Multi-party secret state sample alignment method and device, equipment and storage medium
By using coding functions, Shamir key sharing algorithm and Lagrangian interpolation method in multi-party secret calculation, the privacy protection and robustness of multi-party secret sample alignment methods are solved, efficient and accurate sample alignment is achieved, and data security and calculation stability are ensured.
Patent Information
- Application Number
- CN202510841221.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-07-22
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing multi-party secret sample alignment method has shortcomings in terms of privacy protection and robustness, making it difficult to effectively cooperate with multiple parties, resulting in data security risks.
The original samples are mapped to the bit vector through the client, and the encrypted sample index is generated using the encoding function, and summed it on the server side. The reconstructed sample index is generated by combining the Shamir key sharing algorithm and the Lagrangian interpolation method. The client selects the alignment samples according to the selection strategy, and uses the Goldwasser-Sipser algorithm to verify the intersection size of the reconstructed sample index.
It ensures data privacy and computing efficiency in multi-party dense state computing, improves the accuracy and robustness of sample alignment, can maintain stability in case of failure or error, and improves service quality.
Smart Images

Figure CN120358090A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of privacy computing, and in particular, to a multi-party encrypted sample alignment method, apparatus, device, and storage medium. Background Art
[0002] Multi-party encrypted computation (MPC, Secure Multi-Party Computation) is a cryptographic technology for protecting data privacy. It enables multiple different parties to collaborate to achieve a computing goal without a trusted third party, and ensures that each party cannot obtain any private data information of other parties except for the computing result. Sample alignment is a crucial step in multi-party encrypted computation. Its purpose is to integrate different data features of the same user owned by different parties, thereby improving the overall quality of multi-party encrypted computation and ensuring that data privacy is protected and unauthorized access is prevented when aligning samples between different clients. However, the current multi-party encrypted sample alignment methods have poor privacy protection, lack an effective multi-party collaboration mechanism, and also have insufficient robustness when dealing with the complexity and uncertainty in actual multi-party encrypted network transmission, which may lead to data security risks.
[0003] Therefore, how to perform efficient and reliable private sample alignment is a technical problem to be solved in current multi-party encrypted computation. Summary of the Invention
[0004] According to embodiments of the present application, a multi-party encrypted sample alignment method, apparatus, device, and storage medium are provided, which can effectively protect the data privacy of multiple clients and promote multi-party secure collaboration.
[0005] In the first aspect of the present application, a multi-party encrypted sample alignment method is provided. The method includes: Each client maps the original sample to a bit vector, converts the bit vector into a sample index vector by using an encoding function, generates a first encrypted sample index according to the sample index vector, the first privacy vector, and the public matrix, and sends the first encrypted sample index to the server; After receiving the first encrypted sample index, the server performs a summation calculation on the first encrypted sample index to obtain a second encrypted sample index, and then generates a reconstructed sample index according to the second encrypted sample index, the public matrix, and the second privacy vector, and sends the reconstructed sample index to the client; The client selects aligned samples from the samples corresponding to the reconstructed sample index according to the first selection strategy.
[0006] In a possible implementation, the first privacy vector is randomly generated by the client; The public matrix is shared among each client.
[0007] In a possible implementation, the method for calculating the second privacy vector includes: The first client inputs the first privacy vector into the Shamir secret sharing algorithm to obtain N key blocks. Then, the N key blocks are encrypted to generate an encrypted key, and the encrypted key is sent to the server; The server obtains the encrypted key from the first client and forwards it to the second client; The second client decrypts the encrypted key and generates an intermediate result, and sends the intermediate result to the server; The server performs Lagrange interpolation calculation on the intermediate result according to the homomorphic additivity of the Shamir secret sharing algorithm to obtain the second privacy vector; The first client and the second client are different clients among the clients.
[0008] Optionally, the server performs Lagrange interpolation calculation on the intermediate result according to the homomorphic additivity of the Shamir secret sharing algorithm to obtain the second privacy vector, and further includes: When the number of intermediate results is greater than the first threshold, the server can perform Lagrange interpolation calculation.
[0009] In a possible implementation, the first selection strategy includes: After receiving the reconstructed sample index, the client performs inverse coding on the reconstructed sample index according to the coding function; When the inverse coding result value of the reconstructed sample index is 1, the sample corresponding to the reconstructed sample index is selected as the alignment sample.
