Arithmetic consistency attack resistant bidirectional integrity verification method and system

Through homomorphic encryption and arithmetic secret sharing technology, optimized secure data and result verification protocols are designed to solve the confidentiality and integrity of outsourced data and calculation results in the Internet of Things, and reliable and efficient two-way integrity verification of outsourced data and calculation results in open links is achieved, reducing the calculation cost of the verification process, and effectively resisting arithmetic consistency attacks.

CN120498890APending Publication Date: 2025-08-15MINJIANG UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510923468.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing data security computing protocol cannot effectively resist arithmetic consistency attacks in the Internet of Things environment, resulting in the insecurity and integrity of outsourcing data and calculation results being unable to be guaranteed, and the calculation cost is high, ignoring the integrity verification of data uploaded by the client.

Method used

Homomorphic encryption and arithmetic secret sharing technology are adopted to generate public and private key pairs through third-party servers, and random numbers are generated by collaborative clients and servers to generate random numbers. Optimized secure data and result verification protocols are designed to ensure the confidentiality and integrity of data and calculation results, and to resist arithmetic consistency attacks under the assumption that pre-generated random numbers are unchanged.

Benefits of technology

Reliable and efficient two-way integrity verification of outsourced data and calculation results in open links is achieved, reducing the computational cost of the verification process, and effectively resisting arithmetic consistency attacks of malicious opponents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498890A_ABST
    Figure CN120498890A_ABST
Patent Text Reader

Abstract

The invention provides an arithmetic consistency attack resistant bidirectional integrity verification method and system, and the method can ensure the confidentiality and integrity of outsourcing data and calculation results under an invariant hypothesis of pre-generating random numbers through designing optimized security data verification and security result verification. According to the method and the system, the problem that outsourcing data and calculation results are eavesdropped and tampered in the transmission process is solved, arithmetic consistency attacks of malicious opponents can be resisted, and integrity verification with higher safety and high efficiency is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security computing and Internet of Things technology, and in particular to a bidirectional integrity verification method and system for resisting arithmetic consistency attacks. Background Art

[0002] In the IoT environment, outsourced computing enables clients to offload data and computing tasks to cloud servers, freeing them from storage and computing resource constraints. With the transfer of data ownership and the open communication link between client and server, security issues inevitably arise. For example, data uploaded by the client and the computational results returned by the server can be eavesdropped and tampered with during transmission. Addressing the confidentiality and integrity of transmitted data has attracted widespread attention in academia and industry.

[0003] Several approaches have been proposed for verifying computations for machine learning models such as support vector machines. These approaches employ homomorphic encryption and bilinear mapping to design verifiably secure computation protocols, achieving input privacy, model privacy, and result verifiability. Furthermore, some approaches leverage digital signatures and blockchain to verify outsourced data. Recently, to ensure the reliability of inference results provided by cloud servers to clients, researchers have designed non-interactive verification protocols based on homomorphic encryption. These protocols prevent the server from providing false results and third-party adversaries from tampering with the results. However, these integrity verification protocols still face several challenges. First, the verification items are constructed based on the properties of homomorphic encryption, which incurs significant computational costs. Second, these protocols only verify the integrity of the outsourced computation results, ignoring the integrity of the data uploaded by the client. Finally, these protocols have security vulnerabilities. Malicious adversaries can exploit the homomorphic properties of homomorphic encryption to insert random numbers into the verification items and construct a carefully constructed arithmetic consistency attack to tamper with the data. Therefore, there is an urgent need to develop a bidirectional integrity verification method and system that is resistant to arithmetic consistency attacks to effectively address these limitations. Summary of the Invention

[0004] The purpose of the present invention is to propose a bidirectional integrity verification method and system that are resistant to arithmetic consistency attacks. This method and system are conducive to achieving reliable and efficient bidirectional integrity verification, effectively ensuring the confidentiality and integrity of outsourced data and calculation results, and being able to resist arithmetic consistency attacks.

