Systems and methods for encrypting data and algorithms - Patents.com

By dividing and encrypting algorithms and data into subsets and using advanced mathematical structures, the system securely processes proprietary information while maintaining privacy and efficiency, addressing the challenges of existing technologies.

JP7682179B2Active Publication Date: 2025-05-23TRIPLEBLIND INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2022536507
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-03-24
Filing Date
2020-12-10
Publication Date
2025-05-23
Estimated Expiration
2040-12-10

AI Technical Summary

Technical Problem

Existing technologies face challenges in securely exchanging and processing proprietary data and algorithms between entities while maintaining privacy and efficiency.

Method used

The system divides algorithms and data into subsets, encrypts them, and processes them in a way that maintains privacy by using techniques such as Boolean logic gate sets, neural networks, and Beaver sets to reduce communication overhead and enhance efficiency.

Benefits of technology

This approach allows for secure and efficient processing of encrypted data and algorithms, ensuring privacy for both parties involved and reducing computational overhead through optimized communication and processing strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007682179000035
    Figure 0007682179000035
  • Figure 0007682179000036
    Figure 0007682179000036
  • Figure 0007682179000037
    Figure 0007682179000037
Patent Text Reader

Abstract

A system, method, and computer-readable medium for achieving privacy for both data and algorithms operating on the data. The system can involve receiving an algorithm from an algorithm provider, receiving data from a data provider, dividing the algorithm into a first algorithm subset and a second algorithm subset and dividing the data into a first data subset and a second data subset, sending the first algorithm subset and the first data subset to the algorithm provider and sending the second algorithm subset and the second data subset to the data provider, receiving a first partial result based on the first algorithm subset and the first data subset from the algorithm provider and receiving a second partial result based on the second algorithm subset and the second data subset from the data provider, and determining a combined result based on the first partial result and the second partial result.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Provisional Patent Application No. 16 / 828,085, filed March 24, 2020, which claims priority to U.S. Provisional Patent Application No. 62 / 948,105, filed December 13, 2019, entitled “Systems and Methods for Encryption,” the disclosure of which is incorporated herein by reference.

[0002] Related Applications This disclosure is related to Application No. 16 / 828,216 (Docket No. 213-0101), Application No. 16 / 828,354 (Docket No. 213-0102), and Application No. 16 / 828,420 (213-0103), each of which was filed on March 24, 2020, each of which is incorporated herein by reference.

[0003] The technology relates to encrypting data, algorithms, neural networks, and other information, and then performing complex operations on the split or encrypted data accurately and more efficiently. [Background technology]

[0004] There are many situations in which a person, entity, or company may interact with another person, entity, or company. In these situations, a first entity may need to exchange information with a second entity and the second entity may need to exchange information with the first entity in order to work on a job, project, or task. However, the first entity may want to restrict the second entity from being able to view that information because that information may include proprietary information. Additionally, the second entity may want to restrict the first entity from being able to view that information because that information may include proprietary information.

[0005] In order to describe the manner in which the above-enumerated and other advantages and features of the present disclosure can be obtained, a more particular description of the principles briefly described above will be made by reference to specific embodiments thereof which are illustrated in the accompanying drawings, with the understanding that these drawings depict only exemplary embodiments of the present disclosure and therefore should not be considered as limiting its scope, the principles herein will be described and explained with additional specificity and detail through the use of the accompanying drawings in which: [Brief description of the drawings]

[0006]

Figure 1

Figure 2

Figure 3

Figure 4A

Figure 4B

Figure 4C

Figure 4D

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9A

Figure 9B

Figure 9C

Figure 9D

Figure 10

Figure 11

Figure 12

Figure 13

[0007] Description of exemplary embodiments Various embodiments of the present disclosure are discussed in detail below. While specific implementations are discussed, it should be understood that this is done for purposes of illustration. A person skilled in the art will recognize that other components and configurations can be used without departing from the spirit and scope of the present disclosure.

[0008] Overview Additional features and advantages of the present disclosure will be set forth in the description that follows, and in part will be obvious from the description, or may be learned by practice of the principles disclosed herein. The features and advantages of the present disclosure may be realized and obtained by means of the instruments and combinations particularly pointed out in the appended claims. These and other features of the present disclosure will become more fully apparent from the following description and the appended claims, or may be learned by practice of the principles as set forth herein.

[0009] Disclosed herein are systems, methods, and computer readable media for encrypting data, algorithms, neural networks, and other information and performing complex operations on the split or encrypted data accurately and more efficiently. According to at least one example, a system is provided for achieving privacy for both the data and the algorithms operating on the data. The system may be at least one computing device including a memory and at least one processor for executing instructions stored by the memory. The at least one computing device may receive an algorithm from an algorithm provider and may receive data from a data provider. The algorithm may be selected from a list of algorithms provided by the algorithm provider, and the data may be retrieved from a database by the data provider. The database may be accessed from any type of memory, such as a disk, RAM, cache, etc. Additionally, the computing device may encrypt the algorithm and encrypt the data. In one example, the computing device may be a computing device associated with the algorithm provider. In another example, the computing device may be a computing device associated with the data provider. In a further example, the computing device may be a third-party computing device and may not be associated with the algorithm provider or the data provider.

[0010] The following disclosure describes how an algorithm that will operate on data can be split or divided into at least two sub-parts. The data can also be divided into sub-parts. The algorithm sub-part operates on the data sub-part to maintain privacy between the algorithm provider and the data provider. The process of splitting the algorithm and subsequent processing can be accomplished in several different ways. For example, the algorithm can be converted into a set of Boolean logic gates or can be represented as a neural network or an algebraic or non-Boolean circuit. These various approaches each apply to the more general idea of ​​processing data via an algorithm in a new way.

[0011] The at least one computing device can divide the algorithms into a first algorithm subset and a second algorithm subset, and can divide the data into a first data subset and a second data subset. The at least one computing device can send the first algorithm subset and the first data subset to an algorithm provider, and can send the second algorithm subset and the second data subset to a data provider. The at least one computing device can then receive a first partial result based on the first algorithm subset and the first data subset from the algorithm provider, and can receive a second partial result based on the second algorithm subset and the second data subset from the data provider. The at least one computing device can determine a combined result based on the first partial result and the second partial result.

[0012] In a further example, there may be a Boolean logic gate set associated with an algorithm. The algorithm may be converted to a Boolean logic gate set. The computing device may convert a first algorithm subset to a first Boolean logic gate subset from the Boolean logic gate set, and a second algorithm subset to a second Boolean logic gate subset from the Boolean logic gate set. This is the approach used for non-neural networks. The original Boolean logic gate subset may include AND gates and XOR gates, and the subsets are simply the assigned shares of the encoding. For example, if the system encodes an AND gate with 1,1, the first subset may be 0,1, and the second subset may be 1,0. As discussed herein, the algorithm provider may include at least one first computing device, and the data provider may include at least one second computing device. In one example, the combined result may be sent to the data provider, and the data provider may display a representation of the combined result. In another example, the combined result may be sent to the algorithm provider, and the algorithm provider may display a representation of the combined result. In another example, the combined result may be transmitted to another computing device, and the other computing device may display a representation of the combined result.

[0013] In the case of neural networks, the present disclosure introduces the concept of splitting algorithms according to weights, where the Boolean logic gate set is replaced by the structure of the network. Essentially, the neural network is treated as a (non-Boolean) circuit itself. In another aspect, this concept can be generalized to an algebraic decomposition of the algorithm (rather than just a decomposition of the Boolean logic gate set of the algorithm). For example, in the case of neural networks, the system can treat the architecture of the nodes of the neural network as a circuit in itself, where the nodes represent gates and the connections between them represent wires. The present disclosure also covers the representation of algorithms in purely algebraic structures. Thus, algorithms can be represented in these three ways (circuits, neural networks, algebraic structures). It is further contemplated that algorithms can be transformed or represented as other structures as well. The present disclosure is not limited to the three listed ways of representing algorithms.

[0014] In another example, a method is provided for achieving privacy for both data and algorithms operating on the data. The method can include receiving, by at least one processor, an algorithm from an algorithm provider, receiving, by at least one processor, data from a data provider, dividing, by at least one processor, the algorithm into a first algorithm subset and a second algorithm subset, dividing, by at least one processor, the data into a first data subset and a second data subset, transmitting, by at least one processor, the first algorithm subset and the first data subset to the algorithm provider, transmitting, by at least one processor, the second algorithm subset and the second data subset to the data provider, receiving, by at least one processor, a first partial result based on the first algorithm subset and the first data subset from the algorithm provider and a second partial result based on the second algorithm subset and the second data subset from the data provider, and determining, by the at least one processor, a combined result based on the first partial result and the second partial result.

[0015] An exemplary system can include one or more processors and a computer-readable storage device that stores computer instructions that, when executed by at least one processor, cause the processor to perform operations including receiving an algorithm from an algorithm provider, receiving data from a data provider, dividing the algorithm into a first algorithm subset and a second algorithm subset, dividing the data into a first data subset and a second data subset, and transmitting the first algorithm subset and the first data subset to the algorithm provider, the operations further including transmitting the second algorithm subset and the second data subset to the data provider, receiving a first partial result based on the first algorithm subset and the first data subset from the algorithm provider, receiving a second partial result based on the second algorithm subset and the second data subset from the data provider, and determining a combined result based on the first partial result and the second partial result.

[0016] In another example, a non-transitory computer-readable storage medium is provided for achieving privacy for both data and the algorithms operating on the data. The non-transitory computer-readable storage medium can store instructions that, when executed by one or more processors, cause the one or more processors to perform the methods and / or operations described above. For example, the instructions can cause the one or more processors to receive an algorithm from an algorithm provider, receive data from a data provider, divide the algorithm into a first algorithm subset and a second algorithm subset, divide the data into a first data subset and a second data subset, send the first algorithm subset and the first data subset to the algorithm provider, send the second algorithm subset and the second data subset to the data provider, receive a first partial result based on the first algorithm subset and the first data subset from the algorithm provider, receive a second partial result based on the second algorithm subset and the second data subset from the data provider, and determine a combined result based on the first partial result and the second partial result.

[0017] Another exemplary method includes receiving, by at least one processor, an algorithm from an algorithm provider, receiving, by at least one processor, data from a data provider, dividing, by at least one processor, the algorithm into a first algorithm subset and a second algorithm subset, and dividing, by at least one processor, the data into a first data subset and a second data subset. The method may include processing, by at least one processor, the first algorithm subset and the first data subset, and processing, by at least one processor, the second algorithm subset and the second data subset. The method may also include receiving, by at least one processor, a first partial result based on the first algorithm subset and the first data subset, receiving a second partial result based on the second algorithm subset and the second data subset, and determining, by the at least one processor, a combined result based on the first partial result and the second partial result.

[0018] Another aspect of the present disclosure relates to providing additional efficiency when processing a data subset by an algorithm subset. The algorithm is split into two parts and then distributed between two parties in a transaction. Control bits would be used between the two different spots or places that perform the calculations on the different data subsets and the algorithm subset that ultimately deciphers what the actual final evaluation is of the circuit.

[0019] One approach disclosed herein uses Beaver sets to allow multiplication with fewer communication hops by moving the communication hops to a pre-processing step. Beaver sets are used at the time of calculation (e.g., after the algorithm is encrypted and / or distributed) to reduce the amount of exchanges between different devices or locations where the calculations are occurring. This approach allows more calculations to be performed faster before an exchange is required. This approach is described in the context of filters in various layers of a neural network.

