Fully homomorphic encryption method and system and computer readable storage medium

By performing disturbance processing and decryption operations between the computing nodes of the fully homomorphic encryption system, the target ciphertext equal to the product of the encrypted original data plaintext is generated, and the leakage problem of the full homomorphic encryption optimization method based on trusted hardware is solved when it is attacked by side channel, achieving higher data security.

CN120200726APending Publication Date: 2025-06-24HUAWEI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311778541.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-21
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Fully homomorphic encryption optimization method based on trusted hardware may lead to leakage of raw data plaintext and plaintext products when it is attacked by side channel.

Method used

By performing disturbance processing and decryption operations between the first computing node and the second computing node, it is ensured that the second computing node performs calculations based on the ciphertext decrypted after the disturbance processing, and generates a target ciphertext equal to the product of the encrypted original data plaintext, thereby avoiding the leakage of the original data plaintext and the product of the plaintext.

Benefits of technology

It effectively prevents the leakage of raw data plaintext and plaintext products caused by side channel attacks, and enhances the security of the data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200726A_ABST
    Figure CN120200726A_ABST
Patent Text Reader

Abstract

The invention discloses a fully homomorphic encryption method and system and a computer readable storage medium, the system comprises a first computing node and a second computing node, the second computing node is deployed in a TEE, the first computing node is used for receiving fully homomorphic encrypted ciphertexts uploaded by different participants and performing disturbance processing on the fully homomorphic encrypted ciphertexts, and the second computing node is used for receiving the fully homomorphic encrypted ciphertexts; then the fully homomorphic encrypted ciphertext after disturbance processing is sent to a second computing node, the second computing node receives and decrypts the fully homomorphic encrypted ciphertext after disturbance processing to obtain corresponding decrypted data, and then the second computing node cooperates with the first computing node to perform calculation on the basis of the decrypted data to obtain a target ciphertext; the target ciphertext is equal to the product of the encrypted original data plaintext. The system can avoid leakage of the original data plaintext and the product of the original data plaintext when multiplication calculation in fully homomorphic encryption is realized, and data security is protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and particularly to a fully homomorphic encryption (FHE) method, system, and computer-readable storage medium. Background Art

[0002] Fully homomorphic encryption is a special encryption technology that allows computations to be performed in the encrypted state without decrypting the data. This means that various operations, including addition, multiplication, and logical operations, can be executed on the encrypted data without decrypting the data or exposing the plaintext. The applications of fully homomorphic encryption are very extensive, especially in the fields of secure computing and privacy protection.

[0003] Since the multiplication calculation in traditional fully homomorphic encryption requires a bootstrapping operation, and the bootstrapping process usually needs to be iterated multiple times, which is time-consuming and results in low computational efficiency. To improve the computational efficiency, an optimization method for fully homomorphic encryption based on trusted hardware has emerged. In this method, the ciphertext is decrypted in a highly secure trusted hardware, and after the multiplication calculation is completed in the plaintext domain, the plaintext product is encrypted again, replacing the bootstrapping operation in the multiplication calculation of traditional fully homomorphic encryption.

[0004] However, since the above optimization method for fully homomorphic encryption based on trusted hardware decrypts the ciphertext in the trusted hardware, and then encrypts the plaintext product after the multiplication calculation is completed in the plaintext domain, if the trusted hardware is subjected to a side-channel attack, the original data plaintext and the plaintext product will be leaked. Summary of the Invention

[0005] This application provides a fully homomorphic encryption method, system, and computer-readable storage medium, which can avoid the leakage of the original data plaintext and the plaintext product when implementing the multiplication calculation in fully homomorphic encryption and protect data security.

[0006] In a first aspect, a fully homomorphic encryption system is provided. The system includes a first computing node and a second computing node, and the second computing node is deployed in a first trusted execution environment (TEE).

[0007] The first computing node is configured to obtain a first ciphertext and a second ciphertext. The first ciphertext is obtained by performing fully homomorphic encryption on a first data, and the second ciphertext is obtained by performing fully homomorphic encryption on a second data.

[0008] The first computing node is configured to send a first perturbed ciphertext and a second perturbed ciphertext to the second computing node. The first perturbed ciphertext is obtained by perturbing the first ciphertext, and the second perturbed ciphertext is obtained by perturbing the second ciphertext.

[0009] The second computing node is used to decrypt the first perturbed ciphertext to obtain the first decrypted data and decrypt the second perturbed ciphertext to obtain the second decrypted data;

[0010] The second computing node is used to cooperate with the first computing node to perform calculations based on the first decrypted data and the second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, and the first product is the product of the first data and the second data.

[0011] In the above solution, the first computing node sends to the second computing node the ciphertexts after perturbation processing of the first ciphertext and the second ciphertext. The second computing node decrypts the perturbed ciphertexts to obtain the corresponding decrypted data, and then, based on the decrypted data, cooperates with the first computing node to perform calculations to obtain the target ciphertext equal to the encrypted product of the original data plaintext (i.e., the above first product). Since the second computing node decrypts the perturbed ciphertexts rather than the original ciphertexts, the decrypted data obtained by the second computing node decrypting the perturbed ciphertexts is different from the original data plaintext (i.e., the above first data and second data). Even if the first computing node and the second computing node are subject to side-channel attacks, the attacker can only steal the decrypted data different from the original data plaintext and cannot steal the original data plaintext, thereby avoiding the leakage of the original data plaintext and better protecting data security.

[0012] In addition, since the second computing node cooperates with the first computing node to perform calculations based on the decrypted data to obtain the target ciphertext equal to the encrypted product of the original data plaintext, unlike the existing trusted hardware-based fully homomorphic encryption optimization method that performs multiplication calculations on the original data plaintext to obtain the plaintext product and then encrypts it, even if the first computing node and the second computing node are subject to side-channel attacks, the attacker cannot steal the plaintext product, thereby avoiding the leakage of the plaintext product and better protecting data security.

[0013] In some possible implementation manners, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm. Alternatively, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm.

[0014] In some possible implementation manners, when the first ciphertext is obtained by performing fully homomorphic encryption on first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on second data according to the BGV algorithm, the second computing node is used to calculate and encrypt a second product to obtain the encrypted second product, where the second product is the product of the first decrypted data and the second decrypted data; the second computing node is used to send the encrypted second product to the first computing node; the first computing node is used to perform a de-scrambling process on the encrypted second product to obtain the target ciphertext.

[0015] In some possible implementation manners, when the first ciphertext is obtained by performing fully homomorphic encryption on first data according to the CKKS algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on second data according to the CKKS algorithm, the second computing node is used to calculate a second product, where the second product is the product of the first decrypted data and the second decrypted data; the second computing node is used to calculate a first sum and send it to the first computing node, where the first sum is the sum of the second product and the square of a first perturbation; the first computing node is used to perform a modulo operation and a shift operation on the first sum to obtain a processing result, where the processing result is equal to the sum of a first product and the first perturbation; the first computing node is used to calculate a second sum and send it to the second computing node, where the second sum is the sum of the processing result and a second perturbation; the second computing node is used to calculate a first difference, where the first difference is the difference between the second sum and the first perturbation; the second computing node is used to encrypt the first difference to obtain the encrypted first difference and send the encrypted first difference to the first computing node; the first computing node is used to calculate the target ciphertext, where the target ciphertext is the difference between the encrypted first difference and the second perturbation.

[0016] In some possible implementation manners, the second computing node is used to receive a first authentication request sent by a key generation device, where the key generation device is used to generate a public key and private key pair for fully homomorphic encryption, and the first authentication request is used to obtain the authentication information of the second computing node; the second computing node is used to send the authentication information of the second computing node to the key generation device based on the first authentication request; the second computing node is used to receive the public key and private key sent by the key generation device when the second computing node is authenticated to pass based on the authentication information of the second computing node.

[0017] It can be understood that in specific implementations, if there are security risks in the second computing node before executing the fully homomorphic encryption method provided in the above first aspect or any implementation manner of the first aspect, it may affect the execution process of the fully homomorphic encryption method or the data involved in the execution process (such as the above first perturbed ciphertext, second perturbed ciphertext, first decrypted data, second decrypted data). For example, if the second computing node is controlled by an attacker and the first perturbed ciphertext is tampered with, to ensure the secure and accurate execution of the fully homomorphic encryption method, the second computing node needs to be secure and trustworthy. Therefore, before executing the fully homomorphic encryption method, the second computing node can be authenticated. When the second computing node passes the authentication (that is, the second computing node is authenticated as secure and trustworthy), the public key and private key for fully homomorphic encryption are sent to the second computing node, and the second computing node is allowed to execute the corresponding steps in the fully homomorphic encryption method based on the public key and private key, which can improve the security and accuracy of the method. In addition, the security of the private key can also be protected, and the security of the data that needs to be decrypted using the private key can be improved.

[0018] In some possible implementation manners, the first computing node is used to receive the second authentication request sent by the first terminal device and the third authentication request sent by the second terminal device. The second authentication request and the third authentication request are used to obtain the authentication information of the second computing node; the first computing node is used to send the authentication information of the first computing node to the first terminal device based on the second authentication request and send the authentication information of the first computing node to the second terminal device based on the third authentication request; the first computing node is used to receive the first ciphertext sent by the first terminal device when the first terminal device authenticates that the first computing node passes based on the authentication information of the first computing node, and receive the second ciphertext sent by the second terminal device when the second terminal device authenticates that the first computing node passes based on the authentication information of the first computing node.

