Distributed privacy protection extreme value solving method and device with efficient calculation, and product
By using inadvertent transmission protocols and homomorphic xenoor operations in distributed systems, the problems of high computational complexity or needing trusted third parties in the existing technology are solved, and efficient calculations of extreme value solutions for distributed privacy protection are realized, ensuring data privacy and ability to resist accomplice attacks.
Patent Information
- Application Number
- CN202510213844.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-06-27
AI Technical Summary
When calculating distributed minimum and maximum values in a distributed environment, the calculation complexity is high or a trusted third party is required, making it difficult to achieve efficient calculations while ensuring user data privacy.
A distributed privacy protection extreme value solution algorithm based on the inadvertent transmission protocol (OT) is proposed. Through the OT protocol and homomorphic xOR operation, it avoids the use of expensive public key operations to achieve efficient extreme value calculations.
This algorithm can efficiently calculate the extreme values in the distributed system without exposing any sensitive information, reduce computing overhead and resource consumption, and resist attacks from the accomplices of the participants.
Smart Images

Figure CN120217424A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data protection algorithms, and in particular to a computationally efficient distributed privacy-preserving extreme value solving method, device, and product. Background Art
[0002] With the development of information technology, mobile devices are equipped with a large number of sensors, such as cameras, GPS, acceleration sensors, fingerprint sensors, light sensors, etc. These sensors generate a large amount of data about human health, location, and its surrounding environment (such as noise, temperature). By collecting and analyzing this data, people's quality of life can be improved. However, the data generated by these sensors often contains sensitive information of users. Therefore, if data privacy is not guaranteed, some users are reluctant to share their private data. This in turn leads to a decrease in the accuracy of data results. To solve the above problems, privacy-preserving data aggregation has emerged. It can not only protect the privacy of user data but also allow data analysis. Currently, most existing solutions can accurately calculate the sum or average value in a distributed environment. However, there is not much existing research work on the privacy-preserving calculation of distributed minimum and maximum values. Distributed privacy-preserving minimum / maximum value calculation allows each user to generate sensitive data at each time period and securely calculate the minimum / maximum value among all user data while ensuring the privacy of user sensitive data. This problem has a wide range of application scenarios, such as calculating the lowest temperature / highest temperature or the lowest power consumption / highest power consumption in the environment where the user is located. Existing work can accurately calculate extreme values by using privacy-preserving summation algorithms, but they either require high computational complexity or a trusted third party. In addition, based on homomorphic bit operations, Zhang et al. (Yuan Zhang, Qingjun Chen, Sheng Zhong. Efficient and Privacy-Preserving Min and kth Min Computations in Mobile Sensing Systems[J]. IEEE Transactions on Dependable and Secure Computing, 2017, 14(1): 9-21) and Yu et al. (Jiahui Yu, Kun Wang, Deze Zeng, et al. Privacy-preserving Data Aggregation Computing in Cyber-Physical Social Systems. ACM Transactions on Cyber-Physical Systems. 2019, 3(1): 8:1-8:23) proposed two highly efficient algorithms to calculate the minimum value. However, their solutions require a trusted third party to distribute keys. It should be noted that in real life, it is very difficult to find a completely trusted third-party authority. In summary, the existing algorithms have problems: high computational complexity or the need for a trusted third party. Summary of the Invention
[0003] To solve the above problems, a new computationally efficient distributed privacy-preserving extreme value solving algorithm needs to be proposed. In addition, this new algorithm does not require the use of a trusted third party to distribute keys.
