A privacy data computing method and system based on homomorphic encryption

CN122845265APending Publication Date: 2026-09-29JILIN ACAD OF AGRI SCI
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202611122359.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-28
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0005]1、当前未能实现计算资源与安全强度的有效平衡;系统缺乏对公开计算图谱的预分析能力,无法前瞻性评估不同计算路径的复杂度(如计算开销和通信成本),也难以设定合理的动态转换阈值;该机制导致系统无法智能判断何时可转为明文计算以提升效率,何时需维持密文计算以保证安全;其在实际运行中仍等同于“一刀切”式的全流程加密,造成巨大的性能损耗,或为追求速度而盲目解密,引发安全风险,从而无法在安全性与效率之间取得整体优化

Benefits of technology

[0039]本申请的有益效果在于:1、本申请提供的一种基于同态加密的隐私数据计算方法及系统,通过融合同态加密、分层密码学承诺与零知识证明,构建了一套兼顾高隐私保护、高效计算与可公开审计的数据处理流程;在保障原始数据不泄露的前提下,通过同态加密与动态明文转换机制,实现了隐私与计算效率的优化平衡,显著降低了全流程密文计算的开销;分层密码学承诺与存证机制,将计算过程的关键中间状态生成可公开验证的承诺,为整个计算过程提供了可追溯且不可篡改的审计线索;借助零知识证明技术响应审计挑战,能够在无需暴露任何敏感中间数据的情况下,向验证方证明计算过程的正确性与合规性,有效解决了数据外包计算中的信任难题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845265A_ABST
    Figure CN122845265A_ABST
Patent Text Reader

Abstract

This application discloses a privacy-preserving data computation method and system based on homomorphic encryption, relating to the field of data encryption technology. By integrating homomorphic encryption, layered cryptographic commitments, and zero-knowledge proofs, this application constructs a data processing workflow that balances high privacy protection, efficient computation, and public auditability. While ensuring the original data is not leaked, homomorphic encryption and a dynamic plaintext conversion mechanism achieve an optimized balance between privacy and computational efficiency, significantly reducing the overhead of the entire encrypted computation process. Layered cryptographic commitments and a proof-of-concept mechanism generate publicly verifiable commitments for key intermediate states in the computation process, providing traceable and tamper-proof audit trails for the entire computation process. By leveraging zero-knowledge proof technology to address audit challenges, the correctness and compliance of the computation process can be proven to the verifier without exposing any sensitive intermediate data, effectively solving the trust problem in outsourced data computation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data encryption technology, specifically to a privacy data computation method and system based on homomorphic encryption. Background Technology

[0002] In an environment of increasingly stringent regulations on data elementization and privacy protection, ensuring data privacy and the trustworthiness of the computation process while leveraging the powerful computing capabilities of the cloud to process sensitive data has become a critical challenge. Existing technologies such as fully homomorphic encryption can achieve encrypted computation, but the computational overhead is enormous, making it difficult to apply to complex business logic. Secure multi-party computation has high communication costs and complex collaboration among participants. The traditional "encryption followed by outsourcing of computation, result return and decryption" model leaves users unable to verify whether the server honestly executed the specified computation, posing a risk of result fraud. Some solutions attempt to introduce verifiable computation, but these typically only prove the final result, lacking transparent auditing capabilities for key intermediate steps in the computation process. If the result is questionable, it is difficult to pinpoint the problematic step. Therefore, a new technical solution is needed that can balance computational efficiency and privacy protection strength, providing verifiable and auditable evidence for the entire computation process.

[0003] Existing technology, such as the invention application patent with announcement number CN118332608B, discloses a data processing method based on privacy computing, including the following steps: S1, multiple users upload local data to a cloud server to obtain a multi-party shared encrypted set; S2, input the multi-party shared encrypted set into an SVM model to construct a multi-party shared encrypted model; S3, send the multi-party shared encrypted model to multiple users through the cloud server, encrypt the local data through the multi-party shared encrypted model, and complete the data processing method based on privacy computing. By uploading data from multiple user nodes to a cloud server, a privacy-preserving data transmission method is achieved. The improved Grey Wolf algorithm is used to train the SVM model on the cloud server, ensuring security during model training while achieving optimal model parameters and high computational efficiency. It can establish a multi-party shared encrypted model in a single round of communication, ensuring the security and efficiency of multi-party privacy computing.

[0004] Regarding the above-mentioned solutions, the inventors of this application have discovered that the above-mentioned technology has at least the following technical problems:

[0005] 1. Currently, an effective balance between computing resources and security strength has not been achieved; the system lacks the ability to pre-analyze publicly available computing graphs, making it impossible to proactively assess the complexity of different computing paths (such as computing overhead and communication costs), and it is also difficult to set reasonable dynamic conversion thresholds; this mechanism prevents the system from intelligently determining when to switch to plaintext computing to improve efficiency and when to maintain ciphertext computing to ensure security; in actual operation, it is still equivalent to a "one-size-fits-all" full-process encryption, causing huge performance losses, or blindly decrypting in pursuit of speed, triggering security risks, thus failing to achieve overall optimization between security and efficiency.

[0006] 2. Currently, a reliable and verifiable global audit trail has not been established. The cryptographic commitments (such as hash values) generated in key steps lack a hierarchical and orderly organization and release mechanism, and are not effectively connected to the public evidence storage system, resulting in the lack of a credible "digital notarized record" for the entire computation process. This weakens the transparency and credibility of the computation process, making it difficult for third parties (such as auditors) to verify the consistency of commitments afterward, and to confirm whether the computation process was faithfully executed or whether it was tampered with. As a result, effective supervision of black-box computation services cannot be achieved, damaging the credibility and reliability of the system.

[0007] 3. Currently, efficient and privacy-preserving proof of computational correctness cannot be achieved. When faced with audit challenges targeting intermediate steps, service providers cannot quickly generate zero-knowledge proofs based on plaintext intermediate states. It is difficult to effectively prove to the verifier that "I know the correct intermediate data and the computation steps are correct," and the specific content of the intermediate data may be leaked during the proof process. This exacerbates the key contradiction in verifiable computation, failing to meet audit and compliance requirements (difficult to prove computational honesty) and failing to adhere to privacy protection principles (potentially exposing sensitive procedural information). Summary of the Invention

[0008] To address the aforementioned technical shortcomings, the purpose of this application is to provide a privacy data computation method and system based on homomorphic encryption.

[0009] To solve the above-mentioned technical problems, this application adopts the following technical solution: In the first aspect, this application provides a privacy data computation method based on homomorphic encryption, which includes the following steps: S1, client data encryption and uploading: homomorphically encrypting personal privacy data to generate encrypted data and obtaining the corresponding public computation graph.

[0010] S2. Complexity Pre-analysis and Transformation Threshold Setting: Based on the publicly available computational graph, analysis is performed to obtain the complexity score and dynamic transformation threshold of each layer in each logic layer.

[0011] S3. Plaintext intermediate state and plaintext generation: Based on the complexity score and dynamic conversion threshold, the encrypted data is analyzed to obtain the plaintext intermediate state and the plaintext of the final result.

