .
[0080] In the case where the mantissa in the initial encoding array corresponding to the floating-point number is less than the mantissa threshold , the initial mantissa can be encrypted using threshold Paillier encryption, and the encryption method is expressed as , where is a random number, thus obtaining the encrypted data corresponding to the floating-point number . It can be seen that when encrypting, it is necessary to encrypt based on "N" in the public key and the random number .
[0081] In this embodiment, when the target floating-point number type of the data owner node in the secure computing system is the preset floating-point number type, the original data is encoded using a floating-point encoder to obtain an initial encoding array corresponding to the original data; the initial encoding array includes an initial mantissa, an initial exponent, and an initial sign bit; based on the public key, a mantissa threshold is determined, and when the initial mantissa in the initial encoding array corresponding to the floating-point number is greater than or equal to the mantissa threshold, the step of encoding the original data using the floating-point encoder is returned until the initial mantissa in the initial encoding array corresponding to the original data is less than the mantissa threshold; the initial encoding array corresponding to the original data is used as the encoding array corresponding to the original data; in this way, the dynamic radix adjustment mechanism can be utilized to automatically trigger re-encoding when it is detected that the mantissa is greater than or equal to the mantissa threshold, and the calculation error can be effectively controlled.
[0082] In an exemplary embodiment, the data owner node is configured to: when the target floating-point number type is not the preset floating-point number type, encode the original data into a preset encoding array; the preset encoding array includes a preset mantissa, a preset exponent, and a preset sign bit; the preset encoding array is used as the encoding array corresponding to the original data.
[0083] Among them, when the target floating-point number type is not the preset floating-point number type (i.e., the ordinary floating-point number), the target floating-point number type of the original data is a special floating-point number, that is, the original data belongs to special floating-point numbers such as NaN, +∞, or -∞.
[0084] For example, NaN can be encoded as (0, 255, 0), +∞ can be encoded as (1, 255, 0), and -∞ can be encoded as (1, 255, 1), then (0, 255, 0), (1, 255, 0), and (1, 255, 1) are defined as the preset encoding array.
[0085] When NaN is encoded as the preset encoding array (0, 255, 0), the preset mantissa is 0, the preset exponent is 255, and the preset sign bit is 0. When +∞ is encoded as the preset encoding array (1, 255, 0), the preset mantissa is 1, the preset exponent is 255, and the preset sign bit is 0. When -∞ is encoded as the preset encoding array (1, 255, 1), the preset mantissa is 1, the preset exponent is 255, and the preset sign bit is 1.
[0086] Optionally, in the process of encoding the original data according to the encoding method corresponding to the target floating-point number type to obtain the encoding array corresponding to the original data, specifically: when the floating-point number is NaN, an exception handling mechanism is adopted, and the data owner node encodes the floating-point number NaN as the preset encoding array (0, 255, 0), the data owner node obtains a random number, and based on the random number and the public key Encrypt the preset mantissa in the preset encoding array corresponding to the floating-point number to obtain the encrypted data corresponding to the floating-point number.
[0087] In this embodiment, when the data owner node of the secure computing system determines that the target floating-point number type is not the preset floating-point number type, the original data is encoded into a preset encoding array; the preset encoding array includes a preset mantissa, a preset exponent, and a preset sign bit; the preset encoding array is used as the encoding array corresponding to the original data; in this way, the high-precision encoding of floating-point numbers that do not belong to the preset floating-point number type can be achieved by using the abnormal floating-point number processing mechanism.
[0088] In an exemplary embodiment, the data owner node is configured to jointly use the first private key and the second private key to decrypt the encrypted calculation result to obtain the data calculation result of the secure computing task.
[0089] Optionally, when the data owner node of the secure computing system subsequently decrypts the encrypted calculation result, the data owner node jointly uses the first private key and the second private key to decrypt the encrypted calculation result to obtain the data calculation result of the secure computing task.
[0090] In this embodiment, the data owner node of the secure computing system jointly uses the first private key and the second private key to decrypt the encrypted calculation result to obtain the data calculation result of the secure computing task; in this way, the encrypted calculation result can be accurately decrypted securely.