[0004] A computationally efficient distributed privacy-preserving extreme value solving method, which is applied to a distributed privacy-preserving system model and can resist collusion among t participating parties, where the extreme value is the maximum or minimum value, and the system model includes n participating parties { , , …, , …, }; where represents the i-th participating party; The sensitive data generated by is denoted as is the length of
[0005] The method includes the following steps:
[0006] Step A1: Each participating party sets the data status it owns to "active";
[0007] Step A2: Each participating party ( ) converts the corresponding into a binary representation , that is, represents the highest bit of represents the lowest bit of
[0008] Step A3: For each j , from to 0, execute the following loop (Steps B1 - B8):
[0009] Step B1: Each participating party ( ) calculates t + 1 message pairs where , is a security parameter;
[0010] Step B2: For each h , each participating party , where, is the left neighbor set;
[0011] When the extreme value is the minimum value:
[0012] If and its data status is "active", set ; otherwise set ;
[0013] When the extreme value is the maximum value:
[0014] If and its data status is "active", set ; otherwise set ;
[0015] Step B3: Each participating party respectively executes the OT protocol with each corresponding participating party (k ) that is, acts as the receiver, and its input is ; acts as the sender, and its input is ; Let represent the output obtained from the OT protocol; where is the right neighbor set;
[0016] Step B4: For each participating party ,
[0017] When the extreme value is the minimum value:
[0018] If and its data status is "active", Randomly draw uniformly from to obtain , that is, and calculate ;
[0019] Otherwise calculate ;
[0020] When the extreme value is the maximum value:
[0021] If and its data status is "active", Randomly draw uniformly from to obtain , that is, and calculate ;
[0022] Otherwise calculate ;
[0023] Among them The calculation parameter for the j-th bit of the i-th participant; The calculation result for the j-th bit of the i-th participant;
[0024] Step B5: Each participating party Sends To the preset participating party;
[0025] Step B6: The preset participating party calculates ,
[0026] When the extreme value is the minimum value:
[0027] If , Set ; Otherwise set ;
[0028] When the extreme value is the maximum value:
[0029] If , Set ; Otherwise set ;
[0030] Wherein, Represents the j-th tag data;
[0031] Step B7: The preset participating party sends To the other participating parties;
[0032] Step B8: For each participating party ( ), if And its data status is "active", Set its data status to "inactive;
[0033] Step A4: The preset participating party calculates ; Wherein, Represents the extreme value in the sensitive data of all participating parties.
[0034] Furthermore, the preset participating party is
[0035] Furthermore, the value of t is 0
[0036] The present invention also provides a computationally efficient distributed privacy-preserving extreme value solving device, which is applied to a distributed privacy-preserving system model and can resist Collusion of Participating parties, the extreme value is the maximum value or the minimum value, and the system model includes , , …, , …, }; where represents the i-th participant; The sensitive data generated is denoted as ; where, is the length of, n is the number of participants, and t is the number of colluding participants;
[0037] The device includes the following modules:
[0038] Initialization module: Each user participant sets the data status they own to "active";
[0039] Binary conversion module: For each participant ( ) converts the corresponding to binary representation , that is, represents the highest bit of, represents the lowest bit of;
[0040] Data exchange module: For each j , from to 0, the following loop is executed (Steps B1 - B8):
[0041] Step B1: Each participant ( ) calculates t + 1 message pairs where , is a security parameter;
[0042] Step B2: For each h , each participant , where, is the left neighbor set;
[0043] When the extreme value is the minimum value:
[0044] If and its data status is "active", set ; otherwise set ;
[0045] When the extreme value is the maximum value:
[0046] If and its data status is "active", set ; Otherwise, set ;
[0047] Step B3: Each participating party respectively executes the OT protocol with each corresponding participating party (k ), that is, acts as the receiver, and its input is ; acts as the sender, and its input is ; Let represent the output obtained from the OT protocol; where is the right neighbor set;
[0048] Step B4: For each participating party ,
[0049] When the extreme value is the minimum value:
[0050] If and its data status is "active", Randomly draw from uniformly at random to obtain , that is, , calculate ;
[0051] Otherwise, calculate ;
[0052] When the extreme value is the maximum value:
[0053] If and its data status is "active", Randomly draw from uniformly at random to obtain , that is, , calculate ;
[0054] Otherwise, calculate ;
[0055] Where is the calculation parameter of the j-th bit of the i-th participant; is the calculation result of the j-th bit of the i-th participant;
[0056] Step B5: Each participating party sends to the preset participating party;
[0057] Step B6: The preset participating party calculates ,
[0058] When the extreme value is the minimum value:
[0059] If , set ; otherwise set ;
[0060] When the extreme value is the maximum value:
[0061] If , set ; otherwise set ;
[0062] Wherein, represents the j-th tag data;
[0063] Step B7: The preset participant sends to other participants;
[0064] Step B8: For each participant ( ), if and its data status is "active", set its data status to "inactive;
[0065] Result calculation module: For the preset participant to calculate ; wherein, represents the extreme value in the sensitive data of all participants.
