Data processing method and apparatus for secure computation, medium, and electronic device
By directly covering and exchanging data in multi-party security calculations, the two participants directly calculate the data product under arithmetic sharing and Boolean sharing forms, solving the high traffic and computing overhead problems caused by the conversion of shared forms in the prior art, and improving the security computing efficiency.
Patent Information
- Application Number
- PCT/CN2024/131796
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-11-13
- Publication Date
- 2025-05-30
AI Technical Summary
In multi-party security calculation, when calculating the product of Boolean sharing and arithmetic sharing, expensive sharing form conversion is required, resulting in excessive traffic and computing overhead, affecting the efficiency of security computing.
Through a new data processing method, two participants directly mask and exchange data under arithmetic sharing and Boolean sharing forms to generate intermediate results, thus avoiding the step of sharing form conversion.
This method improves the service processing efficiency of secure computing by reducing data traffic and computing overhead, and realizes the function of directly calculating data product.
Smart Images

Figure CN2024131796_30052025_PF_FP_ABST
Abstract
Description
Data processing method, device, medium and electronic device for secure computing
[0001] This application claims priority to Chinese Patent Application No. 202311559334.8 filed on November 21, 2023, and the contents of the above-mentioned Chinese patent application disclosure are hereby cited in their entirety as part of this application. Technical Field
[0002] The present disclosure relates to a data processing method, device, medium and electronic device for secure computing. Background Art
[0003] Secure multi-party computation, also known as multi-party secure computation, allows multiple parties to jointly compute the result of a function without disclosing the input data of each party involved in the function. The result of the computation is publicly available to one or more of the parties involved. Typical applications of secure multi-party computation include joint statistical analysis of privacy-preserving multi-party data and machine learning. The function here can be a statistical operation, a machine learning algorithm, or something similar.
[0004] In multi-party secure computation, to prevent the leakage of data and intermediate computation results, data or intermediate results can be shared among all parties. A single party holds a data shard, and the shards held by all parties are combined to restore the corresponding data. Typically, computations are performed in a shared state. Therefore, the number and volume of data communications in multi-party secure computations are important factors affecting the efficiency of secure computations.
[0005] Summary of the Invention
[0006] This summary is provided to briefly introduce concepts that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0007] In a first aspect, the present disclosure provides a data processing method for secure computing, wherein the secure computing is used by two participants to collaboratively compute the product of first data and second data, wherein the first data is in an arithmetic shared form between the two participants, and the second data is in a Boolean shared form between the two participants. The method is applied to any of the participants, and includes:
[0008] generating first masked data based on a first arithmetic slice of the first data held by the participant and a first Boolean slice of the second data held by the participant, and generating second masked data based on the first Boolean slice;
[0009] sending the first masked data and the second masked data to other parties;
[0010] receiving third masked data and fourth masked data sent by the other party, wherein the third masked data is generated based on the second arithmetic slice of the first data held by the other party and the second Boolean slice of the second data held by the other party, and the fourth masked data is generated based on the second Boolean slice;
[0011] A first intermediate result is generated based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data.
[0012] In a second aspect, the present disclosure provides a data processing device for secure computing, wherein the secure computing is used by two participants to collaboratively compute the product of first data and second data, wherein the first data is in an arithmetic shared form between the two participants, and the second data is in a Boolean shared form between the two participants. The device is applied to any of the participants, and comprises:
[0013] a first generating module, configured to generate first masked data based on a first arithmetic slice of the first data held by the participant and a first Boolean slice of the second data held by the participant, and generate second masked data based on the first Boolean slice;
[0014] a sending module, configured to send the first masked data and the second masked data to other participants;
[0015] a receiving module, configured to receive third masked data and fourth masked data sent by the other party, wherein the third masked data is generated based on a second arithmetic slice of the first data held by the other party and a second Boolean slice of the second data held by the other party, and the fourth masked data is generated based on the second Boolean slice;
[0016] The second generating module is configured to generate a first intermediate result based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data.
[0017] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the data processing method for secure computing provided in the first aspect of the present disclosure.
[0018] In a fourth aspect, the present disclosure provides an electronic device, comprising:
[0019] a storage device having a computer program stored thereon;
[0020] A processing device is used to execute the computer program in the storage device to implement the steps of the data processing method for secure computing provided in the first aspect of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale. In the drawings:
[0022] FIG1 is a flow chart showing a data processing method for secure computing according to an exemplary embodiment;
[0023] FIG2 is a data interaction diagram of a secure computing according to an exemplary embodiment;
[0024] FIG3 is a data interaction diagram of a secure computing according to another exemplary embodiment;
[0025] FIG4 is a block diagram showing a data processing device for secure computing according to an exemplary embodiment; and
[0026] Fig. 5 is a schematic structural diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0027] Before introducing the specific embodiments of the present disclosure, the specific application scenarios of multi-party secure computing and the terms involved in the present disclosure are first introduced and explained.
