Computer-implemented method and device for the distributed generation of correlated pseudorandomness
By partitioning instances into subsets for simultaneous computation, the method addresses inefficiencies in generating correlated pseudorandomness, achieving faster and more resource-efficient large-scale pseudorandomness generation.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-10-02
- Publication Date
- 2026-03-12
AI Technical Summary
Existing methods for generating correlated pseudorandomness are limited by the number of instances of secret-sharing functions and require significant computational time, making them inefficient for large-scale applications.
A computer-implemented method that partitions a set of instances into subsets for overlapping or simultaneous computation, utilizing hardware-based parallelization and network resources to optimize the generation of correlated pseudorandomness, allowing for efficient distribution and calculation across multiple computing facilities.
This approach significantly reduces computation time and resource utilization, enabling the generation of correlated pseudorandomness at scale while maintaining security and efficiency.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
State of the art
[0001] The invention is based on a computer-implemented method and a device for the distributed generation of correlated pseudorandomness.
[0002] In Boyle, E., Couteau, G., Gilboa, N., Ishai, Y., Kohl, L., Scholl, P. “Efficient Pseudorandom Correlation Generators from Ring-LPN” https: / / doi.org / 10.1007 / 978-3-030-56880-1 14 an example of a pseudorandom correlation generator is described in which secret sharing of functions is used.
[0003] For security reasons, the number of instances of the secret-sharing function is limited to a few thousand. Each instance comprises a function that calculates a partial piece of correlated pseudorandomness and an input value for that function. Each instance requires a runtime of several seconds. This partial information is determined in a distributed manner and combined locally to form the correlated pseudorandomness. Disclosure of the invention
[0004] The device and the method, particularly the computer-implemented method according to the independent claims, accelerate the calculation of the instances.
[0005] The computer-implemented method for the distributed computation of correlated pseudorandomness provides that a set of instances for sharing secrets of functions is specified, wherein each instance comprises a pair of a function for computing a partial piece of information of the correlated pseudorandomness and an input value for the function, wherein a partition of the set into subsets is provided, wherein the partition enables the at least partially overlapping computation of the results of several instances, wherein at least partially overlapping computation of the results of instances from at least a part of the subsets for the distributed generation of the correlated pseudorandomness is initiated by sending at least one message via a communication link or in response to receiving at least one message via a communication link.where at least one message includes or identifies a program for the distributed generation of the correlated pseudorandomness based on the decomposition.
[0006] It may be provided that the set is divided into subsets of the decomposition, particularly depending on a condition for the order in which the results are used according to a type of correlated randomness to be provided. For example, a correlated randomness of the type beaver triple specifies the conditions for the order.
[0007] It may be intended that the partially overlapping or simultaneous calculation of results from instances of a subset, which are independent of each other, is initiated or carried out.
[0008] It may be intended that the partially overlapping or simultaneous calculation of results from instances of different subsets is initiated or carried out.
[0009] It may be provided that the partially overlapping or simultaneous calculation of results of the instances of a subset, for which the calculation of the result of the individual instances within the subset is independent of the result of other instances of the same subset, is initiated or carried out.
[0010] It may be provided that the partially overlapping or simultaneous calculation of results of the instances of the subsets, for which the calculation of the result of the individual instances within the respective subset is independent of the result of other instances of the same subset, is initiated or carried out.
[0011] It may be provided that the instances which are to be calculated partially overlapping in time or simultaneously are assigned to different computing facilities for the calculation.
[0012] It may be provided that a result of the respective instance is calculated, wherein the calculation of the result of the respective instances includes a distributed point function (DPF) calculation, wherein the partially overlapping or simultaneous calculation of the result of two instances includes a partially overlapping or simultaneous calculation of the DPF calculation of the two instances.
[0013] It may be possible to determine the partitioning of the set into subsets depending on one or more computing and / or network resources available for calculating the results of the instances. This adapts the partitioning to the available resources.
[0014] Preferably, the partially overlapping or simultaneous calculation is performed, wherein the partially overlapping or simultaneous calculation includes hardware-based parallelization, in particular parallelization of arithmetic operations or pseudorandom number generators.
[0015] For example, the number of subsets and / or the size of at least one of the subsets is determined depending on the available memory of a computing device on which the result of at least one instance is to be determined, or of multiple computing devices on which the result of at least one instance is to be determined, or of network latency. This means that the number or size is adapted to the available memory or the network latency.
[0016] For example, a larger number of instances in a smaller number of larger subsets are chosen for a larger available memory than for a correspondingly smaller available memory, and / or a larger number of small subsets are chosen for a smaller available memory than for a correspondingly larger available memory. This means the number of instances is adjusted to the available memory.
[0017] It may be possible to determine a partition of the set into subsets for which the number of independent instances in the subsets is greater than for other partitions. This means that the largest possible number of instances that can be computed at least partially overlapping or in parallel over time is determined.
[0018] A device for the distributed generation of correlated pseudorandomness is configured to execute the procedure.
[0019] A computer program may be provided that includes instructions executable by a computer, the execution of which by the computer causes the procedure to take place.
[0020] Further advantageous embodiments can be found in the following description and the drawing. The drawing shows: Fig. 1 a schematic representation of a division of secrets between functions , Fig. 2. A schematic representation of a procedure for sharing secrets of functions with distributed provision of a description of the function to be shared. Fig. 3 a schematic representation of the procedure for sharing secrets of functions with distributed provision of the description of the function to be shared, wherein the function is composed of several correlated sub-functions, Fig. 4 a schematic representation of the procedure for sharing secrets of functions with distributed provision of the description of the function to be shared, wherein the provision is distributed over several steps, Fig. 5 a schematic representation of an example of a binary protocol tree that can be used for the secret sharing of functions, Fig. 6. A schematic representation of an example of uniting two trees to form a single tree. Fig. 7 an exemplary protocol for independent key generation for multiple distributed point functions, Fig. 8 an exemplary protocol for combined key generation for multiple distributed point functions, Fig. 9 a flowchart showing the steps of a procedure for the distributed generation of correlated pseudorandomness, Fig. 10 a sequence diagram of an exchange of messages for the distributed generation of correlated pseudorandomness.
[0021] Function secret sharing, i.e., function secret sharing, for a class C allows n parties P to i each a part f i (x) ∀x ∈ I of a function f(x) ∈ C that can be decomposed into n parts, with an algorithm depending on the input variable x of the function f(x) and depending on a private key k assigned to the respective party ican be determined. The function f(x) can be decomposed as follows in the example: f(x)=f1(x)+⋯+fn
[0022] The keys k i reveal no information about the function f.
