Data processing method

The data processing method addresses the limitations of existing secure systems by employing a distributed approach with dual encryption techniques across a server and TEE, ensuring data confidentiality and integrity even against malicious server behavior and 'honest-but-curious' TEEs.

FR3157599A1Active Publication Date: 2025-06-27COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
FR2023014913
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-21
Publication Date
2025-06-27
Estimated Expiration
2043-12-21

AI Technical Summary

Technical Problem

Existing data processing methods in secure systems face challenges in ensuring data confidentiality and integrity, particularly when dealing with homomorphic encryption and Trusted Execution Environments (TEEs), as they are limited in application scope and do not provide adequate protection against malicious server behavior or 'honest-but-curious' TEEs.

Method used

A data processing method that utilizes a distributed approach across two computers: a server and a secure hardware module (TEE), employing a combination of first and second encryption techniques. The method ensures that the server and TEE only process data under encryptions they cannot decipher, thereby maintaining data confidentiality even if the server is malicious and the TEE is 'honest-but-curious'.

Benefits of technology

This method effectively ensures the confidentiality and integrity of data processing, even in scenarios where the server is malicious or the TEE is 'honest-but-curious', while also reducing computational burdens and enhancing security measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for processing data to obtain a result (x) by a combination of elementary operations (f,g,h;gj); in which two ciphers [Enc1,Dec1; Enc2,Dec2] are defined, one indecipherable by a server, the other indecipherable by a TEE; and S1) a sending client (CL1) provides and encrypts an input data (x); S2) it transmits it under the cipher (Enc1) to the server or to the TEE; S3) by data processing, these two computers apply the combination of elementary operations to the received encrypted data so as to obtain an encrypted ([F(x)]) of the result, which they transmit to a receiving client (CL1,CL2); S4) the latter decrypts the encrypted of the result ([F(x)]) and obtains the result (F(x)). During step S3, the server only processes data processed under encryption that cannot be deciphered by the server, and the TEE only processes data processed under encryption that cannot be deciphered by the TEE. Figure for abstract: Fig.1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Data processing method TECHNICAL FIELD OF THE INVENTION

[0001] The field of the invention is the field of data processing and more particularly, of data processing in a secure manner.

[0002] More specifically, the invention relates to a method for processing data in a system comprising two computers to securely obtain a result based on input data provided by clients or users of the system. STATE OF THE ART

[0003] The present disclosure is part of a considerable trend in recent years in data processing, which is the increasing use of the 'cloud', i.e. cloud architectures, to carry out various processing operations on data regardless of the nature of the data.

[0004] However, the transfer of these operations to the cloud in turn naturally raises new issues, in particular the difficulty of ensuring the confidentiality of data and the integrity of the operations carried out.

[0005] Different encryption techniques have been developed to meet the need for data confidentiality.

[0006] Among these, homomorphic encryption techniques are particularly distinguished. Advantageously, homomorphic encryption allows the processing applied to the data to be carried out on encrypted data. However, homomorphic encryption uses ciphers whose size is very large compared to that of the initial data. This leads to a considerable increase in the quantity of calculations to be carried out, which naturally is extremely problematic for the implementation of this technique.

[0007] Furthermore, although these techniques prove effective in preventing data breaches against third parties, they may, however, have limited effectiveness against certain types of actors, in particular privileged actors: system administrator, cloud infrastructure provider, or more generally any person authorized to intervene in the processing.

[0008] To overcome these drawbacks, it has been proposed (see for example document Ref.2 or 4) to delegate at least part of the data processing carried out on homomorphic ciphers (such calculations will subsequently be called 'carried out in homomorphic mode') in a secure secondary computer of the Trusted Execution Environment type, or "TEE". Such a type of computer is defined in particular by document Ref.4.

[0009] Such delegation of calculation advantageously significantly reduces the quantity of calculations to be carried out.

[0010] However, these methods which combine homomorphic encryption and the delegation of certain data processing to a TEE remain limited to very specific applications, for example, the secure sharing of a key, the training of a neural network with homomorphic encryption for quadratic functions and the rest of the calculation in the TEE, an aggregation method combining homomorphic calculation and delegation of calculation to a TEE, etc.

[0011] Furthermore, all these solutions are in the context of a TEE which is assumed to be trustworthy. For this reason, these methods do not provide protection measures against an "honest-but-curious" TEE. For the record, in the field of cryptography and security protocols, an "honest-but-curious" computer (also called a passive or semi-honest adversary) is a type of adversary that follows the protocol correctly, but tries to learn as much as possible from the available information (see document Ref.4).

[0012] Finally, these solutions do not necessarily ensure the security of calculations in the event that the server adopts malicious behavior. Statement of the invention

[0013] The present invention aims to propose a data processing method making it possible to avoid the risks suggested above.

[0014] To this end, a data processing method is proposed in which calculations are carried out in a distributed manner on two computers, namely a server and a security hardware module, or TEE, the method making it possible to ensure the confidentiality of the data even in the case where the server adopts malicious behavior, while the TEE adopts "honest-but-curious" behavior.

[0015] For this purpose, according to the present disclosure, there is proposed a method for processing data in a system comprising two computers to obtain a result from at least one input data to be provided by at least one transmitting client, the result being calculable by applying a combination of elementary operations to at least one input data; in which one of the computers is a server, and the other is a secure execution environment, TEE; a first encryption and a second encryption are defined, one being indecipherable by the server, and the other being indecipherable by the TEE; the method comprises the following steps:

[0016] SI) at least one sending client provides an input data and applies the first encryption to it;

[0017] S2) said at least one transmitting client transmits the input data under the first encryption to one of the calculators;

[0018] S3) during data processing, the two computers apply the combination of elementary operations to said encrypted data received in step S2 so as to obtain an encrypted result, and transmit this result to at least one receiving client, step S3 comprising the following elementary steps:

[0019] S31) the first calculator encrypts the data processed under second encryption;

[0020] S32) the first computer transmits the processed data to the second computer obtained, encrypted under first and second encryption; and

[0021] S33) the second calculator removes the first encryption from the processed data received;

[0022] S4) said at least one receiving client decrypts the result ciphertext and obtains the result ;

[0023] during the data processing carried out in step S3, the server only processes processed data under at least the encryption indecipherable by the server, and the TEE only processes processed data under at least the encryption indecipherable by the TEE, which may in particular be a masking encryption; and

[0024] the first and second encryption verify the property, for any processed data x:

[0025] Dec2(Decl(Enc2(Encl(x)))) = Dec2(Enc2(x)).

[0026] In this document, the expression 'encrypted data' means data that is encrypted at least using the encryption in question. The data may optionally be under double (or even triple) encryption.

[0027] The fact that the encryption is indecipherable by the server means, for example, that the server does not have the decryption function, or does not have the decryption key.

[0028] The fact that the server only processes processed data under at least the encryption indecipherable by the server means that any processed data transmitted to the server is previously encrypted under at least the encryption indecipherable by the server. Similarly, the fact that the TEE only processes processed data under at least the encryption indecipherable by the TEE means that any processed data transmitted to the TEE is previously encrypted under at least the encryption indecipherable by the TEE.

[0029] In some embodiments, one of the ciphers is decipherable by the server and not by the TEE, and the other of the two ciphers conversely is decipherable by the TEE but not by the server.

[0030] The TEE is a component that generally has a relatively low memory capacity. Preferably, the memory of the TEE has a capacity that does not exceed 1 GB, or preferably that does not exceed 512 MB (Megabytes), and even more preferably which does not exceed 256 MB. Naturally, it is assumed that the TEE is honest with regard to the processing it applies to the processed data.

[0031] In the method, the first computer can be the server and the second computer the TEE, or vice versa.

[0032] The central step of the method defined above is step S3. During this step, a processing operation is applied by the computers to the encrypted input data received in step S2.

[0033] This treatment involves a certain number of elementary operations.

[0034] These elementary operations successively transform the initial input data into different processed data. The term 'processed data' designates data obtained from the initial data during processing. When all the elementary operations constituting the processing have been carried out, the computers obtain a figure of the result. This is then transmitted to one or more clients (called receiving clients).

[0035] Thus, during processing, the computers apply the combination of elementary operations to the received input data, which allows them to obtain the desired result.

[0036] Importantly in the method, in step S3, instead of being executed on plain data x, all operations performed during processing are executed on encrypted data [x].

[0037] Each of the computers is therefore configured to apply each of the processing operations incumbent upon it not on a plain text data item, but on a corresponding encrypted data item. Thus, in particular, if an elementary operation consists of applying a function f to a processed data item x, according to the method one of the computers actually applies a function f to the encrypted data item [x] so as to provide as output an encrypted result equal to the encrypted value of the result, i.e. [f(x)]. The computer therefore actually applies a function f to the encrypted value [x] of the data item x, and provides as output the encrypted value of the result: / ([x]) = [ / (x)]- To simplify in what follows, the function f is noted f as the function from which it is derived.

[0038] In the method, most often, in a manner known per se, the operations constituting the processing are executed exclusively on integers modulo a predefined maximum value T.

[0039] In the method, advantageously the data is encrypted during all the steps (or operations) carried out, whether these are carried out by the server or by the TEE. Consequently, this method makes it possible to carry out these steps securely, not only even if the server is malicious, but also if the TEE adopts “honest but curious” behavior.

[0040] In the method, depending on the mode of implementation and unless otherwise indicated, any application and any removal of encryption to a piece of data may possibly be preceded or followed by an elementary operation modifying the data processed.

[0041] In this document, a masking cipher includes any logical addition that allows the modification of the data that is encrypted (using the mask), for example an addition, a logical 'exclusive OR' (XOR) function, etc.

[0042] In the method, any type of encryption that is indecipherable by the server can be used. The encryption that is indecipherable by the server can thus be or can thus comprise a homomorphic encryption, in particular a totally homomorphic encryption.

[0043] Preferably, each operation on processed data performed by the server is performed under homomorphic encryption. In this case, the server only processes processed data under at least one homomorphic encryption.

[0044] Thus in certain implementation modes, the first encryption is a homomorphic encryption and the second encryption a masking encryption, or vice versa.

[0045] To enable the computers to perform the processing on encrypted data, the method includes support operations during which support functions are applied to the input data, to the processed data or to the results, each optionally being encrypted.

[0046] By 'support function', we mean here a function other than said elementary operations and which:

[0047] - contributes to the execution of homomorphic calculations by the server or to the verification of these;

[0048] - used to encrypt or decrypt data to be processed received from the client, data processed (by the calculators), or results sent to the client; and / or

[0049] - used to prepare data (verification data) used to verify data to process received from the client, processed data, and / or results sent to the client.