[0005] To achieve the above object, the technical solution of the present invention is as follows:

[0006] The present invention proposes a bidirectional integrity verification system that is resistant to arithmetic consistency attacks, comprising:

[0007] Third-party server T: Generates public-private key pairs (pk c ,skc ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links; two input-independent random numbers φ1 and φ2 are generated, and φ1 is sent to client C and server S1, and φ2 is sent to client C and server S2;

[0008] Client C: Provides encrypted data to servers S1 and S2, randomly splits any element d of the outsourced data into two secret shares [[d]]1 and [[d]]2 for the two servers to collaboratively perform secure computations, and encrypts [[d]]1 and [[d]]2, d·φ1+φ2, and sends them to servers S1 and S2 respectively. After servers S1 and S2 complete the computation, they reconstruct the complete outsourced computation result based on the secret shared ciphertext of the outsourced computation results of the two servers, and construct a verification item s for verifying the integrity of the outsourced computation result. r , combined with the verification item s′ constructed by the server to verify the integrity of the outsourced calculation results r , verify whether the calculation results returned by servers S1 and S2 are complete;

[0009] Two servers S1 and S2: construct the verification item s for verifying the integrity of the uploaded data based on [[d]]1, [[d]]2 and d·φ1+φ2 obtained after decryption d and s′ d , collaboratively verify the integrity of the outsourced data and broadcast the verification results; collaboratively perform secure computations, return the secret shared encryption of the outsourced computation results to the client C, and construct a verification item s′ for verifying the integrity of the outsourced computation results r .

[0010] The present invention proposes a bidirectional integrity verification method that is resistant to arithmetic consistency attacks. The method is implemented using the above-mentioned cloud-assisted privacy-preserving biometric authentication system based on multi-key fully homomorphic encryption, and includes security data verification and security result verification.

[0011] Preferably, the specific steps of the security data verification are as follows:

[0012] Step C1: Using arithmetic secret sharing technology, for any element d of the outsourced data, client C randomly splits it into secret shares [[d]]1 and [[d]]2; the third-party server T generates a public-private key pair (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links; the third-party server T generates two input-independent random numbers φ1 and φ2, and sends φ1 to client C and server S1, and sends φ2 to client C and server S2;

[0013] Step C2: Using homomorphic encryption technology, client C uses public key pk1 to encrypt [[d]]1 and sends the ciphertext Send to server S1; client C uses public key pk2 to encrypt [[d]]2 and d·φ1+φ2, where φ1 and φ2 are random numbers used to blind the input, and the ciphertext and Send to server S2;

[0014] Step C3: Server S1 decrypts using private key sk1 Restore the plaintext [[d]]1; server S2 uses private key sk2 to decrypt and Recover the plaintext [[d]]2 and d·φ1+φ2, and construct the verification item s d ←d·φ1+φ2; Servers S1 and S2 execute the secure shared transformation protocol π M2A , calculate [[g d ]]1,[[g d ]]2←Π M2A (φ1,[[d]]2), respectively obtain the secret sharing [[g d ]]1 and [[g d ]]2, satisfy[[g d ]]1+[[g d ]]2=φ1·[[d]]2;

[0015] Step C4: Server S1 calculates and sends [[d]]1·φ1+[g d ]]1 to server S2, server S2 calculates another verification item s′ d ←([[d]]1·φ1+[[g d ]]1)+[[g d ]]2+φ2;

[0016] Step C5: Server S2 determines two verification items s d and s′ d Are they equal? If s d =s′ d , under the assumption that the pre-generated random numbers φ1 and φ2 remain unchanged, indicating that the secret shares [[d]]1 and [[d]]2 have not been tampered with during transmission, server S2 returns 1 and informs server S1 of the verification result; if s d ≠s′ d, it means that the integrity of secret shares [[d]]1 and [[d]]2 is destroyed, server S2 returns ⊥ and informs server S1 of the verification result.

