Secure multi-party computing method and device

The MPC agent replaces the computing participants to perform secure multi-party calculations, which solves the problem of trusted third parties distributing random numbers and multiple interactions in the existing technology, and achieves more efficient and flexible secure multi-party calculations.

CN120200766APending Publication Date: 2025-06-24HUAWEI TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311775456.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-21
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing secure multi-party computing solution requires trusted third parties to distribute random numbers, and each calculation requires multiple interactions, resulting in large consumption of communication resources, long transaction time and low computing efficiency.

Method used

By replacing the computing participants with the MPC agent, the MPC agent can prove his innocence and meet the security assumptions of cryptography MPC, and the computing resources can be dynamically configured to achieve more flexible secure multi-party computing.

Benefits of technology

It improves the efficiency of secure multi-party computing, reduces the consumption of communication resources, shortens transaction time, and enhances computing flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200766A_ABST
    Figure CN120200766A_ABST
Patent Text Reader

Abstract

The invention provides a secure multi-party computing method and device, and relates to the field of computing. The method and the device are used for performing secure multi-party calculation through an MPC agent instead of a calculation participant, so that the secure multi-party calculation can be realized more flexibly, and the efficiency of the secure multi-party calculation is improved. The method comprises the steps that a first MPC agent receives a first password from a first CVM, and the first MPC agent derives a first Seed according to the password; the first MPC agent generates a first random number sequence according to the first Seed; the first MPC agent receives first user data from the first CVM and second user data from the second CVM; the first MPC agent performs secure multi-party calculation with the second MPC agent according to the first random number sequence, the first user data, the second user data and the calculation task expression, a second random number sequence of the second MPC agent is the same as the first random number sequence, and a second Seed of the second MPC agent is the same as the first Seed; the second password received by the second MPC agent from the second CVM is the same as the first password.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of computing, and in particular, to a secure multi-party computing method and apparatus. Background Art

[0002] In existing secure multi-party computing solutions, a multi-party computation (MPC) protocol can be directly deployed in a trusted execution environment (TEE) to prevent the MPC execution program from being maliciously tampered with.

[0003] A trusted third party and two trading parties exchanging data are both in a software guard extensions (SGX) environment. The random number splitting module of the trusted third party distributes random numbers to the two trading parties, loads the computing program related to secure multi-party computing into the trusted execution environment; based on the trusted execution environment and other participating parties to mutually verify the integrity of their respective computing programs related to secure multi-party computing; if the integrity verification of the computing program is successful, execute the computing program in the trusted execution environment and interact with other participating parties for the calculation results to complete secure multi-party computing.

[0004] In existing secure multi-party computing solutions, a trusted third party is required to distribute random numbers, and multiple interactions are required for each calculation, consuming a large amount of communication resources, having a long transaction time, and low computing efficiency. Summary of the Invention

[0005] Embodiments of the present application provide a secure multi-party computing method and apparatus, which can use an MPC agent to perform secure multi-party computing on behalf of computing participants, can more flexibly implement secure multi-party computing, and improve the efficiency of secure multi-party computing.

[0006] In a first aspect, embodiments of the present application provide a signal synchronization method, which includes: a first secure multi-party computing (MPC) agent receives a first password from a first user cloud virtual machine (CVM); the first MPC agent derives a first Seed according to the password; the first MPC agent generates a first random number sequence according to the first Seed; the first MPC agent receives first user data from the first CVM and second user data from a second CVM; the first MPC agent performs secure multi-party computing with a second MPC agent according to the first random number sequence, the first user data, the second user data, and a calculation task expression, the second random number sequence of the second MPC agent is the same as the first random number sequence, the second Seed of the second MPC agent is the same as the first Seed, and the second password received by the second MPC agent from the second CVM is the same as the first password.

[0007] In this possible implementation, the MPC agent is used to replace the computing participants in performing secure multi-party computation. The MPC agent module can prove its innocence, better meet the security assumptions of cryptographic MPC, and the computing resources of the MPC agent can be set according to the needs of the computing participants. The computing resources can be dynamically configured, enabling more flexible implementation of secure multi-party computation. At the same time, through the password-based key distribution function, the synchronization of Seed does not require interaction between MPC agents. In the scenario of multiple computing participants, the synchronization between MPC agents can be achieved more efficiently, improving the efficiency of secure multi-party computation.

[0008] In one possible implementation, before the first MPC agent receives the first password from the first user cloud server CVM, the method further includes: the first MPC agent receives a verification request from the first CVM, where the verification request indicates verifying whether the MPC protocol program of the first MPC agent has been tampered with; the first MPC agent sends verification information to the first CVM, where the verification information indicates that the MPC protocol program of the first MPC agent has not been tampered with.

[0009] In this possible implementation, through the verification of the MPC agent, it is determined that the MPC protocol program of the MPC agent has not been tampered with.

[0010] In a second aspect, an embodiment of the present application provides a method for signal synchronization. The method includes: the first user cloud server CVM sends a first password to the first secure multi-party computation MPC agent, where the first password is used for the first MPC agent and the second MPC agent to perform secure multi-party computation; the first CVM sends first user data to the first MPC agent and sends third user data to the second MPC agent, where the first user data and the third user data are used for the first MPC agent and the second MPC agent to perform secure multi-party computation.

