Private data protection method and device, equipment and medium
By calculating the secret shared values of the horizontal coordinates and the vertical coordinates in the security calculations of both parties, and using the additive homomorphic encryption algorithm to generate data in product form, the problems of privacy data leakage and low calculation efficiency are solved, and safe and efficient linear slope calculation is achieved.
Patent Information
- Application Number
- CN202510655801.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-08
AI Technical Summary
The prior art has problems of privacy data leakage and low computing efficiency in both parties' security calculations, especially in the calculation slope process, when the numerator and denominator are mutually primed, it will lead to private information leakage, and the variations of the Paillier algorithm use cumbersome and expensive calculation steps.
The first participant and the second participant jointly calculate the secret shared values of the horizontal coordinates and vertical coordinates, use the additive homomorphic encryption algorithm to generate random numbers and parameters, convert them into product form, and determine the straight line slope through basic four-line operations to prevent privacy data leakage and improve calculation efficiency.
It effectively prevents privacy data leakage, improves computing efficiency, and realizes accurate calculation of the linear slope without leaking coordinate information.
Smart Images

Figure CN120454988A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a method, apparatus, device and medium for protecting privacy data. Background Art
[0002] Multi-party secure computation (MSPC) securely handles collaborative computations involving multiple parties with private data in distributed computing scenarios. It has become an indispensable component of cryptography and information security, playing a particularly significant role in confidential scientific computing. Currently, several general solutions for secure MPC exist. However, in practical applications, these solutions suffer from poor computational efficiency and network communication performance.
[0003] Two-party secure computation often involves securely computing a line passing through two points. One approach uses a variant of the Elgamal algorithm (an asymmetric encryption algorithm) to develop a secure computation protocol for this line. However, when calculating the slope, the numerator and denominator are multiplied by the same random number. If the numerator and denominator are coprime, this can lead to the leakage of private information. Another approach uses a variant of the Paillier algorithm (an additive homomorphic encryption algorithm) to securely compute a line passing through two points. However, this method is relatively cumbersome and requires significant computational and communication overhead to implement.
[0004] In summary, how to effectively prevent the leakage of private data and improve computing efficiency is a problem that needs to be solved. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a privacy data protection method, apparatus, device, and medium that can effectively prevent the leakage of privacy data and improve computing efficiency. The specific solution is as follows:
[0006] In a first aspect, the present application discloses a privacy data protection method, which is applied to a first participant, comprising:
[0007] jointly calculating a first secret shared value for a horizontal coordinate with a second participant; the first secret shared value includes first data held by the first participant and second data held by the second participant, where the product of the first data and the second data is the horizontal coordinate difference between the first coordinate and the second coordinate; wherein the private data held by the first participant is the first coordinate, and the private data held by the second participant is the second coordinate;
[0008] jointly calculating a second secret shared value regarding the ordinate with the second party; the second secret shared value includes third data held by the first party and fourth data held by the second party, and the product of the third data and the fourth data is the ordinate difference between the first coordinate and the second coordinate;
[0009] sending a first quotient value determined based on the third data and the first data to the second participant, and obtaining a second quotient value determined based on the fourth data and the second data and sent by the second participant;
[0010] The slope of the straight line is determined based on the product of the first quotient and the second quotient, and the corresponding safety calculation result of the straight line passing through two points is determined based on the first coordinate and the slope of the straight line.
[0011] Optionally, the process of the first party and the second party jointly calculating a target secret shared value corresponding to any target coordinate in the abscissa or the ordinate includes:
[0012] Determine a pre-generated target array; the target array includes a first random number and a first parameter held by the first participant and a second random number and a second parameter held by the second participant, wherein the product of the first random number and the second random number is the sum of the first parameter and the second parameter;
[0013] The first participant performs a difference operation on the target coordinates in the first coordinates and the first parameter to obtain a first difference result, and obtains a third quotient obtained by dividing the first difference result and the first random number;
[0014] sending the third quotient to the second party, so that the second party performs a sum operation on the third quotient and the second random number to obtain a target secret shared value held by the second party, performs a difference operation on the target coordinate in the second coordinates and the second parameter to obtain a second difference result, and then performs a division operation on the second difference result and the locally held target secret shared value to obtain a fourth quotient;
[0015] The first participant obtains the fourth quotient value sent by the second participant, and performs a sum operation on the fourth quotient value and the first random number to obtain a target secret shared value held by the first participant.
[0016] Optionally, obtaining a third quotient obtained by dividing the first difference result and the first random number includes:
[0017] Determine a preset first error value between a product of the data held by the two parties in the target secret shared value and a target coordinate difference between the first coordinate and the second coordinate;
[0018] A first truncation error is determined based on the first error value and the first random number, and a division operation is performed on the first difference result and the first random number based on the first truncation error to obtain a third quotient value.
[0019] Optionally, performing a division operation on the second difference result and the locally held target secret shared value to obtain a fourth quotient includes:
[0020] determining a second truncation error based on the first error value, the second random number, and the third quotient value;
[0021] A division operation is performed on the second difference result and the locally held target secret shared value based on the second truncation error to obtain a fourth quotient value.
[0022] Optionally, the process of generating the target array includes:
[0023] The first participant determines a first initial random number, encrypts the first initial random number based on an additive homomorphic encryption algorithm, and then sends the encrypted random number to the second participant;
[0024] The second party determines a second initial random number and initial parameters, encrypts the initial parameters based on the additive homomorphic encryption algorithm to obtain ciphertext parameters, then calculates the ciphertext parameters and the ciphertext random number based on a preset rule, and sends the calculation result to the first party;
[0025] The first participant decrypts the calculation result based on the additive homomorphic encryption algorithm to obtain a plaintext parameter;
[0026] The first party processes the first initial random number and the plaintext parameter based on a random value predetermined with the second party to obtain the first random number and the first parameter;
[0027] The second participant processes the second initial random number and the initial parameter based on the random value predetermined with the first participant to obtain the second random number and the second parameter.