[0066] Furthermore, the preset participant is
[0067] Furthermore, the value of t is 0
[0068] The present invention also provides a computer program product, including a computer program, characterized in that when the computer program is executed by a processor, the above method is implemented.
[0069] Beneficial effects: The present invention is based on an oblivious transfer protocol to calculate an efficient distributed privacy-preserving extreme value solving algorithm, avoiding the use of computationally expensive public key operations, reducing the computational overhead and resource consumption, and achieving an improvement in the efficiency of privacy-preserving data processing in a distributed environment. This achievement brings the following specific and beneficial effects:
[0070] 1. Data privacy protection: For the present invention, since only during the execution of the OT protocol step, the data sending step, and the tag data sending step will data be sent during the calculation process of the present invention. During the execution of the OT protocol step, the data received by the receiver is one of the message pairs randomly generated by the sender. Therefore, the receiver cannot obtain sensitive information from it. During the data sending step, The received data is also generated by other participating parties through homomorphic exclusive-or operation on the first data in the message pair, and no sensitive information can be obtained either. In the step of sending the tag data, a single bit is sent, and the participating party still cannot obtain sensitive information. For the remaining steps, the participating party only performs local calculations. Therefore, this process does not disclose sensitive information. Thus, the present invention can ensure the privacy and security of the data of the participating parties.
[0071] 2. Resistance to collusion: Even if there are t participating parties colluding with each other in the system, the present invention can still ensure that the data privacy of other participating parties will not be leaked, which makes the present invention have a broader applicable environment.
[0072] 3. Efficiency improvement: Since the present invention mainly uses the OT protocol and homomorphic exclusive-or operation, avoiding the use of computationally expensive public-key operations, this greatly improves the calculation speed and efficiency and reduces the cost of the participating parties.
[0073] In summary, for the distributed privacy protection extreme value solving algorithm based on the OT protocol of the present invention, without exposing any sensitive information, the participating parties can efficiently calculate the extreme value. Brief Description of the Drawings
[0074] Figure 1 is the system model in the embodiment;
[0075] Figure 2 is the operation steps for the highest bit 1 in the embodiment;
[0076] Figure 3 is the operation steps for the lowest bit 0 in the embodiment. Detailed Embodiments
[0077] To make the objectives, features, and advantages of the present invention more obvious and understandable, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the embodiments described below are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0078] "Oblivious transfer (OT) is a two-party protocol, where one party is the sender, whose input is a pair of n-bit messages ( ), and the other party is the receiver, whose input is a bit . After running OT, the receiver only obtains the message , while the sender has no output and cannot obtain any information about b. Denotes m times of oblivious transfer protocols are executed on m-bit message pairs. Note that by using OT extension technology, a large number of OT protocols can be generated by using cheap symmetric keys and a small number of computationally expensive public key operations. The present invention proposes a distributed privacy-preserving extreme value solving algorithm based on the oblivious transfer protocol, which is secure under the semi-honest model.
[0079] Embodiment 1
[0080] A computationally efficient distributed privacy-preserving extreme value solving method, which is applied to a distributed privacy-preserving system model and can resist collusion among multiple parties. The extreme value is the maximum or minimum value. The system model includes multiple parties { , , …, , …, }; where represents the i-th party; The sensitive data generated by is denoted as , where is the length of; The present invention can efficiently and securely calculate the extreme value in the sensitive data of all parties, that is, =min{ , , …, } or max{ , , …, }.