[0010] In a possible implementation, the method further includes: Evaluating the intersection size of the reconstructed sample indexes of the clients. When the intersection size of the reconstructed sample indexes of the clients is greater than the second threshold, the clients can participate in multi-party encrypted state calculation.
[0011] Optionally, the intersection size of the reconstructed sample indexes of the clients is determined by the Goldwasser-Sipser algorithm; The Goldwasser-Sipser algorithm performs cyclic verification on each client according to the set of reconstructed sample indexes sent by each client to the server.
[0012] In the second aspect of the present application, a multi-party encrypted state sample alignment device is provided. The device includes: An encryption index module, where each client maps the original sample to a bit vector, converts the bit vector into a sample index vector by using the coding function, generates a first encrypted sample index according to the sample index vector, the first privacy vector, and the public matrix, and sends the first encrypted sample index to the server; The reconstructed index module, after receiving the first encrypted sample index by the server, performs a summation calculation on the first encrypted sample index to obtain a second encrypted sample index, then generates a reconstructed sample index according to the second encrypted sample index, the public matrix, and the second privacy vector, and sends the reconstructed sample index to the client; The selection module, by which the client selects aligned samples from the samples corresponding to the reconstructed sample index according to the first selection strategy.
[0013] In the third aspect of the present application, an electronic device is provided. The electronic device includes: a memory and a processor, a computer program is stored on the memory, and when the processor executes the program, the method as described above is implemented.
[0014] In the fourth aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the method according to the first aspect of the present application is implemented.
[0015] In the multi-party encrypted sample alignment method provided by the embodiments of the present application, each client maps the original sample to a bit vector, converts the bit vector into a sample index vector by using an encoding function, generates a first encrypted sample index according to the sample index vector, the first privacy vector, and the public matrix, and sends the first encrypted sample index to the server. Then, after receiving the first encrypted sample index, the server performs a summation calculation on the first encrypted sample index to obtain a second encrypted sample index, then generates a reconstructed sample index according to the second encrypted sample index, the public matrix, and the second privacy vector, and sends the reconstructed sample index to the client. Finally, the client selects aligned samples from the samples corresponding to the reconstructed sample index according to the first selection strategy. While ensuring data privacy and security, the computing efficiency and flexibility are improved, an effective privacy solution is provided for multi-party encrypted sample alignment, and the robustness of the computing process and the accuracy of the alignment result are ensured. Even in the case of failures or untrusted clients, it can remain stable, be able to handle potential errors or failures, ensure the accuracy of the sample alignment process, meet the requirements of practical applications, and improve the service quality.
[0016] It should be understood that the content described in the summary of the invention section is not intended to limit the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Combined with the drawings and referring to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present application will become more obvious. In the drawings, the same or similar reference numerals represent the same or similar elements, where: Figure 1Flowchart of a multi-party encrypted sample alignment method according to an embodiment of the present application; Figure 2 Flowchart of a calculation method for a second privacy vector according to an embodiment of the present application; Figure 3 System architecture diagram related to the method provided by the embodiment of the present application.
[0018] Figure 4 Block diagram of a multi-party encrypted sample alignment device according to an embodiment of the present application; Figure 5 Structural schematic diagram of a terminal device or a server suitable for implementing the embodiments of the present application. Detailed implementation manners
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.
[0020] In addition, the term "and / or" in this document is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, both A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after.
[0021] Figure 1 Shows a flowchart of a multi-party encrypted sample alignment method according to an embodiment of the present disclosure. Refer to Figure 1 , the method includes: S101. Each client maps the original sample to a bit vector, converts the bit vector into a sample index vector by using an encoding function, generates a first encrypted sample index according to the sample index vector, the first privacy vector, and a public matrix, and sends the first encrypted sample index to the server.