[0028] Optionally, the privacy data protection method of this application further includes:
[0029] The first participant multiplies the random value by the first initial random number to obtain the first random number, and multiplies the square of the random value by the plaintext parameter to obtain the first parameter;
[0030] The second participant performs a product operation on the random value and the second initial random number to obtain the second random number, and performs a product operation on the square of the random value and the initial parameter to obtain the second parameter.
[0031] Optionally, sending a first quotient value determined based on the third data and the first data to the second participant, and obtaining a second quotient value determined based on the fourth data and the second data and sent by the second participant, includes:
[0032] calculating an absolute value of a ratio of the third data to the first data, determining a first target parameter that is greater than the absolute value of the ratio, and sending the first target parameter to the second participant;
[0033] Acquire a second target parameter sent by the second participant; the second target parameter is greater than an absolute value of a ratio between the fourth data and the second data;
[0034] determining a third truncation error based on the first target parameter, the second target parameter, and a preset straight line slope threshold, performing a division operation on the third data and the first data based on the third truncation error to obtain a first quotient value, and then sending the first quotient value to the second participant;
[0035] A second quotient value sent by the second participant after performing a division operation on the fourth data and the second data based on the third truncation error is obtained.
[0036] In a second aspect, the present application discloses a privacy data protection device, which is applied to a first participant and includes:
[0037] a first shared value calculation module, configured to jointly calculate, with a second party, a first secret shared value regarding a horizontal coordinate; the first secret shared value comprising first data held by the first party and second data held by the second party, the product of the first data and the second data being the horizontal coordinate difference between the first coordinate and the second coordinate; the first coordinate being the private data held by the first party, and the second coordinate being the private data held by the second party;
[0038] a second shared value calculation module, configured to jointly calculate a second secret shared value with the second party regarding the ordinate; the second secret shared value comprising third data held by the first party and fourth data held by the second party, the product of the third data and the fourth data being the ordinate difference between the first coordinate and the second coordinate;
[0039] a data transmission module, configured to send a first quotient value determined based on the third data and the first data to the second participant, and obtain a second quotient value determined based on the fourth data and the second data, sent by the second participant;
[0040] The result determination module is used to determine the slope of the straight line based on the product of the first quotient and the second quotient, and to determine the corresponding safety calculation result of the straight line passing through two points based on the first coordinate and the slope of the straight line.
[0041] In a third aspect, the present application discloses an electronic device, comprising:
[0042] Memory, used to store computer programs;
[0043] A processor is used to execute the computer program to implement the steps of the aforementioned disclosed privacy data protection method.
[0044] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned disclosed privacy data protection method are implemented.
[0045] It can be seen that the present application calculates a first secret shared value about the horizontal coordinate by the first participant and the second participant jointly; the first secret shared value includes first data held by the first participant and second data held by the second participant, and the product of the first data and the second data is the horizontal coordinate difference between the first coordinate and the second coordinate; wherein the private data owned by the first participant is the first coordinate, and the private data owned by the second participant is the second coordinate; jointly calculates a second secret shared value about the vertical coordinate with the second participant; the second secret shared value includes third data held by the first participant and fourth data held by the second participant, and the product of the third data and the fourth data is the vertical coordinate difference between the first coordinate and the second coordinate; sends a first quotient value determined based on the third data and the first data to the second participant, and obtains a second quotient value sent by the second participant and determined based on the fourth data and the second data; determines the slope of a straight line based on the product of the first quotient value and the second quotient value, and determines the corresponding security calculation result of the straight line passing through two points based on the first coordinate and the slope of the straight line.
[0046] Beneficial Effects: This application discloses a secure computation process for a line passing through two points, in which two parties jointly complete the computation. The private data held by the first party is the first coordinate, and the private data held by the second party is the second coordinate. First, the first party and the second party jointly compute a first secret shared value for the horizontal coordinate and a second secret shared value for the vertical coordinate. The first secret shared value comprises first data held by the first party and second data held by the second party, where the product of the first data and the second data is the horizontal coordinate difference between the first and second coordinates. The second secret shared value comprises third data held by the first party and fourth data held by the second party, where the product of the third data and the fourth data is the vertical coordinate difference between the first and second coordinates. In other words, the two parties each convert the corresponding horizontal and vertical coordinate differences into the product of two data, each holding one of the two data. Simultaneously, the first party cannot know the coordinate information of the second party, and the second party cannot know the coordinate information of the first party, effectively preventing the leakage of private data. Furthermore, the first participant sends a first quotient value determined based on the third data and the first data to the second participant. Simultaneously, the second participant sends a second quotient value determined based on the fourth data and the second data to the first participant. The first and second quotient values here serve as the secret shared value of the slope of the line. The two parties then multiply the first and second quotient values to obtain the slope of the line. Finally, the slope of the line and the coordinates of the points owned by each participant are used to determine the secure calculation result of the line passing through the two points. Because the above process utilizes basic arithmetic operations, computational efficiency is also improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.
