Methods, media, and programs for secure multi-party computing and communication.
By jointly generating noise in secure multi-party computing, the method addresses inconsistencies in differential privacy protocols, ensuring consistent data privacy protection and secure computation across parties.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- LEMON CO LTD
- Filing Date
- 2024-04-04
- Publication Date
- 2026-05-01
AI Technical Summary
Existing differential privacy protocols and algorithms face inconsistencies in data privacy protection due to individual parties adding noise independently, leading to inconsistent results across multiple parties in multi-party computation scenarios.
A method for secure multi-party computing and communication where parties jointly generate noise to achieve a desired level of data privacy protection, using a confidential mechanism that involves generating random binomial noise to disrupt true dataset query results.
Ensures consistent data privacy protection across parties by jointly generating noise, maintaining data privacy while allowing secure computation and communication without revealing sensitive information.
Smart Images

Figure 2026513825000001_ABST
Abstract
Description
[Technical Field]
[0001] Cross-references to related applications This application claims priority over the U.S. application No. 18 / 297545, “SECURE MULTI-PARTY COMPUTATION AND COMMUNICATION,” filed on April 7, 2023, which is incorporated herein by reference in its entirety.
[0002] The embodiments described herein generally relate to private and confidential multiparty computation and communication. More specifically, the embodiments described herein relate to private and confidential multiparty computation and communication algorithms or operations in which parties jointly generate noise in a confidential mechanism to achieve a desired level of data privacy protection for differential privacy protocols or algorithms. [Background technology]
[0003] Differential Privacy (DP) protocols and algorithms have been used to provide robust data privacy protection. For each interactive query or operation from a user to a dataset, DP protocols and algorithms can provide a certain level of data privacy protection (known as differential privacy guarantees). Confidential Multi-Party Computation (MPC) algorithms or operations are performed on multiple datasets owned or hosted by multiple parties, and the results may be distributed among the parties. Each party may individually add or insert noise into its dataset or the query results of that dataset to achieve the desired level of data privacy protection in the DP protocol or algorithm. However, the final results may be inconsistent across parties due to noise added by other parties. [Overview of the project]
[0004] The features of the embodiments disclosed herein provide a confidential MPC algorithm or operation that enables parties to jointly generate noise data in a confidential mechanism to achieve a certain level of data privacy protection against the DP protocol or algorithm. For example, instead of each party individually adding or inserting noise data into a dataset or the query results of that dataset, two parties jointly operate on those datasets, obtain results or shares of results, and noise data is generated during the MPC operation and added to the results or shares to achieve a certain level of data privacy protection against the DP protocol or algorithm.
[0005] Features of embodiments disclosed herein can provide efficient distributed algorithms or protocols for generating shares of random noise to protect data privacy to semi-honest parties. Features of embodiments disclosed herein (e.g., co-noise generation) can provide distributed implementations of privacy-protected statistical datasets that can achieve data privacy by adding a desired or predetermined amount of random binomial noise to disrupt the true results of dataset queries.
[0006] In a semi-honest security model, it is understood that all parties may honestly follow private join operations and computational protocols while attempting to extract more information from, or about, other parties' input datasets. The features of the embodiments disclosed herein can provide security with respect to semi-honest and computationally limited adversaries.
[0007] In one exemplary embodiment, a method is provided for protecting data privacy in secure multi-party computing and communication. This method includes determining a differential privacy setting, which includes at least a first parameter and a second parameter. This method includes determining the number of iterations based on the first and second parameters, generating random value and random noise data at each iteration, generating a first message and a second message based on the random value and random noise data, and performing a transfer based on the first message, the second message, and input data to output one of the first message and the second message. This method further includes generating first noise data based on random noise data at each iteration, generating a first share based on a first and second dataset, applying the first noise data to the first share, and constructing a result based on the first and second share.
[0008] Another exemplary embodiment provides a method for protecting data privacy in secure multi-party computing and communication. This method includes determining a differential privacy setting, which includes at least a first parameter and a second parameter. This method further includes determining the number of iterations based on the first and second parameters, and in each iteration, generating a random value, and performing a transfer based on a first message, a second message, and the random value to receive one of the first and second messages. This method further includes generating first noise data based on the received one of the first and second messages in each iteration, generating a first share based on a first and second dataset, applying the first noise data to the first share, and constructing a result based on the first and second shares.
[0009] In yet another exemplary embodiment, a non-temporary computer-readable medium is provided on which computer-executable instructions are stored. When executed, the instructions cause one or more processors to perform an operation which includes determining a differential privacy setting. The differential privacy setting includes at least a first parameter and a second parameter. The operation includes determining the number of iterations based on the first and second parameters; generating random values and random noise data at each iteration; generating a first message and a second message based on the random values and random noise data; performing a transfer based on the first message, the second message, and input data to output one of the first message and the second message. The operation further includes generating first noise data based on the random noise data at each iteration; generating a first share based on a first and second dataset; applying the first noise data to the first share; and constructing a result based on the first and second shares. [Brief explanation of the drawing]
[0010] The accompanying drawings illustrate various embodiments of the system, the method, and various other embodiments of the present disclosure. Those skilled in the art will understand that the element boundaries shown in the drawings (e.g., boxes, groups of boxes, or other shapes) represent examples of boundaries. In some examples, one element may be designed as multiple elements, and multiple elements may be designed as one element. In some examples, an element shown as an internal component of one element may be implemented as an external component of another element, and vice versa. A non-limiting and non-exclusive description is made with reference to the following drawings. The components in the drawings are not necessarily to scale, and the emphasis is on illustrating the principle. Embodiments are described only as examples, as various changes and modifications will become apparent to those skilled in the art from the following detailed description.
[0011] [Figure 1]A schematic diagram of an exemplary secure computing and communication system arranged according to at least some embodiments described herein.
[0012] [Figure 2] A flowchart showing an exemplary processing flow for protecting data privacy in private and secure multiparty computing and / or communication according to at least some embodiments described herein.
[0013] [Figure 3] A schematic diagram showing an example of the processing flow of FIG. 2 according to at least some embodiments described herein.
[0014] [Figure 4] A flowchart showing an exemplary processing flow for jointly generating noise in private and secure multiparty computing and / or communication according to at least some embodiments described herein.
[0015] [Figure 5] A schematic structural diagram of an exemplary computer system applicable to the implementation of an electronic device arranged according to at least some embodiments described herein.
Mode for Carrying Out the Invention
[0016] In the following detailed description, specific embodiments of the present disclosure are described herein with reference to the accompanying drawings which constitute part of the description. In this description and drawings, unless otherwise specified in the context, similar reference numerals represent elements capable of performing the same, similar, or equivalent functions. Furthermore, unless otherwise noted, the description of each sequence of drawings may refer to one or more features of a previous drawing to provide a clearer context and a more substantial description of the current exemplary embodiment. Nevertheless, the exemplary embodiments described in the detailed description, drawings, and claims are not intended to be limiting. Other embodiments may be utilized and other modifications may be made without departing from the spirit or scope of the subject matter presented herein. It will be readily apparent that the aspects of the present disclosure generally described herein and shown in the drawings may be arranged, substituted, combined, separated, and designed in a wide variety of different configurations, all of which are expressly assumed herein.