[0012] S4. Generate and publish layered cryptographic commitments: Based on the plaintext intermediate state, generate and publish the corresponding layered cryptographic commitments to the public evidence storage system.

[0013] S5. The server returns the encryption result: the plaintext of the final result is encrypted and the encryption result is returned to the client.

[0014] S6. Zero-knowledge proof generation: When an audit challenge for a specific layered cryptographic commitment is received, the plaintext intermediate state corresponding to the specific layered cryptographic commitment is analyzed to generate a zero-knowledge proof and respond accordingly.

[0015] S7. Audit Verification: Verification is performed based on the received zero-knowledge proof.

[0016] Preferably, the step of analyzing based on the publicly available computation graph to obtain the complexity score and dynamic transformation threshold of each layer in each logic layer includes: S301, receiving the publicly available computation graph.

[0017] S302, based on the publicly available computation graph, preprocessing analysis is performed on each logical layer in the computation task to obtain the operation type and parameter scale of each logical layer. The static complexity score of each layer in each logical layer is calculated through the layer complexity scoring function, and the summation operation is performed to obtain the total score.

[0018] S303, based on the total score and the preset efficiency gain target, the dynamic conversion threshold is calculated using the dynamic conversion threshold calculation function.

[0019] Preferably, the calculation of the dynamic conversion threshold includes: using a calculation formula Determine the dynamic conversion threshold ,in This is represented as the total score. This is expressed as an efficiency gain objective. This is represented as the floor function.

[0020] Preferably, the step of generating and publishing the corresponding layered cryptographic commitment to the public evidence storage system based on the plaintext intermediate state includes: S601, based on the plaintext intermediate state, traversing each plaintext intermediate state as the current commitment generation point.

[0021] S602, for the current commitment generation point, select all plaintext intermediate states generated from the plaintext intermediate state corresponding to the current commitment generation point to the plaintext of the final result, so as to obtain a subset of plaintext intermediate states.

[0022] S603, based on a preset vector commitment scheme, calculates all data in the plaintext intermediate state subset to obtain the corresponding hierarchical commitment.

[0023] S604 publishes all generated hierarchical commitments and the final calculated commitment root hash to the pre-defined public notarization system.

[0024] Preferably, the step of analyzing the plaintext intermediate state corresponding to a specific layered cryptographic commitment, generating a zero-knowledge proof, and responding includes: S801, receiving an audit challenge message from the auditor, and parsing the audit challenge message to obtain the index of the challenged commitment.

[0025] S802, based on the challenged commitment index, retrieve the corresponding plaintext intermediate state from local storage, and combine it with the preceding ciphertext intermediate result, the server private key and the model weight parameters to generate a private input tuple.

[0026] S803, based on the challenged commitment index, obtain the corresponding layered cryptographic commitment from the public evidence storage system, and generate a public input tuple by combining the public encrypted input data and the public computation graph.

[0027] S804, invoke the preset zero-knowledge proof algorithm, and perform a proof generation operation based on the private input tuple and the public input tuple to generate a zero-knowledge proof.

[0028] S805, the zero-knowledge proof is encapsulated into a response message and sent to the auditor to complete the response to the audit challenge.

[0029] Preferably, the verification based on the received zero-knowledge proof includes: S701, obtaining the public verification key, public input, and received zero-knowledge proof based on a preset public evidence storage system to obtain the data required for verification.

[0030] S702, based on the data required for verification, a preset zero-knowledge proof verification algorithm is invoked to perform a verification operation on the zero-knowledge proof in order to obtain the verification result.

[0031] S703, Based on the verification result, perform an honesty determination operation to obtain a server behavior determination result.

[0032] In a second aspect, this application provides a system for a privacy data computation method based on homomorphic encryption, comprising: preferably, a client data encryption and uploading module, used to perform homomorphic encryption on personal privacy data to generate encrypted data and obtain the corresponding public computation graph.

[0033] The complexity pre-analysis and transformation threshold setting module analyzes the publicly available computational graph to obtain the complexity score and dynamic transformation threshold of each layer in each logic layer.

[0034] The plaintext intermediate state and plaintext generation module analyzes the encrypted data based on the complexity score and dynamic conversion threshold to obtain the plaintext intermediate state and the plaintext of the final result.

[0035] Generate and publish layered cryptographic commitment modules. Based on plaintext intermediate states, generate and publish corresponding layered cryptographic commitments to the public evidence storage system.

[0036] The server returns an encryption result module, which is used to encrypt the plaintext of the final result and return the encrypted result to the client.

[0037] The zero-knowledge proof generation module is used to analyze the plaintext intermediate state corresponding to the specific layered cryptographic commitment when an audit challenge is received, generate a zero-knowledge proof, and respond.

[0038] The audit verification module performs verification based on the received zero-knowledge proofs.

[0039] The beneficial effects of this application are as follows: 1. This application provides a privacy-preserving data computation method and system based on homomorphic encryption. By integrating homomorphic encryption, layered cryptographic commitments, and zero-knowledge proofs, it constructs a data processing flow that balances high privacy protection, efficient computation, and public auditability. Under the premise of ensuring that the original data is not leaked, the homomorphic encryption and dynamic plaintext conversion mechanism achieve an optimized balance between privacy and computational efficiency, significantly reducing the overhead of the entire process of encrypted computation. The layered cryptographic commitment and evidence storage mechanism generate publicly verifiable commitments for the key intermediate states of the computation process, providing traceable and tamper-proof audit clues for the entire computation process. By leveraging zero-knowledge proof technology to respond to audit challenges, it can prove the correctness and compliance of the computation process to the verifier without exposing any sensitive intermediate data, effectively solving the trust problem in data outsourcing computation.

[0040] 2. This application achieves a dynamic and intelligent balance between computing resources and security strength. By pre-analyzing the publicly available computing graph, the system can proactively assess the complexity of different computing paths (such as computing overhead and communication costs) and set dynamic conversion thresholds accordingly. This mechanism allows the system to intelligently decide where it can securely convert to plaintext computing to improve efficiency and where it must maintain ciphertext computing to ensure security. It avoids the huge performance loss caused by the "one-size-fits-all" full-process encryption in traditional schemes and also prevents security vulnerabilities caused by blindly decrypting in pursuit of speed, thus achieving the optimal solution for security and efficiency overall.

[0041] 3. The outstanding contribution of this application is the establishment of a traceable and verifiable global audit trail. By publishing the cryptographic commitments (such as hash values) generated at each key step (plaintext intermediate state) in a layered and orderly manner to a public notarization system, it is equivalent to creating an immutable "digital notarized record" for the entire computation process; this provides the cornerstone for the transparency and credibility of the computation process. Any third party (such as an auditor) can afterwards verify the consistency of these commitments to confirm whether the computation process was faithfully executed and whether there was any tampering, thereby achieving effective supervision of the black-box computation service and enhancing the credibility and reliability of the system.

