Data processing method and device for protecting privacy and computer equipment
By encoding private data into coefficients of polynomial functions and using secret sharing algorithms, the problem of data privacy protection in joint analysis and processing of multi-party data is solved, and safe and efficient data processing is achieved.
Patent Information
- Application Number
- CN202510500154.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-15
- Publication Date
- 2025-06-27
AI Technical Summary
During the joint analysis and processing of multi-party data, how to achieve coordinated data processing without leaking data privacy and protect the security of privacy data of various institutions.
By encoding the private data into the coefficients of the polynomial function, splitting it into multiple shards, and using a secret sharing algorithm for calculation, the target data shard is obtained, and the data is safely processed.
Without revealing data privacy, the coordinated processing of multi-party data is realized, which improves the computing efficiency of the secret sharing algorithm and is suitable for multi-party secure computing scenarios.
Smart Images

Figure CN120223307A_ABST
Abstract
Description
[0001] This application is a divisional application of the invention patent application with the application number 202210394145.9 and the title "Data Processing Method, Device and Computer Equipment for Protecting Privacy", which was filed on April 15, 2022. Technical Field
[0002] The embodiments of this specification relate to the field of computer technology, and particularly to a data processing method, device and computer equipment for protecting privacy. Background Art
[0003] In some scenarios, it is often necessary to perform joint analysis and processing on data from different data parties. During the process of joint analysis and processing of multi-party data, the protection and security of data privacy have become issues worthy of attention.
[0004] For example, the data volume of an institution is limited. Therefore, in many scenarios, it is necessary to perform joint analysis and processing on the data of multiple institutions. However, the data of institutions may involve data that needs to be kept confidential, such as user privacy or business information. Therefore, during the process of joint analysis and processing of the data of multiple institutions, it is necessary to protect the security of the privacy data of each institution. Summary of the Invention
[0005] The embodiments of this specification provide a data processing method, device and computer equipment for protecting privacy, so as to achieve collaborative data processing without leaking data privacy. The technical solutions of the embodiments of this specification are as follows.
[0006] In the first aspect of the embodiments of this specification, a data processing method for protecting privacy is provided, which is applied to the field of multi-party secure computing and includes:
[0007] Encoding privacy data into the coefficients of a first polynomial function;
[0008] Obtaining multiple function values of the first polynomial function as multiple shards after splitting the privacy data, and the shards of the privacy data are used to perform calculations using a secret sharing algorithm to obtain target data shards.
[0009] In the second aspect of the embodiments of this specification, a data processing method for protecting privacy is provided, which is applied to the field of multi-party secure computing and includes:
[0010] Obtaining multiple shards of privacy data, where the shards of the privacy data include the function values of a first polynomial function, and privacy data is encoded in the coefficients of the first polynomial function;
[0011] Performing calculations on the multiple shards of privacy data using a secret sharing algorithm to obtain shards of the target data.
[0012] In the third aspect of the embodiments of this specification, a data processing method for protecting privacy is provided, which is applied in the field of multi-party secure computing and includes:
[0013] Obtain multiple shards of target data, where the shards of the target data are calculated based on the shards of the private data, and the shards of the private data include function values of a first polynomial function, and the private data is encoded in the coefficients of the first polynomial function;
[0014] Use the multiple shards of the target data as multiple function values of a second polynomial function, and calculate the coefficients of the second polynomial function according to the multiple function values of the second polynomial function, and the target data is encoded in the coefficients of the second polynomial function;
[0015] Restore the target data according to the coefficients of the second polynomial function.
[0016] In the fourth aspect of the embodiments of this specification, a data processing device for protecting privacy is provided, which is applied in the field of multi-party secure computing and includes:
[0017] An encoding unit for encoding private data into the coefficients of a first polynomial function;
[0018] An obtaining unit for obtaining multiple function values of the first polynomial function as multiple shards after splitting the private data, and the shards of the private data are used for calculation by a secret sharing algorithm to obtain shards of the target data.
[0019] In the fifth aspect of the embodiments of this specification, a data processing device for protecting privacy is provided, which is applied in the field of multi-party secure computing and includes:
[0020] An obtaining unit for obtaining multiple shards of private data, where the shards of the private data include function values of a first polynomial function, and the private data is encoded in the coefficients of the first polynomial function;
[0021] A calculation unit for calculating the shards of the target data by using a secret sharing algorithm for the multiple shards of the private data.
[0022] In the sixth aspect of the embodiments of this specification, a data processing device for protecting privacy is provided, which is applied in the field of multi-party secure computing and includes:
[0023] An obtaining unit for obtaining multiple shards of the target data, where the shards of the target data are calculated based on the shards of the private data, and the shards of the private data include function values of a first polynomial function, and the private data is encoded in the coefficients of the first polynomial function;
[0024] A computing unit, configured to use multiple shards of target data as multiple function values of a second polynomial function, calculate the coefficients of the second polynomial function according to the multiple function values of the second polynomial function, and encode the target data in the coefficients of the second polynomial function;
[0025] A recovery unit, configured to recover the target data according to the coefficients of the second polynomial function.
[0026] In a seventh aspect of the embodiments of this specification, a computer device is provided, including:
[0027] At least one processor;
[0028] A memory storing program instructions, where the program instructions are configured to be executed by the at least one processor, and the program instructions include instructions for executing the methods described in the first aspect, the second aspect, or the third aspect.