[0011] In this possible implementation, the MPC agent is used to replace the computing participants in performing secure multi-party computation. The MPC agent module can prove its innocence, better meet the security assumptions of cryptographic MPC, and the computing resources of the MPC agent can be set according to the needs of the computing participants. The computing resources can be dynamically configured, enabling more flexible implementation of secure multi-party computation. At the same time, through the password-based key distribution function, the synchronization of Seed does not require interaction between MPC agents. In the scenario of multiple computing participants, the synchronization between MPC agents can be achieved more efficiently, improving the efficiency of secure multi-party computation.

[0012] In a possible implementation, before the first CVM sends the first password to the first MPC proxy, the method further includes: the first CVM configures the computing resources of the first MPC proxy; the first CVM starts the first MPC proxy.

[0013] In a possible implementation, after the first CVM starts the first MPC proxy and before the first CVM sends the first password to the first MPC proxy, the method further includes: the first CVM sends a verification request to the first MPC proxy, where the verification request indicates verifying whether the MPC protocol program of the first MPC proxy has been tampered with; the first CVM receives verification information from the first MPC proxy, where the verification information indicates that the MPC protocol program of the first MPC proxy has not been tampered with.

[0014] In this possible implementation, by verifying the MPC proxy, it is determined that the MPC protocol program of the MPC proxy has not been tampered with.

[0015] In a third aspect, an embodiment of the present application provides a secure multi-party computing MPC proxy device. The MPC proxy device is used to implement the method of any item in the first aspect. The MPC proxy device includes: a seed derivation module, a random number generation module, and an MPC execution module, where: the seed derivation module is used to derive a first Seed according to the first password, and the first Seed comes from the first user cloud server CVM; the random number generation module is used to generate a first random number sequence according to the first Seed; the MPC execution module is used to perform secure multi-party computing with a second MPC proxy according to the first random number sequence, the first user data, the second user data, and the calculation task expression. The second random number sequence of the second MPC proxy is the same as the first random number sequence, the second Seed of the second MPC proxy is the same as the first Seed, and the second password received by the second MPC proxy from the second CVM is the same as the first password.

[0016] In a possible implementation, the MPC proxy device further includes a transceiver module, and the transceiver module is used to: receive a verification request from the first CVM, where the verification request indicates verifying whether the MPC protocol program of the first MPC proxy has been tampered with; send verification information to the first CVM, where the verification information indicates that the MPC protocol program of the first MPC proxy has not been tampered with.

[0017] Fourth aspect, an embodiment of the present application provides a user Cloud Virtual Machine (CVM), where the CVM includes a transceiver module and a user data output module, and specifically: The transceiver module is configured to send a first password to a first Secure Multi-Party Computation (MPC) proxy, and the first password is used for the first MPC proxy and the second MPC proxy to perform secure multi-party computation; The user data output module is configured to send first user data to the first MPC proxy and send third user data to the second MPC proxy, and the first user data and the third user data are used for the first MPC proxy and the second MPC proxy to perform secure multi-party computation.

[0018] In a possible implementation, the transceiver module is further configured to: configure the computing resources of the first MPC proxy; start the first MPC proxy.

[0019] In a possible implementation, the transceiver module is further configured to: send a verification request to the first MPC proxy, where the verification request is used to indicate verifying whether the MPC protocol program of the first MPC proxy has been tampered with; receive verification information from the first MPC proxy, where the verification information indicates that the MPC protocol program of the first MPC proxy has not been tampered with.

[0020] Fifth aspect, an embodiment of the present application provides a Secure Multi-Party Computation (MPC) proxy device, where the MPC proxy device includes: a first receiving module, configured to receive a first password from a first user Cloud Virtual Machine (CVM); a derivation module, configured to derive a first Seed according to the password; a generation module, configured to generate a first random number sequence according to the first Seed; a second receiving module, configured to receive first user data from the first CVM and second user data from a second CVM; a computing module, configured to perform secure multi-party computation with a second MPC proxy according to the first random number sequence, the first user data, the second user data, and a computation task expression, where the second random number sequence of the second MPC proxy is the same as the first random number sequence, the second Seed of the second MPC proxy is the same as the first Seed, and the second password received by the second MPC proxy from the second CVM is the same as the first password.

[0021] In a possible implementation, the MPC proxy device further includes: a third receiving module, configured to receive a verification request from the first CVM, where the verification request is used to indicate verifying whether the MPC protocol program of the first MPC proxy has been tampered with; a sending module, configured to send verification information to the first CVM, where the verification information indicates that the MPC protocol program of the first MPC proxy has not been tampered with.

[0022] Sixth aspect, an embodiment of the present application provides a user cloud server. The user cloud server CVM includes: a first sending module, configured to send a first password to a first secure multi-party computing MPC agent, where the first password is used for the first MPC agent and the second MPC agent to perform secure multi-party computing; a second sending module, configured to send first user data to the first MPC agent and send third user data to the second MPC agent, where the first user data and the third user data are used for the first MPC agent and the second MPC agent to perform secure multi-party computing.

[0023] In a possible implementation manner, the CVM further includes: a configuration module, configured to configure the computing resources of the first MPC agent; a starting module, configured to start the first MPC agent.