[0042] 4. This application achieves efficient and privacy-preserving proof of computational correctness; when faced with an audit challenge targeting a certain intermediate step, the service provider can quickly generate a zero-knowledge proof based on the corresponding plaintext intermediate state; it can convincingly verify that "I know the correct intermediate data and the computation steps are correct," but at the same time, it does not disclose the specific content of the intermediate data at all; this solves the key contradiction in verifiable computation, satisfying both audit and compliance requirements, which require proving computational honesty, and adhering to the principle of privacy protection, without exposing any process-sensitive information. Attached Figure Description

[0043] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0044] Figure 1 This is a flowchart illustrating the implementation steps of the method described in this application.

[0045] Figure 2 This is a schematic diagram of the system structure connection of this application. Detailed Implementation

[0046] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0047] Please see Figure 1 As shown, this application provides a privacy data computation method based on homomorphic encryption in the first aspect, including: S1, client data encryption and uploading: homomorphically encrypting personal privacy data to generate encrypted data and obtaining the corresponding public computation graph.

[0048] In a specific instance, the step of homomorphically encrypting personal privacy data to generate encrypted data and obtaining the corresponding public computation graph includes: S201, obtaining privacy data based on the user terminal to obtain the original privacy data set.

[0049] S202, based on an encryption algorithm that supports homomorphic operations of addition and multiplication, the original privacy data set is encrypted to obtain encrypted data.

[0050] S203, based on the computing task, obtain the public computing graph corresponding to the computing task, and upload the encrypted data and the public computing graph to the server.

[0051] It should be noted that obtaining privacy data refers to the user's client reading raw information to be calculated from local storage devices or external sensors and other input devices. This raw information constitutes the raw privacy data set, which may include any non-public data that needs to be protected, such as the user's personal identification information, medical and health data, financial records, biometrics, or device operating parameters.

[0052] It should be noted that the encryption operation on the original privacy data set is implemented using a homomorphic encryption algorithm such as the CKKS (Cheon-Kim-Kim-Song) scheme. This algorithm allows addition and multiplication operations to be performed on the encrypted data, and the decrypted result is identical to the result of performing the same operation on the original plaintext, thus enabling computation on the ciphertext without decryption. Specifically, the encryption operation involves generating a public and private key pair using preset public parameters, and then using the public key to homomorphically encrypt each data point in the original privacy data set, generating a corresponding ciphertext data block. The set of all ciphertext data blocks constitutes the encrypted data. Furthermore, the homomorphic property of the CKKS scheme allows the server to directly perform complex computations (such as neural network forward propagation) on the encrypted data without accessing the plaintext content of the original privacy data, thereby protecting user privacy.

[0053] It should be noted that obtaining a public computation graph refers to the user client constructing or loading a specification file describing the computational logic from a local database based on the requirements of the computation task. The computation graph defines the sequence of operators involved in the computation (such as convolutional layers, fully connected layers, or activation function layers in a neural network), the connections between operators, and the data dimensions of the input and output, but does not include any model weights or biases. As a blueprint for computation execution, the public computation graph can be made public to the server.

[0054] It should be noted that uploading encrypted data and a publicly available computation graph to the server (via the internet or other network communication links from the user's end) and transmitting encrypted private data and a publicly available computation task description file to the remote computation server delivers all the necessary inputs (ciphertext data and computation logic) for the privacy computation task to the server, laying the foundation for the server to execute the privacy computation task without decrypting the user data.

[0055] In a preferred embodiment, the user terminal executes the initialization process for data encryption and task upload. Specifically, the user first triggers the computation task, and the user terminal then initiates the data preparation process. In step S201, acquiring privacy data is the initial step of privacy computation. The user terminal's application or hardware sensors collect, call, or read sensitive information to be processed. This information is organized in the form of structured arrays or tensors, forming the original privacy data set. For example, in a medical image analysis scenario, this set might be a matrix of pixel values ​​from CT scan images before encryption. Step S202 is one of the core technical actions for privacy protection in this solution. The CKKS encryption algorithm is a homomorphic encryption scheme that supports approximate arithmetic, and is particularly suitable for protecting real or complex data. Its encryption process... It can be formally represented as for a plaintext message Through public key Calculate the ciphertext The ciphertext c has the following homomorphic property: for any two ciphertexts... and There exist valid addition and multiplication operations such that ,and ,in To use the private key Decryption operation, This indicates the existence of a controllable, minor computational error. By performing this encryption operation, the original sensitive data is transformed into an unreadable yet computable ciphertext form, namely the encrypted data. Step S203 ensures the explicitness and publicly verifiable nature of the computation task. The publicly available computation graph is a metadata file that does not disclose any secrets related to user data or model intellectual property (weights). It clearly declares to the server the computational structure to be executed, such as a neural network topology containing five fully connected layers and ReLU activation functions. Uploading the encrypted data along with this graph constitutes a complete "privacy computation task package," enabling the server to correctly transform the encrypted data based on the publicly available logic, ultimately completing the computation task, without knowing the original data content. This separation design (data encryption, logic disclosure) is a key prerequisite for achieving efficient and auditable privacy computation.

[0056] S2. Complexity Pre-analysis and Transformation Threshold Setting: Based on the publicly available computational graph, analysis is performed to obtain the complexity score and dynamic transformation threshold of each layer in each logic layer.

[0057] In a specific instance, the step of analyzing based on the publicly available computation graph to obtain the complexity score and dynamic transformation threshold of each layer in each logic layer includes: S301, receiving the publicly available computation graph.

[0058] S302, based on the publicly available computation graph, preprocessing analysis is performed on each logical layer in the computation task to obtain the operation type and parameter scale of each logical layer. The static complexity score of each layer in each logical layer is calculated through the layer complexity scoring function, and the summation operation is performed to obtain the total score.

[0059] S303, based on the total score and the preset efficiency gain target, the dynamic conversion threshold is calculated using the dynamic conversion threshold calculation function.

[0060] It should be noted that receiving the publicly available computation graph refers to the server receiving a metadata file describing the logical structure of the computation task from the user through its network interface. This operation enables the server to understand and prepare to execute subsequent privacy-preserving computation processes without knowing the specific weights of the model or the user's original data content.

[0061] It should be noted that preprocessing analysis of each logical layer in the computation task refers to the server parsing the publicly available computation graph (quantifying the computational overhead that each layer may incur during execution) before starting the actual privacy-preserving computation. For each logical layer defined in the publicly available computation graph, its operation type identifier (e.g., indicating whether it is matrix multiplication, convolution operation, or nonlinear activation) and parameter scale (e.g., convolution kernel size, number of input or output channels, and the dimension of the weight matrix of fully connected layers, etc.) are extracted.

[0062] It should be noted that the layer complexity scoring function is a function that quantifies the relative computational complexity of a layer based on its operation type and parameter size; its mathematical expression is: In the formula, Indicates the first The static complexity score of a layer is a scalar value that measures the relative computational cost of performing the operation in the encrypted state. Indicates the first The operation type identifier for the layer is an enumerated variable derived from the public computation graph; Indicates the first The parameter scale description vector of a layer contains dimensional information that defines the computational cost of that layer; This represents the operation type weighting function, whose function is to weight different operation types. (For example, convolution, fully connected, or pooling) are assigned a base weight coefficient that reflects the inherent differences in computational intensity between different types of operations; This represents a parameter scaling function, which operates based on the parameter size. (For example, the size of the input feature map or the number of convolutional kernels) Calculate a scaling factor that is positively correlated with the parameter size, used to scale the base weights up or down to match the actual size of the layer.