[0048] Figure 1 A flow chart of a privacy data protection method disclosed in this application;
[0049] Figure 2 A flow chart of a method for calculating a secret shared value disclosed in this application;
[0050] Figure 3 A flowchart of a method for securely calculating a secret shared value between two parties disclosed in this application;
[0051] Figure 4 This is a flowchart of a two-party secure calculation of a straight line passing through two points disclosed in this application;
[0052] Figure 5 This is a schematic diagram of the structure of a privacy data protection device disclosed in this application;
[0053] Figure 6 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0054] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0055] Two-party secure computation often involves the secure computation of straight lines passing through two points. For example, in Geographic Information System (GIS) applications such as mapping and navigation route planning, it is often necessary to determine straight lines based on discrete spatial point information provided by different users in order to draw map elements or plan routes. Using secure computation of straight lines passing through two points can accurately calculate straight lines while protecting user privacy, ensuring the security and accuracy of spatial data. In location-based services (LBS), service providers need to process the location data of large amounts of users. Using secure computation of straight lines passing through two points allows for location relationship analysis and service optimization without disclosing the privacy of users' specific locations.
[0056] Currently, one method uses a variant of the Elgamal algorithm to provide a secure calculation protocol for a straight line between two points. However, when calculating the slope, the random numbers multiplied by the numerator and denominator are the same. If the numerator and denominator are relatively prime, this can lead to the leakage of private information. Another method uses a variant of the Paillier algorithm (an additive homomorphic encryption algorithm) to securely calculate a straight line passing through two points. However, this method is relatively cumbersome and requires a significant amount of computational and communication overhead to implement. To this end, the embodiments of the present application disclose a privacy data protection method, apparatus, device, and medium that can effectively prevent the leakage of private data and improve computational efficiency.
[0057] See also Figure 1 As shown, the embodiment of the present application discloses a privacy data protection method, which is applied to a first participant, and the method includes:
[0058] Step S11: Calculate the first secret shared value about the horizontal coordinate together with the second participant; the first secret shared value includes the first data held by the first participant and the second data held by the second participant, and the product of the first data and the second data is the horizontal coordinate difference between the first coordinate and the second coordinate; wherein, the private data owned by the first participant is the first coordinate, and the private data owned by the second participant is the second coordinate.
[0059] This embodiment discloses a secure computation process for a line passing through two points, where the first party's private data is the first coordinate and the second party's private data is the second coordinate. Specifically, the secure computation of a line passing through two points can be formulated as follows: Assume that party P1 has the coordinate data , participant P2 has coordinate data , a confidentiality agreement is required to allow participants P1 and P2 to obtain the points and point The straight line, while the participant P1 cannot obtain The value of , participant P2 cannot obtain value.
[0060] In order to achieve the above purpose, the first participant needs to jointly calculate the first secret shared value regarding the horizontal coordinate with the second participant. The first secret shared value includes the first data held by the first participant and the second data held by the second participant. The product of the first data and the second data is the horizontal coordinate difference between the first coordinate and the second coordinate.
[0061] Step S12: Calculate a second secret shared value about the vertical coordinate together with the second participant; the second secret shared value includes third data held by the first participant and fourth data held by the second participant, and the product of the third data and the fourth data is the vertical coordinate difference between the first coordinate and the second coordinate.
[0062] In this embodiment, in addition to jointly calculating the first secret shared value for the horizontal coordinate, a second secret shared value for the vertical coordinate must also be calculated with the second participant. The second secret shared value includes third data held by the first participant and fourth data held by the second participant. The product of the third data and the fourth data is the vertical coordinate difference between the first and second coordinates. It should be noted that this application does not limit the order in which the first and second secret shared values are calculated; they can also be calculated in parallel.
[0063] That is, the two participating parties convert the corresponding difference between the horizontal and vertical coordinates into the product of two data, and each party owns one of the two data. At the same time, the first participant cannot know the coordinate information of the second participant, and the second participant cannot know the coordinate information of the first participant, which effectively prevents the leakage of private data.
[0064] It should be pointed out that secret sharing is an important technology in multi-party secure computing. Because it is relatively simple to use, it is widely used in the field of privacy protection. Suppose that participant P1 has data x and participant P2 has data y. After multiplication secret sharing, to achieve the goal of participant P1 having data , participant P2 owns the data , and they satisfy That is, two-party multiplication secret sharing is an algorithm that converts the multiplication result of the private data owned by two parties into the sum of the two data, and the converted data is held secretly by each party. This application discloses an inverse algorithm for multiplication secret sharing, which is an algorithm that converts the addition result of the private data owned by two parties into the product of the two data. Specifically, for the inverse process of multiplication secret sharing, suppose that participant P1 has data , participant P2 owns the data , after the inverse process of multiplication secret sharing, it is finally achieved that participant P1 has data x, participant P2 has data y, and they satisfy At the same time, P1 does not disclose its own data to P2 , and P2 does not disclose its own data to P1 .
[0065] For further information, see Figure 2 As shown, the process of the first participant and the second participant jointly calculating the target secret shared value corresponding to any target coordinate in the horizontal coordinate or the vertical coordinate includes the following steps:
[0066] Step S21: Determine a pre-generated target array; the target array includes a first random number and a first parameter held by the first participant and a second random number and a second parameter held by the second participant, and the product of the first random number and the second random number is the sum of the first parameter and the second parameter.
[0067] In this embodiment, the pre-generated target array is determined ; The target array includes the first random number and the first parameter held by the first participant P1 , and the second random number and second parameter held by the second party , the product of the first random number and the second random number is the sum of the first parameter and the second parameter, that is, .