[0081] The method includes the following steps:
[0082] Step A1 (Initialization): Each party sets the data status it owns to "active";
[0083] Step A2 (Data Binary Conversion): Each party ( ) converts the corresponding into the binary representation form , that is, represents the highest bit (the -th bit) of, represents the lowest bit (the 0-th bit) of;
[0084] Step A3 (Data Exchange): For each j , from to 0, perform the following loop (Steps B1 - B8):
[0085] Step B1 (Generate random message pairs): Each participant ( ) calculates t + 1 message pairs where , that is is uniformly and randomly drawn from ;
[0086] Step B2 (Set bit values): For each h , each participant ,
[0087] When the extreme value is the minimum value:
[0088] If and its data status is "active", set ; otherwise set ;
[0089] When the extreme value is the maximum value:
[0090] If and its data status is "active", set ; otherwise set ;
[0091] Step B3 (Execute the OT protocol): Each participant respectively executes the OT protocol with each corresponding participant (k ), that is acts as the receiver, with its input being ; acts as the sender, with its input being ; Let represent the output obtained from the OT protocol;
[0092] Step B4 (Calculate data): For each participant ,
[0093] When the extreme value is the minimum value:
[0094] If and its data status is "active", draw uniformly and randomly from to obtain , that is , calculate ;
[0095] Otherwise, calculate ;
[0096] When the extreme value is the maximum value:
[0097] If and its data status is "active", Randomly draw uniformly from to obtain , that is , calculate ;
[0098] Otherwise, calculate ;
[0099] Step B5 (Send data): Each participating party Send to ;
[0100] Step B6 (Generate tag data): The preset participating party calculates ,
[0101] When the extreme value is the minimum value:
[0102] If , Set ; Otherwise, set ;
[0103] When the extreme value is the maximum value:
[0104] If , Set ; Otherwise, set ;
[0105] Among them, represents the j-th tag data
[0106] Step B7 (Send tag data): The participating party Sends to other participating parties;
[0107] Step B8 (Update data status): For each participating party ( ), if and its data status is "active", Set its data status to "inactive;
[0108] Step A4 (Calculation result): The participating party Calculates the extreme value .
[0109] It can be understood that in this embodiment, the values of h and k have a corresponding relationship, and the values of h and k can be exchanged, which also belongs to the equivalent technical solutions of this embodiment; for the symbol description, please refer to Table 1.
[0110] Table 1 Symbol Description
[0111]
[0112] Embodiment 2
[0113] In this embodiment, the extreme value is the minimum value. On the basis of Embodiment 1, the values of h and k are exchanged, and the value of t is 0; at this time, although the technical solution in this embodiment cannot resist multi-party collusion, it effectively improves the calculation efficiency, reduces the calculation cost, and protects the privacy of the sensitive data of the participating parties.
[0114] Embodiment 3
[0115] In this embodiment, based on Embodiment 2, specific numerical values are given for illustration.
[0116] As Figures 1 to 3 shown;
[0117] In this embodiment, there are 3 participating parties in the system , , , and they each hold a sensitive data , , . For the convenience of description, it is assumed that the binary representation of the sensitive data of each participating party has only two significant bits.
[0118] The following is a detailed elaboration of the design solution of this embodiment:
[0119] Step A1 (Initialization): The three participating parties , , respectively set the data status they own to "active";
[0120] Step A2 (Data Binary Conversion): The three participating parties convert the sensitive data they own into binary representation forms, that is, convert into binary representation 01 (that is, ), convert into binary representation 11 (that is, ), convert into binary representation 10 (that is, );
[0121] Step A3 (Data Exchange): In this step, for each significant bit of the binary representation, starting from the most significant bit to the least significant bit, i.e., j , from the -th bit (the most significant bit) to the 0-th bit (the least significant bit) (note that since it is assumed that the binary representation of the sensitive data of each party has only two significant bits, in this embodiment ), the following loop (B1 - B17) is executed:
[0122] First, for the most significant bit 1, the following operations are performed:
[0123] Step B1 (Generate Random Message Pairs): Party calculates a message pair Party calculates a message pair , Party calculates a message pair , where , , (for the sake of simplicity of this embodiment, it is assumed here that ).