[0029] The technical solution provided in the embodiments of this specification splits privacy data by using a first polynomial function. In addition, multiple shards of privacy data can be calculated locally to obtain shards of target data without relying on a third party, thereby improving the calculation efficiency of the secret sharing algorithm. In addition, the target data is recovered by using a second polynomial function. Description of the Drawings
[0030] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. The drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0031] Figure 1 It is a schematic diagram of the operation process of the secret sharing addition algorithm in the related art;
[0032] Figure 2 It is a schematic diagram of the operation process of the secret sharing multiplication algorithm in the related art;
[0033] Figure 3 It is a schematic diagram of the structure of a data processing system for protecting privacy in the embodiments of this specification;
[0034] Figure 4 It is a schematic flowchart of a data processing method for protecting privacy in the embodiments of this specification;
[0035] Figure 5 It is a schematic flowchart of a data processing method for protecting privacy in the embodiments of this specification;
[0036] Figure 6 Schematic flowchart of the data processing method for protecting privacy in the embodiments of this specification;
[0037] Figure 7 Schematic structural diagram of the data processing device for protecting privacy in the embodiments of this specification;
[0038] Figure 8 Schematic structural diagram of the data processing device for protecting privacy in the embodiments of this specification;
[0039] Figure 9 Schematic structural diagram of the data processing device for protecting privacy in the embodiments of this specification;
[0040] Figure 10 Schematic structural diagram of the computer device in the embodiments of this specification. Detailed implementation manners
[0041] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this specification without making creative efforts shall fall within the scope of protection of this specification.
[0042] To facilitate understanding of the technical solutions in the embodiments of this specification, the following introduces polynomial functions.
[0043] A polynomial function can be obtained through a finite number of addition, multiplication, and exponentiation operations. The polynomial function can include one or more monomials (hereinafter simply referred to as terms). The coefficients of the polynomial function can include the coefficients of each term in the polynomial function. The coefficient of the constant term can be understood as the constant term itself. The degree of the polynomial function can be the degree of the highest term. For example, the polynomial function can be expressed as f(x) = a n x n + a n-1 x n-1 + … + a2x 2 + a1x + a0. The coefficients of the polynomial function can include a n 、a n-1 、a2、a1、a0, etc., and the degree of the polynomial function can be n.
[0044] The polynomial function can include a coefficient representation method and a point representation method. In the coefficient representation method, the polynomial function can be represented according to the coefficients of the polynomial function. For example, according to the coefficients {a n 、a n-1, …, a2, a1, a0} can determine the polynomial function f(x) = a n x n + a n-1 x n-1 + … + a2x 2 + a1x + a0. In the point representation, the polynomial function can be represented according to the sampling points of the polynomial function, and the sampling points include the corresponding independent variable values and function values. For example, according to the sampling points {(x0, y0), (x1, y1), (x2, y2), …, (x n-1 , y n-1 ), (x n , y n )}, the polynomial function f(x) = a n x n + a n-1 x n-1 + … + a2x 2 + a1x + a0 can be determined. The point representation and the coefficient representation of the polynomial function are equivalent. Among them, in the point representation, if the degree of the polynomial function is n, at least n + 1 sampling points are required to determine the polynomial function.
[0045] Secure Multi-Party Computation (MPC), also known as Secure Multiparty Computation, is an algorithm for protecting data privacy and security. Secure Multi-Party Computation enables multiple participating parties holding private data to perform collaborative computational processing without revealing data privacy. Secret Sharing, also known as Secret Sharing, is a technology for implementing Secure Multi-Party Computation. The idea of Secret Sharing is to split the secret in an appropriate way to obtain multiple shards. The multiple shards are respectively handed over to different participating parties for safekeeping. A single participating party cannot recover the secret. Only several participating parties collaborating can recover the secret. For example, in a (t, n) threshold secret sharing scheme, the secret is split in an appropriate way to obtain n shards. The n shards are handed over to n participating parties for safekeeping. A single participating party cannot recover the secret, and only at least t participating parties collaborating can recover the secret. If there are fewer than t participating parties, the secret cannot be recovered. Among them, the t can be understood as the threshold value of the secret sharing scheme.
[0046] In the related art, the secret sharing algorithm can include a secret sharing addition algorithm and a secret sharing multiplication algorithm. Taking two participating parties, Alice and Bob, as an example, the secret sharing addition algorithm and the secret sharing multiplication algorithm are introduced respectively below.
[0047] Alice holds the secret A, and Bob holds the secret B. Alice can split the secret A to obtain shards a1 and a2; can keep the shard a1 by herself; can hand over the shard a2 to Bob for safekeeping. a1 + a2 = A. Bob can split the secret B to obtain shards b1 and b2; can hand over the shard b1 to Alice for safekeeping; can keep the shard b2 by himself. b1 + b2 = B.
[0048] Please refer to Figure 1 , in the secret sharing addition algorithm, Alice can add the shard a1 and the shard b1 to obtain the shard c1. Bob can add the shard a2 and the shard b2 to obtain the shard c2. Both c1 and c2 are shards of the secret C. c1 + c2 = C = A + B.
[0049] Please refer to Figure 2 , in the secret sharing multiplication algorithm, it is necessary to rely on a trusted third party (TTP, Trusted Third Party). Alice and Bob need to communicate with the third party respectively. Specifically, the third party can generate auxiliary data (triple). The auxiliary data can include random numbers u1, u2, v1, v2, p1, p2. The random numbers in the auxiliary data satisfy specific conditions: u1 + u2 = U, v1 + v2 = V, p1 + p2 = P, U × V = P. The third party can send the random numbers u1, v1, and p1 to Alice; can send the random numbers u2, v2, and p2 to Bob. Alice can calculate d1 = a1 - u1 and e1 = b1 - v1; can send d1 and e1 to Bob. Bob can calculate d2 = a2 - u2 and e2 = b2 - v2; can send d2 and e2 to Alice. Alice can calculate z1 = p1 + E × u1 + D × v1 + D × E. Bob can calculate z2 = p2 + E × u2 + D × v2. Both z1 and z2 are shards of the secret Z. z1 + z2 = Z = A × B. D = d1 + d2, E = e1 + e2.