[0050] It is understood that the support functions do not participate in the performance of the elementary operations (since they are other than the elementary operations), but only serve either to enable these elementary operations to be performed on encrypted data, or to encrypt or decrypt data provided to the computers or sent by them, or to verify or ensure that the various operations that the method comprises, in particular the elementary operations, have been properly performed.

[0051] In certain implementation modes, in step S3, the TEE applies to the processed data or to the processed data only one or more support functions. The elementary processing operations are then carried out exclusively by the server.

[0052] In certain embodiments, the method comprises the following steps:

[0053] S0235) the second computer applies the first encryption to the data decrypted during step S33, and transmits the data obtained to the first computer; and

[0054] S0236) the first calculator removes the second encryption from the processed data received at the end of step S0235.

[0055] Thus, from the data processed under second encryption available in the server at step S33, the server can provide data processed under double encryption to the first computer. The latter can remove the second encryption. If the data processed at this stage is in fact the encrypted result, the first computer can then transmit this encrypted result (under first encryption) to the client which decrypts it.

[0056] Preferably, step S0235 is performed immediately after step S33, such that during step S0235, the second computer applies the first encryption to the processed data obtained at the output of step S33. Thanks to this, when the first encryption is a homomorphic encryption, steps S33 and S0235 make it possible to carry out a noise reset or a relinearization.

[0057] Since the two steps S33 and S0235 are executed immediately after each other, without any intermediate operation, they constitute a decryption / re-encryption operation. These two grouped operations, more generally, can also constitute a bootstrapping, a re-linearization of LHE ('Levelled Homomorphic Encryption'), or both at the same time, or any other ciphertext management operation. They can thus be operations conducted to obtain again a ciphertext having the format of a 'fresh' ciphertext.

[0058] This latter operation is normally carried out in the case where removing and then reapplying the encryption makes it possible to reduce the noise level in the ciphers, which is the case in particular for certain homomorphic encryptions (first encryptions). This operation is preferably carried out in the case where the second computer is a TEE.

[0059] In this case, thanks to the successive decryption and re-encryption operations carried out by the TEE, when there is a transcryption operation with a high expansion factor, the size of the ciphers transmitted from and to the client can be drastically reduced, which results in a reduction in bandwidth consumption between the client and the server.

[0060] Furthermore, since the encryption maintenance operations are thus delegated to the TEE, which performs them much less expensively than the server, the performance of the server's homomorphic calculation is considerably increased. Re-encryption allows to refresh homomorphic ciphers and has an effect equivalent to a bootstrapping operation but with a better resulting noise level.

[0061] In certain embodiments, the method is implemented iteratively during a plurality of calculation loops. One of the encryptions may also be a mask encryption. In this case, for the application of the mask encryption during the method, the client or the calculator concerned generates a mask stream; and at each calculation loop, a new mask is generated and used for masking.

[0062] In many implementations, the encrypted result returned to the receiving client(s) at the end of step S3 is encrypted under at least the first cipher, but this is not necessarily the case.

[0063] Thus, on the contrary, in certain embodiments of the method, during step S3, the processed data is encrypted using an encryption other than the first encryption or is encrypted with the first encryption but with another encryption key; and the encrypted result returned at the end of step S3 is encrypted with an encryption different from the first encryption or is encrypted with the first encryption but with another encryption key.

[0064] These implementation methods therefore make it possible to carry out a key switching operation in a secure manner.

[0065] Depending on the implementation modes, the receiving client(s) receiving the encrypted result at the end of step S3 may be identical to or different from the or each of said at least one sending client providing the data in step S1.

[0066] In certain embodiments, the method further comprises a step S0411 preceding step S2 and during which the first client applies additional encryption, in particular symmetric encryption, to the data; and after the data has been transmitted to the first computer in step S2, the first computer removes the additional encryption.

[0067] This additional encryption allows the transmission of the initial, encrypted data from the client to the first computer. The second encryption can thus be applied by the first computer, and not by the client. This reduces on the one hand the calculation operations carried out by the client (the application of the additional encryption, for example symmetric, can be simpler than the application of the second encryption, typically homomorphic). In addition, this does not require the client to have the encryption key of the second encryption, and reduces communication costs.

[0068] In certain embodiments of the method, during an operation S0533, the TEE removes the first encryption, called the first initial encryption, which may in particular be a masking encryption, from the processed data; and

[0069] - during an operation S0535, the TEE applies encryption to the processed data homomorphic, as the first final cipher;

[0070] - during an operation S0535a, following step S0535, the data processed under first final encryption and second sub-encryption is transmitted to the server;

[0071] when all the elementary operations have been carried out, the encrypted result is transmitted to the client under first final encryption; and in step S4, the client withdraws the first final encryption.

[0072] In this mode of implementation, the client applies a first initial encryption to the data that it transmits to the first computer. During steps S0533 and S0535, the first initial encryption will be removed, then replaced by the first final encryption. It is therefore this which will be decrypted by the client in the final step S4. This mode of implementation therefore makes it possible to carry out a transcryption, and in particular, possibly, to replace a masking encryption with a homomorphic encryption.

[0073] In this mode of implementation, the TEE is preferably the first calculator.

[0074] In step S2, the input data under first initial encryption is first transmitted to the server.

[0075] After receiving this data, during a step S0531, the server applies the second encryption to the processed data, which is a masking encryption, and transmits it to the TEE, encrypted under this second encryption.

[0076] After following step S0535a, the data processed under first final encryption and under second encryption has been transmitted to the server, during a step S0536, the server removes the second encryption (the masking encryption). All or part of the elementary operations can be carried out by the server only after carrying out step S0536.

[0077] In certain embodiments of the method, the first encryption applied in step S1 is the homomorphic encryption, called first homomorphic encryption;

[0078] during a step S0633, the TEE removes the first homomorphic encryption from the processed data;

[0079] during a step S0635 performed after step S0633, the TEE applies to the data a second homomorphic encryption other than the first homomorphic encryption; and

[0080] in step S4, the client removes the second homomorphic encryption from the encrypted result.

[0081] This mode of implementation makes it possible to carry out a transcryption, the first homomorphic encryption being replaced by the second homomorphic encryption by the TEE during steps S33 and S35.

[0082] Iterative process

[0083] In certain embodiments of the method, the combination of elementary operations comprises N elementary operations of order j, j=1.. .N;

[0084] step S3 comprises the execution of a plurality of calculation loops, in an iterative manner;

[0085] at each loop of index j, j=L.N, steps S1, S31, S32 and S33, a step S0730, a step S0735 and a step S0736 are carried out in the following manner:

[0086] during step S1, the client provides an input data item of index j, and transmits said input data item of index j to the first computer, which is the server, as input data for step S0730;

[0087] during step S0730, the server applies the elementary operation of index j to the data provided to it as input;

[0088] the server performs step S31 of applying the second encryption to the processed data and step S32 of transmitting the encrypted processed data to the TEE;

[0089] the TEE carries out step S33 of deleting the first encryption of the processed data, then in step S0735 applies the first encryption to the data again, then retransmits the data thus re-encrypted to the server;

[0090] upon receipt of said data thus re-encrypted, the server during a step S0736a removes the second encryption therefrom; the data thus modified is then provided as input data for operation S0730 of the following calculation loop if this takes place.

[0091] Furthermore, the security of the processing carried out by the computers can be increased when a verifiable calculation protocol is known for the processing to be carried out.

[0092] We consider more particularly the case where a verifiable calculation protocol is defined, and makes it possible to verify the result by carrying out an elementary verification for each of said elementary operations.

[0093] We consider the case where the first calculator is the server, and the second calculator is the TEE. A tag calculation function is defined within the framework of the verifiable calculation protocol, this function being commutative with the elementary operations gj (for the composition of functions o).

[0094] The first computer is the server, and the second computer is the TEE.

[0095] A tag calculation function is defined as part of the calculation protocol verifiable, this function being commutative with elementary operations.

[0096] The method then comprises the following steps:

[0097] in step SI, the client further transmits to the server a tag of the encrypted data under first encryption;

[0098] the second cipher is a mask cipher;

[0099] at each loop of index j, j = 1.. .N:

[0100] at a step S0701a, the client provides the server with a mask (mj) and a mask tag of the mask;

[0101] during a step S0730, the server applies the elementary operation of index j to the processed data tag which is provided to it as input;

[0102] during a step S0731, the server encrypts the processed data under second encryption;

[0103] during a step S0732, the server transmits to the TEE the processed data obtained, encrypted under first and second encryption;

[0104] during a step S0730a, the server applies the elementary operation (gj) of index j to the data tag provided to it as input;

[0105] during a step S0731a, the server calculates the tag of the double-encrypted cipher from the tag obtained in step S0730a and the tag of the mask, and transmits this tag to the TEE;

[0106] during a step S0732a, depending on the encrypted data received in step S0732, and the encrypted data tag received in step S0731a, the TEE verifies the elementary operation carried out in step S0730 by carrying out the elementary verification corresponding to this operation;

[0107] if the result is positive and the loop index j verifies j <N, à l’étape S0733 :

[0108] - the TEE removes the first encryption (DecHEl) from the encrypted data received in step S0732 performed during the loop, then

[0109] - during a step S0735, applies the first encryption to the data under second encryption and transmits the obtained encrypted data to the server;

[0110] - during a step S0736, the server removes the second encryption from the data received at the end of step S0735, and provides the data thus decrypted as input data for operation S0730 of the following calculation loop;

[0111] - during a step S0735a, the TEE calculates a tag of the encrypted data calculated at step S0735 and transmits this tag to the server; then

[0112] - during a step S0736a, the server calculates the tag of the unmasked ciphertext (i.e. i.e. the cipher whose mask, corresponding to the second cipher, has been removed) from the tag received at the end of step S0735a and the tag of the mask, and provides the tag of the unmasked cipher as input data for operation S0730a of the following calculation loop.

[0113] Thanks to a signature, verification and, optionally, homomorphic re-encryption operation in the TEE, a scheme is constructed which establishes step by step that all the manipulated ciphers are either generated by the TEE (which, as holder of the homomorphic encryption secret key, is not an attacker on the homomorphic scheme), or generated by the application of the homomorphic operators legitimate to ciphertexts generated by the TEE. There is therefore no possible CCA adversary for homomorphic encryption, which provides a reinforced level of security.

[0114] A signature is here any value attached to a message and which makes it possible to prove its integrity: From the message, the signature makes it possible to verify that it has not been altered. A signature is generally obtained in cryptography from a hash of the message, for example by using a known public key signature function such as RSA or ECDSA.

[0115] Furthermore, certain implementation modes exploiting the commutativity of the two ciphers allow calculations to be carried out with increased security, and in particular by benefiting from protection against CCA attacks.