[0022] In a possible embodiment, the original sample of the client can be mapped and represented as a bit vector by using a hash function. Then, since directly performing calculations using bit operations may disclose sensitive information in the client data, to avoid this situation, the client will continue to use the encoding function to convert the bit vector from the encoding space into a sample index vector in the The encoding function has a mapping formula of , where is a preset security parameter . Then, the first encrypted sample index is generated based on the sample index vector, the first privacy vector, and the public matrix , and its calculation formula is as follows , where is the public matrix is the first privacy vector
[0023] In this embodiment, by mapping the client's original sample to a bit vector and then converting it to a sample index vector using the encoding function, the server does not need to access the sensitive data of the client, effectively protecting the privacy of the client's original sample data
[0024] Optionally, the first privacy vector is randomly generated by the client The public matrix is shared among each client
[0025] In this embodiment, the first privacy vector is randomly generated by the client, increasing the randomness and unpredictability in the sample alignment process and improving the robustness of multi-party encrypted computing. Moreover, the public matrix is shared among each client, making the calculations in the sample alignment process consistent and ensuring that the samples between different clients can be correctly matched and aligned
[0026] S102. After receiving the first encrypted sample index, the server performs a summation calculation on the first encrypted sample index to obtain a second encrypted sample index, then generates a reconstructed sample index based on the second encrypted sample index, the public matrix, and the second privacy vector, and sends the reconstructed sample index to the client
[0027] In a possible embodiment, after the server receives the first encrypted sample index , it performs a summation calculation on the first encrypted sample index to obtain the second encrypted sample index , and the reconstructed sample index can be obtained from the formula , where is the second privacy vector
[0028] In this embodiment, the server side can aggregate the first encrypted sample index, protecting the data privacy of the client while realizing data reconstruction, providing a basis for sample alignment in subsequent multi-party encrypted computing
[0029] Optionally, the calculation method of the second privacy vector includes S201, the first client inputs the first privacy vector into the Shamir key sharing algorithm to obtain N key blocks, then encrypts the N key blocks to generate an encryption key, and sends the encryption key to the server; S202, the server obtains an encryption key from the first client and forwards it to the second client; S203, the second client decrypts the encryption key and generates an intermediate result, and sends the intermediate result to the server; S204, the server performs Lagrange interpolation calculation on the intermediate result according to the homomorphic additivity of the Shamir key sharing algorithm to obtain a second privacy vector; S205: The first client and the second client are different clients.
[0030] Figure 2 A flow chart of a method for calculating a second privacy vector according to an embodiment of the present disclosure is shown. Figure 2 shown.
[0031] Shamir's Secret Sharing Scheme is a threshold cryptography method. It allows a secret to be divided into multiple parts, which are called "shares". Only when a sufficient number of shares are collected can the original secret be reconstructed. Specifically, if the secret S is divided into n shares and a threshold k is set (1 ≤ k ≤ n), then any combination of k shares or more can be used to reconstruct the original secret, but combinations with less than k shares cannot be reconstructed. In multi-party secret computing, each participating client needs to jointly calculate certain private results. Using the Shamir's Secret Sharing Scheme, these sensitive private results can be divided into multiple shares and sent to different participating clients. Only when the preset threshold is reached can these shares be used to reconstruct the original private results, thereby ensuring that even if individual participating clients are attacked, sensitive information will not be leaked, which not only ensures effective multi-party secret computing, but also avoids the risk of data exposure of a single participant.
[0032] In a possible embodiment, the first client The first privacy vector In the Shamir key sharing algorithm, it is divided into N key blocks, and the representation of N key blocks is as follows: , in, For Clients The first privacy vector Then, the first client Using a Second Client public key Mix-encrypt the key block of the k-th column to generate an encryption key An example of the calculation formula can be as follows: , where represents the process of splitting the key into multiple shares in the Shamir secret sharing algorithm. The server forwards the encryption key to the second client After that, the second client decrypts the encryption key An example of the decryption formula can be as follows: , where represents the process of the second client decrypting according to the key data it stores in the Shamir secret sharing algorithm. Then, the second client aggregates the N decrypted key blocks to generate an intermediate result The calculation formula is as follows: .
[0033] Finally, the server performs Lagrange interpolation calculation on the intermediate result according to the homomorphic additivity of the Shamir secret sharing algorithm. The calculation formula is as follows: , where is the Lagrange coefficient is the first threshold.
[0034] Among them, Lagrange Interpolation is a method for constructing a polynomial function through known data points. The main purpose is to construct a polynomial based on the given points so that this polynomial can take the corresponding function values at these points, and it is suitable for the case where the number of data points is small.