[0028] In practical applications, multi-party secure computing (MPCC) algorithms are typically black-box algorithms for privacy protection purposes. Data transmission between computing nodes using MPC algorithms is opaque. As discussed in the background, typical applications of MPC include machine learning. MPC technology can be used to protect private data during the inference and training phases of machine learning, primarily involving the protection of model parameters and the data of each participant during the training process.
[0029] Currently, common strategies for privacy-preserving machine learning based on secure multi-party computation include: privacy-preserving machine learning protocols based on technologies such as obfuscated circuits and oblivious transfer, and two-party secure multi-party computation protocols to perform nonlinear operations such as activation functions. Secret sharing technology allows multiple parties to participate in machine learning network model training or prediction without revealing data or model information.
[0030] In addition to the above application areas, multi-party secure computing can also be applied to privacy-protected network security detection, joint statistical analysis of privacy-protected multi-party data, spam cleaning and filtering of encrypted emails, advertising conversion and other fields.
[0031] Ring: refers to a set that defines two operations, addition and multiplication, and forms a commutative group for addition, a semigroup for multiplication for elements other than 0, and multiplication satisfies the distributive property for addition.
[0032] The ring of addition and multiplication is defined above, where addition is defined as integer addition modulo N, and multiplication is defined as integer multiplication mod N, where N is an integer greater than 1.
[0033] Secret sharing, also known as secret splitting or secret sharing, is based on the principle of splitting a secret (such as a key or private data) into multiple shares, each of which is held by different data parties. The secret can only be recovered by combining the shares of a certain number of parties. Shares obtained from fewer than the threshold number of parties cannot reveal any information about the secret. In multi-party secure computation, the threshold number is typically equal to the number of participating parties, and the shares into which the secret is split are also called shards.
[0034] Secret sharing is a crucial tool in multi-party secure computation. Common forms of secret sharing in multi-party secure computation include arithmetic sharing, Boolean sharing, and Yao's sharing. The following describes various sharing methods, using the example of sharing secret data x.
[0035] Among them, arithmetic sharing is also called sum sharing. In a two-party secure computation, an integer x is divided into two slices x=x L +x R Modulo 2 N Shared form (translated to [0, 2 N -1] interval) is distributed and stored on both parties, that is, X is stored on both parties in a shared form in ring A. So that one party does not know x R , the other party does not know x L , neither party can get the complete form of x, x R and x L is the arithmetic share of x or A-shares. Furthermore, two parties can be expanded to multiple parties, such as x = x1 + x2 + ... + x dAssuming N = 64, a single shard of x in a single participant can be represented by a 64-byte binary number. The way to split a data x into and share it is, for example, to randomly generate (d-1) 2 64 The values in the (e.g., randomly generated 64-byte binary numbers) are taken as (d-1) fragments, such as x1, x2, ..., x d-1 , use and 2 64 (Shift to [0, 2 64 -1] interval) modulo as another slice, such as x d =x-x1-x2-…-x d-1 .
[0036] Boolean sharing is a secret sharing method that performs XOR operations on bits. For example, still taking two participants as an example, assuming that x is a one-bit data (value is 0 or 1), and In the Boolean shared form between the two participants, x0 and x1 are the two Bool shares (Bool Shares) or B-Shares of x in the two participants, both of which take values of 0 or 1. That is, x is stored in the shared form in the ring B between the two parties. Represents an exclusive OR operation. A single participant does not know the shards held by another participant and therefore cannot infer the data x.
[0037] Yao's sharing is a sharing method related to garbled circuits. This disclosure does not involve this sharing method and will not be described in detail here.
[0038] In secure two-party computation, the A-shares form is more suitable for arithmetic operations, such as addition and multiplication, while the B-shares form is more suitable for logical operations, such as AND and OR. However, sometimes mixed operations using A-shares and B-shares are performed.
[0039] For example, when calculating the expression if (x>y) then a else 0, we will first calculate b=(x>y), the result of which is a B-shares, and then calculate b*a.
[0040] However, when calculating b*a, b is B-Shares and a is A-Shares, and the two cannot be directly multiplied.
[0041] For example, when performing the operation select a.key, max(b.value) from a join b group by a.key, a.key is one-hot encoded. That is, each row of a.key is converted into an m-dimensional vector (m is the number of possible values for a.key), where only one of the m dimensions is 1 and the rest are 0. Each dimension of the one-hot encoding is then multiplied by b.value. The multiplication here is also a multiplication of B-shares and A-shares.