[0124] Step B2 (Set Bit Values): (1) For Party , since and its data status is "active", set ; (2) For Party , since , set ; (3) For Party , since , set ;
[0125] Step B3 (Execute OT Protocol): (1) Party executes the OT protocol with its left neighbor , i.e., acts as the receiver, with its input being ; acts as the sender, with its input being ; The output obtained from the OT protocol ; (2) Party executes the OT protocol with its left neighbor , i.e., acts as the receiver, with its input being ; Act as the sender, with its input being ; The output obtained from the OT protocol ; (3) The participating party executes the OT protocol with its left neighbor , that is Act as the receiver, with its input being ; Act as the sender, with its input being ; The output obtained from the OT protocol ;
[0126] Step B4 (Calculating data): (1) For the participating party , since and its data status is "active", randomly select , and calculate ; (2) For the participating party , since , calculate ; (3) For the participating party , since , calculate and calculate ;
[0127] Step B5 (Sending data): The participating parties and respectively send and to ;
[0128] Step B6 (Generating tag data): The participating party ( ) calculates , since , set ;
[0129] Step B7 (Sending tag data): The participating party sends to the other participating parties and ;
[0130] Step B8 (Updating data status): (1) For the participating party , since , so its data status remains unchanged and is still "active", set its data status to "inactive;
[0131] So far, the operation on the highest bit is completed. Next, the following steps will be executed for the lowest bit 0:
[0132] Step B9 (Generate random message pairs): The participating party calculates a pair of messages The participating party calculates a pair of messages , and the participating party calculates a pair of messages , where , .
[0133] Step B10 (Set bit values): (1) For the participating party , because , set ; (2) For the participating party , because its data status is "inactive", set ; (3) For the participating party , similarly, because its data status is "inactive, set ;
[0134] Step B11 (Execute the OT protocol): (1) The participating party executes the OT protocol with its left neighbor , that is acts as the receiver, and its input is ; acts as the sender, and its input is ; The output obtained from the OT protocol ; (2) The participating party executes the OT protocol with its left neighbor , that is acts as the receiver, and its input is ; acts as the sender, and its input is ; The output obtained from the OT protocol ; (3) The participating party executes the OT protocol with its left neighbor , that is acts as the receiver, and its input is ; acts as the sender, and its input is ; The output obtained from the OT protocol ;
[0135] Step B13 (Calculate data): (1) For Participant , because , calculate ; (2) For Participant , because its data status is "inactive", calculate ; (3) For Participant , also because its data status is "inactive", calculate calculate ;
[0136] Step B14 (Send data): Participants and respectively send and to ;
[0137] Step B15 (Generate tag data): Participant calculates , because , sets ;
[0138] Step B16 (Send tag data): Participant sends to other participants and ;
[0139] Step B17 (Update data status): For Participant , if , 's data status remains unchanged, still "active"; for Participants and their data status remains unchanged, still "inactive";
[0140] Step A4 (Calculation result): Participant calculates the minimum value .