[0020] An exemplary method includes dividing, via one or more computing devices, a plurality of filters in a first layer of a neural network into a first filter set and a second filter set, applying, via the one or more computing devices, each of the first filter sets to an input of the neural network to generate a first set of outputs, and obtaining a second set of outputs associated with the second filter set, the second set of outputs being based on application of each of the second filter sets to the input of the neural network. For each filter set in the first filter set and the second filter set corresponding to a same filter from the plurality of filters, the method includes aggregating, via the one or more computing devices, in the second layer of the neural network, a respective one of the first output sets associated with the first filter in the filter set and a respective one of the second output sets associated with the second filter in the filter set to generate an aggregated set of outputs associated with the first filter set and the second filter set.

[0021] The method further includes splitting, via one or more computing devices, the weights of each of the particular neurons activated in each remaining layer of the neural network to generate a first set of weights and a second set of weights, the particular neurons being activated based on one or more activation functions applied to the aggregated output set. At each particular neuron from each remaining layer, the method includes applying, via one or more computing devices, a respective filter and a first corresponding weight from the first weight set associated with each particular neuron to generate a first set of neuron outputs, and obtaining a second set of neuron outputs associated with the particular neuron, the second set of neuron outputs being based on application of a respective filter associated with each particular neuron to a second corresponding weight from the second weight set, and for each particular neuron, aggregating one of the first set of neuron outputs associated with the particular neuron and one of the second set of neuron outputs associated with the particular neuron to generate an aggregated neuron output associated with the particular neuron, and generating an output of the neural network based on one or more of the aggregated neuron outputs. The method may include any one or more of the identified steps in any order.

[0022] In one example, the use of Beaver sets (or similar mathematical structures) can be used to split algorithms and data to reduce the amount of computations required to perform the operations disclosed herein. Beaver sets have typically been used in the past to perform multiplication securely. This disclosure extends the state of the art by applying Beaver sets in a new way to accomplish multiplication with fewer communication hops. Generally, Beaver sets are used to compute multiplication. This disclosure extends the use of Beaver sets to apply them to division and exponential calculations. An exemplary method includes each party or entity receiving an algorithm subset, generating, by the first party, two shares of a first Beaver set based on the nature of the first algorithm (or other factors), generating, by the second party, two shares of a second Beaver set based on the nature of the second algorithm subset (or other factors), then providing the first data subset to the first party and the second data subset to the second party, executing the first algorithm subset on the first data subset based on the two shares of the first Beaver set to obtain a first output subset, and executing the second algorithm subset on the second data subset based on the two shares of the second Beaver set to obtain a second output subset. The system then combines the first output subset and the second output subset as a final result.

[0023] This brief introduction is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used alone to determine the scope of the claimed subject matter, which subject matter should be understood by reference to appropriate portions of the entire specification of this patent, any or all drawings, and each claim.

[0024] The above, together with other features and embodiments, will become more apparent with reference to the following specification, claims, and accompanying drawings. <Mode for carrying out the invention>

[0025] The disclosed technology involves systems, methods, and computer readable media for encrypting data, algorithms, neural networks, and other information, and for accurately and more efficiently performing complex operations on the split or encrypted data. The technology is described in the following disclosure as follows. The discussion begins with an introduction to a general scenario in which the technology can be applied, followed by an overview of multi-party computation.

[0026] One exemplary scenario in which the concepts disclosed herein can be applied is in a medical context. An individual's medical data is protected by laws such as HIPAA (Health Insurance Portability and Accountability Act). In some cases, convolutional neural networks (CNNs) are valuable for identifying patterns in images. A patient may need to have an electrocardiogram (EKG) evaluated. Typically, the CNN (algorithm) "sees" the EKG data that may lead to the patient's identification. In another aspect, proprietary CNN features may also be obtained from those who provide the data. Companies may not only want to protect patient data from identification, but would also want to protect proprietary algorithms from disclosure. The concepts disclosed herein allow algorithms to operate on data in a way that protects both the data and the algorithm from identification. This disclosure will address various scenarios such as medical, credit card, insurance, etc. more fully below.

[0027] We next provide a description of an exemplary multi-party computing environment, as shown in FIG. 1, as well as an exemplary method and technique for achieving privacy for both data and algorithms operating on data, as shown in FIGS. 2-9B. FIGS. 9C-12 provide further illustrations of the embodiments disclosed herein, including convolutional neural networks and flow diagrams of various methods related to achieving privacy for both algorithms and data in an efficient manner. The discussion concludes with a description of an exemplary computing device architecture, as shown in FIG. 13, including exemplary hardware components suitable for performing multi-party computing operations. In one aspect, standard or unencrypted algorithms may be processed with secure multi-party computing as well. This is in addition to the use of homomorphic encryption, a secure element (hardware-based or otherwise) based approach, as described herein. Systems may interact with homomorphically encrypted data (without using secure multi-party computing) by using encrypted standard algorithms, or even using secure enclaves. The disclosure now moves to an introductory overview of multi-party computing.

[0028] As shown in FIG. 1, the approach herein provides a system and / or process for hiding or encrypting the algorithm 106 from the data provider 102 that provides the data 108 to the algorithm 106 and hiding or encrypting the data 108 from the algorithm provider 102 that provides the algorithm 106 that operates on the data 108. In some examples, the algorithm 106 may be divided or split between at least one party that jointly executes the algorithm. Further, in some examples, the data 108 may be split or split between at least one party. In one aspect, a communication network 110 may be configured between the data provider 102 and the algorithm provider 104. The system discussed herein may achieve privacy by encryption on both the data and the algorithm that operates on the data. As an example, the proprietary algorithm 106 provided by the first party may be kept secret from the second party, and the proprietary data 108 from the second party may be kept secret from the first party. In another example, a third party may be involved.

[0029] As an example, secure multi-party computation (MPC) may enable the operation of a function on two data sets without the owner or custodian of each data set obtaining any proprietary information. MPC is based on a number of cryptographic tools and strategies, such as secret sharing. As an example, a first party may possess data that represents a number, such as 10. The number 10 may be represented using multiple numbers, such as the operation 6+4. A second party may possess data that represents a number, such as 5. The number 5 may be represented using multiple numbers, such as the operation 7+(-2). As an example, the first and second parties may perform an operation on the data, such as addition, without identifying the data.

[0030] The first party may send some of their data to the second party, and the second party may send some of their data to the first party. The first party may send one of two numbers representing the data, for example 4, to the second party. The second party may send one of two numbers representing the data, for example 7, to the first party. The first party may add the remaining number, for example 6, with one of the two numbers from the second party, for example 7, to determine a sum of 13. The second party may add the remaining number, for example -2, with one of the two numbers from the first party, for example 4, to determine a sum of 2. Either the first party or the second party may add the sums to determine a result of 15.

[0031] Secure multi-party computation as discussed herein provides several advantages in several scenarios, such as those discussed below, based on an exemplary protocol. In one example, as described above, a physician may obtain data associated with a patient, such as electrocardiogram (EKG) information. Traditionally, a physician may analyze the EKG information and make a diagnosis of whether the EKG information is abnormal. The abnormality may indicate that there are one or more conditions associated with the patient, such as atrial fibrillation. Making such a determination may be very difficult. However, there are ways to improve the diagnosis, and each patient may have certain attributes that make each diagnosis different from one another. As an example, the patient's age, the patient's gender, and other information may be relevant to the diagnosis. The physician may utilize multi-party computation to possibly improve the diagnosis.

[0032] The physician may represent a first party and may wish to communicate with a second party that has access to an algorithm to perform a more detailed analysis of the data. The data may include identifying information associated with the patient. The second party may be an algorithm holder that performs an analysis of the EKG information by comparing the EKG information to a library of EKG information to determine if there may be an abnormality associated with the patient. The CNN may be an algorithm for evaluating the EKG information. As an example, the second party may be able to perform image analysis by comparing the patient's EKG information with each instance of EKG information in a library. This may allow the physician to provide a more accurate diagnosis by comparing the EKG information to a library of EKG information. In another aspect, the owner or entity providing the CNN for the analysis of the EKG information may want details regarding their algorithm not to be disclosed or made public. The approach disclosed herein allows for the data to be processed by an algorithm in a specific technical manner that protects both the data and the algorithm from being identifiable to the other party while the data is being processed.

[0033] The above examples are not limited to the analysis of EKG information. In another example, a physician may obtain medical images representing a patient, such as X-rays, magnetic resonance imaging (MRI) images, computed tomography (CT) scans, or another type of image. The physician may obtain medical images and wish to perform a diagnosis based on the medical images. The physician may utilize multi-party computation to possibly improve the diagnosis. The physician may wish to communicate with a second party, which may represent a first party, and has access to an algorithm to perform a detailed analysis of the data. As an example, the second party may be an algorithm holder that performs an analysis of the medical images by comparing the medical images to a library of medical images to determine whether there may be an abnormality associated with the patient. The algorithm may be a CNN or machine learning or artificial intelligence system trained on various medical images for the purpose of diagnosing issues with the presented medical data. The systems and methods discussed herein may enable the physician to communicate the medical images with the algorithm holder in a manner that maintains the patient's privacy and the privacy of the algorithm holder. The identification data and the medical images associated with the patient may be HIPAA protected data. Similarly, the algorithm holder may perform an analysis on the medical images without sharing the algorithm with the physician, such that the algorithm maintains its proprietary nature.

[0034] In another example, a retail store may have a customer who wishes to open a credit account, and the customer may be requested to provide data associated with the customer, such as name, address, and unique identification information that represents the customer, such as a social security number. The retail store may be a first party. The retail store may be able to analyze the data, but may be able to perform a more thorough analysis of the data by obtaining access to additional information and algorithms. The retail store may utilize multi-party computation to perhaps improve the analysis. The retail store may wish to communicate with a second party that has access to one or more algorithms to perform a detailed analysis of the customer data and determine whether to open a credit account. The systems and methods discussed herein may enable the retail store to communicate customer data with the algorithm holder in a manner that maintains the customer's privacy. Similarly, the algorithm holder may perform analysis on the customer data without sharing the algorithm with the retail store, such that the algorithm remains proprietary.

[0035] As another example, a customer may be in the process of obtaining insurance, such as vehicle or property insurance. The customer may be requested to provide data associated with the customer, such as name, address, and unique identification information representing the customer, such as a social security number. The insurance agent may be the first party. The insurance agent may be able to analyze the data, but may be able to perform a more thorough analysis of the data by obtaining access to additional information and algorithms. The insurance agent may utilize multi-party computation to possibly improve the analysis. The insurance agent may wish to communicate with a second party that has access to one or more algorithms to perform a detailed analysis of the customer data and determine whether to provide insurance to the customer. The systems and methods discussed herein may enable the insurance agent to communicate customer data with the algorithm holder in a manner that maintains the customer's privacy. Similarly, the algorithm holder may perform analysis on the customer data without sharing the algorithm with the insurance agent, such that the algorithm remains proprietary.