[0035] In this embodiment, by using the Shamir secret sharing algorithm to calculate the second private vector, efficient, secure and robust privacy protection is achieved, and the privacy of each client's data is guaranteed.
[0036] Optionally, when the server performs Lagrange interpolation calculation on the intermediate result according to the homomorphic additivity of the Shamir secret sharing algorithm to obtain the second private vector, it further includes: When the number of intermediate results is greater than the first threshold, the server can perform Lagrange interpolation calculation.
[0037] In a possible embodiment, such as the second client Perform an aggregation operation on the N decrypted key blocks to generate an intermediate result As shown in the calculation formula, as long as the number of intermediate results is greater than or equal to the first threshold Lagrange interpolation can be performed to obtain the second private vector, which well solves the learning with errors (LWE) problem. The learning with errors problem uses a given positive integer, prime number, error parameter, and a spatial distribution range to randomly select a vector from the spatial distribution and calculate a linear equation that can tolerate errors. It has many important applications in fields such as constructing encryption schemes. By introducing error terms, it becomes extremely difficult to recover secret information from public data, providing a security foundation for cryptography.
[0038] In this embodiment, by setting the first threshold, the server can perform Lagrange interpolation without all the intermediate results, enabling the calculation of the second private vector to have a certain fault tolerance ability.
[0039] S103. The client selects aligned samples from the samples corresponding to the reconstructed sample index according to the first selection strategy.
[0040] In this embodiment, by using the first selection strategy, it can ensure the consistency of sample alignment between different clients, and further guarantee the consistency and accuracy of data samples in the multi-party encrypted state learning process.
[0041] Optionally, the first selection strategy includes: After receiving the reconstructed sample index, the client performs inverse coding on the reconstructed sample index according to the coding function; When the inverse coding result value of the reconstructed sample index is 1, the sample corresponding to the reconstructed sample index is selected as the aligned sample.
[0042] In a possible embodiment, from the mapping formula of the aforementioned coding function it can be obtained that the inverse coding function is , where is a preset security parameter, . If there exists a bit vector , then the sample corresponding to the reconstructed sample index will be uniformly distributed in the coding space , indicating that it can be used as a sample in the intersection of the reconstructed samples. That is, the aligned sample, otherwise it cannot be used as the aligned sample. Among them, In this embodiment, the first selection strategy filters the aligned samples from the samples corresponding to the reconstructed sample index through the inverse coding result value, realizing the selection of aligned samples in multi-party encrypted state calculation while ensuring the privacy of multiple clients.
[0043] Optionally, the method further includes: Evaluating the size of the intersection of the reconstructed sample indexes of the client. Only when the size of the intersection of the reconstructed sample indexes of the client is greater than a second threshold can the client participate in the multi-party encrypted state calculation.
[0044] For example, the sizes of the intersections of the reconstructed sample indexes between client A and client B are 150 and 80 respectively, and the second threshold is 100. Then, the size of the intersection of the reconstructed sample indexes of client A meets the requirements, and it has enough reconstructed sample index data to participate in the multi-party encrypted state calculation, while client B does not have enough reconstructed sample index data and cannot participate in the multi-party encrypted state calculation.
[0045] In this embodiment, by evaluating the size of the intersection of the reconstructed sample indexes of the client, it can be ensured that only the client with a larger intersection of the reconstructed sample indexes can participate in the multi-party encrypted state calculation, which helps to improve the quality of the data of each participating client in the multi-party encrypted state calculation and ensures the fairness of multiple clients.
[0046] Optionally, the size of the intersection of the reconstructed sample indexes of the client is determined by the Goldwasser-Sipser algorithm; The Goldwasser-Sipser algorithm circularly verifies each client according to the set of reconstructed sample indexes sent by each client to the server.
[0047] The Goldwasser-Sipser algorithm is an algorithm for generating pseudo-random numbers. It cleverly uses the concept of zero-knowledge proof. Without revealing any information about the graph, it proves to the verifier that the prover knows a sufficiently large clique or independent set in the graph without the verifier actually knowing what the clique / independent set is specifically. In multi-party encrypted state calculation, the Goldwasser-Sipser algorithm can be used as a tool to enhance security and privacy protection. It verifies the attributes and correctness of the data in a zero-knowledge proof manner, ensuring the protection of the data of the participating parties during the federated learning process, thereby enhancing the trust between the participating parties.