[0141] The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A computationally efficient distributed privacy-preserving extremum solution method, applied to distributed privacy-preserving system models and resistant to attacks The participants conspire, the extreme value is the maximum value or the minimum value, and the system model includes Participants , , …, , …, };in represents the i-th participant; The generated sensitive data is recorded as ;in, for The length of , n is the number of participants, t is the number of accomplices; The method comprises the following steps: Step A1: Each participant sets the status of the data they own to "active"; Step A2: Each participant ( ) will correspond to Convert to binary representation ,Right now express The highest position, express The lowest bit of Step A3: For each j [ ] ,from To 0, execute the following loop (step B1-step B8): Step B1: Each participant ( ) Calculate t+1 message pairs in , is a safety parameter; Step B2: For each h , each participant ,in, is the left neighbor set; When the extreme value is the minimum value: if and its data status is "active", set up ; Otherwise set ; When the extremum is at its maximum value: if and its data status is "active", set up ; Otherwise set ; Step B3: Each participant With each corresponding party (k ) implement the OT protocol, i.e. Plays the role of receiver, whose input is ; Plays the role of sender, whose input is ;make express The output obtained from the OT protocol; where, is the right neighbor set; Step B4: For each participant , When the extreme value is the minimum value: if and its data status is "active", from Uniform random sampling, we get ,Right now ,calculate ; Otherwise calculate ; When the extremum is at its maximum value: if and its data status is "active", from Uniform random sampling, we get ,Right now ,calculate ; Otherwise calculate ; in is the calculation parameter of the jth position of the ith participant; is the calculation result of the jth position of the ith participant; Step B5: Each participant send To the intended parties; Step B6: Preset Participant Calculation , When the extreme value is the minimum value: if , set up ; Otherwise set ; When the extremum is at its maximum value: if , set up ; Otherwise set ; in, Represents the jth label data; Step B7: Preset participants to send To other parties; Step B8: For each participant ( ),if and its data status is "active", Set its data state to "inactive; Step A4: Preset Participant Calculation ;in, Represents extreme values in the sensitive data of all parties.
2. The method for solving a distributed privacy-preserving extreme value with high computational efficiency according to claim 1, characterized in that: The preset participants are 3. The method for solving a distributed privacy-preserving extreme value with high computational efficiency according to claim 1, characterized in that: The value of t is 0 4. A computationally efficient distributed privacy protection extreme value solving device, applied to the distributed privacy protection system model and resistant to anti- The participants conspire, the extreme value is the maximum value or the minimum value, and the system model includes Participants , , …, , …, };in represents the i-th participant; The generated sensitive data is recorded as ;in, for The length of , n is the number of participants, t is the number of accomplices; The device is characterized in that it comprises the following modules: Initialization module: Each user participant sets the data status to "active"; Binary conversion module: for each participant ( ) will correspond to Convert to binary representation ,Right now express The highest position, express The lowest bit of Data exchange module: for each j [ ] ,from To 0, execute the following loop (step B1-step B8): Step B1: Each participant ( ) Calculate t+1 message pairs in , is a safety parameter; Step B2: For each h , each participant ,in, is the left neighbor set; When the extreme value is the minimum value: if And its data status is "active", set up ; Otherwise set ; When the extremum is at its maximum value: if And its data status is "active", set up ; Otherwise set ; Step B3: Each participant With each corresponding party (k ) implement the OT protocol, i.e. Plays the role of receiver, whose input is ; Plays the role of sender, whose input is ;make express The output obtained from the OT protocol; where, is the right neighbor set; Step B4: For each participant , When the extreme value is the minimum value: if And its data status is "active", from Uniform random sampling, we get ,Right now ,calculate ; Otherwise calculate ; When the extremum is at its maximum value: if And its data status is "active", from Uniform random sampling, we get ,Right now ,calculate ; Otherwise calculate ; in is the calculation parameter of the jth position of the ith participant; is the calculation result of the jth position of the ith participant; Step B5: Each participant send To the intended parties; Step B6: Preset Participant Calculation , When the extreme value is the minimum value: if , set up ; Otherwise set ; When the extremum is at its maximum value: if , set up ; Otherwise set ; in, Represents the jth label data; Step B7: Preset participants to send To other parties; Step B8: For each participant ( ),if And its data status is "active", Set its data state to "inactive; Result calculation module: used for preset participant calculation ;in, Represents extreme values in the sensitive data of all parties.
5. The computationally efficient distributed privacy-preserving extremum solving device according to claim 4, characterized in that: The preset participants are 6. The computationally efficient distributed privacy-preserving extremum solving device according to claim 4, characterized in that: The value of t is 0 7. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.