[0091] In one of the embodiments, the cloud platform node is configured to: based on the secure computing protocol, perform secure computing operations on the encrypted data involved in the first secure computing subtask to obtain a first encrypted calculation result, and cooperate with the computing service node to perform secure computing operations on the encrypted data involved in the second secure computing subtask based on the secure computing protocol to obtain a second encrypted calculation result; the first secure computing subtask is a subtask of the secure computing task with an operation complexity less than the preset complexity; the second secure computing subtask is a subtask of the secure computing task with an operation complexity greater than or equal to the preset complexity; aggregate the first encrypted calculation result and the second encrypted calculation result to obtain the encrypted calculation result.
[0092] Among them, the first secure computing subtask may be a subtask of the secure computing task with an operation complexity less than the preset complexity, and the second secure computing subtask may be a subtask of the secure computing task with an operation complexity greater than or equal to the preset complexity. In practical applications, the secure computing task may only have the first secure computing subtask, or may only have the second secure computing subtask, or may have both the first secure computing subtask and the second secure computing subtask. In any case, the technical solution of the present application can be used to implement the calculation of the secure computing task.
[0093] Among them, each encrypted data involved in the first secure computing subtask may refer to the encrypted data corresponding to each original data required when performing secure computing operations on the first secure computing subtask.
[0094] Among them, each encrypted data involved in the second secure computing subtask may refer to the encrypted data corresponding to each original data required when performing secure computing operations on the second secure computing subtask.
[0095] Among them, the first encrypted calculation result may refer to the encrypted calculation result corresponding to the first secure computing subtask.
[0096] Among them, the second encrypted calculation result may refer to the encrypted calculation result corresponding to the second secure computing subtask.
[0097] Among them, the preset complexity may be a preset value set according to actual needs for determining the computational complexity of the secure computing task.
[0098] Among them, the encrypted calculation result may refer to the result obtained by aggregating the first encrypted calculation result calculated by the cloud platform node and the second encrypted calculation result calculated by the computing service node.
[0099] Optionally, the cloud platform node of the secure computing system needs to determine the operation complexity of each subtask in the secure computing task. According to the operation complexity of each subtask, each subtask in the secure computing task is divided into a first secure computing subtask set and a second secure computing task set. Among them, the division result of the secure computing task can include three cases. The first case is that the first secure computing subtask set is an empty set while the second secure computing subtask set is not an empty set. The second case is that the second secure computing subtask set is an empty set while the first secure computing subtask set is not an empty set. The third case is that both the first secure computing subtask set and the second secure computing subtask set are not empty sets. When the first case occurs, the cloud platform node performs secure computing operations on each encrypted data involved in the first secure computing subtask based on the secure computing protocol to obtain a first encrypted computing result. When the second case occurs, the cloud platform node requests the cooperation of the computing service node. The cloud platform node and the computing service node jointly perform secure computing operations on each encrypted data involved in the second secure computing subtask based on the secure computing protocol to obtain a second encrypted computing result. When the third case occurs, the cloud platform node performs secure computing operations on each encrypted data involved in the first secure computing subtask based on the secure computing protocol to obtain a first encrypted computing result. At the same time, the cloud platform node and the computing service node jointly perform secure computing operations on each encrypted data involved in the second secure computing subtask based on the secure computing protocol to obtain a second encrypted computing result. The computing service node returns part of the second encrypted computing result to the cloud platform node. The cloud platform node aggregates its own calculated first encrypted computing result, part of the second encrypted computing result, and the part of the second encrypted computing result calculated by the computing service node to obtain an aggregation result, and returns the aggregation result to the data owner node.
[0100] In this embodiment, the cloud platform node of the secure computing system performs secure computing operations on each encrypted data involved in the first secure computing subtask based on the secure computing protocol to obtain a first encrypted computing result, and, cooperates with the computing service node to perform secure computing operations on each encrypted data involved in the second secure computing subtask based on the secure computing protocol to obtain a second encrypted computing result. The first secure computing subtask is a subtask in the secure computing task with an operation complexity less than a preset complexity. The second secure computing subtask is a subtask in the secure computing task with an operation complexity greater than or equal to the preset complexity. Aggregate the first encrypted computing result and the second encrypted computing result to obtain an encrypted computing result. In this way, the secure computing tasks involving floating-point calculations in the data owner node can be outsourced to the cloud platform node and the computing service node for data operations, and multiple types of floating-point operation tasks can be realized through the cooperation of the cloud platform node and the computing service node, achieving efficient and high-precision floating-point operations while protecting the data security of all parties and improving the secure computing efficiency.