[0024] In a possible implementation manner, the CVM further includes: a third sending module, configured to send a verification request to the first MPC agent, where the verification request is used to indicate verifying whether the MPC protocol program of the first MPC agent has been tampered with; a receiving module, configured to receive verification information from the first MPC agent, where the verification information indicates that the MPC protocol program of the first MPC agent has not been tampered with.

[0025] Seventh aspect, an embodiment of the present application provides a secure multi-party computing MPC agent device, including: a processor and a memory. The processor is coupled to the memory; the memory is used to store computer instructions, and the computer instructions are loaded and executed by the processor to enable the MPC agent device to implement any method provided in the first aspect.

[0026] Eighth aspect, an embodiment of the present application provides a user cloud server, including: a processor and a memory. The processor is coupled to the memory; the memory is used to store computer instructions, and the computer instructions are loaded and executed by the processor to enable the user cloud server to implement any method provided in the second aspect.

[0027] Ninth aspect, an embodiment of the present application provides a chip, where the chip includes: a processor and an interface circuit; the interface circuit is configured to receive code instructions and transmit them to the processor; the processor is configured to run the code instructions to execute any method provided in the first aspect.

[0028] Tenth aspect, an embodiment of the present application provides a chip, where the chip includes: a processor and an interface circuit; the interface circuit is configured to receive code instructions and transmit them to the processor; the processor is configured to run the code instructions to execute any method provided in the second aspect.

[0029] Eleventh aspect, an embodiment of the present application provides a computer-readable storage medium, where at least one computer program instruction is stored in the computer-readable storage medium, and the computer program instruction is loaded and executed by the processor to implement any method provided in the first aspect as described above.

[0030] In a twelfth aspect, an embodiment of the present application provides a computer-readable storage medium, in which at least one computer program instruction is stored, and the computer program instruction is loaded and executed by a processor to implement any one of the methods provided in the second aspect above.

[0031] In a thirteenth aspect, an embodiment of the present application provides a computer program product, including computer-executable instructions, which when running on a computer, cause the computer to execute any one of the methods provided in the first aspect.

[0032] In a fourteenth aspect, an embodiment of the present application provides a computer program product, including computer-executable instructions, which when running on a computer, cause the computer to execute any one of the methods provided in the second aspect.

[0033] For the technical effects brought by any implementation manner in the third aspect to the fourteenth aspect, reference may be made to the technical effects brought by the corresponding implementation manner in the first aspect or the second aspect, which will not be elaborated here. Description of the Drawings

[0034] Figure 1 It is a schematic diagram of a scenario of a secure multi-party computing method;

[0035] Figure 2 It is a schematic diagram of the architecture of a secure multi-party computing method provided by an embodiment of the present application;

[0036] Figure 3 It is a schematic flowchart of a secure multi-party computing method provided by an embodiment of the present application;

[0037] Figure 4 It is a schematic diagram of a scenario of a secure multi-party computing method provided by an embodiment of the present application;

[0038] Figure 5 It is a schematic diagram of the structure of an MPC proxy device provided by an embodiment of the present application;

[0039] Figure 6 It is a schematic diagram of the structure of a user cloud server provided by an embodiment of the present application;

[0040] Figure 7 It is a schematic diagram of the structure of another MPC proxy device provided by an embodiment of the present application;

[0041] Figure 8 It is a schematic diagram of the structure of another user cloud server provided by an embodiment of the present application;

[0042] Figure 9 It is a schematic diagram of the structure of a secure multi-party computing system provided by an embodiment of the present application. Detailed implementation manners

[0043] In the description of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B. The "and / or" in this application is only a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Among them, A and B may be singular or plural.

[0044] In the description of this application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple.

[0045] In addition, for the convenience of clearly describing the technical solutions of the embodiments of this application, in the embodiments of this application, words such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and effects. Those skilled in the art can understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit to be different.

[0046] In the embodiments of this application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.

[0047] It can be understood that the "embodiments" mentioned throughout the specification mean that specific features, structures or characteristics related to the embodiments are included in at least one embodiment of this application. Therefore, the various embodiments throughout the specification do not necessarily refer to the same embodiments. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It can be understood that in the various embodiments of this application, the magnitude of the serial numbers of each process does not mean the sequence of execution, and the execution sequence of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.

[0048] It can be understood that some optional features in the embodiments of the present application can, in some scenarios, be implemented independently without relying on other features, such as the current solution they are based on, to solve corresponding technical problems and achieve corresponding effects. In some scenarios, they can also be combined with other features according to requirements. Correspondingly, the devices given in the embodiments of the present application can also implement these features or functions accordingly, which will not be elaborated herein.

[0049] In the present application, unless otherwise specified, the same or similar parts between various embodiments can be referred to each other. In the present application, if there is no special description and logical conflict in each embodiment, the terms and / or descriptions between different embodiments are consistent and can be mutually referred to, and different embodiments can be combined to form new embodiments according to their internal logical relationships. The following embodiments of the present application do not constitute a limitation on the protection scope of the present application.

[0050] Only through exchange and sharing can data maximize its value. However, the problem of privacy leakage has a great negative impact on the value of data resources. How to securely and efficiently analyze and use the dispersed data resources of different owners on the premise of ensuring data security is the main challenge for realizing the monetization of data value. Secure multi-party computation technology is a key technology for realizing the secure circulation of data, which can enable a group of independent data owners to complete the calculation of a certain function with their respective data as inputs without trusting each other, and the calculation process will not expose the input data.