[0019] It can be understood that in specific implementations, if there are security risks in the first computing node before executing the fully homomorphic encryption method provided in the above first aspect or any implementation manner of the first aspect, it may affect the execution process of the fully homomorphic encryption method or the data involved in the execution process (such as the above first ciphertext, second ciphertext, first perturbed ciphertext, second perturbed ciphertext). For example, if the first computing node is controlled by an attacker and the first perturbed ciphertext is tampered with, to ensure the secure and accurate execution of the fully homomorphic encryption method, the first computing node needs to be secure and trustworthy. Therefore, before executing the fully homomorphic encryption method, the first computing node can be authenticated by the first terminal device and the second terminal device. When the first computing node passes the authentication (that is, the first computing node is authenticated as secure and trustworthy), the first terminal device and the second terminal device upload the first ciphertext and the second ciphertext to the first computing node, and the first computing node is allowed to execute the corresponding steps in the fully homomorphic encryption method based on the first ciphertext and the second ciphertext, which can improve the security and accuracy of the method.

[0020] In some possible implementations, the first computing node is used to obtain a third ciphertext and a fourth ciphertext. The third ciphertext is obtained by performing fully homomorphic encryption on third data, and the fourth ciphertext is obtained by performing fully homomorphic encryption on fourth data. The first computing node is used to calculate a third sum, where the third sum is the sum of the third ciphertext and the fourth ciphertext, and the third sum is equal to the encrypted fourth sum, and the fourth sum is the sum of the third data and the fourth data.

[0021] Through the above implementation, addition calculation of fully homomorphic encryption can also be realized.

[0022] In some possible implementations, the first computing node is a first virtual machine, and the second computing node is a second virtual machine;

[0023] Alternatively, the first computing node is a first container, and the second computing node is a second container;

[0024] Alternatively, the first computing node is a first virtual machine, the second computing is a second container, and the second container does not belong to the first virtual machine;

[0025] Alternatively, the first computing node is a first container, the second computing node is a second virtual machine, and the first container does not belong to the second virtual machine.

[0026] It can be understood that the first computing node and the second computing node are virtual machines or containers, and virtual machines and containers are software. That is to say, in this application, users can implement fully homomorphic encryption with the help of software. Compared with the existing fully homomorphic encryption optimization method based on trusted hardware, since the development cycle of trusted hardware is usually relatively long, this results in a relatively high cost of trusted hardware. Users need to spend a relatively high cost to purchase trusted hardware to implement fully homomorphic encryption, which can help users save costs.

[0027] In some possible implementations, the first computing node is deployed in the first TEE or the second TEE.

[0028] It can be understood that the first computing node is deployed in the TEE. Since the TEE has high security, compared with the first computing node being deployed in an untrusted execution environment, the risk of the data received and processed by the first computing node being stolen can be reduced, and data security can be better protected.

[0029] In addition, compared with being deployed in the second TEE, when the first computing node is deployed in the first TEE, since the second computing node is also deployed in the first TEE, the communication distance between the first computing node and the second computing node is shorter, the communication duration is shorter, and the encryption efficiency will be higher.

[0030] In a second aspect, a fully homomorphic encryption method is provided, which is applied to the first computing node. The method includes:

[0031] The first computing node obtains a first ciphertext and a second ciphertext, where the first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data;

[0032] The first computing node sends a first perturbed ciphertext and a second perturbed ciphertext to a second computing node, where the first perturbed ciphertext is obtained by perturbing the first ciphertext, and the second perturbed ciphertext is obtained by perturbing the second ciphertext, and the second computing node is deployed in a first TEE;

[0033] The first computing node cooperates with the second computing node to perform a calculation based on first decrypted data and second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, and the first product is the product of the first data and the second data, the first decrypted data is obtained by the second computing node decrypting the first perturbed ciphertext, and the second decrypted data is obtained by the second computing node decrypting the second perturbed ciphertext.

[0034] In some possible implementation manners, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm, or, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm.

[0035] In some possible implementation manners, when the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm, the first computing node cooperates with the second computing node to perform a calculation based on first decrypted data and second decrypted data to obtain a target ciphertext, including:

[0036] The first computing node receives an encrypted second product sent by the second computing node, where the second product is the product of the first decrypted data and the second decrypted data;

[0037] The first computing node performs a de-perturbation process on the encrypted second product to obtain a target ciphertext.

[0038] In some possible implementation manners, the first computing node is a first virtual machine, and the second computing node is a second virtual machine;

[0039] Or, the first computing node is a first container, and the second computing node is a second container;

[0040] Alternatively, the first computing node is the first virtual machine, the second computing is the second container, and the second container does not belong to the first virtual machine;

[0041] Alternatively, the first computing node is the first container, the second computing node is the second virtual machine, and the first container does not belong to the second virtual machine.

[0042] In some possible implementation manners, the first computing node is deployed in the first TEE or the second TEE.

[0043] In a third aspect, a fully homomorphic encryption method is provided, which is applied to a second computing node deployed in a first TEE. The method includes:

[0044] The second computing node receives a first perturbed ciphertext and a second perturbed ciphertext sent by a first computing node. The first perturbed ciphertext is obtained by the first computing node through perturbing a first ciphertext, and the second ciphertext is obtained by the first computing node through perturbing a second ciphertext. The first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data;

[0045] The second computing node decrypts the first perturbed ciphertext to obtain first decrypted data, and decrypts the second perturbed ciphertext to obtain second decrypted data;

[0046] The second computing node cooperates with the first computing node to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, and the first product is the product of the first data and the second data.

[0047] In some possible implementation manners, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm. Alternatively, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm.

[0048] In some possible implementation manners, when the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm, the second computing node cooperates with the first computing node to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, including:

[0049] The second computing node calculates and encrypts the second product to obtain the encrypted second product, where the second product is the product of the first decrypted data and the second decrypted data;

[0050] The second computing node sends the encrypted second product to the first computing node, and the encrypted second product is used by the first computing node to obtain the target ciphertext.

[0051] In some possible implementation manners, the first computing node is a first virtual machine, and the second computing node is a second virtual machine;

[0052] Alternatively, the first computing node is a first container, and the second computing node is a second container;

[0053] Alternatively, the first computing node is the first virtual machine, the second computing is the second container, and the second container does not belong to the first virtual machine;

[0054] Alternatively, the first computing node is the first container, the second computing node is the second virtual machine, and the first container does not belong to the second virtual machine.

[0055] Fourthly, a fully homomorphic encryption device is provided, which is applied to the first computing node. The device includes:

[0056] An obtaining module, configured to obtain a first ciphertext and a second ciphertext, where the first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data;

[0057] A perturbation processing module, configured to perform perturbation processing on the first ciphertext to obtain a first perturbed ciphertext, and perform perturbation processing on the second ciphertext to obtain a second perturbed ciphertext;

[0058] A sending module, configured to send the first perturbed ciphertext and the second perturbed ciphertext to a second computing node, where the second computing node is deployed in a first TEE;

[0059] A collaborative computing module, configured to collaborate with the second computing node to perform a calculation based on first decrypted data and second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, the first product is the product of the first data and the second data, the first decrypted data is obtained by the second computing node decrypting the first perturbed ciphertext, and the second decrypted data is obtained by the second computing node decrypting the second perturbed ciphertext.

[0060] Fifthly, a fully homomorphic encryption device is provided, which is applied to the second computing node, and the second computing node is deployed in a first TEE. The device includes:

[0061] A receiving module, configured to receive a first perturbed ciphertext and a second perturbed ciphertext sent by a first computing node, where the first perturbed ciphertext is obtained by the first computing node performing perturbation processing on a first ciphertext, and the second ciphertext is obtained by the first computing node performing perturbation processing on a second ciphertext. The first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data;

[0062] A decryption module, configured to decrypt the first perturbed ciphertext to obtain first decrypted data, and decrypt the second perturbed ciphertext to obtain second decrypted data;

[0063] A collaborative computing module, configured to collaborate with the first computing node to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, and the first product is the product of the first data and the second data.

[0064] Regarding the fully homomorphic encryption method provided in the second aspect / third aspect and the related beneficial effects and descriptions of any implementation manner of the second aspect / third aspect, and the fully homomorphic encryption device provided in the fourth aspect / fifth aspect and the related beneficial effects and descriptions of any implementation manner of the fourth aspect / fifth aspect, reference may be made to the fully homomorphic encryption system provided in the foregoing first aspect and the related beneficial effects and descriptions of any implementation manner of the first aspect, which will not be elaborated herein.

[0065] In a sixth aspect, a computing device is provided. The computing device includes a processor and a memory; the processor is configured to execute instructions stored in the memory, so that the computing device implements the method provided in any one of the second aspect to the third aspect, and any implementation manner of any one aspect.

[0066] In a seventh aspect, a fully homomorphic encryption system is provided, including the fully homomorphic encryption device described in the fourth aspect and the fully homomorphic encryption device described in the fifth aspect.

[0067] In an eighth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions, and the instructions are used to implement the method provided in any one of the second aspect to the third aspect, and any implementation manner of any one aspect.

