Methods, media, and programs for secure computation and communication.
Secure computation and communication methods using translation schemes and oblivious shuffling optimize privacy matching and computation for large data sets, addressing high complexity in existing schemes and ensuring confidentiality in semi-honest security models.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- LEMON CO LTD
- Filing Date
- 2024-04-04
- Publication Date
- 2026-05-01
AI Technical Summary
Existing private matching-computing schemes for inner joins of data sets from multiple data owners have high communication and computational complexity, necessitating the development of optimized protocols for privacy matching and computation of large amounts of big data.
The implementation of secure computation and communication methods using translation schemes, oblivious shuffling, and deterministic Diffie-Hellman assumptions to reduce communication and computational complexity, ensuring privacy and confidentiality in semi-honest security models.
These methods effectively reduce communication and computational complexity while maintaining privacy and security in semi-honest adversarial environments, enabling secure sharing of data without revealing common parts of datasets.
Smart Images

Figure 2026513891000001_ABST
Abstract
Description
Technical Field
[0001] [Cross - Reference to Related Applications] This application claims priority based on U.S. Application No. 18 / 297424, filed on April 7, 2023, entitled "SECURE COMPUTATION AND COMMUNICATION", the entire disclosure of which is incorporated herein by reference.
[0002] [Technical Field] The embodiments described herein generally relate to private and secure computing and communication. More specifically, the embodiments described herein relate to private inner - joins of data from multiple data owners and secure computing and communication.
Background Art
[0003] The inner - join of records of data sets from multiple data owners may be a prerequisite for subsequent operations in many applications, such as the collection of aggregated statistics, the training of distributed machine - learning models, etc. For example, when one party owns the feature data or attribute data of an element and the other party owns the label or identifier of the element, a private inner - join that does not reveal the common part is required before performing distributed or federated training in a machine - learning application.
[0004] Existing private - matching - for - computing schemes can complete private identity matching without revealing the common part of the data sets or databases of two parties, and after the members or user identifiers in the data sets are matched, they can generate secure sharing of the data of the two parties for subsequent multi - party computations.
Summary of the Invention
[0005] Existing schemes can have relatively high communication and computational complexity, highlighting the need to design schemes optimized for privacy matching and computation of large amounts of big data. Features of the embodiments disclosed herein help to solve problems related to privacy matching of data between two or multiple parties in two-party or multi-party confidential computation, and generating confidential sharing of data relating to common parts of datasets from two or more parties. Features of the embodiments disclosed herein provide private and confidential protocols based on computational complexity assumptions (e.g., the deterministic Diffie-Hellman assumption) and various algorithms such as the oblivious shuffling algorithm, which can effectively reduce communication and computational complexity compared to existing schemes.
[0006] In a semi-honest security model, it is understood that all parties may honestly follow private join operations and computational protocols while attempting to extract more information from or about the input datasets of other parties. The features of the embodiments disclosed herein can provide security with respect to semi-honest and computationally limited adversaries.
[0007] In one exemplary embodiment, a method for secure computation and communication is provided. This method includes the steps of: translating identifiers of a first dataset using a translation scheme; dispatching the translated identifiers of the first dataset; receiving identifiers of a second dataset; translating identifiers of the second dataset; dispatching the translated identifiers of the second dataset; receiving a set of identifiers; generating a first intersection of the received set of identifiers and the translated identifiers of the second dataset; and determining a first permutation based on the first intersection. This method further includes the step of performing oblivious shuffling based on the first permutation and a set of attributes to generate a first share. The size of the first share is the same as the size of the first intersection. This method further includes the step of receiving a second share; and constructing a first result based on the first and second shares.
[0008] In another exemplary embodiment, a method for secure computation and communication is provided. This method includes the steps of: translating identifiers of a first dataset using a translation scheme; dispatching the translated identifiers of the first dataset; receiving identifiers of a second dataset; translating identifiers of the second dataset; dispatching the translated identifiers of the second dataset; receiving a set of identifiers; and generating a first intersection of the received set of identifiers and the translated identifiers of the second dataset. This method further includes the step of performing oblivious shuffling based on a first permutation and attributes of the first dataset to generate a first share. The size of the first share is the same as the size of the first intersection. This method further includes the steps of: receiving a second share; and constructing a first result based on the first and second shares.
[0009] In yet another exemplary embodiment, a non-temporary computer-readable medium is provided on which computer executable instructions are stored. When an instruction is executed by one or more processors, it causes one or more processors to perform an operation that includes: translating identifiers of a first dataset using a translation scheme; dispatching the translated identifiers of the first dataset; receiving identifiers of a second dataset; translating identifiers of the second dataset; dispatching the translated identifiers of the second dataset; receiving a set of identifiers; generating a first intersection of the received set of identifiers and the translated identifiers of the second dataset; determining a first permutation based on the first intersection; performing oblivious shuffling based on the first permutation and a set of attributes to generate a first share, wherein the size of the first share is the same as the size of the first intersection; receiving a second share; and constructing a first result based on the first and second shares. [Brief explanation of the drawing]
[0010] The accompanying drawings illustrate various embodiments of the system, the method, and various other embodiments of the present disclosure. Those skilled in the art will understand that the element boundaries shown in the drawings (e.g., boxes, groups of boxes, or other shapes) represent examples of boundaries. In some examples, one element may be designed as multiple elements, and multiple elements may be designed as one element. In some examples, an element shown as an internal component of one element may be implemented as an external component of another element, and vice versa. A non-limiting and non-exclusive description is made with reference to the following drawings. The components in the drawings are not necessarily to scale, and the emphasis is on illustrating the principle. Embodiments are described only as examples, as various changes and modifications will become apparent to those skilled in the art from the following detailed description.
[0011] [Figure 1] This is a schematic diagram of an exemplary secure computing and communication system arranged according to at least some embodiments described herein.
[0012] [Figure 2] This flowchart shows an exemplary internal coupling processing flow for private and secure computing and communication according to at least some embodiments described herein.
[0013] [Figure 3] This flowchart shows an exemplary secret sharing processing flow for private and secure computing and communication according to at least some embodiments described herein.
[0014] [Figure 4A] This figure shows the first part of a schematic diagram illustrating an example of the processing flow in Figure 2, according to at least some embodiments described herein.
[0015] [Figure 4B] This figure shows the second part of a schematic diagram illustrating an example of the processing flow in Figure 2, according to at least some embodiments described herein.
[0016] [Figure 4C] This figure shows the third portion of the schematic diagram illustrating an example of the processing flow in Figure 3, according to at least some embodiments described herein.
[0017] [Figure 5] This is a schematic diagram of an exemplary computer system applicable to the implementation of electronic devices, arranged according to at least some embodiments described herein. [Modes for carrying out the invention]
[0018] In the following detailed description, specific embodiments of the present disclosure are described herein with reference to the accompanying drawings which constitute part of the description. In this description and drawings, unless otherwise specified in the context, similar reference numerals represent elements capable of performing the same, similar, or equivalent functions. Furthermore, unless otherwise noted, the description of each sequence of drawings may refer to one or more features of the preceding drawings to provide a clearer context and a more substantial description of the current exemplary embodiment. Nevertheless, the exemplary embodiments described in the detailed description, drawings and claims are not intended to be limiting. Other embodiments may be used and other modifications may be made without departing from the spirit or scope of the subject matter presented herein. It will be readily apparent that the aspects of the present disclosure generally described herein and shown in the drawings may be arranged, substituted, combined, separated and designed in a wide variety of different configurations, all of which are expressly assumed herein.
[0019] It should be understood that the disclosed embodiments are merely examples of the disclosure and may be embodied in various ways. To avoid obscuring this disclosure with unnecessary details, well-known functions or structures are not described in detail. Therefore, the specific structural and functional details disclosed herein should not be construed as restrictive, but rather as representative grounds to teach a person skilled in the art how to use this disclosure in various ways with substantially any suitable detailed structure.