[0051] In existing secure multi-party computation solutions, the secure multi-party computation (MPC) protocol can be directly deployed in a trusted execution environment (TEE) to prevent the MPC execution program from being maliciously tampered with, and promote the secure multi-party computation suitable for the semi-honest attack model to the secure multi-party computation suitable for the malicious attack model.

[0052] As Figure 1 shown, the trusted third party and the two trading parties for data exchange are both in the software guard extensions (SGX) environment. The random number splitting module of the trusted third party distributes random numbers to the two trading parties, and loads the calculation program related to secure multi-party computation into the trusted execution environment; based on the trusted execution environment, mutually verify the integrity of the calculation programs related to secure multi-party computation with other participating parties; if the integrity verification of the calculation program is successful, execute the calculation program in the trusted execution environment and interact with other participating parties for the calculation results to complete the secure multi-party computation.

[0053] In existing secure multi-party computation (MPC) schemes, a trusted third party is required to distribute random numbers, and multiple interactions are needed for each computation, resulting in high consumption of communication resources and long transaction times.

[0054] Based on this, an embodiment of the present application provides a secure multi-party computation method, which includes: a first secure multi-party computation MPC agent receives a first password from a first user cloud virtual machine (CVM), and the first MPC agent derives a first Seed according to the password; the first MPC agent generates a first random number sequence according to the first Seed; the first MPC agent receives first user data from the first CVM and second user data from a second CVM; the first MPC agent performs secure multi-party computation with a second MPC agent according to the first random number sequence, the first user data, the second user data, and a computation task expression, where the second random number sequence of the second MPC agent is the same as the first random number sequence, the second Seed of the second MPC agent is the same as the first Seed, and the second password received by the second MPC agent from the second CVM is the same as the first password.

[0055] The secure multi-party computation method provided by the embodiment of the present application can be applied to Figure 2 the communication system shown in the figure. The exception levels (EL) 0 and EL1 of this communication system include virtual machines (VM) 0, VM1, user cloud virtual machines (CVM) 0, secure multi-party computation agent MPC agent0, user CVM1, and MPC agent0. Among them, the MPC agent corresponds to the user CVM one by one. The MPC agent is a part of the confidential computing architecture (CCA) software stack, and the function of the MPC agent is fixed, similar to the migration agent Migrationagent of secure encrypted virtualization (SEV) or the Quoting Enclave of software guard extensions (SGX). This MPC agent can only execute MPC, and the code can be open source and remotely verifiable.

[0056] The EL2 of the communication system includes a TMM and a host kernel. In the kernel-based virtual machine KVM-virt CCA of the host kernel, there are a trustzone management interface (TMI) and an MPC agent manager. Among them, the computing parties can, through the MPC agent manager, configure the resources of the MPC agent computing nodes according to the needs of the computation.

[0057] The EL3 of the communication system includes a secure monitor, and in the secure monitor, there is a single program multiple data (SPMD) dispatcher.

[0058] In the embodiments of this application, an MPC agent module and an MPC agent manager module are newly added to the communication system to implement the agency of secure multi-party computation, so as to more efficiently achieve secure interaction.

[0059] It can be understood that in the embodiments of this application, the execution subject can execute some or all of the steps in the embodiments of this application. These steps or operations are only examples, and the embodiments of this application can also execute other operations or various deformations of the operations. In addition, the various steps can be executed in different orders presented in the embodiments of this application, and it is possible not to execute all the operations in the embodiments of this application.

[0060] It should be noted that the message names between various devices or the names of each parameter in the message in the following embodiments of this application are only examples, and in specific implementations, they can also be other names, and the embodiments of this application do not make specific limitations on this.

[0061] As Figure 3 shown, a secure interaction method provided by the embodiments of this application includes the following steps:

[0062] In the offline phase, the secure interaction method provided by the embodiments of this application can perform the following steps:

[0063] 301. Configure computing resources for the MPC agent.

[0064] Each computing party configures the computing resources of the MPC agent through the MPC agent Manager and deploys the MPC program.

[0065] In the embodiments of the present application, the MPC agent Manager can configure the resources of the MPC agent computing nodes according to the computing needs. Therefore, user Alice can configure the computing resources of MPC agent0 through the MPC agent Manager, and user Bob can configure the computing resources of MPC agent1 through the MPC agent Manager.

[0066] 302. Start the MPC agent.

[0067] Each computing participant starts the MPC agent through the corresponding CVM, and each MPC agent corresponds to a CVM one by one.

[0068] Specifically, for example, user Alice starts MPC agent0 through CVM0, and user Bob starts MPC agent0 through CVM1.

[0069] 303. Remotely verify the MPC agent.

[0070] Each computing participant remotely verifies the corresponding MPC agent to ensure that the MPC protocol program in the MPC agent has not been tampered with.

[0071] Specifically, for example, MPC agent0 receives a verification request from CVM0, and the verification request instructs to verify whether the MPC protocol program of MPC agent0 has been tampered with; after verification, MPC agent0 confirms that the MPC protocol program has not been tampered with, and MPC agent0 sends verification information to CVM0, and the verification information indicates that the MPC protocol program of MPC agent0 has not been tampered with.

[0072] 304. Input a password to the MPC agent.

[0073] Each participant inputs the same password to the corresponding MPC agent through the password input module in the CVM.