[0050] In the above secret sharing algorithm, the secret is split in an additive form. For example, for secret A, the two shards a1 and a2 after splitting satisfy a1 + a2 = A, and for secret B, the two shards b1 and b2 after splitting satisfy b1 + b2 = B. As a result, in the secret sharing multiplication algorithm, it is necessary to rely on auxiliary data (triple) generated by a third party. The participants in the secret sharing algorithm need to communicate with the third party. This reduces the computational efficiency of the secret sharing algorithm. Additionally, the auxiliary data generated by the third party also needs to meet specific conditions. For example, the random numbers u1, u2, v1, v2, p1, and p2 generated by the third party need to meet the following specific conditions: u1 + u2 = U, v1 + v2 = V, p1 + p2 = P, and U × V = P. When the number of participants in the secret sharing algorithm is small (e.g., 2 or 3), it is relatively easy to generate auxiliary data that meets the specific conditions. However, when the number of participants in the secret sharing algorithm is large (e.g., 4 or more), it is more difficult to generate auxiliary data that meets the specific conditions. Therefore, the above secret sharing algorithm is only applicable to a small number of participants and is difficult to apply to a large number of participants.
[0051] Please refer to Figure 3 Embodiments of this specification provide a data processing system for protecting privacy. The data processing system may include multiple data party devices, multiple participant devices, and at least one recovery party device. The data party devices, the participant devices, and the recovery party devices may be computer devices with data processing capabilities. The computer device may be a personal computer, a laptop computer, a cellular phone, a smart phone, a personal digital assistant, a media player, a navigation device, a game console, a tablet computer, a wearable device, a server, or any combination of these devices.
[0052] The data party devices, the participant devices, and the recovery party devices may be different computer devices. Alternatively, multiple of the data party devices, the participant devices, and the recovery party devices may also be integrated into one computer device. For example, the data party device and the participant device may be integrated into one computer device, or the participant device and the recovery party device may be integrated into one computer device, or the data party device and the recovery party device may be integrated into one computer device.
[0053] The data party devices may be established by data parties. The participant devices may be established by participants. The recovery party devices may be established by recovery parties. The data parties, the participants, and the recovery parties may be different institutions. Alternatively, multiple of the data parties, the participants, and the recovery parties may also be the same institution. Among them, the institution may include financial institutions, government institutions, big data companies, e-commerce companies, cloud computing manufacturers for providing computing services, etc.
[0054] In some embodiments, the data provider device may hold private data. For the security of the private data, the data provider device cannot send the plaintext private data externally. The data provider device may split the private data. Specifically, the data provider device may encode the private data into the coefficients of a polynomial function (hereinafter referred to as the first polynomial function); may obtain multiple function values of the first polynomial function as multiple shards after splitting the private data; and may send the multiple shards of the private data to multiple participant devices. Thus, the private data is split using the first polynomial function.
[0055] Among them, the multiple data provider devices hold multiple different private data. Different data provider devices may encode the private data into the coefficients of different first polynomial functions. The degrees of different first polynomial functions may be the same or different.
[0056] In some embodiments, the participant device is used to perform encrypted calculations on multiple private data. Specifically, the participant device may obtain the shards of multiple private data; and may use a secret sharing algorithm to calculate the shards of the multiple private data to obtain the shards of the target data. Thus, the participant device can perform calculations on the shards of multiple private data locally without relying on a third party, improving the calculation efficiency of the secret sharing algorithm. Moreover, the calculation process does not need to depend on auxiliary data that meets specific conditions, and is applicable to multi-party secure calculation scenarios with a relatively large number of participant devices.
[0057] In some embodiments, the recovery device is used to recover the target data based on the shards of the target data. Specifically, the recovery device may obtain the multiple shards of the target data; may use the multiple shards of the target data as the multiple function values of a polynomial function (hereinafter referred to as the second polynomial function); may calculate the coefficients of the second polynomial function according to the multiple function values of the second polynomial function, where the target data is encoded in the coefficients of the second polynomial function; and may recover the target data according to the coefficients of the second polynomial function. Thus, the target data is recovered using the second polynomial function.
[0058] The embodiments of this specification provide a data processing method for protecting privacy. The method may be applied to the field of multi-party secure calculation. The method may be executed by any one of the multiple data provider devices.
[0059] Please refer to Figure 4 . The method may include the following steps.
[0060] Step S11: Encode the private data into the coefficients of the first polynomial function.
[0061] In some embodiments, the privacy data includes service data for performing multi-party secure computing. For example, the privacy data may include user data, commodity data, transaction data, behavior data, etc. The user data includes age, gender, occupation, etc., the commodity data includes the category of the commodity, review data, etc., the transaction data includes the transaction amount, transaction channel, etc., and the behavior data includes transaction behavior data, payment behavior data, purchase behavior data, etc. For another example, the privacy data may further include text data, image data, audio data, etc.
[0062] In some embodiments, the degree of the first polynomial function can be set according to at least one of the following.
[0063] (1) The number of participating party devices.
[0064] The sharding of the privacy data can be understood as the function values of the sampling points in the point representation. In the point representation, if the degree of the polynomial function is n, at least n + 1 sampling points are required to determine the polynomial function. Therefore, in order to be able to recover the privacy data from the sharding of the privacy data, the degree of the first polynomial function can be less than the number of shards of the privacy data. And considering that each participating party device can hold one shard of the privacy data, the number of shards of the privacy data can be equal to the number of participating party devices. Therefore, the degree of the first polynomial function can be less than the number of participating party devices.