[0017] Preferably, the specific steps of the security result verification are as follows:

[0018] Step D1: For any element r of the outsourced computation result, servers S1 and S2 hold the secret shares of r [[r]]1 and [[r]]2 respectively; the third-party server T generates a public-private key pair (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links; the third-party server T generates two input-independent random numbers φ1 and φ2, and sends φ1 to client C and server S1, and sends φ2 to client C and server S2;

[0019] Step D2: Using homomorphic encryption technology, server S1 uses the public key pk c Encrypt [[r]]1 and convert the ciphertext Sent to client C; server S2 uses public key pk c Encrypt [[r]]2 and convert the ciphertext Send to client C;

[0020] Step D3: Client C uses the private key sk c Decryption and Recover the plaintext [[r]]1 and [[r]]2, reconstruct the complete outsourced calculation result r←[[r]]1+[[r]]2, and construct the verification item s r ←r·φ1+φ2;

[0021] Step D4: Servers S1 and S2 execute the secure shared conversion protocol Pi M2A , calculate [[g r ]]1,[[g r ]]2←Π M2A (φ1,[[r]]2), respectively obtain the secret sharing [[g r ]]1 and [[g r ]]2, satisfy[[g r ]]1+[[g r ]]2=φ1·[[r]]2;Server S1 calculates and sends [[r]]1·φ1+[g r ]]1 to server S2, server S2 calculates another verification item s′ r←([[r]]1·φ1+[[g r ]]1)+[[g r ]]2+φ2, and use the public key pk c Encrypted to Send to client C;

[0022] Step D5: Client C uses private key sk c Decryption Recover the verification item s′ r ; Client C determines two verification items s r and s′ r Are they equal? If s r =s′ r , under the assumption that the pre-generated random numbers φ1 and φ2 remain unchanged, it means that the secret shares [[r]]1 and [[r]]2 have not been tampered with during transmission, and the reconstructed calculation result r is correct; if s r ≠s′ r , then the integrity of the secret shares [[r]]1 and [[r]]2 is destroyed.

[0023] Compared with the prior art, the present invention has the following beneficial effects:

[0024] This invention provides a bidirectional integrity verification method and system that is resistant to arithmetic consistency attacks. Leveraging homomorphic encryption and arithmetic secret sharing, this method and system proposes a method for verifying data integrity. By designing an optimized secure data and result verification protocol specifically for arithmetic consistency attacks launched by malicious adversaries, this method and system ensures the confidentiality and integrity of transmitted data and effectively resists arithmetic consistency attacks. This protocol can serve as the integrity verification component of privacy-preserving outsourced computing systems and is suitable for large-scale deployment. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 This is a diagram illustrating the implementation of the system of the present invention. DETAILED DESCRIPTION

[0026] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings.

[0027] The present invention proposes a bidirectional integrity verification method and system that are resistant to arithmetic consistency attacks, so as to overcome the defect that the security data integrity verification protocol based on homomorphic encryption and arithmetic secret sharing cannot resist arithmetic consistency attacks. The adversary can combine the homomorphic properties of HE to tamper with the data without affecting the equality of the verification items. The present invention negotiates two random numbers for blinding the input in advance, designs an optimized security data and result verification protocol, and realizes more secure and efficient integrity verification.

[0028] A secure data verification protocol based on homomorphic encryption and arithmetic secret sharing supports integrity verification of outsourced data. The introduction of lightweight arithmetic secret sharing can reduce the computational cost of the verification process. In arithmetic consistency attacks, malicious adversaries can exploit the homomorphic properties of homomorphic encryption to tamper with data. The following describes a secure data verification protocol based on homomorphic encryption and arithmetic secret sharing, as well as an arithmetic consistency attack method.