[0023] The keys k i are generated depending on a description of the function f. The keys k i are generated, for example, by an independent, trusted party or via a secure protocol.
[0024] An example of a function f that can be used in the sharing of secrets of functions, and in particular for a Distributed Point Function (DPF), is a point function: fα,A:[0,N)→G|α∈[0,N),A∈G,fα,A(x)={0 if x≠αA if x=α where α denotes a position and A a value.
[0025] The point function f α,Ais completely described by the position α ∈ I and the value A ∈ G. For a realistic application, the value A and positions α are correlated.
[0026] Function secret sharing is described, for example, in Boyle, E., Gilboa, N., Ishai, Y. (2015). Function Secret Sharing. In: Oswald, E., Fischlin, M. (eds) Advances in Cryptology - EUROCRYPT 2015. EUROCRYPT 2015. Lecture Notes in Computer Science 0, vol 9057. Springer, Berlin, Heidelberg. https: / / doi.org / 10.1007 / 978-3-662-46803-6_12
[0027] DPF is e.g. in Gilboa, N., Ishai, Y. (2014). Distributed Point Functions and Their Applications. In: Nguyen, PQ, Oswald, E. (eds) Advances in Cryptology - EUROCRYPT 2014. EUROCRYPT 2014. Lecture Notes in Computer Science, vol 8441. Springer, Berlin, Heidelberg. https: / / doi.org / 10.1007 / 978-3-642-55220-5_35.
[0028] Secure Multiparty Computation, MPC, can use an offline phase independent of input size x to generate secret shared correlated randomness, which is consumed in an online phase dependent on input size x.
[0029] One way to create the offline phase is a pseudorandom correlation generator (PCG). A PCG based on the sharing of secrets of functions is described in Boyle, E., Couteau, G., Gilboa, N., Ishai, Y., Kohl, L., Scholl, P. (2020). Efficient Pseudorandom Correlation Generators from Ring-LPN. In: Micciancio, D., Ristenpart, T. (eds) Advances in Cryptology - CRYPTO 2020. CRYPTO 2020. Lecture Notes in Computer Science(), vol 12171. Springer, Cham. https: / / doi.org / 10.1007 / 978-3-030-56880-1_14.
[0030] The following describes a PCG based on randomly distributed functions in class C.
[0031] This means that the class C is referred to as the probability space C{f ω : I - G|ω ∈ Ω}, where Ω is a probability space on the descriptions of the functions in class C.
[0032] For example, the probability space Ω = [0, N) × G is described for the class C of point functions. The set of function descriptions Ω encodes the function class C ≃ Ω .
[0033] A program for generating Beaver Triples over a finite field F It can look like this (Efficient Pseudorandom Correlation Generators from Ring-LPN). How the pseudorandom correlation generator (Bt-PCG) works:
[0034] The Bt-PCG functions over a polynomial R over F modulo F, where F is a polynomial of degree N (and factors completely into linear factors). Let R tthe set of t-thin N-dimensional polynomials in R, i.e., polynomials that are 0 everywhere except for t coefficients.
[0035] In the following, [·] denotes a linear secret sharing scheme over F or the ring R, where the coefficients are over F are individually and secretly shared with [·].
[0036] The principle of Bt-PCG is as follows: Let [u], [v], [w] be secret-shared c-dimensional vectors of polynomials where • u∈Rtc,v∈Rtc are random • w=u⊗v∈Rt2c×c corresponds to the tensor product His r ∈ R c randomly. Then it follows from the ring-LPN conjecture that the R scalar products [x]=<[u],r>c,[y]=<[v],r>c,[z]=<[w],r⊗r>c×c To describe a beaver triple [x] · [y] = [z] in R, which is equivalent to N beaver triples over IF for the above F.
[0037] The local part of the Bt-PCG consists of calculating [x], [y], [z] from [u], [v], [w], r.
[0038] First, the interactive part of the Bt-PCG consists of generating [x], [y], [z]. This can be done using distributed point functions, each of which describes an "entry" of u, v, w. These are correlated as follows: Let α ∈ [0, N) ct the positions (non-zero points) of u and β ∈ [0, N) ct Given the positions of v, then w has the positions γ=α⊞β∈[0,N)ct×ct (Tensor sum). The values α, β, y must remain secret between the parties. Let A∈Fct the values (at the non-zero places) of u and B∈Fct Given the positions of v, then w has the positions C=A⊗B∈Fct×ct. Values A, B, and C must remain secret between the parties.
[0039] In Fig. Figure 1 is a schematic representation of a secret division of functions, for example, for an MPC algorithm with one input variable x and two parties, namely a first party P0 and a second party P1. The algorithm can be applied to many input variables x at once.
[0040] According to the first example, the procedure includes step 102.
[0041] In step 102, a description ω is drawn from the distribution Ω.
[0042] Then step 104 is executed.
[0043] In step 104, a first key k0 and a second key k1 are determined based on the description ω. The first key k0 is provided to the first party P0. The second key k1 is provided to the second party P1.
[0044] Then, step 106 and step 108 are executed.
[0045] In step 106, a first part y0 of an evaluation of the random function f is performed. ω calculated at the position defined by the input variable x and the first key k0.
[0046] In step 108, a second part y1 of the evaluation of the random function fω is calculated at the point defined by the input variable x and the second key k1.
[0047] In Fig. 2 is a method for sharing secrets of functions with distributed provision of the description ω of the function to be shared, for example for the MPC method, shown schematically.
[0048] For example, in step 102, a first part [ω]0 of the description is drawn from the distribution Ω for the first party P0 and a second part [ω]1 of the description is drawn for the second party P1.
[0049] For example, in steps 104 and 106, the first key k0 is interactively determined depending on the first part [ω]0 of the description and depending on the second part [ω]1 of the description, as is the second key k1. Information about these parts is exchanged interactively between the parties.
[0050] In Fig. Figure 3 schematically illustrates the method for sharing the secrets of functions with distributed provision of the description ω of the function to be shared, for example, for the MPC method, where the function is composed of several correlated subfunctions. The description for the function, which is composed of several correlated subfunctions, is given in the form of several parameters; for example, several point functions with corresponding positions and values are given. The distribution Ω is, for example, the product of t mutually correlated parts Ω. i specified: Ω=Ω1×…×Ωt
[0051] According to the second possibility, in step 102 t descriptions ω1, ...,ω are entered. t The distributions Ω1, ..., Ωt from the description are drawn. In the example, each of the distributions Ω1, ..., Ω is used. t one of the descriptions ω1, ..., ω t pulled.