[0101] In an exemplary embodiment, a cloud platform node is configured to send a collaborative computing request to a computing service node to request the computing service node to perform a secure computing operation; the computing service node is configured to, in response to the collaborative computing request, perform a secure computing operation on each encrypted data involved in the second secure computing subtask to obtain a second encrypted computing result.
[0102] Among them, the collaborative computing request may refer to a request from the cloud platform node to the computing service node to request it to collaborate in completing the computing of a secure computing task.
[0103] Optionally, in the case where the computational complexity in the secure computing task exceeds a preset complexity, the cloud platform node sends a collaborative computing request to the computing service node to request the computing service node and the cloud platform node to synchronously perform a secure computing operation to complete the computing of the secure computing task. The computing service node, in response to the collaborative computing request sent by the cloud platform node, performs a secure computing operation on each encrypted data involved in the second secure computing subtask to obtain a second encrypted computing result.
[0104] In this embodiment, the cloud platform node of the secure computing system sends a collaborative computing request to the computing service node of the secure computing system to request the computing service node of the secure computing system and the cloud platform node of the secure computing system to synchronously perform a secure computing operation; by the computing service node of the secure computing system, in response to the collaborative computing request, performing a secure computing operation on each encrypted data involved in the second secure computing subtask to obtain a second encrypted computing result; thus, the cloud platform node of the secure computing system can, in the case of needing to perform a secure computing subtask with a computational complexity greater than the preset complexity, quickly request the computing service node of the secure computing system to collaborate in computing, thereby improving the computing efficiency.
[0105] In an exemplary embodiment, the cloud platform node adopts a dual-channel communication architecture during deployment; the dual-channel communication architecture includes a control channel and a data channel; the control channel is used to transmit the parameters of the secure computing protocol; the data channel is used to transmit the encrypted computing result.
[0106] Optionally, during the deployment of the cloud platform, a dual-channel communication architecture is adopted. The control channel in the dual-channel communication architecture transmits protocol parameters, and the data channel in the dual-channel communication architecture transmits encrypted payloads to implement a load balancing strategy: Support the function of resuming calculation from a breakpoint and save intermediate results through a status snapshot , where, , is an operation identifier, is a timestamp.
[0107] In this embodiment, through the dual-channel communication architecture, dynamic balance of computing load can be achieved.
[0108] For the convenience of those skilled in the art to understand, Figure 2 An exemplary data interaction diagram of each node in a secure computing system is provided. When implementing secure computing using a secure computing system, the following steps are included:
[0109] Step 1: Key generation.
[0110] Specifically, first, input the security parameter , and generate two -bit large prime numbers , calculate the modulus and the Carmichael function . Then, construct the public key and the master private key . Finally, generate the shard private key through the Chinese Remainder Theorem, satisfying and .
[0111] For example, when generating keys, 64-bit security parameters can be selected to generate prime numbers and , construct the modulus , and decompose the private key into two 32-bit shards and using the Chinese Remainder Theorem, satisfying .
[0112] Step 2: Data preprocessing.
[0113] Specifically, use a floating-point encoder to encode any floating-point number into a triple , where:
[0114]
[0115] Perform threshold Paillier encryption on the integer : , where is a random number.
[0116] For example, using a floating-point encoding scheme with dynamic radix adjustment, encode the IEEE 754 standard floating-point number into a triple , where the mantissa is a 32-bit integer, the exponent is an 8-bit signed integer, the sign bit , and execute when and Adjustment operation to ensure that the numerical precision error is less than . Additionally, construct an outlier handling mechanism, define special encoding rules, and encode NaN as , and encode as , encode as , and set an outlier detection bit in the secure computing protocol. When the exponent , trigger the preset processing logic.