[0020] Furthermore, in this specification, functional blocks may also be described in the form of functional block components and various processing steps. It is understood that such functional blocks can be realized by any number of hardware and / or software components configured to perform a specified function.
[0021] The scope of the disclosure should be determined by the appended claims and their legal equivalents, rather than by the examples described herein. For example, the steps recited in a method claim can be performed in any order and are not limited to the order shown in the claim. Further, there are no elements essential to the implementation of the disclosure unless specifically recited herein as "important" or "essential".
[0022] As used herein, the term "dataset" may refer to an organized collection of data that is electronically stored and accessed. In one embodiment, a dataset may refer to a database, a data table, a part of a database or a data table. It is understood that a dataset corresponds to one or more database tables, each column of a database table represents a particular variable or field, and each row of a database table corresponds to a particular record of the dataset. A dataset may list the values of each variable and / or the values of each record of the dataset. A dataset may further or alternatively refer to a collection of related data and the way the related data is organized. In an exemplary embodiment, each record of a dataset may include one or more predefined or predetermined identifiers (e.g., membership identifiers such as a username, an email address, a phone number, a unique ID of a user, a user identifier), and / or one or more fields or elements such as one or more attributes, characteristics, or values associated with the one or more identifiers. It is understood that any of the user identifiers and / or user data described herein are permitted, approved, and / or authenticated by the user for use in the embodiments described herein and appropriate legal equivalents understood by those skilled in the art.
[0023] The "inner join" mentioned here is a technical term, and in particular, it may refer to an operation or function that involves joining records of a dataset when there are values that match fields common to the datasets. For example, an inner join can be performed on a "department" dataset and an "employee" dataset to determine all employees in each department. It should be understood that in the resulting dataset of the inner join operation (i.e., the "common part"), the inner join may include related information from both datasets. On the other hand, in an outer join, the resulting dataset may also include information that is not related to other datasets. A private inner join refers to an inner join operation on datasets of two or more parties that does not reveal data in the common part of the datasets of two or more parties.
[0024] The "hash" mentioned here may refer to an operation or function that converts or transforms an input (such as a key like a numerical value or a string) into an output (such as another numerical value or another string). Hash is a technical term, and it should be understood that in cyber security applications, it can be used to access data in a short and approximately constant time for each acquisition.
[0025] The "federated", "distributed", or "collaborative" learning or training mentioned here is a technical term, and it may refer to a machine learning technique that trains an algorithm across multiple distributed edge devices or servers that store local data samples without exchanging data samples between devices or servers. It should be understood that "federated" learning or training may be contrasted with traditional centralized machine learning techniques where all local datasets are uploaded to one server, or more typical distributed approaches where it is assumed that local data samples are evenly distributed. Federated learning or training enables multiple actors to build a common robust machine learning model without sharing data among the actors, and can address important issues such as data privacy, data security, data access rights, and access to heterogeneous data.
[0026] The terms "MPC" or "Multi-Party Computation" used here are technical terms and may refer to a field of cryptography aimed at creating schemes for parties to collaboratively compute a function on a shared input while keeping each input private. Unlike traditional encryption tasks where encryption guarantees the security and integrity of communications or storage, MPC encryption may protect the privacy of the participants themselves, especially when adversaries are outside the participants' systems (e.g., eavesdroppers on the sender and / or receiver).
[0027] The terms "ECC" or "elliptic curve cryptography" used here are technical terms and may refer to public-key cryptography based on the algebraic structure of elliptic curves over a finite field. ECC is understood to offer equivalent security with smaller keys compared to non-EC cryptography. It is also understood that "EC" or "elliptic curves" can be applied to key sharing, digital signatures, pseudorandom number generators, and / or other tasks. Elliptic curves can be used indirectly for encryption by combining key sharing between parties with symmetric encryption schemes. Elliptic curves can also be used in integer factorization algorithms based on elliptic curves that are applied to cryptography.
[0028] The terms "Deterministic Diffie-Hellman Assumption" or "DDH Assumption" used here are technical terms and may refer to computational complexity assumptions concerning specific problems, including discrete logarithms of cyclic groups. It should be understood that the DDH assumption can be used as a basis for proving the security of many cryptographic protocols.
[0029] The terms "Elliptic Curve Diffie-Hellman" or "ECDH" used here are technical terms and may refer to a key-sharing protocol or corresponding algorithm that enables two or more parties, each possessing an elliptic curve public-key and private-key pair, to establish a shared secret over an unsecured channel. The shared secret can be used directly as a key or to derive another key. This key, or any derived key, can then be used to encrypt or encode subsequent communications using symmetric-key cryptography. Furthermore, ECDH may also refer to a variant of the Diffie-Hellman protocol that uses elliptic curve cryptography.
[0030] The term "homomorphic" encryption used here is a technical term and may refer to an encryption format in which calculations can be performed on encrypted data without the user first decrypting it. It should be understood that the results of homomorphic encryption remain encrypted and, upon decryption, yield the same output as if the operation had been performed on unencrypted data. It should also be understood that homomorphic encryption can be used for privacy-protected outsourced storage and computation, allowing data to be encrypted and then outsourced for processing in a commercial cloud environment while remaining encrypted. Furthermore, it should be understood that additive homomorphic encryption or cryptographic systems may refer to a form of encryption or cryptographic system in which, given only the public key and the encryption of messages m1 and m2, the encryption of m1+m2 can be calculated.
[0031] The terms "secret sharing" or "secret partitioning" used here are technical terms and may refer to an encryption action or algorithm that generates a secret, divides it into multiple shares, distributes those shares among multiple parties, and allows the secret to be reconstructed only when the parties combine their respective shares. Secret sharing may refer to an action or algorithm that distributes a secret within a group, so that no individual possesses any understandable information about the secret, but allows it to be reconstructed when a sufficient number of individuals combine their "shares." It should also be understood that in non-secret secret sharing, an attacker may be able to obtain more information from each share, while secure secret sharing is "all or nothing," where "all" may mean the required number of shares.
[0032] As used herein, “shuffle,” “shuffling,” and “rearrange” are technical terms and may refer to actions or algorithms that rearrange the order of records (elements, rows, etc.) in, for example, arrays, datasets, databases, data tables, etc., and / or randomly rearrange them.
[0033] The term “permutation” as used herein is a technical term and may refer to any of several possible order or arrangement variations of a dataset (e.g., records or elements of a dataset) or a part thereof. In one embodiment, permutation of a dataset may refer to arranging at least some of the records (e.g., rows) or elements of a dataset in a sequence or linear order, or rearranging at least some of the records or elements of a dataset.
[0034] As used herein, “oblivious shuffling” is a technical term and may refer to the implementation or execution of a “shuffling” algorithm or operation that rearranges the order of at least some records (such as rows) or elements in a dataset or similar. This prevents the processor (such as a device or server running the algorithm) from linking the position of a record or element before shuffling to the position of the same record or element after shuffling. It should be understood that “oblivious shuffling” may be used to remove any links that the processor may have created with respect to a record at its position before oblivious shuffling.
[0035] In one embodiment, the "oblivious shuffling" algorithm or operation (1) receives a "permutation" as input (e.g., from party A), receives a dataset (or part thereof) as another input (e.g., from party B), and (2) shuffles or rearranges the input dataset (or part thereof) based on the arrangement defined by the input "permutation," but does not disclose any information regarding the "permutation" or actual contents of the dataset (or part thereof) to, for example, another party.
