Data processing method, device and equipment and computer readable storage medium
By mapping subfunctions from the modulo 2k ring to the Galois ring and performing parallel computations, the computational efficiency and security issues of the modulo 2k ring are solved using RMFE and NM-RMFE techniques, achieving efficient and secure data processing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2026-03-27
AI Technical Summary
In non-interactive secure computation, the modulo 2k ring suffers from the inability to use Lagrange interpolation and zero-factor unreliability, resulting in low computational efficiency and insufficient data security, and is unable to effectively handle the sender's second data.
The subfunctions are mapped from the modulo 2k ring to the Galois ring, and computed in parallel. The inverse multiplication-friendly embedding (RMFE) and non-extendable inverse multiplication-friendly embedding (NM-RMFE) techniques are combined with re-embedding and cut selection techniques to ensure data security and computational efficiency.
It improves the computational efficiency of data processing, ensures data security, prevents data leakage, and prevents dishonest execution of RMFE, thus achieving efficient and secure data processing.
Smart Images

Figure CN121744347A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a data processing method and device, equipment and computer readable storage medium. BACKGROUND
[0002] In the field of computer technology, secure two-party computation (STC) allows a sender and a receiver to complete a computing task while protecting their respective input data, without leaking each other's input data. The STC includes non-interactive secure computation (NISC), in which the receiver and the sender perform two rounds of communication. In the first round of communication, the receiver encrypts the input data to obtain first data and discloses the first data. The first data disclosed by the receiver can be used by the sender in the second round of communication. For example, the sender uses the first data and the second data as the second data to calculate ciphertext information in the second round of communication, and returns the ciphertext information to the receiver. Therefore, there is an urgent need for a data processing method to process the second data of the sender in the second round of communication. SUMMARY
[0003] The present application provides a data processing method, device, equipment and computer readable storage medium to process the second data of the sender, and the technical solution is as follows:
[0004] In a first aspect, a data processing method is provided, the method is applied to a first device, and the method includes: obtaining a plurality of sub-functions, the plurality of sub-functions are obtained by decomposing a computing function located in a modulo 2 k ring, the computing function is used to calculate second data of the first device based on first data published by a second device, k is a positive integer and is used to indicate the number of bits of the first data and the second data; mapping the plurality of sub-functions from the modulo 2 k ring to a Galois ring, calculating the first data and the second data by using the mapped sub-functions, obtaining ciphertext information corresponding to the second data based on a calculation result, at least two mapped sub-functions are located in the same Galois ring and the first data and the second data are calculated in parallel; and sending the ciphertext information to the second device.
[0005] Since the computing function is located in the modulo 2 k ring, a computing protocol defined in the modulo 2 k ring can be used in the process of processing the first data and the second data by using the computing function, and the computing protocol has low overhead. By mapping the sub-function from the modulo 2 k ring to its ring extension (Galois ring), the problems existing in the modulo 2 k ring are solved, such as the modulo 2k The Lagrange interpolation method cannot be used in the ring, and there are many zero factors that cannot guarantee reliability. The sub-functions that can be calculated in parallel are mapped to the same Galois ring, and the mapped sub-functions are calculated in parallel, thereby effectively improving the calculation efficiency of data processing.
[0006] In a possible implementation, the first data and the second data are located on the Galois ring and are calculated based on reverse multiplicative friendly embedding (RMFE), and the RMFE is negotiated between the first device and the second device. The sub-function is mapped from the modulo 2 k The ring mapping to the Galois ring refers to mapping the data used for sub-function calculation from the modulo 2 k The ring mapping to the Galois ring, the data used for sub-function calculation includes the first data and the second data, and the algorithm used for calculating the first data and the second data is uniformly calculated as the RMFE algorithm through negotiation. In the process of mapping the sub-function to the Galois ring by the first device, only the second data needs to be calculated by using the RMFE, and the first data does not need to be processed, thereby controlling the data processing amount and improving the processing efficiency.
[0007] In a possible implementation, the RMFE includes non-malleable reverse multiplicative friendly embedding (NM-RMFE), and the NM-RMFE is obtained by cascading two RMFEs. In the case of using the NM-RMFE technology, if any one of the first data or the second data is not calculated according to the NM-RMFE, the calculation result of the first data and the second data calculated by using the sub-function is a random output result, which is irrelevant to the input first data and second data, and the input first data and second data cannot be inferred from the calculation result, thereby ensuring that the data calculated based on the NM-RMFE cannot be leaked, and ensuring the data security.
[0008] In a possible implementation, before the first data and the second data are calculated by using the mapped sub-function, the method further includes: obtaining the first data of the second device; clipping the first data to obtain a plurality of sub-data; selecting a sub-data from the plurality of sub-data, and verifying whether the first data of the second device is calculated by using the RMFE according to the selected sub-data. After obtaining the first data published by the second device, the first data is further verified to verify whether the first data is calculated based on the RMFE. In the case that the first data is calculated based on the RMFE, the second data is calculated according to the first data, and the security of the calculation process is high.
[0009] In a possible implementation, the first data and the second data are calculated by using the mapped sub-function, including: inputting the second data into the mapped sub-function by using a re-embedding technique, and calculating the first data and the second data inputted based on the re-embedding technique by using the mapped sub-function, wherein the re-embedding technique is used to convert the second data into an element in a RMFE image set in a case where the second data is not the element in the RMFE image set. The data calculated by using the RMFE is an element in the RMFE image set, and the second data is not calculated by using the RMFE in a case where the second data is not the element in the RMFE image set. In this case, the second data can be automatically converted into the element in the RMFE image set by using the re-embedding technique, and the behavior of the first device not honestly performing the RMFE is effectively prevented, and the data security in the process of calculating the first data and the second data is ensured.
[0010] The application does not limit the manner of preventing the first device or the second device from not performing the RMFE, which can be performing the NM-RMFE, or using the re-embedding and cutting and selecting technique, and has high flexibility.
[0011] In a possible implementation, the plurality of sub-functions are obtained, including: obtaining a calculation function; decomposing the calculation function into a plurality of unit functions by adding virtual gates in the calculation function; and converting any unit function into a sub-function belonging to an arithmetic branching program (BP). The decomposition of the calculation function can be implemented by adding the virtual gates, and the decomposition process is simple. Moreover, the functions that can be calculated in the current cryptography field are in the form of the arithmetic BP, and the unit functions obtained by decomposition are converted into the sub-functions in the form of the arithmetic BP, so as to be suitable for the cryptography field.
[0012] In a possible implementation, the second data corresponds to the ciphertext information based on the calculation result, including: obtaining the ciphertext information by using the first element to confuse the calculation result, wherein the first element is an element in a RMFE image set. The calculation result is converted into the ciphertext information by using the first element to confuse the calculation result, so as to avoid the calculation result from being leaked in the transmission process, and the security in the data transmission process is improved.
[0013] In a possible implementation, the ciphertext information is sent to the second device, including: sending the ciphertext information to the second device by using a vector oblivious linear function evaluation (VOLE). The ciphertext information is encrypted in the process of transmitting the ciphertext information by using the VOLE, and the security of transmitting the encrypted ciphertext information is higher than that of directly transmitting the ciphertext information.
[0014] In a possible implementation, the VOLE includes a certified vector oblivious linear function evaluation (cVOLE), and the cVOLE is further used for the second device to verify whether the first device obtains the ciphertext information based on a decomposable affine randomized encoding (DARE) obfuscated calculation result. The ciphertext information is transmitted through the cVOLE, and in addition to ensuring the security of data transmission, it can also be verified whether the ciphertext information is obfuscated according to the DARE after being transmitted to the second device, so as to timely detect dishonest behavior of the first device in the case that the first device does not calculate the result according to the DARE obfuscation.
[0015] In a second aspect, a data processing apparatus is provided, and the apparatus is applied to the first device, and the apparatus includes: a transceiver module, configured to perform the receiving and / or sending related operations in the first aspect or any possible implementation of the first aspect; and a processing module, configured to perform other operations in addition to the receiving and / or sending related operations in the first aspect or any possible implementation of the first aspect.
[0016] In a possible implementation, the processing module is configured to obtain a plurality of sub-functions, the plurality of sub-functions are obtained by decomposing a calculation function located in a Galois ring, the calculation function is used to calculate second data of the first device based on first data published by the second device, k is a positive integer and is used to indicate bit numbers of the first data and the second data, and the processing module is further configured to map the plurality of sub-functions from the Galois ring to a Galois field, calculate the first data and the second data by using the mapped sub-functions, obtain ciphertext information corresponding to the second data based on a calculation result, and at least two mapped sub-functions are located in a same Galois field and are used to calculate the first data and the second data in parallel. k k In a possible implementation, the first data and the second data are located in a Galois ring and are obtained based on an RMFE, and the RMFE is obtained by negotiation between the first device and the second device.
[0017] In a possible implementation, the first data and the second data are located in a Galois ring and are obtained based on an RMFE, and the RMFE is obtained by negotiation between the first device and the second device.
[0018] In a possible implementation, the RMFE includes an NM-RMFE, and the NM-RMFE is obtained by cascading two RMFEs.
[0019] In a possible implementation, the processing module is further configured to obtain the first data of the second device; cut the first data to obtain a plurality of sub-data; and select a sub-data from the plurality of sub-data, and verify whether the first data of the second device is calculated by using the RMFE according to the selected sub-data.