[0117] The above floating-point encoding scheme supports dynamic radix adjustment and automatically triggers re-encoding when is detected: ; The floating-point encoder also provides an outlier handling mechanism to encode special floating-point values such as NaN / Inf as reserved identification codes:
[0118] ,
[0119] Among them, is the maximum value under the IEEE 754 standard.
[0120] Step 3: Secure computing.
[0121] Specifically, secure computing is based on a secure computing protocol, which includes homomorphic addition rules and scalar multiplication rules used by cloud platform nodes, as well as a secure addition protocol, a secure multiplication protocol (SMUL), and a secure comparison protocol (SCMP) used in cooperation between cloud platform nodes and computing service nodes.
[0122] Among them, homomorphic addition means that for , directly calculate .
[0123] Among them, scalar multiplication means that for a constant , calculate .
[0124] Among them, the technical key points of the secure addition protocol include: 1) Perform exponent alignment operation: For and , calculate the alignment factor: ; 2) Perform mantissa adjustment operation: If , then calculate ; Otherwise, calculate ; 3) Perform homomorphic operation: The final result satisfies: .
[0125] For example, the implementation process of the secure addition protocol can be: For two encrypted floating-point numbers and , calculate the exponent difference , when the mantissa is adjusted by homomorphic scalar multiplication or , and finally is executed and the exponent is maintained as .
[0126] Among them, the technical points of the secure multiplication protocol (SMUL) include: 1) Introducing the dual random masking technique: ; 2) Adopting a distributed decryption process: The cloud platform CP calculates , the computing service provider CSP calculates , and jointly reconstructs . 3) Result correction: Eliminating noise through homomorphic operations .
[0127] For example, the implementation process of the secure multiplication protocol (SMUL) can adopt the dual masking technique: For the encrypted values and , 16-bit random numbers and are respectively generated, and and are calculated. After obtaining and through distributed decryption, the noise term is eliminated through .
[0128] Among them, the technical points of the secure comparison protocol (SCMP) include: 1) Introducing a random permutation to achieve result confusion: ; 2) Setting a comparison threshold , and when the decryption result is determined as ; 3) Adopting zero-knowledge proof to verify that the participating parties execute the protocol correctly:
[0129] For example, in the implementation process of the secure comparison protocol (SCMP), a random permutation factor and a 32-bit random number are introduced, a comparison predicate is constructed, and the output is determined by comparing the jointly decrypted result with the threshold or .
[0130] Step 4: Result decryption. Specifically, the cloud platform CP and the computing service provider CSP respectively calculate partial decryption results:
[0131] ;
[0132] Then joint decryption is performed: , where .
[0133] When generating the key in Step 1, a secure computing environment is constructed through a distributed key generation protocol and a private key sharding technique based on the Chinese Remainder Theorem; when preprocessing the data in Step 2, a dynamic radix adjustment mechanism and an outlier handling algorithm are used to implement high-precision floating-point data encoding; when performing secure computing in Step 3, a complete set of floating-point operation protocols including secure addition, multiplication, comparison, and sign bit extraction is developed. In particular, the three-stage processing flow of "exponent alignment - mantissa operation - result reduction", combined with the double random masking technique and the zero-knowledge proof mechanism, significantly improves the operation efficiency while ensuring the computing accuracy.
[0134] In summary, the secure computing system based on threshold homomorphic encryption technology in the floating-point cloud environment of this application realizes efficient and high-precision privacy-preserving floating-point operations through an innovative floating-point encoding scheme and an optimized secure computing protocol, and has significant advantages compared with the prior art. The secure computing system based on threshold homomorphic encryption technology in the floating-point cloud environment of this application adopts a dynamic radix adjustment and mantissa correction mechanism, effectively controls the computing error while ensuring compatibility with the IEEE 754 standard, and supports the secure processing of special floating-point values including NaN and Inf; through an optimized threshold Paillier encryption architecture and a double random masking technique, a secure multiplication operation 40% faster than the traditional scheme is achieved under a 1024-bit key strength, and at the same time, a zero-knowledge proof mechanism is introduced to enhance the protocol security; the unique distributed key management and dual-channel communication architecture not only effectively prevent the risk of single-point key leakage, but also can achieve dynamic load balancing of the computing, enabling the system to demonstrate excellent practical value in privacy computing scenarios such as financial risk analysis and medical data processing that require high-precision floating-point operations.