[0042] To calculate the product of B-shares and A-shares, a common approach is to use Boolean to Arithmetic Sharing (B2A) to convert B-shares into A-shares, and then multiply them by A-shares.
[0043] However, B2A conversion usually has huge communication and computation overhead, as shown in Table 1 below:
[0044] Table 1 Cost of multiplying B-shares and A-shares
[0045] In view of this, the present disclosure provides a data processing method, apparatus, medium, and electronic device for secure computing.
[0046] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0047] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0048] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment," the term "another embodiment" means "at least one additional embodiment," and the term "some embodiments" means "at least some embodiments." Other terms are defined in the following description.
[0049] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0050] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0051] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0052] It is understandable that before using the technical solutions disclosed in the various embodiments of this disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0053] For example, in response to a user's active request, a prompt message is sent to the user to clearly inform the user that the operation requested will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the electronic device, application, server, storage medium, or other software or hardware that performs the operations of the disclosed technical solution based on the prompt message.
[0054] As an optional but non-limiting implementation, in response to receiving a user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. Furthermore, the pop-up window may also contain a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0055] It is understandable that the above notification and user authorization process are merely illustrative and do not limit the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0056] At the same time, it is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) must comply with the requirements of relevant laws, regulations and relevant provisions.
[0057] Fig. 1 is a flow chart showing a data processing method for secure computing according to an exemplary embodiment. As shown in Fig. 1 , the data processing method may include the following steps S101 to S104.
[0058] In S101 , first mask data is generated according to a first arithmetic slice of first data held by a participant and a first Boolean slice of second data held by the participant, and second mask data is generated according to the first Boolean slice.
[0059] In the present disclosure, secure computing is used for two parties to collaboratively compute the product of first data and second data, where the first data is in an arithmetic shared form between the two parties, and the second data is in a Boolean shared form between the two parties. It is understandable that the first data and the second data in the present disclosure may be any data that is not convenient for public disclosure, and may include but is not limited to data representing user personal information, business secrets, model parameters of a neural network model, and the like. The multi-party secure computing method provided in the embodiments of the present disclosure can be applied to ciphertext multiplication operations in tasks such as data calculation, cleaning, analysis, model training, storage, and database query based on ciphertext.
[0060] The above data processing method can be applied to any of the two participants. The above two participants can be referred to as the first party and the second party. This disclosure takes the application of the above data processing method to the first party as an example for explanation. That is, the participant in S101 is the first party, wherein the first party holds the first arithmetic slice a0 of the first data a and the first Boolean slice b0 of the second data b, and the second party (i.e., the other participant) holds the second arithmetic slice a1 of the first data a and the second Boolean slice b1 of the second data b. And N>1.
[0061] In S102, the first masked data and the second masked data are sent to other participants.
[0062] In S103, the third masked data and the fourth masked data sent by other participants are received.
[0063] In the present disclosure, the third masked data is generated based on the second arithmetic slice of the first data held by the other party and the second Boolean slice of the second data held by the other party, and the fourth masked data is generated based on the second Boolean slice.
[0064] The other participants generate third masked data based on the second arithmetic slice of the first data and the second Boolean slice of the second data, and generate fourth masked data based on the second Boolean slice; then, the third masked data and the fourth masked data are sent to the above-mentioned participants; and the above-mentioned participants receive the third masked data and the fourth masked data.
[0065] In S104 , a first intermediate result is generated based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data.
[0066] At the same time, the other participant generates a second intermediate result based on the second Boolean slice, the first masked data, the second masked data, and the fourth masked data. The two participants can then share their respective intermediate results and combine them to obtain the final calculation result (i.e., the product of the first data and the second data).
[0067] Each participant masks its own data shards and shares them with other participants. This allows two participants to directly multiply the first and second data through a single round of masked data exchange. The first and third masked data are both N bits, and the second and fourth masked data are both 1 bit, resulting in an online communication volume of (2N+2) bits.
[0068] It should be noted that the above S103 may be executed before the above S102, or after the above S102, or simultaneously with the above S102, which is not specifically limited in the present disclosure.
[0069] In the above technical solution, when calculating the product of first data in the form of arithmetic sharing between two participants and second data in the form of Boolean sharing between the two participants, the two participants can realize the direct multiplication calculation of the first data and the second data through a round of masked data exchange without converting the Boolean sharing into arithmetic sharing, thereby eliminating the communication volume of the two participants in the conversion between Boolean sharing and arithmetic sharing, which can greatly reduce the data communication volume for calculating the product of Boolean sharing and arithmetic sharing, and improve the business processing efficiency of secure computing.