[0116] Thus in certain modes of implementation of the method, the first calculator is the TEE;

[0117] during at least one of the calculation loops, called loop J, of index j=J, and preferably for all the loops, the method is executed in the following manner:

[0118] in step S32 of loop J, in addition to the data encrypted under first and second encryption, the first computer transmits to the second computer a signature of the latter, as well as another data encrypted under first and second encryption accompanied by a signature of the latter;

[0119] in step S33 of loop J, the server removes the first encryption from the data encrypted under double encryption and from said other data received in step S32;

[0120] at a step S0934 of the loop J, the server applies the elementary operation of index J to the two decrypted data obtained at step S33;

[0121] at a step S0934a of the loop J, the server applies the first encryption to the data obtained (by applying the elementary operation of index J);

[0122] the server further calculates a proof of calculation proving that the encrypted data obtained at the end of step S0934a is indeed the result of the application of the elementary operation of index J to the two data used as input for step S0934, and transmits the encrypted data obtained in step S0934a as well as the proof to the TEE;

[0123] during a step S0934b, the TEE verifies at least whether the proof corresponds to the result of the calculation; and,

[0124] if the result of the verification is positive, at a step S0936 the first calculator removes the second encryption from the data, and provides the data obtained as input for a step S31 of the next index loop if this takes place; if the result of the verification is negative, the TEE interrupts the processing.

[0125] The verification carried out during loop J makes it possible to detect a CCA attack which would have taken place during loop J.

[0126] Furthermore, in certain variants of these implementation modes, at a step S31b of the loop J, the first computer obtains signatures for two data figures calculated at step S31 performed for iteration j=J or at a previous iteration;

[0127] in step S32 of loop J, the first computer also transmits the signatures of said two encrypted data to the second computer;

[0128] after having calculated the proof of calculation during the loop J, the second calculator returns to the first calculator the two input data and their respective signatures; and

[0129] the verification carried out in step S34b includes, for each of the two data thus returned to the first computer with their signatures, a verification that each of the data corresponds to its signature.

[0130] Thanks to the verification operation, preferably carried out in a TEE, the validity of the calculation carried out by the server can be assured to the client with a lower additional cost than with conventional protocols.

[0131] Certain variants of the above implementation modes, also aiming to carry out the calculations more securely against CCA attacks, use suitable encryption schemes, such as the Paillier encryption scheme.

[0132] In these variants of implementation of the method, the first calculator is the TEE;

[0133] the first calculator is the TEE;

[0134] the second encryption being a homomorphic encryption providing security against CCA attacks, for example the Paillier encryption;

[0135] during at least one of the calculation loops, called loop J, of index j=J, the method is executed in the following manner:

[0136] in step S32 of loop J, in addition to the data encrypted under first and second encryption, the TEE transmits to the server another encrypted data ([z']nj2) under first and second encryption;

[0137] in step S33 of loop J, the server removes the first encryption from the data encrypted under double encryption and from said other data received in step S32;

[0138] at a step S1 134 of the loop J, the server applies the elementary operation of index J to the two decrypted data obtained at step S33;

[0139] at a step SI 134a of the loop J, the server applies the first encryption to the data obtained by applying the elementary operation of index J at step SI 134;

[0140] the server transmits the encrypted data obtained in step SI 134a to the TEE; and,

[0141] at a step SI 136, the TEE removes the second encryption of the data (DecCp), and provides the data obtained as input for a step S31 of the next index loop if this must take place.

[0142] In the implementation modes presented above, thanks to the verifiable cryptographic calculation scheme, it is then possible to carry out the verifications indicated previously in a systematic manner, for each of the operations of the combination of elementary operations (unless this verification is not necessary for certain types of elementary operations, for example for additions).

[0143] In this case, this systematic verification makes it possible to provide proof that the calculation carried out benefits from CCA security. BRIEF DESCRIPTION OF THE FIGURES

[0144] Other advantages, aims and particular characteristics of the present invention will emerge from the following non-limiting description of at least one particular embodiment of the devices and methods which are the subject of the present invention, with reference to the appended drawings, in which:

[0145] [Fig. 1] is a schematic perspective view illustrating a first and a sixth embodiment of the invention;

[0146] [Fig.2] is a schematic perspective view illustrating a second and a third mode of implementation of the invention;

[0147] [Fig.3] is a schematic perspective view illustrating a fourth embodiment of the invention;

[0148] [Fig.4] is a schematic perspective view illustrating a fifth embodiment of the invention;

[0149] [Fig.5] is a schematic perspective view illustrating a sixth embodiment of the invention;

[0150] [Fig.6] is a schematic perspective view illustrating a seventh embodiment of the invention;

[0151] [Fig.7] is a schematic perspective view illustrating an eighth embodiment of the invention;

[0152] [Fig.8] is a schematic perspective view illustrating the steps of providing input data, for a ninth embodiment of the invention;

[0153] [Fig.9] is a schematic perspective view illustrating the calculation steps, for the ninth embodiment of the invention;

[0154] [Fig. 10] is a schematic perspective view illustrating the steps of providing input data, for a tenth embodiment of the invention;

[0155] [Fig. 11] is a schematic perspective view illustrating the calculation steps, for the tenth embodiment of the invention; and

[0156] [Fig. 12] is a flowchart schematically presenting the steps of an embodiment of a method according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0157] As non-limiting examples of embodiment, different modes of implementation of the data processing method according to the present disclosure will now be presented.

[0158] Each of these implementation modes involves the following three entities: a group of at least one client, a server and a TEE.

[0159] Any type of computer can be considered as constituting the server. However, the server is preferably a computer with large computing capabilities.

[0160] In the data processing methods according to the present disclosure, each of the computers executes the processing operations entrusted to it on encrypted data. These data are encrypted with an encryption that cannot be deciphered by the computer, such that the latter does not have access to the information contained in these data. This encryption may in particular be a homomorphic encryption or a masking encryption.

[0161] The encryption and decryption functions are denoted Encxx respectively 1, EncYY2,.. and respectively Decxxl, DccYy2, ..., where '1', '2' are indices; XX and YY indicate the type of cipher used: for example HE for a homomorphic cipher, S for a symmetric cipher, and M for a masking cipher.

[0162] The encrypted data are denoted in brackets in the form [x]b where '1' is the index of the encryption function used (here: Encl). The notation [x]i>2 indicates a data x which has been encrypted successively with the first encryption function Encl, then the second encryption function Enc2.

[0163] The steps of the method, in the different embodiments presented, are noted in the form Sffnn, where ff refers to the number of the figure in which the embodiment is presented, and nn is a step number assigned to the step considered. In the different embodiments presented, as far as possible the steps which correspond to each other bear the same step number.

[0164] Each of the implementation modes presented aims to obtain a result, F(x) or F(x,y), which can be obtained (or equivalently, which is calculable) by applying a function F to at least one input data x, or in certain cases to several input data x, y, etc., as in the third implementation mode presented below in relation to [Fig.3].

[0165] This function F is broken down into a certain number of elementary calculation operations, or elementary operations (each of these being able to be of any level of complexity).

[0166] In the examples developed here, these elementary operations are represented by functions, noted here f, g, h, or also gj for the case where a function (gj) is called iteratively, in a loop, by the calculation method.

[0167] Naturally, the proposed data processing method is applicable to functions F decomposable into elementary operations f such that they can be transposed and executed by a computer on the data ciphers. This condition is not limiting if the encryption scheme is a completely homomorphic encryption, but must be taken into account in other cases, for example for an encryption that is only partially homomorphic, for example only additive or multiplicative. 1st implementation mode - General case

[0168] In a first mode of implementation of the method presented as an example, we wish to calculate a result F(x) from an input data x provided by a client CL1.

[0169] In this mode of implementation, the function F is broken down into two elementary operations f and g: F(x) = f(g(x)).

[0170] To calculate F(x), the following operations are performed:

[0171] In step S1 (step S0101, in [Fig.l]), the client CL1 provides the data x.

[0172] The client CL1 then applies a first Encli encryption to the data x; in this For example, Encli is a fully homomorphic cipher.

[0173] In step S0102, the first client CL1 transmits the data [x]ib encrypted under Encli encryption to the server.

[0174] As the data [x]i is encrypted using Encli encryption, the decryption key of which is not known to the server, the server is unable to access the information contained in the data [x]b

[0175] In step S0130, the server performs a first elementary operation, g, consisting of applying a function g to the received data [x]ib and thus obtains the data g([x]ii). When the Encli encryption is commutative (in the sense of the composition function o) with the function g, this value is equal to [g(x)]ib as shown in [Fig.l]. This is the case for example when the Encli encryption is an FHE encryption, taking into account the convention according to which the function g applied to the plaintexts and the function g applied to the corresponding homomorphic ciphertexts are both denoted g.

[0176] Then in step S31 (S0131), the server applies a second encryption, Enc2, to the data [g(x)hb which therefore becomes the data [g(x)]ii, 2.

[0177] When the first cipher Encli is a fully homomorphic cipher, any type of cipher can be used as the second cipher Enc2.

[0178] In the implementation mode presented in Fig.l, the first cipher Encli is a fully homomorphic cipher, and the second cipher Enc2 is a masking cipher. Applying the secondary cipher therefore consists of adding a mask m to the current data [g(x)] ib The result is therefore the data [g(x)] ii >2 , with [g(x)]ii,2 = [g(x)li rS m, the function O being an addition of a plaintext and a ciphertext.

[0179] In step S32 (S0132), the server transmits the data [g(x)]ii >2, encrypted under double encryption Encli and Enc2 to the second computer, the TEE.

[0180] Since the data [g(x)]ii, 2 is encrypted under the second cipher (i.e. hidden), the TEE is unable to access the information contained in this data.

[0181] In step S33 (S0133), the TEE removes the first encryption (removes the homomorphic encryption layer) from the data [g(x)]ii, 2, and thus obtains a data [g(x)]2, still masked by the mask m.

[0182] In most variants of this mode of implementation, the calculation method then continues with the TEE carrying out step S0135 (described later), directly based on the data [g(x)]i>2.

[0183] However, an intermediate calculation step SOI34 consisting of applying a function f to the data [g(x)]2 produced by the operation S33 can be provided when the function f and the second encryption / decryption function (generally, by masking) are commutative for the function composition law (function 'o'; fog (.) is also noted f(g(.))).

[0184] In this case, as shown in [Fig.l] at an intermediate step SOI34 the TEE applies the function f to the received data [g(x)]2. It thus obtains the data [f(g(x))]2.

[0185] It is assumed in the following by way of example that in the implementation mode presented, step S0134 is carried out.

[0186] In step S0135, the TEE applies an additional encryption Encl2 (a homomorphic encryption) to the data [f(g(x))]2, and thus obtains the intermediate encrypted data [f(g(x))]2, i 2, which it transmits encrypted under double encryption (homomorphically encrypted and masked) to the server.