[0063] It should be noted that the static complexity score is a dimensionless relative score (used to compare the expected computational cost of different layers in a ciphertext computing environment). A higher score indicates that the layer requires relatively more computational resources and time to execute in ciphertext. This score serves as one of the core inputs for subsequent dynamic transformation decisions.

[0064] It should be noted that the static complexity scores of all layers are summed; this operation is a simple arithmetic summation process, which adds up the static complexity scores of all layers to obtain a quantitative index representing the estimated total cost of the entire computation task in pure ciphertext state, and is recorded as the total score.

[0065] In a specific example, the calculation of the dynamic conversion threshold includes: using a calculation formula Determine the dynamic conversion threshold ,in This is represented as the total score. This is expressed as an efficiency gain objective. This is represented as the floor function.

[0066] It should be noted that the dynamic conversion threshold is a dimensionless integer value; the floor function ensures that the threshold is an integer, facilitating comparison with the accumulated integer complexity. The dynamic conversion threshold represents the threshold value that the server's accumulated complexity variable needs to exceed during computation. Once it exceeds this value, a conversion operation from ciphertext to plaintext will be triggered, aiming to achieve a significant efficiency improvement in the remaining computation, while balancing the privacy protection brought by ciphertext computation with the performance advantages of plaintext computation.

[0067] It should be noted that the preset efficiency gain target is selected by the user from parameters pre-set by the system (the maximum tolerable reduction in overhead expected by converting from ciphertext computation to plaintext computation). For example, an efficiency gain target of 0.7 means that the user expects to start considering conversion when the total overhead reaches 70% of the pure ciphertext overhead, in order to obtain an efficiency improvement in subsequent computations. Furthermore, the system is pre-set to dynamically optimize based on historical task performance data, real-time system load, or security policy libraries. However, this optimization itself relies on an external policy engine rather than being directly calculated. Its output is still used as a preset value input to the dynamic conversion threshold calculation function, and is selected by the user.

[0068] This application achieves a dynamic and intelligent balance between computing resources and security strength. By pre-analyzing the publicly available computing graph, the system can proactively assess the complexity of different computing paths (such as computing overhead and communication costs) and set dynamic conversion thresholds accordingly. This mechanism allows the system to intelligently decide where it can securely convert to plaintext computing to improve efficiency and where it must maintain ciphertext computing to ensure security. It avoids the huge performance loss caused by the "one-size-fits-all" full-process encryption in traditional schemes and also prevents security vulnerabilities caused by blindly decrypting in pursuit of speed, thus achieving the optimal solution for security and efficiency overall.

[0069] S3. Plaintext intermediate state and plaintext generation: Based on the complexity score and dynamic conversion threshold, the encrypted data is analyzed to obtain the plaintext intermediate state and the plaintext of the final result.

[0070] In a specific instance, the step of analyzing encrypted data based on the complexity score and dynamic conversion threshold to obtain the plaintext intermediate state and the plaintext of the final result includes: S301, based on the loaded pre-computation model and encrypted data, initializing the cumulative complexity variable to zero and setting the current processing layer index.

[0071] S302, Based on the current processing layer index, determine the current processing layer and its corresponding complexity score.

[0072] S303, based on encrypted data, performs the calculations defined by the current processing layer in the ciphertext state to obtain intermediate ciphertext results.

[0073] S304, based on the complexity score of the current processing layer, update the cumulative complexity variable.

[0074] S305, based on the updated cumulative complexity variable and the dynamic conversion threshold, determine whether the cumulative complexity variable is greater than the dynamic conversion threshold for the first time.

[0075] S306, perform a branch decision operation based on the judgment result. If the judgment result is greater than the first time, then execute S307; otherwise, execute S310.

[0076] S307. Based on the ciphertext intermediate result and the private key required for homomorphic decryption, perform homomorphic decryption to obtain the plaintext intermediate state.

[0077] S308, based on the current processing layer index and plaintext intermediate state, records the point where the conversion occurs.

[0078] S309, based on the plaintext intermediate state, continue to execute the calculations of all subsequent layers to obtain the plaintext of the final result.

[0079] S310: Based on the ciphertext intermediate result, process the next layer in ciphertext state, update the index of the current processing layer, and then return to S302.

[0080] It's important to note that the initialization operation refers to the server setting two key state variables before starting privacy-preserving computation. The accumulated complexity variable dynamically accumulates the quantified computational overhead of each processed layer during the computation process; its initial value is zero, indicating that computation has not yet begun. The current processing layer index is an identifier pointing to a specific logical layer in the public computation graph, indicating the layer currently performing computation.

[0081] It should be noted that the current processing layer is determined from the computational model based on the structural order of the publicly available computational graph, sequentially locating the specific computational unit (such as a layer in a neural network) specified by the current processing layer index. The corresponding complexity score is a dimensionless value obtained from the preprocessing analysis of S2.

[0082] It should be noted that performing computation in encrypted state means that the server strictly follows the computational logic (such as matrix multiplication, convolution, and activation functions) defined in the current processing layer of the publicly available computational graph to operate on the input encrypted data or the encrypted intermediate results from the previous layer. All arithmetic operations (addition and multiplication) are completed within the encrypted domain, and the server cannot obtain any plaintext information of the original data throughout the entire process. This operation is a core technical action to ensure user data privacy.

[0083] It should be noted that the intermediate ciphertext result is the output data generated after the current processing layer performs ciphertext calculation. It is still in the form of homomorphic encryption and is a stage product of the calculation process under privacy protection.

[0084] It should be noted that updating the cumulative complexity variable involves adding the complexity score of the current processing layer to the current value of the cumulative complexity variable and assigning the result back to the cumulative complexity variable. This operation enables the dynamic accumulation and tracking of the estimated total cost of all processed layers in ciphertext state from the start of computation to the current layer.

[0085] It's important to note that determining whether the cumulative complexity exceeds the dynamic transformation threshold for the first time is a crucial decision point for the adaptive transformation mechanism. This determination involves two conditions: first, the updated value of the cumulative complexity variable is greater than the preset dynamic transformation threshold; second, this "greater than" event occurs for the first time in this computational task. This logic ensures the uniqueness and determinism of the transformation trigger point, preventing repeated triggering of transformations near the threshold.

[0086] It should be noted that the branch decision operation is based on the logical result of the above judgment, controlling the program execution flow to turn to different processing paths. If the judgment result is greater than the first value, the process enters the branch of conversion and subsequent plaintext calculation; otherwise, the process enters the branch of continuing ciphertext calculation.

[0087] It should be noted that homomorphic decryption uses the private key corresponding to the homomorphic encryption scheme to perform a decryption algorithm on the intermediate ciphertext result generated by the current S303, restoring it to unencrypted plaintext data that can be efficiently processed by a regular CPU or GPU. This operation is a concrete implementation of "adaptive plaintext conversion," marking a shift in computation from a high-overhead, high-privacy ciphertext mode to a low-cost, low-privacy (but limited to within the server) plaintext mode.