[0070] The following describes in detail the specific implementation method of generating the first masked data based on the first arithmetic slice of the first data held by the participant and the first Boolean slice of the second data held by the participant in S101. Specifically, it can be achieved by the following steps (11) to (13):
[0071] Step (11): Obtain the first random number in the N-th power space modulo 2.
[0072] The first random number belongs to the N-th power space of modulo 2, that is, the value range of the first random number is [0, 2 N -1].
[0073] Step (12): Use the first random number to perform masking processing on the first arithmetic slice to obtain fifth masked data.
[0074] For example, the first random number may be used to perform masking processing on the first arithmetic slice using the following equation (1) to obtain fifth masked data:
[0075] Among them, δa0 is the fifth mask data; is the first random number.
[0076] Step (13): Generate first mask data according to the fifth mask data and the first Boolean slice.
[0077] For example, the first mask data may be generated according to the fifth mask data and the first Boolean slice by the following equation (2):
[0078] Wherein, C1 is the first mask data.
[0079] The following describes in detail the specific implementation of generating the second mask data according to the first Boolean slice in S101. Specifically, it can be achieved by the following steps (21) and (22):
[0080] Step (21): Obtain a third random number in the modulo 2 space.
[0081] The third random number belongs to the modulo 2 space, that is, the value of the third random number is 0 or 1.
[0082] Step (22): Use the third random number to mask the first Boolean slice to obtain second masked data.
[0083] For example, the third random number may be used to mask the first Boolean slice using the following equation (3) to obtain the second masked data:
[0084] Among them, δb0 is the second masking data; is the third random number.
[0085] The following describes in detail the specific implementation method for the other participants to generate the third masked data based on the second arithmetic slice of the first data and the second Boolean slice of the second data. Specifically, this can be achieved by following the steps (31) to (33):
[0086] Step (31): Obtain a fourth random number in the Nth power space modulo 2.
[0087] The fourth random number belongs to the N-th power space of modulo 2, that is, the value range of the fourth random number is [0, 2 N -1].
[0088] Step (32): Use the fourth random number to mask the second arithmetic slice to obtain sixth masked data.
[0089] For example, the fourth random number may be used to perform masking processing on the second arithmetic slice using the following equation (4) to obtain sixth masked data:
[0090] Among them, δa1 is the sixth masking data; is the fourth random number.
[0091] Step (33): Generate third mask data based on the sixth mask data and the second Boolean slice.
[0092] For example, the third masked data may be generated according to the sixth masked data and the second Boolean slice by the following equation (5):
[0093] Wherein, C2 is the third mask data.
[0094] The following describes in detail the specific implementation method of generating the fourth mask data based on the second Boolean slice. Specifically, it can be achieved by the following steps (41) and (42):
[0095] Step (41): Obtain a fifth random number in the modulo 2 space.
[0096] The fifth random number belongs to the modulo 2 space, that is, the value of the fifth random number is 0 or 1.
[0097] Step (42): masking the second Boolean slice using the fifth random number to obtain fourth masked data.
[0098] For example, the fifth random number may be used to mask the second Boolean slice using the following equation (6) to obtain fourth masked data:
[0099] Among them, δb1 is the fourth mask data; is the fifth random number.
[0100] The following describes in detail the specific implementation of generating the first intermediate result based on the first Boolean slice, the second masked data, the third masked data, and the fourth masked data in S104. Specifically, the method may further include the following steps:
[0101] Get a second random number in the space of powers of N modulo 2.
[0102] The second random number belongs to the N-th power space of modulo 2, that is, the value range of the second random number is [0, 2 N -1].
[0103] At this time, the above S104 may include: generating a first intermediate result based on the first random number, the second random number, the first Boolean slice, the second masked data, the third masked data, the fourth masked data, and the fifth masked data.
[0104] For example, based on the first random number, the second random number, the first Boolean slice, the second masked data, the third masked data, the fourth masked data, and the fifth masked data, a first intermediate result is generated by the following equation (7):
[0105] Among them, y0 is the first intermediate result; u0 is the second random number, f(b,a)=a if b==1 else 0.
[0106] The following describes in detail the specific implementation method for generating the second intermediate result based on the second Boolean fragment, the first masked data, the second masked data, and the fourth masked data by the other participants. Specifically, the above method may further include the following steps:
[0107] Get the sixth random number in the space of powers of N modulo 2.
[0108] The sixth random number belongs to the N-th power space of modulo 2, that is, the value range of the sixth random number is [0, 2 N -1].