[0187] At step SOI36, the server then removes the second encryption by applying the decryption function Dec2 applied to the intermediate encrypted data [f(g(x))]2ji2, i.e. by subtracting the mask m, and obtains an intermediate encrypted data [f(g(x))]i2 under the additional encryption Encl2.

[0188] The server then completes step S3 (S0103) by transmitting the encrypted result [F(x)]i 2, to the client CL1.

[0189] In step S0104, the client CL1 decrypts the encrypted result [F(x)]b, i.e. applies the decryption function Decl2 to it, and thus obtains the result F(x).

[0190] In this embodiment, the second computer is a TEE. Since the second computer must be capable of removing and applying the homomorphic encryption (at steps SOI33 and 0135), the choice of a secure computer such as a TEE as the second computer makes it possible to carry out the encryption / decryption functions Encl2 and Decl2, for example using a symmetric key pair, which makes it possible to execute these functions under satisfactory security conditions.

[0191] The additional cipher Encl2 / Decl2 may be the same cipher as the first cipher Encli / Decli, with the same encryption key or not. It may also be two different ciphers.

[0192] In this embodiment, the TEE removes the homomorphic encryption (DecHEll, step S0133) and applies the additional encryption (Encl2, step S0135): these are two examples of support functions applied by the TEE. Step S0133 contributes to the execution of homomorphic calculations by the server. Step SOI35 is used to encrypt results sent to the client. It is noted that the server also performs support functions, for example in step SOI36. Furthermore, in this embodiment, in step S0134, the TEE performs an elementary operation, which is not a support function. 2nd implementation method

[0193] In the second implementation mode, illustrated by [Fig.2], we also wish to calculate a result F(x) from an input data x provided by a client CL1.

[0194] In this second mode of implementation, the function F to be calculated is broken down into a plurality of elementary operations gj, where j=l....N, in the following manner:

[0195] F(x) = gN (g^ (gx 2 (.... (gl(x))))))

[0196] The elementary operations gj are applied successively to the current data in an iterative manner by repeating a calculation loop N times.

[0197] At each iteration of index j, the first calculator, the server, applies a elementary function gj to the current processed data gj.i (gj 2 (gj 3 (.... (gi(x)))))). To simplify, in this document the processed data gj (gj4 (gj 2 (.... (gi(x)))))) conventionally denoted gj(x).

[0198] As the number of elementary operations gj to be applied can be very high, it may be necessary for certain encryption schemes to periodically reset the noise. This concerns in particular the case where the first encryption is a homomorphic encryption in which a noise component is integrated into the homomorphic cipher: it is then necessary to periodically reset the noise (so-called 'Bootstrapping' operation) (for more details, refer to Ref.2).

[0199] This second mode of implementation of the method provides a solution for this reset. The TEE in this case is advantageously used to carry out the reset operation. At each iteration, the server applies an elementary function gj to the data, and the TEE performs a noise reset operation.

[0200] The operations carried out in the second embodiment are the same as those carried out in the first embodiment except for the following points:

[0201] The main difference is that, as the function F is broken down into N elementary operations gj, at the end of step S0236 of deleting the second encryption (of subtraction of the mask m) (comparable to the function SOI36 of the first mode of implementation), in the second mode of implementation, there are two possibilities:

[0202] If the index j is strictly less than N, the cipher [gj (gj_i (gj_2 (gi (x))))))]i calculated in step S0236 by the server is then provided as input data for the following iteration of the calculation loop (composed of steps S0230, S0231, S0232, S0233, S0235, S0236).

[0203] Conversely, during the last iteration, in which the index j is equal to N, the ciphertext [gN (gN4 (gN_2 (.... (gi(x))))))]i calculated in step S0236 by the server, and equal to the ciphertext of the result [F(x)]i, is then transmitted to the client CL1. The latter then decrypts this ciphertext and thus obtains the result (step S4).

[0204] However, in a variant, during the last calculation loop (j=N), once step S0230 is performed, instead of performing steps S0231, S0232, S0233 and S0235 to allow the noise reset operation, the server transmits the result obtained in step S0230 directly to the client CL1 (dotted arrow in [Fig.2]). The client can then remove the first encryption from the transmitted result and thus obtain the result of the calculation F(x).

[0205] At each iteration, the elementary calculation operation S0230 (application of a function gj) by the server is therefore followed by operations S0233 and S0235 of resetting the noise by the TEE.

[0206] The function of the TEE is therefore only to remove and then reapply the homomorphic encryption, by applying the functions DecHE i and EncHE b which are two support functions: unlike the first mode of implementation, the TEE only performs support functions, and does not perform an elementary calculation operation f; there is no step comparable to step S0134.

[0207] Advantageously, in particular in encryption schemes based on the LWE problem, the encryption and decryption operations can be extremely fast, which means that the processing operations (operations S0233, S0235) carried out by the TEE only negligibly slow down the calculations carried out by the server.

[0208] In some implementations, the mask m is a mask provided to the server by the client CL1 in a keystream. In this case, the second encryption performed in step S0231 at each iteration of index j uses a mask mj having a value specific to the iteration of index j. 3rd implementation method

[0209] A third mode of implementation, also illustrated by [Fig.2], comprises the same operations as the second mode of implementation.

[0210] The difference between the second and third implementation modes is that while in the second, the TEE performs a noise reset operation, in contrast in the third implementation mode, the TEE performs a relinearization of the encrypted data [gj (gj^ (g, 2 (.... (gi(x))))))h,2.

[0211] This relinearization advantageously makes it possible to modify the encrypted data: the relinearization operation makes it possible to restore the form of the encrypted data, and to give it back the form of the initial ciphertexts or 'fresh' ciphertexts (in English: 'fresh ciphertext'). The TEE is advantageously used to carry out the relinearization operation.

[0212] The encryption schemes for which relinearization is necessary may in particular be schemes of the so-called LHE (Leveled Homomorphic Encryption) type, such as BGV and BFV for example. 4th mode of implementation

[0213] A fourth mode of implementation, illustrated by [Fig.3], corresponds to a case where the calculation to be carried out is a function F of several variables, provided respectively by two clients (or users) or more.

[0214] In the example we have considered only the case of two variables x and y provided respectively by two clients CL1 and C2L, but the method is applicable to any number of variables, provided respectively by any number of clients CL1... CLN.

[0215] In the example presented, the function F is broken down into elementary operations as follows: F(x,y) = h(f(g(x)),y)).

[0216] The operations carried out in this embodiment are the same as those carried out in the first embodiment except for the following points:

[0217] In the initial operation SI (S0301), two clients CL1 and CL2 (and not only client CL1) provide an input data, respectively x and y, for data processing.

[0218] Each of these two data is encrypted: A first encryption Encli is applied to x by the client CL1, and another 'first encryption' Encl2 is applied to y by the second client. The encryptions Encli and Encl2 are different or not from each other; they can also have the same encryption scheme, but with different keys.

[0219] The obtained encrypted data [x]n and [y][2 are then transmitted to the server (step S0302).

[0220] The following operations S0330, S0331, S0332, S0333, S0334, S0335 and S0336 are then substantially identical to the operations of the same step number carried out in the first mode of implementation.

[0221] It should be noted, however, that in step S0335, the first encryption applied is that used by the second client CL2, so as to prepare the supply to this second client, at the output of the server, of processed data encrypted under the first encryption Encl2 which is that used by the client CL2.

[0222] On the other hand, at the end of step S0336, instead of the result being transmitted directly to the client (CL2) (as in step S0136), an elementary operation h is previously applied (step S0337). This operation h uses as input data the encrypted data [f(g(x))]i2 and the encrypted data [y]i2, and provides as output an encrypted result [F(x,y)][2.

[0223] This cipher of the result [F(x,y)] i2 is then transmitted to the client CL2. The latter then decrypts this cipher and thus obtains the result (step S4).

[0224] In this example, the variable y only intervenes in a calculation phase in which the variable x has already undergone two successive treatments g and f, having made it possible to obtain f(g(x)). That said, naturally any form is possible for the function F; in particular the variable y could be combined with the variable x from the first calculation phase.

[0225] On the other hand, in this mode of implementation the function g is applied to the data x in a first elementary operation carried out by the server, and is followed by a second elementary operation f carried out by the TEE. The third elementary operation is again an operation carried out in the server.

[0226] It is understood that in general, any distribution of elementary operations between the two computers is conceivable. Thus the data processed in each of the computers can be a function of all or part of the input variables (x and y in this example). In addition, although this is not the case in this mode of implementation, in certain modes of implementation the calculation may involve iterative calculations between the two computers, as in the mode of implementation illustrated by [Fig.2].

[0227] The particularity of the fourth mode of implementation, besides the fact that several input data are provided by the different clients (CL1 and CL2) at the input of the method, is that the method makes it possible to carry out a transcryption when the Encli / Decli encryption scheme is different from the Encl2 / Decl2 scheme. The method makes it possible that from a data x encrypted at input with the homomorphic Encli encryption scheme, the client CL2 which receives the result at output receives the result encrypted with another encryption scheme, the Encl2 / Decl2 scheme. It will be noted that the second client CL2 could possibly be the client CL1, then having both encryption schemes.

[0228] If in this mode of implementation, the homomorphic encryption schemes use asymmetric key pairs, the TEE uses the private key of the homomorphic encryption scheme EncHEli; and to encrypt the data under encryption Encl2 in step S0335, the TEE has the public key of the encryption scheme Encl2 and does not need the private key of the client CL2. 5th mode of implementation

[0229] In a fifth mode of implementation, illustrated by [Fig.4], we seek to calculate the result F(x) of a function F which only requires applying an elementary operation f.

[0230] The operations carried out in this embodiment are the same as those carried out in the first embodiment except for the following points:

[0231] First of all, in step S1 (S0401), the client CL1, after having applied the first encryption EncM1, which is a masking encryption, applies another encryption Encs. In this implementation mode, this other encryption is a symmetric encryption (Encs,Decs), which constitutes neither the first encryption nor the second encryption within the meaning of the present disclosure. This symmetric encryption Encs is an additional encryption, used to guarantee the confidentiality of the transmitted data with respect to the server. Although the data [x]i>s in this implementation mode is transmitted directly by the client to the TEE (as the first computer), in other implementation modes this data can be transmitted via the server (in particular because in practice the TEE is most often integrated into the server).

[0232] After having successively applied the first encryption EncMlet and the additional symmetric encryption Encs, the client CL1 transmits the encrypted data [x]i>s to the first computer, which is the TEE and not the server, unlike the first mode of implementation.

[0233] Upon receipt of the data [x]is, the TEE first removes the symmetric encryption (by applying the Decs function) (step S0430).

[0234] The following steps S0431, S0432, S0433 and S0434 are then carried out in a similar manner to the steps of the same step numbers of the first embodiment (with the important difference that the first computer is now the TEE, and the second computer is the server):

[0235] The TEE applies the second encryption (EncHE2) to the data (step S0431) and obtains the data [x][j2, which it transmits to the server (step S0432).