[0052] In step 104, the first key k0 and the second key k1 are determined depending on the descriptions ω1, ..., ω t certainly.
[0053] According to a second example of the procedure, it may be provided that determining the keys and drawing the description or parts of the description are carried out in a common step, instead of carrying out steps 102 and 104 one after the other. Configurable sharing of secrets from functions
[0054] According to a third example of the procedure, a configurable function secret division is provided. The configurable function secret division stipulates that the parameters determining the random function f are individually selected from a distribution. Ω=Ωcond×Ωpre×Ωpost to be drawn, with the following options being provided, for example: a parameter ω cond ∈ Ω cond The distribution Ω is used before step 102. cond pulled, a parameter ω pre ∈ Ω pre In step 102, the distribution Ω is used. Pre pulled, a parameter ω post ∈ Ω post During step 104, the distribution Ω is used. post pulled.
[0055] The parameter ω cond ∈ Ω cond ω is a conditional variable in the procedure, which is specified, for example, without any indication of how the variable was determined. An example of the parameter ω cond ∈ Ω cond is an MPC Message Authentication Code key (MPC MAC key).
[0056] The parameter ω pre ∈ Ω pre is a variable in the procedure that is specified before the respective key is generated.
[0057] The parameter ω post ∈ Ω post is a variable of the procedure that is specified after the generation of the respective key.
[0058] The distributions Ω cond , Ω pre , Ωpost can be stochastically independent of each other. The distributions Ω cond , Ω pre , Ω post can be stochastically dependent on each other. One or more of the distributions Ω cond, Ω pre , Ω post can be empty sets.
[0059] In Fig. 4 is the procedure for sharing secrets of functions with distributed provision of the description of the function to be shared, for example for the MPC procedure for the parties, namely the first party P0 and the second party P1, where the provision is distributed over different steps.
[0060] According to the second example, a random parameter ω is added before step 102. cond ∈ Ω cond provided, e.g. an MPC MAC key.
[0061] According to the second example, step 102 is then executed. According to the second example, in step 102 the parameter ω is passed from the parties.pre ∈ Ω pre subject to the parameter ω cond pulled: ωpre←Ωpre|ωcond
[0062] According to the second example, step 104 is then executed. According to the second example, in step 104 the parameter ω is passed from the parties. post ∈ Ω post subject to the parameter ω cond and the parameter ω pre pulled: ωpost←Ωpost|ωcond,ωpre In the example, the parameter ω includes the parameters ω con , ω pre , ω post ,
[0063] Information about the parameter ω is exchanged interactively between the parties.
[0064] According to the second example, steps 106 and 108 are then executed.
[0065] In one example, the configurable secret sharing of functions looks like a class C* = {f ω : I → G|ω ∈ Ω} ≃ Ω, where Ω = X t∈T Ω t, where T is decomposed into T = T cond × T pre ∪ T post and the respective Ω t As described for Ω, it is decomposed into Ω. cond × Ω Pre ∪ Ω post , i.e.: Ωcond=Xt∈TcondΩt Ωpre=Xt∈TpreΩt Ωpost=Xt∈TpostΩt
[0066] For generating keys, for example, a first algorithm K is provided. The first algorithm K is probabilistic and has, for example, the following syntax: where λ is a safety parameter and $← An assignment is represented by random drawing.
[0067] For a complete evaluation, a second algorithm E is provided. The second algorithm E is deterministic and has, for example, the following syntax: E σ (k σ ), where the index σ denotes the party for which the algorithm E is executed, and where k σThe key of the party is denoted. The output of the second algorithm is R. σ ∈ G I .
[0068] The correctness of the algorithms is ensured, for example, by ensuring that ω is used for all descriptions. cond ∈ Ω cond , ω pre ∈ Ω Pre the following condition is met: Pr(∑σEσ(kσ)=(fω(x))x in l|(k0,k1,ωpost)$←K(1λ,ωpre))=1
[0069] The safety of the algorithms is ensured, for example, by the fact that ω is used for all descriptions. cond ∈ Ω cond The following distributions are indistinguishable by calculation: {(kσ,ω)|ωpre$←Ωpre,(k0,k1,ωpost)$←K(1λ,ωcond,ωpre)} and {(kσ,ω)|ωpre$←Ωpre,(k'0,k'1,ωpost)$←K(1λ,ωcond,ωpre)$←Sim(1λ,L(ω))} where L(ω): {0,1} λ → {0,1} λ denotes a permissible outflow of information. Parallelization of DPF calculation
[0070] For DPF calculation, one instance of a defined DPF protocol is used for each party. Parallelization is based on the fact that mathematical operations and pseudo-random number generators (PRGs) are calculated in parallel not only within a single instance but also for multiple different instances.
[0071] In Fig. 5 is a schematic example of a binary tree 500 that can be used for the secret sharing of functions.
[0072] The tree includes first node 502 and second node 504.
[0073] The binary tree 500 is generated in a first phase. In the first phase, a value of the form s is secretly shared between the two parties, i.e., the first party P0 and the second party P1. n ∈ ({0,1} λ ) N generated, which is the same for both parties except for the position α ∈ [0, N). In the example, λ is a security parameter and N = 2 n .
[0074] For example, a depth n of tree 500 is specified. The nodes of tree 500 are assigned values s. i,j ∈ {0,1} λ , 0 ≤ i < n, 0 ≤ j < 2 i identified, with the tree having 500 levels, each containing a value s i of 2 i multiply {0,1} λ Define values that meet the following condition: s0i,j≠s1i,j⇔j=(αn−1…αn−i)2 where sσi,j the j-th node of party P σ on the level i and α = (α n ... α0)2 is the binary representation of α.
[0075] In a first level 506, the parties each choose a random private value. sσ0,0.
[0076] In an example for n=3 levels, the tree 500 comprises, after the first level 506, a second level 508, a third level 510, and a fourth level 512, in this order. For n>3, the tree 500 has more than three levels.
[0077] To move from one level to the next level of the 500 tree, the DPF protocol stipulates that the parties locally double the length of the values provided by the PRG, i.e., PRG: {0,1} λ → {0,1} λ × {0,1} λ to assign a new value PRG to each node of the next level (sσi,j)=(s¯σi+1.2j,s¯σi+1.2j) to be defined. The new values do not meet the condition. The new values differ in two ways, namely s¯σi+1,(αn…αn−10)2 and s¯σi+1,(αn…αn−11)2. In the example, the new values are applied to sσi+1,∗ Values corrected.