[0017] It should be understood that the disclosed embodiments are merely examples of the disclosure and may be embodied in various ways. To avoid obscuring this disclosure with unnecessary details, well-known functions or structures are not described in detail. Therefore, the specific structural and functional details disclosed herein should not be construed as restrictive, but rather as representative grounds to teach a person skilled in the art how to use this disclosure in various ways with substantially any suitable detailed structure.
[0018] Furthermore, in this specification, functional blocks may also be described in the form of functional block components and various processing steps. It is understood that such functional blocks can be realized by any number of hardware and / or software components configured to perform a specified function.
[0019] The scope of the disclosure should be determined by the appended claims and their legal equivalents, not by the examples set forth herein. For example, the steps described in the claims of a method may be performed in any order, and are not limited to the order shown in the claims. Furthermore, unless specifically stated herein as “material” or “essential,” there are no elements essential to the implementation of the disclosure.
[0020] As used herein, “dataset” is a technical term and may refer to an organized collection of data stored and accessed electronically. In one embodiment, a dataset may refer to a database, a data table, a portion of a database or data table, etc. It is understood that a dataset corresponds to one or more database tables, where each column of a database table represents a specific variable or field, and each row of a database table corresponds to a specific record in a dataset. A dataset may list the values of each variable and / or the values of each record in the dataset. A dataset may also refer to a collection of related data and the way in which the related data is organized. In exemplary embodiments, each record in a dataset may include one or more predefined or predetermined identifiers (e.g., membership identifiers such as usernames, email addresses, telephone numbers, etc., user identifiers), and / or fields or elements such as one or more attributes, features, or values associated with one or more identifiers. It is understood that any user identifiers and / or user data described herein are authorized, approved, and / or authenticated by the user for use in the embodiments described herein and appropriate legal equivalents understood by those skilled in the art.
[0021] The term "inner join" used here is a technical term and may refer specifically to an operation or function that combines records from two or more datasets, particularly when there are matching values in a common field of the datasets. For example, an inner join can be performed on the "Departments" dataset and the "Employees" dataset to determine all employees in each department. It is important to understand that the resulting dataset (i.e., the "common part") of an inner join operation may contain mutually relevant information from both datasets. On the other hand, an outer join may result in a dataset that contains information unrelated to the other dataset. A private inner join refers to an inner join operation of two or more datasets that does not reveal data in the common part of the two or more parties' datasets.
[0022] The term "hash" as used here may refer to an operation or function that transforms or converts an input (a key such as a number or string) into an output (another number, another string, etc.). It's important to understand that hashing is a technical term and can be used in cybersecurity applications to access data in short, nearly constant intervals each time it's retrieved.
[0023] The terms "MPC" or "Multi-Party Computation" used here are technical terms and may refer to a field of cryptography aimed at creating schemes for parties to collaboratively compute a function on a shared input while keeping each input private. Unlike traditional cryptographic tasks where encryption guarantees the security and integrity of communications or storage, MPC encryption may protect the privacy of the participants themselves, especially when adversaries are outside the participants' systems (e.g., eavesdroppers on the sender and / or receiver).
[0024] The terms "ECC" or "elliptic curve cryptography" used here are technical terms and may refer to public-key cryptography based on the algebraic structure of elliptic curves over a finite field. ECC is understood to offer equivalent security with smaller keys compared to non-EC cryptography. It is also understood that "EC" or "elliptic curves" can be applied to key sharing, digital signatures, pseudorandom number generators, and / or other tasks. Elliptic curves can be used indirectly for encryption by combining key sharing between parties with symmetric encryption schemes. Elliptic curves can also be used in integer factorization algorithms based on elliptic curves, which are applied to cryptography.
[0025] The terms "Deterministic Diffie-Hellman Assumption" or "DDH Assumption" used here are technical terms and may refer to computational complexity assumptions concerning certain problems, including discrete logarithms of cyclic groups. It should be understood that the DDH assumption can be used as a basis for proving the security of many cryptographic protocols.
[0026] The terms "Elliptic Curve Diffie-Hellman" or "ECDH" used here are technical terms and may refer to a key-sharing protocol or corresponding algorithm that enables two or more parties, each possessing an elliptic curve public-key and private-key pair, to establish a shared secret over an unsecured channel. The shared secret can be used directly as a key or to derive another key. This key, or any derived key, can then be used to encrypt or encode subsequent communications using symmetric-key cryptography. Furthermore, ECDH may also refer to a variant of the Diffie-Hellman protocol that uses elliptic curve cryptography.
[0027] The term "homomorphic" encryption used here is a technical term and may refer to an encryption format in which computations can be performed on encrypted data without the user first decrypting it. It should be understood that the computational results of homomorphic encryption remain encrypted and, upon decryption, yield the same output as if the operation had been performed on unencrypted data. It should also be understood that homomorphic encryption can be used for privacy-protected outsourced storage and computation, allowing data to be encrypted and then outsourced for processing in a commercial cloud environment while remaining encrypted. Furthermore, it should be understood that additive homomorphic encryption or cryptographic systems may refer to a form of encryption or cryptographic system in which, given only the public key and the encryption of messages m1 and m2, the encryption of m1+m2 can be computed.
[0028] The terms "secret sharing" or "secret partitioning" used here are technical terms and may refer to an encryption action or algorithm that generates a secret, divides that secret into multiple shares, distributes those shares among multiple parties, and allows the secret to be reconstructed only when the parties combine their respective shares. Secret sharing may refer to an action or algorithm that distributes a secret within a group, so that no individual possesses any understandable information about the secret, but allows it to be reconstructed when a sufficient number of individuals combine their "shares." It should also be understood that in non-secret secret sharing, an attacker may be able to obtain more information from each share, while secure secret sharing is "all or nothing," where "all" may mean the required number of shares.
[0029] The term "semi-honest" adversarial, as used here, is a technical term that may refer to a party that attempts to corrupt another party but adheres to the specified protocol. It is understood that a "semi-honest" party may be a corrupt party that honestly carries out the current protocol but attempts to learn from messages received from another party, for example, beyond the purpose intended by the protocol.
[0030] The terms “differential privacy” or “DP” as used herein are technical terms and may refer to standards, protocols, systems, and / or algorithms for publicly sharing information about a dataset by describing patterns of groups of elements within the dataset, while retaining information about individual users listed in the dataset. Differential privacy may refer to constraints on algorithms used to expose aggregated information about a statistical dataset or database to users, and these constraints are understood to limit the disclosure of private information about personal records in which the dataset or database contains information.
[0031] The following is a non-limiting example of a context, setting, or application of differential privacy. A trusted data owner (or a data holder or curator such as a social media platform, website, service provider, or application) may store a dataset of sensitive information about an individual (e.g., a dataset containing records / rows of an individual). Each time the dataset is queried (or manipulated, e.g., analyzed, processed, used, stored, shared, accessed, etc.), there is a potential for an individual's privacy to be compromised (e.g., a data privacy leak or a loss of privacy). Differential privacy can prevent an individual's privacy from being compromised by providing a rigorous framework and security definition for algorithms that manipulate sensitive data and expose aggregate statistics, for example, by resisting link attacks and auxiliary information, and / or providing limits on the quantifiable damage (privacy leak, loss of privacy, etc.) that can occur by individual records in a dataset.