[0236] The server removes the first encryption from the data (step S0433), then performs the elementary operation S0434 during which it applies the function f to the data [x]2. It thus obtains the ciphertext of the result [F(x)]2 which it transmits to the client CLL. The client then removes the second encryption (by applying DecHE2, operation S4 (S0404) and thus obtains the result F(x).

[0237] In this implementation mode, the first EncMl encryption is a masking encryption. Applying this encryption therefore consists of adding a mask m to the data. In the present case, this therefore consists of replacing the current data x by the sum x + m. We thus have: [x] i = x + m.

[0238] To allow the server to remove this encryption, the mask m is shared between the client CL1 and the server. Conversely, as the data [x]i, s is encrypted using this mask m before being transmitted to the TEE, the latter cannot know the content of the processed data transmitted to it: the masking encryption is indecipherable for the TEE.

[0239] Furthermore, in order to be able to apply the second, homomorphic encryption, EncHE 2, the TEE has the public key of this last encryption, the client CL1 having the corresponding private key to be able to withdraw this encryption (Function DecHE2). 6th mode of implementation

[0240] In the 6th implementation mode, we wish to calculate a result F(x) from an input data x; the function F constitutes in itself a single elementary operation F.

[0241] This 6th mode of implementation allows, like the 5th mode of implementation, to carry out a transcryption. This mode of implementation is illustrated by [Fig.5].

[0242] In this 6th mode of implementation, the operations carried out are substantially identical to the operations of the same step number carried out for the 1st mode of implementation, with nevertheless the following particularities or sometimes differences:

[0243] In step S1 (S0501), the first Encli encryption applied is not a homomorphic encryption, but a masking encryption: The encrypted data [x] ii is defined by: [x] ii = x + ml, where ml is a first mask which is unknown to the server and therefore indecipherable by it.

[0244] The data [x]i is then transmitted to the server in step S2 (S0502).

[0245] In step S31 (S0531), the server applies to the data a second encryption EncM2 which in this mode of implementation is also a masking encryption. The data obtained, [x]i b2 is then transmitted to the TEE (step S0532).

[0246] In step S0533, the TEE removes the first encryption (i.e. applies the Decli function, by subtracting the value of the first mask ml).

[0247] Then in step S0535, the TEE again applies an encryption decipherable by the client CL1, namely a totally homomorphic encryption, by a function Encl2, and transmits the result [x]2>i2 to the server.

[0248] At step S0536 the server removes the second encryption (function DecM2) and obtains an encrypted version of the processed data [x] i2.

[0249] Then, in step S0537 the server applies the function F to the ciphertext [x][2 and obtains the homomorphic ciphertext of the result, [F(x)]i2.

[0250] It then sends this cipher [F(x)]i 2 to the client, which decrypts it and thus obtains the result F(x) in step S4 (S0504). 7th mode of implementation

[0251] A 7th mode of implementation, illustrated by [Fig.6], allows, as in the 5th and 6th modes of implementation, to carry out a transcryption.

[0252] This 7th mode of implementation is close to the mode of implementation of [Fig.l]. Consequently, it can be considered that these two modes of implementation are identical, with the exception only of the differences which will now be presented.

[0253] The function F, as in the first mode of implementation, is decomposed as follows: F(x) = f(g(x)).

[0254] Steps S0601, S0602, S0630, S0631, S0632, S0633, S0634 and S0635 are substantially the same as the steps of the same step numbers of the first embodiment, mutatis mutandis.

[0255] In particular, step S0634 can only take place if the function f and the second encryption / decryption function are commutative for the function composition law.

[0256] In step S1 (S0601) as in the first implementation mode, a fully homomorphic encryption is applied by the function EncHEli.

[0257] The EncHEl2 encryption can in particular be a symmetric encryption.

[0258] Furthermore, at the end of step S0635, in the 7th implementation mode, the TEE transmits the encrypted result [F(x)]2,12 directly to the client CL1 (This encrypted result [F(x)]2ji2 could pass through the server, since the encryption EncHEl2 cannot be deciphered by the latter).

[0259] In the 7th mode of implementation, finally, in step S4 (S0604) the client CL1 therefore performs a double decryption, first by applying the function DecHEl2, then by applying the function DecM2. It thus obtains the result F(x) in clear. 8th mode of implementation

[0260] The 8th implementation mode, illustrated by [Fig.7], concerns the case where one would specifically wish to protect against the case where both the server would have malicious behavior, and the TEE would have “honest but curious” behavior.

[0261] This mode of implementation is applicable when there exists for the calculation to be carried out a verifiable calculation protocol making it possible to verify the results of all the calculations carried out during the elementary calculation operations. In this case, the calculation is distributed in the following manner: the elementary operations are carried out by the server, in particular under completely homomorphic encryption; each of these elementary operations is verified by the TEE.

[0262] This protocol makes it possible to verify that the calculation was executed in a compliant manner by carrying out a verification operation for each of the elementary operations carried out.

[0263] Examples of verifiable calculation protocols are cited for example by document Ref.5.

[0264] The integrity of operations carried out within the TEE can also be guaranteed by using a remote attestation process.

[0265] When these provisions are adopted, advantageously the calculation method makes it possible not only to ensure the confidentiality of the data, but also the integrity of the calculation.

[0266] An example of implementation of the method, indicating the checks to be carried out, is represented schematically by [Fig.7].

[0267] In this mode of implementation as in the 2nd mode of implementation, the function F to be calculated is broken down as follows:

[0268] F(x) = gN (g^ (gx 2 (.... (gl(x))))))

[0269] Consequently, the elementary operations are carried out iteratively by performing the same calculation loop N times: each calculation step by the server makes it possible to apply, during a loop of index j, an elementary function gj to the current data gj 4 (gj_ 2 (gj_ 3 (.... (gi(x)))))), also conventionally noted, for simplicity, gj i(x).

[0270] The operations carried out within the framework of this mode of implementation generally comprise the operations (or steps) of the second mode of implementation, to which are added additional verification operations.

[0271] A verification is therefore carried out for each elementary operation, during each of the successive calculation loops.

[0272] Thus in this mode of implementation, the following operations are carried out:

[0273] In step S0701, the client CL1 provides an input data x. It calculates a cipher [x]i of this data x for a first EncHEl encryption (EncHEl is a completely homomorphic encryption).

[0274] The ciphertext [x]i is also used to calculate a tag of the ciphertext [x]i of the input data, denoted tag([x]i), called data tag.

[0275] A tag here designates a value, which could also be called a marker or a label, which is calculated from an initial data item and then stored in such a way as to allow the authentication of the initial data item or to keep a trace of it, within the framework of a verifiable calculation verification protocol.

[0276] The data tag tag([x]i), like all the tags mentioned here, is calculated by a tag calculation function ir.tag, within the framework of a verifiable calculation protocol jt. This protocol is determined according to the calculation to be carried out in order to allow its verification.

[0277] In parallel, during successive steps S0701a, the client CL1 generates a flow of encryption keys ('keystream'). At each iteration of the calculation loop which will be described below between the two computers, the server and the TEE, the client CL1 generates a new key value mj at a step S0701a. In addition, from this key value mj, also at each step S0701a, the client CL1 also calculates a key tag tag(mj).

[0278] Thus, at each iteration of the index calculation loop j (j=l.. .N), the client CL1 transmits to the server the new calculated key mj and the associated key tag tag(mj).

[0279] Sending the keys nij allows the server to carry out the operations of applying and removing the second encryption (EncM2, DecM2) to the data processed in steps S0731 and S0736 described later.

[0280] Similarly, sending the key tags tag(mj) allows the server to carry out the operations of applying and removing the second encryption (EncM2, DecM2) to the data tags in steps S0731a and S0736a described later.

[0281] In step S0702, the client CL1 transmits to the server the encrypted data [x]i and the data tag tag([x]i).

[0282] Upon receipt of the information received (encrypted data [x]b tag thereof tag[x]b keys mj, key tags tag(mj), the server and the TEE progressively calculate the result F(x) by performing N calculation loops, in the following manner in step S3 (S0703).

[0283] At each loop of index j (j=1.. .N), the server performs an elementary operation gj, by applying a function gj to the processed data received as input (step S0730). At the first iteration, the data received as input is the encrypted data [x]i; at the following iterations, the data received as input at step S0730 at an iteration of index j is an intermediate processed data [gj x(gj 2(- - --gi(x)))))]x calculated during a decryption step S0736 which will be described later.

[0284] In parallel, at a step S0730a the server again applies the function gj, but this time it applies it successively, at the first iteration, to the data tag tag([x]i) of the encrypted (initial) data [x]i; then, at the following iterations of index j, to the successive data tags of the intermediate data tags tag([gj. i(gj. 2(....gi(x)))))]i), also noted tag([gj(x)]i) calculated during decryption steps S0736a which will be described later.

[0285] The tag calculation function is commutative with the elementary operations gj; consequently, the result can be written indifferently gj(tag([gj. i(gj. 2(.. ..gi(x)))))]i) or tag([gj(gj.1(gj.2(....g1(x)))))]1), also noted tag([gj(x)h).

[0286] The result [gj(gj-1 (-. ..gl(x)))))]i, also noted [gj(x)h obtained in step S0730 is then encrypted by masking in step S31, with the mask mj, which constitutes the application of a second encryption (function EncM2).

[0287] In parallel, from the tag (tag[gj(x)]i)) obtained in step S0730a and the tag tag(mj) of the mask mj, the server calculates the tag of the double-encrypted cipher of the processed data (tag([gj(x)]i2)) in step S0731a, which requires the application of the second encryption to the processed data (function EncM2).

[0288] All data processed by the server which are functions of the input data x are under first encryption EncHEl and consequently are indecipherable for the server, which is unable to access the information contained in this data.

[0289] The server then transmits to the TEE in parallel the data [gj(x)]i >2 and the data tag tag([gj(x)]i, 2), both under double encryption at step S32 (S0732).

[0290] In step S0732a the second calculator, the TEE, then performs a verification of the calculation carried out in accordance with the verifiable calculation protocol, on the basis in particular of the encrypted data [gj(x)]i>2 and the associated tag tag([gj(x)]i>2).

[0291] This verification may in certain cases include the following verification: the TEE calculates on its side the data tag tag([gj(x)]i>2) from the data [gj(x)]ij2 under double encryption, and verifies that the tag obtained is identical to that received in step S0732.

[0292] If the result of the verification is negative, the data processing is stopped and an alert message is transmitted.

[0293] If the result of the inverse check is positive, the TEE continues processing. For loops of index j <N

[0294] If the verification carried out in step S0732a indicates that the processing is proceeding in accordance with expectations, the TEE then removes the first encryption (applies the function DccHe1) from the data [gj(x)]2> i, i.e. it subtracts the mask mj from it, and thus obtains the data [gj(x)]2 in step S33 (S0733).