[0078] For example, doubling the length is based on two calls to an Advanced Encryption Standard (AES) block code that pseudo-randomly shuffles 128 bits. If λ = 80, the PRG is implemented, for example, with two AES calls and appropriate masking.
[0079] For example, the two AES calls are executed completely independently and in parallel. This is achieved, for example, by using AES in ECB block cipher mode.
[0080] In a second phase, the values are transformed into a unit vector S ∈ G, secretly shared between the two parties, in an output format. For example, in the second phase, a value sσn, transformed into an N-dimensional vector. For example, the value sσn by calling a PRG: {0,1} λ → G is generated.
[0081] In the second phase, the nodes are corrected via G in such a way that differing values at a position α represent the payload A of the DPF.
[0082] Optionally, verification is provided to detect harmful behavior by a compromised party.
[0083] The first phase, i.e., the invocation of the PRG, is interactive in this example, meaning it involves communication. The second phase, specifically the correction, requires communication between the parties. In this example, the communication takes place via a shared communication channel.
[0084] The in Fig. The tree 500 shown comprises, after the start 514, a first local call of PRG 516 and a first interactive correction 518 to determine the values of the second level 508, a second local call of PRG 520 and a second interactive correction 522 to determine the values of the third level 510, a third local call of PRG 524 and a third interactive correction 526 to determine the values of the third level 510, a fourth local call of PRG 528 and a fourth interactive correction 530 to determine the values of the fourth level 512.
[0085] In the example, in the fourth level 512, the payload A is assigned to a leaf 532 of the tree 500. The random position of the payload A is assigned to a node 534 of the fourth level 512. The remaining leaves of the tree 500 are assigned the value zero. The remaining nodes of the fourth level 512 are also assigned the value zero.
[0086] The parallelization process involves combining several trees into one common tree.
[0087] Fig. Figure 6 provides an example of uniting a first tree 602 and a second tree 604, i.e., two trees, to form a common tree 606. For more than two trees, the common tree is generated accordingly.
[0088] In the example for n=3, the two trees comprise, after the start 608, a local call 610 of the PRG followed by a first interactive correction 612, two local calls 614 of the PRG followed by a second interactive correction 616, four local calls 618 of the PRG followed by a third interactive correction 620. In the case of n>3, more rounds are provided.
[0089] The shared tree includes two starts 622, i.e., one start per party. After the starts 622, the shared tree includes two single local calls 624 of the PRG followed by a first interactive correction 626, two sets of two local calls 628 of the PRG followed by a second interactive correction 630, four sets of four local calls 632 of the PRG followed by a third interactive correction 634.
[0090] The call to PRG is an example of a parallelizable operation. This means that the parallelizable operations of one level of the two trees are combined in the common tree 606 at the same level. A second example is a correction of the values. sσn with only one communication channel, whereby a constant number of communication rounds is provided.
[0091] Calls from the same level are made, for example, in a single computation step. This allows for a greater number of parallel calls than would be possible without grouping them in a common tree.
[0092] The procedures are described for the first party P0 and the second party P1. For an MPC with more than two parties, the procedure is carried out for each party as described for the first party P0 and the second party P1.
[0093] For a single DPF at level i, for example, a hardware module with AES instruction set extension with 2 is used. i+1independent AES calls are made. For the parallel execution of the DPF, the parallelization rate of the AES calls can be set to k2. i+2 can be held regardless of the number of trees k.
[0094] For example, a common communication channel is provided for d trees. For example, for m levels per tree, instead of dm calls to the PRG and instead of dm corrections, the parallelization rate is increased by a factor of d. In the case of 2 i Calling the PRG at each level i, for example, results in a higher parallelization rate of d2 by concatenating the vectors for calling the PRG and subsequently splitting the output of the PRG accordingly. i+1 reached.
[0095] For example, the parallelization rate is adjusted depending on the level at which parallelization is performed. For instance, a lower parallelization rate is determined as the level increases in height. The parallelization rate is determined based on a threshold value for the level's height. In this example, the height decreases with the level's distance from the tree root, which represents the starting point of the process. This prevents the parallelization from reaching or exceeding memory limits.
[0096] In Fig. Figure 7 schematically depicts part of an exemplary pass through a tree for a protocol for independent, sequential key generation for multiple distributed point functions. The example includes k = 1, ..., d instances of the DPF.
[0097] The example iteration assumes that the nodes of the binary protocol tree are labelled level by level with values from {0,1}, starting from a randomly selected root of the protocol tree.
[0098] The first party P0 and the second party P1 each draw a random value in one step 702. sσ0,0←{0,1}λ.
[0099] Each level i = 0, ..., n - 1 and node j of level i are randomized in step 704 using a pseudorandom number generator PRG: {0,1} λ → {0,1} 2λ Values (rσi+1,2jrσi+1,2j+1)=PRG(sσi,j) determined. σ denotes the index of the party to which the value is assigned.
[0100] For example, for the level i = 0, it is highly likely that... s00,0≠s10,0. For example, for the level i = 0, it is highly likely that... r01,0≠r11,0 and r01,1≠r11,1.
[0101] For the DPF at level i = 0, an invariant is needed that indicates whether r01,0=r11,0 or r01,1=r11,1. The invariant is private information that indicates which of the pairs of values r01,0,r11,0 and r01,1,r11,1 is the same. Which of the pairs of values r01,0,r11,0 and r01,1,r11,1 The fact that it is the same is secret information, i.e., it remains hidden from parties P0 and P1.
[0102] In step 706, the first party P0 and the second party P1 execute a correction procedure that determines the invariant. The correction procedure used depends on the chosen DPF protocol. For example, the correction procedure uses interactive arithmetic over {0,1}. λ .
[0103] Step 706 is executed iteratively for the levels i = 1, ...,n - 1.
[0104] For each level i, the first party P0 determines the invariants using the correction procedure. (r0i+1,2j,r0i+1,2j+1)←PRG(s0i,j) a value s0i+1 and a key key0i
[0105] For each level i, the second party P1 determines the invariants using the correction procedure. (r11+1,2j,r1i+1,2j+1)←PRG(s1i,j) a value s1i+1 and a key key1i.
[0106] For example, the correction procedure includes c0 rounds of communication.
[0107] The keys key1i encode the DPF.