[0036] For a party providing an input "permutation" (e.g., Party A), the "oblivious shuffle" algorithm can generate a secret share (e.g., a first secret share) as an output to that party (e.g., Party A). For a party providing an input dataset (or part thereof) (e.g., Party B), the "oblivious shuffle" algorithm can generate another secret share (e.g., a second secret share) as an output to that party (e.g., Party B). In one embodiment, the first and second secret shares are additive shares. That is, by adding the first and second secret shares, a result representing the actual data can be produced. Therefore, the first and / or second secret shares can be generated using an additive homomorphic encryption algorithm, etc. As mentioned above, an additive homomorphic encryption or cryptographic system can refer to a form of encryption or cryptographic system that can compute the encryption of m1+m2 given only the public key and the encryption of messages m1 and m2. However, it is understood that the first and second secret shares can be generated using any suitable secret sharing algorithm.
[0037] In exemplary embodiments, “oblivious shuffling” may refer to a shuffling algorithm that uses homomorphic cryptography, Gurble circuits, and / or oblivious switching networks to perform the shuffling. For example, an “oblivious shuffling” algorithm may be a secret-sharing shuffling algorithm, an oblivious switching network algorithm, or any other suitable oblivious shuffling algorithm. It should be understood that Gurble circuits may refer to an encryption algorithm or protocol that enables two-party secure computation where two untrusted parties can jointly evaluate a function based on their private inputs without the presence of a trusted third party. For Gurble circuits and / or oblivious switching network algorithms or protocols, lost communications algorithms or protocols may be used. Also, with respect to encryption, lost communications algorithms or protocols may refer to an algorithm or protocol in which the sender transmits at least one of a potentially large number of pieces of information to the receiver, but remains unaware of, dissatisfied with, or does not know which information (if any) was transmitted.
[0038] The term "semi-honest" adversary, as used here, is a technical term and may refer to a party that, while adhering to the designated protocol, may attempt to corrupt one or more other parties. It is understood that a "semi-honest" party may be a corrupted party that is honestly executing the current protocol but may attempt to intercept and / or decode messages received by another party beyond the purposes intended by the protocol.
[0039] Figure 1 is a schematic diagram of an exemplary secure computing and communication system 100, arranged according to at least some embodiments described herein.
[0040] System 100 may include terminal devices 110, 120, 130, and 140, a network 160, and a server 150. It should be understood that Figure 1 shows only an exemplary number of terminal devices, networks, and servers. The embodiments described herein are not limited to the number of terminal devices, networks, and / or servers described herein. That is, the number of terminal devices, networks, and / or servers described herein are provided for illustrative purposes only and are not limiting.
[0041] According to at least some embodiments, terminal devices 110, 120, 130, and 140 may be various electronic devices. These various electronic devices include, but are not limited to, mobile devices such as smartphones, tablet computers, e-readers, laptop computers, and desktop computers, and / or other suitable electronic devices.
[0042] According to at least some embodiments, network 160 is a medium used to provide communication links between terminal devices 110, 120, 130, 140 and server 150. Network 160 can be the Internet, a local area network (LAN), a wide area network (WAN), a local interconnection network (LIN), a cloud, etc. Network 160 is implemented by various types of connections such as wired communication links, wireless communication links, and fiber optic cables.
[0043] According to at least some embodiments, server 150 may be a server that provides various services to users using one or more of the terminal devices 110, 120, 130, and 140. Server 150 may be implemented as a distributed server cluster including multiple servers, or as a single server.
[0044] A user (for example, Party A or Party B) may use one or more of the terminal devices 110, 120, 130, and 140 to communicate with the server 150 via the network 160. Various applications, such as social media applications and online shopping services, or their localized interfaces, may be installed on the terminal devices 110, 120, 130, and 140.
[0045] It should be understood that software applications or services in accordance with the embodiments and / or services provided by the service provider described herein may be executed by server 150 and / or terminal devices 110, 120, 130, and 140 (which may be referred to herein as user devices). Therefore, the devices for the software applications and / or services may be located within server 150 and / or terminal devices 110, 120, 130, and 140.
[0046] It is also understood that if the service is not performed remotely, system 100 may not include network 160 and may only include terminal devices 110, 120, 130, and 140 and / or server 150.
[0047] Furthermore, it is understood that each of the terminal devices 110, 120, 130, 140 and / or server 150 may include one or more processors, memory, and a storage device for storing one or more programs. Each of the terminal devices 110, 120, 130, 140 and / or server 150 may also include an Ethernet connector, a wireless fidelity receptor, and the like. When one or more programs are executed by one or more processors, they can cause one or more processors to perform the methods described in any embodiment described herein. It is also understood that, according to the embodiments described herein, a computer-readable non-volatile medium is provided. A computer program is stored on the computer-readable medium. When the computer program is executed by a processor, it is used to perform the methods described in any embodiment described herein.
[0048] Figure 2 is a flowchart illustrating an exemplary internal coupling processing flow 200 for private and secure computing and communication according to at least some embodiments described herein. Figure 4A shows the first part 400 of a schematic diagram illustrating an example of the processing flow 200 of Figure 2 according to at least some embodiments described herein. Figure 4B shows the second part 401 of a schematic diagram illustrating an example of the processing flow 200 of Figure 2 according to at least some embodiments described herein.
[0049] It is understood that the processing flow 200 disclosed herein can be executed by one or more processors (for example, one or more processors in terminal devices 110, 120, 130, and 140 in Figure 1, the processor in server 150 in Figure 1, the central processing unit 505 in Figure 5, and / or other suitable processors) unless otherwise specified.
[0050] It is also understood that the processing flow 200 may include one or more operations, actions, or functions, as indicated by one or more blocks 210, 220, 230, and 240. These various operations, functions, or actions may correspond, for example, to processor-executable software, program code, or program instructions that cause the execution of a function. Although shown as separate blocks, obvious modifications may be made, for example, by changing the order of two or more blocks, adding more blocks, splitting various blocks into additional blocks, combining them into fewer blocks, or deleting them, depending on the desired implementation. It is also understood that operations, including initialization, may be performed before the processing flow 200. For example, system parameters and / or application parameters may be initialized. The processing flow 200 may begin with block 210.
[0051] In block 210 (Shuffling and Transforming Datasets), the processor may provide a dataset for party A (e.g., 405A in Figure 4A) and / or a dataset for party B (e.g., 405B in Figure 4A). In one embodiment, the size of dataset 405A or 405B may include tens or hundreds of thousands of elements (or records, rows, etc.). It should be understood that the size of a dataset may refer to the number of elements (or records, rows, etc.) in the dataset. It should be understood that the size of dataset 405A may be significantly larger than the size of dataset 405B, and vice versa.
[0052] In one embodiment, dataset 405A includes multiple records (rows), each record containing a member name or user identifier (ID) and a time (T1) indicating the time (start time or timestamp, etc.) when, for example, a user (with a user ID) clicked a link on Party A's platform.
[0053] Dataset 405B contains multiple records (rows), each containing a member name or user identifier (ID), a time (T2) indicating the time (start time or timestamp, etc.) when the user (with the user ID) accessed Party B's website, and a value (value) indicating the user's value to Party B. In one embodiment, the time (or timestamp) is listed in minutes.
[0054] It should be understood that the format, content, and / or arrangement of datasets 405A and / or 405B described and illustrated herein are for illustrative purposes only and are not limiting. For example, each dataset 405A or 405B may have one or more IDs (columns) and / or one or more features or attributes (columns) associated with one or more IDs. In another exemplary embodiment, dataset 405A or 405B may have one or more IDs (columns) that do not have any features or attributes (columns) associated with one or more IDs.
[0055] In one embodiment, Party A and / or Party B may want to know, for example, (1) the number of users who clicked a link on Party A's platform (activating the link, opening the website, etc.), accessed Party B's website, and had a valuable interaction within a predetermined time frame; (2) the number of users who clicked a link on Party A's platform, accessed Party B's website within a certain time period (e.g., 70 minutes) after clicking the link on Party A's platform, and had a valuable interaction; and / or (3) the total number of all users who clicked a link on Party A's platform, accessed Party B's website within a certain time period (e.g., 70 minutes) after clicking the link on Party A's platform.