[0068] In a ninth aspect, a computer program product is provided, including a computer program. When the computer program is read and executed by a computing device, the computing device is caused to execute the method provided in any one of the second aspect to the third aspect, and any implementation manner of any one aspect. Description of the Drawings

[0069] Figure 1It is a schematic structural diagram of a fully homomorphic encryption system provided by an embodiment of the present application;

[0070] Figure 2 It is a schematic structural diagram of another fully homomorphic encryption system provided by an embodiment of the present application;

[0071] Figure 3A It is a schematic structural diagram of another fully homomorphic encryption system provided by an embodiment of the present application;

[0072] Figure 3B It is a schematic structural diagram of another fully homomorphic encryption system provided by an embodiment of the present application;

[0073] Figure 4 It is a schematic flowchart of a fully homomorphic encryption method provided by an embodiment of the present application;

[0074] Figure 5 It is a schematic flowchart of a specific embodiment of the fully homomorphic encryption method provided by an embodiment of the present application;

[0075] Figure 6 It is a schematic flowchart of another specific embodiment of the fully homomorphic encryption method provided by an embodiment of the present application;

[0076] Figure 7 It is a schematic structural diagram of a fully homomorphic encryption device provided by an embodiment of the present application;

[0077] Figure 8 It is a schematic structural diagram of another fully homomorphic encryption device provided by an embodiment of the present application;

[0078] Figure 9 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. Detailed implementation manners

[0079] The embodiments of the present invention will be described below with reference to the accompanying drawings in the embodiments of the present invention. The terms used in the embodiments of the present invention are only for explaining the specific embodiments of the present invention, and are not intended to limit the present invention.

[0080] The terms "first", "second", etc. in the specification, claims and above-mentioned drawings of the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing the embodiments of the present application. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device comprising a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices.

[0081] To facilitate a clear understanding of the technical solution provided in this application, some nouns and terms related to the technical solution provided in this application are first explained.

[0082] (1) Trusted Execution Environment (TEE), which is usually composed of hardware and software in a computing device, can run on top of a general operating system, providing a secure operating environment that prevents malware from accessing or tampering with the data and code in the TEE, ensuring the security and privacy of sensitive data and code. The TEE can be created in a computing device through technologies such as the TrustZone technology based on the ARM architecture, AMD Secure Encrypted Virtualization (SEV), and Intel Software Guard Extensions (SGX).

[0083] (2) Untrusted Execution Environment, which is composed of the remaining software and hardware resources in the computing device other than those included in the TEE.

[0084] The untrusted execution environment does not mean that the operating system (OS) or software running in it is malicious, but its security is lower than that of the TEE. Because when the processor operates in the untrusted execution environment, the resources in the TEE (such as registers, memory, cache, peripherals, etc.) are prohibited from being accessed. Once the processor attempts to access these resources, the system will crash directly. For example, TrustZone can set sensitive memory as secure memory by configuring the TrustZone Address Space Controller (TZASC) register and the TrustZone Memory Adapter (TZMA) register. When the processor operates in the untrusted execution environment, it cannot access this secure memory. When the processor operates in the TEE, it can access both the resources of the TEE and the resources of the untrusted execution environment.

[0085] (3) Virtual Machine (VM), which refers to a complete computer system with full hardware system functions simulated by software and running in a completely isolated environment implemented by network functions virtualization (NFV) technology.

[0086] (4) A confidential virtual machine (CVM) is the product of the combination of confidential computing technology and cloud native technology, referring to the virtual machine located in the TEE. Based on the TEE, the confidential virtual machine can achieve resource isolation, data encryption, and remote attestation, preventing cloud service providers and any third party with high privileges from stealing and tampering with the data in the confidential virtual machine, thus effectively protecting the tenant data and asset security.

[0087] (5) An ordinary virtual machine, a virtual machine in a non-trusted execution environment, and a virtual machine in a computing device where the software and hardware resources are not divided into a TEE and a non-trusted execution environment all belong to ordinary virtual machines.

[0088] (6) A confidential container is the product of the combination of confidential computing technology and cloud native technology, referring to the container located in the TEE.

[0089] (7) An ordinary container, a container in a non-trusted execution environment, and a container in a computing device where the software and hardware resources are not divided into a TEE and a non-trusted execution environment all belong to ordinary containers.

[0090] (8) Homomorphic encryption (HE) is a special encryption mode in cryptography, referring to an encryption algorithm that satisfies the property of homomorphic operations on ciphertexts. That is, after the data is encrypted by homomorphic encryption, a specific calculation is performed on the ciphertext, and the plaintext obtained after the corresponding homomorphic decryption of the ciphertext calculation result is equivalent to directly performing the same calculation on the plaintext data, realizing the "computable but invisible" of the data.

[0091] The mathematical definition of homomorphic encryption is: Enc(m1)★Enc(m2) = Enc(m1★m2), where m1 and m2 are the original data plaintexts, and Enc() is the encryption algorithm. If the encryption algorithm Enc() satisfies the above mathematical definition, then we say that Enc() conforms to the property of homomorphic encryption in the ★ operation. Currently, the homomorphic encryption algorithms mainly support homomorphisms in two operations: addition and multiplication, that is, ★ is addition or multiplication.

[0092] Homomorphic encryption algorithms are divided into fully homomorphic encryption (FHE) and somewhat homomorphic encryption algorithms. If a homomorphic encryption algorithm supports arbitrary forms of computation on ciphertext, it is called fully homomorphic encryption; if a homomorphic encryption algorithm supports partial forms of computation on ciphertext, such as only addition, only multiplication, or a finite number of additions and multiplications, it is called somewhat homomorphic encryption or partially homomorphic encryption (SWHE) or (PHE). Generally speaking, since any computation can be constructed through addition and multiplication, if an encryption algorithm satisfies both additive homomorphicity and multiplicative homomorphicity, it can be said to satisfy full homomorphicity.

[0093] (9) Bootstrapping operation. In fully homomorphic encryption, bootstrapping is a key technology used to solve an important problem in fully homomorphic encryption schemes, namely how to perform decryption operations in the encrypted state. Fully homomorphic encryption allows multiplication operations on ciphertext, but after these operations are performed, the ciphertext gradually becomes undecipherable. This is because in the multiplication operation, the noise of the ciphertext gradually increases, resulting in incorrect decryption results. The bootstrapping technology embeds a special decryption circuit in the ciphertext to restore the decipherable state of the ciphertext. The basic idea of bootstrapping is to use a special decryption circuit that can perform decryption operations on the ciphertext and then re-encrypt the decryption result into a new decipherable ciphertext. In this way, without exposing the plaintext, the noise of the ciphertext can be cleared and it can be kept in a decipherable state. However, the bootstrapping process usually requires multiple iterations to gradually clear the noise in the ciphertext. In each iteration, the decryption circuit decrypts the ciphertext into plaintext and then re-encrypts the plaintext into a new ciphertext. The iteration process is usually time-consuming.

[0094] (10) Side-channel attack. It is an attack method that uses the physical implementation or operation characteristics of a system to obtain sensitive information, rather than directly attacking the algorithm or protocol of the system. This attack exploits the implicit information leakage generated by the system when processing data, such as power consumption, electromagnetic radiation, execution time, etc. Side-channel attacks usually do not directly target the encryption algorithm itself, but infer the key or other sensitive data by analyzing the side-channel information of the system. For example, by monitoring the power consumption changes or electromagnetic radiation of a device, an attacker can infer the operations being performed by the device or the data being processed.

[0095] (11) The Hadamard product, also known as the element-wise product, is an operation of multiplying corresponding elements, which refers to the operation of multiplying two matrices, vectors, or tensors with the same dimension element by element. For two matrices A and B, their Hadamard product is denoted as C = A ° B, and each element c(i, j) of the resulting matrix C is equal to A(i, j) * B(i, j), where i represents the row index and j represents the column index. It should be noted that in the embodiments of this application, the products mentioned are all Hadamard products. For example, the first product can also be called the first Hadamard product, and the second product can also be called the second Hadamard product.

[0096] The embodiments of this application relate to the fully homomorphic encryption scenario. Since the optimization method for fully homomorphic encryption based on trusted hardware decrypts the ciphertext in the trusted hardware and then performs multiplication calculations in the plaintext domain to obtain the plaintext product and then encrypts it, if the trusted hardware is subject to a side-channel attack, the original data plaintext and the plaintext product will be leaked.

[0097] To address the above problems, this application provides a fully homomorphic encryption method, system, device, etc. By performing calculations on the basis of non-original data plaintext, the final calculation result obtained is equal to the encrypted plaintext product, and the intermediate calculation process does not involve the original data plaintext and the plaintext product, thereby avoiding the leakage of the original data plaintext and the plaintext product.

[0098] The fully homomorphic encryption method, system, device, etc. provided by this application will be introduced in detail below in conjunction with the corresponding drawings.

[0099] First, please refer to Figure 1 , Figure 1 which is a schematic structural diagram of a fully homomorphic encryption system provided by the embodiments of this application. As Figure 1 shown, the system includes a first computing node 100 and a second computing node 200. The second computing node 200 is deployed in the TEE, where the TEE can be the TEE of any computing device.

[0100] The first computing node 100 and the second computing node 200 can be virtual machines or containers. It should be noted that when the first computing node 100 is a container and the second computing node 200 is a virtual machine, the first computing node 100 does not belong to the second computing node 200. Or, when the first computing node 100 is a virtual machine and the second computing node 200 is a container, the second computing node 200 does not belong to the first computing node 100. That is to say, the first computing node 100 and the second computing node 200 are independent of each other. The first computing node 100 can be a confidential virtual machine or an ordinary virtual machine, or a confidential container or an ordinary container, and this application does not make specific limitations. It can be seen that the second computing node 200 is a confidential virtual machine or a confidential container.

[0101] Optionally, the first computing node 100 may also be a computing device (such as a physical server) or other computing resources independent of the second computing node 200, and the present application does not specifically limit the first computing node 100.