[0065] (2) The degree of the secret sharing multiplication algorithm.
[0066] The sharding of the target data can be understood as the function values of the sampling points in the point representation. In the point representation, if the degree of the polynomial function is n, at least n + 1 sampling points are required to determine the polynomial function. Therefore, in order to be able to recover the target data from the sharding of the target data, the degree of the second polynomial function can be less than the number of shards of the target data. And considering that each participating party device can hold one shard of the target data, the number of shards of the target data can be equal to the number of participating party devices. Therefore, the degree of the second polynomial function can be less than the number of participating party devices.
[0067] Since the sharding of the target data is calculated based on the sharding of the privacy data, the degree of the second polynomial function is greater than or equal to the degree of the first polynomial function. For example, the sharding of the target data can be calculated from the sharding of the privacy data through the secret sharing addition algorithm, and then the degree of the second polynomial function can be equal to the degree of the first polynomial function. For another example, the sharding of the target data can also be calculated from the sharding of the privacy data through the secret sharing multiplication algorithm, and then the degree of the second polynomial function can be greater than the degree of the first polynomial function. Moreover, based on the degree of the first polynomial function, as the number of executions of the secret sharing multiplication algorithm increases, the degree of the second polynomial function also increases.
[0068] Therefore, considering the above factors comprehensively, the degree of the first polynomial function is also inversely related to the number of executions of the secret sharing multiplication algorithm. The more the number of executions of the secret sharing multiplication algorithm, the smaller the degree of the first polynomial function. The fewer the number of executions of the secret sharing multiplication algorithm, the greater the degree of the first polynomial function.
[0069] (3) The threshold value of the secret sharing algorithm.
[0070] The degree of the first polynomial function is also positively related to the threshold value of the secret sharing algorithm. The greater the degree of the first polynomial function, the greater the threshold value of the secret sharing algorithm, and the more shards are required to recover the target data. The smaller the degree of the first polynomial function, the smaller the threshold value of the secret sharing algorithm, and the more shards are required to recover the target data.
[0071] For example, the number of participating device is 3, and the number of executions of the secret sharing multiplication algorithm is 1. The degree of the first polynomial function can be set to 1. The first polynomial function can be expressed as f(x) = a1x + a0. Thus, for the sharding of the privacy data, the participating devices can perform the secret sharing addition algorithm multiple times and / or the secret sharing multiplication algorithm once. For another example, considering that compared with the secret sharing addition algorithm, the number of executions of the secret sharing multiplication algorithm is not much. Therefore, if the number of participating devices is p, the degree of the first polynomial function can be n = [p / 2], where [p / 2] represents the largest integer not exceeding p / 2.
[0072] In some embodiments, the coefficient of one or more terms in the first polynomial function can be the privacy data.
[0073] The constant term of the first polynomial function may be private data. Specifically, the private data may be determined as the constant term in the first polynomial function; random numbers may be generated as the coefficients of the other terms except the constant term in the first polynomial function. For example, the degree of the first polynomial function may be n. The private data may be determined as the constant term in the first polynomial function; m random numbers may be generated as the coefficients of the other n - 1 terms except the constant term in the first polynomial function, where m ≤ n - 1. For another example, the private data may be determined as the constant term in the first polynomial function and the coefficients of at least one other term except the constant term; random numbers may be generated as the coefficients of the remaining terms in the first polynomial function.
[0074] Alternatively, the coefficients of at least one other term except the constant term in the first polynomial function may be private data. Specifically, the private data may be determined as the coefficients of at least one other term except the constant term in the first polynomial function; random numbers may be generated as the coefficients of the remaining terms in the first polynomial function. For example, the private data may be determined as the coefficient of the first-degree term in the first polynomial function; random numbers may be generated as the coefficients of the other terms except the first-degree term in the first polynomial function.
[0075] Step S13: Obtain multiple function values of the first polynomial function as multiple shards after splitting the private data.
[0076] In some embodiments, values are corresponding to the participating party devices. The values corresponding to different participating party devices may be the same or different. For example, the number of participating party devices is 4. The values corresponding to the 4 participating party devices include 1, 2, 5, and 7. Multiple values corresponding to multiple participating party devices may be obtained as multiple values of the independent variable in the first polynomial function; multiple function values of the first polynomial function may be calculated according to the multiple values of the independent variable as multiple shards after splitting the private data.
[0077] The values corresponding to the participating party devices may be random numbers. Alternatively, the values corresponding to the participating party devices may also be values that meet certain conditions, such as values that follow a mathematical distribution such as a normal distribution. In practical applications, the values corresponding to the participating party devices may be obtained through negotiation between the data party device and the participating party devices. The data party device may obtain the negotiated values. Alternatively, the values corresponding to the participating party devices may also be generated by the participating party devices. The participating party devices may send the generated values to the data party device. The data party device may receive the values sent by the participating party devices. Of course, the values corresponding to the participating party devices may also be generated by the data party device or other computer devices. The embodiments of this specification do not make specific limitations in this regard.
[0078] In some embodiments, the sharding of private data is used for calculation using a secret sharing algorithm to obtain target data shards. Specifically, multiple shards of private data can be sent to multiple participating device parties. So that the participating device parties use the secret sharing algorithm to calculate based on the received shards of private data to obtain target data shards. In practical applications, for each participating device party, target shards can be selected from multiple shards of private data according to the value corresponding to the participating party and sent to the participating device party. The target shard is the target function value of the first polynomial function. The target function value matches the value corresponding to the participating device party (i.e., the value of the independent variable).