[0032] The above requirements for differential privacy protocols or algorithms may refer to a measure of "how much data privacy is provided when performing an operation or function (e.g., by a single query or operation on an input dataset)?". The DP parameter "ε" may refer to the privacy budget (i.e., the limit of data privacy that is allowed to be leaked). For example, it represents the maximum difference between a query or operation on dataset A and the same query or operation on dataset A' (which differs from A by one element or record). The smaller the value of ε, the stronger the privacy protection of the multi-identity privacy protection mechanism. Another DP parameter "δ" may refer to a probability, such as the probability of information being leaked unintentionally. As an example, the required or given number for ε is in the range of 1 or about 1 to 3 or about 3. The required or given number for δ is 10 -10 or about 10 -10 or 10 -8 or about 10 -8 from 10 -6 or about 10 -6 This ranges up to [a certain point]. Another DP parameter, sensitivity, refers to a quantified quantity indicating how much noise perturbation is necessary in the DP protocol or algorithm. It should be understood that determining sensitivity requires determining the maximum possible change in the results. In other words, sensitivity refers to the effect that changes to the underlying dataset have on the results of queries to the dataset.
[0033] As used herein, “Differential Privacy Composition” or “DP Composition” is a technical term and may refer to the total or overall differential privacy when a particular dataset is queried (or manipulated, e.g., analyzed, processed, used, stored, shared, accessed, etc.) multiple times. DP composition is used to quantify the overall differential privacy (which may be reduced in terms of the DP of a single query or operation) when multiple separate queries or operations are performed on a single dataset. If a single query or operation on a dataset has a privacy loss L, the cumulative impact on data privacy of N queries (referred to as Nx composition or Nx DP composition) may be greater than L, but less than L*N. In one embodiment, the Nx DP composition is determined based on an Nx convolution operation of the privacy loss distribution. For example, the DP composition of two queries is determined based on the convolution of the privacy loss distributions of the two queries. In one embodiment, the number N may be 10 or around, 25 or around, or any other appropriate number. In one embodiment, ε, δ, sensitivity, and / or the number N may be predetermined to achieve a desired or given data privacy protection goal or performance.
[0034] In probability theory and statistics, the "binomial distribution" is a technical term that can refer to the discrete probability distribution of successes in a sequence of n independent experiments, each asking a "yes" or "no" question, each with its own Boolean outcome: success (probability p) or failure (probability q=1-p). It should be understood that in the field of signal processing, Gaussian noise can refer to signal noise with a probability density function equal to that of a normal distribution (i.e., a Gaussian distribution). In other words, the values that Gaussian noise can take follow a normal distribution (i.e., a Gaussian distribution). Similarly, binomial noise can refer to signal noise with a probability density function equal to that of a binomial distribution.
[0035] It is understood that differential privacy requirements can be achieved by anonymizing data by intentionally adding or inserting noise into the dataset. This allows data users to perform all possible or useful statistical analyses on the dataset without identifying personal information. It is also understood that adding controlled noise from a given distribution (such as a binomial, Laplace, or normal / Gaussian distribution) can be a way to design differential privacy algorithms. Furthermore, it is understood that adding noise can be useful in designing privacy protection mechanisms for real-valued functions on sensitive data.
[0036] The term "ring" used here is a technical term and can refer to an algebraic structure that generalizes a field. That is, multiplication does not need to be commutative, nor does it need to have a reciprocal. In other words, a ring can be a set with two binary operations that satisfy properties similar to integer addition and multiplication.
[0037] As mentioned here, in the context of encryption, "lost communication" is a technical term that may refer to an algorithm, protocol, or operation in which the sender transfers at least one of potentially many pieces of information to the receiver, but remains unaware, unconcerned, or unaware of which information (if any) was transferred. One form of lost communication is "1-2 lost communication" or "1 out of 2 lost communication" for private, confidential multi-party computing. For example, in a 1-2 lost communication protocol or algorithm, the sender has two messages, m0 and m1, and wants to ensure that the receiver knows only one. The receiver has bit b, and the sender does not know b, m bWe want to receive a lost message. Lost communication can be generalized to "1-out-of-n lost communication". In this case, the receiver receives only one element of the dataset, but the sender does not know which element was queried, and the receiver knows nothing about the other elements that were not received. A 1-out-of-n lost communication protocol or algorithm can be defined as a natural generalization of a 1-out-of-2 lost communication protocol or algorithm. For example, the sender has n messages, the receiver has index i, the receiver wants to receive the i-th message from the sender without the sender knowing i, and the sender wants to guarantee that the receiver receives only one of the n messages.
[0038] Figure 1 is a schematic diagram of an exemplary secure computing and communication system 100, arranged according to at least some embodiments described herein.
[0039] System 100 may include terminal devices 110, 120, 130, and 140, a network 160, and a server 150. It should be understood that Figure 1 shows only an exemplary number of terminal devices, networks, and servers. The embodiments described herein are not limited to the number of terminal devices, networks, and / or servers described herein. That is, the number of terminal devices, networks, and / or servers described herein are provided for illustrative purposes only and are not limiting.
[0040] According to at least some embodiments, terminal devices 110, 120, 130, and 140 may be various electronic devices. These various electronic devices include, but are not limited to, mobile devices such as smartphones, tablet computers, e-readers, laptop computers, desktop computers, and / or other suitable electronic devices.
[0041] According to at least some embodiments, network 160 is a medium used to provide communication links between terminal devices 110, 120, 130, 140 and server 150. Network 160 can be the Internet, a local area network (LAN), a wide area network (WAN), a local interconnection network (LIN), a cloud, etc. Network 160 is implemented by various types of connections such as wired communication links, wireless communication links, and fiber optic cables.
[0042] According to at least some embodiments, server 150 may be a server that provides various services to users using one or more of the terminal devices 110, 120, 130, and 140. Server 150 may be implemented by a distributed server cluster including multiple servers, or by a single server.
[0043] Users may interact with the server 150 via the network 160 using one or more of the terminal devices 110, 120, 130, and 140. Various applications, such as social media applications and online shopping services, or their localized interfaces, may be installed on the terminal devices 110, 120, 130, and 140.
[0044] It should be understood that software applications or services in accordance with the embodiments and / or services provided by the service provider described herein may be executed by server 150 and / or terminal devices 110, 120, 130, and 140 (which may be referred to herein as user devices). Therefore, the devices for the software applications and / or services may be located within server 150 and / or terminal devices 110, 120, 130, and 140.
[0045] It is also understood that if the service is not run remotely, system 100 may not include network 160 and may only include terminal devices 110, 120, 130, and 140 and / or server 150.
[0046] Furthermore, it is understood that each of the terminal devices 110, 120, 130, 140 and / or server 150 may include one or more processors, memory, and a storage device for storing one or more programs. Each of the terminal devices 110, 120, 130, 140 and / or server 150 may also include an Ethernet connector, a wireless fidelity receptor, and the like. When one or more programs are executed by one or more processors, they can cause one or more processors to perform the methods described in any embodiment described herein. It is also understood that, according to the embodiments described herein, a computer-readable non-volatile medium is provided. A computer program is stored on the computer-readable medium. When the computer program is executed by a processor, it is used to perform the methods described in any embodiment described herein.
[0047] Figure 2 is a flowchart illustrating an exemplary processing flow 200 for protecting data privacy in private and confidential multi-party computing and / or communications, according to at least some embodiments described herein.
[0048] Figure 3 shows a schematic diagram 300 illustrating an example of the processing flow 200 of Figure 2, according to at least some embodiments described herein.