[0102] The first computing node 100 and the second computing node 200 may be implemented by the same computing device or by different computing devices. For example, Figure 2 As shown, the first computing node 100 and the second computing node 200 are confidential virtual machines in the TEE deployed on the same computing device. The confidential virtual machine 100 is the first computing node 100, and the confidential virtual machine 200 is the second computing node 200. For example, Figure 3A As shown, the first computing node 100 and the second computing node 200 are confidential virtual machines in the TEE deployed on different computing devices. The confidential virtual machine 100 is the first computing node 100, and the confidential virtual machine 200 is the second computing node 200. For example, Figure 3B As shown, the first computing node 100 is the confidential virtual machine 100 in the TEE deployed on the first computing device, and the second computing node 200 is the confidential container 200 in the TEE deployed on the second computing device.

[0103] In Figure 3A 、 Figure 3B , the different computing devices to which the first computing node 100 and the second computing node 200 belong can communicate through a communication network of any communication mechanism / communication standard. Among them, the communication network can be a wide area network, a local area network, a point-to-point connection, etc., or any combination thereof.

[0104] The above computing devices may be personal computers, laptop computers, general physical servers. For example, X86 servers or ARM servers, etc., and the present application does not make specific limitations. The above computing devices may be computing devices in the central cloud data center of a cloud service provider or computing devices in the edge data center provided by the cloud service provider to users.

[0105] When the first computing node 100 and the second computing node 200 are deployed on different computing devices, the different computing devices may belong to the same data center or different data centers. The data center may be the central cloud data center of a cloud service provider or the edge data center provided by the cloud service provider to users.

[0106] As described above, the second computing node 200 is deployed in the TEE, and the TEE has high security. Therefore, the private key in the public-private key pair for fully homomorphic encryption can be stored in the second computing node 200, which can prevent the private key from being stolen, protect the security of the private key, and thus protect the security of the data that needs to be decrypted with the private key. Among them, the public-private key pair for fully homomorphic encryption can be generated by a dedicated key generation device 300 and then sent to the second computing node 200 for storage, as Figure 2 shown by the arrow in. In addition, the key generation device 300 can also disclose the public key to the parties participating in the fully homomorphic encryption (which can also be called data owners), so that the parties can use the public key to perform fully homomorphic encryption calculations on the data.

[0107] In Figure 1 、 Figure 2 、 Figure 3A 、 Figure 3B In the fully homomorphic encryption system shown, the first computing node 100 is used to receive the fully homomorphic encryption ciphertext uploaded by different parties, perform perturbation processing (which can also be called scrambling processing, scrambling operation, etc.) on the fully homomorphic encryption ciphertext, and then send the perturbed fully homomorphic encryption ciphertext to the second computing node 200. After receiving the perturbed fully homomorphic encryption ciphertext, the second computing node 200 can use the private key to decrypt the perturbed fully homomorphic encryption ciphertext to obtain the corresponding decrypted data, and then, based on the decrypted data, cooperate with the first computing node 100 to perform calculations to obtain the target ciphertext, where the target ciphertext is equal to the product of the encrypted original data plaintext.

[0108] It can be seen that since the second computing node 200 decrypts the perturbed fully homomorphic encryption ciphertext rather than the original fully homomorphic encryption ciphertext of the parties, the decrypted data obtained by the second computing node 200 by decrypting the perturbed fully homomorphic encryption ciphertext is different from the original data plaintext of the parties. Even if the first computing node 100 and the second computing node 200 are subject to side-channel attacks, the attacker can only steal the decrypted data different from the original data plaintext and cannot steal the original data plaintext, thus avoiding the leakage of the original data plaintext and better protecting the data security.

[0109] In addition, since the second computing node 200 cooperates with the first computing node 100 to perform calculations based on the decrypted data to obtain the target ciphertext equal to the product of the encrypted original data plaintext, rather than directly calculating the product of the original data plaintext and then encrypting it, even if the first computing node 100 and the second computing node 200 are subject to side-channel attacks, the attacker cannot steal the product of the original data plaintext, thus avoiding the leakage of the plaintext product and better protecting the data security.

[0110] Next, in combination with Figure 4The flowchart of the fully homomorphic encryption method provided by the embodiment of the present application shown below introduces the detailed process of the above-mentioned first computing node 100 and the second computing node 200 collaborating to perform fully homomorphic encryption on the data of different parties.

[0111] As Figure 4 shown, the method includes the following steps:

[0112] S410: The first computing node 100 receives the first ciphertext uploaded by the first data party. The first ciphertext is obtained by the first data party performing fully homomorphic encryption on the first data plaintext (which can also be referred to as the first data) using the public key for fully homomorphic encryption.

[0113] S420: The first computing node 100 receives the second ciphertext uploaded by the second data party. The second ciphertext is obtained by the second data party performing fully homomorphic encryption on the second data plaintext (which can also be referred to as the second data) using the same public key.

[0114] S430: The first computing node 100 performs perturbation processing on the first ciphertext to obtain the first perturbed ciphertext, and performs perturbation processing on the second ciphertext to obtain the second perturbed ciphertext.

[0115] S440: The first computing node 100 sends the first perturbed ciphertext and the second perturbed ciphertext to the second computing node 200. Correspondingly, the second computing node 200 receives the first perturbed ciphertext and the second perturbed ciphertext.

[0116] S450: The second computing node 200 uses the private key for fully homomorphic encryption to decrypt the first perturbed ciphertext to obtain the first decrypted data, and decrypts the second perturbed ciphertext to obtain the second decrypted data.

[0117] S460: The second computing node 200 collaborates with the first computing node 100 to perform calculations based on the first decrypted data and the second decrypted data to obtain the target ciphertext. The target ciphertext is equal to the encrypted first product, and the first product is the product of the first data plaintext and the second data plaintext.

[0118] The fully homomorphic encryption ciphertext uploaded by the above-mentioned parties can be obtained by performing fully homomorphic encryption on the original data plaintext according to fully homomorphic encryption algorithms such as floating-point fully homomorphic encryption (Cheon-Kim-Kim-Song, CKKS), BGV (Brakerski-Gentry-Vaikuntanathan), BFV (Brakerski / Fan-Vercauteren), GSW (Gentry-Sahai-Waters), etc. The present application does not make specific limitations.

[0119] In S430, the way for the first computing node 100 to perform perturbation processing on the first ciphertext and the second ciphertext can be to add the ciphertext and the perturbation, subtract the ciphertext from the perturbation. Optionally, it can also be to multiply the ciphertext by the perturbation or divide the ciphertext by the perturbation, etc. Optionally, it can also be multiple of algorithms such as addition, subtraction, multiplication, or division. This application does not limit the way of performing perturbation processing on the ciphertext. Among them, the perturbation can be a preset value or a preset polynomial.

[0120] The following introduces with two specific embodiments Figure 4 The fully homomorphic encryption method shown.

[0121] Embodiment 1: Taking the fully homomorphic encryption algorithm as BGV and the way of performing perturbation processing on the ciphertext as adding the ciphertext and the perturbation as an example:

[0122] In S410, the first computing node 100 receives the first ciphertext Enc(m1) corresponding to the first data plaintext m1 uploaded by the first data party, where Enc() is the fully homomorphic encryption algorithm BGV.

[0123] In S420, the first computing node 100 receives the second ciphertext Enc(m2) corresponding to the second data plaintext m2 uploaded by the second data party.

[0124] In S430, the first computing node 100 adds a third perturbation r1 to the first ciphertext Enc(m1) to obtain a first perturbed ciphertext Enc(m1)+r1, and adds a fourth perturbation r2 to the second ciphertext Enc(m2) to obtain a second perturbed ciphertext Enc(m2)+r2, where the third perturbation r1 and the fourth perturbation r2 can be random numbers or random polynomials.

[0125] In S440, the first computing node 100 sends the first perturbed ciphertext Enc(m1)+r1 and the second perturbed ciphertext Enc(m2)+r2 to the second computing node 200.

[0126] In S450, the second computing node 200 decrypts the first perturbed ciphertext Enc(m1)+r1 to obtain a first decrypted data m1+r1, and decrypts the second perturbed ciphertext Enc(m2)+r2 to obtain a second decrypted data m2+r2. Specifically, the first decrypted data m1+r1 is obtained by calculating Dec(Enc(m1)+r1), and the second decrypted data m2+r2 is obtained by calculating Dec(Enc(m2)+r2), where Dec() is the inverse process of the encryption algorithm Enc(), and can also be called the decryption algorithm corresponding to the encryption algorithm Enc().

[0127] In S460, the specific process can be Figure 5 The steps shown:

[0128] S510: The second computing node 200 calculates a second product m, where the second product m is the product of the first decrypted data m1 + r1 and the second decrypted data m2 + r2.

[0129] That is, the second product m = (m1 + r1) ° (m2 + r2).

[0130] S520: The second computing node 200 encrypts the second product m to obtain the encrypted second product m'.

[0131] That is, the encrypted second product m' = Enc(m).

[0132] S530: The second computing node 200 sends the encrypted second product m' to the first computing node 100. Correspondingly, the first computing node 100 receives the encrypted second product m' sent by the second computing node 200.

[0133] S540: The first computing node 100 performs a de-scrambling process on the encrypted second product m' to obtain the target ciphertext M.