[0020] In a possible implementation, the processing module is configured to input the second data into the mapped sub-function by using a re-embedding technology, and calculate the first data and the second data input based on the re-embedding technology by using the mapped sub-function, where the re-embedding technology is used to convert the second data into an element in the RMFE image set in a case where the second data is not an element in the RMFE image set.
[0021] In a possible implementation, the processing module is configured to obtain a calculation function; decompose the calculation function into a plurality of unit functions by adding a virtual gate in the calculation function; and convert any unit function into a sub-function belonging to the arithmetic BP.
[0022] In a possible implementation, the processing module is configured to obtain the ciphertext information by using the first element to confuse the calculation result, where the first element is an element in the RMFE image set.
[0023] In a possible implementation, the transceiving module is configured to send the ciphertext information to the second device by using the VOLE.
[0024] In a possible implementation, the VOLE includes a cVOLE, and the cVOLE is further configured to enable the second device to verify whether the first device obtains the ciphertext information based on the DARE to confuse the calculation result.
[0025] In a third aspect, a data processing device is provided, and the device includes a processor configured to load and execute at least one instruction to enable the data processing device to perform the method in the first aspect or any possible implementation of the first aspect.
[0026] In a possible implementation, the device includes a memory coupled to the processor, and the memory stores the at least one instruction.
[0027] In a fourth aspect, a computer readable storage medium is provided, and the computer readable storage medium stores at least one instruction, which is loaded and executed by a processor to implement the data processing method in the first aspect or any possible implementation of the first aspect.
[0028] In a fifth aspect, a computer program (product) is provided, and the computer program (product) includes computer programs / instructions, which are executed by a processor to enable a computer to implement the data processing method in the first aspect or any possible implementation of the first aspect.
[0029] In a sixth aspect, a communication apparatus is provided, which comprises a transceiver, a memory and a processor. The transceiver, the memory and the processor are in communication with each other through internal connection paths. The memory is configured to store instructions, and the processor is configured to execute the instructions stored in the memory to control the transceiver to receive a signal and control the transceiver to send a signal. When the processor executes the instructions stored in the memory, the processor is caused to perform the method in the first aspect or any possible implementation manner of the first aspect. Optionally, the communication apparatus can be a chip.
[0030] Optionally, the processor is one or more, and the memory is one or more.
[0031] Optionally, the memory can be integrated with the processor, or the memory and the processor are separately arranged.
[0032] In a specific implementation process, the memory can be a non-transitory memory, such as a read only memory (ROM), which can be integrated on the same chip with the processor, or arranged on different chips respectively. The type of the memory and the arrangement manner of the memory and the processor are not limited in the present application.
[0033] In a seventh aspect, a chip is provided, which comprises a processor configured to invoke and run a running program instruction or code stored in a memory, so that a communication device installed with the chip performs the method in the above aspects.
[0034] In an eighth aspect, another chip is provided, which comprises an input interface, an output interface, a processor and a memory. The input interface, the output interface, the processor and the memory are connected through internal connection paths. The processor is configured to execute the code in the memory. When the code is executed, the processor is configured to perform the method in the above aspects.
[0035] In a ninth aspect, a data processing system is provided, which comprises a first device and a second device. The second device is configured to publish first data, and the first device is configured to perform the method in the first aspect or any possible implementation manner of the first aspect.
[0036] It should be understood that the above data processing apparatus can be a chip or a communication device. The beneficial effects achieved by the technical solutions of the second aspect to the ninth aspect and the corresponding possible implementation manners of the present application can be referred to the technical effects of the first aspect and the corresponding possible implementation manners, which will not be described herein. BRIEF DESCRIPTION OF DRAWINGS
[0037] Figure 1An interaction diagram of non-interactive two-party secure computation provided for an embodiment of the present application;
[0038] Figure 2 A diagram of an implementation environment provided for an embodiment of the present application;
[0039] Figure 3 A flowchart of a data processing method provided for an embodiment of the present application;
[0040] Figure 4 A decomposition diagram of a computing function provided for an embodiment of the present application;
[0041] Figure 5 A diagram of function conversion provided for an embodiment of the present application;
[0042] Figure 6 A conversion diagram of NM-RMFE provided for an embodiment of the present application;
[0043] Figure 7 A diagram of cVOLE provided for an embodiment of the present application;
[0044] Figure 8 A structural diagram of a data processing apparatus provided for an embodiment of the present application;
[0045] Figure 9 A structural diagram of a network device provided for an embodiment of the present application;
[0046] Figure 10 A structural diagram of another network device provided for an embodiment of the present application. DETAILED DESCRIPTION
[0047] The terms used in the embodiment part of the present application are only used for explaining the specific embodiments of the present application, and are not intended to limit the present application. In order to make the purpose, technical solutions and advantages of the present application clearer, the embodiment of the present application will be further described in detail below with reference to the drawings.
[0048] In the field of computer technology, STC technology can allow two mutually distrustful participants to jointly compute a predetermined function by executing a protocol process without revealing their own input data. The two participants are, for example, a sender and a receiver. In some cases, STC needs to meet correctness and security. Correctness means that when both participants honestly execute the protocol process, the probability of outputting a correct calculation result is greater than the probability of outputting an incorrect calculation result, and the probability of outputting a correct calculation result is overwhelming. Security means that when there is a malicious participant, the input data of the honest participant will not be disclosed during the execution of the protocol.
[0049] In one possible implementation, the process of the two parties performing the STC includes: Figure 1 The three phases shown are the initialization phase, the message sending phase, and the result calculation phase. In the initialization phase, the receiver on the right calculates the public information based on the input data x and the protocol description, and then publishes this public information. This public information can be as follows: Figure 1 The image shows the encryption of x. The receiver can disclose the encryption method of x as follows: Figure 1 The encryption of x is shown. Afterwards, during the message sending phase, the sender, having accessed the receiver's public information, calculates the local input data y based on that information. i To obtain the corresponding ciphertext information, that is Figure 1 Msg shown i Msg i Sent to the recipient. During the result calculation phase, the recipient receives the Msg. i Then, calculations are performed based on the local input data x to obtain the result, which is... Figure 1 The f(x, y) shown i ). Figure 1 The STC technique shown, which involves two rounds of communication between the receiver and the sender, can be referred to as NISC in some cases.
[0050] This application provides a data processing method, please refer to the embodiments thereof. Figure 2 This diagram illustrates an implementation environment for the data processing method provided in this application embodiment. The implementation environment includes a first device 01 and a second device 02, which establish a communication connection via a wired or wireless network. The first device 01 acts as the sender, and the second device 02 acts as the receiver. The first device 01 executes the data processing method provided in this application embodiment, calculating encrypted information corresponding to local second data based on first data published by the second device 02, and then sending the encrypted information to the second device 02. The above process corresponds to… Figure 1 The message sending phase shown indicates that the first data corresponds to... Figure 1 The encryption of x in the second data is based on Figure 1 y in i The processed encrypted information corresponds to Figure 1 Msg i .
[0051] Optionally, the first device 01 and the second device 02 can be any device with a data processing function, and the first device 01 and the second device 02 can be a server, for example, a central server, an edge server, or a local server in a local data center. The server can be a physical server, and can also be a cloud server providing cloud computing services. In some embodiments, the first device 01 and the second device 02 can be terminal devices such as desktop computers, notebook computers, or smart phones. The first device 01 and the second device 02 can be independent devices, or can be a component on a device, such as a transceiver, a processor, or a chip. In addition, the data processing method provided in the embodiments of the present application can be executed by one first device 01, or can be executed by multiple first devices 01. In some cases, the multiple first devices 01 can be referred to as a device cluster, and the execution subject of the method is not specifically limited in the embodiments of the present application.
[0052] The embodiments of the present application provide a data processing method, which can be applied to Figure 2 The implementation environment is shown in FIG. 1, and the method is applied to the first device 01, for example. The flowchart of the method is shown in FIG. 2, and includes S301-S303. Figure 3
[0053] S301, obtaining a plurality of sub-functions, the plurality of sub-functions being obtained by decomposing a calculation function located in a modulo 2k k ring, the calculation function being used to calculate second data of the first device based on first data published by the second device, k being a positive integer and used to indicate bit numbers of the first data and the second data.
[0054] In a possible implementation, the sub-function is obtained by decomposing the calculation function, and the sub-function can be obtained at a historical moment or at a current moment. The process of decomposing the calculation function to obtain the sub-function by the first device includes but is not limited to: decomposing the calculation function into a plurality of unit functions by adding a virtual gate in the calculation function; and converting any unit function into a sub-function belonging to an arithmetic BP. The calculation function is used to calculate the second data based on the first data, and the calculation function can be a function negotiated by the first device and the second device, or a function determined by the first device.
[0055] For example, in addition to publishing initial data, the first device may also publish a computational function. Taking a recruitment scenario as an example, the recipient is the recruiter, the sender is the applicant, the second device is the device used by the recruiter, and the first device is the device used by the applicant. The initial data published by the second device indicates the recruitment criteria, and the second data from the first device is the applicant's resume information. Since the resume information includes the applicant's private data, and the applicant may not wish to disclose their resume information, the second device, in addition to publishing the initial data, may also publish a computational function. This allows the first device to encrypt the resume information based on the computational function and send the encrypted resume information to the second device, thereby enabling the resume to be submitted to the recruiter without the applicant disclosing their resume information. Optionally, the computational function published by the first device can be a complete function or the various parameters involved in the execution of the computational function.