[0049] It should be understood that the processing flow 200 disclosed herein can be executed by one or more processors (for example, one or more processors in terminal devices 110, 120, 130, and 140 in Figure 1, the processor in server 150 in Figure 1, central processing unit 505 in Figure 5, and / or other suitable processors) unless otherwise specified.
[0050] It is also understood that the processing flow 200 may include one or more operations, actions, or functions, as indicated in one or more of blocks 210, 220, 230, 240, and 250. These various operations, functions, or actions may correspond, for example, to processor-executable software, program code, or program instructions that cause the execution of a function. Although shown as separate blocks, obvious modifications may be made, for example, the order of two or more blocks may be changed, more blocks may be added, various blocks may be split into additional blocks, combined into fewer blocks, or deleted, depending on the desired implementation. It is also understood that operations such as initialization may be performed before the processing flow 200. For example, system parameters and / or application parameters may be initialized. The processing flow 200 may begin with block 210.
[0051] In block 210 (Dataset Provision), the processor of each device provides a dataset to party A (e.g., 310A in Figure 3) and / or provides a dataset to party B (e.g., 310B in Figure 3). In one embodiment, the size of dataset 310A or 310B may include tens or hundreds of thousands of elements (or records, rows, etc.). It should be understood that the size of a dataset may refer to the number of elements (or records, rows, etc.) in the dataset.
[0052] In one embodiment, dataset 310A contains multiple records (rows), each containing a member or user identifier (ID) and a time (T1) indicating, for example, the time (start time or timestamp) when the member or user clicked a link on Party A's platform. Dataset 310B contains multiple records (rows), each containing a member or user identifier (ID) and a time (T2) indicating, for example, the time (start time or timestamp) when the member or user interacted with Party B's website, and a value indicating the user's value to Party B. In one embodiment, the time (or timestamp) is listed in minutes. It should be understood that the format, content, and / or arrangement of datasets 310A and / or 310B are for illustrative purposes only and are not limiting. For example, each dataset 310A or 310B may contain one or more IDs (columns) and / or zero or one or more features or attributes (columns) associated with one or more IDs.
[0053] In one embodiment, for various reasons related to Party A and / or Party B, it may be wise to determine, for example, (1) the number of members or users who clicked a link on Party A's platform, etc., and subsequently interacted with Party B's website and had a valuable interaction; (2) the number of members or users who clicked a link on Party A's platform, etc., and subsequently interacted with Party B's website and had a valuable interaction within a certain period (e.g., 70 minutes) after clicking the link on Party A's platform; and / or (3) the total number of all members or users who clicked a link on Party A's platform, etc., and subsequently interacted with Party B's website and had a valuable interaction within a certain period (e.g., 70 minutes) after clicking the link on Party A's platform.
[0054] Please understand that for several reasons, Party A and / or Party B may not want to expose at least some of the data in dataset 310A and / or dataset 310B, and / or the data in the common portion of datasets 310A and 310B, to the other party. Processing may proceed from block 210 to block 220.
[0055] In block 220 (performing private operations), the processor of each device can perform various operations on dataset 310A and / or dataset 310B, for example, to generate a private common part of the dataset. For example, the processor can transform the ID (column) of dataset (310A and / or 310B) using a transformation scheme for party A and / or a transformation scheme for party B. The processor can also transform the features or attributes (column) of dataset (310A and / or 310B) using a transformation scheme for party A and / or a transformation scheme for party B.
[0056] It is understood that a function or operation that "transforms" a dataset or a part thereof, such as one or more columns (or rows) of a dataset, such as one or more identifiers or feature / attribute fields / columns (or records / rows), may refer to processing of the dataset or a part thereof (e.g., encryption, decryption, encoding, decoding, manipulation, compression, decompression, conversion, etc.). It is also understood that a corresponding "transformation scheme" may refer to an algorithm, protocol, or function that performs processing of the dataset or a part thereof (e.g., encryption, decryption, encoding, decoding, manipulation, compression, decompression, conversion, etc.).
[0057] In one embodiment, the processor may, for example, use a key of party A based on an ECDH algorithm or protocol (represented by function D0(.)) to encrypt (or decrypt, encode, decode, manipulate, compress, decompress, convert, etc.) the IDs of at least datasets (310A and / or 310B) using a key of party B based on an ECDH algorithm or protocol (represented by function D1(.)).
[0058] In one embodiment, the processor can transform features or attributes (columns) of a dataset (310A and / or 310B) using a transformation scheme for party A and / or a transformation scheme for party B. For example, the processor can encrypt (or decrypt, encode, decode, manipulate, compress, decompress, convert, etc.) features or attributes (columns) of a dataset (310A and / or 310B) based on an additive homomorphic encryption algorithm or protocol (represented by function H0(.)) using, for example, the key of party A, and / or encrypt (or decrypt, encode, decode, manipulate, compress, decompress, convert, etc.) features or attributes (columns) of a dataset (310A and / or 310B) based on an additive homomorphic encryption algorithm or protocol (represented by function H1(.)) using, for example, the key of party B. It is understood that the results of functions D0(D1(p)) and D1(D0(p)) may be the same for the same parameter "p".
[0059] In block 220, the processor of each device performs a search for matches (or an internal join operation, etc.) between the converted datasets 310A and / or 310B to obtain or generate the common part of party A (dataset 320A in Figure 3) and the common part of party B (dataset 320B in Figure 3).
[0060] It should be understood that for Party A, the data in the common part 320A is also transformed (e.g., encoded) by Party B (through D1(.) and H1(.)), and therefore the actual data from Party B in the common part 320A is not known to Party A and is not available to them. For Party B, the data in the common part 320B is also transformed (e.g., encoded) by Party A (through D0(.) and H0(.)), and therefore the actual data from Party A in the common part 320B is not known to Party B and is not available to them. In other words, the matching or inner join operation performed as described above is a “private” matching or inner join operation. The processor performs private identity matching without revealing the common parts of the two parties' datasets. Processing may proceed from block 220 to block 230.
[0061] In block 230 (Share Generation), for each attribute or feature in the dataset (320A and / or 320B) (for example, an element that is not an identifier in the ID field / column), the processor generates a corresponding mask, and then masks each attribute or feature in the dataset (320A and / or 320B) with the corresponding mask using a masking scheme to obtain or generate Party A's dataset (secret share) 330A and / or Party B's dataset (secret share) 330B.
[0062] In one embodiment, each mask is a random number or random plaintext. In one embodiment, the masking scheme includes homomorphic operations or calculations (e.g., addition, subtraction, etc.) in an additive homomorphic encryption algorithm or protocol. For example, as shown in Figure 3, the mask for T2 data H1(50) in dataset 320A is represented as "share0_of_50", and the processor can use the mask "share0_of_50" as the secret share of T2 data H1(50) in dataset 330A. The processor can also homomorphically calculate the share of T2 data H1(50) in dataset 320B and, for example, subtract the mask "share0_of_50" from H1(50) to generate the secret share of T2 data H1(50) in party B's dataset 330B (e.g., represented as "50-share0_of_50"). Because the mask is a random number (for example, a random number with a length of 64 bits), the secret share of dataset 330A (the random number "share0_of_50") may not reveal the actual data to party A. Similarly, the secret share of dataset 330B ("50-share0_of_50" is also a random number, and the result of subtracting a random number from another random number is still random) may not reveal the actual data to party B. Also, if party A's secret share ("share0_of_50") and party B's secret share ("50-share0_of_50") are combined (for example, added), the actual result data ("50") may be exposed to the parties.
