Privacy-preserving pattern matching
By employing cryptographic secure multiparty computation with inverted boolean representation for pattern matching, the inefficiencies and secrecy issues in existing techniques are addressed, achieving substantial performance improvements and robust privacy protection.
Patent Information
- Application Number
- PCT/EP2024/084944
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-15
- Filing Date
- 2024-12-05
- Publication Date
- 2025-06-19
AI Technical Summary
Existing privacy-preserving computation techniques for pattern matching are inefficient and do not adequately protect the secrecy of the sequence and pattern information during multi-party computation.
The use of cryptographic secure multiparty computation (MPC) with inverted boolean representation to efficiently match a sequence of symbols to a pattern, where the comparison values are computed as subtractions and boolean operators are applied to these values, allowing for efficient pattern matching while keeping the sequence and pattern information secret.
This approach significantly reduces computational resources and bandwidth usage by up to 50x for certain string matching operations, while maintaining strong privacy characteristics by keeping the sequence and pattern information secret throughout the computation.
Smart Images

Figure EP2024084944_19062025_PF_FP_ABST
Abstract
Description
[0001] PRIVACY-PRESERVING PATTERN MATCHING
[0002] FIELD OF THE INVENTION
[0003] The invention relates to a cryptographic system for performing a privacypreserving computation on secret data. The invention further relates to a cryptographic device for use in such a system; to a corresponding computer-implemented method; and to a computer-readable medium.
[0004] BACKGROUND OF THE INVENTION
[0005] There is a growing demand for privacy enhancing technologies (PETs), i.e., data processing techniques that intrinsically protect the privacy of the data they operate on. For example, with the cryptographic technique of secure multi-party computation (MPC), multiple parties can perform a computation on their joint input using a distributed cryptographic protocol, such that each party learns nothing beyond the output of computation and his own (private) input.
[0006] One reason for the growing demand for PETs is that citizens are becoming increasingly dependent on the digital information stored about them by various companies and institutions. Because of this increasing dependence, the consequences of a breach of personal data are getting increasingly severe. And due to the worldwide surge of cybercrime and nation-state-sponsored cyber espionage, the risk of a data breach has increased sharply in recent years. Also, data-based collaborations between separate entities (like companies, hospitals, local governments) usually implies that personal data is copied between the entities, which poses the risk of uncontrolled spreading of data, in particular personal information. PETs can enable data collaboration between entities without the need for sharing the data in clear-text form. Another factor driving demand for PETs is the emergence of legal frameworks for data protection, such as the European GDPR and the Californian CCPA legislation, and their mandatory compliance. In the context of such frameworks, PETs are valuable as technical safeguards, and typically provide concrete instantiations of abstract legal notions.
[0007] One important functionality for PETs is to perform a private search in a sensitive dataset. For example, the different records of the dataset may be contributed by different parties (vertically partitioned data), and / or different features of the same record may be contributed by different parties (horizontally partitioned data). For example, the task may be to find a specific string in a text record, or, more generally, to match a text record to a pattern, as represented, e.g., by a regular expression. Such a search functionality may be provided per se, e.g., the functionality may output the number of matching records or the records themselves; or may be part of a larger functionality, e.g., an encrypted database functionality based on MPC. In such an encrypted database, the data may be stored in a distributed way across multiple cryptographic devices, and the cryptographic devices may allow to perform various operations on encrypted database tables, where the resulting tables can remain encrypted or can be output to a user, for example. In such a case, the string matching may be part of a filtering functionality, for example.
[0008] In F. Kerschbaum, "Practical private regular expression matching", proceedings IFIP International Information Security Conference 2006, a technique for privacy-preserving regular expression matching based on MPC is presented. This technique works in the setting where one party has a text string and another party has a regular expression. A first variant hides both respective inputs to the other parties but is slow. A second variant provides better performance, but only limited secrecy.
[0009] SUMMARY OF THE INVENTION
[0010] It would be desirable to provide techniques for performing a privacypreserving computation that involves pattern matching, with improved privacy and / or efficiency characteristics.
[0011] In accordance with a first aspect of the invention, a cryptographic system for performing a privacy-preserving computation is provided, as defined by claim 1. In accordance with further aspects of the invention, a cryptographic device for use in such a system; and a cryptographic method of performing such a privacy-preserving computation are provided, as defined by claims 13 and 14, respectively. In accordance with an aspect of the invention, a computer-readable medium is provided, as defined by claim 15.
[0012] The techniques described herein make use of cryptographic secure multiparty computation (MPC) to perform a privacy-preserving computation on secret data. As is known per se, MPC is a cryptographic technique in which a computation is performed in a distributed way between multiple cryptographic devices in such a way that the inputs, intermediate values, and / or outputs of the computation remain hidden from the parties performing the computation. Such values that remain hidden from the parties may be referred to as the secret values of the MPC. In general, a secret value of the MPC may have the property that a limited number of parties, up to a given threshold, does not know the secret value. However, a number of parties that exceeds the threshold may be able to derive the secret value. A secret value can for example be a threshold encryption, of which the decryption key is distributed among the parties; or a secret sharing, also referred to herein simply as a sharing. A sharing may be defined as a distributed representation of a value into shares of the respective parties such that a limited number of the shares, up to the given threshold, does not allow to derive the represented value. Although the term "secret share" is most commonly used for MPC techniques using so-called arithmetic secret sharing, also other MPC techniques such as garbled circuits are considered herein to operate on secret shares. In multi-party computation, through the use of secret values and of various protocols that allow to perform operations on secret values, e.g., in secret-shared or threshold encrypted form, various computations can be performed, while keeping the underlying values hidden from the parties that perform them, thus providing privacy-preserving computation. The design of efficient cryptographic protocols for implementing specific MPC operations is the topic of a significant amount of research.
[0013] Various embodiments herein relate to the use of MPC to match a sequence of zero or more symbols to a pattern. For example, the sequence can be a string, comprising zero or more characters. The symbols may be secret values of the multi-party computation. In particular, in some embodiments, none of the computation devices that perform the MPC, know the values of the symbols. Optionally, also the length of the sequence may be secret.
[0014] The pattern may be known to the cryptographic devices, but may optionally be parametrised by information that is not known to the cryptographic devices; for example, a set of one or more symbols (e.g., characters), and / or a set of one or more subsequences (e.g., substrings). Also the lengths of the subsequences may or may not be known to the cryptographic devices. For example, it may be known to the cryptographic devices that the pattern represents whether or not the sequence of symbols contains a given subsequence, or that the pattern represents whether or not the sequence of symbols is equal to a given subsequence. However, the specific subsequences in these examples, and optionally their lengths, can remain hidden from the cryptographic devices.
[0015] In particular, the pattern may correspond to a regular expression, that is optionally parametrized by a set of subsequences. In particular, the pattern may be representable as a regular expression, or as a regular grammar, e.g., the pattern may be ",*abc", matching zero or more instances of any character, followed by the character "a", followed by the character "b", followed by the character "c". The language of the grammar may optionally include the one or more subsequences as additional symbols, e.g., "(?1)", etc. For example, the pattern ",(?1)a" may match any symbol (excluding subsequences); followed by the first specified subsequence, followed by the character "a". Interestingly, as discussed in more detail elsewhere, by using a regular expression as a pattern, but allowing subsequences to occur in that regular expression, matching may be implemented efficiently by allowing the cryptographic devices to know the regular expression, while still to allowing the pattern to contain secret information, in the form of the subsequences, that can remain hidden to the cryptographic devices.
[0016] Regardless of the exact form of the pattern, the inventors realized that a main challenge of implementing pattern matching under multi-party computation efficiently, comes from the fact that pattern matching involves comparing symbols of the sequence, to candidate symbols defined by the pattern. For example, in order to match a string to the pattern ",(?1)a", the respective characters of the string may be compared to the symbol "a" occurring in the pattern, and / or to the symbol(s) occurring in the subsequence. To perform such a comparison, conventionally, a secure multi-party comparison protocol may be used. Such a protocol may take as input two secret values [x] and [y], and may output a secret comparison value [b] that is equal to 1 if x and y are equal, and 0 otherwise. Such a secure comparison protocol is described for example in the PhD thesis "Design of large scale applications of secure multiparty computation: secure linear programming" by S.J.A. de Hoogh, Eindhoven University of Technology. A disadvantage of such secure comparison protocols is however that they are relatively costly to perform. In particular, performance scales in the maximum bit length of the input values x and y.
[0017] Interestingly, however, the inventors envisaged an alternative way to perform the comparison between the symbols of the sequence and the symbols defined by the pattern. Namely, the inventors realized that, for values [x] and [y], the subtraction of the symbols, e.g., [x] - [y] may be interpreted as a comparison value representing an equality comparison of the values [x] and [y]; namely, in a representation where a zero value represents true, i.e., equality, and a non-zero value represents false, i.e. , inequality. This representation may be referred to as an inverted boolean operation, since the traditional meaning of zero as false may essentially be inverted. Apart from this inversion, another difference is that any non-zero value may be interpreted as false, as opposed to a regular binary representation using just using values 0 and 1. The subtraction may be the subtraction operation of the mathematical group G over which the multi-party computation is defined, e.g., arithmetic subtraction in the group of integers modulo a modulus m; or XOR in a binary extension field.