[0056] Regardless of how the first device obtains the computation function, it can be decomposed into multiple sub-functions, breaking down the abstract computation function into a concrete process. The computation function is located at modulo 2. k A ring can be used to implement functions modulo 2 using arithmetic circuits. k A ring is a circular ring consisting of 2k points, ranging from 0 to 2k-1. Each point on the ring represents a unique value, modulo 2 in some cases. k Points on the ring can be called modulo 2. k Elements on the ring. Here, k is the number of bits in the first and second data. The first and second data have the same number of bits. For example, if the first and second data are 32 bits, then k is 32; if the first and second data are 64 bits, then k is 64. The calculation function is located modulo 2. k A ring is a function in which all elements used in the calculation are modulo 2. k The elements on the ring, the elements used for calculation include the input data of the calculation function and the coefficients of the calculation function, etc. The input data includes the first data and the second data in the above embodiment.
[0057] For example, an arithmetic circuit refers to a circuit that can perform mathematical operations such as addition, subtraction, multiplication, and division. It includes arithmetic logic units and registers, and is used to perform arithmetic operations such as addition, subtraction, multiplication, and division on binary data, as well as bit shifting operations. An arithmetic circuit is, for example, a Nick's class 1 (NC1) circuit, where 1 refers to the circuit's depth. Operations can be performed using arithmetic circuits based on computational functions. A computational function can be understood as a function used to perform arithmetic operations and bit shifting operations on input data.
[0058] In a possible implementation, after obtaining the computing function, the first device can first determine the NC1 circuit of the computing function. Since the NC1 circuit of the computing function includes multiple layers of circuits, the first device can add dummy gates in each layer of the NC1 circuit, so as to convert the multiple layers of circuits into multiple small NC1 circuits, and one small NC1 circuit corresponds to one unit function obtained by decomposing the computing function. Wherein, the small NC1 circuit refers to a circuit including a number of gates less than a first threshold, and the gate is used to perform an arithmetic operation or a bit shift operation. The first threshold can be a positive integer set based on experience, and the first threshold is not greater than the total number of gates included in the NC1 circuit of the computing function. For example, the NC1 circuit of the computing function includes four gates, and the first device sets the first threshold to be 4 or 3 based on experience.
[0059] Figure 4 A schematic diagram for decomposing a computing function provided by an embodiment of the present application, Figure 4 The left graph in FIG. 1 shows the NC1 circuit of the computing function, which includes an addition (ADD) gate and a multiplication (Mul) gate, a total of four gates. The first device decomposes the NC1 circuit into small NC1 circuits shown in the right graph of FIG. 1 by adding dummy gates. Figure 4 The right graph in FIG. 1 shows the NC1 circuit of the computing function, which includes an addition (ADD) gate and a multiplication (Mul) gate, a total of four gates. The first device decomposes the NC1 circuit into small NC1 circuits shown in the right graph of FIG. 1 by adding dummy gates. Figure 4 In FIG. 1, the small NC1 circuit includes three gates, and the number of gates is less than the number of gates in the NC1 circuit in the left graph of FIG. 1. Figure 4 In FIG. 1, the small NC1 circuit includes three gates, and the number of gates is less than the number of gates in the NC1 circuit in the left graph of FIG. 1.
[0060] Optionally, the multiple unit functions decomposed by the first device can be the same, and the multiple unit functions can also be different, for example, partially different. For example, 10 unit functions obtained by decomposing the computing function include 5 unit functions as shown in the right graph of FIG. 1, and also include 5 unit functions as shown in the right graph of FIG. 1. Figure 4 The right graph in FIG. 1 shows the NC1 circuit of the computing function, which includes an addition (ADD) gate and a multiplication (Mul) gate, a total of four gates. The first device decomposes the NC1 circuit into small NC1 circuits shown in the right graph of FIG. 1 by adding dummy gates. Figure 4 The right graph in FIG. 1 shows the NC1 circuit of the computing function, which includes an addition (ADD) gate and a multiplication (Mul) gate, a total of four gates. The first device decomposes the NC1 circuit into small NC1 circuits shown in the right graph of FIG. 1 by adding dummy gates.
[0061] In a possible case, the function supported by the two-party secure computation technology is in an arithmetic BP form. Alternatively, the arithmetic BP form can be referred to as an arithmetic branching program or an arithmetic branching procedure in some cases. In this case, the properties of the arithmetic BP include that an arithmetic BP form function f(x) in a ring R can be represented as a matrix L(x) with a special form, and a relationship f(x) = det(L(x)) is satisfied between f(x) and the matrix L(x), where the ring R is used to indicate a general ring. The special form of the matrix L(x) includes that: 1) the sub-diagonal line under the main diagonal line is -1, 2) the elements under the sub-diagonal line are 0, 3) each position above the main diagonal line is a single-variable linear polynomial, and 4) L(x) is a square matrix, and the length of the main diagonal line of the square matrix can be used to determine the size of f(x), for example, the length of the main diagonal line + 1 is the size of f(x).
[0062] Based on the case that the function supported by the computation is in the arithmetic BP form, the first device can perform format conversion on the unit functions to convert the unit functions into sub-functions in the arithmetic BP form after the unit functions are decomposed, Figure 5 a conversion schematic diagram provided by an embodiment of the present application, Figure 5 the left graph of which is a unit function, Figure 5 and the right graph of which is a sub-function. By representing the small NC1 circuit shown in Figure 5 as a determinant in the arithmetic BP form, the computation of the circuit is equivalent to the computation of the determinant of L(x, y).
[0063] In S302, the plurality of sub-functions are mapped from the ring Z2 k to a Galois ring, the first data and the second data are calculated by using the mapped sub-functions, the ciphertext information corresponding to the second data is obtained based on the calculation result, and the at least two mapped sub-functions are located on the same Galois ring and the first data and the second data are calculated in parallel.
[0064] In a possible case, since there is no set of more than two elements in the ring Z2 k and any two elements are reversible when subtracted from each other, in the process of using the Lagrange interpolation method, an inverse operation is performed on the calculation coefficient used in the Lagrange interpolation process. Since there is no set of any two elements that are reversible when subtracted from each other in the ring Z2 k , the inverse operation is not supported on the ring Z2 k , and therefore, the Lagrange interpolation method cannot be used on the ring Z2 k , for example, the Lagrange interpolation method cannot be used to interpolate a polynomial with a degree higher than 1.
[0065] In addition, since there is no set of more than two elements in the ring Z2 kHalf of the elements in the ring are zero divisors, where the zero divisors refer to independent variables that exist independently without depending on any other factors. The random linear combination commonly used in the field of secure multi-party computation can only guarantee the reliability of a constant size, i.e., modulo 2 k The zero divisors on the ring cannot guarantee reliability. Moreover, for the sub-functions located in the modulo 2 k ring, it is difficult to use the method in the secure computation protocol for dishonest majority (SPDZ2k) applied to the modulo 2 k ring.
[0066] Therefore, the first device can map the sub-function from the modulo 2 k ring to the Galois ring to solve the problems existing in the above-mentioned modulo 2 k ring. The Galois ring is a ring extension of the modulo 2 k ring. The Galois ring is a finite field containing a finite number of elements, also known as a Galois field. The number of elements contained in the Galois ring is p k , p is the characteristic number of the Galois ring, belongs to a prime number, k is any positive integer and is used to represent the number of bits of the first data and the second data, and the Galois ring GR(p k , d) will be introduced next.
[0067] The Galois ring is a ring obtained by extending the modulo 2 k ring, and the extension process is, for example, wherein, indicates the modulo 2 k ring, and is a d-th primitive polynomial, d≥1 is a positive integer. In addition, f(X) belongs to an irreducible polynomial on F p , F p refers to a field including p elements, and the irreducible polynomial refers to a polynomial that cannot be written as the product of two polynomials with lower degrees. f(X) also satisfies refers to taking the closure of f(X), and mod refers to taking the remainder. By f(X), the ring extension of d times is realized on to obtain the Galois ring.
[0068] Based on the definition of the Galois ring, the number of polynomial roots on the Galois ring can be obtained. For example, the number of roots of a non-zero r-th single variable polynomial on the Galois ring GR(p k , d) is not more than rp (k-1)d , that is, the non-zero r-th single variable polynomial located on the Galois ring has at most rp(k-1)d There are *r* roots, where *r* is the highest degree of the univariate polynomial, and *r* is a positive integer greater than 0. Based on the number of polynomial roots, it can be known that for any Galois ring GR(p)... k For a non-zero r-degree univariate polynomial f(x) on (d), the following relation exists: Pr indicates probability, GR indicates Galois ring, α indicates Galois ring GR(p k Random elements in d), Instructions for random sampling, based on the above relationship, can be used to calculate and determine GR(p) k ,d) contains 1 / p d The zero factor of the proportion.
[0069] Optionally, the subfunction is modulo 2 k Mapping a ring to a Galois ring means mapping the elements used in the computation of subfunctions to modulo 2. k Elements on the ring are converted to elements on the Galois ring. The first device can convert the subfunction from modulo 2 via RMFE. k A ring is mapped to a Galois ring. Taking a prime number p, and k, r, m', D ≥ 1 and are positive integers as an example, a pair of mappings (φ, ψ) is a (m', d; D)-RMFE if φ: GR(p k ,r) m ′→GR(p k ,rd) and ψ:GR(p k ,rd)→GR(p k ,r) m ′ is GR(p k A linear mapping r) satisfies ψ(φ(x1)·φ(x2)…φ(x) D ))=x1*x2*…*x D For all x1, x2, ..., x D ∈GR(p k ,r) m The lemma holds, where * denotes multiplication. Based on the RMFE property, the following lemma can be obtained.