[0063] It is also understood that the processor of each device can perform a private computation (for example, by performing a secret MPC algorithm or operation) on the secret share in Party A's dataset 330A to generate the resulting secret share 340A, and / or perform a private computation on the secret share in Party B's dataset 330B to generate the resulting secret share 340B.
[0064] For example, in the case of Party A, the processor (1) subtracts T1 from T2 (in the case of dataset 330A), (2) determines whether the result of the subtraction is greater than 0 and less than a predetermined value, and (3) if the result of the subtraction in (2) is greater than 0 and less than the predetermined value, sets the variable, which is a random number, to 1 (representing "True") in the secret share. If the result of the subtraction in (2) is less than or equal to 0 or greater than or equal to the predetermined value, sets the variable, which is a random number, to 0 (representing "False") in the secret share. (4) multiplies the corresponding variable by the data in the "Value" field or column, further sums the results of the multiplication, and stores or saves the result in the "Value" field of dataset 340A to generate dataset 340A for Party A. Similar to the process for Party A, the processor also generates dataset 340B for Party B.
[0065] It is understood that multiplying a secret share of 1 by an arbitrary value V still results in the value V, and multiplying a secret share of 0 by an arbitrary value V results in a secret share of 0. It is also understood that during the concealed MPC operation to generate the resulting secret shares (340A and / or 340B), the actual data remains unknown to Party A and Party B.
[0066] Dataset 340A (Secret Share, denoted as "share0_of_121") represents the total value of all users who clicked a link on Party A's platform, interacted with Party B's website within a certain period (e.g., 70 minutes) after clicking the link on Party A's platform, and performed a valuable interaction. It is also understood that, since the Secret Share is a random value, Party A does not know the actual data represented by Dataset 340A (Secret Share). Similarly, Dataset 340B (Secret Share, denoted as "121-share0_of_121") represents the total value of all users who clicked a link on Party A's platform, accessed Party B's website within a certain period (e.g., 70 minutes) after clicking the link on Party A's platform, and performed a valuable interaction. Furthermore, since the Secret Share is a random value, it is also understood that Party B does not know the actual data represented by Dataset 340B (Secret Share). Processing may proceed from block 230 to block 240.
[0067] In block 240 (implementing data privacy protection), the processor of each device can implement data privacy protection for Party A (see detailed explanation in Figure 4), add its noise share (represented as "noise_share_A") to its data secret share ("share0_of_121"), and generate dataset 350A in Figure 3. The processor of each device can also implement data privacy protection for Party B, add its noise share (represented as "noise_share_B") to its data secret share ("121-share0_of_121"), and generate dataset 350B in Figure 3. Processing may proceed from block 240 to block 250.
[0068] In block 250 (Construction of Results), the processor of each device can exchange dataset 350A for dataset 350B between Party A and Party B. For example, in the case of Party A, the processor can dispatch or send dataset 350A to Party B (e.g., Party B's processor) and receive or acquire dataset 350B from Party B. The processor can also construct the result (121 + noise_share_A + noise_share_B) by adding, for example, the data from dataset 350A and the data from the received dataset 350B. In other words, the total value of all users who clicked a link on Party A's platform, then moved to Party B's website within a certain time (e.g., within 70 minutes) after clicking the link on Party A's platform, and performed a valuable interaction is that value (121) plus the noise jointly generated by Party A and Party B (noise_share_A + noise_share_B = noiseR).
[0069] Similarly, in the case of Party B, the processor can construct the result (121 + noise_share_A + noise_share_B) by dispatching or sending dataset 350B to Party A, receiving or acquiring dataset 350A from Party A, and adding the data from dataset 350B and the data from the received dataset 350A. In other words, the sum of all users who clicked on a link on Party A's platform, accessed Party B's website within a certain period (e.g., 70 minutes) after clicking on the link on Party A's platform, and performed a valuable interaction is the value (121) plus the noise jointly generated by Party A and Party B, which is the same result determined by Party A.
[0070] It should be understood that the noise jointly generated by Party A and Party B is small enough not to significantly affect the accuracy of the actual result (e.g., the value 121), but large enough to provide a certain level of differential privacy protection. In other words, the final result is close enough to the actual value (e.g., the value 121), but different enough that neither Party A nor Party B knows the actual value (e.g., the value 121), thus achieving the desired or predetermined level of differential privacy protection. See the detailed explanation in Figure 4.
[0071] Figure 4 is a flowchart illustrating an exemplary processing flow 400 for jointly generating noise in private and confidential multiparty computing and / or communications, according to at least some embodiments described herein.
[0072] It should be understood that the processing flow 400 disclosed herein can be executed by one or more processors (for example, one or more processors in terminal devices 110, 120, 130, and 140 in Figure 1, the processor in server 150 in Figure 1, central processing unit 505 in Figure 5, and / or other suitable processors) unless otherwise specified.
[0073] It should also be understood that the processing flow 400 may include one or more operations, actions, or functions, as shown in one or more of blocks 410, 420, 430, 440, 450, 460, 470, 480, and 490. These various operations, functions, or actions may correspond, for example, to software, program code, or program instructions that can be executed by one or more processors to cause the execution of a function. Although shown as separate blocks, obvious modifications can be made. For example, the order of two or more blocks may be changed, more blocks may be added, various blocks may be split into additional blocks, combined into fewer blocks, or deleted. This will depend on the desired implementation. It should also be understood that operations such as initialization may be performed before the processing flow 400. For example, system parameters and / or application parameters may be initialized from the result of block 230 in Figure 2. It should also be understood that the processes in the processing flow 400 may be part of the processes in block 240 in Figure 2. The processing flow 400 may start from block 410.
[0074] In block 410 (determining differential privacy parameters), the processor of each device can provide or obtain one or more parameters for a desired or predetermined differential privacy (DP) protection. In one embodiment, one or more parameters may include a DP data privacy budget ε (i.e., the limit of acceptable data leakage), a DP data privacy leakage probability δ, a number K of queries or operations on the dataset (DP composition), a DP sensitivity (e.g., the effect of changes to the underlying dataset on the results of queries to the dataset), and / or the probability P that a random variable is equal to a desired or predetermined value (details below). It should be understood that the sequence or order of parameters is not limited to the examples provided in the embodiments disclosed herein. It should also be understood that one or more parameters may be predetermined to achieve a desired or predetermined data privacy protection goal or performance. Processing may proceed from block 410 to block 420.
[0075] In block 420 (determining the number of iterations), the processor of each device can determine the number of iterations N (used in block 430) based on one or more parameters provided or determined for party A and / or party B in block 410. In one embodiment, if the number K is 1, the sensitivity is 1, and the probability P is 0.5, then the number N is 8*log(2 / δ) / ε to achieve the level of data privacy defined or determined by the parameters (ε, δ, K, sensitivity, and / or P, etc.). 2 It may be placed in [location]. Processing may proceed from block 420 to block 430. It should be understood that block 430 contains blocks 440, 450, 460, and / or 470.
[0076] In block 430 (for each iteration), the processor of each device may execute the processes of blocks 440, 450, 460, and / or 470 in each of the N iterations to generate a portion of party A's noise share and / or a portion of party B's noise share.