[0018] Using the inverted boolean representation to compare symbols is advantageous because, in this representation, an equality comparison can be performed much more efficiently than performing a secure comparison with a regular binary output. In particular, if the subtraction of the MPC group is used, then the comparison value can in many cases be computed using only local computation and no communication between the cryptographic devices. Moreover, as the inventors realized, it is possible not only to perform comparisons that have inverted boolean outputs, but also to efficiently apply boolean operators to inverted booleans. In particular, boolean AND and boolean OR can be implemented efficiently on inverted booleans; and, as the inventors realized, pattern matching can to a large degree (and in many cases even completely) be implemented in terms of these boolean operators.
[0019] Thus, by determining comparison values as inverted booleans, and applying boolean operators to them, a string matching can be implemented very efficiently, in particular with the use of no, or much fewer, traditional binary comparisons. Through the use of inverted booleans, for typical string matching computations represented by regular expressions, a 8-9x reduction of computational resources and a 6-7x reduction of bandwidth was observed. For certain string matching operations, in particular finding or checking equality to a given subsequence, the observed performance improvement was even greater, up to a 50x improvement for some inputs. See elsewhere in this specification for details.
[0020] Moreover, this improved efficiency is combined with favourable privacy characteristics: both the sequence of characters to be matched against the pattern, and any subsequences occurring in that pattern, may remain secret to the cryptographic devices carrying out the multi-party computation. In particular, it is possible to apply the matching on inputs that are provided by others than the cryptographic devices themselves, and / or to apply the matching on inputs that are themselves the result of other computations performed under multi-party computation. In particular, it is possible to hide the exact length of the sequence and / or sequences to the cryptographic devices.
[0021] Optionally, as part of the matching, a boolean AND may be applied to two secret input values in inverted boolean representation, e.g., one of them being the comparison value. The boolean AND may be performed by computing a linear combination of the input values. Indeed, such a linear combination may be zero for zero inputs, corresponding to true; and may likely be non-zero if an input is non-zero, corresponding to false. For example, the respective coefficients may be randomly generated from a large domain, such that the probability of the linear combination being zero for non-zero inputs, is negligibly small, e.g., smaller than 2A-20, 2A-30, or 2A-40. Interestingly, the coefficients may be known to the cryptographic devices performing the multi-party computation, and can e.g. be generated using a pseudo-random generator from a seed agreed upon by the cryptographic devices. Thereby, the boolean AND operator may be implemented particularly efficiently: in many cases, even more efficiently than an AND on booleans in the traditional representation, e.g., without communication between the cryptographic devices. Instead or in addition, as part of the matching, a boolean OR may be applied to two secret input values in inverted boolean representation, e.g., one of them being the comparison value. The boolean OR may be performed by computing a product of the input values. The product may be zero, and may accordingly represent true, if and only if one or more of the inputs are zero and accordingly represent true. Since multiplication is typically an efficient operation under MPC, e.g., much more efficient than a secure comparison, also boolean OR may be implemented efficiently.
[0022] Optionally, the pattern that is being matched, may comprises a given subsequence to be contained in the sequence, or may comprise a given subsequence to be equal to the sequence. For example, the sequence of symbols may match the pattern if and only the sequence contains the subsequence, or if and only if the sequence is equal to the subsequence. More complex patterns are also possible, e.g., the sequence of symbols may match the pattern if it contains at least one of a set of one or more subsequences, or if it is equal to one of a set of one or more subsequences. Further examples are provided herein. In general, the symbols and / or length of the subsequence(s) can optionally be secret values of the multi-party computation. Thereby, the general structure of the pattern, e.g., its structure as an automaton, may be known to the cryptographic devices, while still allowing sensitive information represented by subsequences of the pattern to remain secret.
[0023] Optionally, the pattern may be represented by an automaton. A cryptographic device performing the pattern matching may store a representation of the automaton, e.g., may store a list of states and / or a list of transitions of the automaton. The automaton can be a non-deterministic finite automaton (NDA), or a deterministic finite automaton (DFA), for example.
[0024] The automaton may comprise one or more states and one or more transitions. For example, the automaton may comprise one or more respective transitions labelled by a respective symbol to be matched. Instead or in addition, the automaton may comprise one or more respective transitions labelled by a respective interval of possible symbols to be matched. Although such a transition may alternatively be considered as respective transitions for the respective symbols of the interval, interestingly, processing the interval as a unit may be more efficient as also discussed elsewhere. Instead or in addition, the automaton may comprise one or more transitions labelled by an indicator that any symbol may be matched. Instead or in addition, the automaton may comprise one or more transitions labelled by an indicator that an empty subsequence is matched (also referred to as an e-transition). Instead or in addition, the automaton may comprise one or more respective transitions labelled by a respective indicator of a subsequence to be matched. Further types of transition are also possible. In particular, the automaton may comprises a source state, a target state, and a transition from the source state to the target state, wherein the transition is labelled by a candidate symbol. A current symbol of the input sequence may be compared to this candidate symbol, resulting in a comparison value in inverted boolean representation. The comparison value may be used to update a state of the automaton according to the current symbol, in order words to evaluate the transition function of the automaton according to the current symbol.
[0025] Specifically, the comparison value may be used to determine a state value for the target state based on a state value of the source state and the comparison value. The state value may be represented as an inverted boolean and may represent whether, according to the automaton, it is possible to reach the target state from an initial state of the automaton, by following transitions according to the symbols of the input sequence up to the current symbol. Such updating of the state may be represented as a boolean formula in the state value and the comparison value involving ANDs and ORs. For example, the target state value may be a boolean AND of the comparison value and the source state value. Thus, it may be evaluated particularly efficiently using the described techniques.
[0026] Optionally, the automaton may comprise multiple respective transitions from respective source states to the target state. In such a case, the state value for the target state may be determined based on respective state values of the respective source states, and based on respective comparison values for the respective transitions. For example, the target state value may be computed as, or based on, an OR of the ANDs of the respective source state values and comparison values. Again, such a boolean formula may be evaluated particularly efficiently using the described techniques.
[0027] Optionally, the automaton may comprise a transition from a source state to a target state, labelled by an interval of possible symbols to be matched. It is possible to process such an interval in several ways. One way is to process the interval in terms of equality comparisons, in inverted boolean representation, for the respective symbols in the interval. For example, an AND of the source state value with an OR of the equality comparisons may be computed. Another way is to process the interval in terms of order comparisons, e.g., less-than, less-than-or-equal, greater-than, greater-than-equal, or ternary comparisons, of the current symbol to the endpoints of the interval. Such an order comparison can for example be performed by performing a conventional order comparison, e.g., resulting in a binary or ternary output, and by converting the output of the order comparison to inverted boolean representation.
[0028] The use of inverted booleans may be preferred for smaller, known intervals. Order comparisons can be used if one or both endpoints of the interval are secret values of the multi-party computation. Interestingly, moreover, the inventors realized that for larger intervals, it can be beneficial to use an order comparison and convert it to an inverted boolean. At the same time, for one or more other transitions of the automaton, equality comparisons as inverted booleans may be used. In particular, it may be advantageous to use equality comparisons for relatively large intervals. For example, use of equality comparisons or order comparisons may be selected depending on the size of the interval.
[0029] An order comparison result may optionally be used in multiple transitions, e.g., for multiple states of the automaton that have a common endpoint, thereby reducing the overhead of using order comparisons. Accordingly, also an amount of possible re-use may be used to select equality or order comparisons. In particular, an order comparison that is performed may be a ternary comparison between the current symbol and an endpoint value. Such a ternary comparison may have three possible outputs, indicating respectively whether the current symbol is smaller than, equal to, or larger than the endpoint value. Interestingly, from a ternary comparison output between a symbol S and an endpoint value V, it is possible to efficiently derive at least two of: an inverted boolean value indicating whether S <= V; an inverted boolean indicating whether S <= V-1; an inverted boolean indicating whether S >= V; and an inverted boolean indicating whether S >= V+1. Accordingly the ternary comparison value may be used for multiple endpoints and / or for a lower and a higher endpoint of an interval, thereby improving the amount of re-use possible and thereby efficiency.
[0030] Optionally, the length of the sequence of symbols may be a secret value of the multi-party computation. Accordingly, the cryptographic devices carrying out the multiparty computation may not individually know the exact length, although a maximum may be known. This way, data protection of the input data of the matching may be further improved. A match value for the pattern based may be determined based on a boolean length indicator value for a given length. The length indicator value may indicate that the sequence length is equal to a given length L, and can for example be determined as an inverted boolean comparison against a given possible length. By using the length indicator value in pattern matching, effectively, it may be verified that a found pattern relates to symbols of the sequence that do not exceed the length. Thereby, the secret length can be taken into account in a privacy-preserving way.