[0070] Lemma 1 Where (φ,ψ) is a finite element defined in the Galois ring GR(p k (m,d;D)-RMFE on r), Ker(ψ) indicates the null space of ψ, and Im(φ) indicates the range of φ. Indicates a straight sum, where 1 represents a vector of all 1s, i.e., GRE(p k ,r) are Ker(ψ) and φ(1) D-1 The direct sum of Im(φ).
[0071] Lemma Two, there exists an (m', d; D)-RMFE, (φ, ψ), defined on Galois ring GR(p k , r), satisfying φ(l) = 1. Based on Lemma Two, it can be assumed that φ(l) = 1, then Lemma One can be simplified as
[0072] Lemma Three, there exists an (m', d; D)-RMFE family defined on , for all k ≥ 1, when m' → ∞, there is That is, when m' → ∞, there exists an (m', d; 2)-RMFE family defined on , and there is and there also exists an (m', d; 3)-RMFE family defined on , and there is
[0073] Exemplarily, since the mapping process of the RMFE is similar, next, take the ring before mapping as and the ring after mapping as as an example, for illustration. In the process of performing the RMFE mapping, L(G) that exists a mapping relationship with will be determined first, so as to realize the RMFE mapping by using the elements in L(G), wherein L(G) refers to the Riemann-Roch space of G, G is a selected divisor in the function field F, the degree (deg) of G is equal to r+2g-1, r refers to the number of rational points included in the function field F, and g refers to the genus of the function field. Since L(G) can be mapped to The first device can first select a subspace W from L(G), the elements in the subspace W and the elements in are in one-to-one mapping relationship, and then select an element from the subspace W, the degree of the element is l, l > 2degG, and then the first device constructs the RMFE for mapping from based on the selected element. For the specific process of obtaining the first data and the second data located in the Galois ring by using the RMFE mapping, please refer to the related literature of the RMFE, which will not be described here.
[0074] In a possible case, since the input data of the sub-function is the first data and the second data, the input data can be mapped from the modulo 2 kThe ring is mapped onto the Galois ring to obtain first data and second data located in the Galois ring, so as to realize mapping of the sub-function. Optionally, the input data of the sub-function includes the first data and the second data, and the first device and the second device can negotiate to determine that the first data and the second data located in the Galois ring are calculated based on the RMFE. For example, it is negotiated that the first device needs to calculate the second data based on the RMFE, and the second device needs to calculate the first data based on the RMFE. The negotiation can be interactive negotiation between the first device and the second device, or a constraint condition published by the first device in the process of publishing the calculation function.
[0075] However, the first device and the second device only confirm that the calculation is based on the RMFE through negotiation, but there can be dishonest persons among the first device and the second device, that is, the RMFE is not calculated according to the negotiation. Therefore, there are also some protocols to be executed by the first device to prevent the first device and the second device from dishonestly executing the RMFE. Optionally, for different scenarios, the prevention methods are also different.
[0076] Scenario one, malicious security in the sense of information theory. The malicious security in the sense of information theory is also called perfect security. The dishonest person has unlimited computing power, and the security is completely based on the basis of information theory. For scenario one, NM-RMFE can be used to constrain the calculation of the first data and the second data, that is, the RMFE negotiated between the first device and the second device includes the NM-RMFE, and the NM-RMFE is obtained by cascading two RMFEs. The two RMFEs are cascaded, that is, two RMFE mappings are performed.
[0077] Figure 6 An example diagram of the NM-RMFE provided by an embodiment of the present application, Figure 6 Z 2^k Indicate modulo 2 k Ring, indicate power, RMFE mapping is represented by GR, and GR' represents a higher-dimensional Galois ring obtained based on the GR ring. See Figure 6 Elements located in the modulo 2 k Ring are mapped to elements located in the Galois ring through one RMFE mapping, and then a second RMFE mapping is performed. Taking the calculation of the second data by the first device based on the NM-RMFE as an example, in combination with Figure 6 The calculation process of the second data is illustrated. The first device obtains third data to be returned to the second device, for example, the resume information in the above embodiment. The first device performs the first RMFE mapping on the third data, and maps the third data from the modulo 2 kThe ring is mapped to GR to obtain intermediate data, and the first device performs a second RMFE mapping on the intermediate data to map the intermediate data from GR to GR' to obtain second data. The process of calculating the first data by the second device based on the NM-RMFE is similar to the process of calculating the second data based on the NM-RMFE, and will not be repeated here.
[0078] In the case of negotiating between the first device and the second device to calculate the first data and the second data through the NM-RMFE, if a malicious adversary does not calculate the corresponding input data according to the NM-RMFE, the calculation result obtained based on the input data is random and has nothing to do with the input data, and the malicious adversary cannot infer the input data of the honest user through the calculation result. Wherein, the honest user refers to the device that honestly performs the NM-RMFE, and the malicious adversary refers to the device that does not honestly perform the NM-RMFE. If the honest user is the first device and the malicious adversary is the second device, the second data of the first device is calculated based on the NM-RMFE, and the second device does not calculate the first data according to the definition of the NM-RMFE. In this case, the calculation result calculated based on the first data and the second data is random, and the second device cannot infer the second data input by the first device according to the calculation result, which ensures the data security of the second data and effectively prevents the threat caused by the cheating mode of the first device or the second device not calculating the corresponding input data according to the definition of the RMFE.
[0079] Scenario two, malicious security in the sense of calculation. The security in the sense of calculation relies on the calculation strength and the complexity of the algorithm to resist attacks, and the calculation ability of the dishonest person in the sense of calculation is limited. For scenario two, the following two methods can be used to prevent the first device and the second device from not performing RMFE, respectively, including but not limited to the following two methods.
[0080] Method one, obtaining the first data of the second device; cutting the first data to obtain a plurality of sub-data; selecting a sub-data from the plurality of sub-data, and verifying whether the second device calculates the first data by using the RMFE according to the selected sub-data.
[0081] Optionally, method one is used for the second device to prevent the first device from not honestly performing the RMFE, and the first device can use the cut-and-choose technology to verify the first data. The first data is cut into a plurality of sub-data, and the cutting can be random cutting or cutting based on a fixed length window. In this case, the lengths of the plurality of sub-data obtained by cutting are the same. Regardless of the plurality of sub-data obtained by cutting, the second device can select a to-be-verified sub-data from the plurality of sub-data, and the selection can be random selection.
[0082] In some cases, the second device processes the first data in the process of publishing the first data to avoid leakage of the first data in the transmission process. For example, the first data is published by VOLE. The description of publishing the first data based on VOLE is similar to the description of transmitting the ciphertext information based on VOLE in S303 below, and please refer to the related description, which will not be repeated here.
[0083] Since the second device uses a linear homomorphic commitment scheme to commit the input of VOLE, that is, the first data, and the first data is processed, the plurality of sub-data obtained by cutting the first data is also processed sub-data. Therefore, even if the first device randomly obtains the sub-data, the first data of the second device will not be leaked, ensuring the data security of the first data. In some cases, if the second device honestly performs RMFE calculation to obtain the first data, the calculated first data is located in the RMFE image set, wherein the RMFE image set refers to the ring after RMFE mapping, that is, the Galois ring in the above embodiment. For this case, the first device can judge whether the sub-data is located in the RMFE image set. In the case where the sub-data is located in the RMFE image set, it is determined that the second device uses RMFE to calculate the first data, or in the case where the sub-data is not located in the RMFE image set, it is determined that the second device does not use RMFE to calculate the first data.
[0084] If the second device uses RMFE to calculate the first data, the second device belongs to the honest party, and there is no malicious cheating behavior. The first device determines that the first data is usable data, and calculates the second data by using the first data. If the second device does not use RMFE to calculate the first data, the second device belongs to a malicious cheater who does not honestly perform the agreement. The second device may try to obtain the local second data by using the first data. Therefore, the first device determines that the first data is unusable data, and restricts the calculation of the second data by using the first data. The restriction method is, for example, to restrict the input of the first data to the sub-function.
[0085] In a possible implementation, the first device also uses a random oracle model to avoid the increase of the number of communication rounds in the process of verifying the first data by using method one. The random oracle model is used to return a uniform random output for the input, that is, the random oracle model is a function that randomly maps all possible inputs and outputs. The first device takes the first data as the input of the random oracle model, and sends the output of the random oracle model to the second device to ensure that the first device normally returns the ciphertext information to the second device in the message sending stage, thereby avoiding the increase of the number of communication rounds caused by the second device sending data to the second device due to not receiving the ciphertext information in the message sending stage.
[0086] The second method is to input the second data into the mapped sub-function by using the re-embedding technology, and calculate the first data and the input second data based on the re-embedding calculation by using the mapped sub-function. The re-embedding technology is used to convert the second data into an element in the RMFE image set in the case that the second data is not an element in the RMFE image set.