[0074] Specifically, as Figure 4 shown, user Alice inputs the first password to the corresponding MPC agent0 through the password input module of CVM1; user Bob inputs the second password to the corresponding MPC agent1 through the password input module of CVM2, and the first password and the second password are the same.

[0075] In the embodiments of the present application, the password may be password information in the form of a string, a number, a verification code, etc. In addition, it may also be other types of passwords, such as corpus information, etc., which are not specifically limited here. It can be understood that the password sent by the CVM to the MPC agent in the embodiments of the present application is information for deriving the Seed, so any information that can be used to derive the Seed can be used as the password in the embodiments of the present application, which is not specifically limited here.

[0076] 305. Derive the Seed according to the password.

[0077] After each MPC agent receives the password from the corresponding CVM, the Seed derivation module in the MPC agent can derive the corresponding Seed. Since the passwords received by each MPC agent are the same and the derivation algorithms adopted by each MPC agent are also the same, the Seeds derived by each MPC agent are also the same.

[0078] Specifically, for example Figure 4 As shown, after MPC agent0 receives the password from CVM1, the Seed derivation module of MPC agent0 can derive Seed1 according to the received password and the timestamp TimeStamp using the derivation algorithm. After MPCagent1 receives the password from CVM2, the Seed derivation module of MPC agent1 can derive Seed2 according to the received password and the timestamp TimeStamp using the derivation algorithm. Since the passwords received by MPC agent0 and MPC agent1 are the same and the derivation algorithms adopted by MPC agent0 and MPC agent1 are also the same, the Seed1 and Seed2 derived by MPC agent0 and MPCagent1 are also the same.

[0079] In the embodiments of the present application, through the password-based key delivery function, the synchronization of the Seed does not require interaction between MPC agents. In the scenario of multiple computing participants, the synchronization between MPC agents can be more efficiently achieved, increasing the efficiency of secure multi-party computing.

[0080] 306. Generate a random number sequence.

[0081] After each MPC agent derives the Seed, the random number generation module of the MPC agent generates a random number sequence according to the derived Seed. Since the Seeds derived by each MPC agent are the same, the generated random number sequences are also the same.

[0082] Specifically, for example, the random number generation module of MPC agent0 generates a first random number sequence based on the derived Seed1, and the random number generation module of MPC agent1 generates a second random number sequence based on the derived Seed2. The generated first random number sequence and the second random number sequence are the same.

[0083] 307. Perform data secret sharding.

[0084] Each computing participant secret-shards its own data and sends it to the MPC Agent.

[0085] Specifically, for example, CVM0 can encrypt its own data x to generate secret data x0 and x1, send the secret data x0 to MPC agent0, and send the secret data x1 to MPC agent1; CVM1 can encrypt its own data y to generate secret data y0 and y1, send the secret data y0 to MPC agent0, and send the secret data y1 to MPC agent1.

[0086] It can be understood that each CVM in the embodiments of the present application can encrypt its own data and send it to each MPC agent in the system. For example, if there are three MPC agents in the system, namely MPC agent0, MPC agent1, and MPC agent2, CVM0 can send the secret data x0 to MPC agent0, send the secret data x1 to MPC agent1, and send the secret data x2 to MPC agent2.

[0087] 308. Execute the MPC protocol.

[0088] The MPC execution modules of each MPC agent jointly execute the MPC protocol according to the random number sequence, the user's secret-sharded data, and the calculation task expression.

[0089] Specifically, the MPC execution module of MPC agent0, based on the first random number sequence, the user's secret-sharded data, and the calculation task expression, and the MPC execution module of MPC agent1, based on the second random number sequence, the user's secret-sharded data, and the calculation task expression, perform secure multi-party calculation between MPC agent0 and MPC agent1.

[0090] In the embodiments of the present application, through the password-based key distribution function, the synchronization of Seed does not require interaction between MPC agents. In the scenario of multiple computing participants, the synchronization between MPC agents can be more efficiently achieved, increasing the efficiency of secure multi-party computing. At the same time, by using MPC agents to perform secure multi-party computing on behalf of the computing participants, the MPC agent module can prove its innocence, better meeting the security assumptions of cryptographic MPC. Moreover, the computing resources of the MPC agent can be set according to the needs of the computing participants, and the computing resources can be dynamically configured, enabling more flexible implementation of secure multi-party computing.

[0091] The embodiments of the present application provide an MPC proxy device 500. In the embodiments of the present application, the functional modules of the MPC proxy device 500 can be divided according to the above method examples. For example, each functional module can be corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiments of the present invention is illustrative, only a logical function division, and there may be other division methods in actual implementation.

[0092] In the case of dividing each functional module corresponding to each function, Figure 5 A possible structural schematic diagram of the MPC proxy device 500 involved in the above embodiments is shown. As Figure 5 shown, the MPC proxy device 500 includes:

[0093] A third receiving module 501, configured to receive a verification request from the first CVM, where the verification request indicates whether the MPC protocol program of the first MPC proxy has been tampered with; for example, step 303, remotely verifying the MPC agent.

[0094] A sending module 502, configured to send verification information to the first CVM, where the verification information indicates that the MPC protocol program of the first MPC proxy has not been tampered with. For example, step 303, remotely verifying the MPC agent.