[0108] For the last level i = n, the values are sσn,j determined and for small values of l into a ring F or more generally for values of l into an l-dimensional ring F l converted: {0,1}λ→Fl
[0109] For the last level i = n, for example, a conversion function Conv is used for each instance k from the vectors of values. sσ,ki,j the values hσn,j certainly: Fl:hσn,j←Conv(sσ,ki,j) The conversion function is, for example, a PRG.
[0110] In step 708, the first party P0 and the second party P1 perform a correction procedure on the values h determined for the first party P0. o and the value h1 determined for the second party P1 from the ring F l out, which the ring F l corrected. The correction procedure used depends on the selected DPF protocol. For example, the correction procedure uses interactive arithmetic over the ring F. l For example, the correction procedure includes c1 rounds of communication.
[0111] If the correction procedure is successful, the key will be keyσn Output. Otherwise, an error (fail) will be signaled.
[0112] The DPF output is key key00,…,key0n. Several such DPF keys form a PCG seed. For the first party P0, a first seed seed0 is determined as a result. For the second party P1, a second seed seed1 is determined as a result.
[0113] In Fig. Figure 8 schematically illustrates an exemplary protocol for combined, particularly partially overlapping or parallel, key generation for multiple distributed point functions. The example schematically depicts DPF instances k = 1, ..., d.
[0114] The exemplary joint protocol proposes that in one step 802, each party shall have a vector of roots sσ,k0,0(1≤k≤d) is determined.
[0115] The first party P0 determines a first vector s0,k0,0←({0,1}λ)d.
[0116] The second party P1 determines a second vector s1,k0,0←({0,1}λ)d
[0117] The common protocol stipulates in step 804 that values for a level i (rσ,ki+1,2jrσ,ki+1,2j+1)=PRG(sσ,ki,j) is determined.
[0118] In step 806, the first party P0 and the second party P1 execute a correction procedure that jointly determines the invariants. The correction procedure used depends on the chosen DPF protocol. For example, the correction procedure uses interactive arithmetic over {0,1}. λ , where the number of communication rounds is the same for each dimension and the information exchanged in the communication rounds is sent together in each round.
[0119] Step 806 is executed jointly for the levels i = 1, ...,n - 1.
[0120] For each level i, the first party determines P0 using the correction procedure. (r0i+1,2jr0i+1,2j+1)←PRG(s0i,j) a value s0i+1 and a key key0i
[0121] For each level i, the second party P1 determines new values for the nodes in level i + 1. These new values initially violate the invariant. The correction procedure then determines the values for level i + 1. (r1i+1,2j,r1i+1,2j+1)←PRG(s1i,j) a value s1i+1 and a key key1i certainly.
[0122] For example, the correction procedure includes c0 rounds of communication.
[0123] The keys key1i Code the DPF.
[0124] For the last level i = n, the values are sσn,j determined and for small values l into a field F l converted: {0,1}λ→Fl
[0125] For the last level i = n, a conversion function Conv common to all instances is used to convert the vectors of values. sσ,ki,j the values hσ,kn,j certainly: Fl:hσ,kn,j←Conv(sσ,ki,j) The common conversion function is, for example, a PRG.
[0126] In step 808, the first party P0 and the second party P1 perform a correction procedure using the values h0 and h1, respectively, determined for the first party P0 and the second party P1, from the field F. l out, which field F l corrected. The correction procedure used depends on the selected DPF protocol. For example, the correction procedure uses interactive arithmetic over field F. l For example, the correction procedure includes c1 rounds of communication.
[0127] If the correction procedure is successful, the key will be keyσn Output. Otherwise, an error (fail) will be signaled.
[0128] For the first party P0, a first seed seed1 is determined as a result. For the second party P1, a second seed seed1 is determined as a result. Each seed comprises the determined key components. key0,di. DPF evaluation algorithm
[0129] A DPF evaluation algorithm uses a DPF key. (keyσ0,…,keyσn) to evaluate a DPF coded according to the DPF scheme. For this, the procedure is performed as described, for example, in the example protocol for calculating the DPF instance or in the example joint protocol for calculating the DPF instances, whereby steps 706 and 708 or steps 806 and 808 are executed locally by the respective party, i.e., without communication with the other party.
[0130] It is intended that the relevant part of the bowl (keyσ0,…,keyσn) This is an input variable of the correction procedure. The correction procedure stipulates that the input variable is used instead of the correction via field F. l The portion of the DPF determined by the respective key is identified and output. Verification, i.e., determining whether the correction procedure is successful or whether an error (fail) is signaled, is not required.
[0131] In the event that the two parties agree on a 2 without calculating the DPF key n If one wants to secretly exchange a dimensional unit vector, i.e., secretly exchange every coefficient among themselves in a complete evaluation, the steps for calculating the keys can be omitted. Computation of the PCG based on subsets of a set of instances for sharing secrets of functions
[0132] The PCG uses a large number of instances, specifically more than one hundred, more than one thousand, or more than five thousand. These constitute the set of instances. The set of instances is divided into subsets. At least some of the subsets are computed partially overlapping or simultaneously.
[0133] If the calculation of individual instances within a subset is independent of the result of other instances of the same subset, the instances of the subset are calculated partially overlapping in time or simultaneously.
[0134] If the calculation of a single instance within a subset depends on a result of the calculation of another instance within the subset, the partially overlapping or simultaneous calculation is restricted, for example, to the independent instances.
[0135] The calculation can be performed locally by one party using hardware-based parallelization, e.g., by parallelizing arithmetic operations or PRGs.
[0136] For example, the parallelization described in the section on parallelization of the DPF calculation is used.
[0137] Depending on the available hardware, for example, the system chooses to parallelize either a small number of large subsets or a large number of small subsets, depending on the available memory of the computing unit(s) on which the respective processes are executed. For instance, a larger number of instances in a smaller number of larger subsets are chosen for a larger amount of available memory than for a smaller amount of available memory. Conversely, a larger number of small subsets are chosen for a smaller amount of available memory than for a larger amount of available memory. Thus, depending on the available hardware, the system optimizes for a balance between the amount of memory required and the number of parallelized calculations.
[0138] It may be anticipated that a latency will occur due to the complexity of a local link L between instances, for example, if one instance has to wait for the result of another instance. Depending on the complexity of the local link, for instance, a balance is optimized between the size of the subset and the number of subsets.
[0139] This optimizes the costs of performing the calculation depending on the available computing facilities.