[0079] The data processing method of the embodiments of this specification can encode private data into the coefficients of the first polynomial function; multiple function values of the first polynomial function can be obtained as multiple shards after splitting the private data; the shards of private data are used for calculation using a secret sharing algorithm. In this way, the private data is split using the first polynomial function.
[0080] In some scenario examples, the data party device can hold private data A. The value corresponding to the participating device party P1 can be x1, the value corresponding to the participating device party P2 can be x2, and the value corresponding to the participating device party P3 can be x3.
[0081] In this scenario example, the first polynomial function can be expressed as y = ax + b. The data party device can determine the private data A as the constant term in the first polynomial function; a random number R can be generated as the coefficient of the first-degree term in the first polynomial function. That is, a = A and b = R. The encoded first polynomial function can be expressed as y = Ax + R.
[0082] In this scenario example, the data party device can substitute the value x1 into the encoded first polynomial function to obtain the function value y1 as a shard [A]0 after splitting the private data A; the value x2 can be substituted into the encoded first polynomial function to obtain the function value y2 as another shard [A]1 after splitting the private data A; the value x3 can be substituted into the encoded first polynomial function to obtain the function value y3 as another shard [A]2 after splitting the private data A.
[0083] In this scenario example, the data party device can send the shard [A]0 to the participating device party P1; send the shard [A]1 to the participating device party P2; send the shard [A]3 to the participating device party P3.
[0084] The embodiments of this specification also provide another data processing method for protecting privacy. The method can be applied to the field of multi-party secure computing. The method can be executed by any one of the multiple participating device parties.
[0085] Please refer to Figure 5 . The method may include the following steps.
[0086] Step S21: Obtain shards of multiple pieces of privacy data.
[0087] In some embodiments, the shards of privacy data may include function values of a first polynomial function. The process of splitting the privacy data to obtain shards may refer to the previous embodiments and will not be elaborated here.
[0088] In some embodiments, the participating party device and the data provider device may be different computer devices. Thus, multiple data provider devices may send shards of multiple pieces of privacy data to the participating party device. The participating party device may receive the shards of multiple pieces of privacy data. Among them, each data provider device may send at least one shard of privacy data to the participating party device. Alternatively, the participating party device and a certain data provider device may also be integrated into one computer device. Thus, one or more data provider devices may send one or more shards of privacy data to the participating party device. The participating party device may receive the shards of one or more pieces of privacy data. Additionally, the participating party device may also obtain a shard of privacy data locally.
[0089] Step S23: Use a secret sharing algorithm to calculate the shards of multiple pieces of privacy data to obtain shards of the target data.
[0090] In some embodiments, the target data may be the calculation result after performing multi-party secure computation on the privacy data of multiple data provider devices. For example, the target data may be user data, commodity data, transaction data, behavior data, statistical metrics, model parameters, prediction results of a model, etc. For another example, the target data may also include text data, image data, audio data, etc. The target data may be the final result. Alternatively, the target data may also be an intermediate result. Thus, the secret sharing algorithm may continue to be used to calculate based on the shards of the target data.
[0091] In some embodiments, the secret sharing algorithm may include a secret sharing addition algorithm. The target data may be the sum of the multiple pieces of privacy data. In practical applications, the shards of multiple pieces of privacy data may be added to obtain the shards of the target data. Alternatively, the secret sharing algorithm may include a secret sharing multiplication algorithm. The target data may be the product of the multiple pieces of privacy data. In practical applications, the shards of multiple pieces of privacy data may be multiplied to obtain the shards of the target data.
[0092] In some embodiments, the shards of the target data may also be sent to the recovery party device. So that the recovery party device can recover the target data based on the shards of the target data.
[0093] In the data processing method according to the embodiments of this specification, it is possible to obtain shards of multiple pieces of private data; a secret sharing algorithm can be used to calculate the shards of multiple pieces of private data. In this way, the participating device can calculate the shards of multiple pieces of private data locally without relying on a third party, improving the calculation efficiency of the secret sharing algorithm. Moreover, the calculation process does not need to rely on auxiliary data that meets specific conditions, and is applicable to the multi-party secure calculation scenario with a relatively large number of participating devices.
[0094] The embodiments of this specification also provide another data processing method for protecting privacy. The method can be applied to the field of multi-party secure calculation. The method can be executed by a recovery device.
[0095] Please refer to Figure 6 . The method may include the following steps.
[0096] Step S31: Obtain multiple shards of the target data.
[0097] In some embodiments, the generation process of the shards of the target data may refer to the previous embodiments and will not be elaborated here.
[0098] In some embodiments, the recovery device and the participating devices may be different computer devices. In this way, multiple participating devices can send multiple shards of the target data to the recovery device. The recovery device can receive multiple shards of the target data. Among them, each participating device can send one shard of the target data to the recovery device. Alternatively, the recovery device and a certain participating device can also be integrated into one computer device. In this way, one or more participating devices can send one or more shards of the target data to the recovery device. The recovery device can receive one or more shards of the target data. Additionally, the recovery device can also obtain one shard of the target data locally.
[0099] Step S33: Use the multiple shards of the target data as the multiple function values of a second polynomial function, and calculate the coefficients of the second polynomial function according to the multiple function values of the second polynomial function.
[0100] In some embodiments, it is possible to obtain multiple values corresponding to multiple participating devices as multiple values of the independent variable; the coefficients of the second polynomial function can be calculated according to the multiple values of the independent variable and the multiple function values of the second polynomial function.
[0101] The data provider device, the participating device, or other computer devices can send the values corresponding to the participating devices to the recovery device. The recovery device can receive the values corresponding to the participating devices.