[0134] As Figure 5 shown, S540 may specifically include the following steps:

[0135] S5401: The first computing node 100 calculates a first de-scrambling term Q1 = r1 ° Enc(m2), a second de-scrambling term Q2 = r2 ° Enc(m1), and a third de-scrambling term Q3 = r1 ° r2.

[0136] S5402: The first computing node 100 calculates the target ciphertext M based on the encrypted second product m', the first de-scrambling term Q1, the second de-scrambling term Q2, and the third de-scrambling term Q3.

[0137] Specifically, the target ciphertext M = Enc(m - Q3) - Q1 - Q2 = Enc(m - r1 ° r2) - r1 ° Enc(m2) - r2 ° Enc(m1).

[0138] The calculated target ciphertext M = Enc(m1 ° m2).

[0139] Example 2: Taking the CKKS as the fully homomorphic encryption algorithm and taking the method of adding the ciphertext and the perturbation as the way of perturbing the ciphertext:

[0140] In S410, the first computing node 100 receives the first ciphertext Enc(Δm1) corresponding to the first data plaintext m1 uploaded by the first data party, where Δ is the scaling factor in CKKS, and Enc() is the fully homomorphic encryption algorithm CKKS.

[0141] In S420, the first computing node 100 receives the second ciphertext Enc(Δm2) corresponding to the second plaintext m2 uploaded by the second data party.

[0142] In S430, the first computing node 100 adds a fifth perturbation t1 to the first ciphertext Enc(Δm1) to obtain a first perturbed ciphertext Enc(Δm1)+t1, and adds a sixth perturbation t2 to the second ciphertext Enc(Δm2) to obtain a second perturbed ciphertext Enc(Δm2)+t2.

[0143] In S440, the first computing node 100 sends the first perturbed ciphertext Enc(Δm1)+t1 and the second perturbed ciphertext Enc(Δm2)+t2 to the second computing node 200.

[0144] The above-mentioned fifth perturbation t1 = r1°P + e, and the sixth perturbation t2 = r2°P + e′, where P is a random polynomial, and each element in P is greater than Δ 2 m1°m2, to ensure that the finally calculated target ciphertext M is equal to the encrypted first product, e is the noise of the first ciphertext Enc(Δm1), and e′ is the noise of the second ciphertext Enc(Δm2).

[0145] In S450, the second computing node 200 decrypts the first perturbed ciphertext Enc(Δm1)+t1 to obtain the first decrypted data Δm1 + t1, and decrypts the second perturbed ciphertext Enc(Δm2)+t2 to obtain the second decrypted data Δm2 + t2. Specifically, the first decrypted data Δm1 + t1 is obtained by calculating Dec(Enc(Δm1)+t1), and the second decrypted data Δm2 + t2 is obtained by calculating Dec(Enc(Δm2)+t2), where Dec() is the inverse process of the encryption algorithm Enc(), and can also be called the decryption algorithm corresponding to the encryption algorithm Enc().

[0146] In S460, the specific process can be Figure 6 the steps shown:

[0147] S601: The second computing node 200 calculates the second product m, and the second product m is the product of the first decrypted data Δm1 + t1 and the second decrypted data Δm2 + t2.

[0148] That is, the second product m = (Δm1 + t1)°(Δm2 + t2).

[0149] S602: The second computing node 200 calculates the first sum A1, and the first sum A1 is the sum of the second product m and the square of the first perturbation t3.

[0150] That is, the first sum A1 = m + Δ 2t3 = (Δm1 + t1) ° (Δm2 + t2) + Δ 2 t3.

[0151] S603: The second computing node 200 sends the first sum A1 to the first computing node 100. Correspondingly, the first computing node 100 receives the first sum A1 sent by the second computing node 200.

[0152] S604: The first computing node 100 performs a modulo operation and a shift operation on the first sum A1 to obtain a processing result A1'. The processing result A1' is equal to the sum of the first product Δm1 ° m2 and the first perturbation Δt3.

[0153] That is, the processing result A1' = (A1 mod P) >>> Δ = Δm1 ° m2 + Δt3.

[0154] S605: The first computing node 100 calculates a second sum A2. The second sum A2 is the sum of the processing result A1' and the second perturbation Δt4.

[0155] That is, the second sum A2 = A1' + Δt4 = Δm1 ° m2 + Δt3 + Δt4.

[0156] S606: The first computing node 100 sends the second sum A2 to the second computing node 200. Correspondingly, the second computing node 200 receives the second sum A2 sent by the first computing node 100.

[0157] S607: The second computing node 200 calculates a first difference D1. The first difference D1 is the difference between the second sum A2 and the first perturbation Δt3.

[0158] That is, the first difference D1 = A2 - Δt3 = Δm1 ° m2 + Δt3 + Δt4 - Δt3 = Δm1 ° m2 + Δt4.

[0159] S608: The second computing node 200 encrypts the first difference D1 to obtain the encrypted first difference Enc(D1).

[0160] That is, the encrypted first difference Enc(D1) = Enc(Δm1 ° m2 + Δt4).

[0161] S609: The second computing node 200 sends the encrypted first difference Enc(D1) to the first computing node 100. Correspondingly, the first computing node 100 receives the encrypted first difference Enc(D1) sent by the second computing node 200.

[0162] S610: The first computing node 100 calculates the target ciphertext M. The target ciphertext M is the difference between the encrypted first difference Enc(D1) and the second perturbation Δt4.

[0163] That is, the target ciphertext M = Enc(D1) - Δt4 = Enc(Δm1 ° m2 + Δt4) - Δt4.

[0164] The calculated target ciphertext M == Enc(Δm1 ° m2).

[0165] It should be noted that Example 1 and Example 2 are only examples of the fully homomorphic encryption method provided by this application and should not be regarded as specific limitations.

[0166] It can be seen that in the above solution, the second computing node 200 decrypts the fully homomorphic encryption ciphertext after perturbation processing, rather than the original fully homomorphic encryption ciphertext of the participant. Therefore, the decryption data obtained by the second computing node 200 decrypting the fully homomorphic encryption ciphertext after perturbation processing is different from the original data plaintext of the participant. Even if the first computing node 100 and the second computing node 200 are subject to side-channel attacks, the attacker can only steal the decryption data different from the original data plaintext and cannot steal the original data plaintext, thus avoiding the leakage of the original data plaintext and better protecting data security.

[0167] In addition, since the second computing node 200 cooperates with the first computing node 100 to calculate the target ciphertext equal to the product of the encrypted original data plaintext on the basis of decrypting the data, unlike the existing fully homomorphic encryption optimization method based on trusted hardware, which performs multiplication calculation on the basis of the original data plaintext to obtain the plaintext product and then encrypts it, even if the first computing node 100 and the second computing node 200 are subject to side-channel attacks, the attacker cannot steal the plaintext product, thus avoiding the leakage of the plaintext product and better protecting data security.

[0168] Furthermore, it can be understood that the first computing node and the second computing node are virtual machines or containers, and virtual machines and containers are software. That is to say, in this application, users can implement fully homomorphic encryption with the help of software. Compared with the existing fully homomorphic encryption optimization method based on trusted hardware, since the development cycle of trusted hardware is usually relatively long, this results in a relatively high cost of trusted hardware, and users need to spend a relatively high cost to purchase trusted hardware to implement fully homomorphic encryption, which can help users save costs.

[0169] As can be seen from the above introduction to the fully homomorphic encryption system, the first computing node 100 can be deployed in the TEE or in an untrusted execution environment. It can be understood that if the first computing node 100 is deployed in the TEE, due to the high security of the TEE, compared with the first computing node 100 being deployed in an untrusted execution environment, the risk of the data received and processed by the first computing node 100 being stolen can be reduced, and data security can be better protected.

[0170] As can also be seen from the above introduction to the fully homomorphic encryption system, the first computing node 100 and the second computing node 200 can be implemented by the same computing device or by different computing devices. It can be understood that when the first computing node 100 and the second computing node 200 are implemented by the same computing device, the communication distance between the first computing node 100 and the second computing node 200 is shorter, the communication duration is shorter, and the encryption efficiency will be higher.

[0171] It can be understood that in specific implementation, if there are security risks in the second computing node 200 before executing Figure 4 the fully homomorphic encryption method shown, it may affect Figure 4 the execution process of the fully homomorphic encryption method shown or the data involved in the execution process (such as the above-mentioned first perturbed ciphertext, second perturbed ciphertext, first decrypted data, second decrypted data). For example, if the second computing node 200 is controlled by an attacker and the first perturbed ciphertext is tampered with, in order to ensure Figure 4 the safe and accurate execution of the fully homomorphic encryption method shown, the second computing node 200 needs to be secure and trustworthy. Therefore, before executing Figure 4 the fully homomorphic encryption method shown, the second computing node 200 can be authenticated. When the authentication of the second computing node 200 passes (that is, the second computing node 200 is authenticated to be secure and trustworthy), then the public key and private key for fully homomorphic encryption are sent to the second computing node, and the second computing node 200 is allowed to execute Figure 4 the corresponding steps in the fully homomorphic encryption method shown, which can improve the security and accuracy of the method. In addition, the security of the private key can also be protected, and the security of the data that needs to be decrypted with the private key can be improved.