[0036] As noted above, FIG. 1 illustrates an exemplary computing environment 100, according to some examples. As shown in FIG. 1, the exemplary computing environment may include at least one data provider computing device 102 and may include at least one algorithm provider computing device 104. The at least one algorithm provider computing device 104 may have access to and / or store information associated with one or more algorithms 106. The at least one data provider computing device 102 may have access to and / or store data 108. The data 108 may be stored in one or more databases. The at least one data provider computing device 102 may communicate with the at least one algorithm provider computing device 104 using a communications network 110.

[0037] At least one data provider computing device 102 is configured to receive data from and / or transmit data to the at least one algorithm provider computing device 104 over the communications network 110. Although the at least one data provider computing device 102 is shown as a single computing device, it is envisioned that the at least one data provider computing device 102 may include multiple computing devices.

[0038] The communication network 110 can be the Internet, an intranet, or another wired or wireless communication network. For example, the communication network 110 can include a Global System for Mobile Communications (GSM) network, a Code Division Multiple Access (CDMA) network, a Third Generation Partnership Project (GPP) network, an Internet Protocol (IP) network, a Wireless Application Protocol (WAP) network, a WiFi network, a Bluetooth network, a satellite communication network, or an IEEE 802.11 standard network, and various communications thereof. Other conventional and / or later developed wired and wireless networks can also be used.

[0039] At least one data provider computing device 102 includes at least one processor for processing data and memory for storing data. The processor processes communications, constructs communications, retrieves data from memory, and stores data in memory. The processor and memory are hardware. The memory may include computer-readable storage media such as volatile and / or non-volatile memory, e.g., cache, random access memory (RAM), read-only memory (ROM), flash memory, or other memory for storing data and / or computer-readable executable instructions, such as parts or components of an application. Additionally, at least one data provider computing device 102 further includes at least one communication interface for sending and receiving communications, messages, and / or signals.

[0040] At least one algorithm provider computing device 104 includes at least one processor for processing data and memory for storing data. The processor processes communications, constructs communications, retrieves data from memory, and stores data in memory. The processor and memory are hardware. The memory may include computer-readable storage media such as volatile and / or non-volatile memory, e.g., cache, random access memory (RAM), read-only memory (ROM), flash memory, or other memory for storing data and / or computer-readable executable instructions, such as parts or components of an application. Additionally, at least one algorithm provider computing device 104 further includes at least one communication interface for sending and receiving communications, messages, and / or signals.

[0041] The at least one data provider computing device 102 may be a laptop computer, a smartphone, a personal digital assistant, a tablet computer, a standard personal computer, or another processing device. The at least one data provider computing device 102 may include a display, such as a computer monitor, for displaying data and / or a graphical user interface. The at least one data provider computing device 102 may also include an input device, such as a camera, a keyboard, or a pointing device (e.g., a mouse, trackball, pen, or touch screen), for inputting data into or interacting with the graphical and / or other type of user interface. In an exemplary embodiment, the display and input device may be incorporated together as a touch screen on a smartphone or tablet computer.

[0042] The at least one algorithm provider computing device 104 can be a laptop computer, a smartphone, a personal digital assistant, a tablet computer, a standard personal computer, or another processing device. The at least one data provider computing device 102 may include a display, such as a computer monitor, for displaying data and / or a graphical user interface. The at least one algorithm provider computing device 104 may also include an input device, such as a camera, a keyboard, or a pointing device (e.g., a mouse, a trackball, a pen, or a touch screen), for inputting data into or interacting with the graphical and / or other type of user interface. In an exemplary embodiment, the display and input device may be incorporated together as a touch screen in a smartphone or tablet computer.

[0043] A computing device that operates to implement the algorithms or algorithms disclosed herein to process data by a proprietary algorithm is considered a special-purpose computing device. For example, a computing device that executes the algorithm described in connection with Figure 13 is a special-purpose computing device as defined by the steps or operations that the computing device is programmed to perform.

[0044] FIG. 2 illustrates another representation 200 of an exemplary computing environment 100. As illustrated in FIG. 2, at least one data provider computing device 102 may have access to and / or store plaintext data 206. At least one data provider computing device 102 may encrypt the plaintext data into encrypted data 204. Additionally, at least one algorithm provider computing device 104 may have access to and / or store algorithm 214. At least one algorithm provider computing device 104 may encrypt the algorithm to generate encrypted algorithm 212. At least one data provider computing device 102 may transmit the encrypted data 204 to a user or aggregator 202. Additionally, at least one algorithm provider computing device 104 may transmit the encrypted algorithm 212 to a user or aggregator 202. The user or aggregator 202 may execute the encrypted algorithm on the encrypted data 208 to execute a proprietary process 210. A user or aggregator 202 may be at least one data provider computing device 102, although the user or aggregator 202 may be a different entity. In another example, a user or aggregator 202 may be an algorithm provider computing device 104. In this example, the algorithm provider encrypts the algorithm, but this is optional. Additionally, in this example, the data provider encrypts the data, but this is optional. If the algorithm and / or data are not encrypted, this may allow for improved performance such that the algorithm may run proportionately faster.

[0045] In one example, the aggregator 202 may be thought of as an entity that enables an algorithm provider, such as an entity that developed a proprietary convolutional neural network (CNN), to offer its algorithm for evaluating EKGs in the proprietary manner disclosed herein, such that the aggregator 202 may receive EKG data from a physician, process the EKG data, and provide output to a designated recipient of the output data. In this manner, the aggregator 202 may operate a "marketplace" in which data and algorithms may run together under a configuration that allows privacy to be maintained for both the data and the algorithms.

[0046] FIG. 3 illustrates a data provider computing device 102 for dividing data and an algorithm provider computing device 104 for dividing algorithms to set up a secure multi-party computing approach, according to various embodiments. As shown in FIG. 3, the data provider computing device 102 can perform operations to retrieve data from a database 302 and divide the data into a first subset or first share 304 and a second subset or second share 306. Further, as shown in FIG. 3, the algorithm provider computing device 104 can perform operations to obtain an algorithm 308, which may be a representation of an algorithm in a Boolean logic gate set form where the original algorithm is binarized, anonymize the algorithm 309, and divide the algorithm 309 into a first subset or first algorithm 310 and a second subset or second algorithm 312. For example, the system may first convert the algorithm into a Boolean logic set 309, which may then be split into a first Boolean logic subset 310 and a second Boolean logic subset 212. The computing device may perform operations by reducing computer-readable instructions to binary decisions or Boolean logic operations or gates 309. Thus, the data provider computing device 102 and the algorithm provider computing device 104 may reduce the algorithm to an emulated or virtualized circuit that represents the data and / or algorithm and may anonymize the circuit. In another example, the circuit may be represented by hardware. As an example, the first data subset and the second data subset may be a meaningless split of the data. Furthermore, the first algorithm subset 310 and the second algorithm subset 312 may be a meaningless split. Two parties may operate on their respective splits of the algorithm. Neither party runs the entire algorithm on the entire data set and understands what the entire algorithm determines. The split of data and / or the split of the algorithm may occur in any of the components disclosed herein.For example, an entity may provide programming to the data provider 102 that can pre-process or prepare the data in terms of one or more of encryption and data splitting before the data is sent to an entity such as the aggregator 202. The aggregator may simply receive the data and also perform the encryption and splitting on its computing system. A similar process can occur for the algorithm provider 104.

[0047] 4A illustrates a computing device that processes algorithms 308 in the form of Boolean logic gate sets and data 302, according to various embodiments. As an example, the database 302 may be divided into a first data subset 304 and a second data subset 306. Furthermore, the algorithms 308 may be converted into an anonymization circuit (Boolean logic gate set 309) and then divided into a first algorithm subset 310 (by dividing the Boolean logic gate set 309 into a first Boolean logic gate subset) and a second algorithm subset 312 (by dividing the Boolean logic gate set 309 into a second Boolean logic gate subset). The data provider computing device 102 may transmit the second data subset to the algorithm provider computing device 104, or the aggregator 202. The algorithm provider computing device 104 may transmit the first algorithm subset 310 to the data provider computing device 102, or the aggregator 202. The data provider computing device 102 or the aggregator 202 may run a first algorithm subset 310 on the first data subset 304. Additionally, the algorithm provider computing device 104 or the aggregator 202 may run a second algorithm subset 312 on the second data subset 306. The data provider computing device 102 and the algorithm provider computing device 104 (or the aggregator 202) may merge their partial results together to form a final result or answer 402.

[0048] As outlined above, the context of this disclosure concerns party A having a database containing some private information that is not allowed to be shared with other parties. party B has an algorithm, and for some security reasons party B cannot share or disclose the algorithm. To address this problem arising from this context, there are several available solutions. For example, if party A is a hospital and party B has a cancer diagnosis algorithm, party A can send an encrypted version of the patient's medical record, and party B can apply the algorithm homomorphically on party A's input and send the result back to party A. Finally, party A decrypts the result. In another scenario, assume party A has a face dataset and party B wants to train a model based on party A's database. Secure multi-party computation (SMPC) is a possible solution. However, a drawback of MPC is that party A learns information about party B's trained algorithm. Disclosed herein is a new SMPC scheme that is faster than previous schemes. Also disclosed is a new circuit-hiding scheme that transforms gate information into inputs to a circuit. The disclosed idea of ​​SMPC is to use the Chinese Remainder Theorem in polynomial rings to keep the degree of the polynomial low and ensure that after the computation, the resulting polynomial is reconstructible. This approach also ensures that party A does not learn anything about party B's algorithm. These ideas are built upon next.

[0049] FIG. 4B illustrates the interaction 408 between an algorithm provider 410 and a data provider 414. The algorithm provider 410 selects parameters and builds a context associated with processing data using an algorithm. The context 416 is communicated to the data provider 414. The algorithm provider synthesizes the algorithm into logic gates 418 and "hides" the algorithm 420 using principles disclosed herein such as FIG. 7. The result of the hiding process includes gates 422 and general or generic circuits 424. The algorithm provider 410 sends the general circuits 426 to the data provider 414. The algorithm provider then generates shares 428 as disclosed herein and the data provider 414 generates shares from the inputs 436. The algorithm provider 410 sends shares 434 to the data provider 414, which sends shares 442 to the algorithm provider 410. The algorithm provider 410 executes a process that uses the algorithm provider's gate shares 430 and the data provider's gate shares 432. The data provider 414 runs the process using the algorithm provider's input share 438 and the data provider's input share 440. After the algorithm provider generates the share from the data provider's input, the two parties are ready to begin the MPC protocol. See FIG. 6 and related discussion herein.

[0050] "Hiding" occurs when the algorithm provider replaces each gate in the anonymized circuit with a generic circuit, generating the function "general circuit" 424, and stores the information of each gate in a separate table. By replacing each gate with a generic circuit, the circuit is hidden and most of the information of the circuit is transferred to the gate table. All that remains is the location of each gate, as shown in Figure 7. The hidden circuit 702 in Figure 7 shows an example of what is publicly available, as only the location of each gate can be seen. The general structure of the circuit is revealed. The security of this approach depends on the security of the MPC scheme used on top of the circuit hiding method, since the information about each gate is stored separately in the gate table. The actual output of each gate is not available to the opposing party, only a part of it is available, so the calculated output of each gate by the opposing party cannot be used to reverse engineer the circuit. The circuit provider only allows the possibility to calculate the output of those gates.

