Data processing method

A dual-computer system with undecipherable encryptions for the server and TEE securely processes data, addressing large ciphertext sizes and security issues in homomorphic encryption, enhancing efficiency and security against malicious servers and 'honest-but-curious' TEEs.

FR3157599B1Active Publication Date: 2026-02-20COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023014913
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-12-21
Publication Date
2026-02-20
Estimated Expiration
2043-12-21

AI Technical Summary

Technical Problem

Existing homomorphic encryption techniques face challenges with large ciphertext sizes leading to increased computation requirements and limited security against privileged actors and malicious servers, especially when assuming a trustworthy Trusted Execution Environment (TEE) that may exhibit 'honest-but-curious' behavior.

Method used

A data processing method involving two computers, a server and a secure execution environment (TEE), uses undecipherable encryptions for each, ensuring confidentiality by processing encrypted data, with the server handling computations using homomorphic encryption and the TEE performing support operations like noise reset and re-encryption to reduce computational load and enhance security.

Benefits of technology

This approach ensures secure and efficient data processing even with malicious server behavior, reducing computational overhead and bandwidth consumption while maintaining data confidentiality, especially against 'honest-but-curious' TEEs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000044_0000
    Figure 00000044_0000
  • Figure 00000045_0000
    Figure 00000045_0000
  • Figure 00000045_0001
    Figure 00000045_0001
Patent Text Reader

Abstract

Data processing method to obtain a result (x) by a combination of elementary operations (f,g,h ;gj); in which two ciphers [Enc1,Dec1 ; Enc2,Dec2] are defined, one undecipherable by a server, the other undecipherable by a TEE; and S1) a sending client (CL1) provides and encrypts an input data (x); S2) it transmits it under the cipher (Enc1) to the server or the TEE; S3) by data processing, these two computers apply the combination of elementary operations to the received cipher data so as to obtain a cipher ([F(x)]) of the result, which they transmit to a receiving client (CL1,CL2); S4) the latter deciphers the cipher of the result ([F(x)]) and obtains the result (F(x)). During step S3, the server processes only data encrypted using an unbreakable encryption method, and the TEE processes only data encrypted using an unbreakable encryption method. See Figure 1 for abbreviations.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Data processing method TECHNICAL FIELD OF THE INVENTION

[0001] The field of the invention is the field of data processing and more particularly, of data processing in a secure manner.

[0002] More specifically, the invention relates to a data processing method in a system comprising two computers for securely obtaining a result based on input data provided by clients or users of the system. PRIOR TECHNOLOGY

[0003] This disclosure is part of a considerable trend in recent years in data processing, which is the increasing use of the 'cloud', i.e. cloud architectures, to carry out various processing operations on data, regardless of their nature.

[0004] However, the relocation of these operations to the cloud naturally raises new issues in turn, in particular the difficulty of ensuring data confidentiality and the integrity of the operations carried out.

[0005] Various encryption techniques have been developed to meet the need for data confidentiality.

[0006] Among these, homomorphic encryption techniques stand out. Advantageously, homomorphic encryption allows the processing applied to the data to be performed on encrypted data. However, homomorphic encryption uses ciphertexts whose size is very large compared to that of the initial data. This leads to a considerable increase in the amount of computation required, which is naturally extremely problematic for the implementation of this technique.

[0007] Moreover, although these techniques prove effective in preventing data breaches against third parties, they may, on the other hand, have limited effectiveness against certain types of actors, in particular privileged actors: system administrator, cloud infrastructure provider, or more generally any person authorized to intervene in the processing.

[0008] To remedy these drawbacks, it has been proposed (see, for example, document Ref. 2 or 4) to delegate at least part of the data processing performed on homomorphic ciphers (such calculations will be referred to hereafter as 'performed in homomorphic mode') to a secure secondary computer of the Trusted Execution Environment, or 'TEE' type. Such a computer type is defined in particular by document Ref. 4.

[0009] Such a delegation of calculation advantageously reduces significantly the amount of calculations to be performed.

[0010] However, these methods which combine homomorphic encryption and the delegation of certain data processing to a TEE remain limited to very specific applications, for example, the secure sharing of a key, the training of a neural network with homomorphic encryption for quadratic functions and the rest of the computation in the TEE, an aggregation method combining homomorphic computation and the delegation of computation to a TEE, etc.

[0011] Moreover, all these solutions are situated within the context of a TEE which, by hypothesis, is assumed to be trustworthy. For this reason, these methods do not provide protection against an "honest-but-curious" TEE. As a reminder, in the field of cryptography and security protocols, an "honest-but-curious" computer (also called a passive or semi-honest adversary) is a type of adversary that follows the protocol correctly but tries to learn as much as possible from the available information (see document Ref. 4).

[0012] Finally, these solutions do not necessarily ensure the security of calculations in the event that the server adopts malicious behavior. Description of the invention

[0013] The present invention aims to provide a data processing method that avoids the risks suggested above.

[0014] To this end, a data processing method is proposed in which calculations are carried out in a distributed manner on two computers, namely a server and a security hardware module, or TEE, the method making it possible to ensure the confidentiality of the data even in the case where the server adopts malicious behavior, while the TEE adopts an "honest-but-curious" behavior.

[0015] To this end, according to this disclosure, a data processing method is proposed in a system comprising two computers to obtain a result from at least one input data item to be provided by at least one sending client, the result being computable by applying a combination of elementary operations to at least one input data item; wherein one of the computers is a server, and the other is a secure execution environment, TEE; a first encryption and a second encryption are defined, one being undecipherable by the server, and the other being undecipherable by the TEE; the method comprises the following steps:

[0016] IF) at least one sending client provides input data and applies the first encryption to it;

[0017] S2) said at least one sending client transmits the input data under the first encryption to one of the computers;

[0018] S3) during data processing, the two computers apply the combination of elementary operations on said encrypted data received in step S2 so as to obtain an encrypted version of the result, and transmit this result to at least one receiving client, step S3 comprising the following elementary steps:

[0019] S31) the first computer encrypts the processed data under second encryption;

[0020] S32) the first computer transmits the processed data to the second computer obtained, encrypted using first and second encryption; and

[0021] S33) the second computer removes the first encryption of the processed data received;

[0022] S4) said at least one receiving client decrypts the ciphertext of the result and obtains the result ;

[0023] during data processing carried out in step S3, the server only processes data processed under at least encryption that is unbreakable by the server, and the TEE only processes data processed under at least encryption that is unbreakable by the TEE, which may include, in particular, encryption by masking; and

[0024] The first and second encryptions verify ownership, for any processed data x:

[0025] Dec2(Decl(Enc2(Encl(x)))) = Dec2(Enc2(x)).

[0026] In this document, the expression 'encrypted data' refers to data that is encrypted at least using the encryption method in question. The data may optionally be under double (or even triple) encryption.

[0027] The fact that the encryption is undecipherable by the server means, for example, that the server does not have the decryption function, or does not have the decryption key.

[0028] The fact that the server only processes data using at least encryption that is unbreakable by the server means that all processed data transmitted to the server is first encrypted using at least encryption that is unbreakable by the server. Similarly, the fact that the TEE only processes data using at least encryption that is unbreakable by the TEE means that all processed data transmitted to the TEE is first encrypted using at least encryption that is unbreakable by the TEE.

[0029] In some embodiments, one of the ciphers is decipherable by the server but not by the TEE, and the other of the two ciphers conversely is decipherable by the TEE but not by the server.

[0030] The TEE is a component that generally has a relatively small memory capacity. Preferably, the memory of the TEE has a capacity that does not exceed 1 GB, or preferably that does not exceed 512 MB (Megabytes), and even more preferably not exceeding 256 MB. Naturally, it is assumed that the TEE is ethical in the processing it applies to the processed data.

[0031] In the process, the first computer can be the server and the second computer the TEE, or vice versa.

[0032] The central step of the process defined above is step S3. During this step, processing is applied by the computers to the encrypted input data received in step S2.

[0033] This process involves a number of elementary operations.

[0034] These elementary operations successively transform the initial input data into different processed data. The term 'processed data' refers to data obtained from the initial data during the processing. When all the elementary operations constituting the processing have been carried out, the computers obtain an encrypted result. This is then transmitted to one or more clients (called receiving clients).

[0035] Thus during the processing, the computers apply the combination of elementary operations to the input data received, which allows them to obtain the cipher of the desired result.

[0036] Importantly in the process, at step S3, instead of being executed on plaintext data x, all operations carried out during the processing are executed on encrypted data [x].

[0037] Each of the computers is therefore configured to apply each of its processing operations not to plaintext data, but to a corresponding encrypted value. Thus, in particular, if an elementary operation consists of applying a function f to a processed value x, one of the computers actually applies a function f to the encrypted value [x] in such a way as to provide an output encrypted value equal to the value of the result, i.e., [f(x)]. The computer therefore effectively applies a function f to the encrypted value [x] of the value x, and provides the output encrypted value of the result: / ([x]) = [ / (x)]. For simplicity in what follows, the function f is denoted f' as the function from which it is derived.

[0038] In the process most often, in a manner known per se, the operations constituting the processing are executed exclusively on integers modulo a predefined maximum value T.

[0039] In the process, advantageously the data is encrypted throughout all the steps (or operations) performed, whether these are carried out by the server or by the TEE. Consequently, this process makes it possible to carry out these steps securely, not only even if the server is malicious, but also if the TEE adopts "honest but curious" behavior.

[0040] In the process, depending on the implementation method and unless otherwise indicated, any application and any removal of encryption to data may optionally be preceded or followed by an elementary operation modifying the data being processed.

[0041] In this document, a masking encryption includes any logical addition that allows modification of the data that is encrypted (using the mask), for example an addition, an exclusive OR (XOR) logical function, etc.

[0042] In the process, any type of encryption unbreakable by the server may be used. The encryption unbreakable by the server may thus be, or may include, a homomorphic encryption, in particular a totally homomorphic one.

[0043] Preferably, each operation on processed data performed by the server is carried out using homomorphic encryption. In this case, the server only processes data that has been processed using at least one homomorphic encryption.

[0044] Thus in certain implementation modes, the first encryption is a homomorphic encryption and the second encryption a masking encryption, or vice versa.

[0045] To enable computers to perform the processing on encrypted data, the method includes support operations during which support functions are applied to the input data, the processed data or the results, each of which may be encrypted.

[0046] The term 'support function' here refers to a function other than the aforementioned elementary operations and which:

[0047] - contributes to the execution of homomorphic calculations by the server or to the verification of these;

[0048] - is used to encrypt or decrypt data to be processed received from the client, data processed (by the calculators), or results sent to the client; and / or

[0049] - is used to prepare data (verification data) used to verify data to be processed received from the client, data processed, and / or results sent to the client.