[0068] In a specific implementation, the generation process of the target array includes: the first participant determines a first initial random number, encrypts the first initial random number based on an additive homomorphic encryption algorithm, and then sends the ciphertext random number to the second participant; the second participant determines a second initial random number and an initial parameter, and encrypts the initial parameter based on an additive homomorphic encryption algorithm to obtain a ciphertext parameter, and then calculates the ciphertext parameter and the ciphertext random number based on a preset rule, and sends the calculation result to the first participant; the first participant decrypts the calculation result based on the additive homomorphic encryption algorithm to obtain a plaintext parameter; the first participant processes the first initial random number and the plaintext parameter based on a random value predetermined with the second participant to obtain a first random number and a first parameter; the second participant processes the second initial random number and the initial parameter based on a random value predetermined with the first participant to obtain a second random number and a second parameter.
[0069] First, the relevant content of the additive homomorphic encryption algorithm is introduced. The specific additive homomorphic encryption algorithm used in this application is the Paillier algorithm, which is as follows:
[0070] (1) Key generation: Select two large prime numbers p and q, let N = pq, λ = lcm(p-1,q-1), which satisfy gcd(λ, N) = 1. Select g so that it satisfies: ;
[0071] Let (N, g) be the public key and λ be the private key.
[0072] (2) Encryption: For any , select a random number , the ciphertext is:
[0073] ;
[0074] (3) Decryption: For any , the plain text is:
[0075] .
[0076] Note that the above decryption algorithm is divided by means multiplying by its inverse modulo N. Where lcm(a, b) represents the least common multiple of a and b, gcd(a, b) represents the greatest common divisor of a and b, and if gcd(a, b) = 1, a and b are said to be coprime. represents the set {0,1,⋯,n-1}. Representing a collection The set of elements that are coprime to n. amodc is read as a modulo c, which means the remainder when a is divided by c. a=bmodc means that the remainders when a and b are divided by c are the same. If ab=1modc, it means that b is the multiplicative inverse of a modulo c, which is written as , in this case a is also the multiplicative inverse of b modulo c. If , for the set , define S n The function L on is:
[0077] ;
[0078] To generalize this algorithm to the integer range, select N large enough so that the absolute value of the sum of the data does not exceed N / 2. Then, add N to any data less than 0, converting all data into natural numbers, and directly encrypt it using the Paillier algorithm. After decryption using the Paillier algorithm, if the data is greater than N / 2, subtract N from it. If the data is less than N / 2, no further processing is performed, yielding the final decrypted result. Based on the additive homomorphism of the Paillier algorithm, it is easy to verify that the algorithm generalized to the integer range still satisfies additive homomorphism.
[0079] Below we use E(m) and D(c) to represent the encryption and decryption algorithms extended to the integer range. It can be obtained that if and , which means:
[0080] ;
[0081] Furthermore, we can get , where l is a positive integer, then:
[0082] ;
[0083] In addition, due to: ;
[0084] Know (Here, the inversion of the ciphertext refers to the 2 The inverse of the meaning is equivalent to encrypting -m, that is, . From this we can get:
[0085] if , and l is a negative integer, then:
[0086] ;
[0087] And when l=0, obviously there is also ;
[0088] So, if , and l is an integer, then:
[0089] .
[0090] Therefore, the process of generating the target array is:
[0091] 1. Participant P1 establishes the Paillier algorithm key {N,λ,g} and sends the public key {N,g} to participant P2. Among them, N in the key is large enough, such as 1024 bits, then in general, the calculation result of the data is in within the range.
[0092] 2. Participant P1 selects the first initial random number a, encrypts it based on the additive homomorphic encryption algorithm to obtain the ciphertext random number E(a), and sends it to participant P2.
[0093] 3. Participant P2 determines the second initial random number b and initial parameters , and then based on the additive homomorphic encryption algorithm Encrypted ciphertext parameters , then calculate the ciphertext parameters and ciphertext random numbers based on the preset rules, obtain the calculation result val and send it to the participant P1. .
[0094] 4. Participant P1 decrypts the calculation result val based on the additive homomorphic encryption algorithm to obtain the plaintext parameter .
[0095] 5. Participant P1 and participant P2 pre-agreed on a random value r0, which is a relatively small value. P1 then uses the random value r0 to process the first initial random number and the plaintext parameter to calculate the first random number and the first parameter. Participant P2 also uses the random value r0 to process the second initial random number and the initial parameter to calculate the second random number and the second parameter.
[0096] Specifically, the first participant uses the random value to perform a product operation with the first initial random number to obtain the first random number , and use the square of the random value and the plaintext parameter to perform a product operation to obtain the first parameter The second participant uses the random value to multiply the second initial random number to obtain the second random number , and use the square of the random value to multiply the initial parameter to get the second parameter The calculation expression is as follows:
[0097] ;
[0098] .
[0099] Step S22: The first participant performs a difference operation on the target coordinates in the first coordinates and the first parameter to obtain a first difference result, and obtains a third quotient value obtained by dividing the first difference result and the first random number.
[0100] In this embodiment, the target coordinate in the first coordinate is marked as , participant P1's target coordinates in the first coordinate With the first parameter Perform difference operation to obtain the first difference result , that is, participant P1 calculates , and the first difference result With the first random number After the division operation, the third quotient value e is obtained, that is, .
[0101] Step S23: Send the third quotient to the second participant, so that the second participant performs a sum operation on the third quotient and the second random number to obtain the target secret shared value held by the second participant, and performs a difference operation on the target coordinate in the second coordinate and the second parameter to obtain a second difference result, and then performs a division operation on the second difference result and the locally held target secret shared value to obtain a fourth quotient.