[0109] At this time, other participants may generate a second intermediate result based on the fourth random number, the sixth random number, the second Boolean fragment, the first masked data, the second masked data, the fourth masked data, and the sixth masked data.
[0110] For example, other participants may generate a second intermediate result using the following equation (8) based on the fourth random number, the sixth random number, the second Boolean slice, the first masked data, the second masked data, the fourth masked data, and the sixth masked data:
[0111] Among them, y1 is the second intermediate result; u1 is the sixth random number.
[0112] After obtaining the first intermediate result and the second intermediate result from the two parameters, the two can be added together to obtain the final calculation result (i.e., the product of the first data and the second data). Specifically, the above method can also include the following two steps:
[0113] Obtaining a second intermediate result generated by another participant, wherein the second intermediate result is generated based on the second Boolean slice, the first masked data, the second masked data, and the fourth masked data;
[0114] A sum of the first intermediate result and the second intermediate result is determined as a product of the first data and the second data.
[0115] In addition to being performed by the above-mentioned participants, the above steps can also be performed by other electronic devices other than the above-mentioned two participants. In this case, the other electronic device obtains the first intermediate result and the second intermediate result from the two participants respectively, and then determines the sum of the two as the product of the first data and the second data.
[0116] The correctness of the above protocol (i.e., first intermediate result + second intermediate result = first data * second data) is guaranteed by the following equation:
[0117] in,
[0118] The following describes in detail the specific implementation of obtaining the first random number in the N-power space of modulo 2 in step (11). Specifically, it can be implemented in a variety of ways. In one implementation, as shown in FIG2 , a Boolean-arithmetic-arithmetic triple (i.e., BA2A triple) can be generated by a semi-trusted third party, where the triple includes the first random number The second random number u0, the third random number The fourth random number The fifth random number And the sixth random number u1, wherein these six random numbers meet the constraint condition Afterwards, the semi-trusted third party will The second random number u0, the third random number Send to the above participants and send the fourth random number The fifth random number And the sixth random number u1 is sent to other participants. The above operation can be performed offline, and the offline communication volume is (4N+2) bits, where the first random number The fourth random number The second random number u0 and the sixth random number u1 are both N bits, and the third random number and the fifth random number Thus, the above-mentioned participants can obtain the first random number, the second random number and the third random number.
[0119] In another embodiment, as shown in FIG3 , a participant generates a first random number in the N-power space of modulo 2 based on a first seed held by itself, wherein a semi-trusted third party synchronously generates the first random number based on the first seed held by itself. Similarly, a participant generates a second random number in the N-power space of modulo 2 based on a second seed held by itself, wherein the semi-trusted third party synchronously generates the second random number based on the second seed held by itself; a participant generates a third random number in the modulo 2 space based on a third seed held by itself, wherein the semi-trusted third party synchronously generates the third random number based on the third seed held by itself. At the same time, other participants generate a fourth random number in the N-power space of modulo 2 based on a fourth seed held by themselves, wherein the semi-trusted third party synchronously generates the fourth random number based on the fourth seed held by itself. Similarly, other participants generate a fifth random number in the modulo 2 space based on a fifth seed held by themselves, wherein the semi-trusted third party synchronously generates the fifth random number based on the fifth seed held by itself. Afterwards, the semi-trusted third party generates the fifth random number based on the first random number generated locally. The second random number u0, the third random number The fourth random number The fifth random number Based on constraints Calculate a sixth random number u1 and send the sixth random number u1 to other participants.
[0120] First random number The second random number u0, the third random number Generated locally by the participant, the fourth random number and the fifth random number It is generated locally by other participants. Therefore, the semi-trusted third party only needs to send the sixth random number u1 to other participants. The sending operation can be performed offline, and the offline communication volume is N bits.
[0121] In yet another embodiment, the Boolean-arithmetic-arithmetic triples may be generated based on an oblivious transfer protocol or a homomorphic encryption method.
[0122] In one embodiment, the first data may be a query field in a Structured Query Language (SQL) statement, and the second data may be a query condition in the SQL statement.
[0123] For example, the above data processing method can be executed when running the following SQL statement:
[0124] select sum(a)from table1 where b;
[0125] In another embodiment, in the field of machine learning, to calculate RELU(a), b=DRELU(a)=(a>0) can be calculated first, and then f(b,a) can be calculated.