[0029] The specific steps of the secure data verification protocol based on homomorphic encryption and arithmetic secret sharing are as follows:

[0030] Step A1: Using arithmetic secret sharing technology, for any element d of the outsourced data, client C randomly splits it into secret shares [[d]]1 and [[d]]2. The third-party server T generates a public-private key pair (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links;

[0031] Step A2: Using homomorphic encryption technology, client C uses the public key pk1 of server S1 to encrypt [[d]]1 and φ1, and sends the ciphertext and Send to server S1, where φ1 is a random number used to blind [[d]]1; client C uses the public key pk2 of server S2 to encrypt [[d]]2 and d+φ1, and sends the ciphertext and Send to server S2;

[0032] Step A3: Server S1 decrypts using private key sk1 and To recover the plaintext [[d]]1 and φ1, and calculate and send [[d]]1+φ1 to server S2; server S2 uses private key sk2 to decrypt and To recover the plaintext [[d]]2 and d+φ1;

[0033] Step A4: Server S2 determines whether the two verification items [[d]]1+[[d]]2+φ1 and d+φ1 are equal. If [[d]]1+[[d]]2+φ1=d+φ1, then the secret shares [[d]]1 and [[d]]2 have not been tampered with during transmission. Server S2 returns 1 and notifies server S1 of the verification result. If [[d]]1+[[d]]2+φ1≠d+φ1, then the integrity of the secret shares [[d]]1 and [[d]]2 has been compromised. Server S2 returns ⊥ and notifies server S1 of the verification result.

[0034] Arithmetic consistency attack can be defined as follows: for the original data d, if the adversary By selecting a random number a and leveraging the additive homomorphism and multiplicative homomorphism properties of homomorphic encryption, we can change d to d+a or a·d while maintaining the consistency of the left and right terms of the verification equation. This data is then considered vulnerable to arithmetic consistency attacks. Specific arithmetic consistency attack methods include the following:

[0035] B1: In and During the transmission process, the adversary Using the additive homomorphic property of homomorphic encryption, we can calculate and Where a is the adversary The random number selected. Without knowing the private key sk2, the adversary You can and Tampered with and Under this attack, [[d]]1+[[d]]2+φ1+a=d+φ1+a still holds, and the data d of client C is successfully tampered with to d+a without the knowledge of servers S1 and S2;

[0036] B2: In and During the transmission process, the malicious adversary Using the homomorphic encryption of multiplication homomorphic properties, calculation and Without knowing the private keys sk1 and sk2, a malicious adversary You can and Tampered with and Under this attack, a·([[d]]1+[[d]]2+φ1)=a·(d+φ1) still holds, and the data d of client C is successfully tampered with to a·d without the knowledge of servers S1 and S2.

[0037] The present invention proposes a bidirectional integrity verification method that is resistant to arithmetic consistency attacks and designs an optimized security data and result verification protocol. Under the assumption of the invariance of pre-generated random numbers, the confidentiality and integrity of outsourced data and calculation results can be ensured.

[0038] In this embodiment, an optimized secure data verification protocol is designed to ensure the confidentiality and integrity of outsourced data and effectively resist arithmetic consistency attacks by malicious adversaries. The specific steps are as follows:

[0039] Step C1: Using arithmetic secret sharing technology, for any element d of the outsourced data, client C randomly splits it into secret shares [[d]]1 and [[d]]2. The third-party server T generates a public-private key pair (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links. The third-party server T generates two input-independent random numbers φ1 and φ2, and sends φ1 to client C and server S1, and φ2 to client C and server S2;

[0040] Step C2: Using homomorphic encryption technology, client C uses public key pk1 to encrypt [[d]]1 and sends the ciphertext Send to server S1; client C uses public key pk2 to encrypt [[d]]2 and d·φ1+φ2, where φ1 and φ2 are random numbers used to blind the input, and the ciphertext and Send to server S2;