[0050] It is understood that the support functions do not participate in the execution of the elementary operations (since they are other than the elementary operations), but serve only either to enable these elementary operations to be carried out on encrypted data, or to encrypt or decrypt data provided to or sent by computers, or to verify or ensure that the various operations involved in the process, in particular the elementary operations, have been properly carried out.

[0051] In certain implementation modes, at step S3, the TEE applies only one or more support functions to the processed data. The elementary processing operations are then carried out exclusively by the server.

[0052] In some embodiments, the process comprises the following steps:

[0053] S0235) the second computer applies the first encryption to the data deciphered during step S33, and transmits the obtained data to the first computer; and

[0054] S0236) the first computer removes the second encryption of the processed data received at the end of step S0235.

[0055] Thus, starting from the data processed under second encryption available on the server at step S33, the server can provide data processed under double encryption to the first computer. The latter can then remove the second encryption. If the data processed at this stage is in fact the ciphertext of the result, the first computer can then transmit this ciphertext of the result (under first encryption) to the client, which decrypts it.

[0056] Preferably, step S0235 is performed immediately after step S33, such that during step S0235, the second computer applies the first encryption to the processed data obtained from the output of step S33. Thanks to this, when the first encryption is a homomorphic encryption, steps S33 and S0235 make it possible to perform a noise reset or a linearization.

[0057] Since the two steps S33 and S0235 are executed immediately one after the other, without any intermediate operation, they constitute a decryption / re-encryption operation. More generally, these two grouped operations can also constitute bootstrapping, a re-linearization of LHE (Levelled Homomorphic Encryption), or both, or any other ciphertext management operation. They can thus be operations conducted to obtain a ciphertext again in the format of a 'fresh' ciphertext.

[0058] This last operation is normally performed when removing and then reapplying the encryption reduces the noise level in the ciphertexts, which is particularly the case for certain homomorphic ciphers (first ciphers). This operation is preferably performed when the second computer is a TEE.

[0059] In this case, thanks to the successive decryption and re-encryption operations carried out by the TEE, when there is a trans-encryption operation with a high expansion factor, the size of the ciphertexts transmitted from and to the client can be drastically reduced, resulting in a reduction in bandwidth consumption between the client and the server.

[0060] Furthermore, since the maintenance operations for encrypted data are thus delegated to the TEE, which performs them at a much lower cost than the server, the performance of the server's homomorphic computation is considerably increased. Re-encryption allows for the refresh of homomorphic ciphers and has an effect equivalent to a bootstrapping operation but with a better resulting noise level.

[0061] In certain embodiments, the method is implemented iteratively over a plurality of computation loops. One of the encryption methods may also be a mask encryption. In this case, for the application of the mask encryption during the method, the client or the relevant computer generates a mask stream; and at each computation loop, a new mask is generated and used for masking.

[0062] In many implementation modes, the encrypted result returned to the receiving client(s) at the end of step S3 is encrypted under at least the first encryption, but this is not necessarily the case.

[0063] Thus, on the contrary, in certain modes of implementation of the process, during step S3, the processed data is encrypted under an encryption other than the first encryption or is encrypted with the first encryption but with a different encryption key; and the encrypted result returned at the end of step S3 is encrypted with an encryption different from the first encryption or is encrypted with the first encryption but with a different encryption key.

[0064] These implementation methods therefore make it possible to carry out a key switching operation in a secure manner.

[0065] Depending on the implementation methods, the receiving client(s) receiving the encrypted result at the end of step S3 may be identical or different from the or each of said at least one sending client providing the data in step SI.

[0066] In some embodiments, the process further includes a step S0411 preceding step S2 and during which the first client applies additional encryption, in particular symmetric encryption, to the data; and after the data has been transmitted to the first computer in step S2, the first computer removes the additional encryption.

[0067] This additional encryption allows the initial encrypted data to be transmitted from the client to the first computer. The second encryption can then be applied by the first computer, rather than by the client. This reduces the computational workload for the client (applying the additional encryption, for example symmetric, can be simpler than applying the second encryption, which is typically homomorphic). Furthermore, it eliminates the need for the client to possess the encryption key for the second encryption, thus reducing communication costs.

[0068] In certain implementations of the process, during an S0533 operation, the TEE removes the first encryption, referred to as the initial first encryption, which may be, in particular, a masking encryption, from the processed data; and

[0069] - during an S0535 operation, the TEE applies encryption to the processed data homomorphic, as the first final cipher;

[0070] - during an operation S0535a, following step S0535, the data processed under first final encryption and under second encryption is transmitted to the server;

[0071] when all the elementary operations have been carried out, the cipher of the result is transmitted to the customer under first final encryption; and at step S4, the customer removes the first final encryption.

[0072] In this implementation, the client applies an initial encryption to the data it transmits to the first computer. During steps S0533 and S0535, the initial encryption is removed and replaced by the final encryption. It is this final encryption that will be decrypted by the client in the final step S4. This implementation therefore allows for transcryption, and in particular, potentially, for replacing a masking encryption with a homomorphic encryption.

[0073] In this embodiment, the TEE is preferably the first computer.

[0074] At step S2, the input data under initial first encryption is first transmitted to the server.

[0075] After receiving this data, during a step S0531, the server applies the second encryption to the processed data, which is a masking encryption, and transmits it to the TEE, encrypted under this second encryption.

[0076] After the data processed under first and second encryption has been transmitted to the server following step S0535a, the server removes the second encryption (the masking encryption) in step S0536. All or part of the elementary operations can be performed by the server only after step S0536 has been completed.

[0077] In certain implementation modes of the process, the first encryption applied at step SI is the homomorphic encryption, called the first homomorphic encryption;

[0078] during an S0633 step, the TEE removes the first homomorphic encryption of the processed data;

[0079] during a step S0635 performed after step S0633, the TEE applies to the data a second homomorphic encryption other than the first homomorphic encryption; and

[0080] at step S4, the client removes the second homomorphic cipher from the encrypted result.

[0081] This implementation method makes it possible to perform a transcipher, the first homomorphic encryption being replaced by the second homomorphic encryption by the TEE during steps S33 and S35.

[0082] Iterative process

[0083] In certain embodiments of the process, the combination of elementary operations comprises N elementary operations of order j, j=l.. .N;

[0084] Step S3 involves the execution of a plurality of calculation loops, in an iterative manner;

[0085] at each loop of index j, j=L. N, the steps SI, S31, S32 and S33, one step S0730, one step S0735 and one step S0736 are carried out in the following way:

[0086] during the SI step, the client provides an input data index j, and transmits said input data index j to the first computer, which is the server, as input data for the S0730 step;

[0087] During step S0730, the server applies the elementary operation of index j to the data provided to it as input;

[0088] the server performs step S31 of applying the second encryption to the processed data and step S32 of transmitting the encrypted processed data to the TEE;

[0089] the TEE performs step S33 of removing the first encryption of the processed data, then at step S0735 applies the first encryption again to the data, then retransmits the data thus re-encrypted to the server;

[0090] Upon receipt of said data thus re-encrypted, the server during a step S0736a removes the second encryption from it; the data thus modified is then provided as input data for operation S0730 of the next calculation loop if it takes place.

[0091] Furthermore, the security of the processing carried out by the computers can be increased when a verifiable calculation protocol is known for the processing to be carried out.

[0092] We consider more particularly the case where a verifiable calculation protocol is defined, and allows the result to be verified by carrying out an elementary verification for each of the said elementary operations.

[0093] We consider the case where the first computer is the server, and the second computer is the TEE. A tag calculation function is defined within the framework of the verifiable calculation protocol, this function being commutative with the elementary operations gj (for the composition of functions o).

[0094] The first computer is the server, and the second computer is the TEE.

[0095] A tag calculation function is defined within the framework of the calculation protocol verifiable, this function being commutative with elementary operations.

[0096] The process then comprises the following steps:

[0097] at the SI step, the client also transmits to the server a tag of the encrypted data under first encryption;

[0098] the second encryption is a mask encryption;

[0099] at each loop of index j, j = 1.. .N:

[0100] at a step S0701a, the client provides the server with a mask (mj) and a mask tag of the mask;

[0101] during an S0730 step, the server applies the elementary operation of index j to the processed data tag that is provided to it as input;

[0102] during a step S0731, the server encrypts the processed data under second encryption;

[0103] during a step S0732, the server transmits to the TEE the processed data obtained, encrypted under first and second encryption;

[0104] during a step S0730a, the server applies the elementary operation (gj) of index j to the data tag provided to it as input;

[0105] during a step S0731a, the server calculates the tag of the ciphertext under double encryption from the tag obtained in step S0730a and the tag of the mask, and transmits this tag to the TEE;

[0106] during a step S0732a, depending on the encrypted data received at step S0732, and the encrypted data tag received at step S0731a, the TEE verifies the elementary operation performed at step S0730 by performing the elementary check corresponding to that operation;

[0107] if the result is positive and the loop index j satisfies j <N, à l’étape S0733 :

[0108] - the TEE removes the first encryption (DecHEl) from the encrypted data received at the step S0732 performed during the loop, then

[0109] - during a step S0735, applies the first encryption to the data under second encryption and transmits the encrypted data obtained to the server;

[0110] - during an S0736 step, the server removes the second encryption of the data received at the end of step S0735, and provides the data thus decrypted as input data for operation S0730 of the following calculation loop;

[0111] - during a step S0735a, the TEE calculates a tag of the encrypted data calculated at step S0735 and transmits this tag to the server; then

[0112] - during an S0736a step, the server calculates the tag of the unmasked ciphertext (that is- (i.e. the ciphertext whose mask, corresponding to the second encryption, has been removed) from the tag received at the end of step S0735a and the tag of the mask, and provides the tag of the unmasked ciphertext as input data for operation S0730a of the following computation loop.

[0113] Through a signature, verification and, optionally, homomorphic re-encryption operation in the TEE, a scheme is constructed which establishes step by step that all the manipulated ciphertexts are either generated by the TEE (which, as the holder of the homomorphic encryption secret key, is not an attacker on the homomorphic scheme), or generated by the application of the homomorphic operators legitimate ciphers generated by the TEE. Therefore, there is no possible CCA adversary for homomorphic encryption, which provides a reinforced level of security.

[0114] A signature here is any value attached to a message that proves its integrity: The signature allows verification that the message has not been altered. A signature is generally obtained cryptographically from a hash of the message, for example using a known public-key signature function such as RSA or ECDSA.

[0115] Moreover, certain implementation methods exploiting the commutativity of the two ciphers allow calculations to be carried out with increased security, and in particular by benefiting from protection against CCA attacks.