[0126] FIG4 is a block diagram of a data processing device for secure computing according to an exemplary embodiment. The secure computing is used by two participants to collaboratively compute the product of first data and second data, where the first data is shared arithmetic between the two participants, and the second data is shared Boolean between the two participants. The device 300 is applied to any of the participants, and as shown in FIG4 , the device 300 includes:
[0127] A first generating module 301 is configured to generate first masked data based on a first arithmetic slice of the first data held by the participant and a first Boolean slice of the second data held by the participant, and to generate second masked data based on the first Boolean slice;
[0128] A sending module 302, configured to send the first masked data and the second masked data to other participants;
[0129] a receiving module 303 configured to receive third masked data and fourth masked data sent by the other party, wherein the third masked data is generated based on a second arithmetic slice of the first data held by the other party and a second Boolean slice of the second data held by the other party, and the fourth masked data is generated based on the second Boolean slice;
[0130] The second generating module 304 is configured to generate a first intermediate result based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data.
[0131] In the above technical solution, when calculating the product of first data in the form of arithmetic sharing between two participants and second data in the form of Boolean sharing between the two participants, the two participants can realize the direct multiplication calculation of the first data and the second data through a round of masked data exchange without converting the Boolean sharing into arithmetic sharing, thereby eliminating the communication volume of the two participants in the conversion between Boolean sharing and arithmetic sharing, which can greatly reduce the data communication volume for calculating the product of Boolean sharing and arithmetic sharing, and improve the business processing efficiency of secure computing.
[0132] Optionally, the first generating module 301 includes:
[0133] An acquisition submodule, configured to acquire a first random number in a modulo 2 N-power space;
[0134] a masking submodule, configured to perform masking processing on the first arithmetic slice using the first random number to obtain fifth masked data;
[0135] A generating submodule is configured to generate first mask data according to the fifth mask data and the first Boolean slice.
[0136] Optionally, the apparatus 300 further includes:
[0137] A first acquisition module is used to obtain a second random number in the N-th power space modulo 2;
[0138] The second generating module 302 is configured to generate a first intermediate result based on the first random number, the second random number, the first Boolean slice, the second mask data, the third mask data, the fourth mask data, and the fifth mask data.
[0139] Optionally, the first acquisition module is used to generate a first random number in the N-power space modulo 2 based on a first seed held by the participant, wherein the semi-trusted third party synchronously generates the first random number based on the first seed held by itself.
[0140] Optionally, the first acquisition module is used to generate a Boolean-arithmetic-arithmetic triple based on an oblivious transfer protocol or a homomorphic encryption method, wherein the Boolean-arithmetic-arithmetic triple includes the first random number.
[0141] Optionally, the generating submodule is configured to generate first mask data according to the fifth mask data and the first Boolean slice by using the following formula:
[0142] Wherein, C1 is the first mask data; b0 is the first Boolean fragment; δa0 is the fifth mask data.
[0143] Optionally, the first data is a query field in a structured query language statement, and the second data is a query condition in the structured query statement.
[0144] Optionally, the apparatus 300 further includes:
[0145] a second acquisition module, configured to acquire a second intermediate result generated by the other party, wherein the second intermediate result is generated based on the second Boolean slice, the first masked data, the second masked data, and the fourth masked data;
[0146] A determination module is configured to determine the sum of the first intermediate result and the second intermediate result as the product of the first data and the second data.
[0147] The present disclosure also provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the above-mentioned data processing method for secure computing provided by the present disclosure.
[0148] Reference is now made to FIG5 , which illustrates a schematic diagram of the structure of an electronic device (e.g., a terminal device or server) 600 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. The electronic device illustrated in FIG5 is merely an example and should not limit the functionality or scope of use of the embodiments of the present disclosure.
[0149] As shown in Figure 5, the electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. Various programs and data required for the operation of the electronic device 600 are also stored in the RAM 603. The processing device 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0150] Typically, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or by wire to exchange data. Although FIG. 5 shows the electronic device 600 with various devices, it should be understood that not all of the devices shown are required to be implemented or present. More or fewer devices may alternatively be implemented or present.
[0151] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0152] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0153] In some embodiments, the client and server can communicate using any currently known or later developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or later developed network.
[0154] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0155] The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device: generates first mask data based on the first arithmetic slice of the first data held by the participant and the first Boolean slice of the second data held by the participant, and generates second mask data based on the first Boolean slice; sends the first mask data and the second mask data to other participants; receives third mask data and fourth mask data sent by the other participants, wherein the third mask data is generated based on the second arithmetic slice of the first data held by the other participants and the second Boolean slice of the second data held by the other participants, and the fourth mask data is generated based on the second Boolean slice; generates a first intermediate result based on the first Boolean slice, the second mask data, the third mask data and the fourth mask data.
[0156] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0157] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0158] The modules described in the embodiments of this disclosure may be implemented in software or hardware. In some cases, the name of a module does not limit the module itself. For example, a sending module could also be described as a module that sends the first masked data and the second masked data to other parties.