[0087] The second method is used to prevent the first device from dishonestly performing the RMFE calculation to obtain the second data, that is, the first device is a malicious cheater. In this case, even if the first device does not perform the RMFE technology, the calculated second data is not an element in the RMFE image set, and the second data can be automatically converted into an element in the RMFE image set by the re-embedding technology. The converted second data conforms to the calculation result of the RMFE. In addition, similar to the case of the first method, in the process of preventing cheating behavior by using the second method, a random oracle model is also used to avoid the increase of the communication round. In some cases, in addition to receiving the ciphertext information of the second data returned by the first device, the second device will also inform the first device to select which second data to generate the ciphertext information, so as to avoid the cheating of the first device. In this case, the first device can select the second data to be returned to the second device by using the random oracle model. Since the process of selecting the second data by using the random oracle model is random, the first device cannot predict the selected second data. Even if the second device does not inform the first device of the selected second data, the first device cannot cheat.
[0088] Regardless of the method used by the first device to prevent the first device or the second device from dishonestly performing the RMFE, the calculation result of the input first data and second data can be obtained by using the mapped sub-function after the prevention is completed. Continue to take the sub-function shown in the right graph of FIG. 1 as an example. Figure 5 After the first device inputs the first data X1, X2 and the second data Y1, Y2 into the sub-function, the first device adjusts other elements in the sub-function based on the input data in the sub-function, for example, adding -1 shown in FIG. 1 to the sub-function. Figure 5 The numbers in X1, X2, Y1 and Y2 in the sub-function are used to distinguish the first data and the second data input by different sub-functions. The first data and the second data input by multiple sub-functions are different. For example, in order to decompose the calculation function to obtain m sub-functions, the first data includes n Xs, and the second data includes n Ys, where n = 2m. The first sub-function can input X1, X2, Y1 and Y2 as shown in FIG. 1, the second sub-function inputs X3, X4, Y3 and Y4, and the mth sub-function inputs Xn-1, Xn, Yn-1 and Yn. Figure 5 Figure 5
[0089] Optionally, after the first device calculates the calculation result of any sub-function, the first device further performs confusion on the calculation result, converts the calculation result belonging to plaintext information into ciphertext information through the confusion, thereby hiding the content of the calculation result and improving the information security of the calculation result. For example, the first device confuses the calculation result by using a first element, and obtains ciphertext information, wherein the first element is an element in the RMFE image set. For the sub-function belonging to the arithmetic branching program, the confusion technique for confusing the calculation result of the sub-function can be DARE.
[0090] Taking the arithmetic branching program L(x) as an example, L(x) is an sxs matrix on , f(x) = det(L(x)), det(L(x)) represents the determinant of L(x), and the process of confusing the calculation result by using DARE can be represented as R1L(x)R2, wherein R1 is a matrix randomly and uniformly sampled from , and R2 represents a matrix randomly and uniformly sampled from . All sxs matrices on are composed of sxs matrices, the main diagonal of the sxs matrix is 1, and the positions below the main diagonal are all 0. All sxs matrices on are composed of sxs matrices, the main diagonal of the sxs matrix is 1, and the positions except the rightmost column are all 0. Optionally, the set used in the DARE confusion process can further include other sets in addition to the sets and in the above embodiments, for example, , wherein All sxs matrices on are composed of sxs matrices, the secondary diagonal of the sxs matrix is -1, and the positions below the secondary diagonal are all 0. The process of confusing the calculation result by using the first element based on DARE can be referred to formula 1.
[0091]
[0092] In formula 1, Ai, Bi and Ci are random elements in the RMFE image set, that is, the first element, and i is used to identify different elements, which is any positive integer. The execution order of calculating the calculation result based on the sub-function and confusing the calculation result is not limited in the embodiments of the application, which can be serially executed, that is, the calculation result is calculated first, and then the calculation result is confused by using Ai, Bi and Ci. The first device can also execute the sub-function calculation and the confusion of the calculation result in parallel, for example, using formula 1, inputting first data X1, X2 and second data Y1, Y2 into formula 1, and directly outputting the confused calculation result, that is, the ciphertext information M, by using formula 1.
[0093] S303, sending the ciphertext information to the second device.
[0094] In the case that the first device calculates a plurality of calculation results by using a plurality of sub-functions, one calculation result corresponds to one ciphertext information, that is, the first device will send a plurality of ciphertext information to the second device. Since the sending process of the plurality of ciphertext information is similar, next, take any ciphertext information as an example to illustrate. In one possible case, the first device sends the ciphertext information to the second device by using VOLE. Wherein, VOLE is a two-participant cryptographic primitive that allows a sender and a receiver to obtain random, associated values. Wherein, the sender obtains two random vectors a and b, and the receiver obtains a scalar to be transmitted, and the vectors and the scalar obtained by the sender and the receiver can be used to calculate v = a · scalar + b. Next, the process of obtaining corresponding vectors and scalars by the VOLE module to the first device as the sender and the second device as the receiver will be introduced.
[0095] Optionally, in the initialization phase, after the VOLE module receives (security identifier (sid); initialize) sent by the sender and the receiver, α is randomly selected from the R ring, that is, (sid, α) is stored, and the selected α is sent to the receiver. Subsequently, the messages sent by the sender and the receiver with the identifier sid will be ignored. After that, in the sending phase, if (sid; send; li) sent by the receiver and the sender is received, it is checked according to the received sid whether (sid, α) is stored. If not stored, the message is ignored. If already stored, vectors a and b are randomly selected from the R ring, that is, (sid; a, b; li) is stored, and (a, b) is sent to the sender. Subsequently, the messages with the identifier sid received from the sender and the receiver will be ignored. i
[0096] Afterwards, the receiver and sender can jointly calculate v = a·scalar + b. Taking additive homomorphic encryption as an example, the receiver first calculates the public-private key pair (pk, sk) used for aHEnc / aHDec. aHEnc refers to the encryption process in the additive homomorphic encryption algorithm, aHDec refers to the decryption process, pk is the public key, and sk is the private key. Then, the receiver uses the private key to encrypt the scalar, obtaining aHEnc (scalar), and sends aHEnc (scalar) and the public key pk to the sender. The sender uses aHEnc (scalar) to calculate aHEnc(v) = aHEnc(a·scalar + b), for example, aHDec(v) = aHEnc (scalar). a ×aHEnc(b), where aHEnc(b) is obtained by encrypting vector b using a public key. The sender sends the calculated aHDec(v) to the receiver, who decrypts aHDec(v) to obtain the result v of the calculation of a·scalar + b.
[0097] Based on the above examples, it can be seen that VOLE enables collaborative computation between the sender and receiver without revealing each other's input data. This application embodiment can also utilize VOLE to transmit encrypted information. Using VOLE to transmit encrypted information means that the first device, acting as the sender, employs VOLE technology to calculate encrypted encrypted information using the first and second data without decrypting the first data, and then sends the encrypted encrypted information to the second device, acting as the receiver. In the process of VOLE being applied to the computation of encrypted information, v in the above embodiments corresponds to the encrypted information M. Referring to M shown in Formula 1, after expanding M, it can also be expressed as a·scalar + b, meaning that each position in matrix M can be considered as a linear function of the first data from the second device. Here, the scalar corresponds to the input data of the second device, and the scalar can be determined based on the first data and the allocated α, etc. a and b correspond to the input data of the first device, and a and b can be determined based on the second data, Ai, Bi, and Ci, etc.
[0098] In one possible scenario, similar to the RMFE case, the first device's calculation based on the DARE obfuscation result is also an agreement negotiated between the first and second devices. However, the first device may engage in cheating by not honestly performing the DARE calculation. Such cheating can be constrained by VOLE technology. For example, VOLE includes cVOLE, which is also used by the second device to verify whether the first device has obtained the ciphertext information based on the DARE obfuscation calculation result.
[0099] Optionally, the cVOLE can be constructed by an equal VOLE (eVOLE) and a line-point zero-knowledge (LPZK), for example, the eVOLE is used to transfer the input of the first device to a plurality of VOLE instances to another VOLE instance, and the LPZK can be used on the VOLE instance to prove that the input of the first device satisfies the corresponding constraint condition in the plurality of VOLE instances. The input of the first device is ciphertext information obtained by the first device through confusion, and the constraint condition to be satisfied refers to the condition possessed by the ciphertext information obtained by confusion through the DARE technology. The constraint condition is determined by the DARE and can be expressed in the form of a circuit.
[0100] Referring to Figure 7 , taking the first data X1, X2, …, Xn of the second device as an example, in the process of transmitting the ciphertext information using the cVOLE, n+2 VOLE instances are used, the second device randomly selects α and β, and the input of the second device in the first n VOLE instances is X1+α, X2+α, …, Xn+α, respectively; the input of the second device in the n+1th and n+2th VOLE instances is α and β, respectively. Since the VOLE is linear, the first device can calculate the result from the first n+1 instances, and the n+2th VOLE instance is used for proof. The eVOLE technology is used to ensure that the input of the first device in the first n VOLE instances and the n+2th VOLE instance, the n+1th VOLE instance and the n+2th VOLE instance is consistent, that is, the input of the first device in the first n VOLE instances and the n+1th VOLE instance is consistent, Figure 7 , a1, b1, b2 and b3 in the formula are vectors, V1, V2 and V3 are ciphertext information calculated based on the first data and the second data, and the calculation process of V1, V2 and V3 is similar to the calculation process of M in the above embodiment. Please refer to the related description, which will not be repeated here.