[0135] In an exemplary embodiment, as Figure 3 shown, a secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment is provided. Taking the application of this method to the secure computing system in Figure 1 as an example, it includes the following steps S302 to S318. Among them:
[0136] Step S302, the data owner node of the secure computing system obtains the security parameters for the secure computing task; the security parameters characterize the security level of the system; based on the security parameters, a key is generated; the key includes a public key, a first private key, and a second private key; the public key and the first private key are uploaded to the cloud platform node, and the second private key is uploaded to the computing service node.
[0137] Step S304, the data owner node of the secure computing system determines the target floating-point type to which the original data belongs.
[0138] Step S306: The data owner node of the secure computing system encodes the original data according to the encoding method corresponding to the target floating-point number type, obtaining an encoded array corresponding to the original data. Specifically, it includes:
[0139] When the target floating-point number type is the preset floating-point number type, the original data is encoded using a floating-point encoder to obtain an initial encoded array corresponding to the original data. The initial encoded array includes an initial mantissa, an initial exponent, and an initial sign bit. Based on the public key, a mantissa threshold is determined, and when the initial mantissa in the initial encoded array corresponding to the floating-point number is greater than or equal to the mantissa threshold, the step of encoding the original data using the floating-point encoder is returned until the initial mantissa in the initial encoded array corresponding to the original data is less than the mantissa threshold. The initial encoded array corresponding to the original data is used as the encoded array corresponding to the original data.
[0140] When the target floating-point number type is not the preset floating-point number type, the original data is encoded into a preset encoded array. The preset encoded array includes a preset mantissa, a preset exponent, and a preset sign bit. The preset encoded array is used as the encoded array corresponding to the original data.
[0141] Step S308: The data owner node of the secure computing system obtains a random number, and based on the random number and the public key, encrypts the mantissa in the encoded array corresponding to the original data to obtain the encrypted data corresponding to the original data, and uploads the encrypted data to the cloud platform node.
[0142] Step S310: The cloud platform node of the secure computing system receives multiple encrypted data uploaded by the data owner node, and based on the secure computing protocol determined by the threshold homomorphic encryption rule, performs secure computing operations on each encrypted data involved in the first secure computing subtask to obtain a first encrypted computing result.
[0143] Step S312: The cloud platform node of the secure computing system sends a collaborative computing request to the computing service node to request the computing service node to perform secure computing operations.
[0144] Step S314: The computing service node of the secure computing system responds to the collaborative computing request, and collaborates with the cloud platform node to perform secure computing operations on each encrypted data involved in the second secure computing subtask to obtain a second encrypted computing result.
[0145] Among them, the first secure computing subtask is a subtask in the secure computing task with an operation complexity less than the preset complexity; the second secure computing subtask is a subtask in the secure computing task with an operation complexity greater than or equal to the preset complexity.
[0146] Step S316: Aggregate the first encrypted calculation result and the second encrypted calculation result through the cloud platform node of the secure computing system to obtain the encrypted calculation result.
[0147] Step S318: Through the cloud platform node data owner node of the secure computing system, combine the first private key and the second private key to decrypt the encrypted calculation result to obtain the data calculation result of the secure computing task.
[0148] It should be noted that the specific limitations of the above steps can refer to the specific limitations of a secure computing system based on threshold homomorphic encryption technology in a floating-point cloud environment described above.
[0149] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.
[0150] Based on the same inventive concept, the embodiments of the present application also provide a secure computing device based on threshold homomorphic encryption technology in a floating-point cloud environment for implementing the secure computing method based on threshold homomorphic encryption technology in the floating-point cloud environment described above. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the secure computing device based on threshold homomorphic encryption technology in a floating-point cloud environment provided below can refer to the limitations of the secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment described above, and will not be repeated here.