[0056] Party A and / or Party B may not want to expose data within dataset 405A and / or dataset 405B, and / or the common portion of dataset 405A and dataset 405B, to other parties.
[0057] In block 210, the processor of each device may also shuffle dataset 405A (for example, by randomly rearranging it) to obtain or generate dataset 410A for party A, or shuffle dataset 405B to obtain or generate dataset 410B for party B.
[0058] The processor can also transform the ID(column) of dataset 410A using a transformation scheme for party A.
[0059] The function or operation of "transforming" a dataset or part thereof, such as one or more columns (or rows) of a dataset, such as one or more identification fields / columns (or records / rows), is understood to mean processing (e.g., encrypting, decrypting, encoding, decoding, manipulating, compressing, decompressing, converting, etc.) a dataset or part thereof from one format to another. It is also understood that "transformation scheme" may mean an algorithm, protocol, or function that processes (e.g., encrypting, decrypting, encoding, decoding, manipulating, compressing, decompressing, converting, etc.) a dataset or part thereof from one format to another. In one embodiment, the processor may, for example, based on the ECDH algorithm or protocol (represented by function D0(.)), use Party A's key to encrypt (or decrypt, encode, decode, manipulate, compress, decompress, convert, etc.) the ID of dataset 410A into an encrypted (or decrypted, encoded, decode, manipulate, compress, decompressing, convert, etc.) format.
[0060] The processor may also transform the IDs in dataset 410B using a transformation scheme for party B. In one embodiment, the processor may encrypt (or decrypt, encode, decode, manipulate, compress, decompress, convert, etc.) the IDs in dataset 410B using the key of party B, for example, based on the ECDH algorithm or protocol (represented by function D1(.)), into an encrypted (or decrypt, encode, decode, manipulate, compress, decompress, convert, etc.) format. In one embodiment, the T1 (column) of dataset 410A and / or the T2 (column) and values (column) of dataset 410B may not be transformed.
[0061] In block 210, it should be understood that for party A and / or party B, the sequences of dataset transformation and dataset shuffling may be switched or modified without affecting the purpose of the resulting dataset. For example, the processor may transform dataset 405A to obtain or generate party A's dataset 410A, and then shuffle dataset 410A. The processor may also transform dataset 405B to obtain or generate party B's dataset 410B, and then shuffle dataset 410B. Processing may proceed from block 210 to block 220.
[0062] In block 220 (Dataset Exchange, Shuffle, and Transformation), the processor of each device may exchange the ID field of dataset 410A with the ID field of dataset 410B between Party A and Party B. For Party A, the processor dispatches or sends the ID field of dataset 410A to Party B and receives or acquires the ID field of dataset 410B from Party B as dataset 415A (see Figure 4A). For Party B, the processor dispatches or sends the ID field of dataset 410B to Party A and receives or acquires the ID field of dataset 410A from Party A as dataset 415B (see Figure 4A). Because the ID fields of dataset 410A and dataset 410B are transformed (encoded, etc.), the corresponding receiving party may not know the actual data / IDs in the received dataset, and the received dataset may contain only the ID field, without feature or attribute fields.
[0063] The processor may also shuffle Party A's dataset 415A to obtain or generate dataset 420A, and / or shuffle Party B's dataset 415B to obtain or generate dataset 420B.
[0064] The processor can further transform the IDs of dataset 420A using a transformation scheme for party A. In one embodiment, the processor can encrypt (or decrypt, encode, decode, manipulate, compress, decompress, convert, etc.) the IDs of dataset 420A using party A's key based on an ECDH algorithm or protocol (represented by function D0(.)). The processor can further transform the IDs of dataset 420B using a transformation scheme for party B. In one embodiment, the processor can encrypt (or decrypt, encode, decode, manipulate, compress, decompress, convert, etc.) the IDs of dataset 420B using party B's key based on an ECDH algorithm or protocol (represented by function D1(.)).
[0065] In block 220, it should be understood that for party A and / or party B, the sequence of dataset ID transformation and dataset shuffling may be switched or modified without affecting the purpose of the resulting dataset. For example, the processor transforms dataset 415A to obtain or generate party A's dataset 420A, and then shuffles dataset 420A. The processor also transforms dataset 415B to obtain or generate party B's dataset 420B, and then shuffles dataset 420B. Processing may proceed from block 220 to block 230.
[0066] In block 230 (exchange and match), the processor of each device can exchange dataset 420A for dataset 420B between Party A and Party B. If Party A is involved, the processor can dispatch or send dataset 420A to Party B and receive or acquire dataset 420B from Party B. If Party B is involved, the processor can dispatch or send dataset 420B to Party A and receive or acquire dataset 420A from Party A.
[0067] The processor may also search for matches (or perform an inner join operation, etc.) between dataset 420A and the received dataset 420B to obtain or generate a first intersection of party A (referring to a shaded record or element in dataset 425A in Figure 4B, which is identical to dataset 420A, not shown). It should be understood that the above operation involves adding or appending the record (or row) from dataset 420A containing the matched identifier to the first intersection for each identifier in the received dataset 420B that matches an identifier in dataset 420A.
[0068] The processor may also search for matches (or perform an inner join operation, etc.) between dataset 420B and the received dataset 420A to obtain or generate a second intersection of party B (referring to a shaded record or element in dataset 425B in Figure 4B, which is identical to dataset 420B, not shown). It should be understood that the above operation involves adding or appending the record (or row) from dataset 420B containing the matched identifier to the second intersection for each identifier in the received dataset 420A that matches an identifier in dataset 420B.
[0069] In the case of Party A, the data in the first intersection (such as IDs) is transformed (encoded, etc.) by Party B (through D1(.)), so it is understood that Party A cannot know the actual data in the first intersection. In the case of Party B, the data in the second intersection is also transformed (encoded, etc.) by Party A (through D0(.)), so Party B cannot know the actual data in the second intersection. In other words, as described above, the matching or inner join operation performed is a private matching or inner join operation. The processor performs private identity matching without revealing the actual data in the intersection of the two parties' datasets. Processing may proceed from block 230 to block 240.
[0070] In block 240 (performing oblivious shuffling), the processor can perform the oblivious shuffling algorithm (steps described in detail below) by, for example, using inputs from Party A and Party B and / or by outputting a secret share to Party A and Party B.
[0071] In one embodiment, the processor receives or obtains a permutation provided by party A as a first input, and features or attributes (of the dataset) provided by party B as a second input. For example, the permutation from party A is an arrangement of a sequence of records or elements of the dataset (e.g., dataset 425A or 420A), and after the arrangement of the sequence, the records or elements of the first intersection (the same as the shadowed records or elements in dataset 425A, see also the description in block 230) are placed at the top of the arranged / rearranged dataset. For example, considering the shadowed records or elements in dataset 425A, the permutation would include arrangements such as "swap the third record / row with the fourth record / row" or "move the fourth record between the first and second records," resulting in the records or elements of the first intersection (the same as the shadowed records or elements in dataset 425A) becoming the top or front record or element in the rearranged dataset.
[0072] In one embodiment, the permutation also includes sorting the top or front record or element of the first intersection in the rearranged dataset (e.g., in descending or ascending order). Since Party A knows the location of the record or element in the first intersection (e.g., row number), it should be understood that in an embodiment, Party A can provide an injective function based on the location and record or element of the first intersection as input to the "oblivious shuffling" algorithm, instead of providing the permutation. The features or attributes from Party B may be features or attributes (T2 and values) from dataset 410B.