[0101] In a possible case, after receiving the ciphertext information, the second device will calculate the function result using the ciphertext information in addition to verifying whether the ciphertext information is obtained by confusion through the DARE. Taking Figure 1 as an example, Figure 1 , the encryption of x in the formula is the first data, and the first device determines f(x, y i ) using Msg i and x after obtaining the ciphertext information Msg i . i) is a function calculated by the first device and the second device together, which can be any computer program that exists in the cooperative calculation demand. The function can be a function determined by the first device and the second device to be executed together, or a function determined by the second device to be executed together. Continuing with the job application scenario in the above example, the function result output by the function calculated together is the matching score of the resume information of the job applicant and the recruitment conditions.
[0102] Optionally, after the second device calculates the function result by using the function, it can make a corresponding response according to the application scenario. Continuing with the example of the output result as the matching score, the response made by the second device can be that in the case that the matching score is greater than the second threshold, it is determined that the job applicant meets the recruitment conditions, and an admission notice is returned to the first device. Similar to the case that the second device can make a corresponding response, the sender using the first device can also pay attention to the behavior of the receiver after receiving the message, for example, detecting whether the mailbox receives the admission notice.
[0103] In addition, the above example is intended to illustrate the data processing process of the first device as the sender in the non-interactive two-party secure calculation, and is not intended to limit the number of first devices. Since the second device does not specify the sender to make a response to the first data in the process of publishing the first data, for example Figure 1 the second device directly discloses the first data, and the disclosed first data can be obtained by any first device, that is, the first device used to execute the data processing method of the present application can be one or multiple, and the first data published by the second device can be reused by multiple second devices, so that the utilization rate of the first data is high. The non-interactive two-party secure calculation that the above first data can be reused can be called reusable non-interactive secure calculation (rNISC).
[0104] Moreover, the present application takes the recruitment scenario as an example for illustration, but in fact, the data processing method can be applied to other application scenarios of joint calculation of first devices and second devices, such as fund joint income calculation, supply chain query, machine learning and other operations that need to be modified.
[0105] In summary, the data processing method provided by the present application can use the calculation protocol defined on the Galois ring to process the first data and the second data, so that the calculation protocol overhead is low. By mapping the sub-function from the Galois ring to the Galois ring, the problems existing in the Galois ring are solved, such as k the Galois ring, the problems existing in the Galois ring are solved, such as k the Galois ring, the problems existing in the Galois ring are solved, such as k the Galois ring, the problems existing in the Galois ring are solved, such as k the Galois ring, the problems existing in the Galois ring are solved, such as kGalois rings cannot be used with Lagrange interpolation and have many zero factors that cannot guarantee reliability. Mapping computationally parallelizable sub-functions to the same Galois ring and then computing these mapped sub-functions in parallel effectively improves the computational efficiency of data processing. An NM-RMFE technique is proposed to prevent malicious behavior that does not follow NM-RMFE computation without increasing the number of communication rounds. cVOLE is extended to Galois rings and combined with NM-RMFE technique as a modulo-2... k The information-theoretic secure rNISC protocol on rings exhibits the same asymptotic traffic as schemes over finite fields, controlling traffic while enhancing security. In a computational sense, it employs cut-and-choose and re-embedding techniques, combined with cVOLE, as a modular 2^2 protocol for computation. k The rNISC scheme on the ring offers better communication performance.
[0106] The data processing method of the present application embodiments has been described above. Corresponding to the above method, the present application embodiments also provide a data processing device. Figure 8 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Based on Figure 8 The following modules are shown. Figure 8 The data processing device shown is capable of performing the above. Figure 3 All or part of the operations shown. It should be understood that the device may include more additional modules than those shown, or may omit some of the modules shown; this application embodiment does not impose limitations in this regard. For example... Figure 8 As shown, the device includes:
[0107] Transceiver module 801 is used to perform... Figure 3 The receiving and / or sending related operations in the illustrated embodiments;
[0108] Processing module 802 is used to execute Figure 3 Other operations besides the receiving and / or sending related operations in the illustrated embodiments.
[0109] In one possible implementation, processing module 802 is used to obtain multiple sub-functions, which are decomposed into modulo 2. k The ring calculation function is obtained, and the calculation function is used to calculate the second data of the first device based on the first data published by the second device, where k is a positive integer and is used to indicate the number of bits of the first data and the second data; the processing module 802 is also used to convert multiple sub-functions modulo 2 kThe ring is mapped onto a Galois ring, the first data and the second data are calculated by using the mapped sub-functions, the ciphertext information corresponding to the second data is obtained based on the calculation result, and the at least two mapped sub-functions are located on the same Galois ring and the first data and the second data are calculated in parallel; and the transceiver module 801 is configured to send the ciphertext information to the second device.
[0110] In a possible implementation, the first device and the second device negotiate to determine that the first data and the second data located on the Galois ring are calculated based on the RMFE.
[0111] In a possible implementation, the RMFE includes an NM-RMFE, and the NM-RMFE is obtained by cascading two RMFEs.
[0112] In a possible implementation, the processing module 802 is further configured to obtain the first data of the second device; cut the first data to obtain a plurality of sub-data; select a sub-data from the plurality of sub-data, and verify whether the second device calculates the first data by using the RMFE based on the selected sub-data.
[0113] In a possible implementation, the processing module 802 is configured to input the second data into the mapped sub-function by using a re-embedding technology, and calculate the first data and the second data input based on the re-embedding technology by using the mapped sub-function, where the re-embedding technology is used to convert the second data into an element in the RMFE image set in a case where the second data is not an element in the RMFE image set.
[0114] In a possible implementation, the processing module 802 is configured to obtain a calculation function, decompose the calculation function into a plurality of unit functions by adding a virtual gate in the calculation function, and convert any unit function into a sub-function belonging to an arithmetic BP.
[0115] In a possible implementation, the processing module 802 is configured to obtain the ciphertext information by using the first element to confuse the calculation result, where the first element is an element in the RMFE image set.
[0116] In a possible implementation, the transceiver module 802 is configured to send the ciphertext information to the second device by using a VOLE.
[0117] In a possible implementation, the VOLE includes a cVOLE, and the cVOLE is further configured to enable the second device to verify whether the first device obtains the ciphertext information based on the DARE to confuse the calculation result.
[0118] Since the calculation function is located in a ring of modulo 2 k In the process of processing the first data and the second data by using the calculation function, a ring of modulo 2 kThe computation protocol on the ring has low computational overhead. This is achieved by modifying subfunctions from modulo 2. k Mapping a ring to its ring extension (Galois ring) solves the modulo 2 problem. k Problems with rings, such as modulo 2 k Galois rings suffer from limitations in using Lagrange interpolation and contain numerous zero factors whose reliability cannot be guaranteed. Mapping computationally parallelizable sub-functions to the same Galois ring and then computing these mapped sub-functions in parallel effectively improves the computational efficiency of data processing.
[0119] It should be understood that the above Figure 8 The provided device, in implementing its functions, is only illustrated by the division of the aforementioned functional modules. In practical applications, the functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. Furthermore, the device and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process is detailed in the method embodiments, which will not be repeated here. Figure 8 The provided data processing device can be a chip or a communication device; for example, the data processing device can be a network device as described below.
[0120] See Figure 9 , Figure 9 A schematic diagram of the structure of a network device 1400 provided in an exemplary embodiment of this application is shown. Figure 9 The network device 1400 shown is used to perform the above. Figure 3 The data processing method shown involves the operations described. The network device 1400 is, for example, a switch, a router, etc., and can be implemented using a general bus architecture.
[0121] like Figure 9 As shown, the network device 1400 includes at least one processor 1401, a memory 1403, and at least one communication interface 1404.
[0122] The processor 1401 is, for example, a central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing units (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits used to implement a design described in the present application. For example, the processor 1401 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic device, transistor logic, a hardware component, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute various logical blocks, modules, and circuits described in combination with the disclosure of the embodiments of the present application. The processor can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.
[0123] Optionally, the network device 1400 also includes a bus. The bus is used to transmit information between the components of the network device 1400. The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 9 In the figure, only one thick line is used to represent the bus, but it does not mean that there is only one bus or only one type of bus.
[0124] The memory 1403 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions; a random access memory (RAM), or other type of dynamic storage device that can store information and instructions; a flash memory or other optical disk storage, including a compact disc read-only memory (CD-ROM), a compact disc-rewritable (CD-RW), and the like, a magneto-optical disk, a floppy disk, a hard disk, or other magnetic storage device, or any other medium capable of storing instructions or data that is accessible to the computer, but is not limited thereto. The memory 1403 is, for example, independent and connected to the processor 1401 through the bus. The memory 1403 can also be integrated with the processor 1401.
[0125] The communication interface 1404 uses any transceiver-like mechanism for communicating with other devices or a communication network, which can be an Ethernet, a radio access network (RAN), a wireless local area networks (WLAN), or the like. The communication interface 1404 can include a wired communication interface and a wireless communication interface. Specifically, the communication interface 1404 can be an Ethernet interface, a fast Ethernet (FE) interface, a gigabit Ethernet (GE) interface, an asynchronous transfer mode (ATM) interface, a wireless local area networks (WLAN) interface, a cellular network communication interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In the embodiments of the present application, the communication interface 1404 can be used for the network device 1400 to communicate with other devices.