[0051] One of the problems with MPC is the number of communications between different parties. MPC protocols can involve a lot of communication during computation. The main reason is the complexity of the "multiplication" or "AND" operation computations. Using Beaver Triplets is one practical way to deal with multiplications (AND gates). However, this approach adds some pre-processing computations to the protocol and requires two communications for each multiplication, the same problem as in the case of the Goldreich-Micali-Wigderson (GMW) protocol.

[0052] Disclosed herein is a system that supports addition and multiplication on shares of data without any communication. In other words, if the system splits a data set A into A1, A2 and another data set B into B1, B2, how does the system efficiently compute A*B. The most desirable solution would be to be able to compute A*B using A1*B1 and A2*B2, and also to compute A+B using A1+B1 and A2+B2. Currently, there is no SMPC scheme that can do this.

[0053] GMW only supports addition and requires online communication to compute multiplication. The reason why GMW does not support multiplication is that if the system adds two polynomials, the degree of the polynomial does not increase, but if the system multiplies two polynomials, the degree increases, so GMW requires communication to keep the degree of the polynomial low. The main idea of ​​this disclosure is to use the quotient polynomial ring to keep the degree of the polynomial low so that it can be reconstructed using available points (Lagrange polynomial reconstruction). The Chinese Remainder Theorem (CRT) provides a powerful tool to compute the reduction of any polynomial to a principal ideal (if the principal ideal has enough roots) by knowing the roots of the principal ideal.

[0054] The BGW (Ben-Or, Goldwasser, Wigderson) protocol builds on the GMW protocol and considers secure multiparty computation in a computational setting. The BGW protocol uses the polynomial secret share idea, which naturally supports homomorphic computation. If a system stores data in some polynomials as constant values ​​of those polynomials, one can expect the stored data to be multiplied after multiplying two polynomials.

[0055] For example, consider the following two data sets: Data A: 4 Corresponding polynomial: P 1 (x)=2x 2 +3x+4 Data B: 7 Corresponding polynomial: P 2 (x)=x+7 p 1 and p 2 Multiplying by gives: p 1 *p 2 =2x 3 +17x 2 +25x+28. 1 *p 2 We can verify that the constant value of is indeed equal to data A * data B = 28. But the problem is that the degree of the polynomial increases and the system needs more points to reconstruct the final polynomial.

[0056] A solution to needing more data to reconstruct the final polynomial can be found in the use of a quotient polynomial ring with coefficients in the ring of integers to keep the degree of the polynomial small. Unfortunately, this approach creates two other problems. First, it does not retain a constant value after reduction. The second problem is that the secret polynomial can be reduced to another polynomial when the system only has a few points.

[0057] As an example of the first problem, consider the following. Data A: 4 Corresponding polynomial: P 1 (x)=x+4 Data B: 7 Corresponding polynomial: P 2 (x)=x+7 Principal ideal = x 2 Think +1 coeff.modulus(q)=1001 p 1 *p 2 =x 2 +11x+28=11x+27 mod(x 2 +1) p 1 *p 2 The constant value mod x^2+1 is 27, which is not equal to 28.

[0058] However, when using the ring polynomials above, there is other information that is preserved after the reduction, namely:

number

number

[0059] In one example, x=10. p 1 *p 2 (10)=11x+27=137=36 mod 101 p 1 (10)*p 2 (10)=36 mod 101 101 is the evaluation of x^2+1 in 10. The following point is worth making and is the basis for the solution: if there is an overflow in the coefficients, this fact is no longer valid. So, if instead of coeff modulus=1001, the system uses a smaller coeff, like 17, the results will be wrong.

[0060] As an example, let x=1 be the evaluation point, and let the cyclotomic polynomial of order 2 k Let be the principal ideal.

[0061] These decisions allow the system to hide bits in a polynomial as a sum of coefficients, a cyclotomic polynomial of order 2 k teeth,

number

[0062] Using this approach, some information is preserved after reducing a polynomial by another polynomial, so the process requires hiding data in the polynomial using other techniques. However, the second problem identified above still exists: how can one reduce a polynomial to another when only a few points of the polynomial are known.

[0063] One solution to this problem may be to apply the Chinese Remainder Theorem. To make this idea clearer, this disclosure provides an example of the Chinese Remainder Theorem for polynomial rings. Data A: 4 Corresponding polynomial: P 1 (x)=x+4 Data B: 7 Corresponding polynomial: P 2 (x)=x+7 Principal ideal (I)=x 2 +1 Business ring=Z 17 [x] / I p 1 *p 2 =11x+27 mod x 2 +1=11x+10 mod(x 2 +1,17) The system was able to calculate 11x+10 in another way. x 2 +1=(x+4)(x+12) mod 17, with roots 4 and -4. P 1 (4)=8,P 1 (-4)=0, P 2 (4)=11,P 1 (-4)=3 To compute the multiplication, the system 1 (root1)*p 2 (root1)=A and p 1 (root2)*p 2 We can reconstruct the polynomial at two points (root1,A) and (root2,B) by multiplying (root2) = B. The line that passes through (4,88) = (4,3) and (-4,0) is 11x+10 mod 17.

[0064] The present disclosure will next consider the multi-party computation (MPC) protocol in more detail. The protocol is described between two parties for one bit a ∈ {1, 0} from party A and one bit b ∈ {1, 0} from party B to execute only one gate (XOR or AND). q = coeff.modulus n = degree of the polynomial in form 2 k of B = bound for polynomial coefficients

[0065] In the protocol, any number reduced to Z q is

Number

Number

Number

[0066] In step (3), party A stores the bit "a" in the polynomial degree n P

Number

Number

number

number

[0067] Furthermore, Party B:

number

number

number

number

number

number

number

[0068] In step (8), to calculate the final result, P R (1)∈Z q [X] mod 2 is calculated.

[0069] This protocol works if there are no overflows in the coefficients of the polynomial (coefficients larger than q). Such overflows can occur after evaluating many gates. To avoid overflows, two methods are proposed. The first method is to choose parameters large enough to support the computation. For example, if the system has a polynomial, say, x 2 When calculating, the modulus q is 3B 2 and B is a bound on the polynomial coefficients. It is useful that the domain of the polynomial should be large enough to achieve acceptable security.

[0070] Due to computational limitations, the system cannot simply choose q as large as one might wish to allow the system to compute the circuit correctly. We then propose a method to reduce the coefficients to prevent overflow. This disclosure notes that the coefficients referred to here are different from the shares referenced elsewhere. Shares can overflow.

[0071] The proposed method involves updating a polynomial ring P. Based on the Lagrange polynomial reconstruction, which is exactly equivalent to the Chinese Remainder Theorem (CRT) in polynomial rings, we assume that

number

[0072] λ i is easily calculated and is public information. iis a secret share, half of which is held by Party A and the other half is held by Party B. S i When sharing i , the polynomial can be reconstructed and the bit value is revealed. The following protocol can be used for two parties to update the polynomial. Another way to describe this process is to replace the polynomial with a new polynomial having smaller coefficients.

[0073] In step (1), Party A

Number

Number

Number

[0074] In step (2), Party A sends S AB , S sA +rand(1,0) to Party B. In step (3), Party B

Number

Number

Number

Number

number

[0075] After running this protocol, both parties have a share of the updated polynomial that is decoded as the original noise polynomial, but whose coefficients are bounded by 2B.

[0076] For more than two parties, the idea is similar in that each party controls some roots of the ring polynomial. In the following sections, this disclosure describes the application of this protocol. Figure 4C shows the application 450 of MPC to a "multi-party problem" where there is a group of data providers 414 and aggregators 462 who want to execute a private function (provided by the algorithm provider 410) on new inputs 464 and some private databases. The parties need to reach an agreement which party is responsible for which roots of the polynomial ring, and then the protocol starts with the algorithm provider 410. Both parties take some of the same steps as the two-party problem, sharing a "gate share" 458 and a "general circuit" 458 with the other party. The database provider 414 provides a share of the database 460 to the aggregator 462. The only difference between this protocol and the two-party protocol is that there is a share of the new inputs 454, 456 and the evaluation of the polynomial at the root is held by different parties.

[0077] FIG. 4D illustrates an approach 470 for applying SMPC. A new input 472 is provided to an aggregator 478. The aggregator 478 receives encrypted data from a data provider 474 using the data provider's public key KPd 476. The aggregator also receives an encrypted function f from an algorithm provider 482, encrypted under the algorithm provider's public key KPa 480. Both encryptions are homomorphic encryption, which allows the user to compute the encrypted result using only the encrypted data without requiring decryption. The aggregator 478 computes a result 484 using homomorphic encryption. The result may include a function result based on the new input and data. At the end of the computation, the data provider 474 and the algorithm provider 482 compute a decryption algorithm using SMPC. The SMPC 486 can be used to decrypt the results, KSd and KSa. In the SMPC protocol, the algorithm provider input is its corresponding private key KSa, and the data provider input is the private key KSd.

[0078] FIG. 5 illustrates multiple data providers and multiple algorithm providers, according to various embodiments. The approach discussed herein is not limited to one data provider or one algorithm provider. As an example, data may be provided by multiple providers and algorithms may be provided by multiple providers. As an example, FIG. 5 illustrates an arrangement 500 having a first data provider 502 and a second data provider 508. Additionally, FIG. 5 illustrates a first algorithm provider 518 and a second algorithm provider 524. As illustrated in FIG. 5, a first data 506 from the first data provider 502 and a second data 512 from the second data provider 504 may be encrypted (504, 510). Additionally, an algorithm 522 from the first algorithm provider 518 and an algorithm 528 from the second algorithm provider 524 may be encrypted (520, 526). As a result, multiple data providers and multiple algorithm providers may communicate with each other and function with each other.

[0079] The user or aggregator 510 may receive encrypted data 504 from the first data provider 502 and second encrypted data 510 from the second data provider 508, and may receive encrypted algorithm 520 from the first algorithm provider 518 and second encrypted algorithm 526 from the second algorithm provider 524. The user or aggregator 510 may execute an algorithm on the data and determine a result that may include a proprietary business process 516. As described above, the user or aggregator 510 may be one of the first data provider 502 or the second data provider 508, the first algorithm provider 518, the second algorithm provider 5524, or may be a different entity. The aggregator 510 may also be a combination or hybrid of the respective data providers and / or the respective algorithm providers. The aggregator 510 may also receive unencrypted data or algorithms and perform encryption operations within the aggregator 510, in one aspect.

[0080] FIG. 6 illustrates an exemplary circuit 600 associated with an algorithm according to various embodiments. In some secure multi-party computations (MPC), circuit garbling is used for secure communication between two participants, such as a garbler and an evaluator. The embodiments discussed herein are different from circuit garbling. Multi-party computations (MPC) can perform two operations, including multiplication (AND) and addition (XOR). As a result, to perform complex operations and functions, the operations and functions are decomposed into AND and XOR operations. The exemplary circuit 600 illustrated in FIG. 6 includes only XOR, AND, and NOT gates. The NOT gates are replaced by XOR gates with a bit of "1" that allows the circuit to represent only AND and XOR gates.

[0081] According to an embodiment, to hide the algorithm, the gates may be replaced with inputs including A and B with a generic circuit as shown in Figure 6. Inputs g0 and g1 in Figure 6 may act as control bits such that when g1g0=11, the entire circuit may act as an AND gate for A and B. When g1g0 is equal to 01, the entire circuit may be equal to A EXOR B, and when g1g0=10, the entire circuit may act as NOT A.