[0073] In one embodiment, the processor may shuffle or rearrange the features or attributes (T2 and values) of dataset 410B using permutations from party A (e.g., "switch the third and fourth records," "move the fourth record between the first and second records"), so that the sequence or order of the rows of features or attributes in dataset 410B is arranged according to or based on the permutation input from party A. Oblivious shuffling is understood to shuffle or rearrange the features or attributes (T2 and values) from party B's dataset 410B using permutations from party A without leaking information about the input permutations or actual contents of the input dataset (or part thereof), for example, from each other. That is, party B may not know the permutations from party A (i.e., party B may not know how the features or attributes of dataset 410B are rearranged), and party A may not know the actual features or attributes of dataset 410B (before and after rearrangement).
[0074] In one embodiment, to achieve "oblivious" shuffling, features or attributes (T2 and values) from Party B's dataset 410B are shuffled using permutations from Party A, and then a secret share is generated based on the shuffled features or attributes. For example, the processor can generate a secret share (e.g., a first secret share) as output to Party A and another secret share (e.g., a second secret share) as output to Party B. That is, Party A may receive or obtain the first secret share but not know the actual content of the final result (and therefore may not know the actual features or attributes of dataset 410B). Party B may receive or obtain the second secret share but not know the actual content of the final result (and therefore may not know the permutations (from Party A) used in the shuffling).
[0075] In one embodiment, the first secret share and the second secret share may be additive shares. That is, the final result representing the actual data may be generated by adding the first secret share and the second secret share. Therefore, the first secret share and / or the second secret share may be generated using an additive homomorphic encryption algorithm or the like. It is understood that the first secret share and the second secret share can be generated using any suitable secret sharing algorithm.
[0076] For example, after shuffling features or attributes (T2 and values) from Party B's dataset 410B using permutations from Party A, the processor generates a corresponding mask for each element (i.e., each attribute or feature) in the shuffled dataset and uses a masking scheme to mask the element (i.e., attribute or feature) with the corresponding mask. In one embodiment, each mask is a random number or random plain text. For example, as shown in Figure 4B, the processor can generate a mask ("50_share0") for the T2 data (50) in dataset 410B, or a mask ("87_share0") for the value data (87) in dataset 410B. The processor can also, for example, use an additive or subtractive scheme to mask the T2 data (50) in dataset 410B with its mask ("50_share0") (e.g., subtract the mask 50_share0 from data 50 to get "50-50_share0"), or use an additive or subtractive scheme to mask the value data (87) in dataset 410B with its mask ("87_share0") (e.g., subtract the mask 87_share0 from data 87 to get "87-87_share0").
[0077] In one embodiment, the processor can output all masks (e.g., 50_share0, 87_share0, etc.) to Party A as a dataset containing Party A's secret share (features or attributes shuffled from Party B's dataset 410B using permutations from Party A), and all masked data (e.g., 50-50_share0, 87-87_share0, etc.) to Party B as a dataset containing Party B's secret share (features or attributes shuffled from Party B's dataset 410B using permutations from Party A). Assuming the size of the first or second intersection (i.e., the number of records / rows, etc.) is N, it should be understood that both Party A and Party B may retrieve the previous N records / rows of the corresponding dataset. For example, as shown in Figure 4B, the size of the first intersection is 3 (see the shaded records of dataset 425A), and Party A can retrieve the previous 3 records / rows of the corresponding dataset (from the processor) to generate dataset 435A. Since Party A provides a permutation as input (and therefore Party A is also aware of the placement of the ID fields), please understand that dataset 435A may contain the ID fields of the first intersection. Party B can then generate dataset 430B by taking the previous three records / rows from the corresponding dataset (from the processor).
[0078] In another exemplary embodiment, assuming the size of the first or second intersection (i.e., the number of records / rows) is N, the processor can output to Party A the N rows prior to the mask (e.g., 50_share0, 87_share0, etc.) as a dataset containing Party A's secret share (features or attributes shuffled from Party B's dataset 410B using permutations from Party A), and to Party B the N rows prior to the masked data (e.g., 50-50_share0, 87-87_share0, etc.) as a dataset containing Party B's secret share (features or attributes shuffled from Party B's dataset 410B using permutations from Party A). In such embodiments, instead of providing permutations as input, Party A provides an injective function based on the first intersection as input to the “oblivious shuffling” algorithm, thereby reducing the amount of data transferred or used by the oblivious shuffling algorithm.
[0079] In dataset 435A, all values in the T2 and Value fields are masks (random numbers or random plaintext, e.g., 50_share0, 87_share0, etc.), so party A may not know the actual values of the contents of the T2 and Value fields. Similarly, in dataset 430B, all values in the T2 and Value fields are data (features or attributes) masked by the mask (and therefore the values are also random numbers or random plaintext, e.g., 50-50_share0, 87-87_share0, etc.), so party B may not know the actual values of the contents of the T2 and Value fields. In other words, party B may not know the permutations from party A (i.e., party B may not know how the features or attributes of dataset 410B are sorted), and party A may not know the features or attributes of dataset 410B (before and after sorting), so shuffling features or attributes (T2 and Value) from dataset 410B for party B using the permutations from party A becomes an "oblivious" shuffling when the output or result of the algorithm is a secret share.
[0080] It is also important to understand that in dataset 435A, the ID field is transformed (e.g., encrypted) using, for example, the key of party A and the key of party B (e.g., D0(D1(5)), which may be the same as D1(D0(5)) based on, for example, ECDH), so neither party A nor party B knows the actual value of the ID ("5"). In other words, dataset 435A contains party A's secret share, and dataset 430B contains party B's secret share.
[0081] Similarly, the processor may receive or obtain permutations provided by party B as a first input, and features or attributes (of the dataset) provided by party A as a second input. For example, a permutation from party B is an arrangement of a sequence of records or elements in the dataset (e.g., dataset 425B or 420B), and after the arrangement of the sequence, the records or elements of the second intersection (the same as the shadowed records or elements in dataset 425B, see also the description in block 230) are placed on top of the arranged / rearranged dataset. For example, considering the shadowed records or elements in dataset 425B, the permutations may include arrangements such as "swap the third record / row with the fourth record / row" or "move the fourth record before the first record," resulting in the records or elements of the second intersection (the same as the shadowed records or elements in dataset 425B) becoming the top or front record or element in the rearranged dataset. In one embodiment, the permutation may also include sorting the records or elements of the second intersection of the rearranged dataset (for example, in descending or ascending order). The features or attributes from party A may be features or attributes (T1) from dataset 410A.
[0082] Similarly, the processor can use the “oblivious shuffling” algorithm described above to generate a dataset containing Party A’s secret share and a dataset containing Party B’s secret share. Assuming the size of the second intersection (i.e., the number of records / rows) is N, both Party A and Party B can take the previous N records / rows from their corresponding datasets to generate Party A’s dataset 430A and Party B’s dataset 435B. In other words, in one embodiment, the oblivious shuffling process for Party A and the oblivious shuffling process for Party B may be symmetrical.
[0083] In processing flow 200, the features or attributes of the dataset (such as 405A and / or 450B) are not transformed (e.g., encrypted), exchanged with other parties, and / or transferred to generate a common part (e.g., until processing block 230 and block 240). Therefore, it should be understood that the complexity of communication and computation may be significantly reduced compared to existing algorithms.
[0084] Figure 3 is a flowchart illustrating an exemplary secret sharing processing flow 300 for private secure computation and communication, according to at least some embodiments described herein. Figure 4C shows a third part 402 of a schematic diagram illustrating an example of the processing flow 300 of Figure 3, according to at least some embodiments described herein. It should be understood that Figure 4B may also show a portion of the schematic diagram illustrating an example of the processing flow 300 of Figure 3.