[0095] A first receiving module 503, configured to receive a first password from the first user cloud server CVM, for example, step 304, inputting the password to the MPC agent.

[0096] A derivation module 504, configured to derive a first Seed according to the password; for example, step 305, deriving the Seed according to the password.

[0097] A generation module 505, configured to generate a first random number sequence according to the first Seed; for example, step 306, generating the first random number sequence.

[0098] A second receiving module 506, configured to receive first user data from a first CVM and second user data from a second CVM; for example, in step 307, perform data secret sharding.

[0099] A calculation module 507, configured to perform secure multi-party calculation with a second MPC agent according to a first random number sequence, first user data, second user data, and a calculation task expression. The second random number sequence of the second MPC agent is the same as the first random number sequence, the second Seed of the second MPC agent is the same as the first Seed, and the second password received by the second MPC agent from the second CVM is the same as the first password. For example, in step 308, execute the MPC protocol.

[0100] Each module of the above non-linear compensation device can also be used to perform other actions in the above method embodiments. All relevant contents of the steps involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.

[0101] An embodiment of the present application provides a user cloud server CVM600. In the embodiment of the present application, the CVM600 can be divided into functional modules according to the above method examples. For example, each functional module can be corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. It should be noted that the division of modules in the embodiment of the present invention is illustrative, only a logical function division, and there may be other division methods in actual implementation.

[0102] In the case of dividing each functional module corresponding to each function, Figure 6 A possible structural schematic diagram of the CVM600 involved in the above embodiment is shown. As Figure 6 shown, the CVM600 includes:

[0103] A configuration module 601, configured to configure the computing resources of the first MPC agent; for example, in step 301, configure computing resources for the MPC agent.

[0104] A pulling-up module 602, configured to pull up the first MPC agent. For example, in step 302, pull up the MPC agent.

[0105] A third sending module 603, configured to send a verification request to the first MPC agent, where the verification request indicates verifying whether the MPC protocol program of the first MPC agent has been tampered with; for example, in step 303, perform remote verification on the MPC agent.

[0106] A receiving module 604, configured to receive verification information from a first MPC agent, where the verification information indicates that the MPC protocol program of the first MPC agent has not been tampered with. For example, in step 303, remotely verify the MPC agent.

[0107] A first sending module 605, configured to send a first password to the first secure multi-party computation MPC agent, where the first password is used for the first MPC agent to perform secure multi-party computation with the second MPC agent; for example, in step 305, input the password to the MPC agent.

[0108] A second sending module 606, configured to send first user data to the first MPC agent and send third user data to the second MPC agent, where the first user data and the third user data are used for the first MPC agent and the second MPC agent to perform secure multi-party computation. For example, in step 307, perform data secret sharding.

[0109] Each module of the above non-linear compensation device can also be used to perform other actions in the above method embodiments. All relevant contents of the steps involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.

[0110] Figure 7 It is a schematic structural diagram of an MPC agent device provided by an embodiment of the present application. The MPC agent device 700 may include one or more central processing units (CPUs) 701 and a memory 705, and one or more application programs or data are stored in the memory 705.

[0111] Among them, the memory 705 may be volatile storage or persistent storage. The program stored in the memory 705 may include one or more modules, and each module may include a series of instruction operations on the MPC agent device. Further, the central processor 701 may be configured to communicate with the memory 705 and execute a series of instruction operations in the memory 705 on the MPC agent device 700.

[0112] Among them, the central processing unit 701 is used to execute the computer program in the memory 705, so that the MPC proxy device 700 is used to execute: The first secure multi-party computing MPC proxy receives the first password from the first user cloud server CVM, and the first MPC proxy derives the first Seed according to the password; The first MPC proxy generates a first random number sequence according to the first Seed; The first MPC proxy receives the first user data from the first CVM and the second user data from the second CVM; The first MPC proxy performs secure multi-party computing with the second MPC proxy according to the first random number sequence, the first user data, the second user data, and the computing task expression. The second random number sequence of the second MPC proxy is the same as the first random number sequence, the second Seed of the second MPC proxy is the same as the first Seed, and the second password received by the second MPC proxy from the second CVM is the same as the first password. For the specific implementation method, please refer to Figure 3 Steps 301-308 in the illustrated embodiment, which will not be elaborated here.

[0113] The MPC proxy device 700 may further include one or more power supplies 702, one or more wired or wireless network interfaces 703, one or more input / output interfaces 704, and / or, one or more operating systems, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0114] The MPC proxy device 700 can perform the foregoing Figure 3 Operations performed by the MPC proxy device in the illustrated embodiment, which will not be elaborated here specifically.

[0115] Figure 8 It is a schematic diagram of a CVM structure provided by an embodiment of the present application. The CVM 800 may include one or more central processing units (CPUs) 801 and a memory 805, and one or more application programs or data are stored in the memory 805.

[0116] Among them, the memory 805 may be volatile storage or persistent storage. The program stored in the memory 805 may include one or more modules, and each module may include a series of instruction operations in the CVM. Further, the central processing unit 801 may be set to communicate with the memory 805 and execute a series of instruction operations in the memory 805 on the CVM 800.