[0082] An algorithm may be encoded into a logic circuit or emulated circuit by converting the algorithm into a specific circuit 600 as shown in FIG. 6. The circuit may contain the correct number and arrangement of gates such that it represents the algorithm. Each of the specific gates in the circuit may be replaced with a generic gate slot. Each of the generic gate slots may be populated with the correct bit pattern to make the gate function as is. The gate information may then be copied into a matrix.

[0083] In one example, a truth table can be used to describe or resolve the gate shown in Figure 6 into an actual gate. For example, the following truth table can be used: [Table 1]

[0084] 7 illustrates an exemplary algorithm 308 that is converted 700 into a hidden circuit 309, according to various embodiments. The hidden circuit may be, for example, the Boolean logic gate set 309 shown in FIG. 3. As an example, information associated with the gates in the circuit shown in FIG. 6 may be anonymized and replaced with a hidden representation 309, as shown in FIG. 7. As an example, the algorithm 308 may be converted into a hidden representation 309. This provides one exemplary method of anonymizing a circuit structure. Other approaches to anonymization may be applicable as well.

[0085] 8 illustrates a hidden circuit 309 split 800 into a first split or first subset 310 and a second split or second subset 312, according to various embodiments. In other words, the hidden representation 309 may be split into two splits or subsets. The first algorithm subset 310 may be evaluated by a first party, a first computing device, or a first virtual computing environment, and the second algorithm subset 312 may be evaluated by a second party, a second computing device, or a second virtual computing environment. Generally speaking, these different splits of the Boolean logic gate set 309 are separated into different computing spots, locations, parts, physical or virtual components, such that their separated processing may be performed in a separated manner.

[0086] FIG. 9A illustrates an exemplary method 900 for hiding or encrypting an algorithm from a data provider that provides data to an algorithm and for hiding or encrypting data from an algorithm provider that provides an algorithm that operates on the data. The method may include any one or more steps performed in any order. The order disclosed herein is by way of example. According to the exemplary method, in step 902, the algorithm provider may send the algorithm provider to a computing device. Further, the data provider may send the data to the computing device. The computing device may receive the algorithm and receive the data. The algorithm may be selected from a list of algorithms provided by the algorithm provider, and the data may be retrieved from a database by the data provider. Further, the computing device may encrypt the algorithm and encrypt the data. In one example, the computing device may be a computing device associated with the algorithm provider. In another example, the computing device may be a computing device associated with the data provider. In a further example, the computing device may be a third-party computing device and may not be associated with the algorithm provider or the data provider.

[0087] In step 904, the computing device may divide the algorithms into a first algorithm subset and a second algorithm subset. The first algorithm subset and the second algorithm subset may not be equal-sized subsets. As an example, the first algorithm subset may include one-third of the operations associated with the algorithm, and the second algorithm subset may include two-thirds of the operations associated with the algorithm. Alternatively, the first algorithm subset and the second algorithm subset may be divided into equal-sized subsets. As noted above, an alternative step generally includes anonymizing the algorithm or algorithm subset.

[0088] Further, the computing device may divide the data into a first data subset and a second data subset. As an example, the first data subset may include one-third of the data, and the second data subset may include two-thirds of the data. Alternatively, the first data subset and the second data subset may be divided into equal sized subsets. In step 906, the computing device may send the first algorithm subset and the first data subset to the algorithm provider. In step 908, the computing device may send the second algorithm subset and the second data subset to the data provider. In step 910, the computing device may receive a first partial result from the algorithm provider. The first partial result may be based on the first algorithm subset and the first data subset. Further, the computing device may receive a second partial result from the data provider. The second partial result may be based on the second algorithm subset and the second data subset. In step 912, the computing device may determine a combined result based on the first partial result and the second partial result.

[0089] In a further example, there may be a Boolean logic gate set associated with an algorithm. The algorithm may be converted to a Boolean logic gate set. This may be performed by an algorithm provider. The computing device may convert a first algorithm subset to a first Boolean logic gate subset from the Boolean logic gate set and may convert a second algorithm subset to a second Boolean logic gate subset from the Boolean logic gate set. The first Boolean logic gate subset and the second Boolean logic gate subset include AND gates and XOR gates. As discussed herein, the algorithm provider may include at least one first computing device and the data provider may include at least one second computing device. In one example, the combined result may be transmitted to the data provider and the data provider may display a representation of the combined result. In another example, the combined result may be transmitted to the algorithm provider and the algorithm provider may display a representation of the combined result. In another example, the combined result may be transmitted to another computing device and the other computing device may display a representation of the combined result.

[0090] In another aspect, the computing device may hold or transmit the first algorithm subset and the first data subset and the second algorithm subset and the second data subset to any entity. For example, an entity such as the aggregator 202 may perform the partitioning and processing steps to obtain a first partial result and a second partial result. In general, the system may process the first algorithm subset with the first data subset and the second algorithm subset with the second data subset separately, such that the respective algorithms and data are not disclosed to each other.

[0091] 9B illustrates another example method 918. The example method includes receiving, by at least one processor, an algorithm from an algorithm provider, in step 920, and receiving, by at least one processor, data from a data provider, in step 922. The method may also include dividing, by the at least one processor, the algorithm into a first algorithm subset and a second algorithm subset, in step 924, dividing, by the at least one processor, the data into a first data subset and a second data subset, in step 926, processing, by the at least one processor, the first algorithm subset and the first data subset, in step 928, and processing, by the at least one processor, the second algorithm subset and the second data subset, in step 930. The method may also include, in step 932, receiving, by the at least one processor, a first partial result based on the first algorithm subset and the first data subset, and receiving a second partial result based on the second algorithm subset and the second data subset, and, in step 934, determining, by the at least one processor, a combined result based on the first partial result and the second partial result.

[0092] The process of partitioning the algorithm and subsequent processing can be accomplished in a number of different ways: for example, the algorithm can be converted into a set of Boolean logic gates, or it can be represented as a neural network or an algebraic or non-Boolean circuit.

[0093] In some embodiments, the algorithms may include large, complex algebraic expressions, including algorithms with thousands of operations stringed together in a row (e.g., common among CNNs). To handle such complex algorithms, Beaver Set-based mathematical techniques may be used, for example, to perform much faster computations of a large number of arbitrary operations using fewer communication exchanges between two or more parties (e.g., fewer communication exchanges between data providers, algorithm providers, aggregators, etc.). Beaver Sets, which are typically used for multiplication, may be applied in novel ways to the concepts disclosed herein to convert the calculations into a pre-processing step. Beaver Sets typically use pre-processing. Additional concepts disclosed herein to the overall process include the ability to process differently to support division and exponentials, as well as faster multiplication. FIG. 9C illustrates an example method associated with using Beaver Sets to improve computational requirements, for example, when implementing the principles disclosed herein.

[0094] One issue with multi-party computation may be associated with the number of communications that may be transmitted over the communications network 110 between the data provider computing device 102 and the algorithm provider computing device 104. The communications may be associated with the complexity of multiplication and "AND" operation computations. While MPCs can support addition and multiplication, multiplication is typically limited. As the numbers being multiplied continue to increase in size, the computational capabilities of the MPC begin to approach and reach an upper limit due to integer size limitations and computation storage limitations. Once the limit is encountered, the MPC seeks to exchange information between the computing devices performing the operations. This exchange reduces the overall computational performance.

[0095] The embodiments discussed herein utilize Beaver set multiplication to limit communication between the data provider computing device 102 and the algorithm provider computing device 104 to reduce communication and network overhead. The use of Beaver set multiplication may be applied to any two devices or virtual machines used to split data and split algorithms for processing as described herein. Thus, problems may arise between any two devices, virtual or physical, that may be used in conjunction with the principles disclosed herein. In some embodiments, one Beaver set triple may be used for each operation (e.g., a multiplication operation or an AND gate). The Beaver set triple may be pre-generated by one party or one computing device when the two parties work together to determine a combined result. As an example, the data provider computing device 102 may pre-generate a Beaver set and the algorithm provider computing device 104 may pre-generate a Beaver set. In another aspect, the aggregator 202 may pre-generate various Beaver sets for one or more of the algorithms, the data, the subsets of the algorithms, and the subsets of the data.

[0096] According to an embodiment, the Beaver set can be utilized at the time of calculation (e.g., after the algorithm is encrypted and distributed between the data provider computing device 102 and the algorithm provider computing device 104). For example, after the algorithm is encrypted, split, and distributed to the two parties, the Beaver set can be used when one or both of the parties are ready to perform the calculation. Because the calculation of the encrypted circuit is slow, reducing the amount of information exchange between the two parties by using the Beaver set (allowing each party to perform more mathematical calculations before making the exchange) increases the speed and efficiency of the algorithm and the overall data processing. In other words, the following Beaver set-based technique can perform complex operations on the split data and / or algorithms much faster than previous approaches because the technique allows more operations to be calculated while separated before an exchange between the two parties is necessary (e.g., exceeding a threshold error).

[0097] 9C may include each party or entity receiving, by at least one processor, an algorithm subset from an algorithm provider in step 940. The algorithm subset may be, for example, a first algorithm subset from an algorithm divided into a first algorithm subset and a second algorithm subset. In step 942, the first party may generate two shares of the Beaver set based on properties of the first algorithm subset or based on other parameters.

[0098] For example, a first party (e.g., a user A of the data provider computing device 102 or the algorithm provider computing device 104) may generate an N×3 matrix, Beav A It is possible to generate Beav Amay include first and second sequences that are randomly generated, and the third sequence may include the operation of the algorithm subset. A can be partially generated randomly or possibly generated based on a non-random process. In this exemplary embodiment, the third column includes the multiplication of the first two columns. The first two columns of the Beaver set can be generated randomly to mask the actual data (EKG share), and the third column can be calculated depending on the application (multiplication, division, exponential function, ..). It is preferable to generate the first two columns randomly so that the actual data can be hidden.

[0099] Next, user A uses Beav A Two shares of [Beav A ] A and [Beav A ] B User A can then use the public key and encryption to generate pk A ,

number

number

[0100] In some embodiments, the ENC supports homomorphic encryption for one multiplication and one addition. Homomorphic encryption is a form of encryption that allows computations on ciphertext that, when decrypted, produce an encrypted result that matches the result of the operation as if it were performed on the plaintext. Homomorphic encryption is a form of encryption that has the additional evaluation capability to compute over the encrypted data without access to the private key. The result of such computations remains encrypted.

[0101] In step 944, a second party (user B) can generate its two shares of the Beaver set based on properties of the second algorithm subset or based on other factors. User B, such as the data provider computing device 102 or the algorithm provider computing device 104, can generate an N×3 matrix, Beaver B , and a random matrix R having the same size (Nx3) as the Beaver set. The matrix R can also be generated based on a non-random process. A As with Beav B may include first and second columns that are randomly generated or generated based on some non-random process, and the third column may include an operation of the algorithm subset. In this exemplary embodiment, the third column includes a multiplication of the first two columns.