[0140] Fig. Figure 9 presents a flowchart illustrating the steps of a procedure for the distributed generation of correlated pseudorandomness. The procedure involves initiating distributed generation and / or the distributed generation of correlated pseudorandomness. It utilizes a set of instances for sharing the secrets of functions, specifically DPF instances. Each instance comprises a pair consisting of a function for calculating a partial piece of information about the correlated pseudorandomness and an input value for the function. For example, a DPF instance includes a DPF protocol and a distributed description of the function to be shared.
[0141] The procedure includes step 902.
[0142] In step 902, a decomposition of the set into subsets is determined.
[0143] For example, a partition of the set into the subsets of the partition is determined depending on a computing facility available for calculating the results of the instances.
[0144] For example, a partition of the set into the subsets of the partition is determined depending on several computing facilities available for calculating the results of the instances.
[0145] For the decomposition, a number of subsets are determined. The decomposition into subsets yields a size for each subset.
[0146] The number is determined, for example, by available computing and / or network resources. The number is determined, for example, by the available computing resource of a computing facility on which the result of at least one instance is to be determined. An example of a computing resource is memory. An example of a network resource is network latency.
[0147] The number is determined, for example, depending on the available memory of several computing devices, on each of which the result of at least one instance is to be determined.
[0148] It may be possible to determine the size of the subsets instead of the number, as described for the number. Then the number of equally sized subsets results from the determined size.
[0149] For example, a larger number of instances in a smaller number of larger subsets are chosen for a larger available memory than for a correspondingly smaller available memory.
[0150] For example, a larger number of small subsets are chosen for a smaller available memory than for a correspondingly larger available memory.
[0151] The subsets are optimized, for example, to contain the largest possible number of instances that can be computed at least partially in parallel. For instance, a partition of the set into subsets is determined that contains the largest possible number of independent instances, limited by the available resources. Alternatively, a partition of the set into subsets is determined that contains a greater number of independent instances than another partition.
[0152] It may be stipulated that the set is subdivided into subsets, depending in particular on a condition for the order in which the results are subdivided according to a type of correlated randomness to be provided. The correlated randomness is, for example, of the type beaver triple. This means that the subsets are determined under the condition that they are suitable for the type beaver triple.
[0153] For example, the program for generating Beaver Triples over the finite field looks like this: F a disassembly. Example dissections:
[0154] The simplest decomposition (Decomposition 1) distinguishes between the point functions u, v, u, v, w, and separates the LPN transformation between x, y, z. This simplest decomposition provides programs to calculate c, y, z that are not further decomposed.
[0155] Another decomposition (decomposition 2) provides for the (ct) 2 many point functions for w in c 2 many subsets of dimension t 2 to disassemble.
[0156] It may also include a decomposition of other calculation steps, or a coarser or finer decomposition of the w-component.
[0157] The procedure includes step 904.
[0158] In step 904, a calculation of the results of instances from at least a part of the subsets is initiated for the distributed generation of the correlated pseudorandomness by sending at least one message via a communication link or in response to receiving at least one message via a communication link, with at least a partial temporal overlap of the results.
[0159] For example, it is stipulated that at least one message includes or identifies a program for the distributed generation of correlated pseudorandomness based on decomposition.
[0160] At least one message is transmitted, for example, to at least one computing unit with which the instances are to be calculated. The communication link over which the at least one message is transmitted includes, for example, a data bus or a telecommunications link to the respective computing unit.
[0161] The procedure provides, for example, that the partially overlapping or simultaneous calculation of results from instances of a subset that are independent of each other is initiated or carried out.
[0162] The procedure provides, for example, that the partially overlapping or simultaneous calculation of results from instances of different subsets is initiated or carried out.
[0163] Partially overlapping or simultaneous computations are executed as instructed. Partially overlapping or simultaneous computations include, for example, hardware-based parallelization. Parallelization includes, for example, the parallelization of arithmetic operations. Parallelization includes, for example, the parallelization of process algorithms.
[0164] In this example, a result is calculated for each instance. Calculating the result for each instance includes, for example, a DPF calculation for each instance. The partially overlapping or simultaneous calculation of the result for two instances includes, for example, a partially overlapping or simultaneous calculation of the DPF calculation for both instances.
[0165] It may be provided that the overlapping or simultaneous calculation takes place on a single computing unit. It may be provided that the overlapping or simultaneous calculation takes place on different computing units. It may be provided that the instances for the overlapping or simultaneous calculation are assigned to a single computing unit. It may be provided that the instances for the overlapping or simultaneous calculation are assigned to different computing units.
[0166] It can be provided that individual, independent instances from a subset are computed at least partially overlapping in time. For example, the result of an instance of a subset, which is independent of the result of other instances of the same subset, is computed partially overlapping in time or simultaneously with the result of at least one other instance of the same subset.
[0167] It may be provided that several independent instances from a subset are computed at least partially overlapping in time. For example, the results of instances within a subset, for which the computation of the result of the individual instances within the subset is independent of the result of other instances of the same subset, may be computed partially overlapping or simultaneously.
[0168] It may be stipulated that instances from different subsets are computed at least partially overlapping in time. For example, the results of instances in subsets where the computation of the result of individual instances within the respective subset is independent of the result of other instances in the same subset may be computed partially overlapping or simultaneously.
[0169] An example program flow for calculations with Beaver Triples includes the following steps: Generating the vector u using a subprogram for distributed point functions. This subprogram executes ct instances in parallel and is further defined by instructions to determine the values α,A (as ω). post) Generating the vector v using a subprogram for distributed point functions. This subprogram executes ct instances in parallel and is further defined by instructions such that it also determines the values β and B (in secretly shared form).
[0170] Executing an interactive subprogram that γ=α⊞β calculated in a manner shared in secret.
[0171] Executing an interactive subprogram that calculates C = A ⊗ B in a secret-sharing manner.
[0172] Generating the vector w using a subprogram for distributed point functions, given the values γ, C (as ω) pre Depending on the decomposition, this is done by calling subprograms for the secret sharing of dot functions in decomposition 1 or c. 2 Calls for the decomposition of subprograms for the secret division of dot functions.
[0173] The further instructions ensure that the input and output files (the coefficients of α, β, A, C) are correctly assigned.
[0174] Executing a local subprogram to transform the secret-shared values u, v, w in beaver triple via F, the calculation follows the scalar products.
[0175] In Fig. Figure 10 shows an exemplary sequence diagram of a message exchange for the distributed generation of correlated pseudorandomness using a client-server model. The first party, P0, acts as the server, and the second party, P1, acts as the client.
[0176] In step 1002, the first party P0 sends a request to the second party P1 to generate distributed correlated randomness.