[0048] In a possible embodiment, the server will circularly verify and count the clients in sequence of the reconstructed sample indexes the number of elements equal to the number of clients participating in the multi-party encrypted state learning, that is, the size of the intersection of the reconstructed sample indexes of the client. If the size of the intersection of the reconstructed sample indexes of the client is greater than the second threshold, then the client can participate in the multi-party encrypted state calculation.
[0049] In this embodiment, the Goldwasser-Sipser algorithm is used to determine the size of the intersection of the reconstructed sample indices of the client, providing an efficient verification mechanism, improving the quality of the participating clients and reducing the communication overhead, and providing a good data basis for multi-party encrypted state computing.
[0050] Figure 3 The system architecture diagram related to the method provided by the embodiment of this application is as Figure 3 shown: The client calculates the first encrypted sample index by calculating the sample index vector, the first privacy vector, and the public matrix, and sends the first encrypted sample index to the server side to avoid data leakage to other clients. The server side calculates the second encrypted sample index according to the first encrypted sample index. Then, further generate the reconstructed sample index according to the second encrypted sample index, the public matrix, and the second privacy vector, and select the aligned samples according to the first selection strategy, which well solves the problem of inconsistent data of different clients in multi-party encrypted state learning. Among them, the second privacy vector is calculated by the Shamir secret sharing algorithm, which ensures the security of multi-client computing. In addition, the server side will also use the Goldwasser-Sipser algorithm to calculate the size of the intersection of the reconstructed sample indices of the client, screen the clients with sufficient intersection of the reconstructed sample indices for multi-party encrypted state computing, effectively control the value of the client data participating in multi-party encrypted state computing, and ensure the effectiveness of multi-party encrypted state computing.
[0051] According to the embodiments of the present disclosure, the following technical effects are achieved: 1) Through a complex encryption and decryption mechanism, it is ensured that reliable aligned samples can be obtained in multi-party encrypted state computing, guaranteeing the robustness of the computing process and the accuracy of the alignment result.
[0052] 2) The multi-party encrypted state computing between multiple clients is only started when the size of the sample intersection reaches the second threshold, effectively solving the problems of security and scalability.
[0053] 3) The first privacy vector is randomly generated by the client, enhancing the robustness in the sample alignment process and ensuring accurate alignment results can still be obtained in case of failures or errors.
[0054] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0055] The above is the introduction of method embodiments. The following further illustrates the solution of the present application through apparatus embodiments.
[0056] Figure 4 The block diagram of the multi-party encrypted sample alignment apparatus according to an embodiment of the present application is shown. As Figure 4 shown, it includes: The encryption index module 401, where each client maps the original sample to a bit vector, converts the bit vector into a sample index vector using an encoding function, generates a first encrypted sample index according to the sample index vector, the first privacy vector, and the public matrix, and sends the first encrypted sample index to the server; The reconstruction index module 402, where after receiving the first encrypted sample index, the server performs a summation calculation on the first encrypted sample index to obtain a second encrypted sample index, and then generates a reconstructed sample index according to the second encrypted sample index, the public matrix, and the second privacy vector, and sends the reconstructed sample index to the client; The selection module 403, where the client selects aligned samples from the samples corresponding to the reconstructed sample index according to the first selection strategy.
[0057] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the described modules can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0058] Figure 5 The structural schematic diagram of a terminal device or a server suitable for implementing the embodiments of the present application is shown.
[0059] As Figure 5 shown, the terminal device or the server includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 502 or the program loaded from the storage section 508 into the random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the terminal device or the server are also stored. The CPU 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. The input / output (I / O) interface 505 is also connected to the bus 504.
[0060] The following components are connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, etc.; an output section 507 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. as well as a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, a modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as needed. A removable medium 511 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is installed on the drive 510 as needed so that a computer program read therefrom is installed into the storage section 508 as needed.
[0061] Specifically, according to an embodiment of the present application, the above method flow steps can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product that includes a computer program carried on a machine-readable medium, and the computer program includes program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 509, and / or installed from the removable medium 511. When the computer program is executed by a central processing unit (CPU) 501, the above functions defined in the system of the present application are executed.