[0116] Thus in certain modes of implementation of the process, the first calculator is the TEE;

[0117] during at least one of the calculation loops, called loop J, of index j=J, and preferably during all the loops, the process is executed in the following manner:

[0118] at step S32 of loop J, in addition to the data encrypted under first and second encryption, the first computer transmits to the second computer a signature of it, as well as another data encrypted under first and second encryption accompanied by a signature of the latter;

[0119] at step S33 of loop J, the server removes the first encryption from the data encrypted under double encryption and from said other data received at step S32;

[0120] at a step S0934 of the loop J, the server applies the elementary index operation J to the two decrypted data obtained at step S33;

[0121] at a step S0934a of the loop J, the server applies the first encryption to the data obtained (by applying the elementary operation of index J);

[0122] the server further calculates a proof of calculation proving that the encrypted data obtained at the end of step S0934a is indeed the result of applying the elementary operation of index J to the two data used as input for step S0934, and transmits the encrypted data obtained at step S0934a as well as the proof to the TEE;

[0123] during a step S0934b, the TEE verifies at least whether the proof corresponds to the result of the calculation; and,

[0124] if the result of the verification is positive, at a step S0936 the first computer removes the second encryption of the data, and provides the data obtained as input for a step S31 of the next index loop if it takes place; if the result of the verification is negative, the TEE interrupts the processing.

[0125] The check performed during the J loop makes it possible to detect a CCA attack that would have taken place during the J loop.

[0126] Furthermore, in certain variants of these implementation modes, at a step S31b of the J loop, the first computer obtains signatures for two data figures calculated at step S31 performed for iteration j=J or at a previous iteration;

[0127] at step S32 of loop J, the first computer also transmits the signatures of said two encrypted data to the second computer;

[0128] after calculating the proof of computation during the J loop, the second computer returns to the first computer the two input data and their respective signatures; and

[0129] The verification carried out in step S34b includes, for each of the two data thus returned to the first computer with their signatures, a verification that each of the data corresponds to its signature.

[0130] Thanks to the verification operation, preferably carried out in a TEE, the validity of the calculation performed by the server can be assured to the client with a lower additional cost than with classic protocols.

[0131] Some variants of the above implementation methods, also aimed at performing calculations more securely against CCA attacks, use adapted encryption schemes, such as the Paillier encryption scheme.

[0132] In these variants of implementation of the process, the first computer is the TEE;

[0133] the first calculator is the TEE;

[0134] the second encryption being a homomorphic encryption ensuring security against CCA attacks, for example the Paillier cipher;

[0135] during at least one of the calculation loops, called loop J, of index j=J, the process is executed in the following manner:

[0136] at step S32 of loop J, in addition to the encrypted data under first and second encryption, the TEE transmits to the server another encrypted data ([z']nj2) under first and second encryption;

[0137] at step S33 of loop J, the server removes the first encryption from the data encrypted under double encryption and from said other data received at step S32;

[0138] at a step SI 134 of the loop J, the server applies the elementary index operation J to the two decrypted data obtained at step S33;

[0139] at an SI step 134a of the loop J, the server applies the first encryption to the data obtained by applying the elementary operation of index J at the SI step 134;

[0140] the server transmits the encrypted data obtained in step SI 134a to the TEE; and,

[0141] at an SI 136 step, the TEE removes the second encryption of the data (DecCp), and provides the resulting data as input for an S31 step of the next index loop if it is to take place.

[0142] In the implementation modes presented above, thanks to the verifiable cryptographic calculation scheme, it is then possible to perform the checks indicated above systematically, for each of the operations of the combination of elementary operations (unless this check is not necessary for certain types of elementary operations, for example for additions).

[0143] In this case, this systematic verification makes it possible to provide proof that the calculation performed benefits from CCA security. BRIEF DESCRIPTION OF THE FIGURES

[0144] Other advantages, purposes and particular features of the present invention will become apparent from the following non-limiting description of at least one particular embodiment of the devices and methods of the present invention, with reference to the accompanying drawings, in which:

[0145] [Fig. 1] is a schematic perspective view illustrating a first and a sixth embodiment of the invention;

[0146] [Fig.2] is a schematic perspective view illustrating a second and a third embodiment of the invention;

[0147] [Fig.3] is a schematic perspective view illustrating a fourth embodiment of the invention;

[0148] [Fig.4] is a schematic perspective view illustrating a fifth embodiment of the invention;

[0149] [Fig.5] is a schematic perspective view illustrating a sixth embodiment of the invention;

[0150] [Fig.6] is a schematic perspective view illustrating a seventh embodiment of the invention;

[0151] [Fig.7] is a schematic perspective view illustrating an eighth embodiment of the invention;

[0152] [Fig.8] is a schematic perspective view illustrating the input data supply steps, for a ninth embodiment of the invention;

[0153] [Fig.9] is a schematic perspective view illustrating the calculation steps, for the ninth embodiment of the invention;

[0154] [Fig. 10] is a schematic perspective view illustrating the input data supply steps, for a tenth embodiment of the invention;

[0155] [Fig. 11] is a schematic perspective view illustrating the calculation steps for the tenth embodiment of the invention; and

[0156] [Fig. 12] is a flowchart schematically showing the steps of an implementation method of a process according to this disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0157] By way of non-limiting examples of implementation, different modes of implementation of the data processing method according to this disclosure will now be presented.

[0158] Each of these implementation modes involves the following three entities: a group of at least one client, a server and a TEE.

[0159] Any type of computer can be considered as constituting the server. However, the server is preferably a computer with large computing capabilities.

[0160] In the data processing methods described in this disclosure, each computer performs the assigned tasks on encrypted data. This data is encrypted using a cipher that is unbreakable by the computer, such that the computer does not have access to the information contained in this data. This cipher may, in particular, be a homomorphic cipher or a masking cipher.

[0161] The encryption and decryption functions are denoted respectively Encxx 1, EncYY2,... and respectively Decxxl, DccYy2, ..., where '1', '2' are indices; XX and YY indicate the type of encryption used: for example HE for homomorphic encryption, S for symmetric encryption, and M for masking encryption.

[0162] The encrypted data is denoted in square brackets in the form [x]b where '1' is the index of the encryption function used (here: Encl). The notation [x]i>2 indicates a data x that has been encrypted successively with the first encryption function Encl, then the second encryption function Enc2.

[0163] The steps of the process, in the various embodiments presented, are denoted in the form Sffnn, where ff refers to the number of the figure in which the embodiment is shown, and nn is a step number assigned to the step in question. In the various embodiments presented, corresponding steps are assigned the same step number whenever possible.

[0164] Each of the presented implementation modes aims to obtain a result, F(x) or F(x,y), which can be obtained (or equivalently, which is computable) by applying a function F to at least one input data x, or in some cases to several input data x, y, etc., as in the third implementation mode presented below in relation to [Fig.3].

[0165] This function F can be broken down into a number of elementary calculation operations, or elementary operations (each of which can be of any level of complexity).

[0166] In the examples developed here, these elementary operations are represented by functions, denoted here as f, g, h, or also gj for the case where a function (gj) is called iteratively, in a loop, by the calculation process.

[0167] Naturally, the proposed data processing method is applicable to functions F decomposable into elementary operations f such that they can be transposed and executed by a computer on the ciphertexts of the data. This condition is not limiting if the encryption scheme is a completely homomorphic encryption, but must be taken into account in other cases, for example for a only partially homomorphic encryption, for example only additive or multiplicative. First implementation method - General case

[0168] In a first embodiment of the process presented as an example, we wish to calculate a result F(x) from an input data x provided by a client CL1.

[0169] In this embodiment, the function F is decomposed into two elementary operations f and g: F(x) = f(g(x)).

[0170] To calculate F(x), the following operations are performed:

[0171] At the SI step (step S0101, on the [Fig.l]), the client CL1 provides the data x.

[0172] The CL1 client then applies a first Encli encryption to the data x; in this For example, Encli is a totally homomorphic cipher.

[0173] At step S0102, the first client CL1 transmits the encrypted data [x]ib using Encli encryption to the server.

[0174] Since the data [x] is encrypted using Encli encryption, the decryption key of which is not known to the server, the server is unable to access the information contained in the data [x]b

[0175] At step S0130, the server performs a first elementary operation, g, consisting of applying a function g to the received data [x]ib and thus obtaining the data g([x]ii). When the Encli cipher is commutative (in the sense of the composition function o) with the function g, this value is equal to [g(x)]ib as shown in [Fig. 1]. This is the case, for example, when the Encli cipher is an FHE cipher, taking into account the convention according to which the function g applied to plaintexts and the function g applied to the corresponding homomorphic ciphertexts are both denoted g.

[0176] Then at step S31 (S0131), the server applies a second encryption, Enc2, to the data [g(x)hb which therefore becomes the data [g(x)]ii, 2.

[0177] When the first Encli cipher is a totally homomorphic cipher, any type of cipher can be used as a second Enc2 cipher.

[0178] In the implementation shown in Fig. 1, the first cipher Encli is a totally homomorphic cipher, and the second cipher Enc2 is a masking cipher. Applying the secondary cipher therefore consists of adding a mask m to the current data [g(x)] ib. The result is thus the data [g(x)] ii > 2, with [g(x)]ii,2 = [g(x)li rS m, the function O being an addition of a plaintext and a ciphertext.

[0179] At step S32 (S0132), the server transmits the data [g(x)]ii >2, encrypted under double encryption Encli and Enc2 to the second computer, the TEE.

[0180] Since the data [g(x)]ii, 2 is encrypted under the second encryption (i.e. masked), the TEE is unable to access the information contained in this data.

[0181] At step S33 (S0133), the TEE removes the first encryption (removes the homomorphic encryption layer) of the data [g(x)]ii, 2, and thus obtains a data [g(x)]2, still masked by the mask m.

[0182] In most variants of this implementation method, the calculation process then continues with the TEE carrying out step S0135 (described later), based directly on the data [g(x)]i>2.

[0183] However, an intermediate SOI34 computational step consisting of applying a function f to the data [g(x)]2 produced by the S33 operation can be provided when the function f and the second encryption / decryption function (usually, by masking) are commutative for the function composition law (function 'o' ; fog (.) is also denoted f(g(.))).

[0184] In this case, as shown in [Fig.1] at an intermediate step SOI34 the TEE applies the function f to the received data [g(x)]2. It thus obtains the data [f(g(x))]2.

[0185] In the following, it is assumed by way of example that in the implementation mode presented, step S0134 is carried out.