[0102] Next, user B uses Beav B Two shares of [Beav B ] A and [Beav B ] B Then, user B can generate [Beav] B =[Beav A ] B ×[Beav B ] B -R and

number

[0103] The first and second party data provider computing devices 102 and algorithm provider computing devices 104 can perform the following: User A:

number

number

[0104] The first party (user A) and / or the second party (user B) can generate an N×3 matrix Beaver triple set where the third column contains the first column divided by the second column. User A and user B can then collaboratively calculate x'=x×d and y'=y×e (e.g., both parties would know the values ​​of x' and y'). User A can then calculate [xd] A User B can calculate [xd] B Then, both user A and user B can jointly reconstruct xd.

[0105] In one aspect, the data provider computing device 102 and the algorithm provider computing device 104 perform a division

number

number

[0106] In step 946, the data provider can provide the split data set to two parties and use the corresponding beaver sets to execute a split algorithm on the split data set. In some embodiments, the data can be split into random shares of the complete data set to further hide confidential information (e.g., patterns that reveal demographic, gender, age, race, or other biometric identification such as patient identification). In this regard, the method can include executing a first algorithm subset on a first split data subset based on two shares of a first mathematical set to generate a first output subset, and executing a second algorithm subset on a second split data subset based on two shares of a second mathematical set to generate a second output subset. The method can then include combining the first output subset and the second output subset.

[0107] In some embodiments, the calculation speed can be further increased through one or more memoization techniques, which are optimization techniques that can be used to speed up calculations by remembering the results of expensive function calls and returning the cached results when the same input occurs again. A memoized function can cache the results corresponding to some sets of specific inputs, for example. Subsequent calls with remembered inputs (from the cache) can return the remembered results without recalculation, so the main cost of a call with a given parameter is removed except for the first call made to the function with those parameters. Thus, memoization can transparently and on-the-fly insert a cache of the results as needed, rather than beforehand.

[0108] In another example, suppose in a chess game, one player wants to calculate the number of opening moves available. After the first move, the player calculates the possible moves as a result of that first move, and so on. Instead of recalculating all possible moves as a result of that move, the player keeps a list of all possible moves that can be made according to a certain setting so that the chess game is faster. Instead of recalculating the possible moves every time, the player keeps a note. This exemplary model applies to beaver sets, which concern memoization of actions that allow the system to accumulate as little error as possible. Each party generates its own beaver set. In the algorithm example, the system generates a beaver set and runs the algorithm on the data.

[0109] As another example, memoization techniques can be applied to each transaction between two parties. In one example, a number of EKGs (e.g., 50 EKGs) can be specified for batch processing. The same Beaver set can be used for all 50 EKGs rather than recomputing it for each EKG in the set. However, to prevent pattern recognition, the Beaver set is recreated for the next transaction (e.g., the next batch of EKGs) in a distributed fashion.

[0110] Another aspect of the present disclosure relates to providing additional efficiency when processing a data subset by an algorithm subset. The algorithm is split into two parts and then distributed between two parties in a transaction. Control bits would be used between two different spots or locations that perform calculations on different data subsets and algorithm subsets that would ultimately decipher what the actual final evaluation of the circuit is.

[0111] One approach disclosed herein uses Beaver sets to enable multiplication with fewer communication hops. Beaver sets (or similar mathematical structures) are introduced above and can be used during computation (e.g., after the algorithm has been encrypted and / or distributed) to reduce the amount of exchanges between devices, or different locations where computations are occurring. This approach allows computations to be performed faster before an exchange is required. This approach is now described in the context of filters in various layers of a neural network.

[0112] 9D illustrates an exemplary method 948. The method includes, in step 950, dividing a plurality of filters in a first layer of a neural network into a first filter set and a second filter set via one or more computing devices, in step 952, applying each of the first filter sets to an input of the neural network to generate a first output set via one or more computing devices, and in step 954, obtaining a second output set associated with the second filter set, the second output set being based on the application of each of the second filter sets to the input of the neural network. In step 956, for each filter set in the first filter set and the second filter set corresponding to the same filter from the plurality of filters, the method includes, in a second layer of the neural network, aggregating, via one or more computing devices, a respective one of the first output sets associated with the first filter in the filter set and a respective one of the second output sets associated with the second filter in the filter set to generate an aggregated output set associated with the first filter set and the second filter set.

[0113] The method further includes, at step 958, splitting, via one or more computing devices, respective weights of particular neurons activated in each remaining layer of the neural network to generate a first set of weights and a second set of weights, the particular neurons being activated based on the one or more activation functions applied to the aggregated output set. For each particular neuron from each remaining layer, the method includes, in step 960, applying, via one or more computing devices, a respective filter and a first corresponding weight from a first weight set associated with each particular neuron to generate a first set of neuron outputs, in step 962, obtaining a second set of neuron outputs associated with the particular neuron, the second set of neuron outputs being based on application of a respective filter associated with each particular neuron to a second corresponding weight from the second weight set, in step 964, for each particular neuron, aggregating one of the first set of neuron outputs associated with the particular neuron and one of the second set of neuron outputs associated with the particular neuron to generate an aggregated neuron output associated with the particular neuron, and in step 966, generating an output of the neural network based on one or more of the aggregated neuron outputs. The method may include any one or more of the identified steps in any order.

[0114] FIG. 10 illustrates an exemplary neural network 1000 that may represent an algorithm processed as described herein. Neural networks are often used to analyze or evaluate visual images, or may be used for image recognition, video recognition, speech or natural language processing, etc. A convolutional neural network (CNN) has an input layer 1002 that receives an input, convolves the input, and passes it to the next hidden layer 104A or a group of hidden layers 1004A, 1004B, 1004C. Each layer receives input from a previous layer, which may be a restricted sub-area of ​​the previous layer. The hidden layers of the CNN 1000 may include a series of convolution layers that convolve with multiplication or other dot products. An activation function, or Re-LU layer, is then followed by additional convolutions such as pooling layers, fully connected layers, and normalization layers, referred to as hidden layers 1004A, 1004B, 1004C. The term "hidden" is used because the input and output are masked by the activation function and the final convolution. The final convolution may involve backpropagation to more accurately weight the final product at the output layer 1006. Mathematically, a "convolution" may involve applying a sliding dot product or cross-correlation.

[0115] Each neuron in the neural network calculates an output value. It applies a particular function to the input values ​​from the previous layer. The function applied may be determined by a vector of weights and biases. The learning process involves iteratively making adjustments to the biases and weights. In one aspect, the vector of weights and biases is called a filter and represents a particular feature in the input. For example, the feature may include the color of an image, or the shape. In a CNN, some neurons may share the same filter, which may reduce memory requirements since a single filter may be used across a group or across all receptive fields that share the filter. In other aspects, each receptive field may have its own bias and vector weighting. The output layer 1006 provides the results of the neural network process.

[0116] Although CNNs are primarily referred to in this disclosure, this disclosure is not limited to any particular type of neural network or machine learning technique.

[0117] FIG. 11 illustrates an exemplary application of a CNN 1100. An input layer 1102 begins processing an image or a particular portion of an image as shown. The image is processed as described above by one or more convolutional hidden layers 1104A and then communicated to a pooling hidden layer 1104B. The pooling layer can reduce the dimensionality of the data by combining the outputs of neuron clusters in one layer into a single neuron in the next layer. Global pooling can operate on all neurons of a convolutional layer. Additionally, pooling may calculate a maximum or an average. Max pooling uses the maximum value from each of the clusters of neurons in the previous layer. Average pooling uses the average value from each of the clusters of neurons in the previous layer. The pooling layer 1104A can perform any of these operations.

[0118] The fully connected layer 1104C connects all neurons in one layer to all neurons in another layer. This layer is similar to a conventional multi-layer perceptron neural network (MLP). The flattened matrix is ​​passed through the fully connected layer to classify the image. The flattening layer is a rearrangement of the data, possibly involving rearrangement of shares. The output image 1110 can then be classified. For example, the output may identify the image as a park, or a city, etc.

[0119] Convolutional neural networks process data through many different layers. The system first applies a convolution operation in one layer of the CNN 1100. Then the next layer can be max pooling where the system takes the maximum value after applying the convolution operation to each matrix. In the first layer of the CNN, the system is performing a convolution operation, but it is performing a split version of the CNN. For image data, for example, the system still performs the same window per pixel, across the entire image. But the filters (weights, biases, or in other words, numbers) are transformed into two splits, so that 1 in the filter becomes .5, 2 becomes 1 and 1, 3 becomes 2 and 1, etc. Images can also be split in this way.

[0120] The system then performs operations again on this split version of the image. In one example, the system can randomly split the pixel values ​​for each of the color channels. In a color context, the values ​​can be any value between 0 and 256. Similarly, the system can perform a convolution operation where the other side knows that some operation is happening but does not know specifically what the filter is. Then, aggregation can occur in the next layer, the max pooling layer. Then, based on how the convolution and max pooling operations happen, certain points in the neural network can be activated. These points are typically called neurons in the neural network, and the activation function can be a Re-LU function, a sigmoid function, or other functions.

[0121] In an exemplary application of the Re-LU function, the Re-LU function essentially goes up to a certain .0 [point 0], after which the neuron is 1. The neuron is either on or off. Depending on the input value of the image, the Re-LU function turns on a certain point in the neural network, essentially splitting neurons on and off, and those different neurons are weighted differently. In accordance with this disclosure, the system splits the weights here so that the entities participating in the exchange do not know what they are doing themselves.

[0122] The system proceeds to process the data layer by layer by applying these types of operations. The last layer can be a softmax layer. The approach outputs the same softmax layer even though the system performs complex mathematics to hide it. A softmax layer is what reveals the output of the neural network. One technical advantage of this process is that it obtains results with fewer network hops.

[0123] Further referring to FIG. 11 and the various layers of the CNN, the present disclosure proceeds with the next step through an exemplary evaluation of the CNN 1100. In one example, assume an input A: n*m*d. The convolutional layer 1104A can be hidden by hiding the weights corresponding to each kernel. Thus, each kernel travels along each layer of the input with a size of (m*n) and a depth of d. In this example, there are multiplications and additions within and between layers. To minimize the number of communications, the present disclosure provides for computing all multiplications first, and then computing the additions. For each kernel, the system requires on communication.

[0124] A flattening layer can be used to rearrange the shares. A max pooling layer 1104B can be used. There are two exemplary approaches to max pooling. First, the input A > Input B If f = max(input A ,input B) output is A. In such a case, the system can ask for up to two inputs with two communications using SMPC. In another example, the input A > Input B If f = max(input A ,input B ) output is the input A In this case, the system needs to create a comparison circuit and output the larger value using ((1-(A>B))*B+(A>B)*A. The advantage of this method over the first method is that no party learns about the location of the maximum value, but on the other hand, it is expensive in terms of computation and time.

[0125] The sigmoid function was mentioned above. The sigmoid function is e x / (1+e x ) To evaluate this function for an input X, a new idea is applied as follows. The process is divided into two parts. First, the system uses the Beaver Set idea disclosed herein to find e x There is a pre-processing part that includes: ·User A and user B are assigned random numbers for the first column, random numbers for the second column, and 1 / e r A and 1 / e r Generate two random Beaver sets, B and r A and r B are the values ​​in the first column. User A uses enc(r A ) and enc A (1 / e r A) is sent to user B. User B selects a random sequence [a], which is User B’s share from the final Beaver set. B =m 1 and [b] B =m 2 Generate. User B uses enc A (m 1 -(r A +r B)) and enc A (m 2 -(1 / e r Ax1 / e r B) and transmit them to user A. User A's share is [a] A =(r A +r B )-m 1 and [b] A =(1 / e r Ax1 / e r B)-m 2 It is.