[0088] It should be noted that the plaintext intermediate state is the data obtained from the homomorphic decryption operation; it is a plaintext snapshot of the original privacy data after partial ciphertext computation. This state data will serve as the input for all subsequent layers of computation, enabling the remaining computations to be performed efficiently in plaintext form.

[0089] It should be noted that recording the point where the transformation occurs involves marking the layer index that triggered the transformation (the current processing layer index) and the intermediate plaintext state obtained by decryption at that point. This record is crucial for the subsequent generation of layered cryptographic commitments and for supporting possible audit verification, providing a key anchor point for the verifiability of the computation process.

[0090] It should be noted that continuing the calculation of all subsequent layers means using the plaintext intermediate state obtained in S307 as input, and based on the publicly available computation graph, starting from the next layer after the current processing layer, up to the last layer defined in the graph, completing all the prescribed operations in plaintext data state. Since homomorphic encryption operations are no longer required, this process will significantly reduce computational latency and resource consumption.

[0091] It should be noted that the plaintext of the final result refers to the unencrypted computation result data output after all layers of computation (including the ciphertext and plaintext stages) have been completed. This result will be encrypted by the server in subsequent steps and returned to the user.

[0092] It should be noted that processing the next layer in ciphertext state means that, without triggering a transformation, the intermediate ciphertext result generated by the current S303 is used as input, and the computation is continued in the next layer according to the computation graph (indicated by the updated index of the current processing layer). This operation maintains the complete privacy protection of the computation until the accumulated complexity triggers the transformation condition.

[0093] S4. Generate and publish layered cryptographic commitments: Based on the plaintext intermediate state, generate and publish the corresponding layered cryptographic commitments to the public evidence storage system.

[0094] In a specific instance, the step of generating and publishing the corresponding layered cryptographic commitment to the public evidence storage system based on the plaintext intermediate state includes: S601, based on the plaintext intermediate state, traversing each plaintext intermediate state as the current commitment generation point.

[0095] S602, for the current commitment generation point, select all plaintext intermediate states generated from the plaintext intermediate state corresponding to the current commitment generation point to the plaintext of the final result, so as to obtain a subset of plaintext intermediate states.

[0096] S603, based on a preset vector commitment scheme, calculates all data in the plaintext intermediate state subset to obtain the corresponding hierarchical commitment.

[0097] S604 publishes all generated hierarchical commitments and the final calculated commitment root hash to the pre-defined public notarization system.

[0098] It should be noted that traversing each plaintext intermediate state means that the server accesses the plaintext intermediate state corresponding to each transition point recorded in step S3 in the order in which they were generated in the computation task. The purpose of this operation is to construct corresponding cryptographic commitments for each key intermediate state generated during the computation process, so as to ensure that the entire computation process, from the transition point onwards, can be independently verified.

[0099] It should be noted that the plaintext intermediate state subset is a set of continuous intermediate data associated with a specific current commitment generation point; the plaintext intermediate state subset includes all subsequent plaintext intermediate states generated from the plaintext intermediate state corresponding to that generation point to the final end of the computation task. The significance of selecting this subset is that it provides a complete data chain for verifying whether the computation "starting from this point" has been executed correctly.

[0100] It should be noted that the preset vector commitment scheme is a cryptographic primitive that can efficiently compress a set of data into a single, fixed, short string (commitment), and subsequently generate a proof for any element in that set of data to verify that the element indeed belongs to the original dataset from which the commitment was generated. In this method, a Merkle tree is used as the vector commitment scheme. Further, the Merkle tree construction algorithm is as follows: For a given subset of plaintext intermediate states, firstly, each plaintext intermediate state data in the subset is serialized and its hash value is calculated, serving as a leaf node of the Merkle tree; then, the hash values ​​of every two adjacent leaf nodes are concatenated, and their hash value is calculated, serving as the parent node of their next level; this process of pairwise merging and hashing is repeated until a unique top-level hash value is calculated, i.e., the root hash value of the hierarchical commitment.

[0101] It should be noted that the hierarchical commitment is the root hash value calculated based on a specific subset of plaintext intermediate states using the Merkle tree construction algorithm. This commitment is cryptographically bound to the entire subset of data it corresponds to. If any bit in the data is tampered with, the corresponding root hash value will undergo unpredictable changes. Therefore, the hierarchical commitment serves as cryptographic evidence of the integrity and correctness of its corresponding computational fragment.

[0102] It should be noted that the commitment root hash is the final, top-level root hash value calculated by the server after completing steps S601 to S603, which generate hierarchical commitments for all plaintext intermediate states, treating all hierarchical commitments themselves as a new data set, and again applying the vector commitment scheme (such as constructing a higher-level Merkle tree). This root hash value is cryptographically bound to all hierarchical commitments, thereby indirectly binding the entire subsequent computation history of the entire computation task from all transition points.

[0103] It should be noted that a public evidence storage system is a distributed ledger system or public database, such as a blockchain network, that possesses the characteristics of being public, immutable, and traceable. Publication refers to the server permanently writing the set of all hierarchical commitments and the final commitment root hash value, as an auditable record of a computational task, into the evidence storage system via the network. Any third-party auditor can then obtain this public information from the system as the basis for initiating and conducting audit verification.

[0104] The key contribution of this application is the establishment of a traceable and verifiable global audit trail. By publishing the cryptographic commitments (such as hash values) generated at each critical step (plaintext intermediate state) in a layered and orderly manner to a public notarization system, it is equivalent to creating an immutable "digital notarized record" of the entire computation process; this provides the cornerstone for the transparency and credibility of the computation process. Any third party (such as an auditor) can afterwards verify the consistency of these commitments to confirm whether the computation process was faithfully executed and whether there was any tampering, thereby achieving effective supervision of black-box computation services and enhancing the credibility and reliability of the system.

[0105] S5. The server returns the encryption result: the plaintext of the final result is encrypted and the encryption result is returned to the client.

[0106] In a specific instance, encrypting the plaintext of the final result and returning the encrypted result to the client includes: S701, based on the final plaintext result, performing an encryption operation using a homomorphic encryption algorithm to generate an encrypted final result.

[0107] S702, the final encryption result is returned to the user terminal.

[0108] S703, the user terminal decrypts the final encrypted result based on the private key to obtain the desired result.

[0109] It should be noted that the encryption operation refers to the server using a homomorphic encryption algorithm (such as the CKKS scheme) and its corresponding public key to encrypt and encode the final plaintext result. This operation transforms the result data, which has undergone all calculations and is in plaintext, back into homomorphically encrypted ciphertext. This action ensures that the calculation result is cryptographically protected again before leaving the server's internal environment and entering the network transmission stage, preventing leakage during transmission.

[0110] It should be noted that the final encrypted result is the ciphertext data processed by the homomorphic encryption algorithm after the final plaintext result is obtained. Its purpose is to securely encapsulate the result without exposing the plaintext content of the final calculation result, so that it can be returned to the legitimate data owner (i.e., the client) over the network, thereby achieving the privacy and security delivery of the calculation result.