[0186] At step S0135, the TEE applies an additional encryption Encl2 (a homomorphic encryption) to the data [f(g(x))]2, and thus obtains the intermediate encrypted data [f(g(x))]2, i 2, which it transmits encrypted under double encryption (homomorphically encrypted and masked) to the server.

[0187] At the SOI36 step, the server then removes the second encryption by applying the decryption function Dec2 applied to the intermediate ciphertext [f(g(x))]2ji2, i.e. by subtracting the mask m, and obtains an intermediate ciphertext [f(g(x))]i2 under the additional encryption Encl2.

[0188] The server then completes step S3 (S0103) by transmitting the encrypted result [F(x)]i 2, to client CL1.

[0189] At step S0104, the client CL1 decrypts the encrypted result [F(x)]b, that is to say, it applies the decryption function Decl2 to it, and thus obtains the result F(x).

[0190] In this embodiment, the second computer is a TEE. Since the second computer must be able to remove and apply the homomorphic encryption (in steps SOI33 and 0135), choosing a secure computer such as a TEE as the second computer makes it possible to perform the encryption / decryption functions Encl2 and Decl2, using for example a symmetric key pair, which allows these functions to be executed under satisfactory security conditions.

[0191] The additional encryption Encl2 / Decl2 can be the same encryption as the first encryption Encli / Decli, with the same encryption key or not. It can also be two different encryptions.

[0192] In this implementation, the TEE removes the homomorphic encryption (DecHEll, step S0133) and applies the additional encryption (Encl2, step S0135): these are two examples of support functions applied by the TEE. Step S0133 contributes to the execution of homomorphic calculations by the server. Step S0135 is used to encrypt results sent to the client. Note that the server also performs support functions, for example in step S0136. Furthermore, in this embodiment, in step S0134, the TEE performs an elementary operation, which is not a support function. 2nd method of implementation

[0193] In the second mode of implementation, illustrated by [Fig.2], we also wish to calculate a result F(x) from an input data x provided by a client CL1.

[0194] In this second embodiment, the function F to be calculated is decomposed into a plurality of elementary operations gj, where j=l....N, in the following manner:

[0195] F(x) = gN (g^ (gx 2 (.... (gl(x))))))

[0196] The elementary operations gj are applied successively to the current data iteratively by repeating a calculation loop N times.

[0197] At each iteration of index j, the first computer, the server, applies a elementary function gj to the data being processed gj.i (gj 2 (gj 3 (.... (gi(x)))))). To simplify, in this document the data being processed gj (gj4 (gj 2 (.... (gi(x)))))) is conventionally denoted gj(x).

[0198] Since the number of elementary operations gj to be applied can be very high, it may be necessary for some encryption schemes to periodically reset the noise. This is particularly relevant in the case where the first encryption is a homomorphic cipher in which a noise component is integrated into the homomorphic ciphertext: it is then necessary to periodically reset the noise (an operation known as 'Bootstrapping') (for more details, see Ref. 2).

[0199] This second implementation of the process provides a solution for this reset. In this case, the TEE is advantageously used to perform the reset operation. At each iteration, the server applies an elementary function gj to the data, and the TEE performs a noise reset operation.

[0200] The operations performed in the second embodiment are the same as those performed in the first implementation except for the following points:

[0201] The main difference is that, since the function F is decomposed into N elementary operations gj, at the end of the S0236 step of removing the second cipher (of subtracting the mask m) (comparable to the SOI36 function of the first implementation mode), in the second implementation mode there are two possibilities:

[0202] If the index j is strictly less than N, the cipher [gj (gj_i (gj_2 (gi (x))))))]i calculated at step S0236 by the server is then provided as input data for the next iteration of the calculation loop (composed of steps S0230,S0231,S0232,S0233,S0235,S0236).

[0203] Conversely, during the last iteration, in which the index j is equal to N, the ciphertext [gN (gN4 (gN_2 (.... (gi(x))))))]i calculated at step S0236 by the server, and equal to the ciphertext of the result [F(x)]i, is then transmitted to the client CL1. The latter then decrypts this ciphertext and thus obtains the result (step S4).

[0204] However, in one variant, during the last computation loop (j=N), once step S0230 is performed, instead of performing steps S0231, S0232, S0233, and S0235 to allow for the noise reset operation, the server transmits the result obtained at step S0230 directly to the client CL1 (dashed arrow in [Fig. 2]). The client can then remove the first encryption from the transmitted result and thus obtain the result of the computation F(x).

[0205] At each iteration, the elementary calculation operation S0230 (application of a function gj) by the server is therefore followed by operations S0233 and S0235 of noise reset by the TEE.

[0206] The function of the TEE is therefore only to remove and then reapply the homomorphic encryption, by applying the functions DecHE i and EncHE b which are two support functions: unlike the first mode of implementation, the TEE only performs support functions, and does not perform any elementary calculation operation f; there is no step comparable to step S0134.

[0207] Advantageously, particularly in encryption schemes based on the LWE problem, encryption and decryption operations can be extremely fast, which means that the processing (operations S0233, S0235) carried out The TEE only negligibly slows down the calculations performed by the server.

[0208] In some implementation modes, the mask m is a mask provided to the server by the client CL1 in a keystream. In this case, the second encryption performed in step S0231 at each iteration of index j uses a mask mj having a value specific to the iteration of index j. 3rd method of implementation

[0209] A third embodiment, also illustrated by [Fig.2], involves the same operations as the second embodiment.

[0210] The difference between the second and third implementation modes is that while in the second, the TEE performs a noise reset operation, in contrast in the third implementation mode, the TEE performs a relinerization of the encrypted data [gj (gj^ (g, 2 (.... (gi(x))))))h,2.

[0211] This advantageous relinearization allows the encrypted data to be modified: the relinearization operation restores the form of the encrypted data, returning it to the form of the initial ciphertext or 'fresh' ciphertext. The TEE is advantageously used to perform the relinearization operation.

[0212] Encryption schemes for which relinearization is necessary may include schemes of the so-called LHE ('Leveled Homomorphic Encryption') type, such as BGV and BFV for example. 4th implementation method

[0213] A fourth embodiment, illustrated by [Fig.3], corresponds to a case where the calculation to be performed is a function F of several variables, provided respectively by two or more clients (or users).

[0214] In the example we have considered only the case of two variables x and y supplied respectively by two clients CL1 and C2L, but the process is applicable to any number of variables, supplied respectively by any number of clients CL1... CLN.

[0215] In the example shown, the function F can be broken down into elementary operations in the following way: F(x,y) = h(f(g(x)),y)).

[0216] The operations performed in this embodiment are the same as those performed in the first implementation except for the following points:

[0217] During the initial SI operation (S0301), two clients CL1 and CL2 (and not only client CL1) provide input data, respectively x and y, for data processing.

[0218] Each of these two data points is encrypted: A first Encli encryption is applied to x by client CL1, and another 'first encryption' Encl2 is applied to y by the second client. The Encli and Encl2 encryptions may or may not be different from each other; they may also have the same encryption scheme, but with different keys.

[0219] The encrypted data obtained [x]n and [y][2 are then transmitted to the server (step S0302).

[0220] The following operations S0330, S0331, S0332, S0333, S0334, S0335 and S0336 are then substantially identical to the operations of the same step number carried out in the first mode of implementation.

[0221] It should be noted, however, that at step S0335, the first encryption applied is that used by the second CL2 client, in order to prepare the provision to this second client, at the output of the server, of processed data encrypted under the first Encl2 encryption which is that used by the CL2 client.

[0222] On the other hand, at the end of step S0336, instead of the result being transmitted directly to the client (CL2) (as in step S0136), an elementary operation h is applied beforehand (step S0337). This operation h uses as input data the ciphertext [f(g(x))]i2 and the ciphertext [y]i2, and provides as output a ciphertext of the result [F(x,y)][2.

[0223] This ciphertext of the result [F(x,y)] i2, is then transmitted to the client CL2. The latter then decrypts this ciphertext and thus obtains the result (step S4).

[0224] In this example, the variable y only appears in a calculation phase in which the variable x has already undergone two successive operations, g and f, resulting in f(g(x)). That said, naturally any form is possible for the function F; in particular, the variable y could be combined with the variable x from the very first calculation phase.

[0225] On the other hand, in this implementation mode, the function g is applied to the data x in a first elementary operation performed by the server, and is followed by a second elementary operation f performed by the TEE. The third elementary operation is again an operation performed in the server.

[0226] It is understood that, in general, any distribution of elementary operations between the two computers is possible. Thus, the data processed in each computer can be a function of all or part of the input variables (x and y in this example). Moreover, although this is not the case in this implementation, in some implementations the calculation may involve iterative calculations between the two computers, as in the implementation illustrated in [Fig. 2].

[0227] The distinctive feature of the fourth implementation, besides the fact that several input data are provided by the different clients (CL1 and CL2) at the input of the process, is that the process allows for transencryption when the Encli / Decli encryption scheme is different from the Encl2 / Decl2 scheme. The process allows that, starting from a data x encrypted as input with the homomorphic Encli encryption scheme, the client CL2 that receives the output result receives the result encrypted with another encryption scheme, the Encl2 / Decl2 scheme. It should be noted that the second client CL2 could potentially be client CL1, thus having access to both encryption schemes.

[0228] If in this implementation mode, the homomorphic encryption schemes use asymmetric key pairs, the TEE uses the private key of the homomorphic encryption scheme EncHEli; and to encrypt the data under Encl2 encryption at step S0335, the TEE has the public key of the Encl2 encryption scheme and does not need the private key of the CL2 client. 5th implementation method

[0229] In a fifth embodiment, illustrated by [Fig.4], we seek to calculate the result F(x) of a function F which only requires applying an elementary operation f.

[0230] The operations performed in this embodiment are the same as those performed in the first implementation except for the following points:

[0231] First, in step SI (S0401), the CL1 client, after applying the first EncMl encryption, which is a masking encryption, applies another Encs encryption. In this implementation, this other encryption is a symmetric (Encs,Decs) encryption, which is neither the first nor the second encryption within the meaning of this disclosure. This symmetric Encs encryption is an additional encryption, used to guarantee the confidentiality of the transmitted data with respect to the server. Although the data [x]i>s in this implementation is transmitted directly by the client to the TEE (as the first computer), in other implementations this data may be transmitted via the server (notably because in practice the TEE is most often integrated into the server).

[0232] After successively applying the first EncM encryption and the additional symmetric Encs encryption, the CL1 client transmits the encrypted data [x]i>s to the first computer, which is the TEE and not the server, unlike the first implementation mode.

[0233] Upon receipt of the data [x]is, the TEE first removes the symmetric encryption (by applying the Decs function)(step S0430).