[0102] For each participant device, the numerical value corresponding to the participant device and the slice of the target data calculated by the participant device can be understood as a sampling point of the second polynomial function. Therefore, the process of calculating the coefficients of the second polynomial function can be understood as the process of converting the second polynomial function from a point representation to a coefficient representation. In practical applications, the coefficients of the second polynomial function can be calculated by the Lagrange interpolation method. Of course, other methods can also be used to calculate the coefficients of the second polynomial function. For example, the equation combination method can be used to calculate the coefficients of the second polynomial function.
[0103] Step S35: Restore the target data according to the coefficients of the second polynomial function.
[0104] In some embodiments, target data is encoded in coefficients of the second polynomial function.
[0105] The coefficients of one or more items in the second polynomial function may be the target data. Which specific items' coefficients are the target data depends on the encoding method when encoding the private data into the coefficients of the first polynomial function. Specifically, if the coefficients of one or more items in the first polynomial function may be the private data, the coefficients of the corresponding items in the second polynomial function may be the target data, and the corresponding items may be items of the same order.
[0106] For example, the private data may be determined as a constant term in a first polynomial function, and the constant term in the second polynomial function may be the target data. For another example, the private data may be determined as a coefficient of a linear term in a first polynomial function, and the coefficient of a linear term in the second polynomial function may be the target data.
[0107] In some embodiments, the constant term of the second polynomial function may be determined as the target data. Alternatively, the coefficients of other terms except the constant term in the second polynomial function may be determined as the target data.
[0108] In some embodiments, all participating devices may send slices of the target data to the recovery device. The recovery device may recover the target data based on all slices of the target data. Alternatively, some participating devices may send slices of the target data to the recovery device. The recovery device may recover the target data based on some slices of the target data. For example, the degree of the second polynomial may be q. The number of participating devices may be p. p≥q+1. q+1 participating devices may send slices of the target data to the recovery device. The recovery device may recover the target data based on q+1 slices of the target data. In this way, when recovering the target data, only some participating devices may be required to participate.
[0109] The data processing method according to the embodiments of this specification can obtain multiple shards of target data; can use the multiple shards of target data as multiple function values of a second polynomial function, and calculate the coefficients of the second polynomial function according to the multiple function values of the second polynomial function; can restore the target data according to the coefficients of the second polynomial function. In this way, the target data is restored using the second polynomial function.
[0110] Multi-party secure computation based on secret sharing can be applied to various business scenarios, such as medical scenarios, model prediction scenarios, etc. The following introduces a scenario example of the embodiments of this specification. It should be noted that the scenario example is only for helping to understand the technical solutions of the embodiments of this specification, and does not constitute an improper limitation on the technical solutions of the embodiments of this specification.
[0111] The pricing of a restaurant menu is related to customers' evaluations of food, decoration, service, and the pedestrian flow near the restaurant's location.
[0112] In this scenario example, Institution A has trained a price prediction model. The price prediction model can be used to determine the pricing of a restaurant menu. The price prediction model can be a linear regression model. For example, the price prediction model can be expressed as z = β0 + β1x1 + β2x2 + β3x3 + β4y. Among them, β0, β1, β2, β3, β4 are the model parameters of the price prediction model, x1 represents the evaluation score of customers on food, x2 represents the evaluation score of customers on decoration, x3 represents the evaluation score of customers on service, and y represents the pedestrian flow data near the restaurant's location.
[0113] Institution B plans to open a new Italian restaurant at a target location in the city. To price the restaurant menu, Institution B organized a sampling survey in the city and obtained the evaluation scores of customers on aspects such as food, decoration, and service.
[0114] Institution C holds the pedestrian flow data near the target location.
[0115] In this scenario example, Institution B needs to obtain the pricing of the restaurant menu. Since Institution B does not have a price prediction model and the pedestrian flow data near the target location, Institution B can perform multi-party secure computation based on secret sharing with Institution A and Institution C. During the multi-party secure computation process, Institution A cannot disclose the price prediction model to Institution B and Institution C, Institution B cannot disclose the evaluation scores of customers on aspects such as food, decoration, and service to Institution A and Institution C, and Institution C cannot disclose the pedestrian flow data near the target location to Institution A and Institution B.
[0116] In this scenario example, the data processing system can include a first device, a second device, and a third device.
[0117] The first device is established by institution A. The first device has the functions of a data party device and a participant device. The second device is established by institution B. The second device has the functions of a data party device, a participant device and a restorer device. The third device is established by institution C. The third device has the functions of a data party device and a participant device.
[0118] For the model parameter β in the price prediction model i , the first device may adopt Figure 4 The method of the corresponding embodiment is to adjust the model parameter β i Split and get the model parameter β i The three shards [β i ]0,[β i ]1 and [β i ]2. The first device may send a fragment [β i ]1, can send fragments to the third device [β i ]2. The value of i can be 0, 1, 2, 3, 4, etc.
[0119] Customer evaluation score x i , the second device may adopt Figure 4 The method of the corresponding embodiment is to evaluate the score x i Split and get the evaluation score x i The three slices [x i ]0, [x i ]1 and [x i ]2. The second device may send the fragment [x i ]0, you can send fragments to the third device [x i ]2. The value of i can be 1, 2, 3, etc.
[0120] For the human flow data y, the third device can use Figure 4 The method of the corresponding embodiment splits the human flow data y to obtain three fragments [y]0, [y]1 and [y]2 of the human flow data y. The third device can send fragment [y]0 to the first device and can send fragment [y]1 to the second device.