[0102] In this embodiment, the participant P1 sends the third quotient value e to the participant P2, and the participant P2 compares the third quotient value e with the second random number The target secret shared value y held by the second participant is obtained by performing the sum operation, that is, Furthermore, the opposite of the target coordinate in the second coordinate is recorded as ,Will With the second parameter Subtract and get the second difference result , then the second difference result Divide the locally held target secret shared value y to obtain the fourth quotient f, that is, .
[0103] Step S24: the first participant obtains the fourth quotient sent by the second participant, and performs a sum operation on the fourth quotient and the first random number to obtain the target secret shared value held by the first participant.
[0104] In this embodiment, participant P2 sends the fourth quotient value f to participant P1, and participant P1 performs a sum operation on the fourth quotient value and the first random number to obtain the target secret shared value x held by the first participant, that is, .
[0105] Can be verified . And according to the information obtained from P1 , cannot be inferred and information about y; information obtained based on P2 , cannot be inferred And the information of x.
[0106] From the above content, we can know that x and y are the multiplication secret shared values owned by participants P1 and P2 respectively; e and f are intermediate calculation results.
[0107] It should be noted that in the above process, the calculation and There is an error, so the final result of the calculation is also an error. is less than ε, so it is necessary to control and The calculated error is adjusted so that the result error meets the requirements. , . Then we have:
[0108]
[0109] .
[0110] From the above formula, we can see that the final error is divided into two parts. and , so we need to control the error Less than ε, only P1 needs to be set , P2 settings Therefore, after adding the control of calculation error, the process of participants P1 and P2 jointly calculating the secret shared value is as follows: Figure 3 shown.
[0111] In this way, when obtaining the third quotient value obtained after dividing the first difference result and the first random number, it specifically includes: determining a preset first error value about the product of the data held by each party in the target secret shared value and the difference between the target coordinates between the first coordinate and the second coordinate; determining a first truncation error based on the first error value and the first random number, and dividing the first difference result and the first random number based on the first truncation error to obtain the third quotient value.
[0112] The first error value of the difference between the product of the data held by the two parties and the target coordinate between the first coordinate and the second coordinate is the aforementioned ε, so according to the first error value ε and the first random number Determine the first truncation error , so that the first difference result and the first random number can be divided based on the first truncation error to obtain the third quotient. The truncation error satisfies .
[0113] When performing a division operation on the second difference result and the locally held target secret shared value to obtain a fourth quotient, the method specifically includes: determining a second truncation error based on the first error value, the second random number, and the third quotient; and performing a division operation on the second difference result and the locally held target secret shared value based on the second truncation error to obtain a fourth quotient. That is, the second truncation error is , that is, calculation The truncation error satisfies .
[0114] Step S13: sending a first quotient value determined based on the third data and the first data to the second participant, and obtaining a second quotient value determined based on the fourth data and the second data sent by the second participant.
[0115] In this embodiment, the first data and the second data are recorded as g1 and g2 respectively, and the third data and the fourth data are recorded as h1 and h2 respectively. The first participant sends the first quotient value v1 determined based on the third data h1 and the first data g1 to the second participant. At the same time, the second participant also sends the second quotient value v2 determined based on the fourth data h2 and the second data g2 to the first participant. The first quotient value and the second quotient value here are the secret shared values of the slope of the straight line.
[0116] in, , .
[0117] Furthermore, there are errors when calculating v1 and v2. Therefore, the first quotient value determined based on the third data and the first data is sent to the second participant, and the second quotient value determined based on the fourth data and the second data sent by the second participant is obtained, specifically including: calculating the absolute value of the ratio of the third data and the first data, and determining a first target parameter greater than the absolute value of the ratio, and sending the first target parameter to the second participant; obtaining the second target parameter sent by the second participant; the second target parameter is greater than the absolute value of the ratio between the fourth data and the second data; determining a third truncation error based on the first target parameter, the second target parameter and a preset straight line slope threshold, and dividing the third data and the first data based on the third truncation error to obtain a first quotient value, and then sending the first quotient value to the second participant; obtaining the second quotient value sent by the second participant after dividing the fourth data and the second data based on the third truncation error.
[0118] That is, participant P1 gives a satisfying The first target parameter C is sent to participant P2, and participant P2 gives a satisfying The second target parameter D is sent to the participant P1. Then the two parties calculate the target parameter C, the second target parameter D and the preset straight line slope threshold. Determine the third truncation error , participant P1 calculates When the truncation error satisfies , and sent to participant P2, who calculates When the truncation error satisfies , and sent to participant P1.
[0119] Step S14: determining the slope of the straight line based on the product of the first quotient and the second quotient, and determining the corresponding safety calculation result of the straight line passing through the two points based on the first coordinate and the slope of the straight line.
[0120] In this embodiment, both parties multiply the first quotient and the second quotient to obtain the slope of the straight line. Finally, the slope k of the straight line and the coordinates of the points owned by both parties can be used to determine the corresponding safety calculation results of the straight line passing through the two points.
[0121] Specifically, participant P1 calculates the straight line ,Right now .
[0122] Participant P2 calculates the straight line ,Right now .
[0123] Since the above process uses the basic four arithmetic operations, the calculation efficiency is also improved.