[0234] The following steps S0431, S0432, S0433 and S0434 are then carried out in a similar manner to the steps of the same step numbers in the first implementation mode (with the important difference that the first computer is now the TEE, and the second computer is the server):

[0235] The TEE applies the second encryption (EncHE2) to the data (step S0431) and obtains the data [x][j2, which it transmits to the server (step S0432).

[0236] The server removes the first encryption of the data (step S0433), then performs the elementary operation S0434 during which it applies the function f to the data [x]2. It thus obtains the cipher of the result [F(x)]2 which it transmits to the CLL client. The client then removes the second encryption (by applying DecHE2, operation S4 (S0404) and thus obtains the result F(x).

[0237] In this implementation, the first EncMl encryption is a masking encryption. Applying this encryption therefore consists of adding a mask m to the data. In the present case, this consists of replacing the current data x with the sum x + m. We thus have: [x] i = x + m.

[0238] To allow the server to remove this encryption, the mask m is shared between the client CL1 and the server. Conversely, since the data [x]i, s is encrypted using this mask m before being transmitted to the TEE, the latter cannot know the content of the processed data transmitted to it: the encryption by masking is undecipherable for the TEE.

[0239] Furthermore, in order to be able to apply the second, homomorphic encryption, EncHE 2, the TEE has the public key of this last encryption, the client CL1 having the corresponding private key in order to be able to remove this encryption (DecHE2 Function). 6th implementation method

[0240] In the 6th embodiment, we wish to calculate a result F(x) from an input data x; the function F constitutes in itself a unique elementary operation F.

[0241] This 6th implementation method, like the 5th implementation method, allows for transciphering. This implementation method is illustrated by [Fig. 5].

[0242] In this 6th implementation mode, the operations performed are substantially identical to the operations of the same step number performed for the 1st implementation mode, with, however, the following particularities or sometimes differences:

[0243] At the SI step (S0501), the first Encli encryption applied is not a homomorphic encryption, but a masking encryption: The encrypted data [x] ii is defined by: [x]ii = x+ml, where ml is a first mask which is unknown to the server and therefore undecipherable by it.

[0244] The data [x]i is then transmitted to the server at step S2 (S0502).

[0245] At step S31 (S0531), the server applies a second EncM2 encryption to the data, which in this implementation mode is also a masking encryption. The resulting data, [x]i b2, is then transmitted to the TEE (step S0532).

[0246] At step S0533, the TEE removes the first encryption (i.e., applies the Decli function, subtracting the value of the first ml mask).

[0247] Then at step S0535, the TEE again applies a decipherable encryption by the client CL1, namely a totally homomorphic encryption, by a function Encl2, and transmits the result [x]2>i2 to the server.

[0248] At step S0536 the server removes the second encryption (function DecM2) and obtains an encrypted version of the processed data [x] i2.

[0249] Next, at step S0537 the server applies the function F to the ciphertext [x][2 and obtains the homomorphic ciphertext of the result, [F(x)]i2.

[0250] It then sends this ciphertext [F(x)]i 2 to the client, who decrypts it and thus obtains the result F(x) at step S4 (S0504). 7th implementation method

[0251] A 7th implementation method, illustrated by [Fig.6], allows, as in the 5th and 6th implementation methods, for transciphering to be carried out.

[0252] This 7th embodiment is close to the embodiment of [Fig. 1]. Therefore, these two embodiments can be considered identical, except for the differences which will now be presented.

[0253] The function F, as in the first embodiment, is decomposed as follows: F(x) = f(g(x)).

[0254] Steps S0601, S0602, S0630, S0631, S0632, S0633, S0634 and S0635 are substantially the same as the steps of the same step numbers in the first implementation mode, mutatis mutandis.

[0255] In particular, step S0634 can only take place if the function f and the second encryption / decryption function are commutative for the function composition law.

[0256] At the SI step (S0601) as in the first implementation mode, a totally homomorphic encryption is applied by the EncHEli function.

[0257] EncHEl2 encryption can notably be a symmetric encryption.

[0258] Furthermore, at the end of step S0635, in the 7th implementation mode, the TEE transmits the encrypted result [F(x)]2,12 directly to the client CL1 (This encrypted result [F(x)]2ji2 could pass through the server, since the EncHEl2 encryption is not decryptable by the latter).

[0259] In the 7th implementation mode, finally, at step S4 (S0604) the client CL1 therefore performs a double decryption, first by applying the function DecHEl2, then by applying the function DecM2. It thus obtains the result F(x) in plaintext. 8th implementation method

[0260] The 8th implementation mode, illustrated by [Fig.7], concerns the case where one would specifically want to protect against the case where both the server would have malicious behavior, and the TEE would have an "honest but curious" behavior.

[0261] This implementation method is applicable provided that a verifiable calculation protocol exists for the calculation to be performed, allowing verification of the results of all calculations performed during the elementary calculation operations. In this case, the calculation is distributed as follows: the elementary operations are performed by the server, notably under fully homomorphic encryption; each of these elementary operations is verified by the TEE.

[0262] This protocol allows verification that the calculation has been executed correctly by performing a verification operation for each of the elementary operations carried out.

[0263] Examples of verifiable calculation protocols are cited for example by document Ref.5.

[0264] The integrity of the operations carried out within the TEE can, on the other hand, be guaranteed by using a remote attestation process (in English, 'Remote Attestation').

[0265] When these provisions are adopted, advantageously the calculation method not only ensures the confidentiality of the data, but also the integrity of the calculation.

[0266] An example of implementation of the process, indicating the checks to be carried out, is represented schematically by [Fig.7].

[0267] In this implementation mode, as in the 2nd implementation mode, the function F to be calculated is decomposed as follows:

[0268] F(x) = gN (g^ (gx 2 (.... (gl(x))))))

[0269] Consequently, the elementary operations are carried out iteratively by performing N times the same calculation loop: each calculation step by the server allows the application, during a loop of index j, of an elementary function gj to the current data gj 4 (gj_ 2 (gj_ 3 (.... (gi(x)))))), also conventionally noted, for simplicity, gj i(x).

[0270] The operations carried out under this implementation method include overall the operations (or steps) of the second implementation method, plus additional verification operations.

[0271] A check is therefore carried out for each elementary operation, during each of the successive calculation loops.

[0272] Thus, in this implementation mode, the following operations are carried out:

[0273] At step S0701, client CL1 provides input data x. It calculates a ciphertext [x]i of this data x for a first EncHEl encryption (EncHEl is a completely homomorphic encryption).

[0274] The ciphertext [x]i is also used to compute a tag of the ciphertext [x]i of the input data, denoted tag([x]i), called the data tag.

[0275] A tag here designates a value, which could also be called a marker or a label, which is calculated from an initial data and stored in such a way as to allow the authentication of the initial data or to keep a trace of it, within the framework of a verifiable calculation verification protocol.

[0276] The data tag tag([x]i), like all the tags mentioned here, is calculated by a tag calculation function ir.tag, within the framework of a verifiable calculation protocol jt. This protocol is determined according to the calculation to be performed in order to allow its verification.

[0277] In parallel, during successive S0701a steps, the CL1 client generates a keystream. At each iteration of the computation loop described below between the two computers, the server and the TEE, the CL1 client generates a new key value mj at an S0701a step. Furthermore, from this key value mj, also at each S0701a step, the CL1 client also calculates a key tag tag(mj).

[0278] Thus, at each iteration of the index calculation loop j (j=l.. .N), the client CL1 transmits to the server the new calculated key mj and the associated key tag tag(mj).

[0279] Sending the nij keys allows the server to perform the operations of applying and removing the second encryption (EncM2, DecM2) to the data processed in steps S0731 and S0736 described later.

[0280] Similarly, sending the key tags tag(mj) enables the server to perform the application and removal operations of the second encryption (EncM2, DecM2) to the data tags in steps S0731a and S0736a described later.

[0281] At step S0702, the CL1 client transmits to the server the encrypted data [x]i and the data tag tag([x]i).

[0282] Upon receipt of the information received (encrypted data [x]b tag of it tag[x]b keys mj, tags of keys tag(mj), the server and the TEE progressively calculate the result F(x) by performing N calculation loops, in the following manner at step S3 (S0703).

[0283] At each loop of index j (j=1.. .N), the server performs an elementary operation gj, by applying a function gj to the processed data received as input (step S0730). At the 1st iteration, the data received as input is the encrypted data [x]i; at subsequent iterations, the data received as input at step S0730 at an iteration of index j is an intermediate processed data [gj x(gj 2(- - --gi(x)))))]x calculated during a decryption step S0736 which will be described later.

[0284] In parallel, at a step S0730a the server again applies the function gj, but this time it applies it successively, at the first iteration, to the data tag tag([x]i) of the (initial) encrypted data [x]i; then, at subsequent index j iterations, to the successive data tags of the intermediate data tags tag([gj. i(gj. 2(....gi(x)))))]i), also noted tag([gj(x)]i) calculated during decryption steps S0736a which will be described later.

[0285] The tag calculation function is commutative with the elementary operations gj; therefore, the result can be written indifferently as gj(tag([gj. i(gj. 2(.. ..gi(x)))))]i) or tag([gj(gj.1(gj.2(....g1(x)))))]1), also noted as tag([gj(x)h).

[0286] The result [gj(gj-1 (-. ..gl(x)))))]i, also noted [gj(x)h obtained in step S0730 is then encrypted by masking in step S31, with the mask mj, which constitutes the application of a second encryption (function EncM2).

[0287] In parallel, from the tag (tag[gj(x)]i)) obtained in step S0730a and the tag tag(mj) of the mask mj, the server calculates the tag of the ciphertext under double encryption of the processed data (tag([gj(x)]i2)) in step S0731a, which requires the application of the second encryption to the processed data (function EncM2).

[0288] All data processed by the server which are functions of the input data x are under first EncHEl encryption and consequently are undecipherable for the server, which is unable to access the information contained in this data.

[0289] The server then transmits to the TEE in parallel the data [gj(x)]i >2 and the data tag tag([gj(x)]i, 2), both under double encryption at step S32 (S0732).

[0290] At step S0732a the second computer, the TEE, then performs a verification of the calculation carried out in accordance with the verifiable calculation protocol, based in particular on the cipher of the data [gj(x)]i>2 and the associated tag tag([gj(x)]i>2).

[0291] This verification may in some cases include the following verification: the TEE calculates on its side the data tag tag([gj(x)]i>2) from the data [gj(x)]ij2 under double encryption, and verifies that the tag obtained is identical to that received in step S0732.

[0292] If the result of the verification is negative, data processing is stopped and an alert message is transmitted.