[0077] In block 440 (generation of random values), the processor of each device can generate a random value a for Party A with a probability P provided or determined in block 410 A and / or a random value a for Party B B In one embodiment, a A or a B is a random bit, and a A or a B is equal to 1 when the probability P is equal to 0.5 and equal to 0 when the probability (1 - P) is equal to 0.5. The probability P (provided or determined in block 410) may be any suitable probability other than 0.5. The random value a A or a B may be any suitable value other than 0 or 1. The process may proceed from block 440 to block 450
[0078] In block 450 (generating random noise), the processor generates a random number r for Party A. In one embodiment, the length (“l”) of the random number r is 64 bits. In one embodiment, the length of the random number r ensures that operations (such as additive secret sharing) are performed over a ring (algebraic structure). Also, it is understood that the value of the random number r is relatively small (e.g., about 10 or less, about 100 or less, etc.) compared to the data (represented as secret shares, see the description of block 490. Usually, it is tens of thousands or more), and it is ensured that the accuracy of the data is not significantly impaired. Further, it is understood that no operation is performed on Party B in block 450. The process may proceed from block 450 to block 460
[0079] In block 460 (message generation), the processor can generate a message for Party A (used in block 470) based on the random number a determined in block 440 A and the random number / noise r determined in block 450. In one embodiment, for the 1 - 2 lossy communication executed in block 470, the random number a AIf it is 0, the processor will determine that each message in the pair (s0, s1) is ((-r)mod2 l , (-r+1)mod2 l Messages s0 and s1 can be generated such that they are equal to ), where r is a random number generated in block 450, l is the length of r, and "mod" is the "modulo" operation (a binary operation that returns the remainder or signed remainder after dividing one number by another). Random value a A If it is 1, the processor considers each message in the pair (s0, s1) to be ((-r+1)mod2 l , (-r)mod2 l Messages s0 and s1 can be generated such that they are equal to ). It should be understood that the features or configuration of such embodiments ensure that the final noise R (details below) is the result of a logical operation on the noise share (such as an exclusive "OR" operation). It should be understood that, like r, the messages (s0, s1) are also random numbers / noise. Also, if 1-n lost communication occurs in block 470, and / or random value a A It should also be understood that if the value is anything other than 0 or 1, messages s0 and s1 may be generated in different ways. Furthermore, note that no operations are performed on party B in block 460. Processing may proceed from block 460 to block 470.
[0080] In block 470 (Execution of Lost Communication), the processor of each device performs lost communication using input messages from party A (generated in block 460 for party A) and input values from party B (generated in block 440 for party B), and based on the input value from party B, one of the input messages (from party A), "x", can be output to party B. In one embodiment, the processor uses input messages (s0, s1) from party A and input value a from party B. B Use 1-2 lost communication, value a B Based on this, one of the messages (s0, s1) can be output. For example, a BIf is equal to 0, s0 is output to party B by executing the 1-2 lost communication algorithm. B If is equal to 1, then s1 is output to party B by executing the 1-2 lost communication algorithm. When the lost communication algorithm is executed, party A is a B It is understood that Party B may not know the value of (or the message output to Party B), and Party B may not know the remaining messages (from Party A) that are not output to Party B.
[0081] The processes in blocks 440, 450, 460, and 470 may be repeated until each of the N iterations has been processed. Processing may also proceed from block 430 to block 480.
[0082] In block 480 (noise share generation), the processor of each device generates a share of noise R of party A. A Generates and / or shares the noise R of party B B It can generate. In one embodiment, Party A's share R A This is the sum of random numbers / noise generated in each of the N iterations in block 450 (for example, rmod2 in each of the N iterations). l The sum of the values, where l is the length of the random number r. Party B's share R B This is the sum of the outputs determined in each of the N iterations in block 470 (for example, xmod2 in each of the N iterations). l (total of) is equal to one embodiment. Noise R is, for example, noise share (R A and R B It is constructed by adding (etc.). In one embodiment, noise R is the noise share (R A and R B It may also be the result of a logical operation (such as an exclusive "OR" operation) on (etc.). Please note that if it is generated according to the process of processing flow 400, noise R may be binomial noise (following a binomial distribution). Processing may proceed from block 480 to block 490.
[0083] In block 490 (for implementing data privacy protection), the processor of each device controls the noise share (for example, R A By adding noise (e.g., R) to a data share (e.g., the secret share in dataset 340A in Figure 3), a data share with added noise for Party A (e.g., the secret share in 350A) can be generated. The processor of each device then processes the corresponding noise share (e.g., R) B By adding noise (for example, a secret share in dataset 340B) to a data share (for example, a secret share in dataset 340B), a data share with added noise for Party B (for example, a secret share in 350B) can be generated. The lost communication performed in block 470 allows Party A to add noise share R of Party B. B Party B may not know this, and Party A's noise share R A Please understand that they may not be aware of this.
[0084] When constructing the result by combining a data share with added noise from Party A and a data share with added noise from Party B (see explanation of block 250 in Figure 2), the result will be the actual result (for example, value 121) with Party A (R A (through) and PARTB(R B It is understood that the result may include noise R jointly generated by (through). It is also understood that after constructing the result (see explanation of block 250 in Figure 2), either party A or party B, or both parties A and party B, may obtain the same result (for example, the actual value 121 with noise R added).
[0085] It is also understood that the introduced noise R (added to the results of the MPC operation) can achieve a desired or predetermined level of DP protection defined by parameters (such as ε, δ, K, sensitivity, and / or P) in a consistent result. For example, a desired or predetermined level of DP protection defined by parameters (such as ε, δ, K, sensitivity, and / or P) can be achieved by adding controlled noise from a given distribution (such as a Laplace distribution or a Gaussian distribution) to dataset 310A by party A and / or to dataset 310B by party B. However, in such a mechanism, since party A and party B each generate their corresponding noise independently, inconsistent results may be produced between party A (whose results include noise generated by party B) and party B (whose results include noise generated by party A). The features of the embodiments disclosed herein allow for the achievement of the same, nearly identical, or similar levels of DP protection with consistent results (Party A and Party B can obtain results with the same noise R) rather than Party A individually adding noise to dataset 310A and / or Party B individually adding noise to dataset 310B, in order to achieve a desired or predetermined level of DP protection defined by parameters (such as ε, δ, K, sensitivity, and / or P). This can be achieved by adding a share of noise R (jointly generated by Party A and Party B) to the secret data shares of Party A and / or Party B (Party A and / or Party B) (Party A and / or Party B can obtain results with the same noise R). It should be understood that the noise R (jointly generated by Party A and Party B) is small enough not to have a significant impact on the accuracy of the actual results (e.g., a value of 121), but large enough to provide the level of DP protection defined by parameters (such as ε, δ, K, sensitivity, and / or P). In other words, the final result is close enough to the actual value (e.g., value 121), but can be far enough different that neither Party A nor Party B knows the actual value (e.g., value 121), and DP protection defined by the parameters (ε, δ, K, sensitivity, and / or P, etc.) is achieved.
[0086] Furthermore, it should be understood that in one embodiment, to achieve a first level of DP protection, noise is individually added to dataset 310A by party A and / or to dataset 310B by party B, and then noise R (jointly generated by party A and party B) is further added to the confidential data shares of party A and / or party B, thereby achieving a second level of DP protection (e.g., a higher or better level than the first level).
[0087] Figure 5 is a schematic diagram of an exemplary computer system 500 applicable to implementing an electronic device (e.g., one of the servers or terminal devices shown in Figure 1) arranged according to at least some embodiments described herein. It should be understood that the computer system shown in Figure 5 is provided for illustrative purposes only and does not limit the functions and uses of the embodiments described herein.