[0151] In an exemplary embodiment, as Figure 4 shown, a secure computing device based on threshold homomorphic encryption technology in a floating-point cloud environment is provided, which is applied to a secure computing system. The secure computing system includes a data owner node 102, a cloud platform node 104, and a computing service node 106. The device includes: an acquisition module 402, a determination module 404, an encoding module 406, an encryption module 408, a calculation module 410, a request module 412, a collaboration module 414, an aggregation module 416, and a decryption module 418, where:
[0152] An acquisition module 402 is configured to obtain security parameters for a secure computing task through a data owner node of a secure computing system; the security parameters characterize the security level of the system; based on the security parameters, generate keys; the keys include a public key, a first private key, and a second private key; upload the public key and the first private key to a cloud platform node, and upload the second private key to a computing service node.
[0153] A determination module 404 is configured to determine the target floating-point type to which the original data belongs through a data owner node of a secure computing system.
[0154] An encoding module 406 is configured to encode the original data according to the encoding method corresponding to the target floating-point type through a data owner node of a secure computing system to obtain an encoded array corresponding to the original data; specifically including:
[0155] When the target floating-point type is a preset floating-point type, use a floating-point encoder to encode the original data to obtain an initial encoded array corresponding to the original data; the initial encoded array includes an initial mantissa, an initial exponent, and an initial sign bit; based on the public key, determine a mantissa threshold, and when the initial mantissa in the initial encoded array corresponding to the floating-point number is greater than or equal to the mantissa threshold, return to the step of encoding the original data using the floating-point encoder until the initial mantissa in the initial encoded array corresponding to the original data is less than the mantissa threshold; use the initial encoded array corresponding to the original data as the encoded array corresponding to the original data;
[0156] When the target floating-point type is not the preset floating-point type, encode the original data into a preset encoded array; the preset encoded array includes a preset mantissa, a preset exponent, and a preset sign bit; use the preset encoded array as the encoded array corresponding to the original data.
[0157] An encryption module 408 is configured to obtain a random number through a data owner node of a secure computing system, and encrypt the mantissa in the encoded array corresponding to the original data based on the random number and the public key to obtain encrypted data corresponding to the original data, and upload the encrypted data to a cloud platform node.
[0158] A calculation module 410 is configured to receive multiple pieces of encrypted data uploaded by a data owner node through a cloud platform node of a secure computing system, and perform a secure computing operation on each piece of encrypted data involved in a first secure computing subtask based on a secure computing protocol determined by a threshold homomorphic encryption rule to obtain a first encrypted calculation result.
[0159] A request module 412 is configured to send a collaborative computing request from a cloud platform node of a secure computing system to a computing service node to request the computing service node to perform a secure computing operation.
[0160] A collaboration module 414, configured to, in response to a collaborative computing request by a computing service node of the secure computing system, collaborate with a cloud platform node to perform secure computing operations on each of the encrypted data involved in the second secure computing subtask, so as to obtain a second encrypted computing result.
[0161] Wherein, the first secure computing subtask is a subtask in the secure computing task with an operation complexity less than a preset complexity; the second secure computing subtask is a subtask in the secure computing task with an operation complexity greater than or equal to the preset complexity.
[0162] An aggregation module 416, configured to aggregate the first encrypted computing result and the second encrypted computing result through a cloud platform node of the secure computing system, so as to obtain an encrypted computing result.
[0163] A decryption module 418, configured to, through a cloud platform node data owner node of the secure computing system, jointly use a first private key and a second private key to perform decryption processing on the encrypted computing result, so as to obtain a data computing result of the secure computing task.
[0164] Each module in the above-mentioned secure computing device based on threshold homomorphic encryption technology in a floating-point cloud environment can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in a processor in a computer device in hardware form or be independent of the processor, or can be stored in a memory in a computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above-mentioned modules.
[0165] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 5 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store secure computing data based on threshold homomorphic encryption technology in a floating-point cloud environment. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment.
[0166] Those skilled in the art can understand,Figure 5 The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0167] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of the above-mentioned secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment. Here, the steps of the secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment may be the steps in the secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment in the above embodiment.
[0168] In one embodiment, a computer-readable storage medium is provided, storing a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of the above-mentioned secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment. Here, the steps of the secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment may be the steps in the secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment in the above embodiment.