[0041] Step C3: Server S1 decrypts using private key sk1 Restore the plaintext [[d]]1; server S2 uses private key sk2 to decrypt and Recover the plaintext [[d]]2 and d·φ1+φ2, and construct the verification item s d ←d·φ1+φ2; Servers S1 and S2 execute the secure shared transformation protocol π M2A , calculate [[g d ]]1,[[g d ]]2←Π M2A (φ1,[[d]]2), respectively obtain the secret sharing [[g d ]]1 and [[g d ]]2, satisfy[[g d ]]1+[[g d ]]2=φ1·[[d]]2;

[0042] Step C4: Server S1 calculates and sends [[d]]1·φ1+[g d ]]1 to server S2, server S2 calculates another verification item s′ d ←([[d]]1·φ1+[[g d ]]1)+[[g d ]]2+φ2;

[0043] Step C5: Server S2 determines two verification items s d and s′ d Are they equal? If s d =s′ d , under the assumption that the pre-generated random numbers φ1 and φ2 remain unchanged, it can be ensured that the secret shares [[d]]1 and [[d]]2 have not been tampered with during transmission. Server S2 returns 1 and informs the verification result to server S1; if s d ≠s′ d , it means that the integrity of secret shares [[d]]1 and [[d]]2 is destroyed, server S2 returns ⊥ and informs server S1 of the verification result.

[0044] The secure sharing conversion protocol is a prior art. For details, please refer to the protocol STMA proposed in the paper "Achieving Lightweight and Privacy-Preserving Object Detection for Connected Autonomous Vehicles", which is used to securely implement the conversion from multiplicative secret sharing to additive secret sharing.

[0045] In this embodiment, an optimized security result verification protocol is designed to ensure the confidentiality and integrity of outsourced calculation results and effectively resist arithmetic consistency attacks by malicious adversaries. The specific steps are as follows:

[0046] Step D1: For any element r of the outsourced computation result, servers S1 and S2 hold the secret shares of r [[r]]1 and [[r]]2 respectively. The third-party server T generates a public-private key pair (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links. The third-party server T generates two input-independent random numbers φ1 and φ2, and sends φ1 to client C and server S1, and φ2 to client C and server S2;

[0047] Step D2: Using homomorphic encryption technology, server S1 uses the public key pk c Encrypt [[r]]1 and convert the ciphertext Sent to client C; server S2 uses public key pk c Encrypt [[r]]2 and convert the ciphertext Send to client C;

[0048] Step D3: Client C uses the private key sk c Decryption and Recover the plaintext [[r]]1 and [[r]]2, reconstruct the complete outsourced calculation result r←[[r]]1+[[r]]2, and construct the verification item s r ←r·φ1+φ2;

[0049] Step D4: Servers S1 and S2 execute the secure shared conversion protocol Pi M2A , calculate [[g r ]]1,[[g r ]]2←Π M2A (φ1,[[r]]2), respectively obtain the secret sharing [[g r ]]1 and [[g r ]]2, satisfy[[g r ]]1+[[g r ]]2=φ1·[[r]]2;Server S1 calculates and sends [[r]]1·φ1+[g r ]]1 to server S2, server S2 calculates another verification item s′ r ←([[r]]1·φ1+[[g r ]]1)+[[g r ]]2+φ2, and encrypt it as Send to client C;

[0050] Step D5: Client C uses private key sk c Decryption Recover the verification item s′ r ; Client C determines two verification items s r and s′ r Are they equal? If s r =s′ r , under the assumption that the pre-generated random numbers φ1 and φ2 remain unchanged, it can be ensured that the secret shares [[r]]1 and [[r]]2 have not been tampered with during transmission, and the reconstructed calculation result r is correct; if s r ≠s′ r , then the integrity of the secret shares [[r]]1 and [[r]]2 is destroyed.

[0051] To verify the beneficial effects of the present invention, the inventors compared the bidirectional integrity verification method of the embodiment with related work, as shown in Table 1. During transmission and calculation, data and results remain confidential. Based on this, the method proposed in the present invention can implement bidirectional integrity verification of outsourced data and calculation results, and resist arithmetic consistency attacks.