[0031] Optionally, the pattern comprises a subsequence of symbols. E.g., the pattern may specify that the sequence of symbol is equal to or contains the subsequence, or the subsequence may be part of a regular expression, e.g., in the regular expression "a((?1)|b)c", the sequence may comprise the character a, followed by either the character b or the subsequence, followed by the character c. In such cases, the length of the subsequence may be a secret value of the multi-party computation, further improving data protection of the inputs of the matching. In this case, a match value for the subsequence may be determined based on a boolean length indicator value for a given length. Also this length indicator value may be determined as an inverted boolean by comparing the secret length to a given possible length. By using the length indicator value for the subsequence, effectively, it may be achieved that parts of the subsequence that exceed its length, are not matched.
[0032] Optionally, the pattern may comprise a further subsequence of symbols. Also the length of the further subsequence may be a secret value of the multi-party computation. For example, the pattern may dictate that two subsequences do or can follow each other. In such cases, the matching may take into account the possibility that both subsequences are empty by combining an indicator value indicating that the first subsequence is empty, and an indicator value indicating that the second subsequence is empty. For example, as part of the matching of the current symbol, a boolean value may be determined that depends on both indicator values.
[0033] For example, in an automaton having a first subsequence transition from a first state to a second state, and a second subsequence transition from the second state to a third state, the state value of the third state may be determined based on combining the state value for the first state, the indicator value that the first subsequence is empty, and the indicator value that the second subsequence is empty. Namely, in the case that the subsequences are empty, the respective transitions may effectively correspond to E- transitions of the automaton. Accordingly, the state value for the third state may be determined by performing an oblivious propagation of these s-transitions. For example, the state value of the second state may be ORed with the AND of the first state value and the indicator value for the first subsequence, and the state value of the third state may be ORed with the AND of the updated second state value and the indicator value for the second subsequence. Such a propagation may be performed after evaluating the state transitions for a current symbol, and can be performed e.g. by, for a respective target state, ORing the state value by the state value of the source state and an indicator whether the subsequence of the corresponding subsequence transition is empty. Thus, subsequence lengths may be kept private while still allowing their correct matching even if they are empty.
[0034] Optionally, a match result for the pattern may be determined in the inverted boolean representation, and then converted to a regular boolean representation. For this, a conventional multi-party equality comparison protocol may be used, e.g. where the match result is determined to be 1 if the inverted boolean representation is zero, and 0 otherwise. Although this equality comparison protocol may be relatively costly, interestingly, it may be applied only to the matching result and not at all, or much less, as part of the matching itself. It is also possible to open the result in inverted boolean representation without converting to a regular boolean, however.
[0035] It will be appreciated by those skilled in the art that two or more of the above- mentioned embodiments, implementations, and / or optional aspects of the invention may be combined in any way deemed useful. Modifications and variations of any system and / or any computer readable medium, which correspond to the described modifications and variations of a corresponding computer-implemented method, can be carried out by a person skilled in the art on the basis of the present description, and the other way round as well.
[0036] BRIEF DESCRIPTION OF THE DRAWINGS
[0037] These and other aspects of the invention will be apparent from and elucidated further with reference to the embodiments described by way of example in the following description and with reference to the accompanying drawings, in which:
[0038] Fig. 1 shows a cryptographic device;
[0039] Fig. 2 shows a cryptographic system;
[0040] Fig. 3a shows a detailed example of matching a sequence to a subsequence;
[0041] Fig. 3b shows a detailed example of matching a sequence to a subsequence;
[0042] Fig. 4a shows a detailed example of an automaton representing a pattern;
[0043] Fig. 4b shows a detailed example of matching a sequence to a pattern represented by an automaton;
[0044] Fig. 4c shows a detailed example of matching a sequence to a pattern represented by an automaton;
[0045] Fig. 5a shows a detailed example of matching a sequence to a pattern represented by an automaton;
[0046] Fig. 5b shows a detailed example of an automaton representing a pattern;
[0047] Fig. 6 shows a computer-implemented method;
[0048] Fig. 7 shows a computer-readable medium comprising data.
[0049] It should be noted that the figures are purely diagrammatic and not drawn to scale. In the figures, elements which correspond to elements already described may have the same reference numerals.
[0050] DETAILED DESCRIPTION OF EMBODIMENTS
[0051] Fig. 1 shows a cryptographic device 100 for use in a cryptographic system as described herein, e.g., in Fig. 3. The cryptographic system may be for performing a privacypreserving computation on secret data. The computation may be performed as a cryptographic secure multi-party computation between multiple cryptographic devices, including device 100. The privacy-preserving computation may comprise matching a sequence of zero or more symbols to a pattern.
[0052] The device 100 may comprise a data interface 120 for accessing data 030 representing the sequence to be matched to the pattern. The symbols and / or the length of the sequence 030 may be secret values of the multi-party computation. For example, the sequence 030 may be represented by a number L of symbols, e.g, at most or at least 10, at most or at least 100, or at most or at least 500 symbols, and optionally by a length indicator, e.g., as a numeric value or a bit vector, indicating a length N of the sequence. For example, the sequence may correspond to the first N of the L symbols. The symbols can for example be characters. A symbol typically corresponds to a fixed and known number of elementary values, e.g., secret shares, of the multi-party computation.
[0053] Data interface 120 may, instead of or in addition to the input sequence, be for accessing data representing the pattern to be matched. The pattern can be known to device 100, e.g., in some embodiments the pattern may be represented without the use of secret shares. It is also possible however that the pattern is parametrized by secret values of the multi-party computation, e.g., by one or more symbols occurring as labels and / or endpoints of transitions, and / or by one or more subsequences occurring in the pattern. For some or all of the subsequences, the length may be a secret value of the multi-party computation, as described for the sequence to be matched. As an example, the pattern may be presented by an automaton, where the structure of the automaton per se is known to device, and in that sense a public value of the multi-party computation; but the automaton may comprise secret parameters, in particular one or more transition labels and / or subsequences referred to by one or more transition labels.
[0054] Generally, secret values, such as the input sequence and / or pattern parameters, may be stored in various ways, as also discussed elsewhere; e.g., as secret shares or the like.
[0055] For example, as also illustrated in Fig. 1, the input interface may be constituted by a data storage interface 120 which may access the data 030 from a data storage 021. For example, the data storage interface 120 may be a memory interface or a persistent storage interface, e.g., a hard disk or an SSD interface, but also a personal, local or wide area network interface such as a Bluetooth, ZigBee or Wi-Fi interface or an ethernet or fibreoptic interface. The data storage 021 may be an internal data storage of the system 100, such as a hard drive or SSD, but also an external data storage, e.g., a network- accessible data storage. In some embodiments, respective data may each be accessed from or distributed across different data storages, e.g., via a different subsystem of the data storage interface 120. Each subsystem may be of a type as is described above for data storage interface 120.
[0056] The device 100 may further comprise a processor subsystem 140 which may be configured to, during operation of the system 100, match a current symbol of the sequence to the pattern. By matching respective current symbols of the sequence 030, a match value for the sequence may be determined. Processor subsystem 140 may be configured to, using the multi-party computation, determining a secret comparison value representing an equality comparison of the current symbol and a candidate symbol defined by the pattern. The comparison value may be computed as a subtraction of the current symbol and the candidate symbol. The comparison value may have an inverted boolean representation, wherein a zero value represents true and a non-zero value represents false. Processor subsystem 140 may be configured to, using the multi-party computation, obtain a further secret boolean value in the inverted boolean representation. Processor subsystem 140 may be configured to apply a boolean operator to the secret comparison value and the further secret boolean value to obtain a result of the boolean operator in inverted boolean representation.
[0057] As also discussed with respect to Fig. 3, the device 100 may be further configured to provide inputs to the multi-party computation, e.g., to input the sequence to be matched to the pattern, and / or one or more parameters of the pattern, to the multi-party computation, e.g. by secret-sharing, encrypting, or otherwise masking them. Instead or in addition, the device 100 may be further configured to obtain outputs from the multi-party computation, e.g., to obtain a match result for the pattern or a result of a further multi-party computation applied to the match result.