[0293] If the result of the inverse check is positive, the TEE continues processing. For loops with index j <N

[0294] If the check carried out in step S0732a indicates that the processing is proceeding in accordance with expectations, the TEE then removes the first encryption (applies the function DccHe1) from the data [gj(x)]2> i, that is to say it subtracts the mask mj, and thus obtains the data [gj(x)]2 in step S33 (S0733).

[0295] The TEE then applies the first encryption again (applies the Encl function) to the data [gj(x)]2, that is to say it adds a new mask mj to it, and thus obtains the data [gj(x)]2>i (step S0735).

[0296] The TEE then transmits this data to the server as input data to enable execution for index j+1 of step S0736.

[0297] At step S0736 (in the loop at index j+1), the server removes the second encryption (applies the DecM2 function) of the data [gj(x)]24 and thus obtains the data [gj(x)]i, which will serve as input data for step S0730 of the next iteration.

[0298] In parallel, at the end of step S0735, the TEE calculates a new data tag tag([gj(x)i>2]) (step S0735a). It then transmits this tag tag([gj(x)i>2]) to the server as input data for the execution of step S0736a for the j+1 loop.

[0299] At step S0736a (in the loop at index j+1), the server calculates the data tag for the unmasked data (whose second encryption has been removed by applying the DecM2 function) from the received data tag tag([gj(x)]i>2.

[0300] The current index of the calculation loop then changes to j+1.

[0301] The index calculation loop j+1 then begins by the parallel execution of steps S0730 and S0730a, based respectively on the data [gj(x)]i and the data tag tag([gj(x)]!). During the loop with index j=N

[0302] If the index j is equal to N, at the end of step S0732a, the server transmits to client CL1 the data [gN(x)h 2, that is [F(x)]i 2.

[0303] In parallel, once step S0732a is completed, during step S0735b, using the data [gN(x)]i>2 obtained and verified in step S0732a, the TEE calculates a signature sig([gN(x)]i>2) of the obtained data and transmits it to client CL1 (optionally, via the server). This signature is calculated in such a way as to prove that the returned encrypted data is indeed the encrypted data obtained, once all the elementary operations constituting F have been performed.

[0304] This signature and the data [gN(x)]i>2 are therefore transmitted to the client CL1, possibly via the server.

[0305] The CL1 client then performs step S4 (S0704), which has three sub-steps S0741, S0742 and S0743.

[0306] At step S0741, client CL1 verifies, using the signature sig([gN(x)]i>2), that the returned encrypted data [gN(x)]i>2 is indeed the expected encrypted data after the calculations. If the verification is successful, the calculation continues to step S0742; otherwise, it stops and an alert message is transmitted.

[0307] At step S0742, client CL1 removes the second encryption of the data and obtains the data [gN(x)]i.

[0308] At step S0743, the client CL1 decrypts the received data [F(x)h, that is to say removes the first encryption from it, and thus obtains the result F(x) = gN(x).

[0309] In this implementation, the TEE performs only support functions. Specifically, the tag calculation and verification functions applied in steps S0732a and S0735a are functions used to verify the homomorphic calculations performed by the server; the decryption / encryption functions performed in steps S0733 and S0735 are functions that contribute to the execution of homomorphic calculations by the server; and the signature calculation function performed in step S0735b is a function used to prepare verification data used to check the results sent to the CL1 client. 9th implementation

[0310] A 9th implementation mode concerns the case where we want to carry out the calculation in such a way as to secure the calculation against a CCA attack (from the English 'Chosen Ciphertext Attack').

[0311] To this end, the process is implemented in two phases illustrated respectively by Figs. 7 and 8.

[0312] A 10th implementation method will then be presented, which secures the processing in the same way, but this time using the Paillier cryptosystem.

[0313] For the 9th embodiment first of all, [Fig.8] shows the preparation of input data for data processing and [Fig.9] shows the main steps of data processing.

[0314] The preparation phase comprises the following steps:

[0315] At the SI step (S0801), the client (issuing client) CLlfourmits a data x in front to serve as input data for the calculation.

[0316] It applies a first EncMli encryption to it, by masking, in this case by adding a first ml mask.

[0317] It then applies an additional EncMl2 encryption, also by masking, by adding a second mask m2. This additional EncMl2 encryption is neither a first nor a second encryption within the meaning of this disclosure. As in the 5th implementation, this EncMl2 encryption is an additional encryption used to guarantee the confidentiality of the transmitted data with respect to the server. In this implementation, the encrypted data obtained after the two encryption steps is transmitted by the client to the TEE (as the first computer) via the server, which justifies the need for this EncMl2 encryption, which is undecipherable by the server (the EncMll encryption being undecipherable by the TEE).

[0318] At step S2 (S0802), the client CL1 transmits the data [x]ibn under double encryption to the first computer, the TEE (The TEE is indeed the first computer because it is the computer which will encrypt the data under a second encryption at step S31, the server conversely at step S2 only transmitting to the TEE the data received from the client).

[0319] Then at step S3 (S0803), from the data received at step S2, the server and the TEE calculate a cipher [F(x)] of the result of the calculation, and transmit this result to the receiving client which is the CL1 client.

[0320] At step S4 (S0904) client CL1 decrypts the ciphertext of the result [F(x)] of the calculation and obtains the desired result F(x).

[0321] Step S3, mainly represented in [Fig.9], takes place iteratively and is represented by Figs.8 and 9.

[0322] The function F, in this implementation mode, has a certain number of input data. In the example presented, only the provision of two input data x and y to the calculation process is shown in [Fig.8], but in general, any number of input data can be provided to the calculation process, possibly by a plurality of sending clients, in particular during successive calculation loops forming part of the data processing.

[0323] As indicated, [Fig. 8] represents the preparation of input data x and y for data processing. Data x is data provided by a sending client CL1. Data y is data provided by the server (which may hold it from any source or calculate it by any means).

[0324] Before being transmitted to the TEE, the data is first encrypted there under the first Encli encryption by the server at step S0801a.

[0325] The data [x]n i2 and [y]n are transmitted to the TEE, respectively by the client CL1 and the server.

[0326] Upon receipt of the data [x]n i2, the TEE removes the additional encryption (applies Decl2), that is to say subtracts the mask m2 (step S0830).

[0327] At step S31 (S0831), in parallel, the second EncHE2 encryption, a completely homomorphic encryption, is applied to the data [x]n and [y]n.

[0328] The data obtained under double encryption [x]n>2 and [y]n>2 are then signed (step S0831b).

[0329] The data under double encryption [x]n>2 and [y]n>2 and their signatures o([x]n>2) and o([y] 11,2) are transmitted respectively to the TEE at step S32 (S0832).

[0330] These data serve as input data for elementary operations carried out in a loop, during successive iterations, by the server jointly with the TEE, as shown in [Fig.9].

[0331] In [Fig.9], the input supply of two data is shown, this time consisting of two data The inputs [z]n>2 and [z']n>2. This data can be data produced during step S31 (S0831) illustrated in [Fig. 8], whether it be data x provided by a sending client, and / or data y provided by the server. As will be explained, it can also be data such as the data [z']n>2 calculated during step S31 (S0831) represented in [Fig. 8] of the data processing itself.

[0332] We therefore consider the case where two input data [z]n>2 and [z']n>2, each under double encryption EncMli and EncmT, are provided as input to the TEE. The first encryption is a masking encryption: the data z is encrypted with the mask m and the data z' with the mask m'.

[0333] The TEE calculates signatures o([z]nj2) and o([z']nj2) for these data (step S0931b). Each of these data together with its signature is then transmitted to the server at step S32 (S0932).

[0334] At step S33 (S0933), the server removes the first encryption of this data and their associated signatures by applying DecMli to them.

[0335] It then performs an elementary calculation operation (operation S34). This operation can, for example, be the multiplication of the two data z and z', that is to say the calculation of a new data [z”]2 = [z]2 * [z']2. This multiplication is performed between homomorphic ciphers.

[0336] Using any known computational integrity proof method, a proof ir([z”]2 ) of the integrity of the elementary computational operation performed in step S34 is then computed.

[0337] This proof confirms that there exist masks (m,m',m”), applied to the data (z,z',z”), such that

[0338] [zm]2* [z'-m']2= [z”-m”]2

[0339] where * represents the multiplication operation between homomorphic ciphers under Enc2 encryption.

[0340] The encrypted data [z”] obtained is then encrypted again under the EncMli encryption (step S0934a): a mask m” is added to it.

[0341] Following the encryption operation carried out in step S34a, the following elements are transmitted to the TEE for verification operation S0934b: The input data of operation S34 and their signatures, i.e. [z]n>2, [z']n,2, g([z]hj2), o([z']n>2); and the output data: [z”]2>n, ir([z”]2).

[0342] Upon receipt of these elements, at step S0934b the TEE performs the following checks: it verifies the authenticity of the first data [z]n>2 against its signature o([z]nj2), the authenticity of the second data [z']n>2 against its signature o([z']nj2), and then verifies the authenticity of the output data [z”]2 against the proof of the result ir([z”]2). (Other checks may be performed depending on the security constraints that the data processing procedure must comply with).

[0343] If the result of these three checks is positive, the TEE removes the second encryption of the data [z”]n>2(DecHE2, operation S0936).

[0344] The subsequent processing depends on whether the elementary operations are completed or not:

[0345] In the first case, that is, if the index j is strictly less than N, the set of elementary operations (function gj) has not been completely performed. The data [z”] 11 under the first encryption is again encrypted under the second EncHE2 encryption, the homomorphic encryption, to allow the continuation of data processing (step S0931).

[0346] After applying the second EucHe2 encryption again at step S0931, the TEE signs the result [z”]n 2 (operation S0931b) and transmits to the server for further calculations the data [z”]n>2 under double encryption and its signature.

[0347] Conversely, if the index j is equal to N, the data [z”] 11 under first encryption is the result [F(x)] 11 of the calculation, encrypted under first encryption. This result is re-encrypted under the additional encryption EncMl2 (step S0937), and then transmitted under double encryption to the client. The application of the additional encryption EncMl2 guarantees that the result transmitted to the client cannot be understood by the server. This result can therefore potentially be transmitted via the server.

[0348] During the various loops, thanks to the successive operations of the support functions DccHe2 and EncHE2 of deletion and setting up of the second, homomorphic encryption (operations S0936 and S0931), the noise level is reduced in the encrypted result [z”]nj2 finally retransmitted to the server, which allows the continuation of the calculation iterations.

[0349] In the second case above (j=N), upon receiving the result [F(x)]ni2 under double encryption, the client removes the additional encryption (Decl2) and the first encryption (Decli), thus obtaining the result F(x) at step S4 (S0904). Since the second encryption, i.e., the homomorphic encryption, has been removed by the TEE, this saves the client from having to do so: the client only has to perform the much simpler mask removal operations (Dec h and Dec 12).