[0052] Table 1 Functional comparison of integrity verification methods

[0053]

[0054] The present invention also provides a transmission data integrity verification system for implementing the above method, such as Figure 1 As shown, it includes client C, third-party server T, and two servers S1 and S2.

[0055] Client C provides encrypted data to servers S1 and S2, randomly splits any element d of the outsourced data into two secret shares [[d]]1 and [[d]]2 for the two servers to collaboratively perform secure computations, and encrypts [[d]]1 and [[d]]2, d·φ1+φ2, and sends them to servers S1 and S2 respectively. After servers S1 and S2 complete the computation, they reconstruct the complete outsourced computation result based on the secret shared ciphertext of the outsourced computation results of the two servers, and construct a verification item s for verifying the integrity of the outsourced computation result. r , combined with the verification item s′ constructed by the server to verify the integrity of the outsourced calculation results r , verify whether the calculation results returned by servers S1 and S2 are complete;

[0056] Third-party server T: Generates public-private key pairs (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links; two input-independent random numbers φ1 and φ2 are generated, and φ1 is sent to client C and server S1, and φ2 is sent to client C and server S2;

[0057] Two servers S1 and S2: construct the verification item s for verifying the integrity of the uploaded data based on [[d]]1, [[d]]2 and d·φ1+φ2 obtained after decryption d and s′ d , collaboratively verify the integrity of the outsourced data and broadcast the verification results; collaboratively perform secure computations, return the secret shared encryption of the outsourced computation results to the client C, and construct a verification item s′ for verifying the integrity of the outsourced computation results r .

[0058] The above are preferred embodiments of the present invention. Any changes made according to the technical solution of the present invention, as long as the resulting functions and effects do not exceed the scope of the technical solution of the present invention, shall fall within the scope of protection of the present invention.

Claims

1. A bidirectional integrity verification system resistant to arithmetic consistency attacks, characterized in that: include: Third-party server T: Generates public-private key pairs (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links; two input-independent random numbers φ1 and φ2 are generated, and φ1 is sent to client C and server S1, and φ2 is sent to client C and server S2; Client C: Provides encrypted data to servers S1 and S2, randomly splits any element d of the outsourced data into two secret shares [[d]]1 and [[d]]2 for the two servers to collaboratively perform secure computations, and encrypts [[d]]1 and [[d]]2, d·φ1+φ2, and sends them to servers S1 and S2 respectively. After servers S1 and S2 complete the computation, they reconstruct the complete outsourced computation result based on the secret shared ciphertext of the outsourced computation results of the two servers, and construct a verification item s for verifying the integrity of the outsourced computation result. r , combined with the verification item s′ constructed by the server to verify the integrity of the outsourced calculation results r , verify whether the calculation results returned by servers S1 and S2 are complete; Two servers S1 and S2: construct the verification item s for verifying the integrity of the uploaded data based on [[d]]1, [[d]]2 and d·φ1+φ2 obtained after decryption d and s′ d , collaboratively verify the integrity of the outsourced data and broadcast the verification results; collaboratively perform secure computations, return the secret shared encryption of the outsourced computation results to the client C, and construct a verification item s′ for verifying the integrity of the outsourced computation results r .

2. A bidirectional integrity verification method against arithmetic consistency attacks, characterized in that: The method is implemented using the cloud-assisted privacy-preserving biometric authentication system based on multi-key fully homomorphic encryption as described in claim 1, including security data verification and security result verification.