[0058] The system 100 may also comprise a communication interface 180 configured for communication 126 with at least one further cryptographic device of the cryptographic system. Communication interface 180 may internally communicate with processor subsystem 140 via data communication 125. Communication interface 180 may be arranged for direct communication with the other devices, e.g., using USB, IEEE 1394, or similar interfaces. As illustrated in the figure, communication interface 180 may also communicate over a computer network 099, for example, a wireless personal area network, an internet, an intranet, a LAN, a WLAN, etc. For instance, communication interface 180 may comprise a connector, e.g., a wireless connector, an Ethernet connector, a Wi-Fi, 4G or 4G antenna, a ZigBee chip, etc., as appropriate for the computer network. Communication interface 180 may be an internal communication interface, e.g., a bus, an API, a storage interface, etc. In general, each device described in this specification, including but not limited to the system 100 of Fig. 1 may be embodied as, or in, a single device or apparatus, such as a workstation or a server. The device may be an embedded device. The device or apparatus may comprise one or more microprocessors which execute appropriate software. For example, the processor subsystem of the respective system may be embodied by a single Central Processing Unit (CPU), but also by a combination or system of such CPUs and / or other types of processing units. The software may have been downloaded and / or stored in a corresponding memory, e.g., a volatile memory such as RAM or a non-volatile memory such as Flash. Alternatively, the processor subsystem of the respective system may be implemented in the device or apparatus in the form of programmable logic, e.g., as a Field-Programmable Gate Array (FPGA). In general, each functional unit of the respective system may be implemented in the form of a circuit. The respective system may also be implemented in a distributed manner, e.g., involving different devices or apparatuses, such as distributed local or cloud-based servers.
[0059] Fig. 2 shows a cryptographic system 010 for performing a privacy-preserving computation as a cryptographic secure multi-party computation. The computation may comprise matching a sequence of zero or more symbols to a pattern, as described in more detail elsewhere. The cryptographic system 010 may in general comprise multiple input devices, multiple different cryptographic devices, and at least one result device, where the sets of input, cryptographic, and result devices may overlap with each other. As illustrated, the devices typically communicate over a computer network 099, e.g., the internet or a local network.
[0060] In particular, shown in the figure are three cryptographic devices CP1 , 221 ; CP2, 222; and CP3, 223. The cryptographic devices may be based on cryptographic device 100 of Fig. 1. The number of cryptographic devices that is used can vary depending on the particular technique used for the multi-party computation and the security properties which are desired. For example, the number of cryptographic devices CPi can be two, three, or more.
[0061] The cryptographic devices CPi may be configured to perform a secure multiparty computation (also known per se as multi-party computation, secure computation, or MPC). Generally, a multi-party computation may be a distributed protocol between the cryptographic devices for performing a computation in a privacy-preserving way. Depending on the specific technique used, MPC may ensure privacy and / or correctness of the computation against an attacker that eavesdrops or controls one or more (but typically not all) of the cryptographic devices. As known per se, any computation can be performed as a multi-party computation (in other words, “under the multi-party computation”), but concrete computational and communication efficiency can in general greatly depend on how exactly the computation is performed.
[0062] In particular, the multi-party computation can be performed based on one of the following techniques:
[0063] - based on secret sharing, in particular arithmetic secret sharing such as Shamir secret sharing, replicated secret sharing, or additive secret sharing. For example, the multi-party computation can be based on the techniques described in Shamir, “How to Share a Secret”, Communications ACM, 1979; Ben-Or, Goldwasser, Wigderson, “Completeness Theorems for Non-Cryptographic Fault-Tolerant Distributed Computation (Extended Abstract)”, Proceedings of the 20th Annual ACM Symposium on Theory of Computing, 1988; Chaum, Crepeau, Damgaard, “Multiparty Unconditionally Secure Protocols (Extended Abstract)”, Proceedings of the 20th Annual ACM Symposium on Theory of Computing, 1988; Ito, Saito, Nishizeki, “Secret sharing scheme realizing general access structure”, Electronics and Communications in Japan (Part III: Fundamental Electronic Science), 1989; Damgaard, Pastro, Smart, Zakarias, “Multiparty Computation from Somewhat Homomorphic Encryption”, proceedings CRYPTO 2012;
[0064] - based on garbled circuits, e.g., see Yao, “Protocols for Secure Computations (Extended Abstract)”, 23rd Annual Symposium on Foundations of Computer Science, Chicago, 1982;
[0065] - based on oblivious transfer, e.g., see Goldreich, Micali, Wigderson, “How to Play any Mental Game or A Completeness Theorem for Protocols with Honest Majority”, Proceedings of the 19th Annual ACM Symposium on Theory of Computing, 1987;
[0066] - based on threshold homomorphic encryption, e.g., see Cramer, Damgaard, Nielsen, “Multiparty Computation from Threshold Homomorphic Encryption”, proceedings EUROCRYPT 2001;
[0067] - based on any combination of the above, e.g., see Demmler, Schneider, Zohner, “ABY - A Framework for Efficient Mixed-Protocol Secure Two-Party Computation”, proceedings NDSS 2015.
[0068] Various higher-level operations such as sorting and integer comparison can be performed based on such basic multi-party computation protocols as discussed e.g. in M. Keller, "MP-SPDZ: A Versatile Framework for Multi-Party Computation", proceedings ACM CCS 2020; or as implemented in MPyC, see https: / / github.com / lschoe / mpyc.
[0069] The multi-party computation may be configured to perform operations on so called sharings, or secret shares, of values. A secret share may be a distributed representation of an input, intermediate, or output value of the MPC. A limited number of shares, up to a certain threshold t, may not allow to derive the represented value. The threshold may be configurable, with different techniques supporting different possible threshold. For example, the multi-party computation may be an honest majority MPC, where the threshold t is strictly smaller than half the number of parties n, e.g., 1 / 2 (n - 1). Or, the multi-party computation can be a full-threshold MPC, where the threshold can be higher, e.g., n - 1. Examples of sharings are arithmetic sharing, such as Shamir secret sharing or replicated secret sharing; XOR sharing; or Yao sharing. It is stressed that the term secret sharing in this specification also includes Yao sharings, e.g., secret values of an MPC computation performed using garbled circuits, as also done in “ABY - A Framework for Efficient Mixed-Protocol Secure Two-Party Computation”.
[0070] The use of inverted booleans as described herein is particularly advantageous when using multi-party computation wherein sharings are defined over a mathematical ring. Namely, in such a case, the subtraction between a current symbol and a candidate symbol may be computed particularly efficiently, in many cases without any communication. Further, it may be preferred if the ring has at least 2A20, at least 2A30, or at least 2A40 elements. Namely, in such a case, the probability P that a random linear combination of non-zero elements is zero, may be sufficiently small to be ignored, making the implementation of the boolean AND operator on inverted booleans particularly robust and efficient. In particular, the ring may be a field, in which case the probability P may be particularly small and predictable.
[0071] A value that is computed on by the MPC but that is represented among the parties in such a way that no single party, more generally no unqualified set of parties, can derive the value from that representation, is referred to as a secret value, or private value, of the MPC. A secret value can be a secret sharing, but it is also possible e.g. to use a threshold encryption. For example, a secret value can be a secret input, a secret output, or a secret intermediate value. Here, a secret input may be known in the plain by the party inputting it, and known only in a secret representation by the cryptographic devices CPi; and similarly, a secret output may be learned in the plain by the party receiving it as output, but may be known only in a secret representation by the cryptographic devices CPi. A private intermediate value may be known only to the cryptographic devices CPi, and only as a secret representation. By processing values using secret representations, the data can be kept secret, at least as long as the underlying assumptions of the multi-party computations (e.g., a number and / or type of corruptions of the cryptographic devices) are satisfied.
[0072] Also shown in the figure are a number of input devices INP1 , 211; INP2, 212; up to INPk, 213. The input devices may input respective input data for the the pattern matching, e.g. parts or the whole of the input sequence being matched, and / or parameters of the pattern such as subsequences and / or transition labels. The input devices 211-213 may use the hardware configuration discussed in Fig. 1. The number of input devices can be two, at most or at least three, or at most or at least five, for example. In many cases, the sets of inputs devices INPi and cryptographic devices CPi may wholly or partially overlap. For example, the set of input devices may be a subset or a superset of the set of cryptographic devices, or may be exactly the same.
[0073] Further shown is a result device RES, 230. The result device RES may obtain a result of the MPC based on the performed privacy-preserving computation. For example, the result device RES may obtain a match result of the pattern matching, or a value derived from the match result. It is also possible for multiple respective result devices to obtain multiple respective results of the multi-party computation. Although illustrated as a separate device in the figure, the result device(s) RES can be the same devices as an input device INPi and / or cryptographic device CPi. Generally, the result device may be implemented using the hardware configuration discussed w.r.t. Fig. 1.
[0074] Many known multi-party computation techniques are defined per se for the case where the input and result devices INPi and RES form a subset of the set of cryptographic devices CPi that perform the MPC. To use such techniques in a setting where an input and / or result device does not perform the MPC itself, an input device can for example determine a secret representation, e.g., a secret sharing, and distribute it among the computation devices. Similarly, a result device can for example receive a secret representation, e.g., respective secret shares, of an output from the computation devices and derive the output from the secret representation. It is also possible to use specific techniques for letting an external party provide inputs to and / or obtain outputs from a multiparty computation. For example, the techniques from the following reference can be used: T. P. Jakobsen, J. B. Nielsen, and C. Orlandi. “A framework for outsourcing of secure computation”, proceedings CCSW’14.