[0124] As can be seen, this application discloses a secure computation process for a line passing through two points, in which two parties jointly complete the computation. The private data held by the first participant is the first coordinate, and the private data held by the second participant is the second coordinate. First, the first participant and the second participant jointly compute a first secret shared value for the horizontal coordinate and a second secret shared value for the vertical coordinate. The first secret shared value comprises first data held by the first participant and second data held by the second participant, with the product of the first data and the second data being the horizontal coordinate difference between the first and second coordinates. The second secret shared value comprises third data held by the first participant and fourth data held by the second participant, with the product of the third data and the fourth data being the vertical coordinate difference between the first and second coordinates. In other words, the two participants each convert the corresponding horizontal and vertical coordinate differences into the product of two data, each of which possesses one of the two data. Simultaneously, the first participant cannot know the coordinate information of the second participant, and the second participant cannot know the coordinate information of the first participant, effectively preventing the leakage of private data. Furthermore, the first participant sends a first quotient value determined based on the third data and the first data to the second participant. Simultaneously, the second participant sends a second quotient value determined based on the fourth data and the second data to the first participant. The first and second quotient values here serve as the secret shared value of the slope of the line. The two parties then multiply the first and second quotient values to obtain the slope of the line. Finally, the slope of the line and the coordinates of the points owned by each participant are used to determine the secure calculation result of the line passing through the two points. Because the above process utilizes basic arithmetic operations, computational efficiency is also improved.
[0125] The following uses the application in geographic information system as an example to explain the solution of this application in detail. In the application of geographic information system, a large amount of geospatial data will be collected, and these data may come from different users or data sources. For example, the building coordinate information collected by the urban planning department, the road node data collected by the transportation department, etc. During the collection process, the data of each party often contains sensitive privacy information. One of the core functions of geographic information system is spatial analysis, which often requires calculating the straight line relationship between two points, determining the straight line distance and direction between two landmarks in map drawing, or drawing straight lines connecting different geographic features when visualizing geographic data. Specifically, Figure 4 As shown, it is assumed that participant P1 has the coordinate data of a landmark , participant P2 has the coordinate data of a certain landmark , a confidentiality agreement is required for participants P1 and P2 to confirm the passing points and point The specific steps are as follows:
[0126] Step 1: Participants P1 and P2 use the inverse algorithm of the above multiplicative secret sharing to calculate and , where the data obtained by participant P1 are g1 and h1, and the data obtained by participant P2 are g2 and h2. That is, x1 is used as in the inverse algorithm of the above multiplicative secret sharing, -x2 is used as in it, and g1 and g2 respectively correspond to the x and y obtained by both. And y1 is used as in the above process, -y2 is used as in it, and h1 and h2 respectively correspond to the x and y obtained by both. <00 , ;
[0138] You can get:
[0139] ;
[0140] Therefore, we can further obtain:
[0141] ;
[0142] so:
[0143] ;
[0144] Therefore, when using the inverse algorithm of multiplication secret sharing to calculate When the participant P1 needs to control the error of the parameters to meet , participant P2 needs to control the parameter error to satisfy .
[0145] And, using the inverse algorithm of multiplicative secret sharing When the participant P1 needs to control the error of the parameters to meet , participant P2 needs to control the parameter error to satisfy .
[0146] Note that the parameters here Refers to the calculation using the inverse algorithm of multiplication secret sharing Parameters used when Refers to the calculation using the inverse algorithm of multiplication secret sharing Parameters used when
[0147] set up ,So:
[0148] ;
[0149] if , you can set , then we have:
[0150] ;
[0151] This ensures that the calculated slope error meets the requirements. However, this involves giving the values of C and D. Therefore, when the error of the calculation result needs to be strictly controlled, the above step 2 needs to be modified into the following two steps:
[0152] (1) Participant P1 gives a satisfying The first target parameter C is sent to participant P2, and participant P2 gives a satisfying The second target parameter D is sent to participant P1
[0153] (2) Calculation by participant P1 When the truncation error satisfies , and sent to participant P2, who calculates When the truncation error satisfies , and sent to participant P1.
[0154] As can be seen, for the inverse algorithm of multiplication secret sharing, the participants first use the Paillier algorithm to pre-generate triplets. They then use these triplets to mask their own secret information and perform data exchange and related calculations with each other to convert the sum (or difference) of their data into the product of two data points. The method also provides methods for controlling parameters to achieve a given error requirement. For the private calculation of a line, the key lies in the private calculation of its slope. Using the inverse algorithm of double multiplication secret sharing, the difference between the two parties' x and y coordinates is converted into the product of two data points (secret shared values). Each party then calculates the quotient of the y-coordinate secret shared value with the x-coordinate secret shared value to obtain the secret shared value of the slope and sends it to the other party. The slope of the line is then multiplied together to obtain the slope of the line. Finally, each party can use the slope and their own points to calculate the line. This process provides methods for controlling the calculation of parameters to achieve the given slope error requirement. Compared to the Elgamal algorithm, which multiplies the numerator and denominator of a fraction by a random number and sends it to the other party, it is very likely to obtain the user's original data through reduction. The method of this application uses an approximate division method, making it impossible for others to infer the original fraction. Compared to the Paillier algorithm, which selects a large number of random numbers for multiple data encryption, its calculation process is complex and computationally expensive. In addition to pre-generating arrays, the method of this application uses basic arithmetic operations for most of the process, which is computationally efficient.
[0155] In fact, if strict control of the error in the calculation result is not necessary, simply follow the general steps and retain more significant digits each time a division is performed. This will ensure that the calculated slope of the line is very close to the true slope. Furthermore, a slight modification to the process of privately calculating the slope of the line can be transformed into a privately calculating average. Averaging is a common process used in multi-party secure computation, such as finding the center of a category in clustering and using federated averaging to calculate the weighted average of model parameters in federated learning. Combining this private averaging process with secret sharing can solve many common secure multi-party computation problems.