[0117] Among them, the central processing unit 801 is used to execute the computer program in the memory 805, so that the CVM800 is used to execute: the first user cloud server CVM sends a first password to the first secure multi-party computing MPC agent, and the first password is used for the first MPC agent and the second MPC agent to perform secure multi-party computing; the first CVM sends the first user data to the first MPC agent and sends the third user data to the second MPC agent, and the first user data and the third user data are used for the first MPC agent and the second MPC agent to perform secure multi-party computing. For the specific implementation method, please refer to Figure 3 Steps 301-308 in the illustrated embodiment, which will not be elaborated here.

[0118] The CVM800 may further include one or more power supplies 802, one or more wired or wireless network interfaces 803, one or more input / output interfaces 804, and / or one or more operating systems, such as WindowsServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0119] The CVM800 can perform the foregoing Figure 3 Operations performed by the CVM in the illustrated embodiment will not be elaborated here.

[0120] The embodiment of the present application also provides a computer program product containing instructions. The computer program product can be a software or program product containing instructions that can run on the plug-in result reuse device or be stored in any available medium. When the computer program product runs on the plug-in result reuse device, it causes the MPC agent device to perform the foregoing Figure 3 Secure multi-party computing method performed in the illustrated embodiment.

[0121] The embodiment of the present application also provides a computer program product containing instructions. The computer program product can be a software or program product containing instructions that can run on the plug-in result reuse device or be stored in any available medium. When the computer program product runs on the plug-in result reuse device, it causes the CVM to perform the foregoing Figure 3 Secure multi-party computing method performed in the illustrated embodiment.

[0122] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by the cache server or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive), etc. The computer-readable storage medium includes instructions that instruct the MPC agent device to perform the foregoing Figure 3The secure multi-party computation method executed in the illustrated embodiment.

[0123] An embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a cache server can store or a data storage device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that direct the CVM to execute the aforesaid Figure 3 The secure multi-party computation method executed in the illustrated embodiment.

[0124] As Figure 9 As shown, an embodiment of the present application provides a secure multi-party computation system 900. The secure multi-party computation system 900 includes a secure multi-party computation MPC proxy device 901 and a user cloud server 902. The MPC proxy device 901 can implement the secure multi-party computation method executed in the illustrated embodiment as Figure 3 shown, and the user cloud server 902 can implement the secure multi-party computation method executed in the illustrated embodiment as Figure 3 shown.

[0125] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes (or functions) of the embodiments of the present application are implemented. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state disk (SSD)). In the embodiments of the present application, the computer can include the foregoing devices.

[0126] Although the present application has been described in conjunction with various embodiments, it will be understood by those skilled in the art that other variations of the disclosed embodiments can be understood and effected while practicing the claimed application. In the claims, the term "comprising" does not exclude other elements or steps, and the singular "a" or "an" does not exclude a plurality. A single processor or other unit may implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not indicate that these measures cannot be combined to advantage.

Claims

1. A secure multi-party computation method, characterized in that, The method includes: The first secure multi-party computation (MPC) proxy receives a first password from the first user's cloud virtual machine (CVM); The first MPC proxy derives a first Seed according to the first password; The first MPC proxy generates a first random number sequence according to the first Seed; The first MPC proxy receives first user data from the first CVM and second user data from the second CVM; The first MPC proxy performs secure multi-party computation with the second MPC proxy according to the first random number sequence, the first user data, the second user data, and a computation task expression. The second random number sequence of the second MPC proxy is the same as the first random number sequence, the second Seed of the second MPC proxy is the same as the first Seed, and the second password received by the second MPC proxy from the second CVM is the same as the first password.

2. The method according to claim 1, characterized in that, Before the first MPC proxy receives the first password from the first user's cloud server CVM, the method further includes: The first MPC proxy receives a verification request from the first CVM, and the verification request indicates verifying whether the MPC protocol program of the first MPC proxy has been tampered with; The first MPC proxy sends verification information to the first CVM, and the verification information indicates that the MPC protocol program of the first MPC proxy has not been tampered with.

3. A secure multi-party computation method, characterized in that, The method includes: The first user's cloud server CVM sends a first password to the first secure multi-party computation MPC proxy, and the first password is used for the first MPC proxy to perform secure multi-party computation with the second MPC proxy; The first CVM sends first user data to the first MPC proxy and third user data to the second MPC proxy, and the first user data and the third user data are used for the first MPC proxy and the second MPC proxy to perform secure multi-party computation.

4. The method according to claim 3, characterized in that, Before the first CVM sends the first password to the first MPC proxy, the method further includes: The first CVM configures the computing resources of the first MPC proxy; The first CVM starts the first MPC proxy.

5. The method according to claim 4, wherein Before the first CVM sends the first password to the first MPC proxy and after the first CVM starts the first MPC proxy, the method further includes: The first CVM sends a verification request to the first MPC proxy, and the verification request indicates verifying whether the MPC protocol program of the first MPC proxy has been tampered with; The first CVM receives verification information from the first MPC proxy, and the verification information indicates that the MPC protocol program of the first MPC proxy has not been tampered with.

6. A secure multi-party computation MPC proxy device, characterized in that, The MPC proxy device is used to implement the method according to any one of claims 1-2. The MPC proxy device includes: a seed derivation module, a random number generation module, and an MPC execution module, where: The seed derivation module is used to derive a first Seed according to a first password, and the first Seed comes from the first user's cloud server CVM; The random number generation module is used to generate a first random number sequence according to the first Seed; The MPC execution module is used to perform secure multi-party computation with a second MPC agent according to the first random number sequence, the first user data, the second user data, and a computation task expression. The second random number sequence of the second MPC agent is the same as the first random number sequence, the second Seed of the second MPC agent is the same as the first Seed, and the second password received by the second MPC agent from a second CVM is the same as the first password.