[0295] The TEE then applies the first encryption again (applies the Encl function) to the data [gj(x)]2, that is to say it adds a new mask mj to it, and thus obtains the data [gj(x)]2>i (step S0735).

[0296] The TEE then transmits this data to the server as input data to enable execution for index j+1 of step S0736.

[0297] At step S0736 (in the loop with index j+1), the server removes the second encryption (applies the DecM2 function) from the data [gj(x)]24 and therefore obtains the data [gj(x)]i, which will serve as input data for step S0730 of the following iteration.

[0298] In parallel, at the end of step S0735 the TEE calculates a new data tag tag([gj(x)i>2]) (step S0735a). It then transmits this tag tag([gj(x)i>2]) to the server as input data for the execution of step S0736a for loop j+1.

[0299] In step S0736a (in the loop with index j+1), the server calculates the data tag for the unmasked data (from which the second encryption has been removed by applying the function DecM2) from the received data tag tag([gj(x)]i>2.

[0300] The current index of the calculation loop then changes to j+1.

[0301] The index calculation loop j+1 then begins with the parallel execution of steps S0730 and S0730a, on the basis respectively of the data [gj(x)]i and the data tag tag([gj(x)]!). During the loop of index j=N

[0302] If the index j is equal to N, at the end of step S0732a, the server transmits to the client CL1 the data [gN(x)h 2, i.e. [F(x)]i 2.

[0303] In parallel, once step S0732a has been carried out, during a step S0735b, from the data [gN(x)]i>2 obtained and verified in step S0732a, the TEE calculates a signature sig([gN(x)]i> 2) of the data obtained, and transmits it to the client CL1 (possibly, via the server). This signature is calculated so as to make it possible to prove that the encrypted data returned is indeed the encrypted data obtained, once all the elementary operations constituting F have been carried out.

[0304] This signature as well as the data [gN(x)]i>2 are therefore transmitted to the client CL1, possibly via the server.

[0305] The client CL1 then performs step S4 (S0704), which comprises three sub-steps S0741, S0742 and S0743.

[0306] In step S0741, the client CL1 verifies that using the signature sig([gN(x)]i>2) the returned encrypted data [gN(x)]i>2 is indeed the encrypted data expected at the end of the calculations. If the result of the verification is positive, the calculation continues at step S0742; otherwise, it is interrupted and an alert message is transmitted.

[0307] In step S0742, the client CL1 removes the second encryption of the data and obtains the data [gN(x)]i.

[0308] In step S0743, the client CL1 decrypts the received data [F(x)h, i.e. removes the first encryption from it, and thus obtains the result F(x) = gN(x).

[0309] In this mode of implementation, the TEE only performs support functions. Indeed, the tag calculation and verification functions applied during steps S0732a and S0735a are functions which are used to verify the homomorphic calculations performed by the server; the decryption / encryption functions performed in steps S0733 and S0735 are functions which contribute to the execution of the homomorphic calculations by the server; and the signature calculation function performed in step S0735b is a function which is used to prepare verification data used to verify the results sent to the client CL1. 9th mode of implementation

[0310] A 9th mode of implementation concerns the case where we want to carry out the calculation in such a way as to secure the calculation against a CCA attack (from the English 'Chosen Ciphertext Attack').

[0311] For this purpose, the method is implemented in two phases illustrated respectively by Figs. 7 and 8.

[0312] A 10th implementation mode will be presented next, which makes it possible to secure the processing in the same way, but this time by using the Paillier cryptosystem.

[0313] For the 9th implementation mode first, [Fig.8] shows the preparation of input data for data processing and [Fig.9] shows the main steps of data processing.

[0314] The preparation phase includes the following steps:

[0315] In step S0 (S0801), the client (sending client) CLlprovides data x in front of serve as input data for the calculation.

[0316] It applies a first encryption EncMli to it, by masking, in this case by adding a first mask ml to it.

[0317] It then applies an additional encryption EncMl2 to it, also by masking, by adding a second mask m2 to it. This additional encryption EncMl2 is neither a first nor a second encryption within the meaning of the present disclosure. As in the 5th mode of implementation, this encryption EncMl2 is an additional encryption used to guarantee the confidentiality of the transmitted data with respect to the server. In this mode of implementation, the encrypted data obtained at the end of the two encryption steps is transmitted by the client to the TEE (as the first computer) via the server, which justifies the need for this encryption EncMl2 which cannot be deciphered by the server (the encryption EncMli being itself not deciphered by the TEE).

[0318] In step S2 (S0802), the client CL1 transmits the data [x]ibn under double encryption to the first computer, the TEE (The TEE is indeed the first computer because it is the computer which will encrypt the data under a second encryption in step S31, the server conversely in step S2 only transmitting to the TEE the data received from the client).

[0319] Then in step S3 (S0803), from the data received in step S2, the server and the TEE calculate an encrypted value [F(x)] of the result of the calculation, and transmit this result to the receiving client which is the client CL1.

[0320] In step S4 (S0904) the client CL1 decrypts the ciphertext of the result [F(x)] of the calculation and obtains the desired result F(x).

[0321] Step S3, shown mainly in [Fig.9], takes place iteratively and is represented by Figs.8 and 9.

[0322] The function F, in this mode of implementation, comprises a certain number of input data. In the example presented, only the supply of two input data x and y to the calculation process has been shown in [Fig.8], but in general, any number of input data can be supplied to the calculation process, possibly by a plurality of transmitting clients, in particular during successive calculation loops forming part of the data processing.

[0323] As indicated, [Fig.8] represents the preparation of input data x and y for data processing. Data x is data provided by a sending client CL1. Data y is data provided by the server (which can hold it from any source or calculate it by any means).

[0324] Before being transmitted to the TEE, the data is previously encrypted there under the first Encli encryption by the server in step S0801a.

[0325] The data [x]n i2 and [y]n are transmitted to the TEE, respectively by the client CL1 and the server.

[0326] On receipt of the data [x]n i2, the TEE removes the additional encryption (applies Decl2), i.e. subtracts the mask m2 from it (step S0830).

[0327] In step S31 (S0831), in parallel, the second encryption EncHE2, a completely homomorphic encryption, is applied to the data [x]n and [y]n.

[0328] The obtained double-encrypted data [x]n>2 and [y]n>2 are then signed (step S0831b).

[0329] The double-encrypted data [x]n>2 and [y]n>2 and their signatures o([x]n>2) and o([y] 11,2) are transmitted respectively to the TEE in step S32 (S0832).

[0330] These data serve as input data for the elementary operations carried out in a loop, during successive iterations, by the server jointly with the TEE, as shown in [Fig.9].

[0331] In [Fig.9], we have shown the input supply this time of two data of inputs [z]n>2 and [z']n>2. These data can be data produced during step S31 (S0831) illustrated in [Fig.8], whether they are data x provided by a transmitting client, and / or data y provided by the server. As will be explained, these can also be data such as the data [z”]n>2 calculated during step S31 (S0831) shown in [Fig.8] of the data processing process itself.

[0332] We therefore consider the case where two input data [z]n>2 and [z']n>2, each under double encryption EncMli and EncmT, are provided as input to the TEE. The first encryption is a masking encryption: the data z is encrypted with the mask m and the data z' with the mask m'.

[0333] The TEE calculates signatures o([z]nj2) and o([z']nj2) for these data (step S0931b). Each of these data together with its signature is then transmitted to the server in step S32 (S0932).

[0334] In step S33 (S0933), the server removes the first encryption from these data and their associated signatures by applying DecMli to them.

[0335] It then performs an elementary calculation operation (operation S34). This operation can for example be the multiplication of the two data z and z', that is to say the calculation of a new data [z”]2 = [z]2 * [z']2. This multiplication is carried out between homomorphic ciphertexts.

[0336] Using any known computational integrity proof method, a proof ir([z”]2 ) of the integrity of the elementary computational operation performed in step S34 is then calculated.

[0337] This proof confirms that there exist masks (m,m',m”), applied to the data (z,z',z”), such that

[0338] [zm]2* [z'-m']2= [z”-m”]2

[0339] where * represents the multiplication operation between homomorphic ciphertexts under Enc2 encryption.

[0340] The encrypted data [z”] obtained is then encrypted again under the EncMli encryption (step S0934a): a mask m” is added to it.

[0341] At the end of the encryption operation carried out in step S34a, the following elements are transmitted to the TEE for a verification operation S0934b: The input data of operation S34 and their signatures, i.e. [z]n>2, [z']n,2, g([z]hj2), o([z']n>2); and the data obtained at output: [z”]2>n, ir([z”]2).

[0342] Upon receipt of these elements, in step S0934b the TEE carries out the following verifications: it verifies the authenticity of the first data item [z]n>2 with respect to its signature o([z]nj2), the authenticity of the second data item [z']n>2 with respect to its signature o([z']nj2), then verifies the authenticity of the data item obtained at output [z”]2 with respect to the proof of the result ir([z”]2). (Other verifications may be carried out depending on the security constraints that the data processing method must respect).

[0343] If the result of these three checks is positive, the TEE removes the second encryption from the data [z”]n>2 (DecHE2, operation S0936).

[0344] The processing applied next depends on whether the elementary operations are completed or not:

[0345] In the first case, that is to say if the index j is strictly less than N, the set of elementary operations (function gj) has not been completely carried out. The data [z”] 11 under first encryption is encrypted again under second encryption EncHE2, the homomorphic encryption, to allow the continuation of the data processing (step S0931).

[0346] After having applied the second EucHe2 encryption again in step S0931, the TEE signs the result [z”]n 2 (operation S0931b) and transmits to the server for the continuation of the calculations the data [z”]n>2 under double encryption and its signature.

[0347] Conversely, if the index j is equal to N, the data [z”] 11 under first encryption is the result [F(x)] 11 of the calculation, encrypted under first encryption. This result is re-encrypted under the additional encryption EncMl2 (step S0937), then is transmitted under double encryption to the client. The application of the additional encryption EncMl2 guarantees that the result transmitted to the client cannot be understood by the server. This result can therefore possibly be transmitted via the server.

[0348] During the various loops, thanks to the successive operations of the support functions DccHe2 and EncHE2 for deleting and setting up the second, homomorphic encryption (operations S0936 and S0931), the noise level is reduced in the encrypted result [z”]nj2 finally retransmitted to the server, which allows the calculation iterations to continue.

[0349] In the second case above (j=N), upon receipt of the result [F(x)]ni2 under double encryption, the client removes the additional encryption (Decl2) and the first encryption (Decli) and thus obtains the result F(x) in step S4 (S0904). As the second encryption, i.e. the homomorphic encryption, has been removed by the TEE, this avoids the client having to do so: the client only has to carry out much simpler operations of mask deletion (Dec h and Dec 12).