[0111] It should be noted that returning the encrypted final result to the user terminal means that the server, through its network communication interface, sends a data packet containing the encrypted final result via the Internet or other communication links to the user terminal device that initially initiated this privacy computation task. This operation is the final output action of the server after completing its entrusted computing service, marking the end of the server-side computing process.

[0112] It should be noted that the decryption operation refers to the process by which the user, after receiving the encrypted final result, uses its locally stored private key, which is paired with the public key used for encryption, to perform a homomorphic decryption algorithm on the received ciphertext data. This algorithm is the reverse process of the encryption algorithm, and can use the secret information of the private key to correctly restore the encrypted final result in ciphertext form to the original plaintext data.

[0113] It should be noted that the desired result is the plaintext data obtained after the user successfully performs the decryption operation. This is the final output of the entire privacy data computation method based on homomorphic encryption, corresponding to the user's original privacy data. It is the accurate computation result obtained after strictly following all the logic defined in the publicly available computation graph (including the ciphertext and plaintext stages). After obtaining this result, the user can directly use it for subsequent business analysis, decision support, or other applications. The entire process completes the computation task while protecting the privacy of the original data and intermediate states.

[0114] S6. Zero-knowledge proof generation: When an audit challenge for a specific layered cryptographic commitment is received, the plaintext intermediate state corresponding to the specific layered cryptographic commitment is analyzed to generate a zero-knowledge proof and respond accordingly.

[0115] In a specific instance, the step of analyzing the plaintext intermediate state corresponding to a specific layered cryptographic commitment, generating a zero-knowledge proof, and responding includes: S801, receiving an audit challenge message from the auditor, and parsing the audit challenge message to obtain the index of the challenged commitment.

[0116] S802, based on the challenged commitment index, retrieve the corresponding plaintext intermediate state from local storage, and combine it with the preceding ciphertext intermediate result, the server private key and the model weight parameters to generate a private input tuple.

[0117] S803, based on the challenged commitment index, obtain the corresponding layered cryptographic commitment from the public evidence storage system, and generate a public input tuple by combining the public encrypted input data and the public computation graph.

[0118] S804, invoke the preset zero-knowledge proof algorithm, and perform a proof generation operation based on the private input tuple and the public input tuple to generate a zero-knowledge proof.

[0119] S805, the zero-knowledge proof is encapsulated into a response message and sent to the auditor to complete the response to the audit challenge.

[0120] It should be noted that receiving and parsing the audit challenge message refers to the server receiving a data packet containing challenge instructions from an external auditor through its network interface. This parsing operation extracts the identifier of the specific computational step to be audited, specified by the challenger, from the data packet; that is, the challenged commitment index. This commitment index corresponds to a specific layered cryptographic commitment generated and published in step S4, and is thus associated with a specific transition point in the computation process and its corresponding plaintext intermediate state.

[0121] It should be noted that generating the private input tuple is the process by which the server prepares the secret evidence required for the zero-knowledge proof. The private input tuple contains all data known to the server but confidential to the auditor. The plaintext intermediate state is a snapshot of the original data obtained through homomorphic decryption at the transition point in step S3, and is the core secret witness for proof generation. The preceding ciphertext intermediate result refers to the data still in an encrypted state, calculated and output one step before the transition point, used to prove the correct source of the plaintext intermediate state. The server's private key is the key used to perform homomorphic decryption and is the key secret for proving the legality of the decryption operation. The model weight parameters are specific computational parameters defined in the public computation graph. As input to prove the correctness of the computation, they are included here along with the secret data as part of the private input to declare their consistency in the proof construction.

[0122] It should be noted that generating the public input tuple is the process by which the server prepares the public parameters required for the zero-knowledge proof. The public input tuple contains all information known or publicly available to the auditor. The layered cryptographic commitment is a cryptographic digest of a set of intermediate state data that has been published to the public evidence storage system; it is the direct target of the audit challenge and the public benchmark for verification. The encrypted input data is the original data initially uploaded by the client and homomorphically encrypted. The public computation graph defines the complete logical structure of the computation. This public information collectively constitutes the public context upon which the proof is relied upon for verification.

[0123] It should be noted that calling the preset zero-knowledge proof algorithm to perform the proof generation operation is the core technical action of this step. The algorithm is a cryptographic protocol that can generate non-interactive zero-knowledge proofs. Its internal logic is to construct a complex mathematical relation that encodes all the conditions of the statement to be proved. Specifically, it proves that the server has secret inputs (i.e., private input tuples) that satisfy the following relation: (1) using the server's private key to perform homomorphic decryption on the ciphertext intermediate result of the preceding sequence to obtain the plaintext intermediate state; (2) using the plaintext intermediate state and the model weight parameters as input, strictly following the computation logic from the current layer to the next layer in the public computation graph, the result obtained is consistent with the next intermediate state data used when generating the layered commitment (this data is implicit in the generation path of the layered cryptographic commitment); (3) the plaintext intermediate state is an element in the original data subset used to calculate the public layered cryptographic commitment. The algorithm generates a short proof string through complex cryptographic transformations (such as polynomial commitments, linear PCP, etc.). The proof string itself does not reveal any specific content about the plaintext intermediate state, server private key, or other secret information. However, any verifier can efficiently verify the authenticity of the three compound claims using the public input and the proof string. Furthermore, the "zero-knowledge" property of the zero-knowledge proof algorithm ensures that even if an auditor repeatedly verifies, they cannot obtain any additional knowledge about the secret input from the proof string. Thus, while supporting auditability, it still protects the sensitive intermediate state and server private key during the computation process.

[0124] It should be noted that the proof string, denoted as a zero-knowledge proof, is a cryptographic data structure (a mathematically encoded "brief certificate" of the correctness of secret knowledge). It proves that the server has indeed honestly performed the entire computational process from ciphertext decryption to generating a specific commitment. Its purpose is to allow an untrusted third party (auditor) to be certain that the server's computational behavior at a specific stage is correct and fraudulent, without accessing any sensitive original data.

[0125] It should be noted that encapsulating the zero-knowledge proof into a response message and sending it to the auditor is the server's external delivery action after generating the proof. This response operation sends the zero-knowledge proof back to the auditor who initiated the challenge via a network link, enabling the auditor to run the corresponding zero-knowledge proof verification algorithm based on the received proof and the public input obtained from the public evidence storage system, to ultimately determine whether the server acted honestly in the challenged stage, thus completing the entire audit challenge and response process.

[0126] This application achieves efficient and privacy-preserving proof of computational correctness. When faced with an audit challenge targeting a specific intermediate step, the service provider can quickly generate a zero-knowledge proof based on the corresponding plaintext intermediate state. It can convincingly verify that "I know the correct intermediate data and the computation steps are correct," while completely concealing the specific content of the intermediate data. This resolves a key contradiction in verifiable computation, satisfying both audit and compliance requirements, which necessitate proving computational honesty, and adhering to privacy protection principles, without exposing any procedurally sensitive information.

[0127] S7. Audit Verification: Verification is performed based on the received zero-knowledge proof.