[0126] In a specific implementation, as an embodiment, the processor 1401 can include one or more CPUs, such as the CPU0 and the CPU1 shown in FIG. 1. Figure 9 Each of these processors can be a single-CPU processor or a multi-CPU processor. The processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0127] In particular implementations, as one example, network device 1400 can include multiple processors, such as processor 1401 and processor 1405, as shown in FIG. 14B. Each of these processors can be a single-CPU or a multi-CPU. A processor here can refer to one or more devices, circuits, and / or processing cores for processing data, such as computer program instructions. Figure 9 In particular implementations, as one example, network device 1400 can include multiple processors, such as processor 1401 and processor 1405, as shown in FIG. 14B. Each of these processors can be a single-CPU or a multi-CPU. A processor here can refer to one or more devices, circuits, and / or processing cores for processing data, such as computer program instructions.
[0128] In particular implementations, as one example, network device 1400 can include multiple processors, such as processor 1401 and processor 1405, as shown in FIG. 14B. Each of these processors can be a single-CPU or a multi-CPU. A processor here can refer to one or more devices, circuits, and / or processing cores for processing data, such as computer program instructions.
[0129] In some embodiments, memory 1403 is used to store program codes 1410 for execution by processor 1401. That is, network device 1400 can implement the data processing method provided by the method embodiments through processor 1401 and program codes 1410 in memory 1403. Program codes 1410 can include one or more software modules. Alternatively, processor 1401 itself can also store program codes or instructions for implementing the schemes of the present application.
[0130] In particular embodiments, network device 1400 of the embodiments of the present application can correspond to the first device or the second device in the above-mentioned various method embodiments.
[0131] wherein, Figure 3The steps of the data processing method shown are completed by integrated logic circuits of hardware or instructions in the form of software in the processor of the network device 1400. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as execution by a hardware processor, or executed by a combination of hardware and software modules in the processor. The software modules can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, or other mature storage media in the art. The storage medium is located in the memory, and the processor reads information in the memory and combines the hardware to complete the steps of the above method. To avoid repetition, they will not be described in detail here.
[0132] Referring to Figure 10 , Figure 10 shows a structural schematic diagram of a network device 1500 provided by another exemplary embodiment of the present application, Figure 10 The network device 1500 shown is used to execute all or part of the operations involved in the above Figure 3 The data processing method. The network device 1500 is, for example, a switch, a router, etc., and can be implemented by a general bus architecture.
[0133] As Figure 10 shown, the network device 1500 includes a main control board 1510 and an interface board 1530.
[0134] The main control board is also called a main processing unit (MPU) or a route processor card. The main control board 1510 is used for control and management of various components in the network device 1500, including route calculation, device management, device maintenance, and protocol processing functions. The main control board 1510 includes a central processor 1511 and a memory 1512.
[0135] The interface board 1530 is also called a line processing unit (LPU), a line card, or a service board. The interface board 1530 is used to provide various service interfaces and implement data packet forwarding. The service interfaces include, but are not limited to, Ethernet interfaces, POS (Packet over SONET / SDH) interfaces, etc. The Ethernet interface is, for example, a flexible Ethernet service interface (FlexE Clients). The interface board 1530 includes a central processor 1531, a network processor 1532, a forwarding table item memory 1534, and a physical interface card (PIC) 1533.
[0136] The central processor 1531 on the interface board 1530 is configured to control and manage the interface board 1530 and communicate with the central processor 1511 on the master board 1510.
[0137] The network processor 1532 is configured to implement the forwarding processing of the packet. The network processor 1532 can be a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented by an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 1532 is configured to forward the received packet based on a forwarding table stored in the forwarding table entry memory 1534. If the destination address of the packet is the address of the network device 1500, the packet is sent to the CPU (for example, the central processor 1531) for processing. If the destination address of the packet is not the address of the network device 1500, the next hop and the out interface corresponding to the destination address are found from the forwarding table according to the destination address, and the packet is forwarded to the out interface corresponding to the destination address. The processing of the uplink packet can include processing of the packet entry interface and forwarding table lookup. The processing of the downlink packet can include forwarding table lookup, and the like. In some embodiments, the central processor can also perform the function of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, so that the interface board does not need the forwarding chip.
[0138] The physical interface card 1533 is configured to implement the interfacing function of the physical layer. The original traffic enters the interface board 1530 through the physical interface card 1533, and the processed packet is sent out from the physical interface card 1533. The physical interface card 1533, also referred to as a daughter card, can be installed on the interface board 1530 and is responsible for converting the optical and electrical signals into packets and forwarding the packets to the network processor 1532 for processing after performing the legality check. In some embodiments, the central processor 1531 can also perform the function of the network processor 1532, such as implementing software forwarding based on a general-purpose CPU, so that the physical interface card 1533 does not need the network processor 1532.
[0139] Optionally, the network device 1500 includes a plurality of interface boards. For example, the network device 1500 further includes an interface board 1540. The interface board 1540 includes a central processor 1541, a network processor 1542, a forwarding table entry memory 1544, and a physical interface card 1543. The functions and implementation manners of the components in the interface board 1540 are the same as or similar to those of the interface board 1530, and are not described herein again.
[0140] Optionally, the network device 1500 also includes a switch fabric 1520. The switch fabric 1520 can also be referred to as a switch fabric unit (SFU). In the case of the network device 1500 having multiple interface boards, the switch fabric 1520 is used to complete data exchange between the interface boards. For example, the interface board 1530 and the interface board 1540 can communicate through the switch fabric 1520.
[0141] The master board 1510 is coupled with the interface boards. For example, the master board 1510, the interface board 1530, and the interface board 1540, and the switch fabric 1520 are connected through a system bus and a system backplane to communicate with each other. In a possible implementation, an inter-process communication (IPC) channel is established between the master board 1510 and the interface board 1530 and the interface board 1540, and the master board 1510 and the interface board 1530 and the interface board 1540 communicate through the IPC channel.
[0142] In logic, the network device 1500 includes a control plane and a forwarding plane. The control plane includes the master board 1510 and the central processor 1511, and the forwarding plane includes various components that perform forwarding, such as the forwarding table entry memory 1534, the physical interface card 1533, and the network processor 1532. The control plane performs functions such as generating a forwarding table, processing signaling and protocol packets, configuring and maintaining the state of the network device, and the like. The control plane generates a forwarding table and delivers the forwarding table to the forwarding plane. In the forwarding plane, the network processor 1532 performs table lookup and forwarding on a packet received by the physical interface card 1533 based on the forwarding table delivered by the control plane. The forwarding table delivered by the control plane can be stored in the forwarding table entry memory 1534. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same network device.
[0143] It is worth mentioning that the master board can be one or more, and when there are multiple master boards, the master boards can include a main master board and a backup master board. The interface board can be one or more, and the stronger the data processing capability of the network device, the more interface boards are provided. The physical interface card on the interface board can also be one or more. The switching network board can be none or one or more, and when there are multiple switching network boards, the switching network boards can jointly implement load sharing and redundancy. In the centralized forwarding architecture, the network device can not need the switching network board, and the interface board can undertake the processing function of the entire system. In the distributed forwarding architecture, the network device can have at least one switching network board, and the switching network board can be used to realize data exchange between multiple interface boards and provide large-capacity data exchange and processing capability. Therefore, the data access and processing capability of the network device in the distributed architecture is greater than that of the network device in the centralized architecture. Alternatively, the network device can also be in the form of only one board, that is, the functions of the interface board and the master board are integrated on the one board, and at this time, the central processor on the interface board and the central processor on the master board can be combined into one central processor on the one board to perform the functions of the two superimposed boards. The data exchange and processing capability of the network device in this form is relatively low (for example, low-end switches or routers, etc.). Which architecture is used depends on the specific network deployment scenario, and no limitation is made herein.
[0144] In specific embodiments, the network device 1500 corresponds to the data processing apparatus shown in FIG. 1. Figure 8 In some embodiments, the processing module 802 in the data processing apparatus shown in FIG. 2 corresponds to the central processor 1511 or the network processor 1532 in the network device 1500. Figure 8
[0145] The embodiments of the present application also provide a communication apparatus, which comprises a transceiver, a memory and a processor. The transceiver, the memory and the processor communicate with each other through internal connection paths. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals. When the processor executes the instructions stored in the memory, the processor executes the data processing method shown in FIG. 3. Figure 3
[0146] It should be understood that the above processor can be a CPU, and can also be other general-purpose processors, DSPs, ASICs, FPGAs or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc. It is worth mentioning that the processor can be a processor supporting an advanced RISC machine (ARM) architecture.
[0147] Further, in an alternative embodiment, the aforementioned memory can include read-only memory and random access memory, and provide the processor with instructions and data. The memory can also include non-volatile random access memory. For example, the memory can also store device type information.
[0148] The memory can be volatile memory or nonvolatile memory, or can include both volatile and nonvolatile memory. By way of illustration, and not limitation, nonvolatile memory can be ROM, programmable ROM (PROM), erasable PROM (EPROM), EEPROM, or flash memory. Volatile memory can be RAM, which acts as external cache memory. By way of illustration and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), double-data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0149] The embodiments of the present application further provide a data processing device, the device comprising a processor, the processor being configured to load and execute at least one instruction to enable the data processing device to implement the data processing method as shown in Figure 3 Optionally, the device further comprises a memory, the memory being coupled to the processor, and the memory being configured to store the at least one instruction.
[0150] The embodiments of the present application further provide a data processing system, the system comprising a first device and a second device, the second device being configured to publish first data, and the first device being configured to implement the data processing method as shown in Figure 3 .