[0172] It can also be understood that in specific implementation, if there are security risks in the first computing node 100 before executing Figure 4 the fully homomorphic encryption method shown, it may affect Figure 4 the execution process of the fully homomorphic encryption method shown or the data involved in the execution process (such as the above-mentioned first ciphertext, second ciphertext, first perturbed ciphertext, second perturbed ciphertext). For example, if the first computing node 100 is controlled by an attacker and the first perturbed ciphertext is tampered with, in order to ensure Figure 4 the safe and accurate execution of the fully homomorphic encryption method shown, the first computing node 100 needs to be secure and trustworthy. Therefore, before executing Figure 4 the fully homomorphic encryption method shown, the first computing node 100 can be authenticated. When the authentication of the first computing node 100 passes (that is, the first computing node 100 is authenticated to be secure and trustworthy), then the first computing node 100 is allowed to execute Figure 4 the fully homomorphic encryption method shown, which can improve the security and accuracy of the method.

[0173] The following introduces the detailed process of authenticating the second computing node 200 and the first computing node 100:

[0174] Before sending the public key and private key pair to the second computing node 200, the above-mentioned key generation device 300 may first send a first authentication request to the second computing node 200 to request the authentication information of the second computing node 200. After receiving the authentication information of the second computing node 200 returned by the second computing node 200 based on the first authentication request, authenticate the second computing node 200. If the authentication of the second computing node 200 passes (i.e., the second computing node 200 is authenticated as secure and trustworthy), send the public key and private key pair to the second computing node 200; otherwise, do not send the public key and private key pair to the second computing node 200.

[0175] Before uploading the ciphertext (such as the first ciphertext and the second ciphertext) to the first computing node 100, the above-mentioned data party (such as the first data party and the second data party) may send an authentication request to the first computing node 100 through the held terminal device to request the authentication information of the first computing node 100. Then, authenticate the first computing node 100 based on the authentication information of the first computing node 100. If the authentication of the first computing node 100 passes (i.e., the first computing node 100 is authenticated as secure and trustworthy), send the corresponding ciphertext to the first computing node 100; otherwise, do not send the corresponding ciphertext to the first computing node 100.

[0176] Taking the computing node as a virtual machine as an example, the authentication information of the above-mentioned computing node (such as the authentication information of the first computing node 100 and the authentication information of the second computing node 200) may include the current measurement value of the configuration of the virtual machine and the historical measurement value of the configuration of the virtual machine. Optionally, the authentication information of the above-mentioned virtual machine may include the certificate of the virtual machine (which may also be a certificate chain), and the historical measurement value of the configuration of the virtual machine may be carried in the certificate of the virtual machine. Among them, the configuration of the virtual machine may include the virtual processor core type, the number of virtual processor cores, the memory address, the name and version of the application (APP) installed on the virtual machine, and the image of the virtual machine, etc.; the measurement value of the configuration is used to measure whether the configuration of the virtual machine has been tampered with. For example, compare the current number of virtual processor cores with the historical number of virtual processor cores recorded in the certificate. If they are the same, it means that the number of virtual processor cores has not been tampered with; otherwise, it means that the number of virtual processor cores has been tampered with (increased or decreased). Another example is to compare the current hash value of the image of the virtual machine with the historical hash value of the image of the virtual machine recorded in the certificate. If they are the same, it means that the image has not been tampered with; otherwise, it means that the image has been tampered with. In this application, the configuration of the virtual machine being tampered with can be understood as the virtual machine being attacked and the virtual machine being insecure and untrustworthy.

[0177] Optionally, the authentication information of the above virtual machine may include the identity information of the virtual machine, which is used to uniquely identify and recognize the virtual machine. The identity information of the virtual machine may include the name of the virtual machine, universally unique identifier (UUID), media access control address (MAC address), operating system information (such as operating system type, version number), virtual hardware information (such as the number of central processing unit (CPU) cores, memory size, disk capacity, device configuration, etc.). Optionally, the certificate of the above virtual machine also includes the identity information provided when the virtual machine applies for the certificate, the validity period of the certificate, the issuing authority of the certificate, the digital signature of the certificate, etc.

[0178] Taking the computing node as a container as an example, to authenticate the computing node, it can be to authenticate the virtual machine to which the container belongs. This process can refer to the above authentication process of the virtual machine. For the sake of simplicity of the specification, it will not be elaborated here. Optionally, it can also be to authenticate the container itself. The authentication information of the above computing node may include the current measurement value of the container's configuration and the historical measurement value of the container's configuration. Optionally, the authentication information of the above container may include the certificate of the container (which can also be a certificate chain). The historical measurement value of the container's configuration can be carried in the certificate of the container. Among them, the configuration of the container can include the memory address, the name and version of the APP installed on the container, and the image of the container, etc.; the measurement value of the configuration is used to measure whether the configuration of the container has been tampered with. For example, comparing the current memory address with the historical memory address recorded in the certificate. If they are the same, it means the memory address has not been tampered with. Otherwise, it means the memory address has been tampered with. Another example is comparing the current hash value of the container's image with the historical hash value of the container's image recorded in the certificate. If they are the same, it means the image has not been tampered with. Otherwise, it means the image has been tampered with. In this application, the configuration of the container being tampered with can be understood as the container being attacked and the container being insecure and untrusted.

[0179] Optionally, the authentication information of the above container may include the identity information of the container, which is used to uniquely identify and recognize the container. Optionally, the certificate of the above container also includes the identity information provided when the container applies for the certificate, the validity period of the certificate, the issuing authority of the certificate, the digital signature of the certificate, etc.

[0180] Taking the authentication of the second computing node 200 by the key generation device 300 as an example, specifically, after receiving the authentication information of the second computing node 200, the key generation device 300 can authenticate the legality and integrity of the certificate of the second computing node 200. For example, it determines whether the certificate is valid according to the validity period of the certificate, determines whether the issuing authority of the certificate is a legal institution, and determines whether the certificate has been tampered with according to the digital signature of the certificate. When it is determined that the certificate is legal and complete, it determines whether the second computing node 200 is secure and trustworthy by checking the current measurement value and the certificate of the configuration of the second computing node 200, and / or by checking whether the identity information of the second computing node 200 matches the identity information recorded in the certificate.

[0181] In a possible embodiment, the above fully homomorphic encryption system can also implement the ciphertext addition operation in fully homomorphic encryption. For example, the first computing node 100 obtains the third ciphertext and the fourth ciphertext that need to perform the fully homomorphic addition operation, and then calculates the third sum (i.e., the sum of the third ciphertext and the fourth ciphertext). The third sum is equal to the encrypted fourth sum, and the fourth sum is the sum of the third data plaintext (which can also be referred to as the third data) and the fourth data plaintext (which can also be referred to as the fourth data). The third data plaintext is the data plaintext corresponding to the third ciphertext, and the fourth data plaintext is the data plaintext corresponding to the fourth ciphertext. That is to say, the third ciphertext is obtained by performing fully homomorphic encryption on the third data plaintext, and the fourth ciphertext is obtained by performing fully homomorphic encryption on the fourth data plaintext. Another example is that the first computing node 100 obtains the third ciphertext and the fourth ciphertext, and then sends the third ciphertext and the fourth ciphertext to the second computing node 200, and the second computing node 200 calculates the third sum that is equal to the encrypted fourth sum.

[0182] The method of the embodiment of the present application has been elaborated in detail above. To facilitate better implementation of the above solutions of the embodiment of the present application, correspondingly, the following also provides relevant devices and equipment for cooperating to implement the above solutions.

[0183] See Figure 7 , Figure 7 is a schematic structural diagram of a fully homomorphic encryption device 700 provided by an embodiment of the present application. This device 700 can be applied to the above-mentioned first computing node 100. As Figure 7 shown, the device 700 includes: an acquisition module 701, a perturbation processing module 702, a sending module 703, and a collaborative computing module 704.

[0184] Next, the functions of each module of the fully homomorphic encryption device 700 will be introduced exemplarily. It should be understood that the functions of each module described by way of example below are only the functions that the fully homomorphic encryption device 700 can have in some embodiments of the present application, and the present application does not limit the functions of each module.

[0185] An acquisition module 701, configured to acquire a first ciphertext and a second ciphertext, where the first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data.

[0186] A perturbation processing module 702, configured to perform perturbation processing on the first ciphertext to obtain a first perturbed ciphertext, and perform perturbation processing on the second ciphertext to obtain a second perturbed ciphertext.

[0187] A sending module 703, configured to send the first perturbed ciphertext and the second perturbed ciphertext to a second computing node 200.

[0188] A collaborative computing module 704, configured to collaborate with the second computing node 200 to perform a calculation based on first decrypted data and second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, the first product is the product of the first data and the second data, the first decrypted data is obtained by the second computing node 200 decrypting the first perturbed ciphertext, and the second decrypted data is obtained by the second computing node 200 decrypting the second perturbed ciphertext.

[0189] In some possible implementation manners, the above-mentioned first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm, the above-mentioned second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm, or, the above-mentioned first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the above-mentioned second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm.

[0190] In some possible implementation manners, when the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm, the above-mentioned collaborative computing module 704 is specifically configured to: receive the encrypted second product sent by the second computing node 200, and then perform de-perturbation processing on the encrypted second product to obtain the target ciphertext, where the second product is the product of the first decrypted data and the second decrypted data.

[0191] In some possible embodiments, the obtaining module 701 is configured to receive a second authentication request sent by a first terminal device and a third authentication request sent by a second terminal device, where the second authentication request and the third authentication request are used to obtain authentication information of the second computing node 200; the sending module 703 is configured to send the authentication information of the first computing node 100 to the first terminal device based on the second authentication request and send the authentication information of the first computing node 100 to the second terminal device based on the third authentication request; the obtaining module 701 is configured to receive a first ciphertext sent by the first terminal device when the first computing node 100 is authenticated to pass based on the authentication information of the first computing node 100, and receive a second ciphertext sent by the second terminal device when the first computing node 100 is authenticated to pass based on the authentication information of the first computing node 100.