[0121] In this scenario example, the first device can calculate [z]0 = [β0]0 + [β1]0[x1]0 + [β2]0[x2]0 + [β3]0[x3]0 + [β4]0[y]0. The second device can calculate [z]1 = [β0]1 + [β1]1[x1]1 + [β2]1[x2]1 + [β3]1[x3]1 + [β4]1[y]1. The third device can calculate [z]2 = [β0]2 + [β1]2[x1]2 + [β2]2[x2]2 + [β3]2[x3]2 + [β4]2[y]2. [z]0, [z]1, and [z]2 represent shards of the restaurant menu pricing.
[0122] In this scenario example, the first device can send the shard [z]0 to the second device. The third device can send the shard [z]2 to the second device. The second device can adopt Figure 6 the method of the corresponding embodiment to recover the restaurant menu pricing z according to the shards [z]0, [z]1, and [z]2. In this way, Party B obtains the pricing of the restaurant menu through multi-party secure computation based on secret sharing with Party A and Party C. Moreover, the data owned by Party A, Party B, and Party C themselves is not leaked.
[0123] The embodiments of this specification further provide a data processing device for protecting privacy. The device can be applied to the field of multi-party secure computation. The device can be set in any one of the multiple data party devices.
[0124] Please refer to Figure 7 . The device can include the following units.
[0125] An encoding unit 41, configured to encode privacy data into the coefficients of a first polynomial function;
[0126] An obtaining unit 43, configured to obtain multiple function values of the first polynomial function as multiple shards after splitting the privacy data. The shards of the privacy data are used for computation using a secret sharing algorithm to obtain target data shards.
[0127] The embodiments of this specification further provide another data processing device for protecting privacy. The device can be applied to the field of multi-party secure computation. The device can be set in any one of the multiple participating party devices.
[0128] Please refer to Figure 8 . The device can include the following units.
[0129] An obtaining unit 51, configured to obtain multiple shards of privacy data, where the shards of the privacy data include function values of a first polynomial function, and privacy data is encoded in the coefficients of the first polynomial function;
[0130] The calculation unit 53 is configured to calculate shards of multiple pieces of private data by using a secret sharing algorithm to obtain shards of target data.
[0131] An embodiment of this specification further provides another data processing device for protecting privacy. The device can be applied to the field of multi-party secure computing. The device can be set in the recovery party device.
[0132] Please refer to Figure 9 . The device may include the following units.
[0133] The acquisition unit 61 is configured to acquire multiple shards of target data, where the shards of target data are obtained by calculating shards of private data, and the shards of private data include function values of a first polynomial function, and private data is encoded in the coefficients of the first polynomial function;
[0134] The calculation unit 63 is configured to use the multiple shards of target data as multiple function values of a second polynomial function, and calculate the coefficients of the second polynomial function according to the multiple function values of the second polynomial function, and target data is encoded in the coefficients of the second polynomial function;
[0135] The recovery unit 65 is configured to recover the target data according to the coefficients of the second polynomial function.
[0136] Next, an embodiment of the computer device in this specification is introduced. Figure 10 is a schematic diagram of the hardware structure of the computer device in this embodiment. As Figure 10 shown, the computer device may include one or more (only one is shown in the figure) processors, a memory, and a transmission module. Of course, those of ordinary skill in the art can understand that Figure 10 the hardware structure shown is only schematic and does not limit the hardware structure of the above computer device. In practice, the computer device may further include more or fewer component units than Figure 10 shown; or, have a different configuration from Figure 10 shown.
[0137] The memory may include a high-speed random access memory; or, may further include a non-volatile memory, such as one or more magnetic storage devices, a flash memory, or other non-volatile solid-state memories. Of course, the memory may further include a network memory set remotely. The memory may be used to store program instructions or modules of application software, such as the program instructions or modules corresponding to this specification Figure 4 、 Figure 5 or Figure 6 .
[0138] The processor can be implemented in any suitable manner. For example, the processor can take the form of, for example, a microprocessor or a processor, a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, etc. The processor can read and execute the program instructions or modules in the memory.
[0139] The transmission module can be used for data transmission via a network, such as data transmission via networks such as the Internet, an intranet, a local area network, a mobile communication network, etc.
[0140] This specification also provides an embodiment of a computer storage medium. The computer storage medium includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a cache, a hard disk drive (HDD), a memory card, etc. The computer storage medium stores computer program instructions. When the computer program instructions are executed, it realizes: this specification Figure 4 、 Figure 5 Or Figure 6 The program instructions or modules corresponding to the corresponding embodiments.
[0141] It should be noted that the various embodiments in this specification are described in a progressive manner. For the same or similar parts between the various embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the apparatus embodiments, computer device embodiments, and computer storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the partial description of the method embodiments. Additionally, it can be understood that after reading this specification document, those skilled in the art can, without creative labor, think of arbitrarily combining some or all of the embodiments listed in this specification, and these combinations are also within the scope of disclosure and protection of this specification.
[0142] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (improvements to method flows). However, with the development of technology, many method flow improvements today can be regarded as direct improvements to hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented using a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system onto a single PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compilers used when developing and writing programs. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not just one type of HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow using the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.
[0143] The systems, apparatuses, modules or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0144] From the description of the above embodiments, those skilled in the art can clearly understand that this specification can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of this specification, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this specification.
[0145] This specification can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet-type devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on.
[0146] This specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification can also be practiced in a distributed computing environment, where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
Claims
1. A privacy - protecting data processing method, which is applied to a data - holding device that holds privacy data; the method includes: Encoding the privacy data into the coefficients of a first polynomial function, such that the coefficients of one or more terms in the first polynomial function are the privacy data; Taking the multiple values corresponding to multiple participating devices as independent variables and inputting them into the first polynomial function to obtain multiple function values of the first polynomial function as multiple shards after splitting the privacy data; Sending the multiple shards of the privacy data to the multiple participating devices respectively.