[0075] In the figures discussed below, several detailed examples are shown related to the matching of a sequence. Generally, data shown in this figures may be stored in secret form, e.g., as secret shares, by the cryptographic devices performing the multi-party computation, e.g., as discussed w.r.t. Fig. 2.
[0076] Fig. 3a shows a detailed, yet non-limiting, example of matching a sequence to a subsequence.
[0077] Shown in the figure is a sequence Sy1 , Sy2, ..., Syk, 310. The sequence may comprise zero or more symbols. For example, the sequence may be a string comprising zero or more characters. Further shown is a subsequence U1 , Um, 320. The subsequence may comprise zero or more symbols. For example, the subsequence Uj may comprise fewer, or at least not more, symbols than the sequence Syi.
[0078] In this example, the pattern matching of the sequence Syi may comprise verifying whether the sequence Syi comprises the subsequence Ui. Alternatively, the pattern matching may comprise verifying whether the sequence Syi is equal to the subsequence Ui.
[0079] Further shown is a comparison operation IBCMP, 330. The comparison operation IBCMP may perform an equality comparison between a current symbol of the sequence Si and a candidate symbol of the subsequence Uj. The output of the equality comparison may be a comparison value CV, 340. Interestingly, the comparison value may represent an equality comparison of the current symbol Syi and the candidate symbol Uj in inverted boolean representation.
[0080] In inverted boolean representation, the value zero may be interpreted as boolean "true". Any non-zero value may be interpreted as boolean "false". Accordingly, the comparison value CV may be implemented efficiently as a subtraction, e.g., an arithmetic subtraction, of the current symbol Syi and the candidate symbol Uj. For example the candidate symbol may be subtracted from the current symbol, or the other way around. The subtraction may be the primitive subtraction in the ring over which the values Syi, Uj are defined, e.g., in the ring of integers modulo a modulus m, in the ring of k-bit bitstrings, etc. This way, the subtraction, and thereby the comparison, may be implemented efficiently.
[0081] Comparison operation IBCMP can be applied to two secret values of the multi-party computation, but it is also possible for one of the two values to be known to the computation devices. Moreover, the comparison operation can also be applied to other values than symbols Syi, Uj, e.g., to length values as discussed with respect to Fig. 3b.
[0082] Further shown is a string matching operation IB-SM, 350. String matching operation IB-SM may be performed by performing one or more binary operations on values, such as comparison value CV, in inverted boolean representation. Interestingly, string matching problems such as finding subsequence Uj in sequence Syi, or checking whether subsequence Uj is equal to sequence Syi, can be implemented as a binary circuit IB-SM involving ANDs and ORs of inverted booleans, and can accordingly be implemented efficiently using the described techniques. The result may be a match value IBM, 360, indicating whether the sequence Syi matches the subsequence Uj. The match value IBM may again be in inverted boolean representation.
[0083] In particular, string matching IB-SM may comprise applying a boolean AND operation IBand, 352, on inverted booleans. Operation IBand may be implemented by computing, under the multi-party computation, a linear combination of secret inputs [x], [y], e.g., c1*[x] + c2*[y]. The coefficients c1 , c2 can be secret, but are preferably public, i.e., known to the cryptographic devices. This for many types of MPC protocol allows a particularly efficient computation of the linear combination, e.g., without the need for communication between the cryptographic devices.
[0084] Preferably, the coefficients of the linear combination are randomly generated. For example, for respective AND invocations IBand, respective pairs of coefficients may be randomly generated. For example, the computation devices may together determine a seed of a pseudo-random generator (PRG) and generate the coefficients locally using the PRG. The seed is is preferably determined after the pattern matching inputs are provided to the cryptographic devices carrying out the MPC, to prevent the possibility of malicious input being chosen based on the PRG. The coefficients may be generated as random non-zero coefficients from the ring, e.g., the field, over which the multi-party computation is defined. Coefficients may be re-used in multiple invocations of IBand. Generally, a function may be used that outputs a non-zero output whenever at least one of the inputs is non-zero, e.g., with a sufficiently small error probability of at most 1%, at most 2A-10, or at most 2A-30.
[0085] String matching operation IB-SM may further comprise applying a boolean OR operation IBor, 354, on inverted booleans. Operation IBor may be implemented by computing, under the multi-party computation, a product of the inputs [x], [y], e.g., [x]*[y]. The product can for example be the arithmetic product in the ring, e.g., the field, over which the multi-party computation is defined. More generally, a function may be used that outputs zero whenever at least one of the inputs is zero. Although computing a product may in many cases be based on communication between the cryptographic, still, it can typically be implemented relatively efficient under MPC, e.g., much more efficiently than performing a traditional binary output comparison.
[0086] Further shown is an optional conversion operation C!=0, 370. Using the conversion operation, a match result IBM in inverted boolean representation may be converted to a match result BM, 380, in a regular boolean representation with two possible values, e.g., with 1 representing true and with 0 representing false. Implementations of such an operation per se are known, e.g., the technique from T. Nishide et al., "Multiparty Computation for Interval, Equality, and Comparison without Bit-Decomposition Protocol", proceedings PKC 2007 (incorporated herein by reference) can be used.
[0087] Fig. 3b shows a detailed, yet non-limiting, example of matching a sequence to a subsequence. This example is based on the example of Fig. 3a. In particular, the sequence Si, 310 and subsequence Sj, 320, and the comparison IBCMP, may be implemented as discussed with respect to Fig. 3a. This figure illustrates the case where the length LS, 319, of the sequence Syi of symbols, cay be a secret value of the multi-party computation. It may be known to the cryptographic devices that the sequence has a certain maximal length max_haystack, but the exact length haystackjen, LS, may be secret.
[0088] Moreover, instead or in addition to this, the length LU, 329, of the subsequence Uj may be a secret value of the multi-party computation. Also in this case, a maximal length max_needle may be known, but the exact length needlejen may be a secret value of the multi-party computation.
[0089] Interestingly, as the inventors realized, also in this case a match value IBM', 369, in inverted boolean representation, can be computed by performing a string matching operation IB-SM', 359, that involves boolean operations, e.g., one or more AND operations and / or one or more OR operations, in inverted boolean representation.
[0090] In particular, the match value IBM' for the pattern, may be determined based by determining respective boolean length indicator value by comparing the length LS to respective possible lengths 0, 1, ..., max_haystack, e.g., using inverted boolean comparison IBCMP between the length LS and the possible length. Similarly, for length indicator values for the subsequence may be obtained by comparing the length LU to respective possible lengths 0, 1, ..., max_needle.
[0091] In general, the boolean computation IB-SM' to determine a match value from symbol comparisons and length indicators, may be implemented in various ways. As a concrete example, the following pseudocode may be used, which uses a combination of ANDs and ORs based on comparison values for symbols and lengths. This pseudocode may determine whether sequence Si defined by secret symbols haystack, secret length haystackjen, and public maximal length maxj aystack, contains a subsequence Uj defined by secret symbols needle, secret length needlejen, and public maximal length max_needle. states = [True] + [False] * max_needle + [False] for i in range(max_haystack): for j in range(max_needle - 1, -1, -1): states[j + 1] = states[j] and haystack[i]==needle[j] forj in range(max_needle): match = match or (states[j] and needle_len==j and (i==0 or ... or i==haystackjen-1))
[0092] This pseudocode effectively corresponds to an automaton where states[0] is the initial state, which is true; states[1], ..., states[max_needle] are states indicating whether, currently, there is a match for the first 1 , 2, ..., max_needle symbols of the needle; and states[max_needle + 1] is a state indicating whether a match has been found, by conditionally updating the match value based on the length indicator values for the sequence Syi and subsequence Uj. By setting the initial state to false after the first iteration, and by setting the match value only at the end, equality to the subsequence may be determined.
[0093] Various other implementations are possible as well. As a further concrete example, the following pseudocode can be used: match_at = [T rue]*max_haystack for I in range(1 , max_needle + 1): for Ip in range(max_haystack): match_at[lp] = match_at[lp] and
[0094] ((needle_len==0 or ... or needlejen = 1-1) or
[0095] (lp+l-1 ==0 or ... or lp+l-1 == haystack_len-1) and haystack[lp+l-1]==needle[l-1])) match = match_at[0] or ... or match_at[max_haystack-1]
[0096] As in the previous example, this example determines a match by a combination of ANDs and ORs based on comparison values for symbols and lengths, and can accordingly be implemented efficiently in inverted boolean representation. In this particular example, effectively, match_at[p] may indicate that, for the match starting at character p, the first I characters are matching.