[0350] Note: In a simpler implementation, after the checks, the TEE does not remove the second encryption (does not perform the DecHE2 operation): After the checks performed in step S34b (or even without performing these checks), the TEE calculates a signature of the result o([z”]2) (step S0931b) and then returns the result [z”]2 and its signature o([z”]2) to the server. This is equivalent to bypassing steps S0936 and S0931: this process is illustrated by the dashed arrow on the right side of [Fig. 9].

[0351] Advantageously, in this implementation mode, the data exchanged between the client and the server is not encrypted using homomorphic encryption.

[0352] The checks only concern elementary operations, most often simple ones (for example: a multiplication). Consequently, the second cipher may not be completely homomorphic (in the sense that a completely homomorphic cipher would be one that allows an arbitrary number of successive additions and multiplications, i.e., an arbitrary multiplicative depth). Thus, for example, a second cipher that is a homomorphic cipher of depth 1 (or of any finite depth) can be used in this implementation.

[0353] In this implementation, the checks performed make it possible to prove, step by step, that all ciphertexts manipulated during the computational operations are either calculated by the TEE (which, as the holder of the second encryption secret key, is not an attacker for the second encryption), or calculated during legitimate homomorphic computational operations performed on ciphertexts calculated by the TEE (in the dotted 'Proof' rectangle in [Fig. 8]). Therefore, there is no possible CCA adversary at the FHE layer, because an adversary (here, possibly, the server) is not capable of generating homomorphic ciphertexts that are not duly produced by the encryption function or derived from such ciphertexts by legitimate homomorphic operations. 10th method of implementation

[0354] The 10th embodiment will now be presented in relation to Figs. 10 and 11. In this embodiment, the Paillier scheme is used to perform the elementary multiplication operations between second-order digits encryption at the S34 stage; however, it can only be implemented for calculations of multiplicative depth 1.

[0355] Advantageously, since the Paillier scheme inherently provides security against CCA attacks, it is no longer necessary in this implementation mode to resort to signature and signature verification operations as in the implementation mode presented by Figs.8 and 9.

[0356] This 10th implementation method is based on Paillier's cipher multiplication method described in document Ref.3 and briefly recalled below:

[0357] We consider that we have a mask b previously generated randomly in ZN.

[0358] We consider an initial data (or message) m. From this data m and the mask b, we define a cipher CF, with reference to the authors MM Catalano and Fiore of Ref.3, denoted [m,b]CF, in the following way:

[0359] [m,b]CF = (mb;EncP(b)) = (mb; [b]P) =(c0,cl)

[0360] where EncP, also noted [,]P, denotes the Paillier cipher function.

[0361] Now consider two CF ciphers, namely the pair [m,b]CF = (mb ;EncP(b)), also denoted (c0,cl), and the pair [m',b']CF = (m'-b' ;EncP(b')), also denoted (c'0,c'l).

[0362] The intermediate variables a1, a2 and a3 are defined by the equations:

[0363] al = EncP(c0 x c'0 mod n); a2 = cr°mod n2; a3 = c'lc0 mod n2.

[0364] From these variables al, a2 and a3, the product of the two ciphers CF is then defined by the triplet (ala2a3 mod n2 ; cl ; c'1) = (c”0 ; c”l ; c”2).

[0365] It is easily verified that c”0 is indeed equal to the Paillier ciphertext of the product mm'-bb'. The product of the two CF ciphertexts is therefore:

[0366] (mb; EncP(b)) * (m'-b'; EncP(b')) = (EncP(mm'-bb'),EncP(b),EncP(b')).

[0367] This operation therefore makes it possible to carry out a form of multiplication of the two initial CF ciphers, on the basis of Paillier's additive homomorphic cryptosystem.

[0368] However, the result obtained by this multiplication is a triplet: the triplet (c”0,c”i,c”2), and not a CF cipher (a pair), like the initial data. The multiplication operations therefore cannot be performed directly one after the other because a multiplication operation expects CF ciphers as input, not triplets.

[0369] The calculation method described in this disclosure will overcome this difficulty by delegating the conversion of the triplets into CF ciphers to the TEE. This operation is a support function, since it contributes to the server performing calculations under homomorphic encryption.

[0370] Fig. 10 presents the preparation of input data for computation, in a scenario in which data m is provided as input by a CL1 client, and data y is provided as input by the server.

[0371] During the SI step (S1001), the data m undergoes two successive encryption operations by masking: a first masking EncMl1, during which a mask p is applied to the data x; followed by an additional masking EncMl2 (additional encryption) during which a mask a is applied to the data x+p: we obtain [m]lljl2 = m+p+a.

[0372] During step S2 (S 1002), the encrypted data m+p+a is transmitted to the TEE.

[0373] At an S1030 step, the TEE removes the mask a (the additional encryption) and obtains the data under first encryption m+p.

[0374] In parallel, the TEE generates a mask b, and calculates a Paillier cipher [b]P of this mask (step S1031 P).

[0375] These last two elements, together with the data under first encryption x+p, are then combined to form a cipher CF (m+pb ;[b]P) at step S31 (S1031).

[0376] Furthermore, the server provides an input data y for the calculation. It masks it by adding a mask p' and obtains a cipher under first Encl 1 encryption: [y]n = y+p' (step S100la).

[0377] In parallel, the TEE generates a mask b', and calculates a Paillier cipher [b']P of this mask (step S1031P also).

[0378] These last two elements, together with the data under first encryption y+p, are then combined to form a cipher CF (y+p'-b' ;[b']P) at step S31 (S1031).

[0379] In this example, the two ciphers CF (x+pb ;[b]P) and (y+p'-b' ;[b']P) are calculated and transmitted to the server at step S32 (S 1032) for the performance of elementary calculation operations.

[0380] When implementing the calculation method according to this disclosure, these operations are carried out in the following manner.

[0381] The elementary operations that the server must perform are considered to be either additions or multiplications. These two cases are treated differently.

[0382] On the one hand, with regard to additions, the server can successively perform any number of addition operations (since the addition operation does not have the disadvantage indicated previously, of providing as output a triplet and not a CF cipher; for more details on this operation, refer to document Ref.3).

[0383] Conversely, multiplication operations are carried out in the following manner, illustrated by [Fig.1 1].

[0384] To perform a multiplication operation between two data m and m', it is assumed that the TEE has two ciphers of these data, under first cipher Encl 1:

[0385] [m]n=m+p and [m']n = m'+p'.

[0386] These ciphers can be, for example, data provided by clients such as the m+p data of [Fig. 10], or data provided by the server such as the y+p' data of [Fig. 10], or even data produced by the calculation within the TEE from data provided by the server, such as the mm'+p” data which will be presented later.

[0387] The TEE provides two masks b and b', and the Paillier ciphers [b]P and [b']P of these masks (step S1031P or S1131P).

[0388] The TEE then calculates the CF ciphers of the two ciphers to be multiplied (step S1031 or SI 131, which represent the same step). These CF ciphers thus take the form of two pairs (m+pb ;[b]P) and (m'+p'-b' ;[b']P). Here, the masks p and p' are known to the server but undecipherable by the TEE. The CF cipher, which constitutes the second cipher, is undecipherable by the server.

[0389] The TEE transmits the CF ciphers to the server (step S1032 or SI 132).

[0390] The server removes the first Encli cipher by subtracting the first mask p, p' from each of the ciphers at step S33 (SI 133).

[0391] The server then performs the CF cipher multiplication operation described by the algorithm proposed in document Ref.3 (step SI 134). At the end of this operation, the server obtains the triplet ([mm'-bb']P ;[b]P ;[b']P).

[0392] The server then encrypts the triplet by adding a mask p' ' to the first term of the triplet using the additive homomorphism property of the Paillier cipher scheme (step S1134a). It then sends the resulting string (mm'-bb'+p” ;[b]P ;[b']P) to the TEE.

[0393] The TEE removes the encryption from the three ciphertexts under Paillier cipher (step S1136). It obtains (mm'-bb'+p”,b,b') and can thus calculate:

[0394] mm'-bb'+p” +b*b' = mm'+p”

[0395] The product mm' of the multiplication thus remains under first encryption, so that the TEE does not know the value of this product.

[0396] As in the general case of the 9th implementation mode, the processing carried out by the TEE is not the same if all the elementary operations have been carried out and the loop in progress is the last loop of index j=N, or not, in which case there is still at least one calculation loop (j < N).

[0397] In the first case, that is, if j=N, the result obtained at the end of step SI 136 is also the result of the calculation, under first encryption:

[0398] mm'+p” = F(x)+p” = [F(x)]n.

[0399] In this case, this encrypted result is subjected to the operations of steps SI 137 and S4 as in the general case of the 9th implementation mode ([Fig.9]): At step SI 137, the TEE applies an additional encryption Encl2 and transmits the result obtained to the CLE client

[0400] At step S4, the client CL1 successively removes the additional encryption (applies the function DecMl2), then removes the first encryption (applies the function DecME), which allows obtaining the desired result F(x).

[0401] Conversely, if one or more elementary operations remain to be performed (j <n), le tee génère un nouveau masque b”, et calcule chiffré de paillier [b”]p ce (étape s1131p). le b” son sont ensuite combinés avec mm’+p” manière à obtenir cf s31). la paire (mm”+p”-b” ; [b”]p) est alors retransmise au serveur : les calculs peuvent se poursuivre pour l’itération suivante sur la base cette nouvelle en entrée d’une autre valeur laquelle elle doit être multipliée, ainsi suite.

[0402] This 10th method of implementation has the advantage, compared to the 9th method of implementation, that it does not require the signature operations provided for in the latter case. References

[0403] Ref.l - L. Coppolino, S. D'Antonio, V. Formicola, G. Mazzeo and L. Romano, “VISE: Combining Intel SGX and Homomorphic Encryption for Cloud Industrial Control Systems” in IEEE Transactions on Computers, vol. 70, no. 5, pp. 711-724, 1 May 2021, doi: 10.1109 / TC.2020.2995638.

[0404] Ref.2 - Wang, W., Jiang, Y., Shen, Q., Huang, W., Chen, H., Wang, S.,... & Lin, D. (2019). Toward scalable fully homomorphic encryption through light trusted computing assistance. arXiv preprint arXiv: 1905.07766.

[0405] Ref.3 - D.Catalano, D.Fiore, ''Boosting Linearly-Homomorphic Encryption to Evaluate Degree-2 Functions on Encrypted Data”, Cryptology ePrint Archive, Paper 2014 / 813.