[0088] As shown in the diagram, the computer system 500 may include a central processing unit (CPU) 505. The CPU 505 performs various operations and processes based on programs stored in read-only memory (ROM) 510 or programs loaded from storage device 540 into random access memory (RAM) 515. RAM 515 also stores various data and programs necessary for the operation of system 500. The CPU 505, ROM 510, and RAM 515 are interconnected via bus 520. An input / output (I / O) interface 525 is also connected to bus 520.
[0089] Components connected to the I / O interface 525 may further include input devices 530 such as keyboards, mice, digital pens, and drawing pads; output devices 535 such as displays like liquid crystal displays (LCDs) and speakers; storage devices 540 such as hard disks; and communication devices 545 such as LAN cards and modems. The communication device 545 can perform communication processing via networks such as the Internet, WAN, LAN, LIN, and cloud. In one embodiment, a driver 550 may also be connected to the I / O interface 525. Removable media 555 such as magnetic disks, optical disks, magneto-optical disks, and semiconductor memory may be attached to the driver 550 as needed, and computer programs read from the removable media 555 may be installed on the storage device 540.
[0090] It is understood that the processes described with reference to the flowcharts in Figures 2 and 4 and / or other figures can be implemented as computer software programs or in hardware. A computer program product includes a computer program stored on a computer-readable non-volatile medium. The computer program includes program code for performing the methods shown in the flowcharts and / or GUIs. In this embodiment, the computer program is downloaded and installed from a network via a communication device 545 and / or installed from removable media 555. Once executed by a central processing unit (CPU) 505, the computer program can perform the functions specified in the methods of the embodiments disclosed herein.
[0091] It is understood that the disclosed and other solutions, examples, embodiments, modules, and functional operations described herein can be implemented in digital electronic circuits, computer software, firmware, or hardware, or one or more combinations thereof, including the structures disclosed herein and their structural equivalents. The disclosed and other embodiments can be implemented as one or more computer program products, i.e., one or more modules of computer program instructions that are executed by a data processing device or encoded on a computer-readable medium to control the operation of a data processing device. A computer-readable medium may be a machine-readable storage device, a machine-readable storage substrate, a memory device, a composition of material that provides machine-readable propagating signals, or one or more combinations thereof. The term “data processing device” encompasses all devices, machines, and equipment that process data, including, for example, a programmable processor, a computer, or multiple processors or computers. In addition to hardware, a device may include code that creates an environment for the execution of computer programs, such as code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or one or more combinations thereof.
[0092] Computer programs (also called programs, software, software applications, scripts, or code) can be written in any form of programming language, including compiled and interpreted languages, and can be deployed in any form, as standalone programs or as modules, components, subroutines, or other units suitable for use in a computing environment. Computer programs do not necessarily correspond to files in a file system. A program can be part of a file that holds other programs or data (such as one or more scripts stored in a markup language document), a single file dedicated to the program, or multiple coordinated files (such as a file containing one or more modules, subprograms, or parts of code). Computer programs can be deployed to run on a single computer, or to run on multiple computers located in one site or distributed across multiple sites and interconnected by a communication network.
[0093] The processes and logic flows described in this document are executed by one or more programmable processors, and one or more computer programs are executed to perform functions that manipulate input data and produce outputs. The processes and logic flows can also be executed by special-purpose logic circuits, such as field-programmable gate arrays and application-specific integrated circuits, or the devices can be implemented as special-purpose logic circuits.
[0094] Processors suitable for executing computer programs include, for example, both general-purpose and dedicated microprocessors, and one or more processors in any type of digital computer. Generally, a processor receives instructions and data from read-only memory or random-access memory, or both. Essential elements of a computer are a processor that executes instructions and one or more memory devices that store instructions and data. Generally, a computer also includes one or more mass storage devices that store data, such as magnetic disks, magneto-optical disks, or optical disks, or is operationally coupled to receive data from or transfer data to such storage devices, or both. However, a computer is not required to have such devices. Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices. These include, for example, semiconductor memory devices such as erasable programmable read-only memory, electrically erasable programmable read-only memory, and flash memory devices, magnetic disks such as internal hard disks or removable disks, magneto-optical disks, and compact disk read-only memory and digital video disk read-only memory disks. The processor and memory are complemented by or integrated into dedicated logic circuits.
[0095] It should be understood that different features, variations, and multiple different embodiments are described in various details. What is described in this application with respect to a particular embodiment is for illustrative purposes only and is not intended to limit or suggest that the invention is limited to one specific embodiment or specific embodiment only. It should be understood that this disclosure is not limited to a single specific embodiment or the listed variations. A person skilled in the art will come up with many modifications, variations, and other embodiments, which are intended and indeed covered by this disclosure. In fact, the scope of this disclosure is intended to be determined by the appropriate legal interpretation and construction of this disclosure, including its equivalents, as understood by a person skilled in the art relying on the complete disclosure existing at the time of filing.
[0096] manner
[0097] It is understood that all of these configurations can be combined with one another.
[0098] Embodiment 1 is a method for protecting data privacy in secure multi-party computing and communication, comprising: determining a differential privacy setting including at least a first parameter and a second parameter; determining the number of iterations based on the first parameter and the second parameter; generating random values and random noise data in each iteration; generating a first message and a second message based on the random values and random noise data; performing a transfer based on the first message, the second message and input data, and outputting one of the first message and the second message; generating first noise data based on the random noise data in each iteration; generating a first share based on a first dataset and a second dataset; applying the first noise data to the first share; and constructing a result based on the first share and the second share.
[0099] Embodiment 2 is the method of Embodiment 1, wherein the differential privacy setting includes at least a third parameter, and the number of iterations is determined based on the first parameter, the second parameter, and the third parameter.
[0100] Embodiment 3 is the method of Embodiment 2, wherein the differential privacy setting includes at least a fourth parameter, and the number of iterations is determined based on the first, second, third, and fourth parameters.
[0101] Embodiment 4 is the method of Embodiment 3, wherein the differential privacy setting includes at least a fifth parameter, and the number of iterations is determined based on the first, second, third, fourth, and fifth parameters.
[0102] Embodiment 5 is a method in any one of Embodiments 1 to 4 in which, in each iteration, generating a random value includes generating a random value with a probability that the random value is a desired value.
[0103] Embodiment 6 is a method in any one of Embodiments 1 to 5 in which the first noise data is the sum of random noise data for each iteration.
[0104] Embodiment 7 further includes, in any one of Embodiments 1 to 6, generating second noise data based on which of the first and second messages output in each iteration, and applying the second noise data to the second share.
[0105] Embodiment 8 is the method of Embodiment 7, wherein the first message and the second message are noise data, and the second noise data is the sum of whichever of the first message and the second message is output for each iteration.
[0106] Embodiment 9 is a method for protecting data privacy in confidential multiparty computing and communication, comprising: determining a differential privacy setting including at least a first parameter and a second parameter; determining the number of iterations based on the first parameter and the second parameter; in each iteration, generating a random value and performing a transfer based on a first message, a second message, and the random value and receiving one of the first message and the second message; generating first noise data based on the received one of the first message and the second message in each iteration; generating a first share based on a first dataset and a second dataset; applying the first noise data to the first share; and constructing a result based on the first share and the second share.
[0107] Embodiment 10, in the method of Embodiment 9, the differential privacy setting includes at least a third parameter, and the number of iterations is determined based on the first parameter, the second parameter, and the third parameter.