[0159] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0160] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0161] According to one or more embodiments of the present disclosure, Example 1 provides a data processing method for secure computing, wherein the secure computing is used by two participants to collaboratively compute the product of first data and second data, wherein the first data is in an arithmetic shared form between the two participants, and the second data is in a Boolean shared form between the two participants. The method is applied to any of the participants and includes:
[0162] generating first masked data based on a first arithmetic slice of the first data held by the participant and a first Boolean slice of the second data held by the participant, and generating second masked data based on the first Boolean slice;
[0163] sending the first masked data and the second masked data to other parties;
[0164] receiving third masked data and fourth masked data sent by the other party, wherein the third masked data is generated based on the second arithmetic slice of the first data held by the other party and the second Boolean slice of the second data held by the other party, and the fourth masked data is generated based on the second Boolean slice;
[0165] A first intermediate result is generated based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data.
[0166] According to one or more embodiments of the present disclosure, Example 2 provides the method of Example 1, wherein generating first masked data according to a first arithmetic slice of the first data held by the participant and a first Boolean slice of the second data held by the participant includes:
[0167] Get the first random number in the N-power space modulo 2;
[0168] performing masking processing on the first arithmetic slice using the first random number to obtain fifth masked data;
[0169] First mask data is generated according to the fifth mask data and the first Boolean slice.
[0170] According to one or more embodiments of the present disclosure, Example 3 provides the method of Example 2, wherein the method further includes:
[0171] Obtain a second random number in the N-power space modulo 2;
[0172] The generating a first intermediate result based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data includes:
[0173] A first intermediate result is generated based on the first random number, the second random number, the first Boolean slice, the second masked data, the third masked data, the fourth masked data, and the fifth masked data.
[0174] According to one or more embodiments of the present disclosure, Example 4 provides the method of Example 2, wherein obtaining a first random number in a modulo 2 N-power space includes:
[0175] Based on a first seed held by the participant, a first random number in a modulo 2 power N space is generated, wherein a semi-trusted third party synchronously generates the first random number based on the first seed held by itself.
[0176] According to one or more embodiments of the present disclosure, Example 5 provides the method of Example 2, wherein obtaining a first random number in a modulo 2 N-power space includes:
[0177] A Boolean-arithmetic-arithmetic triple is generated based on an oblivious transfer protocol or a homomorphic encryption method, wherein the Boolean-arithmetic-arithmetic triple includes the first random number.
[0178] According to one or more embodiments of the present disclosure, Example 6 provides the method of Example 2, wherein generating first mask data according to the fifth mask data and the first Boolean slice includes:
[0179] According to the fifth mask data and the first Boolean slice, the first mask data is generated by the following formula:
[0180] Wherein, C1 is the first mask data; b0 is the first Boolean fragment; δa0 is the fifth mask data.
[0181] According to one or more embodiments of the present disclosure, Example 7 provides the method described in any one of Examples 1-6, wherein the first data is a query field in a structured query language statement, and the second data is a query condition in the structured query statement.
[0182] According to one or more embodiments of the present disclosure, Example 8 provides the method of any one of Examples 1-6, further comprising:
[0183] Obtaining a second intermediate result generated by the other participant, wherein the second intermediate result is generated based on the second Boolean slice, the first masked data, the second masked data, and the fourth masked data;
[0184] A sum of the first intermediate result and the second intermediate result is determined as a product of the first data and the second data.
[0185] According to one or more embodiments of the present disclosure, Example 9 provides a data processing device for secure computing, wherein the secure computing is used by two participants to collaboratively compute the product of first data and second data, wherein the first data is in an arithmetic shared form between the two participants, and the second data is in a Boolean shared form between the two participants. The device is applied to any of the participants, and includes:
[0186] a first generating module, configured to generate first masked data based on a first arithmetic slice of the first data held by the participant and a first Boolean slice of the second data held by the participant, and generate second masked data based on the first Boolean slice;
[0187] a sending module, configured to send the first masked data and the second masked data to other participants;
[0188] a receiving module, configured to receive third masked data and fourth masked data sent by the other party, wherein the third masked data is generated based on a second arithmetic slice of the first data held by the other party and a second Boolean slice of the second data held by the other party, and the fourth masked data is generated based on the second Boolean slice;
[0189] The second generating module is configured to generate a first intermediate result based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data.
[0190] According to one or more embodiments of the present disclosure, Example 10 provides a computer-readable medium having a computer program stored thereon, which implements the steps of the method described in any one of Examples 1-8 when executed by a processing device.
[0191] According to one or more embodiments of the present disclosure, Example 11 provides an electronic device, including:
[0192] a storage device having a computer program stored thereon;
[0193] A processing device is used to execute the computer program in the storage device to implement the steps of the method described in any one of Examples 1-8.