3. The bidirectional integrity verification method against arithmetic consistency attacks according to claim 2, characterized in that: The specific steps of security data verification are as follows: Step C1: Using arithmetic secret sharing technology, for any element d of the outsourced data, client C randomly splits it into secret shares [[d]]1 and [[d]]2; the third-party server T generates a public-private key pair (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links; the third-party server T generates two input-independent random numbers φ1 and φ2, and sends φ1 to client C and server S1, and sends φ2 to client C and server S2; Step C2: Using homomorphic encryption technology, client C uses public key pk1 to encrypt [[d]]1 and converts the ciphertext E pk1 ([[d]]1) is sent to server S1; client C uses public key pk2 to encrypt [[d]]2 and d·φ1+φ2, where φ1 and φ2 are random numbers used to blind the input, and the ciphertext and Send to server S2; Step C3: Server S1 decrypts using private key sk1 Restore the plaintext [[d]]1; server S2 uses private key sk2 to decrypt and Recover the plaintext [[d]]2 and d·φ1+φ2, and construct the verification item s d ←d·φ1+φ2; Servers S1 and S2 execute the secure shared transformation protocol π M2A , calculate [[g d ]]1,[[g d ]]2←Π M2A (φ1,[[d]]2), respectively obtain the secret sharing [[g d ]]1 and [[g d ]]2, satisfy[[g d ]]1+[[g d ]]2=φ1·[[d]]2; Step C4: Server S1 calculates and sends [[d]]1·φ1+[g d ]]1 to server S2, server S2 calculates another verification item s′ d ←([[d]]1·φ1+[[g d ]]1)+[[g d ]]2+φ2; Step C5: Server S2 determines two verification items s d and s′ d Are they equal? If s d =s′ d , under the assumption that the pre-generated random numbers φ1 and φ2 remain unchanged, indicating that the secret shares [[d]]1 and [[d]]2 have not been tampered with during transmission, server S2 returns 1 and informs server S1 of the verification result; if s d ≠s′ d , it means that the integrity of secret shares [[d]]1 and [[d]]2 is destroyed, server S2 returns ⊥ and informs server S1 of the verification result.

4. The bidirectional integrity verification method against arithmetic consistency attacks according to claim 2, characterized in that: The specific steps for verifying the safety results are as follows: Step D1: For any element r of the outsourced computation result, servers S1 and S2 hold the secret shares of r [[r]]1 and [[r]]2 respectively; the third-party server T generates a public-private key pair (pk c ,sk c ), (pk1, sk1) and (pk2, sk2), and the public key (pk c ,pk1,pk2) are broadcast to other entities for encrypted data transmission in open links; the third-party server T generates two input-independent random numbers φ1 and φ2, and sends φ1 to client C and server S1, and sends φ2 to client C and server S2; Step D2: Using homomorphic encryption technology, server S1 uses the public key pk c Encrypt [[r]]1 and convert the ciphertext Sent to client C; server S2 uses public key pk c Encrypt [[r]]2 and convert the ciphertext Send to client C; Step D3: Client C uses the private key sk c Decryption and Recover the plaintext [[r]]1 and [[r]]2, reconstruct the complete outsourced calculation result r←[[r]]1+[[r]]2, and construct the verification item s r ←r·φ1+φ2; Step D4: Servers S1 and S2 execute the secure shared conversion protocol Pi M2A , calculate [[g r ]]1,[[g r ]]2←Π M2A (φ1,[[r]]2), respectively obtain the secret sharing [[g r ]]1 and [[g r ]]2, satisfy[[g r ]]1+[[g r ]]2=φ1·[[r]]2;Server S1 calculates and sends [[r]]1·φ1+[g r ]]1 to server S2, server S2 calculates another verification item s′ r ←([[r]]1·φ1+[[g r ]]1)+[[g r ]]2+φ2, and use the public key pk c Encrypted to Send to client C; Step D5: Client C uses private key sk c Decryption Recover the verification item s′ r ; Client C determines two verification items s r and s′ r Are they equal? If s r =s′ r , under the assumption that the pre-generated random numbers φ1 and φ2 remain unchanged, it means that the secret shares [[r]]1 and [[r]]2 have not been tampered with during transmission, and the reconstructed calculation result r is correct; if s r ≠s′ r , then the integrity of the secret shares [[r]]1 and [[r]]2 is destroyed.