[0128] In a specific instance, the verification based on the received zero-knowledge proof includes: S701, obtaining the public verification key, public input, and the received zero-knowledge proof based on a preset public evidence storage system to obtain the data required for verification.

[0129] S702, based on the data required for verification, a preset zero-knowledge proof verification algorithm is invoked to perform a verification operation on the zero-knowledge proof in order to obtain the verification result.

[0130] S703, Based on the verification result, perform an honesty determination operation to obtain a server behavior determination result.

[0131] It should be noted that in step S701, obtaining the public verification key, public input, and received zero-knowledge proof is achieved by the auditor accessing the pre-defined public evidence storage system to download or query the commitment root hash and the set of all hierarchical commitments published by the server in step S604, thereby obtaining the hierarchical cryptographic commitments. Simultaneously, the auditor obtains the public verification key from the system's public parameters or the metadata published by the server, and obtains the public input, including encrypted input data, public computation graph, and hierarchical cryptographic commitments, from the information publicly published by the client or server. Furthermore, the auditor receives the zero-knowledge proof from the server as a response to the audit challenge (as described in step S805). The data required for verification is a complete dataset containing all public parameters necessary for executing subsequent verification algorithms, the evidence to be verified, and the verification benchmark.

[0132] It should be noted that in step S702, the verification operation of the zero-knowledge proof π is performed by calling a preset non-interactive zero-knowledge proof verification algorithm. This algorithm uses the public verification key and public input as known parameters to perform cryptographic verification on the received zero-knowledge proof and check the correctness of its mathematical structure. The mathematical logic of the verification operation is to check whether the proof π can formally prove that the server has private inputs that satisfy specific relations (i.e., the private input tuples in S802), which include: (1) the plaintext intermediate state is indeed obtained by decrypting the previous ciphertext intermediate result with the correct private key; (2) starting from the plaintext intermediate state and the correct model weights, subsequent calculations are performed according to the public computation graph, and the resulting intermediate state sequence is completely consistent with the data used to generate the hierarchical commitment. The verification algorithm performs a series of algebraic operations (such as bilinear pairing operations) and finally outputs a Boolean value. The verification result is a Boolean value output by the zero-knowledge proof verification algorithm. Its physical meaning is as follows: if the result is "true", it means that the zero-knowledge proof is valid and that the evidence provided by the server conforms to all preset cryptographic relations; if the result is "false", it means that the proof of π is invalid and cannot pass the verification.

[0133] It should be noted that the zero-knowledge proof verification algorithm is specifically as follows: ,in, The public verification key is a cryptographic parameter generated and made public during the initialization of the verification system for use in verifying proofs. The string representing the zero-knowledge proof to be verified is the proof data generated by the server; It represents the public input set, including all information known to the auditor, such as encrypted input data, public computation graphs, and layered cryptographic commitments. This is the verification algorithm function; output This is the verification result. This indicates that the verification has passed (corresponding to "true"). This indicates that the verification failed (corresponding to "false").

[0134] It should be noted that in step S703, the honesty determination operation is performed by the auditor based on a logical judgment of the Boolean verification result obtained in step S702. If the verification result is "true," the server's computational behavior at the challenged transition point (corresponding to a specific layered commitment) is deemed honest, meaning the server correctly executed the entire segment from ciphertext decryption to subsequent plaintext computation. If the verification result is "false," the server is deemed to have engaged in cheating, implying that the server may have provided incorrect computations, tampered with intermediate states, or used incorrect keys, and its published layered cryptographic commitments are untrustworthy. The server behavior determination result is a final qualitative conclusion based on cryptographic verification regarding the server's integrity in a specific computational stage, providing a clear and objective basis for auditing activities.

[0135] Please see Figure 2 As shown, in a second aspect, this application provides a system for a privacy data computation method based on homomorphic encryption.

[0136] The system 100 of the privacy data computation method based on homomorphic encryption described in this invention can be installed in an electronic device. Depending on the functions implemented, the system 100 may include a client data encryption and upload module 101, a complexity pre-analysis and conversion threshold setting module 102, a plaintext intermediate state and plaintext generation module 103, a layered cryptographic commitment generation and publication module 104, a server-returned encryption result module 105, a zero-knowledge proof generation module 106, and an audit verification module 107. The modules described in this invention can also be called units, referring to a series of computer program segments that can be executed by the processor of an electronic device and perform a fixed function, stored in the memory of the electronic device.

[0137] In this embodiment, the functions of each module / unit are as follows: The client data encryption and upload module is used to perform homomorphic encryption on personal privacy data to generate encrypted data and obtain the corresponding public computation graph.

[0138] The complexity pre-analysis and transformation threshold setting module analyzes the publicly available computational graph to obtain the complexity score and dynamic transformation threshold of each layer in each logic layer.

[0139] The plaintext intermediate state and plaintext generation module analyzes the encrypted data based on the complexity score and dynamic conversion threshold to obtain the plaintext intermediate state and the plaintext of the final result.

[0140] Generate and publish layered cryptographic commitment modules. Based on plaintext intermediate states, generate and publish corresponding layered cryptographic commitments to the public evidence storage system.

[0141] The server returns an encryption result module, which is used to encrypt the plaintext of the final result and return the encrypted result to the client.

[0142] The zero-knowledge proof generation module is used to analyze the plaintext intermediate state corresponding to the specific layered cryptographic commitment when an audit challenge is received, generate a zero-knowledge proof, and respond.

[0143] The audit verification module performs verification based on the received zero-knowledge proofs.

[0144] This application provides a privacy-preserving data computation method and system based on homomorphic encryption. By integrating homomorphic encryption, layered cryptographic commitments, and zero-knowledge proofs, it constructs a data processing workflow that balances high privacy protection, efficient computation, and public auditability. While ensuring the original data is not leaked, homomorphic encryption and a dynamic plaintext conversion mechanism achieve an optimized balance between privacy and computational efficiency, significantly reducing the overhead of the entire encrypted computation process. The layered cryptographic commitment and evidence storage mechanism generate publicly verifiable commitments for key intermediate states in the computation process, providing traceable and tamper-proof audit trails for the entire computation process. Leveraging zero-knowledge proof technology to address auditing challenges, it can prove the correctness and compliance of the computation process to the verifier without exposing any sensitive intermediate data, effectively solving the trust problem in outsourced data computation.

[0145] In the several embodiments provided by this invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0146] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0147] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0148] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0149] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0150] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A privacy-preserving data computation method based on homomorphic encryption, characterized in that, include: S1. Client Data Encryption and Upload: Homomorphic encryption is applied to personal privacy data to generate encrypted data, and the corresponding public computation graph is obtained; S2. Complexity Pre-analysis and Transformation Threshold Setting: Based on the publicly available computational graph, analysis is performed to obtain the complexity score and dynamic transformation threshold of each layer in each logic layer; S3, Plaintext Intermediate State and Plaintext Generation: Based on the complexity score and dynamic conversion threshold, the encrypted data is analyzed to obtain the plaintext intermediate state and the plaintext of the final result; S4. Generate and publish layered cryptographic commitments: Based on the plaintext intermediate state, generate and publish the corresponding layered cryptographic commitments to the public evidence storage system; S5. The server returns the encryption result: the plaintext of the final result is encrypted, and the encryption result is returned to the client; S6. Zero-knowledge proof generation: When an audit challenge to a specific layered cryptographic commitment is received, the plaintext intermediate state corresponding to the specific layered cryptographic commitment is analyzed to generate a zero-knowledge proof and a response is given. S7. Audit Verification: Verification is performed based on the received zero-knowledge proof.