[0156] In addition, the inverse process of the above multiplication secret sharing can be directly used to compare the size of two data privately. For example, participant P1 has data , participant P2 owns the data You can compare the sizes of the two by following the steps below:
[0157] 1. Participant P1 will As the inverse process of the above multiplication secret sharing , participant P2 will As the process , implementing the inverse process of multiplicative secret sharing.
[0158] Assume that the data obtained by participant P1 is (corresponding to x in the above process), the data obtained by participant P2 is (corresponding to y in the above process).
[0159] 2. If , which can be approximately considered . Then participant P1 sends the result to participant P2 and stops; otherwise, go to step 3.
[0160] In fact, it can be deduced that The error expression is:
[0161] ;
[0162] Therefore, if and When the values of are close, The value will be very small.
[0163] 3. Calculation by Party P1 , and sent to P2, participant P2 calculates And send it to P1.
[0164] 4. Both parties P1 and P2 can be calculated If its value is 1, it means If its value is -1, it means .
[0165] Among them, sign(x) represents the sign function of x, and its value is as follows:
[0166]
[0167] See also Figure 5 As shown, the embodiment of the present application discloses a privacy data protection device, which is applied to a first participant, and the device includes:
[0168] A first shared value calculation module 11 is configured to jointly calculate a first secret shared value with the second participant regarding a horizontal coordinate; the first secret shared value includes first data held by the first participant and second data held by the second participant, where the product of the first data and the second data is the horizontal coordinate difference between the first coordinate and the second coordinate; wherein the private data held by the first participant is the first coordinate, and the private data held by the second participant is the second coordinate;
[0169] a second shared value calculation module 12, configured to calculate, together with the second participant, a second secret shared value regarding the ordinate; the second secret shared value comprising third data held by the first participant and fourth data held by the second participant, wherein the product of the third data and the fourth data is the ordinate difference between the first coordinate and the second coordinate;
[0170] a data transmission module 13, configured to send a first quotient value determined based on the third data and the first data to the second participant, and obtain a second quotient value determined based on the fourth data and the second data, sent by the second participant;
[0171] The result determination module 14 is configured to determine the slope of the line based on the product of the first quotient and the second quotient, and determine a corresponding safety calculation result of the line passing through the two points based on the first coordinate and the slope of the line.
[0172] As can be seen, this application discloses a secure computation process for a line passing through two points, in which two parties jointly complete the computation. The private data held by the first participant is the first coordinate, and the private data held by the second participant is the second coordinate. First, the first participant and the second participant jointly compute a first secret shared value for the horizontal coordinate and a second secret shared value for the vertical coordinate. The first secret shared value comprises first data held by the first participant and second data held by the second participant, with the product of the first data and the second data being the horizontal coordinate difference between the first and second coordinates. The second secret shared value comprises third data held by the first participant and fourth data held by the second participant, with the product of the third data and the fourth data being the vertical coordinate difference between the first and second coordinates. In other words, the two participants each convert the corresponding horizontal and vertical coordinate differences into the product of two data, each of which possesses one of the two data. Simultaneously, the first participant cannot know the coordinate information of the second participant, and the second participant cannot know the coordinate information of the first participant, effectively preventing the leakage of private data. Furthermore, the first participant sends a first quotient value determined based on the third data and the first data to the second participant. Simultaneously, the second participant sends a second quotient value determined based on the fourth data and the second data to the first participant. The first and second quotient values here serve as the secret shared value of the slope of the line. The two parties then multiply the first and second quotient values to obtain the slope of the line. Finally, the slope of the line and the coordinates of the points owned by each participant are used to determine the secure calculation result of the line passing through the two points. Because the above process utilizes basic arithmetic operations, computational efficiency is also improved.
[0173] Since the embodiments of the device part correspond to the above embodiments, the embodiments of the device part please refer to the description of the embodiments of the method part, which will not be repeated here.
[0174] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Specifically, the device may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the privacy data protection method performed by the electronic device as disclosed in any of the aforementioned embodiments.
[0175] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0176] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.
[0177] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon include an operating system 221, a computer program 222 and data 223, etc. The storage method can be temporary storage or permanent storage.
[0178] The operating system 221 is used to manage and control the hardware devices and computer programs 222 on the electronic device 20, so as to enable the processor 21 to calculate and process the massive amount of data 223 in the memory 22. The operating system 221 can be Windows, Unix, Linux, etc. In addition to including computer programs capable of implementing the privacy data protection method performed by the electronic device 20 as disclosed in any of the aforementioned embodiments, the computer programs 222 can also include computer programs capable of performing other specific tasks. The data 223 can include not only data transmitted by the electronic device from an external device but also data collected by its own input and output interface 25.
[0179] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium, in which a computer program is stored. When the computer program is loaded and executed by a processor, the steps of the privacy data protection method disclosed in any of the aforementioned embodiments are implemented.
[0180] Furthermore, an embodiment of the present invention also discloses a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the privacy data protection method disclosed in any of the aforementioned embodiments.
[0181] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.
[0182] Those skilled in the art may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0183] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a compact disc read-only memory (CD-ROM), or any other form of storage medium known in the art.