[0192] The obtaining module 701, the perturbation processing module 702, the sending module 703, and the collaborative computing module 704 in all the above possible embodiments can be implemented by software or by hardware. Exemplarily, taking the obtaining module 701 as an example, the implementation manner of the obtaining module 701 will be introduced below. Similarly, the implementation manners of the perturbation processing module 702, the sending module 703, and the collaborative computing module 704 can refer to the implementation manner of the obtaining module 701.

[0193] As an example of a software functional unit, the obtaining module 701 may include a program running on a computing instance. Wherein, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container.

[0194] As an example of a hardware functional unit, the obtaining module 701 may be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Wherein, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0195] See Figure 8 , Figure 8 is a schematic structural diagram of a fully homomorphic encryption device 800 provided by an embodiment of the present application. The device 800 may be applied to the above-mentioned second computing node 200, such as Figure 8As shown, the device 800 includes: a receiving module 801, a decryption module 802, and a collaborative computing module 803.

[0196] The functions of each module of the fully homomorphic encryption device 800 will be introduced exemplarily below. It should be understood that the functions of each module described by way of example below are only the functions that the fully homomorphic encryption device 800 may have in some embodiments of the present application, and the present application does not limit the functions of each module.

[0197] The receiving module 801 is configured to receive a first perturbed ciphertext and a second perturbed ciphertext sent by the first computing node 100. The first perturbed ciphertext is obtained by the first computing node 100 performing a perturbation process on the first ciphertext, and the second ciphertext is obtained by the first computing node 100 performing a perturbation process on the second ciphertext. The first ciphertext is obtained by performing fully homomorphic encryption on the first data, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data.

[0198] The decryption module 802 is configured to decrypt the first perturbed ciphertext to obtain first decrypted data, and decrypt the second perturbed ciphertext to obtain second decrypted data.

[0199] The collaborative computing module 803 is configured to collaborate with the first computing node 100 to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, and the first product is the product of the first data and the second data.

[0200] In some possible implementation manners, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm. Alternatively, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm.

[0201] In some possible implementation manners, in the case where the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm, the collaborative computing module 803 is specifically configured to: calculate and encrypt a second product to obtain the encrypted second product, where the second product is the product of the first decrypted data and the second decrypted data; send the encrypted second product to the first computing node 100, and the encrypted second product is used by the first computing node 100 to obtain the target ciphertext.

[0202] In some possible implementation manners, such as Figure 8As shown, the above-mentioned device 800 further includes a sending module 804; a receiving module 801, configured to receive a first authentication request sent by a key generation device 300, where the key generation device 300 is configured to generate a public key and a private key pair for fully homomorphic encryption, and the first authentication request is used to obtain authentication information of a second computing node 200; a sending module 804, configured to send the authentication information of the second computing node 200 to the key generation device 300 based on the first authentication request; a receiving module 801, configured to receive the public key and the private key sent by the key generation device 300 when the second computing node 200 is authenticated as passed based on the authentication information of the second computing node 200.

[0203] The receiving module 801, the decryption module 802, the collaborative computing module 803, and the sending module 804 in all the above possible implementation manners can be implemented by software. For example, each module may include a program running on a computing instance. Among them, the computing instance may include at least one of a virtual machine and a container.

[0204] Specifically, for the specific implementation of the above-mentioned fully homomorphic encryption device 700 and fully homomorphic encryption device 800 to perform various operations, reference may be made to the description in the relevant content of the above-mentioned fully homomorphic encryption method embodiment. For the sake of simplicity of the specification, it will not be elaborated here.

[0205] See Figure 9 , Figure 9 is a schematic structural diagram of a computing device 900 provided by an embodiment of the present application. The computing device 900 includes: a processor 910, a memory unit 920, a communication interface 930, a memory 940, an input device 950, and an output device 960. Among them, the processor 910, the memory unit 920, the communication interface 930, the memory 940, the input device 950, and the output device 960 can be interconnected through a bus 970.

[0206] Among them,

[0207] The processor 910 can read the program code (including instructions) stored in the memory unit 920 and execute the program code stored in the memory unit 920, so that the computing device 900 executes the steps performed by the first computing node 100 and / or the second computing node 200 in the fully homomorphic encryption method provided in the above method embodiment.

[0208] The processor 910 may have various specific implementation forms. For example, the processor 910 may be at least one CPU, such as Figure 9As shown, including CPU0 and CPU1, the processor 910 can also be a graphics processing unit (GPU), etc. The processor 910 can also be a single-core processor or a multi-core processor. The processor 910 can be a combination of a CPU and a hardware chip. The above hardware chip can be implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The above PLD can be implemented by a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 910 can also be implemented by a logic device with built-in processing logic alone, such as an FPGA or a digital signal processor (DSP), etc.

[0209] The memory unit 920 is used to store kernels, program codes, and program data generated when the processor 910 executes the program codes stored in the memory unit 920.

[0210] When the computing device 900 is used to execute the steps performed by the first computing node 100 in the fully homomorphic encryption method provided in the above method embodiment, the program codes stored in the memory unit 920 include: the code of the acquisition module 701, the code of the perturbation processing module 702, the code of the sending module 703, the code of the collaborative computing module 704, etc. The program data stored in the memory unit 920 includes: the first ciphertext, the second ciphertext, the first perturbed ciphertext, the second perturbed ciphertext, etc.

[0211] When the computing device 900 is used to execute the steps performed by the second computing node 200 in the fully homomorphic encryption method provided in the above method embodiment, the program codes stored in the memory unit 920 include: the code of the receiving module 801, the code of the decryption module 802, the code of the collaborative computing module 803, the code of the sending module 804, etc. The program data stored in the memory unit 920 includes: the first perturbed ciphertext, the second perturbed ciphertext, the first decrypted data, the second decrypted data, etc.

[0212] The communication interface 930 can be a wired interface (such as an Ethernet interface, a fiber optic interface, other types of interfaces (e.g., an InfiniBand (IB) interface)), or a wireless interface (such as a cellular network interface or a wireless local area network interface), for communicating with other computing devices or apparatuses. When the communication interface 930 is a wired interface, the communication interface 930 can adopt a protocol family over the Transmission Control Protocol / Internet Protocol (TCP / IP), such as, for example, the Remote Function Call (RFC) protocol, the Simple Object Access Protocol (SOAP) protocol, the Simple Network Management Protocol (SNMP) protocol, the Common Object Request Broker Architecture (CORBA) protocol, and distributed protocols, etc.

[0213] The memory 940 can be a non-volatile memory, such as, for example, a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable Programmable ROM (EPROM), an Electrically Erasable Programmable ROM (EEPROM), or a flash memory. The memory 940 can also be a volatile memory, and the volatile memory can be a Random Access Memory (RAM), which is used as an external cache.

[0214] The input device 950 can include a mouse, a keyboard, and so on. A user can input data or instructions to the computing device 900 through the input device 950.

[0215] The output device 960 may include a display, and the computing device 900 may provide data to the user through the display. The display may include a cathode ray tube (CRT) display, a plasma display panel (PDP), a liquid crystal display (LCD), and so on. Taking the LCD as an example, the liquid crystal display includes a liquid crystal panel and a backlight module. Among them, the liquid crystal display panel includes a polarizing film, a glass substrate, a black matrix, a color filter, a protective film, a common electrode, an alignment layer, a liquid crystal layer (liquid crystal, spacer, sealant), a capacitor, a display electrode, a prism layer, and a diffuser layer. The backlight module includes: a lighting source, a reflector, a light guide plate, a diffuser, a brightness enhancement film (prism sheet), and a frame, etc.

[0216] The bus 970 may be a high-speed serial computer expansion bus standard (Peripheral Component Interconnect Express, PCIE) or an Extended Industry Standard Architecture (EISA) bus, etc. The above bus 970 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 9 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0217] It should be understood that the computing device 900 in the embodiments of the present application may correspond to the computing device including the fully homomorphic encryption device 700 and / or the fully homomorphic encryption device 800 in the embodiments of the present application, and may correspond to the execution of the Figure 4 、 Figure 5 、 Figure 6 corresponding main body in the method shown, and the operations and / or functions of each module in the computing device 900 are respectively for implementing Figure 4 、 Figure 5 、 Figure 6 the corresponding processes of the method shown. For the sake of brevity, they will not be elaborated here.

[0218] It should be understood that the computing device 900 is only an example provided in the embodiments of the present application, and, the computing device 900 may have more or fewer components than Figure 9 the components shown, may combine two or more components, or may have different configurations of components to implement.

[0219] The embodiments of the present application further provide a fully homomorphic encryption system, and the system may include the above-mentioned fully homomorphic encryption device 700 and fully homomorphic encryption device 800.

[0220] An embodiment of the present application further provides a computer-readable storage medium. Instructions are stored in the computer-readable storage medium, and when the instructions are run, some or all of the steps of the fully homomorphic encryption method described in the above embodiments can be implemented.

[0221] An embodiment of the present application further provides a computer program product. When the computer program product is read and executed by a computer, some or all of the steps of the fully homomorphic encryption method described in the above method embodiments can be implemented.

[0222] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0223] In the above embodiments, it can be implemented in whole or in part by software, hardware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium, or a semiconductor medium, etc.

[0224] The above is only the specific implementation manner of the present application. Those skilled in the art of this technology can think of variations or substitutions according to the specific implementation manner provided by the present application, and all should be covered within the protection scope of the present application.