[0406] Ref.4 - D.Natarajan, A.Loveless, W.Dai, R.Dreslinski, "Chex-Mix: Combining homomorphic Encryption with Trusted Execution Environments for Two-party Oblivious Inference in the Cloud’, IACR, International Association for Cryptographie Research, vol.20220908:153418.

[0407] Ref.5 - D.Fiore, R.Gennaro, V.Pastro, "Efficiently Vérifiable Computation on Encrypted Data”, Cryptology ePrint Archive, Paper 2014 / 202.

Claims

1. Demands A method for processing data in a system comprising two computers to obtain a result from at least one input data (x) to be provided by at least one sending client (CL1,CL2), the result being obtained by applying a combination of elementary operations (f,g,h;gj) to at least one input data (x); in which one of the computers is a server, and the other is a secure execution environment, TEE; a first encryption [Encl,Decl] and a second encryption [Enc2,Dec2] are defined, one being undecipherable by the server, and the other being undecipherable by the TEE; The process involves the following steps: SI) at least one sending client (CL1) provides an input data (x) and applies the first encryption (Encl) to it; S2) said at least one sending client (CL1) transmits the input data ([x]i ;[x]1>2)) under the first encryption (Encl) to one of the computers; S3) during data processing, the two computers apply the combination of elementary operations to said encrypted data received in step S2 so as to obtain an encrypted ([F(x)]) of the result, and transmit this result to at least one receiving client (CL1,CL2), step S3 comprising the following elementary steps: S31) the first computer encrypts the processed data under second encryption (Enc2); S32) the first computer transmits to the second computer the processed data ([x] i>2) obtained, encrypted using first and second encryption; and S33) the second computer removes the first encryption (Decl) of the processed received data; S4) said at least one receiving client decrypts the ciphertext of the result ([F(x)]) and obtains the result (F(x)); During data processing performed in step S3, the server only processes data using at least encryption that is unbreakable by the server, and the TEE only processes data using at least encryption that is unbreakable by the TEE, which may include masking encryption; and the first and second encryption checks the property, for any processed data x: Dec2(Decl(Enc2(Encl(x)))) = Dec2(Enc2(x)).

2. A data processing method according to claim 1, wherein said server-unbreakable encryption is or comprises homomorphic encryption, in particular totally homomorphic encryption.

3. A data processing method according to claim 2, wherein in step S3, the TEE applies to the processed data or data processed only one or more support functions; a support function being a function other than said elementary operations and which: - contributes to the execution of homomorphic calculations by the server or to the verification thereof; - serves to encrypt or decrypt data to be processed received from the client, data processed (by the computers), or results sent to the client; and / or - serves to prepare (verification) data used to verify data to be processed received from the client, data processed, and / or results sent to the client.

4. A data processing method according to any one of claims 1 to 3, comprising the following steps: S0235) the second computer applies the first encryption (EncHEl) to the data decrypted during step S33, and transmits the resulting data to the first computer; and S0236) the first computer removes the second encryption (DecM2) from the processed data received at the end of step S0235.

5. Data processing method according to claim 4, wherein step S0235 is carried out immediately after step S33, such that during step S0235, the second computer applies the first encryption (EncHEl) to the processed data obtained from the output of step S33.

6. A data processing method according to any one of claims 1 to 5, wherein in step S3, the processed data is encrypted using a cipher (Encl2) other than the first cipher, or is encrypted with the first cipher but with a different encryption key; and the encrypted result returned at the end of step S3 is encrypted with a cipher different from the first encryption or is encrypted with the first encryption but with a different encryption key.

7. Data processing method according to any one of claims 1 to 6, wherein a receiving client (CL1,CL2) receiving the encrypted result at the end of step S3, is identical or different from the or each of said at least one sending client (CL1) providing the data (x) at step SI.

8. A data processing method according to any one of claims 1 to 7, further comprising a step S0411 preceding step S2 and during which the first client (CL1) applies an additional encryption (EncS), in particular symmetric, to the data (x); and after the data ([x] xs) has been transmitted to the first computer in step S2, the first computer removes the additional encryption (S0430).

9. A data processing method according to any one of claims 1 to 8, wherein - during an operation S0533, the TEE removes the first encryption (DecMli), referred to as the initial first encryption, which may be, in particular, a masking encryption, from the processed data; and - during an operation S0535, the TEE applies a homomorphic encryption (EncHEl2) to the processed data, as the final first encryption; - during an operation S0535a, following step S0535, the processed data under the final first encryption (EncMli) and under the second encryption (EncHEl2) is transmitted to the server; when all the elementary operations have been performed, the ciphertext of the result is transmitted to the client under the final first encryption (EncHEl2); and in step S4, the client removes the final first encryption (DecHEl2).

10. A data processing method according to any one of claims 1 to 8, wherein the first encryption applied in step SI is the homomorphic encryption (EncHEli), referred to as the first homomorphic encryption; in a step S0633, the TEE removes the first homomorphic encryption (DecHEli) from the processed data; In an S0635 step performed after the S0633 step, the TEE applies to the data a second homomorphic encryption (Encl2) other than the first homomorphic encryption; and in the S4 step, the client removes the second homomorphic encryption from the encrypted result.

11. A data processing method according to any one of claims 1 to 10, wherein the combination of elementary operations comprises N elementary operations of order j, j=1...N; step S3 comprises the execution of a plurality of computation loops, iteratively; at each loop of index j, j=1..N, steps SI (0701), S31 (S0731), S32 (S0732) and S33 (S0733), one step S0730, one step S0735 and one step S0736 are carried out as follows: during step SI (S0701), the client provides an input data of index j (xj), and transmits said input data of index j to the first computer, which is the server, as input data for step S0730; During step S0730, the server applies the elementary operation (gj) of index j to the data provided to it as input;The server performs step S31 (S0731) of applying the second encryption to the processed data and step S32 of transmitting the encrypted processed data to the TEE; the TEE performs step S33 of removing the first encryption from the processed data, then in step S0735 applies the first encryption to the data again, and then retransmits the re-encrypted data to the server; upon receiving said re-encrypted data, the server, during a step S0736a, removes the second encryption from it; the modified data is then provided as input data for operation S0730 of the next calculation loop if it takes place.

12. Data processing method according to claim 11, wherein a verifiable calculation protocol (ji) is defined, which allows verification of the result by performing an elementary check for each of said elementary operations; the first computer is the server, and the second computer is the TEE; a tag calculation function ( ir.tag ) is defined within the framework of the verifiable calculation protocol, this function being commutative with the elementary operations gj; at the SI step (S0701), the client also transmits to the server a tag (tag([x]i) of the cipher under first encryption of the data (x); the second encryption is a mask encryption (mj); at each loop with index j, j = 1.. .N: at step S0701a, the client provides the server with a mask (nij) and a mask tag (tag(nij)) of the mask; during an S0730 step, the server applies the elementary operation (gj) of index j to the processed data tag provided to it as input; during an S0731 step, the server encrypts the processed data (Enc2) using a second encryption; during an S0732 step, the server transmits to the TEE the processed data ([x] 12) obtained, encrypted under first and second encryption; during an S0730a step, the server applies the elementary operation (gj) of index j to the data tag provided to it as input; During an S0731a step, the server calculates the tag of the ciphertext under double encryption (tag([gj(x)]i2)) from the tag (tag([gj(x)]i)) obtained in the S0730a step, and the tag (tag(mj)) of the mask mj, and transmits this tag to the TEE; During an S0732a step, depending on the encrypted data received in the S0732 step, and the encrypted data tag received in the S0731a step, the TEE verifies the elementary operation performed in the S0730 step by performing the elementary check corresponding to that operation; if the result is positive and the loop index j satisfies j <N, à l’étape S0733 : - the TEE removes the first encryption (DecHEl) from the encrypted data received at step S0732 performed during the loop, then - during an S0735 step, applies the first encryption (EncHE 1) to the data under second encryption and transmits the resulting encrypted data to the server; - During an S0736 step, the server removes the second encryption (DecM2) from the data received at the end of the S0735 step, and provides the data thus decrypted as input data for the S0730 operation of the next calculation loop; - During an S0735a step, the TEE calculates a tag of the cipher data calculated in the S0735 step and transmits this tag to the server; then - During an S0736a step, the server calculates the tag of the unmasked ciphertext (tag([gj(x)]i)) from the tag received at the end of the S0735a step and the tag of the mask, and provides the tag of the unmasked ciphertext as input data for the S0730a operation of the next calculation loop.

13. A data processing method according to claim 11, wherein the first computer is the TEE; during at least one of the calculation loops, referred to as loop J, of index j=J, the method is executed as follows: at step S32 of loop J, in addition to the data encrypted under first and second encryption ([z]n>2), the first computer transmits to the second computer a signature (o([z]nj2)) of it, as well as another data encrypted ([z']n>2) under first and second encryption accompanied by a signature (o([z']nj2)) of the latter; at step S33 of loop J (S0933), the server removes the first encryption from the data encrypted under double encryption and from said other data received at step S32; at a step S0934 of the J loop, the server applies the elementary index operation J to the two decrypted data obtained at step S33;at a step S0934a of the loop J, the server applies the first encryption (EncMli) to the data obtained; the server further calculates a proof of computation proving that the encrypted data obtained at the end of step S0934a is indeed the result of applying the elementary operation of index J to the two data used as input for step S0934, and transmits the encrypted data obtained at step S0934a as well as the proof to the TEE; During an S0934b step, the TEE checks at least whether the proof corresponds to the result of the calculation; and, if the result of the check is positive, at an S0936 step the first computer removes the second encryption of the data (DecHE2), and provides the data obtained as input for an S31 step of the next index loop if it takes place; if the result of the check is negative, the TEE interrupts the processing.

14. A data processing method according to claim 11, wherein the first computer is the TEE; the second encryption being a homomorphic encryption ensuring security against CCA attacks, for example the Paillier cipher; during at least one of the computation loops, called loop J, of index j=J, the method is executed as follows: at step S32 of loop J (SI 132), in addition to the data encrypted under first and second encryption ([z]n>2), the TEE transmits to the server another data encrypted ([z']n>2) under first and second encryption; at step S33 of loop J (SI 133), the server removes the first encryption from the data encrypted under double encryption and from said other data received at step S32; at a step SI 134 of the J loop, the server applies the elementary index operation J to the two decrypted data obtained at step S33;At an SI 134a step of the J loop, the server applies the first encryption (EncMli) to the data obtained by applying the elementary operation (gj) of index J at the SI 134 step; the server transmits the encrypted data obtained at the SI 134a step to the TEE; and, at an SI 136 step, the TEE removes the second encryption from the data (DecCF), and provides the resulting data as input for an S31 step of the next index loop if one is to take place.