2. The privacy data computation method based on homomorphic encryption according to claim 1, characterized in that, The process of homomorphically encrypting personal privacy data to generate encrypted data and obtaining the corresponding public computation graph includes: S201, based on the user terminal, obtain privacy data to obtain the original privacy data set; S202, Based on an encryption algorithm that supports homomorphic operations of addition and multiplication, the original privacy data set is encrypted to obtain encrypted data; S203, based on the computing task, obtain the public computing graph corresponding to the computing task, and upload the encrypted data and the public computing graph to the server.

3. The privacy data computation method based on homomorphic encryption according to claim 1, characterized in that, The analysis based on the publicly available computational graph to derive the complexity score and dynamic transformation threshold for each layer in each logic layer includes: S301, Receive the publicly available computational graph; S302, based on the publicly available computation graph, preprocessing analysis is performed on each logical layer in the computation task to obtain the operation type and parameter scale of each logical layer. The static complexity score of each layer in each logical layer is calculated through the layer complexity scoring function, and the summation operation is performed to obtain the total score. S303, based on the total score and the preset efficiency gain target, the dynamic conversion threshold is calculated using the dynamic conversion threshold calculation function.

4. The privacy data computation method based on homomorphic encryption according to claim 3, characterized in that, The calculation of the dynamic conversion threshold includes: Through calculation formula Determine the dynamic conversion threshold ,in This is represented as the total score. This is expressed as an efficiency gain objective. It is represented as the floor function.

5. The privacy data computation method based on homomorphic encryption according to claim 1, characterized in that, The analysis of encrypted data based on the complexity score and dynamic transformation threshold, yielding the plaintext of intermediate states and the final result, includes: S301, based on the loaded pre-computed model and encrypted data, initializes the cumulative complexity variable to zero and sets the index of the current processing layer; S302, Based on the current processing layer index, determine the current processing layer and its corresponding complexity score; S303, based on encrypted data, performs the calculations defined by the current processing layer in the ciphertext state to obtain intermediate ciphertext results; S304, Update the cumulative complexity variable based on the complexity score of the current processing layer; S305, based on the updated cumulative complexity variable and dynamic conversion threshold, determine whether the cumulative complexity variable is greater than the dynamic conversion threshold for the first time; S306, perform a branch decision operation based on the judgment result. If the judgment result is greater than the first time, then execute S307; otherwise, execute S310. S307, Based on the ciphertext intermediate result and the private key required to perform homomorphic decryption, perform homomorphic decryption to obtain the plaintext intermediate state; S308, based on the current processing layer index and plaintext intermediate state, and records the point where the conversion occurs; S309, based on the plaintext intermediate state, continue to execute the calculation of all subsequent layers to obtain the plaintext of the final result; S310: Based on the ciphertext intermediate result, process the next layer in ciphertext state, update the index of the current processing layer, and then return to S302.

6. The privacy data computation method based on homomorphic encryption according to claim 1, characterized in that, The process of generating and publishing corresponding layered cryptographic commitments to a public evidence storage system based on plaintext intermediate states includes: S601, based on the plaintext intermediate state, traverse each plaintext intermediate state as the current commitment generation point; S602, For the current commitment generation point, select all plaintext intermediate states generated between the plaintext intermediate states corresponding to the current commitment generation point and the final result, so as to obtain a subset of plaintext intermediate states; S603, based on a preset vector commitment scheme, calculates all data in the plaintext intermediate state subset to obtain the corresponding hierarchical commitment; S604 publishes all generated hierarchical commitments and the final calculated commitment root hash to the pre-defined public notarization system.

7. The privacy data computation method based on homomorphic encryption according to claim 1, characterized in that, The step of encrypting the plaintext of the final result and returning the encrypted result to the client includes: S701, Based on the final plaintext result, a homomorphic encryption algorithm is used to perform an encryption operation to generate the final encrypted result; S702, the final encryption result is returned to the user terminal; S703, the user terminal decrypts the final encrypted result based on the private key to obtain the desired result.

8. The privacy data computation method based on homomorphic encryption according to claim 1, characterized in that, The process of analyzing the plaintext intermediate states corresponding to specific layered cryptographic commitments, generating zero-knowledge proofs, and responding includes: S801, Receive an audit challenge message from the auditor and parse the audit challenge message to obtain the challenged commitment index; S802, based on the challenged commitment index, retrieve the corresponding plaintext intermediate state from the local storage, and combine it with the preceding ciphertext intermediate result, the server private key and the model weight parameters to generate a private input tuple; S803, based on the challenged commitment index, obtain the corresponding hierarchical cryptographic commitment from the public evidence storage system, and combine it with the public encrypted input data and public computation graph to generate a public input tuple; S804, invoke the preset zero-knowledge proof algorithm, and perform a proof generation operation based on the private input tuple and the public input tuple to generate a zero-knowledge proof; S805, the zero-knowledge proof is encapsulated into a response message and sent to the auditor to complete the response to the audit challenge.

9. The privacy data computation method based on homomorphic encryption according to claim 1, characterized in that, The verification based on the received zero-knowledge proof includes: S701, based on a pre-defined public evidence storage system, obtains a public verification key, public input, and received zero-knowledge proof to obtain the data required for verification; S702, based on the data required for verification, a preset zero-knowledge proof verification algorithm is invoked to perform a verification operation on the zero-knowledge proof in order to obtain a verification result; S703, Based on the verification result, perform an honesty determination operation to obtain a server behavior determination result.

10. A system for implementing the privacy data computation method based on homomorphic encryption as described in any one of claims 1-9, characterized in that, include: The client-side data encryption and upload module is used to perform homomorphic encryption on personal privacy data to generate encrypted data and obtain the corresponding public computation graph; The complexity pre-analysis and transformation threshold setting module analyzes the publicly available computational graph to obtain the complexity score and dynamic transformation threshold of each layer in each logic layer. The plaintext intermediate state and plaintext generation module analyzes the encrypted data based on the complexity score and dynamic conversion threshold to obtain the plaintext intermediate state and the plaintext of the final result. Generate and publish layered cryptographic commitment modules, which generate and publish corresponding layered cryptographic commitments to the public evidence storage system based on plaintext intermediate states; The server returns an encryption result module, which is used to encrypt the plaintext of the final result and return the encrypted result to the client. The zero-knowledge proof generation module is used to analyze the plaintext intermediate state corresponding to the specific layered cryptographic commitment when an audit challenge is received, generate a zero-knowledge proof, and respond accordingly. The audit verification module performs verification based on the received zero-knowledge proofs.

Citation Information

Patent Citations

  • A data processing method based on privacy computing

    CN118332608B