[0062] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this application, a computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. And in this application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0063] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code, and the aforementioned module, program segment, or part of code contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutively shown blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0064] The units or modules involved in the embodiments described in this application can be implemented in software or in hardware. The described units or modules can also be provided in a processor. Among them, the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves.
[0065] As another aspect, this application also provides a computer-readable storage medium, which can be included in the electronic device described in the foregoing embodiments; or can exist separately without being assembled into the electronic device. The foregoing computer-readable storage medium stores one or more programs, and when the foregoing programs are executed by one or more processors, the methods described in this application are implemented.
[0066] The above description is only a preferred embodiment of this application and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the application involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing application concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions described in this application.
Claims
1. A multi-party confidential sample alignment method, characterized in that, Including: Each client maps the original sample to a bit vector, converts the bit vector into a sample index vector by using an encoding function, generates a first encrypted sample index according to the sample index vector, the first privacy vector, and a public matrix, and sends the first encrypted sample index to the server; After receiving the first encrypted sample index, the server performs a summation calculation on the first encrypted sample index to obtain a second encrypted sample index, and then generates a reconstructed sample index according to the second encrypted sample index, the public matrix, and a second privacy vector, and sends the reconstructed sample index to the client; The client selects an aligned sample from the samples corresponding to the reconstructed sample index according to a first selection strategy.
2. The multi-party encrypted sample alignment method according to claim 1, wherein: The first privacy vector is randomly generated by the client; The public matrix is shared among each of the clients.
3. The multi-party confidential sample alignment method according to claim 1, wherein The calculation method of the second privacy vector includes: The first client inputs the first privacy vector into the Shamir secret sharing algorithm to obtain N key blocks, then encrypts the N key blocks to generate an encrypted key, and sends the encrypted key to the server; The server obtains the encrypted key from the first client and forwards it to the second client; The second client decrypts the encrypted key and generates an intermediate result, and sends the intermediate result to the server; The server performs Lagrange interpolation calculation on the intermediate result according to the homomorphic additivity of the Shamir secret sharing algorithm to obtain the second privacy vector; The first client and the second client are different clients among the clients.
4. The multi-party confidential sample alignment method according to claim 3, wherein The server performs interpolation calculation on the Lagrange intermediate result according to the homomorphic additivity of the Shamir secret sharing algorithm to obtain the second privacy vector, and further includes: When the number of the intermediate results is greater than a first threshold, the server can perform the Lagrange interpolation calculation.
5. The multi-party encrypted sample alignment method according to claim 1, wherein The first selection strategy includes: After receiving the reconstructed sample index, the client performs inverse encoding on the reconstructed sample index according to the encoding function; When the inverse encoding result value of the reconstructed sample index is 1, the sample corresponding to the reconstructed sample index is selected as the aligned sample.
6. The multi-party encrypted sample alignment method according to claim 1, wherein The method further includes: Evaluating the size of the intersection of the reconstructed sample indexes of the client, and when the size of the intersection of the reconstructed sample indexes of the client is greater than a second threshold, the client can participate in the multi-party encrypted calculation.
7. The multi-party confidential sample alignment method according to claim 6, wherein The size of the intersection of the reconstructed sample indexes of the client is determined by the Goldwasser-Sipser algorithm; The Goldwasser-Sipser algorithm performs circular verification on each client according to the set of reconstructed sample indexes sent by each client to the server.
8. A multi-party confidential sample alignment device, characterized in that, Including: The encryption index module, where each client maps the original sample to a bit vector, converts the bit vector into a sample index vector by using an encoding function, generates a first encrypted sample index according to the sample index vector, the first privacy vector, and a public matrix, and sends the first encrypted sample index to the server; The reconstruction index module, where after receiving the first encrypted sample index, the server performs a summation calculation on the first encrypted sample index to obtain a second encrypted sample index, then generates a reconstructed sample index according to the second encrypted sample index, the public matrix, and a second privacy vector, and sends the reconstructed sample index to the client; The selection module, where the client selects an alignment sample from the samples corresponding to the reconstructed sample index according to a first selection strategy.
9. An electronic device, comprising a memory and a processor, wherein a computer program is stored on the memory, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method according to any one of claims 1 to 7.