7. The MPC proxy device according to claim 6, characterized in that, The MPC agent device further includes a transceiver module, and the transceiver module is used for: Receiving a verification request from the first CVM, where the verification request indicates verifying whether the MPC protocol program of the first MPC agent has been tampered with; Sending verification information to the first CVM, where the verification information indicates that the MPC protocol program of the first MPC agent has not been tampered with.

8. A user Cloud Virtual Machine (CVM), characterized in that, The CVM includes a transceiver module and a user data output module, where: The transceiver module is used to send a first password to a first secure multi-party computation MPC agent, and the first password is used for the first MPC agent to perform secure multi-party computation with a second MPC agent; The user data output module is used to send first user data to the first MPC agent and send third user data to the second MPC agent, and the first user data and the third user data are used for the first MPC agent and the second MPC agent to perform secure multi-party computation.

9. The CVM according to claim 8, wherein, The transceiver module is further used for: Configuring the computing resources of the first MPC agent; Starting up the first MPC agent.

10. The CVM according to claim 9, wherein The transceiver module is further used for: Sending a verification request to the first MPC agent, where the verification request indicates verifying whether the MPC protocol program of the first MPC agent has been tampered with; Receiving verification information from the first MPC agent, where the verification information indicates that the MPC protocol program of the first MPC agent has not been tampered with.

11. A secure multi-party computing MPC proxy device, characterized in that, The MPC agent device includes: A first receiving module, used to receive a first password from a first user cloud server CVM; A derivation module, used to derive a first Seed according to the password; A generation module, used to generate a first random number sequence according to the first Seed; A second receiving module, used to receive first user data from the first CVM and second user data from a second CVM; A computing module, used to perform secure multi-party computation with a second MPC agent according to the first random number sequence, the first user data, the second user data, and a computation task expression. The second random number sequence of the second MPC agent is the same as the first random number sequence, the second Seed of the second MPC agent is the same as the first Seed, and the second password received by the second MPC agent from a second CVM is the same as the first password.

12. The MPC proxy device according to claim 11, characterized in that, The MPC agent device further includes: A third receiving module, used to receive a verification request from the first CVM, where the verification request indicates verifying whether the MPC protocol program of the first MPC agent has been tampered with; A sending module, configured to send verification information to the first CVM, where the verification information indicates that the MPC protocol program of the first MPC agent has not been tampered with.

13. A user cloud server, characterized in that, The user cloud server CVM includes: A first sending module, configured to send a first password to a first secure multi-party computation (MPC) agent, where the first password is used for the first MPC agent to perform secure multi-party computation with a second MPC agent; A second sending module, configured to send first user data to the first MPC agent and send third user data to the second MPC agent, where the first user data and the third user data are used for the first MPC agent and the second MPC agent to perform secure multi-party computation.

14. The server according to claim 13, wherein The CVM further includes: A configuration module, configured to configure the computing resources of the first MPC agent; A startup module, configured to start up the first MPC agent.

15. The server according to claim 14, wherein The CVM further includes: A third sending module, configured to send a verification request to the first MPC agent, where the verification request indicates verifying whether the MPC protocol program of the first MPC agent has been tampered with; A receiving module, configured to receive verification information from the first MPC agent, where the verification information indicates that the MPC protocol program of the first MPC agent has not been tampered with.

16. A secure multi-party computing MPC proxy device, characterized in that, The MPC agent device includes a processor and a memory; the processor is coupled to the memory; the memory is used to store computer instructions, and the computer instructions are loaded and executed by the processor to enable the MPC agent device to implement the method according to claim 1 or 2.

17. A user cloud server, characterized in that, The user cloud server includes a processor and a memory; the processor is coupled to the memory; the memory is used to store computer instructions, and the computer instructions are loaded and executed by the processor to enable the user cloud server to implement the method according to any one of claims 3-5.

18. A computer-readable storage medium, characterized in that, At least one computer program instruction is stored in the computer-readable storage medium, and the computer program instruction is loaded and executed by a processor to implement the method according to claim 1 or 2.

19. A computer-readable storage medium, characterized in that, At least one computer program instruction is stored in the computer-readable storage medium, and the computer program instruction is loaded and executed by a processor to implement the method according to any one of claims 3-5.

20. A computer program product, characterized in that, The computer program product includes computer execution instructions, and when the computer execution instructions run on a computer, the computer is used to implement the method according to claim 1 or 2.

21. A computer program product, characterized in that, The computer program product includes computer execution instructions, and when the computer execution instructions run on a computer, the computer is used to implement the method according to any one of claims 3-5.

22. A secure multi-party computing system, characterized in that, The secure multi-party computation system includes a secure multi-party computation (MPC) agent device and a user cloud server. The MPC agent device can implement the method according to claim 1 or 2, and the user cloud server can implement the method according to any one of claims 3-5.

Citation Information

Cited By

  • Secure multi-party computation method and device

    EP4811722A1

  • Secure multi-party computation method and device

    WO2025130307A1