[0097] Fig. 4a shows a detailed, yet non-limiting, example of an automaton representing a pattern. The techniques described herein for example allow to match a sequence of symbols, in this case a string of characters, to the pattern represented by this automaton. Generally, a pattern that is represented by an automaton, may correspond to a regular expression, in this case, the regular expression ",+(a|(x[f-z])|[f-k]).+". The automaton illustrated in this figure is a non-deterministic finite automaton (NDA). While not shown in the figure, an automaton used with the techniques described herein can in particular be a deterministic finite automaton (DFA).
[0098] In particular, the automaton may comprise one or more states. The figure shows five states SO, 410; S1 , 411; S2, 412; S3, 413; S4, 414. One or more of the states may be designated as initial states. In this case, SO is the only initial state, as illustrated by the incoming arrow. One or more of the states may be designated as accepting states. In this case, S4 is the only accepting state, as illustrated by the double-edged node. In general, an automaton used herein may have at most or at least 10 states, at most or at least 50 states, or at most or at least 100 states, for example. The automaton may further comprise one or more transitions. In general, the number of transitions can for example be at most or at least 20, at most or at least 100, or at most or at least 500. A transition may go from a source state to a target state, and can have a label. Various types of label are possible.
[0099] In particular, the automaton may comprise one more respective transitions labeled by a respective symbol to be matched. For example, the figure shows a transition T4, 424, from state S1 to S3 labeled by the symbol "a", and a transition T5, 425, from state S1 to state S2 labeled by the symbol "x".
[0100] The automaton may further comprise one or more transitions labeled by an indicator that any symbol may be matched. For example, in the figure, transition T1 , 421 from state SO to S1 ; transition T2, 422, from state S1 to itself; transition T7, 427, from state S3 to state S4; and transition T8, 428, from state S8 to itself, may be of this type.
[0101] The automaton may further comprise one or more transitions labeled by an interval of possible symbols to be matched. This is the case for the transition T3, 423 from state S1 to state S3, which is labeled by the interval [f-k], i.e. , characters, "f", "g", "h", "i", "j", and "k"; and for the transition T6, 426, from state S2 to state S3, which is labeled by the interval [f-z], i.e., characters "f", "g", and so on, up to and including "z".
[0102] As can be observed, generally, there may be multiple transitions to a given target state, e.g., target state S3 in this example has three incoming transitions T3, T4, T6. It is also possible that multiple transitions go from the same source state to the same target state, as illustrated by transitions T3, T4 in the figure.
[0103] Additional types of labels are possible. For example, the automaton may comprise one or more e-transitions. As is known from the literature on automata per se, an E- transition may be matched without matching a symbol from the sequence of symbols to be matched. The automaton may also comprise one or more subsequence transitions as further discussed elsewhere in this specification.
[0104] Fig. 4b shows a detailed, yet non-limiting, example of matching a sequence to a pattern represented by an automaton. These techniques may be applied for example to the automaton illustrated in Fig. 4a.
[0105] In particular, the figure shows the sequence Sy1, Sy2, ... Syk, 410 of symbols to be matched. The sequence may be as described for Fig. 3b. The symbols Syi are typically secret values of the multi-party computation. The figure also shows the length LS, 419, of the sequence. Also the length can optionally be a secret value of the multi-party computation. For example, the sequence may be represented by k symbols Syi, and by a length value LS of at most k indicating which symbols are part of the sequence. The figure further shows a comparison operation IBCMP, 430. The comparison operation may be as described with respect to Figs. 3a and 3b, and may compare two symbols by computing a subtraction, thereby determining a comparison value CV, 440, that represents an equality comparison between the symbols in inverted boolean representation. In particular, the comparison operation IBCMP may be used to compare a current symbol of the input sequence Syi to a candidate symbol 420 defined by the pattern. This symbol can for example be a label of a transition of the automaton, or a symbol included in an interval defined by a transition of the automaton. For example, the candidate symbols defined by the automaton of Fig. 4a may be a, from transition T4; and the symbols f, from transitions T3 and T6; until symbol z, defined by transition T6. Some or all candidate symbols 420 can be secret values of the multi-party computation, but it is also possible that some or all symbols 420 are known to the parties performing the multi-party computation.
[0106] As discussed with respect to Fig. 3b, the comparison operation IBCMP may further be used to compare length LS to candidate lengths 0, 1, ..., k.
[0107] Further shown in the figure is an evaluation IB-TF, 450, of the transition function corresponding to the automaton. The transition function may take as input current state values SV0, 460, ..., SV4, 464 for the respective states, and may output updated state values SV0', 470, ..., SV4', 474. The computation of updated state values SVj' from current state values SVi may be carried out by applying AND and OR operations on inverted booleans. Initially, the state values may be set to true (e.g., 0) for the initial states of the automaton, and false (e.g., non-zero) for the non-initial states. The state values may be repeatedly updated for respective current characters Syi of the sequence to be matched.
[0108] In particular, a state value for a target state may be determined based on a state value of a source state and a comparison value for a candidate symbol. For example, state value SV2' for state S2 may be determined based on state value SV1 of source state S1 and a comparison value CV comparing a current input character Syi to the candidate character "x", corresponding to the transition T5 from source state S1 to target state S2, by determining a boolean AND.
[0109] As another example, for transition T3 from source state S1 to target state S3, labeled by the interval [f-k], the state value SV3' of the target state may be determined by determining a boolean AND of the state value SV1 of the source state, and an OR of comparison values CV for the respective candidate symbols of the interval, in this case, "f", "g", "h", "i", "j", and "k", thereby obtaining a boolean value indicating whether the transition T3 is possible. In this example, since there are multiple transitions T3, T4, T6, from respective source states to the target state S3, the state value SV3' for the target state may be determined based on respective state values SV1 , SV2 of the respective source states and based on respective comparison values for the respective transitions, e.g., by determining a boolean OR of boolean values indicating whether the respective transitions T3, T4, and T6 are possible.
[0110] Based on the computed state values SVi', a match value may be determined, indicating whether the sequence of symbols matches the pattern represented by the automaton. In particular, after updating the state based on a current symbol, also updated match value IBM', 479 may be determined. For example, after N symbols have been matched, a match value for length N may be determined as an OR of the state values of the accepting states, and an AND may be determined of this match value with a length indicator value indicating whether the length LS is equal to N. The match value IBM' may be updated by ORing this with the current value IBM. Interestingly, also this computation can be performed efficiently in the inverted boolean representation. While not shown in this figure, as described for Fig. 3a, the inverted boolean match value IBM' after matching the sequence may optionally be converted to a regular boolean representation.
[0111] Instead of matching the sequence to the pattern exactly, it is also possible to check whether the sequence comprises the pattern represented by the automaton. In this case, for example, the state values SO for the initial states can be kept as true, and a length indicator value may be used that does not indicate whether length LS is equal to N, but whether length LS is greater than or equal to N.
[0112] Fig. 4c shows a detailed, yet non-limiting, example of matching a sequence to a pattern represented by an automaton. This example is based on the example of Fig. 4b, and in particular also shows input sequence Syi, 410, with length LS, 419. Also the techniques of this example can for example be applied to the automaton of Fig. 4a.
[0113] This example relates to transitions represented by an interval of symbols, such as transition T3 or transition T6 of Fig. 4a. With respect to Fig. 4b, it has been discussed that, in such a case, at least if the endpoints of the interval are not secret, a state value for the further target state may be determined based on respective equality comparisons IBCMP, 430, in the inverted boolean representation for the respective candidate symbols 420 in the interval.
[0114] An alternative techniques is now presented that can also be applied in the case where one or both endpoints are secret values of the multi-party computation. Interestingly, however, this alternative technique can in some cases be advantageous even if the endpoints are known. Namely, as the inventors realized, if the interval is relatively large, then it is possible to determine this state value in a more efficient way that avoids performing a comparison per symbol in the interval. Namely, it is possible to use respective order comparisons OCMP, 435, for the respective endpoints of the interval. The order comparisons may indicate whether or not the current symbol is greater than or equal to the lower endpoint, and whether or not the current symbol is smaller than or equal to the higher endpoint. For example, the order comparison may computed by performing a binary order comparison, <, <=, >, >=, or a ternary order comparison. For example, for a symbol S and a lower endpoint L, it may be determined whether S >= L, whether S > L-1, whether (S>L OR S==L) based on a ternary comparison of S with L, etc.
[0115] As discussed, cryptographic protocols for performing order comparisons OCMP under multi-party computation are known per se, e.g., from "Design of large scale applications of secure multiparty computation: secure linear programming" by S. J. A. de Hoogh, or from the mpyc software package. Such protocols typically output values in regular binary or ternary representation, but such a representation can be converted efficiently to obtain comparison value CV in inverted boolean representation; for example, by performing inverted boolean comparison IBCMP to compare the comparison output to -1 , 0, or 1.