[0085] It is understood that the processing flow 300 disclosed herein can be executed by one or more processors (for example, one or more processors in terminal devices 110, 120, 130, and 140 in Figure 1, the processor in server 150 in Figure 1, the central processing unit 505 in Figure 5, and / or other suitable processors) unless otherwise specified.
[0086] It is also understood that the processing flow 300 may include one or more operations, actions, or functions, as shown in one or more of blocks 310, 320, and 330. These various operations, functions, or actions may correspond, for example, to processor-executable software, program code, or program instructions that cause the execution of a function. Although shown as individual blocks, a desirable implementation may make obvious changes, for example, by changing the order of two or more blocks, adding more blocks, splitting various blocks into additional blocks, combining them into fewer blocks, or deleting them. It is also understood that operations such as initialization may be performed before the processing flow 300. For example, system parameters and / or application parameters may be initialized from the results of block 240 in Figure 2. The processing flow 300 may begin with block 310.
[0087] In block 310 (Constructing Shares), the processor can combine (for example, perform a join operation) parts of the secret share (such as dataset 430A and dataset 435A) to construct Party A's secret share (dataset 440A). The processor can also combine (for example, perform a join operation) parts of the secret share (such as dataset 430B and dataset 435B) to construct Party B's secret share (dataset 440B). Processing may then proceed from block 310 to block 320.
[0088] In block 320 (performing a confidential MPC), the processor of each device can perform a confidential multiparty computation (see description below) based on Party A's secret share, or a confidential multiparty computation (see description below) based on Party B's secret share.
[0089] In one embodiment, the processor can obtain or generate a dataset 445A for party A by subtracting T1 from T2 for dataset 440A, and / or obtain or generate a dataset 445B for party B by subtracting T1 from T2 for dataset 440B.
[0090] In one embodiment, the processor can determine whether T2 is greater than 0 and less than a predetermined value in the dataset 445A, and then acquire or generate the dataset 450A for party A. If T2 is greater than 0 and less than the predetermined value, the processor can set the value of T2 in the dataset 450A, which is a random number for party A, to 1 (representing "true") for the secret share. If T2 is not greater than 0 or less than or equal to the predetermined value, the processor can set the value of T2 in the dataset 450A, which is a random number for party A, to 0 (representing "false") for the secret share.
[0091] In one embodiment, the processor can determine whether T2 is greater than 0 and less than a predetermined value in dataset 445B, and then obtain or generate dataset 450B for party B. If T2 is greater than 0 and less than the predetermined value, the processor can set the value of T2 in dataset 450B, which is a random number for party B, to 1 (representing "true") for the secret share. If T2 is not greater than 0 or less than or equal to the predetermined value, the processor can set the value of T2 in dataset 450B, which is a random number for party B, to 0 (representing "false") for the secret share.
[0092] In one embodiment, the processor may also generate dataset 455A for party A by multiplying the corresponding T2 value in dataset 450A and storing the result in the value field of dataset 455A. The processor may also generate dataset 455B for party B by multiplying the corresponding T2 value in dataset 450B and storing the result in the value field of dataset 455B. It should be understood that multiplying a secret share of 1 by any value V results in the same value V. Multiplying a secret share of 0 by any value V results in a secret share of 0.
[0093] In one embodiment, the processor can further sum the values of dataset 455A and store or save the result in the value field of dataset 460A to generate dataset 460A for party A. The processor can further sum the values of dataset 455B and store or save the result in the value field of dataset 460B to generate dataset 460B for party B. It should be understood that adding 0 to any value V results in the same value V.
[0094] Here, it is understood that Party A owns a dataset 460A (secret share) that represents the total number of users who clicked on links on Party A's platform and then accessed Party B's website and performed a valuable interaction within a certain period (e.g., 70 minutes) after clicking on those links. It is also understood that, because the secret share is a random value, Party A does not know the data in dataset 460A.
[0095] Here, it is understood that Party B owns a dataset 460B (secret share) that represents the total value of all users who clicked on a link on Party A's platform and then accessed Party B's website and performed a valuable interaction within a certain period (e.g., 70 minutes) after clicking the link on Party A's platform. It is also understood that Party B does not know the data in dataset 460B because the secret share is a random value. Processing may proceed from block 320 to block 330.
[0096] In block 330 (Construction of Results), the processor of each device can exchange dataset 460A for dataset 460B between Party A and Party B. In the case of Party A, the processor can dispatch or send dataset 460A to Party B and / or receive or acquire dataset 460B from Party B. The processor can also construct a result ("121") by adding the data of dataset 460A to the data of the received dataset 460B. That is, the sum of all users who clicked a link etc. on Party A's platform, and then accessed Party B's website within a certain period (e.g., within 70 minutes) after clicking the link etc. on Party A's platform and performed a valuable interaction is "121".
[0097] In the case of Party B, the processor can dispatch or send dataset 460B to Party A and / or receive or retrieve dataset 460A from Party A. The processor can also construct the result ("121") by adding the data from dataset 460B and the data from the received dataset 460A. That is, the sum of all users who clicked a link on Party A's platform, and then accessed Party B's website and performed a valuable interaction within a certain period (e.g., 70 minutes) after clicking the link on Party A's platform is "121", which is the same result as determined by Party A.
[0098] It is understood that other results can be constructed or determined by combining secret shares (440A and 440B), secret shares (445A and 445B), secret shares (450A and 450B), secret shares (455A and 455B), etc. For example, the value of column T2 in dataset 445A and / or 445B can be constructed or determined by combining T2 from secret shares 445A and 445B, and the constructed or determined result can be used to determine the corresponding value of T2 in dataset 450A and / or 450B. It is also understood that other results can be further constructed or determined by performing other MPC calculations on the secret shares to obtain the secret shares of Party A and Party B, and then combining the secret shares of both Party A and Party B.
[0099] Figure 5 is a schematic diagram of an exemplary computer system 500 applicable to implementing an electronic device (e.g., one of the server or terminal devices shown in Figure 1) arranged according to at least some embodiments described herein. It should be understood that the computer system shown in Figure 5 is provided for illustrative purposes only and does not limit the functions and uses of the embodiments described herein.
[0100] As shown in the diagram, the computer system 500 may include a central processing unit (CPU) 505. The CPU 505 performs various operations and processes based on programs stored in read-only memory (ROM) 510 or programs loaded from storage device 540 into random access memory (RAM) 515. RAM 515 also stores various data and programs necessary for the operation of system 500. The CPU 505, ROM 510, and RAM 515 are interconnected via bus 520. An input / output (I / O) interface 525 is also connected to bus 520.
[0101] Components connected to the I / O interface 525 may further include input devices 530 such as keyboards, mice, digital pens, and drawing pads; output devices 535 such as displays like liquid crystal displays (LCDs) and speakers; storage devices 540 such as hard disks; and communication devices 545 such as LAN cards and modems. The communication device 545 can perform communication processing via networks such as the Internet, WAN, LAN, LIN, and cloud. In one embodiment, a driver 550 may also be connected to the I / O interface 525. Removable media 555 such as magnetic disks, optical disks, magneto-optical disks, and semiconductor memory may be attached to the driver 550 as needed, and computer programs read from the removable media 555 may be installed on the storage device 540.
[0102] It is understood that the processes described with reference to the flowcharts in Figures 2 and 3 and / or other figures can be implemented as computer software programs or in hardware. A computer program product includes a computer program stored on a computer-readable non-volatile medium. The computer program includes program code for performing the methods shown in the flowcharts and / or GUIs. In this embodiment, the computer program is downloaded and installed from a network via a communication device 545 and / or installed from removable media 555. When executed by a central processing unit (CPU) 505, the computer program can perform the functions specified in the methods of the embodiments disclosed herein.