[0177] The request includes, for example, the type and quantity and the planned time t of provision.
[0178] In step 1004, the second party P1 sends to the first party P0 the resources of the second party P1 available to generate distributed correlated randomness according to the request.
[0179] The first party P0 determines the subset of instances for generating the distributed correlated randomness depending on the resources available to the first party P0 and the second party P1.
[0180] In step 1006, the first party P0 sends a message to the second party P1, which includes a program sequence for generating the correlated pseudorandomness.
[0181] The program flow includes, for example, instructions for creating a program to execute subsets for the secret sharing of functions. The program flow also includes, for example, instructions for program steps that correlate the secret sharing of functions.
[0182] The program flow is, for example, the program flow for calculations using Beaver Triples.
[0183] In step 1008, the second party P1 sends its consent or feedback to the first party P0 for a re-execution of step 1006.
[0184] The first party P0 and the second party P1 each generate, in step 1010, the program for generating the respective partial information for the correlated pseudorandomness, depending on the program flow. The program includes, for example, the execution of the subsets for the secret division of functions and the steps that correlate the secret division of functions.
[0185] In step 1012, the first party P0 sends a message to the second party P1 that includes or identifies a program for the distributed generation of correlated pseudorandomness based on the decomposition.
[0186] The example assumes that the first party P0 and the second party P1 each already have different programs, each designed to generate correlated pseudorandomness based on a specific decomposition.
[0187] This means that the first party P0 informs the second party P1 in the message which program the second party P1 should execute. In this example, the first party P0 informs the second party P1 of the program that the first party P0 will also execute for the distributed generation of correlated pseudorandomness based on the decomposition.
[0188] The program is chosen, for example, depending on program parameters that define the program.
[0189] The program parameters specify, for example, the size, i.e., the scope of the correlated randomness to be generated, e.g., the number N = 2. nThe parameters to be generated are Beaver triples, or the number of distributed dot functions, i.e., the parameter d = c · t. Other program parameters may also be provided, e.g., a security level, for which a number of distributed dot functions and a way in which these should be summed and combined are derived from the ring-LPN conjecture.
[0190] The program defines the necessary steps for the distributed generation of correlated pseudorandomness.
[0191] The program parameters influence the number of instances required, or the size of the individual instances, and thus also the number of steps required in the program.
[0192] The program is executed based on the program parameters.
[0193] The task of a program is to execute the pseudorandom correlation generator.
[0194] There can be several programs provided for a given pseudorandom correlation generator, which differ in how the pseudorandom correlation generator is executed.
[0195] The choice of program and program parameters depends, for example, on the requirements of the MPC protocol, e.g., security guarantees, and the available computing resources.
[0196] The output of each program is to generate correlated pseudorandomness in several steps using the pseudorandomness correlation generator executed by the program. The scope of the correlated pseudorandomness is determined by the program parameters.
[0197] Each program includes the execution of various subprograms, for example: • A subprogram for sharing secrets of functions, especially distributed point functions • Subprograms to correlate different instances of function secret sharing • A subprogram to transform the output of the subprograms for sharing secrets of functions into correlated pseudorandomness.
[0198] According to a first example, the subprograms for secret sharing of functions consist of two parts: the protocol for key generation and the evaluation algorithm.
[0199] According to a second example, the subprograms for secret sharing of functions consist of a single protocol that combines the key generation and the evaluation algorithm, e.g. the construct described in “Efficient Pseudorandom Correlation Generators from Ring-LPN”.
[0200] The subprograms for correlating different instances of the secret division of functions follow the probability space Ω.
[0201] The subprogram for transforming the outputs of the subprograms for sharing secrets of functions includes, for example, linking the outputs of the other subprograms and applying a cryptographic transformation, for example, given by the ring-LPN assumption ("Efficient Pseudorandom Correlation Generators from Ring-LPN").
[0202] The subprograms are either algorithms that the parties execute locally or interactive protocols. For example, the subprogram to transform the output of the secret-sharing function subprograms is a local algorithm, and the subprograms to correlate different instances of secret-sharing functions are interactive protocols.
[0203] It may be possible for each subprogram to execute different instances of its associated task in parallel. The task here refers, for example, to the secret sharing of functions, the correlation of several secretly shared functions, or the transformation of a single secretly shared function.
[0204] The pseudorandom correlation generator provides a set of instances for each task. The size of these sets depends on the program parameters.
[0205] Different programs differ in how the sets of instances are decomposed into subsets.
[0206] The execution of a program consists of executing subprograms, with each subset of instances being assigned the execution of one subprogram. This means, in particular, that each subprogram executes exactly as many instances as the subset contains. The execution of the subprograms involves running the instances in parallel; for example, instances for calculating distributed point functions, as in Fig. 6 can be described as parallelized.
[0207] The execution of a program refers to the execution of subprograms for all tasks.
[0208] Different programs that use the same subset partitioning may differ in the chronological order of execution of the subprograms.
[0209] Different programs that use the same subset partitioning may differ in the allocation of subprograms to available computing resources.
[0210] When executing a program, it is particularly intended to run different subprograms for different instances in parallel on different computing devices.
[0211] Each subprogram receives the program parameters, or at least partial information about them, as input, along with further instructions. In particular, the number of instances to be executed can be determined from this.
[0212] The other instructions include, for example, input and output files, which link the execution of various subprograms.
[0213] The additional instructions allow you to specify the execution of a subprogram. For example, the pseudorandom correlation generator can be configured to specify that the function size of the instances of the secret sharing function is different. The additional instructions then define, for example, the function size of the secret sharing function for a given execution of a subprogram.
[0214] Different values of the program parameters result in programs that define different work steps. These different work steps can have different resource requirements, for example, regarding memory or communication.
[0215] For example, by choosing the values of the program parameters, the program is determined that optimizes the type and number of work steps with regard to resources.
[0216] For example, the values of the program parameters are determined, which adapt the resulting program to the available resources.
[0217] For example, by choosing the values of the program parameters, the program is determined that optimizes the type and number of work steps with regard to the benefit of parallelization.
[0218] For example, the values of the program parameters are determined, resulting in a decomposition with the greatest possible parallelization, limited by available resources.
[0219] The first party, P0, identifies the available resources and derives from this a choice of parameters that is suitable for the resources or optimized with regard to the benefits of parallelization. The first party, P0, determines the decomposition for the chosen parameters.
[0220] The choice of program parameter values and the decomposition do not yet determine which input values the second party P1 must choose for the individual instances. The input values are defined by a program flow that both parties agree upon when executing the program.