2. According to the method of claim 1, the encoding of the privacy data into the coefficients of the first polynomial function includes: Determining the privacy data as the constant term in the first polynomial function; Generating random numbers as the coefficients of the terms other than the constant term in the first polynomial function.
3. The method according to claim 1, wherein The multiple values are negotiated between the data - holding device and each participating device.
4. The method according to claim 1, wherein The multiple values are generated by the multiple participating devices and sent to the data - holding device.
5. A privacy - protecting data processing method, which is applied to a participating device, the method includes: Obtaining multiple shards of privacy data, where any shard of privacy data includes the function value of a first polynomial function, and the function value of the first polynomial is obtained by taking the value corresponding to the participating device as an independent variable and inputting it into the first polynomial function, and the coefficients of one or more terms in the first polynomial function are the privacy data; Calculating the shards of the target data by using a secret - sharing algorithm on the multiple shards of privacy data.
6. According to the method of claim 5, The calculating the shards of the target data by using a secret - sharing multiplication algorithm includes: Multiplying the multiple shards of privacy data; and / or Adding the multiple shards of privacy data.
7. According to the method of claim 5, the method further includes: Sending the shards of the target data to a recovery device.
8. A privacy - protecting data processing method, which is applied to a recovery device, the method includes: Obtaining multiple shards of the target data, where the shards of the target data are obtained by calculating multiple shards of privacy data by using a secret - sharing algorithm, and any shard of privacy data includes the function value of a first polynomial function, and the function value of the first polynomial is obtained by taking the value corresponding to the participating device as an independent variable and inputting it into the first polynomial function, and the coefficients of one or more terms in the first polynomial function are the privacy data held by the data - holding device; Taking the multiple shards of the target data as the multiple function values of a second polynomial function, and calculating the coefficients of the second polynomial function according to the multiple function values of the second polynomial function, where the target data is encoded in the coefficients of the second polynomial function; Recovering the target data according to the coefficients of the second polynomial function.
9. According to the method of claim 8, the calculating the coefficients of the second polynomial function includes: Obtaining the multiple values corresponding to multiple participating devices as multiple values of the independent variables; Calculate the coefficients of the second polynomial function based on multiple values of the independent variable and multiple function values of the second polynomial function.
10. The method according to claim 8, wherein The constant term in the first polynomial function is the privacy data, and recovering the target data includes: Determine the constant term in the second polynomial function as the target data.
11. A privacy-protecting data processing method applied to a data processing system, which includes multiple data party devices, multiple participating party devices, and at least one recovery party device; the method includes: Any one of the multiple data party devices encodes the privacy data it holds into the coefficients of a first polynomial function, such that one or more coefficients in the first polynomial function are the privacy data; inputs the multiple values corresponding to the multiple participating party devices as independent variables into the first polynomial function to obtain multiple function values of the first polynomial function as multiple shards after splitting the privacy data; and respectively sends the multiple shards of the privacy data to the multiple participating party devices. Any one of the multiple participating party devices obtains multiple shards of privacy data from the multiple data party devices, and calculates the shards of the target data by using a secret sharing algorithm for the multiple shards of privacy data. Any recovery party device obtains multiple shards of the target data from the multiple participating party devices, takes the multiple shards of the target data as multiple function values of a second polynomial function, calculates the coefficients of the second polynomial function according to the multiple function values of the second polynomial function, and the target data is encoded in the coefficients of the second polynomial function; and recovers the target data according to the coefficients of the second polynomial function.
12. A privacy-protecting data processing device applied to a data party device that holds privacy data; The device includes: An encoding unit for encoding the privacy data into the coefficients of a first polynomial function, such that one or more coefficients in the first polynomial function are the privacy data. An obtaining unit for inputting the multiple values corresponding to the multiple participating party devices as independent variables into the first polynomial function to obtain multiple function values of the first polynomial function as multiple shards after splitting the privacy data. A sending unit for respectively sending the multiple shards of the privacy data to the multiple participating party devices.
13. A privacy-protecting data processing device applied to a participating party device, the device includes: An obtaining unit for obtaining multiple shards of privacy data, where any shard of privacy data includes a function value of a first polynomial function, and the function value of the first polynomial is obtained by inputting the value corresponding to the participating party device as an independent variable into the first polynomial function, and one or more coefficients in the first polynomial function are the privacy data. A calculating unit for calculating the shards of the target data by using a secret sharing algorithm for the multiple shards of privacy data.
14. A privacy-protecting data processing device applied to a recovery party device, the device includes: An acquisition unit, configured to acquire multiple shards of target data, wherein the shards of the target data are obtained by performing calculations on the shards of multiple private data by using a secret sharing algorithm, and the shard of any private data includes the function value of a first polynomial function, and the function value of the first polynomial is obtained by taking the value corresponding to the participating party device as the independent variable and inputting it into the first polynomial function, and the coefficient of one or more terms in the first polynomial function is the private data held by the data party device; A calculation unit, configured to use the multiple shards of target data as the multiple function values of a second polynomial function, and calculate the coefficients of the second polynomial function according to the multiple function values of the second polynomial function, wherein the target data is encoded in the coefficients of the second polynomial function; A recovery unit, configured to recover the target data according to the coefficients of the second polynomial function.
15. A computer device, comprising: At least one processor; A memory storing program instructions, wherein the program instructions are configured to be executed by the at least one processor, and the program instructions include instructions for executing the method according to any one of claims 1-10.