[0151] The embodiments of the present application further provide a computer readable storage medium, the storage medium storing at least one instruction, the instruction being loaded and executed by a processor to enable a computer to implement the data processing method as shown in Figure 3 .
[0152] The embodiment of the present application further provides a computer program (product), which, when executed by a computer, can enable a processor or the computer to perform the corresponding steps and / or processes in the above method embodiments.
[0153] The embodiment of the present application further provides a chip, which comprises a processor, and is used for calling and running instructions stored in a memory, so that a communication device installed with the chip performs the data processing method as shown in the above method embodiments. Figure 3
[0154] The embodiment of the present application further provides another chip, which comprises an input interface, an output interface, a processor and a memory, and the input interface, the output interface, the processor and the memory are connected through internal connection paths; the processor is used for executing code in the memory, and when the code is executed, the processor is used for performing the data processing method as shown in the above method embodiments. Figure 3
[0155] In the above embodiments, all or part of the embodiments can be realized by software, hardware, firmware or any combination thereof. When realized by software, all or part of the embodiments can be realized in the form of a computer program product. The computer program product comprises one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk), etc.
[0156] It should be noted that the information (including but not limited to user equipment information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions. For example, the first data and the like involved in the present application are acquired under full authorization.
[0157] Those skilled in the art can appreciate that, in combination with the method steps and modules described in the embodiments disclosed in the present application, all or part of the steps can be realized by software, hardware, firmware or any combination thereof. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of the embodiments have been described in the above description in general terms. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0158] Those skilled in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by program to instruct related hardware, and the program can be stored in a computer readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.
[0159] When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the method of the embodiments of the present application can be described in the context of machine executable instructions, such as program modules executed by devices included in the target real or virtual processor. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., which perform specific tasks or implement specific abstract data structures. In various embodiments, the functions of the program modules can be combined or divided among the described program modules. Machine executable instructions for program modules can be executed within local or distributed devices. In distributed devices, program modules can be located in both local and remote storage media.
[0160] The computer program code implementing the method of embodiments of the present application can be written in one or more programming languages. These computer program codes can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, when executed by the computer or other programmable data processing apparatus, produce the functions / operations specified in the flow diagrams and / or block diagrams. The computer program code can be executed completely on a computer, partially on a computer, as a stand-alone software package, partially on a computer and partially on a remote computer or completely on a remote computer or server.
[0161] In the context of the embodiments of the present application, the computer program code or related data can be carried by any suitable carrier, to enable the device, apparatus or processor to perform the various processes and operations described above. Examples of carriers include signals, computer readable media, and the like.
[0162] Examples of signals can include, but are not limited to, electronic, electromagnetic, optical, sound, or other forms of propagated signals, such as carrier waves, infrared signals, and the like.
[0163] A machine-readable medium can be any tangible medium that includes or stores the program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable storage medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), and the like.
[0164] It can be clearly understood by a person skilled in the art that, for the convenience and brevity of description, the specific working processes of the above-described system, device and module can refer to the corresponding processes in the foregoing method embodiments, which will not be described herein.
[0165] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are merely illustrative, for example, the division of the module is only a logical function division, and actual implementation can have another division manner, for example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be indirect coupling or communication connection through some interfaces, devices or modules, and can also be electrical, mechanical or other form of connection.
[0166] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, i.e., may be located in one place, or may be distributed to multiple network modules. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0167] In addition, the functional modules in each embodiment of the present application can be integrated in one processing module, or each module can exist physically alone, or two or more modules can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software functional module.
[0168] The integrated module, if realized in the form of a software functional module and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the technical solutions, or all or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0169] In the present application, the terms "first", "second", and the like are used to distinguish between items or similar items with substantially the same function and should be understood that there is no logical or chronological dependency between "first", "second", and "n", and the quantity and execution order are not limited. It should also be understood that although the following description uses the terms first, second, and the like to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various described examples, a first image can be referred to as a second image, and similarly, a second image can be referred to as a first image. The first image and the second image can both be images, and in some cases, can be separate and distinct images.
[0170] It should also be understood that in various embodiments of the present application, the size of the serial number of each process does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0171] The term "at least one", as used herein, means one or more, the term "multiple", as used herein, means two or more, for example, a plurality of second packets means two or more second packets. The terms "system" and "network" are often used interchangeably herein.
[0172] It should be understood that the terms used in the description of various described examples herein are merely for describing specific examples and are not intended to be limiting. As used in the description of various described examples and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0173] It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The term "and / or", is a description of associating relationship between associated objects, means that there can be three kinds of relationships, for example, A and / or B, can represent: A exists alone, A and B exist together, B exists alone. In addition, the character " / " in the present application generally represents that the front and rear associated objects are a kind of "or" relationship.
[0174] It should also be understood that the term "comprise", also known as "includes", "including", "comprises" and / or "comprising", when used in the present specification specifies the presence of stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0175] It should also be understood that the terms "if" and "when" can be interpreted to mean "when" or "upon" or "in response to a determination" or "in response to detecting". Similarly, the phrase "if determined" or "if detected [a stated condition or event]" can be interpreted to mean "upon determining" or "in response to determining" or "upon detecting [a stated condition or event]" or "in response to detecting [a stated condition or event]", depending on the context.
[0176] It should be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0177] It is also to be understood that the use of "an" or "the" article is not intended to supersede the use of "comprising" or "including" wherein specifically recited steps can or can not be required. Likewise, the use of "a" or "an" is expressly limited to "one or more" unless explicitly stated otherwise. Furthermore, the use of the term "including" as well as "comprising" is not limiting and is specifically intended to be read as "including but not limited to" or "comprising but not limited to," respectively.
Claims
1. A data processing method, characterized by, The method is applied to a first device, and the method comprises: obtaining a plurality of sub-functions, the plurality of sub-functions being obtained by decomposing a calculation function located in a modulo 2 k ring, the calculation function being used to calculate second data of the first device based on first data published by a second device, the k being a positive integer and being used to indicate bit numbers of the first data and the second data; mapping the plurality of sub-functions from the ring Z2 k onto Galois rings, calculating the first data and the second data by using the mapped sub-functions, obtaining the ciphertext information corresponding to the second data based on the calculation result, and at least two mapped sub-functions are located on the same Galois ring and the first data and the second data are calculated in parallel. sending the ciphertext information to the second device.
2. The method of claim 1, wherein, The first data and the second data are located on the Galois ring and are calculated based on a reverse multiplication friendly embedding RMFE, and the RMFE is negotiated between the first device and the second device.
3. The method of claim 2, wherein, The RMFE comprises a non-malleable reverse multiplication friendly embedding NM-RMFE, and the NM-RMFE is obtained by cascading two RMFEs.
4. The method of claim 2, wherein, Before the first data and the second data are calculated by using the mapped sub-function, the method further comprises: obtaining first data of the second device; cutting the first data to obtain a plurality of sub-data; selecting a sub-data from the plurality of sub-data, and verifying whether the second device calculates the first data by using the RMFE according to the selected sub-data.
5. The method according to claim 2 or 4, characterized in that, The first data and the second data are calculated by using the mapped sub-function, comprising: inputting the second data into the mapped sub-function by using a re-embedding technology, and calculating the first data and the second data input based on the re-embedding technology, wherein the re-embedding technology is used to convert the second data into an element in an RMFE image set when the second data is not an element in the RMFE image set.
6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: obtaining the calculation function; decomposing the calculation function into a plurality of unit functions by adding virtual gates in the calculation function; converting any unit function into a sub-function belonging to an arithmetic branching program BP.
7. The method according to any of claims 1 to 6, characterized in that The method further comprises: obtaining the ciphertext information by using a first element to confuse the calculation result, wherein the first element is an element in an RMFE image set.
8. The method according to any of claims 1 to 7, characterized in that The method further comprises: sending the ciphertext information to the second device by using a vector oblivious linear function assignment VOLE.
9. The method of claim 8, wherein, The VOLE comprises a certified vector oblivious linear function assignment cVOLE, and the cVOLE is further used to verify, by the second device, whether the first device obtains the ciphertext information based on a decomposably affine randomized encoding DARE confusion of the calculation result.
10. A data processing apparatus, characterized by, The device is applied to a first device, and the device comprises: a transceiver module configured to perform receiving and / or sending operations in the method of any one of claims 1-9; a processing module configured to perform operations other than the receiving and / or sending operations in the method of any one of claims 1-9.
11. A data processing system, characterized by The data processing system comprises a first device and a second device, the second device is configured to publish first data, and the first device is configured to perform the data processing method of any one of claims 1-9.
12. A data processing device, characterized by The device comprises a processor configured to load and execute at least one instruction to enable the data processing device to implement the data processing method of any one of claims 1-9. The device comprises a processor configured to load and execute at least one instruction to enable the data processing device to implement the data processing method of any one of claims 1-9.
13. A computer-readable storage medium, characterized in that, The computer readable storage medium stores at least one instruction, which is loaded and executed by the processor to implement the data processing method according to any one of claims 1-9.
14. A chip, characterized by The chip comprises a processor, which is used to run program instructions or codes, so that the device containing the chip executes the data processing method according to any one of claims 1-9.
15. A computer program product, characterised in that, The computer program product comprises computer programs / instructions, which are executed by the processor to make the computer execute the data processing method according to any one of claims 1-9.