Claims

1. A fully homomorphic encryption system, characterized in that, The system includes a first computing node and a second computing node, and the second computing node is deployed in a first trusted execution environment (TEE). The first computing node is configured to obtain a first ciphertext and a second ciphertext. The first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data. The first computing node is configured to send a first perturbed ciphertext and a second perturbed ciphertext to the second computing node. The first perturbed ciphertext is obtained by perturbing the first ciphertext, and the second perturbed ciphertext is obtained by perturbing the second ciphertext. The second computing node is configured to decrypt the first perturbed ciphertext to obtain first decrypted data and decrypt the second perturbed ciphertext to obtain second decrypted data. The second computing node is configured to cooperate with the first computing node to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, and the first product is the product of the first data and the second data.

2. The system according to claim 1, characterized in that, The first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm. Alternatively, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm.

3. The system according to claim 2, wherein In the case where the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm The second computing node is configured to calculate and encrypt a second product to obtain the encrypted second product, where the second product is the product of the first decrypted data and the second decrypted data. The second computing node is configured to send the encrypted second product to the first computing node. The first computing node is configured to perform a de-perturbation process on the encrypted second product to obtain the target ciphertext.

4. The system according to claim 2, wherein In the case where the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm The second computing node is configured to calculate a second product, where the second product is the product of the first decrypted data and the second decrypted data. The second computing node is configured to calculate a first sum and send it to the first computing node. The first sum is the sum of the second product and the square of the first perturbation. The first computing node is configured to perform a modulo operation and a shift operation on the first sum to obtain a processing result, where the processing result is equal to the sum of the first product and the first perturbation. The first computing node is configured to calculate a second sum and send it to the second computing node. The second sum is the sum of the processing result and the second perturbation. The second computing node is configured to calculate a first difference, where the first difference is the difference between the second sum and the first perturbation. The second computing node is configured to encrypt the first difference to obtain the encrypted first difference, and send the encrypted first difference to the first computing node; The first computing node is configured to calculate the target ciphertext, where the target ciphertext is the difference between the encrypted first difference and the second perturbation.

5. The system according to any one of claims 1 to 4, wherein The second computing node is configured to receive a first authentication request sent by a key generation device, where the key generation device is configured to generate a public and private key pair for fully homomorphic encryption, and the first authentication request is used to obtain authentication information of the second computing node; The second computing node is configured to send the authentication information of the second computing node to the key generation device based on the first authentication request; The second computing node is configured to receive the public key and the private key sent by the key generation device when the second computing node is authenticated to pass based on the authentication information of the second computing node.

6. The system according to any one of claims 1 to 5, wherein The first computing node is configured to receive a second authentication request sent by a first terminal device and a third authentication request sent by a second terminal device, where the second authentication request and the third authentication request are used to obtain authentication information of the second computing node; The first computing node is configured to send the authentication information of the first computing node to the first terminal device based on the second authentication request, and send the authentication information of the first computing node to the second terminal device based on the third authentication request; The first computing node is configured to receive the first ciphertext sent by the first terminal device when the first computing node is authenticated to pass based on the authentication information of the first computing node, and receive the second ciphertext sent by the second terminal device when the first computing node is authenticated to pass based on the authentication information of the first computing node.

7. The system according to any one of claims 1 to 6, wherein The first computing node is a first virtual machine, and the second computing node is a second virtual machine; Or, the first computing node is a first container, and the second computing node is a second container; Or, the first computing node is the first virtual machine, and the second computing is the second container, and the second container does not belong to the first virtual machine; Or, the first computing node is the first container, and the second computing node is the second virtual machine, and the first container does not belong to the second virtual machine.

8. The system according to claim 7, characterized in that, The first computing node is deployed in the first TEE or the second TEE.

9. A fully homomorphic encryption method, characterized in that, Applied to a first computing node, the method includes: The first computing node obtains a first ciphertext and a second ciphertext, where the first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data; The first computing node sends a first perturbed ciphertext and a second perturbed ciphertext to the second computing node. The first perturbed ciphertext is obtained by perturbing the first ciphertext, and the second perturbed ciphertext is obtained by perturbing the second ciphertext. The second computing node is deployed in the first TEE; The first computing node collaborates with the second computing node to perform calculations based on the first decrypted data and the second decrypted data to obtain a target ciphertext. The target ciphertext is equal to the encrypted first product, where the first product is the product of the first data and the second data. The first decrypted data is obtained by the second computing node decrypting the first perturbed ciphertext, and the second decrypted data is obtained by the second computing node decrypting the second perturbed ciphertext.

10. The method according to claim 9, characterized in that, The first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm. Alternatively, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm.

11. The method according to claim 10, characterized in that, In the case where the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm, the first computing node collaborates with the second computing node to perform calculations based on the first decrypted data and the second decrypted data to obtain a target ciphertext, including: The first computing node receives the encrypted second product sent by the second computing node, where the second product is the product of the first decrypted data and the second decrypted data; The first computing node performs de-perturbation processing on the encrypted second product to obtain the target ciphertext.

12. The method according to any one of claims 9 to 11, wherein The first computing node is a first virtual machine, and the second computing node is a second virtual machine; Or, the first computing node is a first container, and the second computing node is a second container; Or, the first computing node is the first virtual machine, and the second computing is the second container, and the second container does not belong to the first virtual machine; Or, the first computing node is the first container, and the second computing node is the second virtual machine, and the first container does not belong to the second virtual machine.

13. The method according to claim 12, characterized in that, The first computing node is deployed in the first TEE or the second TEE.

14. A fully homomorphic encryption method, characterized in that, Applied to the second computing node, the second computing node is deployed in the first TEE, the method includes: The second computing node receives the first perturbed ciphertext and the second perturbed ciphertext sent by the first computing node. The first perturbed ciphertext is obtained by the first computing node perturbing the first ciphertext, and the second ciphertext is obtained by the first computing node perturbing the second ciphertext. The first ciphertext is obtained by performing fully homomorphic encryption on the first data, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data; The second computing node decrypts the first perturbed ciphertext to obtain first decrypted data, and decrypts the second perturbed ciphertext to obtain second decrypted data; The second computing node cooperates with the first computing node to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, and the first product is the product of the first data and the second data.

15. The method according to claim 14, characterized in that The first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the CKKS algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the CKKS algorithm. Alternatively, the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm.

16. The method according to claim 15, wherein In the case where the first ciphertext is obtained by performing fully homomorphic encryption on the first data according to the BGV algorithm, and the second ciphertext is obtained by performing fully homomorphic encryption on the second data according to the BGV algorithm, the second computing node cooperates with the first computing node to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, including: The second computing node calculates and encrypts a second product to obtain the encrypted second product, where the second product is the product of the first decrypted data and the second decrypted data; The second computing node sends the encrypted second product to the first computing node, and the encrypted second product is used by the first computing node to obtain the target ciphertext.

17. The method according to any one of claims 14 to 16, wherein the first computing node is a first virtual machine, and the second computing node is a second virtual machine; alternatively, the first computing node is a first container, and the second computing node is a second container; alternatively, the first computing node is the first virtual machine, and the second computing is the second container, and the second container does not belong to the first virtual machine; alternatively, the first computing node is the first container, and the second computing node is the second virtual machine, and the first container does not belong to the second virtual machine.

18. A fully homomorphic encryption device, characterized in that Applied to a first computing node, the apparatus includes: an acquisition module, configured to acquire a first ciphertext and a second ciphertext, where the first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data; a perturbation processing module, configured to perform perturbation processing on the first ciphertext to obtain a first perturbed ciphertext, and perform perturbation processing on the second ciphertext to obtain a second perturbed ciphertext; a sending module, configured to send the first perturbed ciphertext and the second perturbed ciphertext to a second computing node, where the second computing node is deployed in a first TEE; A collaborative computing module, configured to collaborate with the second computing node to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, the first product is the product of the first data and the second data, the first decrypted data is obtained by the second computing node decrypting the first perturbed ciphertext, and the second decrypted data is obtained by the second computing node decrypting the second perturbed ciphertext.

19. A fully homomorphic encryption device, characterized in that, Applied to a second computing node, the second computing node is deployed in a first TEE, and the apparatus includes: A receiving module, configured to receive a first perturbed ciphertext and a second perturbed ciphertext sent by a first computing node, where the first perturbed ciphertext is obtained by the first computing node performing a perturbation process on a first ciphertext, the second ciphertext is obtained by the first computing node performing a perturbation process on a second ciphertext, the first ciphertext is obtained by performing fully homomorphic encryption on first data, and the second ciphertext is obtained by performing fully homomorphic encryption on second data; A decryption module, configured to decrypt the first perturbed ciphertext to obtain first decrypted data, and decrypt the second perturbed ciphertext to obtain second decrypted data; A collaborative computing module, configured to collaborate with the first computing node to perform a calculation based on the first decrypted data and the second decrypted data to obtain a target ciphertext, where the target ciphertext is equal to the encrypted first product, and the first product is the product of the first data and the second data.

20. A computing device, characterized in that, The computing device includes a processor and a memory, the memory stores code, and the processor executes the code to implement the method according to any one of claims 9 to 17.

21. A computer-readable storage medium, characterized in that, Including computer program instructions, when the computer program instructions are executed by a computing device, the computing device executes the method according to any one of claims 9 to 17.

Citation Information

Cited By

  • Method for verifying coordination consistency of athletes in group project

    CN120389909A