[0126] Next, e x We present an approach to calculate User A is [x] A +[a] A where a is the first column and the nth row, where n is a counter for each a that the system consumes across a row. User B: [x] B +[a] B where both parties learn x+a. e x User A's share of (e (x+a) )x[b] A and e x User B's share of (e (x+a) x[b] B ).

[0127] Nest shows an example of a division algorithm for x / y. User A and User B each generate two random numbers [r] A and [r] B Select x and y and jointly calculate y and 1 / y. User A and User B are [xr] A and [xr] B Calculate jointly. User A's share of division is [xr] A / yr, and User B's share is [xr] B / yr.

[0128] The sigmoid function consists of division and exponential functions, so the system can calculate it as explained above. The present disclosure uses the exponential invention to then calculate the ReLU activation for the neural network. This is accomplished by approximately ReLU via a sigmoid-like function. The Relu function works as a sigmoid-like function and can also be calculated as a derivative of the idea above. There are several possible approaches to calculating Relu. First, both parties learn whether x is greater than or less than zero. If it is greater than zero, the parties do not change their shares. If it is less than zero, their shares are replaced with 0. This approach has several security issues. In another approach, the parties do not learn anything, but it is slower because it operates at the gate level.

[0129] In the fully connected layer 1104C, each layer acts as a matrix multiplication on the inputs, and SMPC supports addition and multiplication. To hide this layer, the system adds some dummy nodes with input weights all equal to zero, so that neither the weights nor the structure of the network are learned.

[0130] The basic idea of ​​a convolutional neural net is that the system does not need the output of the convolutional net until the next layer. The system can postpone the multiplication communication. In other words, for each filter, f i For an input I and I, the system can walk the filters along and compute partial multiplications, or it can do whatever is necessary before communication to the next layer occurs.

[0131] FIG. 12 illustrates a method 1200 for processing a neural network according to the principles disclosed herein. In step 1202, the method includes dividing a plurality of filters in a first layer of the neural network into a first filter set and a second filter set. In step 1204, the method includes applying each of the first filter sets to an input of the neural network to generate a first output set, and in step 1206, obtaining a second output set associated with the second filter set, the second output set being based on the application of each of the second filter sets to the input of the neural network. In step 1208, for each filter set in the first filter set and the second filter set corresponding to the same filter from the plurality of filters, the method includes aggregating, in a second layer of the neural network, a respective one of the first output sets associated with the first filter in the filter set and a respective one of the second output sets associated with the second filter in the filter set to generate an aggregated output set associated with the first filter set and the second filter set. In step 1210, the method includes splitting respective weights of particular neurons activated in each remaining layer of the neural network to generate a first set of weights and a second set of weights, the particular neurons being activated based on one or more activation functions applied to the aggregated set of outputs. In step 1212, the method includes applying, at each particular neuron from each remaining layer, a respective filter associated with each particular neuron and a first corresponding weight from the first weight set to generate a first set of neuron outputs. In step 1214, the method includes obtaining a second set of neuron outputs associated with the particular neuron, the second set of neuron outputs being based on application of a respective filter associated with each particular neuron to a second corresponding weight from the second weight set.The method includes, in step 1216, for each particular neuron, aggregating one of the first set of neuron outputs associated with the particular neuron and one of the second set of neuron outputs associated with the particular neuron to generate an aggregated neuron output associated with the particular neuron, and in step 1218, generating an output of the neural network based on one or more of the aggregated neuron outputs.

[0132] In one aspect, the plurality of filters may include a plurality of filter values, with the first filter set including a first set of values ​​and the second filter set including a second set of values. As mentioned above, the input of the neural network may include image data or any other type of data. The first output set may further include a first respective output from each filter in the first filter set.

[0133] In one aspect, the first layer of the neural network can include a convolutional layer, and the neural network can include a convolutional neural network. However, as noted above, the present disclosure is not limited to a particular convolutional neural network. At least one remaining layer in the neural network can include at least one of a pooling layer, a normalization layer, a fully connected layer, and an output layer. The normalization layer can be one of the hidden layers. Training state-of-the-art deep neural networks can be computationally expensive. One way to reduce training time is to normalize the activity of neurons in the neural network. Batch normalization uses the distribution of the summed inputs to a neuron over a mini-batch of training cases to calculate the mean and variance, which are then used to normalize the summed inputs to that neuron at each training case. This significantly reduces the training time of a feedforward neural network. In one aspect, using a normalization layer can stabilize the dynamics of the hidden state.

[0134] In another aspect, one or more activation functions can include at least one of a rectified linear unit function, a sigmoid function, a hyperbolic tangent function, and a softmax function.

[0135] The input of the neural network can include an image, and the output of the neural network can include at least one of a display of one or more features detected in the image and / or a classification of one or more features in the image.

[0136] In another aspect, dividing a plurality of filters into a first filter set and a second filter set can include randomly dividing each filter in the plurality of filters into a set of a first value and a second value that, when combined, are equal to the value of the filter.

[0137] The method can further include sending the second filter set to a remote computing device and obtaining a second set of outputs associated with the second filter set from the remote computing device. In another aspect, the method can include sending a second set of weights to the remote computing device and obtaining a second set of neuron outputs associated with a particular neuron from the remote computing device.

[0138] FIG. 13 illustrates an exemplary computing system architecture of a system 1300 that may be used to process data operations and requests, store data content and / or metadata, and perform other computing operations. In this example, the components of the system 1300 communicate electrically with each other using a connection 1305, such as a bus. The system 1300 includes a processing unit (CPU or processor) 1310 and connections 1305 that couple various system components, including memory 1315, such as read-only memory (ROM) 1320 and random access memory (RAM) 1325, to the processor 1310. The system 1300 may include a cache of high-speed memory directly connected to the processor 1310, in close proximity to the processor 1310, or integrated as part of the processor 1310. The system 1300 may copy data from the memory 1315 and / or storage device 1330 to the cache 1312 for quick access by the processor 1310. In this manner, the cache may provide a performance boost that avoids delays to the processor 1310 while waiting for data. These and other modules may control or be configured to control the processor 1310 to perform various actions. Other memories 1315 may be available as well. The memory 1315 may include multiple different types of memories with different performance characteristics. The processor 1310 may include any general-purpose processor, as well as hardware or software services, such as service 1 1332, service 2 1334, and service 3 1336 stored in the storage device 1330, configured to control the processor 1310, as well as special-purpose processors where the software instructions are embedded in the actual processor design. The processor 1310 may be a completely self-contained computing system including multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.

[0139] To enable user interaction with the computing system 1300, the input device 1345 can represent any number of input mechanisms, such as a microphone for speaking, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, speech, etc. The output device 1335 can also be one or more of several output mechanisms known to those skilled in the art. In some cases, a multi-modal system can enable a user to provide multiple types of input to communicate with the computing system 1300. The communication interface 1340 can generally govern and manage user input and system output. There is no limitation to operation to any particular hardware arrangement, and thus the basic features herein can be easily substituted with improved hardware or firmware arrangements as they are developed.

[0140] The storage device 1330 is a non-volatile memory and may be a hard disk or other type of computer-readable medium capable of storing data accessible by a computer, such as a magnetic cassette, a flash memory card, a solid-state memory device, a digital versatile disk, a cartridge, a random access memory (RAM) 1325, a read-only memory (ROM) 1320, and hybrids thereof.

[0141] The storage device 1330 may include services 1332, 1334, 1336 for controlling the processor 1310. Other hardware or software modules are contemplated. The storage device 1330 may be connected to the connection 1305. In one aspect, a hardware module that performs a particular function may include software components stored in a computer-readable medium in association with the necessary hardware components, such as the processor 1310, the connection 1305, the output device 1335, etc., to perform the function.

[0142] For clarity of explanation, in some examples, the technology may be presented as including individual functional blocks, including devices, device components, method steps or routines implemented in software, or combinations of hardware and software.

[0143] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as energy, carrier signals, electromagnetic waves, and the signals themselves.

[0144] The method according to the above-mentioned examples can be implemented using computer-executable instructions stored on or otherwise available from a computer-readable medium. Such instructions can include, for example, instructions and data that cause or otherwise configure a general-purpose computer, a special-purpose computer, or a special-purpose processing device to perform a particular function or group of functions. Portions of the computer resources used may be accessible over a network. The computer-executable instructions may be, for example, binaries, intermediate form instructions such as assembly language, firmware, or source code. Examples of computer-readable media that may be used to store instructions, information used, and / or information created during the method according to the described examples include magnetic or optical disks, flash memory, USB devices with non-volatile memory, network storage devices, and the like.

[0145] Devices implementing methods according to these disclosures can include hardware, firmware, and / or software and can take any of a variety of form factors. Typical examples of such form factors include laptops, smartphones, small form factor personal computers, personal digital assistants, rack-mounted devices, standalone devices, etc. The functionality described herein can also be embodied in peripherals or add-in cards. Such functionality can also be implemented on a circuit board among different chips or different processes running on a single device, as further examples.

[0146] The instructions, media for carrying such instructions, computational resources for executing them, and other structures for supporting such computational resources are means for providing the functionality described in these disclosures.

[0147] Although various examples and other information have been used to describe aspects within the appended claims, those skilled in the art will be able to derive a wide variety of implementations using these examples, and therefore no limitations to the claims are implied based on the specific features or arrangements of such examples. Furthermore, while some subject matter may be described in language specific to example structural features and / or method steps, it should be understood that the subject matter defined in the appended claims is not necessarily limited to these described features or acts. For example, such functionality may be distributed or embodied differently in components other than those identified herein. Rather, the described features and steps are disclosed as example components of the systems and methods within the appended claims.

[0148] Claim language reciting "at least one of" a set indicates that one member of the set or multiple members of the set satisfy the claim. For example, claim language reciting "at least one of A and B" means A, B, or A and B.

[0149] Statement Bank Statement 1: A system comprising at least one processor and a computer readable storage device storing instructions, which when executed by the at least one processor cause the at least one processor to: receive an algorithm from an algorithm provider; receive data from a data provider; and partition the algorithm into a first algorithm subset and a second algorithm subset for separate and independent processing of respective data sets by the first algorithm subset and the second algorithm subset, where the first algorithm subset and the second algorithm subset, when combined, constitute an algorithm. The steps may further include having the processor divide the data into a first data subset and a second data subset; transmitting the first algorithm subset and the first data subset to a first entity for processing; and transmitting the second algorithm subset and the second data subset to a second entity for processing, wherein the first entity processes the first algorithm subset with the first data subset and the second entity processes the second algorithm subset with the second data, and wherein the first entity and the second entity exchange and transmit intermediate partial results while processing the first algorithm subset with the first data subset and processing the second algorithm subset with the second data. The steps may further include having the processor receive from the first entity a first partial result based on the first algorithm subset and the first data subset, receive from the second entity a second partial result based on the second algorithm subset and the second data subset, and / or determine a combined result based on the first partial result and the second partial result. Any one or more of the steps of statement 1 may be performed in any order.

[0150] Statement 2: The system of statement 1, wherein the computer-readable storage device stores additional instructions that, when executed by the at least one processor, cause the at least one processor to convert an algorithm into a Boolean logic gate set, wherein a first algorithm subset corresponds to a first Boolean logic gate subset of the Boolean logic gate set and a second algorithm subset corresponds to a second Boolean logic gate subset of the Boolean logic gate set.