[0103] Tests and / or analyses have shown that, compared to existing algorithms, protocols, or systems, the features of the embodiments disclosed herein may improve efficiency, reduce the number of transformation actions or steps (e.g., homomorphic encryption, decryption, addition, exchange, and transmission), and alleviate communication and computational complexity.
[0104] It is understood that the disclosed and other solutions, examples, embodiments, modules, and functional operations described herein can be implemented in digital electronic circuits, computer software, firmware, or hardware, or one or more combinations thereof, including the structures disclosed herein and their structural equivalents. The disclosed and other embodiments can be implemented as one or more computer program products, i.e., modules of computer program instructions that are executed by or encoded on a computer-readable medium to control the operation of a data processing device. The computer-readable medium may be a machine-readable storage device, a machine-readable storage substrate, a memory device, a composition of material that provides machine-readable propagated signals, or one or more combinations thereof. The term “data processing device” encompasses all devices, machines, and equipment that process data, including, for example, a programmable processor, a computer, or multiple processors or computers. In addition to hardware, an equipment may include code that creates an environment for the execution of computer programs, such as code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or one or more combinations thereof.
[0105] Computer programs (also called programs, software, software applications, scripts, or code) can be written in any form of programming language, including compiled and interpreted languages, and can be deployed in any form, as standalone programs or as modules, components, subroutines, or other units suitable for use in a computing environment. Computer programs do not necessarily correspond to files in a file system. A program can be part of a file that holds other programs or data (such as one or more scripts stored in a markup language document), a single file dedicated to the program, or multiple coordinated files (such as a file containing one or more modules, subprograms, or parts of code). Computer programs can be deployed to run on a single computer, or to run on multiple computers located in one site or distributed across multiple sites and interconnected by a communication network.
[0106] The processes and logic flows described in this document are executed by one or more programmable processors, and one or more computer programs are executed to perform operations on input data and produce outputs. The processes and logic flows can also be executed by special-purpose logic circuits, such as field-programmable gate arrays and application-specific integrated circuits, or the devices can be implemented as special-purpose logic circuits.
[0107] Processors suitable for executing computer programs include, for example, both general-purpose and dedicated microprocessors, and one or more processors in any type of digital computer. Generally, a processor receives instructions and data from read-only memory or random-access memory, or both. Essential elements of a computer are a processor that executes instructions and one or more memory devices that store instructions and data. Generally, a computer also includes one or more mass storage devices that store data, such as magnetic disks, magneto-optical disks, or optical disks, or is operationally coupled to receive data from or transfer data to such storage devices, or both. However, a computer is not required to have such devices. Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices. These include, for example, semiconductor memory devices such as erasable programmable read-only memory, electrically erasable programmable read-only memory, and flash memory devices, magnetic disks such as internal hard disks or removable disks, magneto-optical disks, and compact disk read-only memory and digital video disc read-only memory disks. The processor and memory are complemented by or integrated into dedicated logic circuits.
[0108] It should be understood that different features, variations, and multiple different embodiments are described in various details. Any descriptions made in this application regarding specific embodiments are for illustrative purposes only and are not intended to limit or suggest that the invention is limited to one specific embodiment or only one specific embodiment. It should be understood that this disclosure is not limited to a single specific embodiment or the listed variations. A person skilled in the art will conceive of many modifications, variations, and other embodiments, which are intended and indeed covered by this disclosure. In fact, the scope of this disclosure is intended to be determined by the appropriate legal interpretation and construction of this disclosure, including its equivalents, as understood by a person skilled in the art relying on the complete disclosure existing at the time of filing. manner
[0109] It is understood that all of these configurations can be combined with one another.
[0110] Embodiment 1 is a method for secure computation and communication, the method comprising: translating identifiers of a first dataset using a translation scheme; dispatching the translated identifiers of the first dataset; receiving identifiers of a second dataset; translating identifiers of the second dataset; dispatching the translated identifiers of the second dataset; receiving a pair of identifiers; generating a first intersection of the received pair of identifiers and the translated identifiers of the second dataset; determining a first permutation based on the first intersection; performing a first oblivious shuffling based on the first permutation and a pair of attributes to generate a first share, wherein the size of the first share is the same as the size of the first intersection; receiving a second share; and constructing a first result based on the first and second shares.
[0111] Embodiment 2 further includes, in the method of Embodiment 1, the steps of shuffling the first dataset before dispatching the transformed identifier of the first dataset, and shuffling the second dataset before dispatching the transformed identifier of the second dataset.
[0112] Embodiment 3 further includes the step of manipulating the first share before constructing the first result, in the method of Embodiment 1 or 2.
[0113] Embodiment 4 is a method in any one of Embodiments 1 to 3 in which the step of generating a first share by performing a first oblivious shuffling based on a first permutation and a set of attributes includes the steps of generating a first part of the first share based on the first permutation and a set of attributes, generating a second part of the first share, and generating a first share based on the first part of the first share and the second part of the first share.
[0114] Embodiment 5 further includes the step of performing a second oblivious shuffling based on the second permutation and the attributes of the first dataset, thereby generating a second portion of the first share, in the method of Embodiment 4.
[0115] Embodiment 6 further includes the step of determining a random exponent for the transformation scheme in any one of Embodiments 1 to 5.
[0116] Embodiment 7, in the method of Embodiment 6, the step of transforming identifiers of the first dataset using a transformation scheme includes the steps of mapping identifiers of the first dataset to an elliptic curve and applying a power to the mapped identifiers using a random exponent.
[0117] Embodiment 8 is a method for secure computation and communication, the method comprising: translating identifiers of a first dataset using a translation scheme; dispatching the translated identifiers of the first dataset; receiving identifiers of a second dataset; translating identifiers of the second dataset; dispatching the translated identifiers of the second dataset; receiving a pair of identifiers; generating a first intersection of the received pair of identifiers and the translated identifiers of the second dataset; performing a first oblivious shuffling based on a first permutation and the attributes of the first dataset to generate a first share, wherein the size of the first share is the same as the size of the first intersection; receiving a second share; and constructing a first result based on the first and second shares.
[0118] Embodiment 9 further includes, in the method of Embodiment 8, the steps of shuffling the first dataset before dispatching the transformed identifier of the first dataset, and shuffling the second dataset before dispatching the transformed identifier of the second dataset.
[0119] Embodiment 10 further includes the step of manipulating the first share before constructing the first result, in the method of Embodiment 8 or 9.
[0120] Embodiment 11 is a method among embodiments 8 to 10 in which the step of generating a first share by performing a first oblivious shuffling based on the attributes of a first permutation and a first dataset includes the steps of generating a first part of the first share based on the attributes of the first permutation and a first dataset, generating a second part of the first share, and generating a first share based on the first part of the first share and the second part of the first share.
[0121] Embodiment 12 further includes, in the method of Embodiment 11, the steps of determining a second permutation based on a first common part, and performing a second oblivious shuffling based on the second permutation and a set of attributes to generate a second part of the first share.
[0122] Embodiment 13 further includes the step of determining a random exponent for the transformation scheme in any one of the methods of Embodiments 8 to 12.
[0123] Embodiment 14 further includes, in the method of Embodiment 13, the step of transforming identifiers of the first dataset using a transformation scheme, the steps of mapping identifiers of the first dataset to elliptic curves, and applying a power to the mapped identifiers using random exponents.
[0124] Embodiment 15 is a non-temporary computer-readable medium storing a computer-executable instruction, the computer-executable instruction, when executed by one or more processors, causes one or more processors to perform an operation including: translating identifiers of a first dataset using a translation scheme; dispatching the translated identifiers of the first dataset; receiving identifiers of a second dataset; translating identifiers of the second dataset; dispatching the translated identifiers of the second dataset; receiving a set of identifiers; generating a first intersection of the received set of identifiers and the translated identifiers of the second dataset; determining a first permutation based on the first intersection; performing a first oblivious shuffling based on the first permutation and a set of attributes to generate a first share, wherein the size of the first share is the same as the size of the first intersection; receiving a second share; and constructing a first result based on the first and second shares.