[0108] Embodiment 11 is the method of Embodiment 10, wherein the differential privacy setting includes at least a fourth parameter, and the number of iterations is determined based on the first, second, third, and fourth parameters.
[0109] Embodiment 12 is the method of Embodiment 11, wherein the differential privacy setting includes at least a fifth parameter, and the number of iterations is determined based on the first, second, third, fourth, and fifth parameters.
[0110] Embodiment 13 is a method in any one of Embodiments 9 to 12 in which, in each iteration, generating a random value includes generating a random value with a probability that the random value is a desired value.
[0111] Embodiment 14 is a method in any one of Embodiments 9 to 13 in which one of the received first message and the second message is noise data, and the first noise data is the sum of the received one of the first message and the second message for each iteration.
[0112] Embodiment 15 further includes, in any one of Embodiments 9 to 14, generating random noise data in each iteration, generating second noise data based on the random noise data generated in each iteration, and applying the second noise data to the second share.
[0113] Embodiment 16 is the method of Embodiment 15, wherein the second noise data is the sum of the random noise data for each iteration.
[0114] Embodiment 17 is a non-temporary computer-readable medium storing a computer-executable instruction, which, when executed, causes one or more processors to perform operations including: determining a differential privacy setting including at least a first parameter and a second parameter; determining the number of iterations based on the first and second parameters; generating random values and random noise data at each iteration; generating a first message and a second message based on the random values and random noise data; performing a transfer based on the first message, the second message and input data; outputting one of the first message and the second message; generating first noise data based on the random noise data at each iteration; generating a first share based on a first dataset and a second dataset; applying the first noise data to the first share; and constructing a result based on the first and second shares.
[0115] Embodiment 18, in the computer-readable medium of Embodiment 17, the differential privacy setting includes at least a third parameter, a fourth parameter, and a fifth parameter, and the number of iterations is determined based on the first parameter, the second parameter, the third parameter, the fourth parameter, and the fifth parameter.
[0116] Embodiment 19, in a computer-readable medium according to Embodiment 17 or 18, generating a random value in each iteration includes generating a random value with a probability that the random value is a desired value.
[0117] Embodiment 20, in any one of embodiments 17 to 19 on a computer-readable medium, further comprises generating second noise data based on which of the first and second messages output in each iteration, and applying the second noise data to the second share.
[0118] The terms used herein are intended to describe, and not limit, specific embodiments. Technical terms include plural forms unless otherwise specified. The terms “includes” and / or “compose” as used herein specify the presence of the features, integers, steps, operations, elements, and / or components described herein, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, and / or components.
[0119] It should be understood that, with respect to the description in the preamble, particularly with respect to the constituent materials used, the shape, size, and arrangement of the components, modifications can be made in detail without departing from the scope of the invention. The embodiments described herein are for illustrative purposes only, and the true scope and spirit of this disclosure are shown by the following claims.
Claims
1. A method for protecting data privacy in secure multi-party computing and communications, Determine differential privacy settings that include at least the first and second parameters, The number of iterations is determined based on the first and second parameters, In each of the aforementioned number of iterations, Generate random values and random noise data, Based on the aforementioned random values and the aforementioned random noise data, a first message and a second message are generated, and The transfer is performed based on the first message, the second message, and the input data, and one of the first message and the second message is output. To generate first noise data based on the random noise data in each of the aforementioned number of iterations, To generate the first share based on the first and second datasets, Applying the first noise data to the first share, This includes constructing results based on the first and second shares. A method for protecting data privacy in secure multi-party computing and communications.
2. The differential privacy setting includes at least a third parameter, and the number of iterations is determined based on the first, second, and third parameters. The method according to claim 1.
3. The differential privacy setting includes at least a fourth parameter, and the number of iterations is determined based on the first, second, third, and fourth parameters. The method according to claim 2.
4. The differential privacy setting includes at least a fifth parameter, and the number of iterations is determined based on the first, second, third, fourth, and fifth parameters. The method according to claim 3.
5. In each of the aforementioned iterations, generating the random value includes generating the random value with a probability that the random value is a desired value. The method according to claim 1.
6. The first noise data is the sum of the random noise data for each of the number of iterations. The method according to claim 1.
7. A second noise data is generated based on which of the first message and the second message is output in each of the aforementioned number of iterations. The further includes applying the second noise data to the second share. The method according to claim 1.
8. The first message and the second message are noise data, and the second noise data is the sum of whichever of the first message and the second message was output in each of the number of iterations. The method according to claim 7.
9. A method for protecting data privacy in secure multi-party computing and communications, Determine differential privacy settings that include at least the first and second parameters, The number of iterations is determined based on the first and second parameters, In each iteration, Generate random values, and The transfer is performed based on the first message, the second message, and a random value, and one of the first message and the second message is received. To generate first noise data based on which of the first message and the second message received in each of the aforementioned number of iterations, To generate the first share based on the first and second datasets, Applying the first noise data to the first share, This includes constructing results based on the first and second shares. A method for protecting data privacy in secure multi-party computing and communications.
10. The differential privacy setting includes at least a third parameter, and the number of iterations is determined based on the first, second, and third parameters. The method according to claim 9.
11. The differential privacy setting includes at least a fourth parameter, and the number of iterations is determined based on the first, second, third, and fourth parameters. The method according to claim 10.
12. The differential privacy setting includes at least a fifth parameter, and the number of iterations is determined based on the first, second, third, fourth, and fifth parameters. The method according to claim 11.
13. In each of the aforementioned iterations, generating the random value includes generating the random value with a probability that the random value is a desired value. The method according to claim 9.
14. Of the first message and the second message, the one that was received is noise data. The first noise data is the sum of the received first message and second message in each of the number of iterations. The method according to claim 9.
15. In each of the aforementioned number of iterations, random noise data is generated, A second noise data is generated based on the random noise data generated in each of the aforementioned number of iterations. The further includes applying the second noise data to the second share. The method according to claim 9.
16. The second noise data is the sum of the random noise data for each of the number of iterations. The method according to claim 15.
17. A non-temporary, computer-readable medium containing computer-executable instructions, When the aforementioned computer executable instruction is executed, it will cause one or more processors to: Determine differential privacy settings that include at least the first and second parameters, The number of iterations is determined based on the first and second parameters, In each of the aforementioned number of iterations, Generate random values and random noise data, Based on the aforementioned random values and the aforementioned random noise data, a first message and a second message are generated, and The transfer is performed based on the first message, the second message, and the input data, and one of the first message and the second message is output. To generate first noise data based on the random noise data in each of the aforementioned number of iterations, To generate the first share based on the first and second datasets, Applying the first noise data to the first share, Perform an operation that includes constructing results based on the first and second shares. A non-temporary, computer-readable medium containing computer-executable instructions.
18. The differential privacy setting includes at least a third parameter, a fourth parameter, and a fifth parameter, The number of iterations is determined based on the first parameter, the second parameter, the third parameter, the fourth parameter, and the fifth parameter. The computer-readable medium according to claim 17.
19. In each of the aforementioned iterations, generating the random value includes generating the random value with a probability that the random value is a desired value. The computer-readable medium according to claim 17.
20. The aforementioned operation is, A second noise data is generated based on which of the first message and the second message is output in each of the aforementioned number of iterations. The further includes applying the second noise data to the second share. The computer-readable medium according to claim 17.