[0350] Note: In another simpler implementation mode, at the end of the verifications, the TEE does not remove the second encryption (does not perform the DecHE2 operation): At the end of the verifications carried out in step S34b (or even without performing these verifications), the TEE calculates a signature of the result o([z”]2) (step S0931b) then returns the result [z”]2 and its signature o([z”]2) to the server. This amounts to bypassing steps S0936 and S0931: this process is illustrated by the dotted arrow on the right part of [Fig.9].

[0351] Advantageously, in this mode of implementation, the data exchanged between the client and the server are not homomorphically encrypted.

[0352] The verifications only concern elementary operations, most often simple (for example: a multiplication). Consequently, the second encryption may not be completely homomorphic (in the sense that one would call a completely homomorphic encryption an encryption allowing an arbitrary number of successive additions and multiplications to be made, i.e. arbitrary multiplicative depth). Thus, for example, a second encryption which is a homomorphic encryption of depth 1 (or of any finite depth) can be used in this mode of implementation.

[0353] In this mode of implementation, the verifications carried out make it possible to prove, step by step, that all the ciphers manipulated during the calculation operations are either calculated by the TEE (which, as holder of the second encryption secret key, is not an attacker for the second encryption), or calculated during legitimate homomorphic calculation operations carried out on ciphers calculated by the TEE (in the dotted 'Proof' rectangle in [Fig.8]). There is therefore no possible CCA adversary on the FHE layer, because an adversary (here, possibly, the server) is not capable of generating homomorphic ciphers which would not be duly produced by the encryption function or derived from such ciphers by legitimate homomorphic operations. 10th mode of implementation

[0354] The 10th mode of implementation will now be presented in relation to Figs. 10 and 11. In this mode of implementation, the Paillier scheme is used to carry out the elementary multiplication operations between ciphertexts under second encryption in step S34; however, it can only be implemented for calculations of multiplicative depth 1.

[0355] Advantageously, since the Paillier scheme intrinsically provides security against CCA attacks, it is no longer necessary in this mode of implementation to resort to signature and signature verification operations as in the mode of implementation presented by Figs. 8 and 9.

[0356] This 10th mode of implementation is based on the Paillier cipher multiplication method described in document Ref.3. and briefly recalled below:

[0357] We consider that we have a mask b previously generated randomly in ZN.

[0358] We consider an initial data (or message) m. From this data m and the mask b, we define a cipher CF, with reference to the authors MM. Catalano and Fiore of Ref.3, noted [m,b]CF, in the following manner:

[0359] [m,b]CF = (mb;EncP(b)) = (mb;[b]P) =(c0,cl)

[0360] where EncP, also noted [,]P, denotes the Paillier encryption function.

[0361] Let us now consider two CF ciphers, namely the pair [m,b]CF = (mb ;EncP(b)), also noted (c0,cl), and the pair [m',b']CF = (m'-b' ;EncP(b')), also noted (c'0,c'l).

[0362] The intermediate variables al, a2 and a3 are defined by the equations:

[0363] al = EncP(c0 x c'0 mod n); a2 = cr°mod n2; a3 = c'lc0 mod n2.

[0364] From these variables al, a2 and a3, the product of the two figures CF is then defined by the triplet (ala2a3 mod n2; cl; c'1) = (c”0; c”l; c”2).

[0365] It is easily verified that c”0 is indeed equal to the Paillier ciphertext of the product mm'-bb'. The product of the two ciphertexts CF is therefore:

[0366] (mb; EncP(b)) * (m'-b'; EncP(b')) = (EncP(mm'-bb'),EncP(b),EncP(b')).

[0367] This operation therefore makes it possible to carry out a form of multiplication of the two initial CF ciphers, on the basis of the additive homomorphic cryptosystem of Paillier.

[0368] However, the result obtained by this multiplication is a triplet: the triplet (c”0,c”i,c”2), and not a CF ciphertext (a pair), like the initial data. The multiplication operations cannot therefore follow one another directly because a multiplication operation expects CF ciphertexts as input and not triplets.

[0369] The calculation method according to the present disclosure will make it possible to overcome this difficulty by delegating to the TEE the reconversion of the triplets into CF ciphertexts. This operation is a support function, since it contributes to the performance of calculations under homomorphic encryption by the server.

[0370] [Fig. 10] shows the preparation of input data for computation, in a scenario where a data m is input by a client CL1, and a data y is input by the server.

[0371] During step S1 (S1001), the data m undergoes two successive masking encryption operations: a first masking EncM11, during which a mask p is applied to the data x; followed by an additional masking EncM12 (additional encryption) during which a mask a is applied to the data x+p: we obtain [m]llj12 = m+p+a.

[0372] During step S2 (S 1002), the encrypted data m+p+a is transmitted to the TEE.

[0373] At a step S1030, the TEE removes the mask a (the additional encryption) and obtains the data under first encryption m+p.

[0374] In parallel, the TEE generates a mask b, and calculates a Paillier cipher [b]P of this mask (step S1031 P).

[0375] These last two elements, as well as the data under first encryption x+p are then combined to form a ciphertext CF (m+pb;[b]P) in step S31 (S1031).

[0376] Furthermore, the server provides an input data y for the calculation. It masks it by adding a mask p' and obtains an encrypted value under first encryption Encl 1: [y]n = y+p' (step S100la).

[0377] In parallel, the TEE generates a mask b', and calculates a Paillier cipher [b']P of this mask (step S1031P also).

[0378] These last two elements, as well as the data under first encryption y+p are then combined to form a ciphertext CF (y+p'-b';[b']P) in step S31 (S1031).

[0379] In this example, the two CF ciphers (x+pb;[b]P) and (y+p'-b';[b']P) are calculated and transmitted to the server in step S32 (S 1032) for carrying out elementary calculation operations.

[0380] When implementing the calculation method according to the present disclosure, these operations are carried out in the following manner.

[0381] The elementary operations that the server must perform are considered to be either additions or multiplications. These two cases are treated differently.

[0382] On the one hand, with regard to additions, the server can successively perform any number of addition operations (since the addition operation does not have the previously indicated disadvantage of providing a triplet as output and not a CF cipher; for more details on this operation, refer to document Ref.3).

[0383] Conversely, the multiplication operations are carried out in the following manner, illustrated by [Fig.l 1].

[0384] To carry out a multiplication operation between two data m and m', we assume that the TEE has two ciphers of these data, under first cipher Encl 1:

[0385] [m]n=m+p and [m']n = m'+p'.

[0386] These figures may be, for example, data provided by clients such as the data m+p of [Fig. 10], or data provided by the server such as the data y+p' of [Fig. 10], or even data produced by the calculation within the TEE from data provided by the server, such as the data mm'+p” which will be presented later.

[0387] The TEE provides two masks b and b', and the Paillier ciphers [b]P and [b']P of these masks (step S1031P or S1131P).

[0388] The TEE then calculates the CF ciphers of the two ciphers to be multiplied (step S1031 or SI 131, which represent the same step). These CF ciphers are therefore in the form of two pairs (m+pb;[b]P) and (m'+p'-b';[b']P). Here the masks p and p' are known to the server but cannot be deciphered by the TEE. The CF cipher, which constitutes the second cipher, cannot be deciphered by the server.

[0389] The TEE transmits the CF ciphers to the server (step S1032 or SI 132).

[0390] The server removes the first cipher Encli by subtracting the first mask p, p' from each of the ciphers in step S33 (SI 133).

[0391] The server then performs the multiplication operation between CF ciphertexts described by the algorithm proposed by document Ref.3 (step SI 134). At the end of this operation, the server obtains the triplet ([mm'-bb']P;[b]P;[b']P).

[0392] The server then encrypts the triplet by adding a mask p' ' to the first term of the triplet using the additive homomorphism property of the Paillier encryption scheme (step S1134a). It then sends the result obtained (mm'-bb'+p” ;[b]P ;[b']P) to the TEE.

[0393] The TEE removes the encryption of the three ciphertexts under Paillier encryption (step S1136). It obtains (mm'-bb'+p”,b,b') and can thus calculate:

[0394] mm'-bb'+p” +b*b' = mm'+p”

[0395] The product mm' of the multiplication thus remains under first encryption, such that the TEE does not know the value of this product.

[0396] As in the general case of the 9th mode of implementation, the processing carried out by the TEE is not the same if all the elementary operations have been carried out and the current loop is the last loop of index j=N, or not, in which case there still remains at least one calculation loop (j < N).

[0397] In the first case, that is to say if j=N, the result obtained at the end of step SI 136 is also the result of the calculation, under first encryption:

[0398] mm'+p” = F(x)+p” = [F(x)]n.

[0399] In this case, this encrypted result is subjected to the operations of steps S1 137 and S4 as in the general case of the 9th implementation mode ([Fig.9]): In step S1 137, the TEE applies an additional encryption Encl2 to it and transmits the result obtained to the client CLE

[0400] In step S4, the client CL1 successively removes the additional encryption (applies the function DecMl2), then removes the first encryption (applies the function DecME), which makes it possible to obtain the desired result F(x).

[0401] Conversely, if one or more elementary operations remain to be carried out (j <n), le tee génère un nouveau masque b”, et calcule chiffré de paillier [b”]p ce (étape s1131p). le b” son sont ensuite combinés avec mm’+p” manière à obtenir cf s31). la paire (mm”+p”-b” ; [b”]p) est alors retransmise au serveur : les calculs peuvent se poursuivre pour l’itération suivante sur la base cette nouvelle en entrée d’une autre valeur laquelle elle doit être multipliée, ainsi suite.

[0402] This 10th mode of implementation has the advantage, compared to the 9th mode of implementation, that it does not require the signature operations provided for in the latter case. References

[0403] Ref.l - L. Coppolino, S. D'Antonio, V. Formicola, G. Mazzeo and L. Romano, “VISE: Combining Intel SGX and Homomorphic Encryption for Cloud Industrial Control Systems” in IEEE Transactions on Computers, vol. 70, no. 5, pp. 711-724, 1 May 2021, doi: 10.1109 / TC.2020.2995638.

[0404] Ref.2 - Wang, W., Jiang, Y., Shen, Q., Huang, W., Chen, H., Wang, S.,... & Lin, D. (2019). Toward scalable fully homomorphic encryption through light trusted computing assistance. arXiv preprint arXiv: 1905.07766.

[0405] Ref.3 - D.Catalano, D.Fiore, ''Boosting Linearly-Homomorphic Encryption to Evaluate Degree-2 Functions on Encrypted Data”, Cryptology ePrint Archive, Paper 2014 / 813.