[0151] Statement 3. The system of any one of the preceding statements, wherein the first subset of Boolean logic gates and the second subset of Boolean logic gates include AND gates and XOR gates.

[0152] Statement 4. The system of any one of the preceding statements, wherein the algorithm provider includes at least one first computing device and the data provider includes at least one second computing device.

[0153] Statement 5. The system of any one of the preceding statements, wherein the computer-readable storage device stores additional instructions that, when executed by the at least one processor, cause the at least one processor to transmit the combined result to a data provider and display a representation of the combined result.

[0154] Statement 6. The system of any one of the preceding statements, wherein the computer-readable storage device stores additional instructions that, when executed by the at least one processor, cause the at least one processor to send the combined result to an algorithm provider and display a representation of the combined result.

[0155] Statement 7. The system of any one of the preceding statements, wherein the algorithm is selected from a list of algorithms provided by an algorithm provider.

[0156] Statement 8. The system of any one of the preceding statements, wherein the algorithm is represented by one of a Boolean logic set, a neural network, or an algebraic circuit.

[0157] Statement 9. The system of any one of the preceding statements, wherein the computer-readable storage device stores additional instructions that, when executed by the at least one processor, cause the at least one processor to encrypt the algorithm and to encrypt the data.

[0158] Statement 10. A method for providing a method for providing a data set comprising the steps of: receiving, by at least one processor, an algorithm from an algorithm provider; receiving, by at least one processor, data from a data provider; partitioning, by at least one processor, the algorithm into a first algorithm subset and a second algorithm subset for separate and independent processing of a respective data set by the first algorithm subset and the second algorithm subset, the first algorithm subset and the second algorithm subset comprising, when combined, an algorithm; partitioning, by at least one processor, the data into a first data subset and a second data subset; transmitting the first algorithm subset and the first data subset to a first entity for processing; transmitting the second algorithm subset to a data provider; the data provider processes the second algorithm subset and the second data subset; the first entity and the second entity exchanging and transmitting a plurality of intermediate partial results while the algorithm provider processes the first algorithm subset with the first data subset and the second algorithm subset with the second data subset; receiving, by at least one processor, a first partial result based on the first algorithm subset and the first data subset and receiving a second partial result based on the second algorithm subset and the second data subset; and / or determining, by at least one processor, a combined result based on the first partial result and the second partial result.

[0159] Statement 11. The method of statement 10, wherein dividing the algorithm into a first algorithm subset and a second algorithm subset further includes converting the algorithm into a Boolean logic gate set, the first algorithm subset being represented by a first Boolean logic gate subset of the Boolean logic gate set, and the second algorithm subset being represented by a second Boolean logic gate set.

[0160] Statement 12. The method of any one of the preceding statements, wherein the first subset of Boolean logic gates and the second subset of Boolean logic gates include AND gates and XOR gates.

[0161] Statement 13. The method of any one of the preceding statements, wherein the algorithm provider includes at least one first computing device and the data provider includes at least one second computing device.

[0162] Statement 14. The method of any one of the preceding statements, further comprising sending the combined result to a data provider and displaying a representation of the combined result.

[0163] Statement 15. The method of any one of the preceding statements, further including sending the combined result to an algorithm provider and displaying a representation of the combined result.

[0164] Statement 16. The method of any one of the preceding statements, wherein the algorithm is selected from a list of algorithms provided by an algorithm provider.

[0165] Statement 17. The method of any one of the preceding statements, wherein the algorithm is represented by one of a Boolean logic set, a neural network, or an algebraic circuit.

[0166] Statement 18. The method of any one of the preceding statements, further comprising encrypting the algorithm and encrypting the data.

[0167] Statement 19. A non-transitory computer readable storage medium having instructions stored therein which, when executed by one or more processors, cause the one or more processors to perform any one or more of the following actions in any order: receiving an algorithm from an algorithm provider; receiving data from a data provider; dividing the algorithm into a first algorithm subset and a second algorithm subset for separate and independent processing of the respective data by the first algorithm subset and the second algorithm subset, the first algorithm subset and the second algorithm subset being, when combined, an algorithm; dividing the data into a first data subset and a second data subset; transmitting the first algorithm subset and the first data subset to a first entity; transmitting the algorithm subset and the second data subset to a second entity, wherein the first entity and the second entity process the first algorithm subset with the first data subset and the second algorithm subset with the second data subset while exchanging / transmitting intermediate partial results; receiving a first partial result based on the first algorithm subset and the first data subset from the first entity and receiving a second partial result based on the second algorithm subset and the second data subset from the second entity; and / or determining a combined result based on the first partial result and the second partial result.

[0168] Statement 20. A non-transitory computer-readable storage medium as recited in statement 19, storing instructions that, when executed by one or more processors, cause the one or more processors to convert an algorithm into a set of Boolean logic gates, wherein a first algorithm subset corresponds to a first Boolean logic gate subset of the set of Boolean logic gates and a second algorithm subset corresponds to a second Boolean logic gate subset of the set of Boolean logic gates.

Claims

1. 1. A system comprising: At least one processor; and a computer-readable storage device storing instructions that, when executed by the at least one processor, cause the at least one processor to: receiving an algorithm from an algorithm provider; receiving data from a data provider; partitioning the algorithms into a first algorithm subset and a second algorithm subset for separate and independent processing of respective data sets by the first algorithm subset and the second algorithm subset, the first algorithm subset and the second algorithm subset constituting the algorithm when combined; Partitioning the data into a first data subset and a second data subset; transmitting the first subset of algorithms and the first subset of data to a first entity for processing; transmitting the second algorithm subset and the second data subset to a second entity for processing, wherein the first entity processes the first algorithm subset with the first data subset and the second entity processes the second algorithm subset with the second data subset, and the first entity and the second entity exchange intermediate partial results while processing the first algorithm subset with the first data subset and processing the second algorithm subset with the second data subset; receiving from the first entity a first partial result based on the first subset of algorithms and a first subset of data, and receiving from the second entity a second partial result based on the second subset of algorithms and the second subset of data; determining a combined result based on the first partial result and the second partial result.

2. The computer-readable storage device stores additional instructions that, when executed by the at least one processor, cause the at least one processor to: Converting the algorithm into a set of Boolean logic gates, wherein the first algorithm subset corresponds to a first subset of Boolean logic gates of the set of Boolean logic gates, and the second algorithm subset corresponds to a second subset of Boolean logic gates of the set of Boolean logic gates, and causing the conversion to be performed, the system according to claim 1.

3. The system according to claim 2, wherein the first subset of Boolean logic gates and the second subset of Boolean logic gates include AND gates and XOR gates.

4. The system according to claim 1, wherein the algorithm provider includes at least one first computing device, and the data provider includes at least one second computing device.

5. The computer-readable storage device stores additional instructions, and when the additional instructions are executed by the at least one processor, the at least one processor is caused to send the combined result to the data provider and display a representation of the combined result, the system according to claim 1.

6. The computer-readable storage device stores additional instructions, and when the additional instructions are executed by the at least one processor, the at least one processor is caused to send the combined result to the algorithm provider and display a representation of the combined result, the system according to claim 1.

7. The system according to claim 1, wherein the algorithm is selected from a list of algorithms provided by the algorithm provider.

8. The system according to claim 1, wherein the algorithm is represented by one of a Boolean logic set, a neural network, or an algebraic circuit.

9. The computer-readable storage device stores additional instructions, and when the additional instructions are executed by the at least one processor, the at least one processor is caused to encrypt the algorithm and encrypt the data, the system according to claim 1.

10. A method comprising: receiving, by at least one processor, an algorithm from an algorithm provider; receiving, by the at least one processor, data from a data provider; partitioning, by the at least one processor, the algorithms into a first algorithm subset and a second algorithm subset for separate and independent processing of respective data sets by the first algorithm subset and the second algorithm subset, the first algorithm subset and the second algorithm subset constituting the algorithm when combined; partitioning, by the at least one processor, the data into a first data subset and a second data subset; transmitting the first subset of algorithms and the first subset of data to a first entity for processing by the at least one processor; transmitting, by the at least one processor, the second algorithm subset and the second data subset to a second entity for processing, wherein the first entity processes the first algorithm subset and the first data subset, the second entity processes the second algorithm subset and the second data subset, and the first entity and the second entity exchange a plurality of intermediate partial results while processing the first algorithm subset with the first data subset and processing the second algorithm subset with the second data subset; receiving, by the at least one processor, a first partial result based on the first subset of algorithms and a first subset of data, and receiving a second partial result based on the second subset of algorithms and the second subset of data; determining, by the at least one processor, a combined result based on the first partial result and the second partial result.

11. said dividing the algorithms into a first subset of algorithms and a second subset of algorithms further comprising:

11. The method of claim 10, further comprising: converting the algorithm to a set of Boolean logic gates, the first algorithm subset being represented by a first Boolean logic gate subset and the second algorithm subset being represented by a second Boolean logic gate subset of the set of Boolean logic gates.

12. 12. The method of claim 11, wherein the first subset of Boolean logic gates and the second subset of Boolean logic gates include AND gates and XOR gates.

13. The method of claim 10 , wherein the algorithm provider comprises at least one first computing device and the data provider comprises at least one second computing device.

14. The method of claim 10 , further comprising transmitting the combined result to the data provider and displaying a representation of the combined result.

15. The method of claim 10 , further comprising transmitting the combined result to the algorithm provider and displaying a representation of the combined result.

16. The method of claim 10 , wherein the algorithm is selected from a list of algorithms provided by the algorithm provider.

17. The method of claim 10 , wherein the algorithm is represented by one of a Boolean logic set, a neural network, or an algebraic circuit.

18. The method of claim 10, further comprising: encrypting the algorithm; and encrypting the data.

19. A non-transitory computer-readable storage medium having instructions stored therein, the instructions, when executed by one or more processors, causing the one or more processors to: receiving an algorithm from an algorithm provider; receiving data from a data provider; partitioning the algorithms into a first algorithm subset and a second algorithm subset for separate and independent processing of data by the first algorithm subset and the second algorithm subset, the first algorithm subset and the second algorithm subset constituting the algorithm when combined; Partitioning the data into a first data subset and a second data subset; transmitting the first subset of algorithms and the first subset of data to a first entity; transmitting the second algorithm subset and the second data subset to a second entity, wherein the first entity and the second entity exchange intermediate partial results while processing the first algorithm subset with the first data subset and processing the second algorithm subset with the second data subset; receiving a first partial result based on the first subset of algorithms and a first subset of data from the first entity and receiving a second partial result based on the second subset of algorithms and the second subset of data from the second entity; and determining a combined result based on the first partial result and the second partial result.

20. and storing instructions that, when executed by the one or more processors, cause the one or more processors to:

20. The non-transitory computer readable storage medium of claim 19 storing instructions that cause the algorithm to be converted to a set of Boolean logic gates, the first algorithm subset corresponding to a first Boolean logic gate subset of the set of Boolean logic gates and the second algorithm subset corresponding to a second Boolean logic gate subset of the set of Boolean logic gates.

Citation Information

Patent Citations

  • Embedded software code protection system

    JP2014531663A

  • Neural network mapping dictionary generation

    US20170323198A1