[0194] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also includes other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned disclosed concepts. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0195] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0196] Although the subject matter has been described using language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims. Regarding the apparatus in the above-described embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method and will not be elaborated upon here.
Claims
1. A data processing method for secure computing, wherein the secure computing is used by two participants to collaboratively compute the product of first data and second data, wherein the first data is in an arithmetic shared form between the two participants, and the second data is in a Boolean shared form between the two participants, characterized in that: The method is applied to any of the participants, and the method includes: generating first masked data according to a first arithmetic slice of the first data held by the participant and a first Boolean slice of the second data held by the participant, and generating second masked data according to the first Boolean slice; sending the first masked data and the second masked data to other parties; receiving third masked data and fourth masked data sent by the other participants, wherein the third masked data is generated based on a second arithmetic slice of the first data held by the other participants and a second Boolean slice of the second data held by the other participants, and the fourth masked data is generated based on the second Boolean slice; A first intermediate result is generated based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data.
2. The method according to claim 1, wherein: The generating first masked data according to the first arithmetic slice of the first data held by the participant and the first Boolean slice of the second data held by the participant comprises: Get the first random number in the N-power space modulo 2; Using the first random number to perform masking processing on the first arithmetic slice to obtain fifth masked data; First mask data is generated according to the fifth mask data and the first Boolean slice.
3. The method according to claim 2, further comprising: Obtain a second random number in the N-power space modulo 2; The generating a first intermediate result based on the first Boolean slice, the second mask data, the third mask data, and the fourth mask data comprises: A first intermediate result is generated based on the first random number, the second random number, the first Boolean slice, the second masked data, the third masked data, the fourth masked data, and the fifth masked data.
4. The method according to claim 2, wherein: The obtaining of a first random number in a modulo 2 N-power space includes: Based on a first seed held by the participant, a first random number in a modulo 2 power space is generated, wherein a semi-trusted third party synchronously generates the first random number based on the first seed held by itself.
5. The method according to claim 2, wherein: The obtaining of a first random number in a modulo 2 N-power space includes: A Boolean-arithmetic-arithmetic triplet is generated based on an oblivious transfer protocol or a homomorphic encryption method, wherein the Boolean-arithmetic-arithmetic triplet includes the first random number.
6. The method according to claim 2, wherein: The step of generating first mask data according to the fifth mask data and the first Boolean slice comprises: According to the fifth mask data and the first Boolean slice, the first mask data is generated by the following formula: Wherein, C1 is the first mask data; b0 is the first Boolean slice; δa0 is the fifth mask data.
7. The method according to any one of claims 1 to 6, wherein: The first data is a query field in a structured query language statement, and the second data is a query condition in the structured query statement.
8. The method according to any one of claims 1 to 6, wherein: The method further comprises: Obtaining a second intermediate result generated by the other party, wherein the second intermediate result is generated based on the second Boolean slice, the first masked data, the second masked data, and the fourth masked data; A sum of the first intermediate result and the second intermediate result is determined as a product of the first data and the second data.
9. A data processing device for secure computing, wherein the secure computing is used for two participants to collaboratively compute the product of first data and second data, wherein the first data is in an arithmetic shared form between the two participants, and the second data is in a Boolean shared form between the two participants, wherein: The device is applied to any of the participants, and the device includes: a first generating module configured to generate first masked data according to a first arithmetic slice of the first data held by the participant and a first Boolean slice of the second data held by the participant, and to generate second masked data according to the first Boolean slice; a sending module, configured to send the first masked data and the second masked data to other participants; a receiving module configured to receive third masked data and fourth masked data sent by the other participants, wherein the third masked data is generated based on a second arithmetic slice of the first data held by the other participants and a second Boolean slice of the second data held by the other participants, and the fourth masked data is generated based on the second Boolean slice; The second generating module is configured to generate a first intermediate result based on the first Boolean slice, the second mask data, the third mask data and the fourth mask data.
10. A computer readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processing device, the data processing method according to any one of claims 1 to 8 is implemented.
11. An electronic device, comprising: a storage device having a computer program stored thereon; as well as A processing device configured to execute the computer program in the storage device to implement the method of claims 1 to 8. Any data processing method described in claim 1.
Citation Information
Patent Citations
Selection problem processing method for protecting data privacy
CN113158239A
Sharing form conversion method and device for target data
CN115442033A
Sharing form conversion method and device for target data
CN115766156A
Boolean arithmetic sharing conversion method and device for protecting private data
CN116821961A
Data processing method and device for security computing, medium and electronic equipment
CN117556441A