[0406] Ref.4 - D.Natarajan, A.Loveless, W.Dai, R.Dreslinski, "Chex-Mix: Combining homomorphic Encryption with Trusted Execution Environments for Two-party Oblivious Inference in the Cloud’, IACR, International Association for Cryptographie Research, vol.20220908:153418.

[0407] Ref.5 - D.Fiore, R.Gennaro, V.Pastro, "Efficiently Vérifiable Computation on Encrypted Data”, Cryptology ePrint Archive, Paper 2014 / 202.

Claims

1. Claims Method for processing data in a system comprising two computers to obtain a result from at least one input data (x) to be provided by at least one transmitting client (CL1, CL2), the result being obtained by applying a combination of elementary operations (f, g, h; gj) to at least one input data (x); in which one of the computers is a server, and the other is a secure execution environment, TEE; a first cipher [Encl,Decl] and a second cipher [Enc2,Dec2] are defined, one being indecipherable by the server, and the other being indecipherable by the TEE; The process involves the following steps: SI) at least one sending client (CLl) provides an input data (x) and applies the first encryption (Encl) to it; S2) said at least one transmitting client (CL1) transmits the input data ([x]i; [x]1>2)) under the first encryption (Encl) to one of the computers; S3) during data processing, the two computers apply the combination of elementary operations to said encrypted data received in step S2 so as to obtain an encrypted ([F(x)]) of the result, and transmit this result to at least one receiving client (CL1, CL2), step S3 comprising the following elementary steps: S31) the first computer encrypts the data processed under second encryption (Enc2); S32) the first computer transmits to the second computer the processed data ([x] i>2) obtained, encrypted under first and second encryption; and S33) the second calculator removes the first encryption (Decl) from the received processed data; S4) said at least one receiving client decrypts the ciphertext of the result ([F(x)]) and obtains the result (F(x)); during the data processing carried out in step S3, the server only processes processed data under at least the encryption indecipherable by the server, and the TEE only processes processed data under at least the encryption indecipherable by the TEE, which may in particular be a masking encryption; and the first and second encryptions verify the property, for any processed data x: Dec2(Decl(Enc2(Encl(x)))) = Dec2(Enc2(x)).

2. Data processing method according to claim 1, wherein said encryption indecipherable by the server is or comprises homomorphic encryption, in particular totally homomorphic encryption.

3. Data processing method according to claim 2, wherein in step S3, the TEE applies to the processed data or to the processed data only one or more support functions; a support function being a function other than said elementary operations and which: - contributes to the execution of homomorphic calculations by the server or to the verification thereof; - serves to encrypt or decrypt data to be processed received from the client, data processed (by the computers), or results sent to the client; and / or - serves to prepare (verification) data serving to verify data to be processed received from the client, data processed, and / or results sent to the client.

4. Data processing method according to any one of claims 1 to 3, comprising the following steps: S0235) the second computer applies the first encryption (EncHEl) to the data decrypted during step S33, and transmits the data obtained to the first computer; and S0236) the first computer removes the second encryption (DecM2) from the processed data received at the end of step S0235.

5. Data processing method according to claim 4, wherein step S0235 is performed immediately after step S33, such that during step S0235, the second computer applies the first encryption (EncHEl) to the processed data obtained at the output of step S33.

6. A data processing method according to any one of claims 1 to 5, wherein during step S3, the processed data is encrypted under an encryption (Encl2) other than the first encryption or is encrypted with the first encryption but with another encryption key; and the encrypted result returned at the end of step S3 is encrypted with an encryption different from the first encryption or is encrypted with the first encryption but with a different encryption key.

7. Data processing method according to any one of claims 1 to 6, in which a receiving client (CL1, CL2) receiving the encrypted result at the end of step S3, is identical to or different from the or each of said at least one sending client (CL1) providing the data (x) in step S1.

8. Data processing method according to any one of claims 1 to 7, further comprising a step S0411 preceding step S2 and during which the first client (CL1) applies an additional encryption (EncS), in particular symmetric, to the data (x); and after the data ([x] xs) has been transmitted to the first computer in step S2, the first computer removes the additional encryption (S0430).

9. Data processing method according to any one of claims 1 to 8, wherein - during an operation S0533, the TEE removes the first encryption (DecMli), called first initial encryption, which may in particular be a masking encryption, from the processed data; and - during an operation S0535, the TEE applies to the processed data a homomorphic encryption (EncHEl2), as first final encryption; - during an operation S0535a, following step S0535, the data processed under first final encryption (EncMli) and under second encryption (EncHEl2) is transmitted to the server; when all the elementary operations have been carried out, the cipher of the result is transmitted to the client under first final encryption (EncHEl2); and in step S4, the client removes the first final encryption (DecHEl2).

10. Data processing method according to any one of claims 1 to 8, wherein the first encryption applied in step S1 is the homomorphic encryption (EncHEli), called first homomorphic encryption; during a step S0633, the TEE removes the first homomorphic encryption (DecHEli) from the processed data; during a step S0635 carried out after step S0633, the TEE applies to the data a second homomorphic encryption (Encl2) other than the first homomorphic encryption; and in step S4, the client removes the second homomorphic encryption from the encrypted result.

11. A data processing method according to any one of claims 1 to 10, wherein the combination of elementary operations comprises N elementary operations of order j, j=1...N; step S3 comprises the execution of a plurality of calculation loops, iteratively; at each loop of index j, j=1.. N, steps S1 (0701), S31 (S0731), S32 (S0732) and S33 (S0733), a step S0730, a step S0735 and a step S0736 are carried out in the following manner: during step S1 (S0701), the client provides an input data of index j (xj), and transmits said input data of index j to the first calculator, which is the server, as input data for step S0730; during step S0730, the server applies the elementary operation (gj) of index j to the data provided to it as input;the server performs step S31 (S0731) of applying the second encryption to the processed data and step S32 of transmitting the encrypted processed data to the TEE; the TEE performs step S33 of deleting the first encryption of the processed data, then in step S0735 applies the first encryption to the data again, then retransmits the data thus re-encrypted to the server; upon receipt of said data thus re-encrypted, the server during a step S0736a deletes the second encryption therefrom; the data thus modified is then provided as input data for operation S0730 of the following calculation loop if this takes place.;

12. Data processing method according to claim 11, in which a verifiable calculation protocol (ji) is defined, which makes it possible to verify the result by carrying out an elementary verification for each of said elementary operations; the first calculator is the server, and the second calculator is the TEE; a tag computation function (ir.tag) is defined within the verifiable computation protocol, this function being commutative with the elementary operations gj; in step S1 (S0701), the client further transmits to the server a tag (tag([x]i) of the ciphertext under first encryption of the data (x); the second encryption is a mask encryption (mj); at each loop of index j, j = 1.. .N: in a step S0701a, the client provides the server with a mask (nij) and a mask tag (tag(nij)) of the mask; during a step S0730, the server applies the elementary operation (gj) of index j to the processed data tag provided to it as input; during a step S0731, the server encrypts the processed data under second encryption (Enc2); during a step S0732, the server transmits to the TEE the processed data ([x] 12) obtained, encrypted under first and second encryption; during a step S0730a, the server applies the elementary operation (gj) of index j to the data tag provided to it as input; during a step S0731a, the server calculates the tag of the double-encrypted cipher (tag([gj(x)]i2)) from the tag (tag([gj(x)]i)) obtained in step S0730a, and the tag (tag(mj)) of the mask mj, and transmits this tag to the TEE; during a step S0732a, depending on the encrypted data received in step S0732, and the encrypted data tag received in step S0731a, the TEE verifies the elementary operation carried out in step S0730 by carrying out the elementary verification corresponding to this operation; if the result is positive and the loop index j verifies j <N, à l’étape S0733 : - the TEE removes the first encryption (DecHEl) from the encrypted data received in step S0732 performed during the loop, then - during a step S0735, applies the first encryption (EncHE 1) to the data under second encryption and transmits the encrypted data obtained to the server; - during a step S0736, the server removes the second encryption (DecM2) from the data received at the end of step S0735, and provides the data thus decrypted as input data for the operation S0730 of the following calculation loop; - during a step S0735a, the TEE calculates a tag of the encrypted data calculated in step S0735 and transmits this tag to the server; then - during a step S0736a, the server calculates the tag of the unmasked cipher (tag([gj(x)]i)) from the tag received at the end of step S0735a and the tag of the mask, and provides the tag of the unmasked cipher as input data for the operation S0730a of the following calculation loop.

13. Data processing method according to claim 11, wherein the first computer is the TEE; during at least one of the calculation loops, called loop J, of index j=J, the method is executed in the following manner: in step S32 of loop J, in addition to the data encrypted under first and second encryption ([z]n>2), the first computer transmits to the second computer a signature (o([z]nj2)) thereof, as well as another data encrypted ([z']n>2) under first and second encryption accompanied by a signature (o([z']nj2)) thereof; in step S33 of loop J (S0933), the server removes the first encryption from the data encrypted under double encryption and from said other data received in step S32; at a step S0934 of the loop J, the server applies the elementary operation of index J to the two decrypted data obtained at step S33;at a step S0934a of the loop J, the server applies the first encryption (EncMli) to the data obtained; the server further calculates a proof of calculation proving that the encrypted data obtained at the end of step S0934a is indeed the result of the application of the elementary operation of index J to the two data used as input for step S0934, and transmits the encrypted data obtained at step S0934a as well as the proof to the TEE; during a step S0934b, the TEE verifies at least whether the proof corresponds to the result of the calculation; and, if the result of the verification is positive, at a step S0936 the first calculator removes the second encryption of the data (DecHE2), and provides the data obtained as input for a step S31 of the next index loop if this takes place; if the result of the verification is negative, the TEE interrupts the processing.

14. Data processing method according to claim 11, wherein the first calculator is the TEE; the second encryption being a homomorphic encryption ensuring security against CCA attacks, for example the Paillier encryption; during at least one of the calculation loops, called loop J, of index j=J, the method is executed in the following manner: in step S32 of loop J (SI 132), in addition to the data encrypted under first and second encryption ([z]n>2), the TEE transmits to the server another data encrypted ([z']n>2) under first and second encryption; in step S33 of loop J (SI 133), the server removes the first encryption from the data encrypted under double encryption and from said other data received in step S32; at a step SI 134 of the loop J, the server applies the elementary operation of index J to the two decrypted data obtained at step S33;at a step SI 134a of the loop J, the server applies the first encryption (EncMli) to the data obtained by applying the elementary operation (gj) of index J at step SI 134; the server transmits the encrypted data obtained at step SI 134a to the TEE; and, at a step SI 136, the TEE removes the second encryption from the data (DecCF), and provides the data obtained as input for a step S31 of the loop of the following index if this must take place.;

Citation Information

Patent Citations

  • Privacy calculation method and system based on TEE and FHE technologies

    CN116506100A

  • Outsourcing processing operations with homomorphic encryption

    US20190327077A1