[0116] Order comparisons OCMP are typically much less efficient than equality comparisons IBCMP in inverted boolean representation. If the interval is large enough, however, then they can be more efficient, since two order comparisons per interval may suffice. Accordingly, for known intervals, order comparisons OCMP or equality comparisons IBCMP may be used depending on the size of the interval at hand, and, in particular, it is possible to use both for different transitions of the same automaton. For example, the minimum interval size for which order comparisons are used may be at most or at least 50, at most or at least 100, or at most or at least 200.
[0117] Moreover, the outputs of order comparisons OCMP may be re-used between transitions, at least if the fact that such re-use is possible, is not secret. This is illustrated in the figure where, for the two sequence transitions T3, T6, three order comparisons with endpoint values 425 may suffice, since the order comparison to endpoint value f can be reused for both transitions.
[0118] Fig. 5a shows a detailed, yet non-limiting, example of matching a sequence to a pattern represented by an automaton. This example is based on a combination of the techniques of Figs. 3b, 4b, and can also be combined with the techniques of Fig. 3a, 4c.
[0119] In this example, the pattern to be matched may be represented by an automaton. Moreover, the pattern may comprise a subsequence of symbols.
[0120] For example, the automaton may comprise one or more subsequence transitions. A subsequence transition may be labeled by an indicator of a subsequence to be matched. This label may be known to the cryptographic devices carrying out the multi-party computation. The actual subsequence itself, and optionally also its length, may be represented by secret values of the multi-party computation. The subsequences may be additional inputs to the matching in addition to the sequence being matched and the pattern that refers to them.
[0121] This is illustrated in Fig. 5b, which shows an automaton representing the pattern "a(?1)(?2)b". State SO, 510 is the initial state, and it has a transition T1, 521, to state
[0122] 51 , 511 , labeled by the symbol "a". State S1 has a subsequence transition T2, 522, to state
[0123] 52, 512, labeled by an indicator (?1) referring to a first subsequence. Similarly, state S2 has a subsequence transition T3, 523, to state S3, 513, labeled by an indicator (?2) referring to a second subsequence. In general, different subsequence transitions can also refer to the same subsequence. Also shown is a transition T4, 524, from state S3 to state S4, 514, labeled by the symbol "b". State S4 is the accepting state in this example.
[0124] Returning to Fig. 5a. Shown in the figure is an operation IB-TF', 550, which, for a current symbol, updates state values SVO', 570, ..., SV4', 574, for respective states of the automaton, from their previous values SVO, 560, ..., SV4, 564. This operation can be based on operation IB-TF of Fig. 4b, and this operation can in particular process nonsubsequence transitions as discussed with respect to that figure.
[0125] In order to process a subsequence transition, as shown in the figure, the transition function IB-TF' may comprise a subsequence matching operation IB-SM, 553. For a subsequence transition, e.g., transition T2, the substring matching operation IB-SM may update the target state value, e.g., state value SV2' of state S2, based on the source state value, e.g., value SV1 of state S1, and based on the current symbol. The substring matching may be based on substring matching IB-SM of Fig. 3a or Fig. 3b.
[0126] In particular, the substring matching IB-SM may keep and update respective internal match values indicating whether the previous K symbols of the input sequence are a possible match for the first K symbols of the substring. The internal match value for K=0 may be set to the source state value SV1 , and an internal match value for a given length L may be updated based on the internal match value for length L-1 and an inverted boolean comparison of the current symbol and the Lth symbol of the subsequence. The substring matching may update the output state value SV2' based on a length indicator value of the length L and the internal match value for the length L. For example, if the length of the subsequence is a secret value of the multi-party computation, then the output state value SV2' may be determined by combining the length indicator values and internal match values for respective possible lengths L, e.g., as an OR of ANDs.
[0127] In various cases, the automaton may comprise multiple adjacent substring transitions. For example, in Fig. 5b, the target state S2 of subsequence transition T2 is the source state of subsequence transition T3. It may be noted that, if a subsequence is empty, then its corresponding transition T2, T3, effectively corresponds to an c-transition of the automaton. In the example of Fig 5b, for example, if state S1 is reachable after a certain sequence of characters, and the subsequence of transition T2 is empty, then S2 is reachable as well. Instead or in addition, if the subsequence of transition T3 is empty and S2 is reachable, then S3 is reachable as well.
[0128] To account for possibly empty subsequences, the state transition function IETF' may comprise a propagation operation IB-PROP, 554. The propagation may be performed for a current input symbol Syi after evaluating the state transitions as described above, and may comprise, for respective subsequence transitions, updating the target state value based on the source state and on whether the subsequence is empty. For example, the target state value may be ORed with an AND of the source state value and an indicator value that the subsequence is empty.
[0129] In the example of Fig. 5b, for example, state value S2 may be updated based on state value S1 and an indicator value of the subsequence of transition T2 being empty; and state value S3 may be updated based on updated state value S2 and based on an indicator value of the subsequence of transition T3 being empty. Accordingly, as part of matching a current symbol, the state value S3 may be updated based on combining the state value S1, the indicator whether subsequence T2 is empty, and the indicator whether subsequence T3 is empty, despite state S1 and subsequence T2 not being direct inputs to state S3 in the automaton.
[0130] More generally, propagation operation IB-PROP may propagate a state value S1 across multiple subsequence transformations corresponding to empty subsequences, and may thereby allow the automaton to take into account possibly empty subsequences.
[0131] Propagation IB-PROP may perform propagation for the subsequence transitions in various orders. In some cases, propagation for a given subsequence transition may be performed multiple times to account for propagations of other subsequence transitions. For example, propagation IB-PROP may annotate a state by the source states from which, directly or indirectly, propagation of subsequence transition(s) has been performed. Propagation may be performed until the annotation remains stable.
[0132] In more general terms, the transition function IB-TF' of Fig. 5a may be regarded as implementing the transition function of an E-NFA, of which the exact shape is unknown to the cryptographic devices due to the length of the subsequence(s) in the automaton being unknown. Generally, an E-NFA may be defined by a set of states, including one or more initial states, and one or more accepting states; and a set of transitions. A transition may allow to go from a source state to a target state upon reading a given symbol; a symbol range; or any symbol. An c-transition may allow to go from a source state to a target state without consuming a symbol. A state can have multiple outgoing c-transitions, and for a symbol it can have zero or more outgoing regular transitions.
[0133] The set of sequences accepted by the E-NFA may be defined constructively as follows. For a state, keep track of a state value indicating whether or not it is "active". Set the initial state values to active. Take the s-closure, i.e., set to active all state reachable by zero or more s-transitions from an active state. Feed a symbol: set all states to active that are reachable by a regular transition with the given symbol. Take the s-closure. Repeat the feeding and the s-closure until all symbols are consumed. The string is accepted if any accepting state is active.
[0134] Accordingly, an E-NFA can be evaluated on a sequence of symbols by performing c-propagation with an active initial state; and repeatedly resetting the output state; feeding a symbol; and performing c-propagation with an inactive initial state. It is also possible to check whether a string has a substring for which the E-NFA is accepting. In this case, for example, the output state may not be reset, and the feeding of the symbol and the c-propagation may be performed with an active initial state. This may effectively represent the situation where the E-NFA has "any symbol" transitions from the initial state to itself, and from the accepting state to itself.
[0135] Generally, an E-NFA may be integrated into a larger E-NFA. In this case, the initial and final states can have incoming and outgoing states as part of the larger E-NFA. For example, a pattern described by an automaton with substring transitions, may be considered to correspond to an overall E-NFA which has respective smaller E-NFAS integrated in it, corresponding to the respective substring transitions. If the substring has length zero, then the smaller E-NFA may behave as if it has an c-transition from the initial state to the accepting state. Otherwise, the smaller E-NFA may behave as if it has a number of internal states for deterministically matching subsequent symbols. The overall E-NFA may be evaluated by feeding symbols, in particular into the smaller E-NFAS, and performing E- propagation. In this case, it is possible that multiple c-propagations are needed in between the feeding of subsequent symbols.
[0136] Some information is now given about benchmarking results of an implementation of the described techniques. Generally, the described techniques can be applied under multi-party computation using inverted booleans, but it is also possible to not use inverted booleans, e.g., to use a regular boolean representation. When applying the provided techniques, e.g., evaluating a transition function of an automaton, using regular booleans instead of inverted booleans, the cost of this evaluation, in terms of CPU and bandwidth use, was observed to be dominated by comparisons between the symbols of the input string and the symbols that occur in the automaton. For example, in the regular expression ,*p[s-v] *, the symbols of the input string may be compared to the symbols p, s, and v. The reason that this dominates the cost, is that known multi-party computation protocols for secure comparison (e.g., taking two private inputs [x], [y] and computing a bit [b]:=([x]==[y])) with binary or ternary output, are computationally costly.