[0184] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0185] The above is a detailed introduction to the privacy data protection method, device, equipment and storage medium provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A privacy data protection method, characterized in that: Applicable to the first party, including: jointly calculating a first secret shared value for a horizontal coordinate with a second participant; the first secret shared value includes first data held by the first participant and second data held by the second participant, where the product of the first data and the second data is the horizontal coordinate difference between the first coordinate and the second coordinate; wherein the private data held by the first participant is the first coordinate, and the private data held by the second participant is the second coordinate; jointly calculating a second secret shared value regarding the ordinate with the second party; the second secret shared value includes third data held by the first party and fourth data held by the second party, and the product of the third data and the fourth data is the ordinate difference between the first coordinate and the second coordinate; sending a first quotient value determined based on the third data and the first data to the second participant, and obtaining a second quotient value determined based on the fourth data and the second data and sent by the second participant; The slope of the straight line is determined based on the product of the first quotient and the second quotient, and the corresponding safety calculation result of the straight line passing through two points is determined based on the first coordinate and the slope of the straight line.
2. The privacy data protection method according to claim 1, characterized in that: The process of the first participant and the second participant jointly calculating a target secret shared value corresponding to any target coordinate in the horizontal coordinate or the vertical coordinate includes: Determine a pre-generated target array; the target array includes a first random number and a first parameter held by the first participant and a second random number and a second parameter held by the second participant, wherein the product of the first random number and the second random number is the sum of the first parameter and the second parameter; The first participant performs a difference operation on the target coordinates in the first coordinates and the first parameter to obtain a first difference result, and obtains a third quotient obtained by dividing the first difference result and the first random number; sending the third quotient to the second party, so that the second party performs a sum operation on the third quotient and the second random number to obtain a target secret shared value held by the second party, performs a difference operation on the target coordinate in the second coordinates and the second parameter to obtain a second difference result, and then performs a division operation on the second difference result and the locally held target secret shared value to obtain a fourth quotient; The first participant obtains the fourth quotient value sent by the second participant, and performs a sum operation on the fourth quotient value and the first random number to obtain a target secret shared value held by the first participant.
3. The privacy data protection method according to claim 2, characterized in that: The obtaining a third quotient value obtained by dividing the first difference result and the first random number includes: Determine a preset first error value between a product of the data held by the two parties in the target secret shared value and a target coordinate difference between the first coordinate and the second coordinate; A first truncation error is determined based on the first error value and the first random number, and a division operation is performed on the first difference result and the first random number based on the first truncation error to obtain a third quotient value.
4. The privacy data protection method according to claim 3, characterized in that: The dividing operation on the second difference result and the locally held target secret shared value to obtain a fourth quotient includes: determining a second truncation error based on the first error value, the second random number, and the third quotient value; A division operation is performed on the second difference result and the locally held target secret shared value based on the second truncation error to obtain a fourth quotient value.
5. The privacy data protection method according to claim 2, characterized in that: The process of generating the target array includes: The first participant determines a first initial random number, encrypts the first initial random number based on an additive homomorphic encryption algorithm, and then sends the encrypted random number to the second participant; The second party determines a second initial random number and initial parameters, encrypts the initial parameters based on the additive homomorphic encryption algorithm to obtain ciphertext parameters, then calculates the ciphertext parameters and the ciphertext random number based on a preset rule, and sends the calculation result to the first party; The first participant decrypts the calculation result based on the additive homomorphic encryption algorithm to obtain a plaintext parameter; The first party processes the first initial random number and the plaintext parameter based on a random value predetermined with the second party to obtain the first random number and the first parameter; The second participant processes the second initial random number and the initial parameter based on the random value predetermined with the first participant to obtain the second random number and the second parameter.
6. The privacy data protection method according to claim 5, characterized in that: Also includes: The first participant multiplies the random value by the first initial random number to obtain the first random number, and multiplies the square of the random value by the plaintext parameter to obtain the first parameter; The second participant performs a product operation on the random value and the second initial random number to obtain the second random number, and performs a product operation on the square of the random value and the initial parameter to obtain the second parameter.
7. The privacy data protection method according to any one of claims 1 to 6, characterized in that: The sending a first quotient value determined based on the third data and the first data to the second participant, and obtaining a second quotient value determined based on the fourth data and the second data and sent by the second participant, includes: calculating an absolute value of a ratio of the third data to the first data, determining a first target parameter that is greater than the absolute value of the ratio, and sending the first target parameter to the second participant; Acquire a second target parameter sent by the second participant; the second target parameter is greater than an absolute value of a ratio between the fourth data and the second data; determining a third truncation error based on the first target parameter, the second target parameter, and a preset straight line slope threshold, performing a division operation on the third data and the first data based on the third truncation error to obtain a first quotient value, and then sending the first quotient value to the second participant; A second quotient value sent by the second participant after performing a division operation on the fourth data and the second data based on the third truncation error is obtained.
8. A privacy data protection device, characterized in that: Applicable to the first party, including: a first shared value calculation module, configured to jointly calculate, with a second party, a first secret shared value regarding a horizontal coordinate; the first secret shared value comprising first data held by the first party and second data held by the second party, the product of the first data and the second data being the horizontal coordinate difference between the first coordinate and the second coordinate; the first coordinate being the private data held by the first party, and the second coordinate being the private data held by the second party; a second shared value calculation module, configured to jointly calculate a second secret shared value with the second party regarding the ordinate; the second secret shared value comprising third data held by the first party and fourth data held by the second party, the product of the third data and the fourth data being the ordinate difference between the first coordinate and the second coordinate; a data transmission module, configured to send a first quotient value determined based on the third data and the first data to the second participant, and obtain a second quotient value determined based on the fourth data and the second data, sent by the second participant; The result determination module is used to determine the slope of the straight line based on the product of the first quotient and the second quotient, and to determine the corresponding safety calculation result of the straight line passing through two points based on the first coordinate and the slope of the straight line.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the steps of the privacy data protection method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the steps of the privacy data protection method according to any one of claims 1 to 7 are implemented.