[0125] Embodiment 16, in the computer-readable medium of Embodiment 15, further includes the steps of shuffling the first dataset before dispatching the transformed identifier of the first dataset, and shuffling the second dataset before dispatching the transformed identifier of the second dataset.
[0126] Embodiment 17, in the computer-readable medium of Embodiment 15 or 16, further includes the step of manipulating a first share before constructing a first result.
[0127] Embodiment 18 provides a computer-readable medium from any one of Embodiments 15 to 17, wherein the step of generating a first share by performing a first oblivious shuffling based on a first permutation and a set of attributes includes the steps of generating a first portion of the first share based on the first permutation and a set of attributes, generating a second portion of the first share, and generating a first share based on the first portion of the first share and the second portion of the first share.
[0128] Embodiment 19, in a computer-readable medium of Embodiment 18, further includes the step of performing a second oblivious shuffling based on a second permutation and the attributes of the first dataset to generate a second portion of the first share.
[0129] Embodiment 20, in any one of embodiments 15 to 19 on a computer-readable medium, the operation further includes the step of determining a random exponent of a transformation scheme, the step of transforming identifiers of a first dataset using the transformation scheme includes the steps of mapping identifiers of the first dataset to an elliptic curve, and applying a power to the mapped identifiers using a random exponent.
[0130] The terms used herein are intended to describe, and not limit, specific embodiments. Technical terms include plural forms unless otherwise specified. The terms “includes” and / or “compose” as used herein specify the presence of the features, integers, steps, operations, elements, and / or components described herein, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, and / or components.
[0131] It should be understood that, with respect to the description in the preamble, particularly with respect to the constituent materials used, the shape, size, and arrangement of the components, modifications can be made in detail without departing from the scope of the present invention. This specification and the embodiments described herein are for illustrative purposes only, and the true scope and spirit of this disclosure are shown by the following claims.
Claims
1. A method for secure computation and communication, the method is The steps include: transforming the identifiers of the first dataset using a transformation scheme, The steps include dispatching the transformed identifier of the first dataset, The steps include receiving the identifier of the second dataset, The steps include: converting the identifier of the second dataset, The steps include dispatching the transformed identifier of the second dataset, A step of receiving a set of identifiers, A step of generating a first intersection between a set of received identifiers and the transformed identifiers of the second dataset, The steps include determining the first permutation based on the first intersection, A step of performing a first oblivious shuffling based on the first permutation and a set of attributes to generate a first share, wherein the size of the first share is the same as the size of the first intersection, The steps include receiving the second share, The steps include constructing a first result based on the first share and the second share, method.
2. Before dispatching the transformed identifier of the first dataset, the first dataset is shuffled, The process further includes the step of shuffling the second dataset before dispatching the transformed identifier of the second dataset, The method according to claim 1.
3. The first result is further comprised of the step of manipulating the first share, The method according to claim 1.
4. The step of generating a first share by performing a first oblivious shuffling based on the first permutation and the set of attributes is: A step of generating a first portion of the first share based on the first permutation and the set of attributes, The steps include generating the second portion of the first share, The process includes the step of generating the first share based on the first portion of the first share and the second portion of the first share, The method according to claim 1.
5. The further step includes performing a second oblivious shuffling based on a second permutation and the attributes of the first dataset to generate the second portion of the first share. The method according to claim 4.
6. The step further includes determining a random exponent for the transformation scheme, The method according to claim 1.
7. The step of transforming the identifier of the first dataset using the transformation scheme is: The steps include mapping identifiers of the first dataset to elliptic curves, The steps include: applying a power to a mapped identifier using the aforementioned random exponent; The method according to claim 6.
8. A method for secure computation and communication, the method is The steps include: transforming the identifiers of the first dataset using a transformation scheme, The steps include dispatching the transformed identifier of the first dataset, The steps include receiving the identifier of the second dataset, The steps include: converting the identifier of the second dataset, The steps include dispatching the transformed identifier of the second dataset, A step of receiving a set of identifiers, A step of generating a first intersection between a set of received identifiers and the transformed identifiers of the second dataset, A step of generating a first share by performing a first oblivious shuffling based on a first permutation and the attributes of the first dataset, wherein the size of the first share is the same as the size of the first intersection, The steps include receiving the second share, The steps include constructing a first result based on the first share and the second share, method.
9. Before dispatching the transformed identifier of the first dataset, the first dataset is shuffled, The process further includes the step of shuffling the second dataset before dispatching the transformed identifier of the second dataset, The method according to claim 8.
10. The first result is further comprised of the step of manipulating the first share, The method according to claim 8.
11. The step of generating the first share by performing a first oblivious shuffling based on the first permutation and the attributes of the first dataset is: A step of generating a first portion of the first share based on the attributes of the first permutation and the first dataset, The steps include generating the second portion of the first share, The process includes the step of generating the first share based on the first portion of the first share and the second portion of the first share, The method according to claim 8.
12. The steps include determining the second permutation based on the first intersection, The process further includes the step of performing a second oblivious shuffling based on the second permutation and a set of attributes to generate the second portion of the first share, The method according to claim 11.
13. The step further includes determining a random exponent for the transformation scheme, The method according to claim 8.
14. The step of transforming the identifier of the first dataset using the aforementioned transformation scheme is: The steps include mapping identifiers of the first dataset to elliptic curves, The further step includes applying a power to a mapped identifier using the aforementioned random exponent, The method according to claim 13.
15. A non-temporary, computer-readable medium on which computer executable instructions are stored, When the aforementioned computer executable instruction is executed by one or more processors, the one or more processors will: The steps include: transforming the identifiers of the first dataset using a transformation scheme, The steps include dispatching the transformed identifier of the first dataset, The steps include receiving the identifier of the second dataset, The steps include: converting the identifier of the second dataset, The steps include dispatching the transformed identifier of the second dataset, A step of receiving a set of identifiers, A step of generating a first intersection between a set of received identifiers and the transformed identifiers of the second dataset, The steps include determining the first permutation based on the first intersection, A step of performing a first oblivious shuffling based on the first permutation and a set of attributes to generate a first share, wherein the size of the first share is the same as the size of the first intersection, The steps include receiving the second share, Perform an operation that includes the step of constructing a first result based on the first share and the second share, A non-temporary, computer-readable medium.
16. The aforementioned operation is, Before dispatching the transformed identifier of the first dataset, the first dataset is shuffled, The process further includes the step of shuffling the second dataset before dispatching the transformed identifier of the second dataset, A non-temporary computer-readable medium as described in claim 15.
17. The aforementioned operation is, The first result is further comprised of the step of manipulating the first share, A non-temporary computer-readable medium as described in claim 15.
18. The step of generating a first share by performing a first oblivious shuffling based on the first permutation and a set of attributes is: A step of generating a first portion of the first share based on the first permutation and the set of attributes, The steps include generating the second portion of the first share, The process includes the step of generating the first share based on the first portion of the first share and the second portion of the first share, A non-temporary computer-readable medium as described in claim 15.
19. The aforementioned operation is, The process further includes the step of performing a second oblivious shuffling based on a second permutation and the attributes of the first dataset to generate a second portion of the first share. A non-temporary computer-readable medium according to claim 18.
20. The aforementioned operation is, The process further includes the step of determining the random exponent of the transformation scheme, The step of transforming the identifier of the first dataset using the transformation scheme is: The steps include mapping identifiers of the first dataset to elliptic curves, The steps include: applying a power to a mapped identifier using the aforementioned random exponent; A non-temporary computer-readable medium as described in claim 15.