[0169] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of the above-mentioned secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment. Here, the steps of the secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment may be the steps in the secure computing method based on threshold homomorphic encryption technology in a floating-point cloud environment in the above embodiment.
[0170] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0171] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0172] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A secure computing system based on threshold homomorphic encryption technology in a floating point cloud environment, characterized in that: The system includes: a data owner node and a cloud platform node; wherein: The data owner node is used to obtain the original data of the secure computing task, and encrypt the original data using a floating point encoder to obtain the encrypted data corresponding to the secure computing task, and upload the encrypted data to the cloud platform node; The cloud platform node is used to receive the multiple encrypted data uploaded by the data owner node, and perform a secure computing operation on the multiple encrypted data based on a secure computing protocol determined by a threshold homomorphic encryption rule to obtain an encrypted computing result, and return the encrypted computing result to the data owner node; The data owner node is used to decrypt the encrypted calculation result to obtain the data calculation result of the security calculation task.
2. The system according to claim 1, characterized in that The data owner node is used to: Acquire a security parameter for the security computing task; the security parameter represents a security level of the system; Based on the security parameters, generating a key; The original data is encrypted based on the key to obtain encrypted data corresponding to the original data.
3. The system according to claim 2, characterized in that The system also includes a computing service node; the key includes a public key, a first private key and a second private key; The data owner node is used to upload the public key and the first private key to the cloud platform node, and to upload the second private key to the computing service node.
4. The system according to claim 3, characterized in that The data owner node is used to: Determine the target floating point number type to which the original data belongs; Encode the original data according to the encoding method corresponding to the target floating-point number type to obtain an encoding array corresponding to the original data; A random number is obtained, and based on the random number and the public key, the mantissa in the encoding array corresponding to the original data is encrypted to obtain encrypted data corresponding to the original data.
5. The system according to claim 4, characterized in that The data owner node is used to: In the case where the target floating-point number type is a preset floating-point number type, the floating-point number encoder is used to encode the original data to obtain an initial encoding array corresponding to the original data; the initial encoding array includes an initial mantissa, an initial exponent, and an initial sign bit; Based on the public key, determine a mantissa threshold, and when the initial mantissa in the initial encoding array corresponding to the floating-point number is greater than or equal to the mantissa threshold, return to the step of encoding the original data using the floating-point encoder until the initial mantissa in the initial encoding array corresponding to the original data is less than the mantissa threshold; The initial encoding array corresponding to the original data is used as the encoding array corresponding to the original data.
6. The system according to claim 5, characterized in that The data owner node is used to: When the target floating-point number type is not the preset floating-point number type, encoding the original data into a preset encoding array; the preset encoding array includes a preset mantissa, a preset exponent, and a preset sign bit; The preset coding array is used as the coding array corresponding to the original data.
7. The system according to claim 3, characterized in that The data owner node is used to decrypt the encrypted calculation result in conjunction with the first private key and the second private key to obtain the data calculation result of the secure computing task.
8. The system according to claim 3, characterized in that The cloud platform node is used to: Based on the secure computing protocol, perform a secure computing operation on each encrypted data involved in the first secure computing subtask to obtain a first encrypted computing result, and, in collaboration with the computing service node, perform a secure computing operation on each encrypted data involved in the second secure computing subtask based on the secure computing protocol to obtain a second encrypted computing result; The first security computing subtask is a subtask in the security computing task whose computational complexity is less than a preset complexity; The second security computing subtask is a subtask in the security computing task whose computational complexity is greater than or equal to a preset complexity; The first encryption calculation result and the second encryption calculation result are aggregated to obtain the encryption calculation result.
9. The system according to claim 8, characterized in that The cloud platform node is used to send a collaborative computing request to the computing service node to request the computing service node to perform the secure computing operation; The computing service node is used to perform a security computing operation on each encrypted data involved in the second security computing subtask in response to the collaborative computing request to obtain the second encryption computing result.
10. The system according to claim 1, characterized in that The cloud platform node adopts a dual-channel communication architecture when deployed; the dual-channel communication architecture includes a control channel and a data channel; the control channel is used to transmit the parameters of the secure computing protocol; and the data channel is used to transmit the encrypted computing results.