[0221] In step 1012, the instances of the subsets are calculated by each party executing their respective program. This means that for each instance, the partial information required to generate the correlated pseudorandomness is determined. The partial information calculated by each party represents a private result.
[0222] Step 1012 stipulates that the first party P0 signals the second party P1, via message 1012-1, to start executing the program for calculating the instances of a subset, and that the instances from the subset are determined in step 1012-2. The computation of the independently computable instances is performed in parallel in step 1012-2.
[0223] Then, step 1012-1 is executed to calculate the instances of the next subset, until the instances from all subsets have been calculated.
[0224] This means that step 1012 involves a loop through all interactive subsets of the decomposition.
[0225] Subsequently, depending on the respective private outcome, a private part of the correlated pseudorandomness is determined. This means that each party locally combines the partial information from the respective private outcome to create the correlated pseudorandomness.
[0226] The correlated pseudorandomness is provided in step 1014, which is executed at the time of deployment.
[0227] The correlated pseudorandomness is then used in step 1016, e.g. in an MPC online phase. QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited Non-Patent Literature
[0000] Boyle, E., Couteau, G., Gilboa, N., Ishai, Y., Kohl, L., Scholl, P. „Efficient Pseudorandom Correlation Generators from Ring-LPN“ https: / / doi.org / 10.1007 / 978-3-030-56880-1014 Boyle, E., Gilboa, N., Ishai, Y. (2015). Function Secret Sharing. In: Oswald, E., Fischlin, M. (eds) Advances in Cryptology - EUROCRYPT 2015. EUROCRYPT 2015. Lecture Notes in Computer Science0, vol 9057. Springer, Berlin, Heidelberg. https: / / doi.org / 10.1007 / 978-3-662-46803-6_12
[0026] Gilboa, N., Ishai, Y. (2014). Distributed Point Functions and Their Applications. In: Nguyen, PQ, Oswald, E. (eds) Advances in Cryptology - EUROCRYPT 2014. EUROCRYPT 2014. Lecture Notes in Computer Science, vol 8441. Springer, Berlin, Heidelberg. https: / / doi.org / 10.1007 / 978-3-642-55220-5_35
[0027] Boyle, E., Couteau, G., Gilboa, N., Ishai, Y., Kohl, L., Scholl, P. (2020). Efficient Pseudorandom Correlation Generators from Ring-LPN. In: Micciancio, D., Ristenpart, T. (eds) Advances in Cryptology - CRYPTO 2020. CRYPTO 2020. Lecture Notes in Computer Science(), vol 12171. Springer, Cham. https: / / doi.org / 10.1007 / 978-3-030-56880-1_14
[0029]
Claims
[1] Method, in particular a computer-implemented method, for the distributed generation of correlated pseudorandomness, characterized by, that a set of instances for sharing secrets of functions is specified, wherein the instances each comprise a pair of a function for calculating a partial piece of information of the correlated pseudorandomness and an input value for the function, wherein a partition of the set into subsets is provided (902), wherein the partition enables the at least partially overlapping calculation of the results of several instances, wherein at least partially overlapping calculation of the results of instances from at least a part of the subsets for the distributed generation of the correlated pseudorandomness is caused by sending at least one message (1012) via a communication link or is carried out in response to receiving at least one message (1012) via a communication link (904),wherein at least one message (1012) includes or identifies a program for the distributed generation of the correlated pseudorandomness based on the decomposition. [2] Method according to claim 1, characterized by , that the set is divided into the subsets of the decomposition depending in particular on a condition for the order in which the results are used according to a type of correlated randomness to be provided (902). [3] Method according to any one of the preceding claims, characterized by , that the partially overlapping or simultaneous calculation of results is initiated or carried out by instances of a subset that are independent of each other (904). [4] Method according to any one of the preceding claims, characterized by , that the partially overlapping or simultaneous calculation of results is initiated or carried out by instances of different subsets (904). [5] Method according to any one of the preceding claims, characterized by , that the partially overlapping or simultaneous calculation of results of the instances of a subset, for which the calculation of the result of the individual instances within the subset is independent of the result of other instances of the same subset, is initiated or carried out (904). [6] Method according to any one of the preceding claims, characterized by , that the partially overlapping or simultaneous calculation of results of the instances of the subsets, for which the calculation of the result of the individual instances within the respective subset is independent of the result of other instances of the same subset, is initiated or carried out (904). [7] Method according to any of the preceding claims, characterized by, that the instances which are to be computed in a partially overlapping or simultaneous manner are assigned to different computing facilities for computation (904). [8] Method according to any one of the preceding claims, characterized by , that a result of the respective instance is calculated, wherein the calculation of the result of the respective instances includes a distributed point function (DPF) calculation, wherein the partially overlapping or simultaneous calculation of the result of two instances includes a partially overlapping or simultaneous calculation of the DPF calculation of the two instances (904). [9] Method according to any one of the preceding claims, characterized by, that a partition of the set into the subsets is determined depending on one or more computing and / or network resources available for calculating the results of the instances (902). [10] Method according to any of the preceding claims, characterized by , that the partially overlapping or simultaneous computation is performed, wherein the partially overlapping or simultaneous computation includes hardware-based parallelization, in particular parallelization of arithmetic operations or pseudorandom number generators (PRGs). [11] Method according to any of the preceding claims, characterized by, that a number of subsets and / or a size of at least one of the subsets is determined depending on an available memory of a computing device on which the result of at least one instance is to be determined, or of several computing devices on which the result of at least one instance is to be determined, or of a network latency (902). [12] Method according to claim 11, characterized by , that for a larger available memory a larger number of instances in a smaller number of larger subsets is chosen (902) than for a correspondingly smaller available memory, and / or that for a smaller available memory a larger number of small subsets is chosen (902) than for a correspondingly larger available memory. [13] Method according to claim 11 or 12, characterized by, that a partition of the set into subsets is determined (902) for which a number of independent instances in the subsets is greater than for any other partition. [14] Device for distributed generation of correlated pseudorandomness, characterized by that the device is configured to perform the method according to one of the preceding claims. [15] Computer program, characterized by , that the computer program comprises instructions executable by a computer, the execution of which by the computer results in the procedure according to one of claims 1 to 13.
Citation Information
Patent Citations
METHOD AND SYSTEM FOR ERROR-TOLERANT AND SECURE MULTI-PARTY CALCULATION WITH SPDZ
DE102019208032A1
Devices and methods for secure multi-party computation with correlated randomness
DE102023212693A1