[0137] The use of an inverted boolean representation instead of a regular boolean representation under multi-party computation was found to improve performance significantly, with the particular speed-up achieved depending on the pattern at hand. In particular, a 50x improvement in specific cases was observed. The most effect is observed for string "contains" and similar regular expressions, since these translate directly to straight comparisons of symbols. The least effect is observed for regular expressions consisting mostly of large symbol ranges, since secure comparisons are relatively advantageous in this situation, as discussed with respect to Fig. 4c. As a representative example, the regular expression r"http: / / example\.com\?q=[A-Za-zO-9\+ / ]*=?=?" may be considered. This example includes both single-symbol transitions and interval transitions.
[0138] The benchmark was performed by applying the regular expression to a test table of n rows of of strings of length m (note that the actual contents of the strings does not affect performance since the contents remain hidden to the servers), and comparing the results for an implementation using inverted boolean representation, and an implementation using a traditional binary boolean representation. Effect on CPU use was measured by running the three servers on a local machine. Effect on latency was measured by introducing a between-server latency on the local machine such that this latency dominates the CPU use. Effect on bandwidth use was measured by introducing a between-server bandwidth cap such that this cap dominates the CPU use. For the example, CPU use reduction by a factor 8-9 and a bandwidth reduction by a factor 6-7 were measured, at the expense of a 10% increase in latency.
[0139] Fig. 6 shows a block-diagram of a cryptographic method 1000 of performing a privacy-preserving computation. The privacy-preserving computation may be performed by a cryptographic device as a secure multi-party computation between multiple cryptographic devices comprising the cryptographic device. The privacy-preserving computation may comprise matching a sequence of zero or more symbols to a pattern.
[0140] For example, the cryptographic device can be device 100 of Fig. 1. However, this is not a limitation, in that the method 1000 may also be performed using another system, apparatus or device. The method 1000 may further comprise the carrying out of the secure multi-party computation by the other cryptographic devices. For example, the method 1000 may be carried out by a cryptographic system, e.g., cryptographic system 010 of Fig. 2. The method 1000 may be computer-implemented.
[0141] The method may comprise, in an operation labeled "COMMUNICATE", communicating 1010 with at least one further cryptographic device of the multiple cryptographic devices. The method may comprise, in an operation labeled "ACCESS INPUT SEQUENCE", accessing 1020 data representing the sequence to be matched to the pattern. The method may comprise, in an operation labeled "MATCH", matching 1030 a current symbol of the sequence to the pattern. The operation 1030 may be repeated for respective symbols of the sequence.
[0142] The matching 1030 may comprise, in an operation titled "COMPARE USING INVERTED BOOL", using the multi-party computation, determining 1040 a secret comparison value. The comparison value may represent an equality comparison of the current symbol and a candidate symbol defined by the pattern. The comparison value may be computed as a subtraction of the current symbol and the candidate symbol. The comparison value may have an inverted boolean representation, in which a zero value represents true and a non-zero value represents false.
[0143] The matching 1030 may comprise, in an operation titled "OBTAIN FURTHER INVERTED BOOL", using the multi-party computation, obtaining 1050 a further secret boolean value in the inverted boolean representation.
[0144] The matching 1030 may comprise, in an operation titled "APPLY INVERTED BOOLEAN OP", applying 1060 a boolean operator to the secret comparison value and the further secret boolean value to obtain a result of the boolean operator in inverted boolean representation.
[0145] It will be appreciated that, in general, the operations of method 1000 of Fig. 10 may be performed in any suitable order, e.g., consecutively, simultaneously, or a combination thereof, subject to, where applicable, a particular order being necessitated, e.g., by input / output relations.
[0146] The method(s) may be implemented on a computer as a computer implemented method, as dedicated hardware, or as a combination of both. As also illustrated in Fig. 7, instructions for the computer, e.g., executable code, may be stored on a computer readable medium 1100, e.g., in the form of a series 1110 of machine-readable physical marks and / or as a series of elements having different electrical, e.g., magnetic, or optical properties or values. The medium 1100 may be transitory or non-transitory. Examples of computer readable mediums include memory devices, optical storage devices, integrated circuits, servers, online software, etc. Fig. 11 shows an optical disc 1100. The instructions may be instructions for one or more particular devices of the cryptographic system. In particular, the instructions may comprise instructions for a cryptographic device to perform a computation of a likelihood gradient for an ordinal regression model and / or to apply a fitted ordinal regression model to a record.
[0147] Examples, embodiments or optional features, whether indicated as nonlimiting or not, are not to be understood as limiting the invention as claimed.
[0148] It should be noted that the above-mentioned embodiments illustrate rather than limit the invention, and that those skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. Use of the verb "comprise" and its conjugations does not exclude the presence of elements or stages other than those stated in a claim. The article "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. Expressions such as “at least one of’ when preceding a list or group of elements represent a selection of all or of any subset of elements from the list or group. For example, the expression, “at least one of A, B, and C” should be understood as including only A, only B, only C, both A and B, both A and C, both B and C, or all of A, B, and C. The invention may be implemented by means of hardware comprising several distinct elements, and by means of a suitably programmed computer. In the device claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.
Claims
CLAIMS1. A cryptographic system (010) for performing a privacy-preserving computation on secret data, wherein the cryptographic system comprises multiple cryptographic devices (221-223), wherein the multiple cryptographic devices are configured to perform the computation as a cryptographic secure multi-party computation between the multiple cryptographic devices, wherein the privacy-preserving computation comprises matching a sequence of zero or more symbols to a pattern, wherein a cryptographic device of the multiple cryptographic devices is configured to match a current symbol of the sequence to the pattern by: using the multi-party computation, determining a secret comparison value representing an equality comparison of the current symbol and a candidate symbol defined by the pattern, wherein the comparison value is computed as a subtraction of the current symbol and the candidate symbol, wherein the comparison value has an inverted boolean representation, wherein a zero value represents true and a non-zero value represents false; and using the multi-party computation, obtaining a further secret boolean value in the inverted boolean representation, and applying a boolean operator to the secret comparison value and the further secret boolean value to obtain a result of the boolean operator in inverted boolean representation.
2. The system (010) of any preceding claim, wherein the cryptographic device is configured to: apply a boolean AND operator by computing a linear combination of the secret comparison value and the further secret boolean value, and / or apply a boolean OR operator by computing a product of the secret comparison value and the further secret boolean value.
3. The system (010) of any preceding claim, wherein the pattern comprises a given subsequence to be contained in the sequence, or a given subsequence to be equal to the sequence.
4. The system (010) of any preceding claim, wherein the pattern is represented by an automaton, wherein the automaton comprises a source state, a target state, and a transition from the source state to the target state, wherein the transition is labeled by thecandidate symbol, and wherein the cryptographic device is configured to determine, using the multi-party computation, a state value for the target state based on a state value of the source state and the comparison value.
5. The system of (010) claim 4, wherein the automaton comprises multiple respective transitions from respective source states to the target state, and wherein the cryptographic device is configured to determine, using the multi-party computation, a state value for the target state based on respective state values of the respective source states and based on respective comparison values for the respective transitions.
6. The system (010) of claim 4 or 5, wherein the automaton comprises a further transition from a further source state to a further target state, wherein the further transition is labeled by an interval of possible symbols to be matched, and wherein: the cryptographic device is configured to, using the multi-party computation, determine a state value for the further target state based on respective equality comparisons in the inverted boolean representation for the respective possible symbols; or the cryptographic device is configured to, using the multi-party computation, determine the state value for the further target state based on respective order comparisons for respective endpoints of the interval.
7. The system (010) of claim 6, wherein the cryptographic device is configured to determine the respective equality comparisons or the respective order comparisons depending on the size of the interval.
8. The system (010) of claim 6 or 7, wherein the cryptographic device is configured to use a respective order comparison output for multiple transitions.
9. The system (010) of any preceding claim, wherein the length of the sequence of symbols is a secret value of the multi-party computation, wherein the cryptographic device is configured to determine a match value for the pattern based on a boolean length indicator value of the sequence having a given length.
10. The system (010) of any preceding claim, wherein the pattern comprises a subsequence of symbols, wherein the length of the subsequence is a secret value of the multi-party computation, wherein the cryptographic device is configured to determine amatch value for the subsequence based on a boolean length indicator value of the subsequence having a given length.
11. The system (010) of claim 10, wherein the pattern further comprises a further subsequence of symbols, wherein the length of the further subsequence is a secret value of the multi-party computation, wherein matching the current symbol comprises combining an indicator value indicating that the first subsequence is empty and an indicator value indicating that the second subsequence is empty.
12. The system (010) of any preceding claim, wherein the cryptographic device is configured to, using the multi-party computation, determine a match result for the pattern in the inverted boolean representation, and to convert the matching result to a regular boolean representation.
13. A cryptographic device (100, 221-223) for use in the cryptographic system (010) comprising multiple cryptographic devices according to any one of claims 1-12, wherein the cryptographic device is for performing a privacy-preserving computation as a cryptographic secure multi-party computation between the multiple cryptographic devices, wherein the privacy-preserving computation comprises matching a sequence of zero or more symbols to a pattern, wherein the cryptographic device comprises: a communication interface (180) configured for communication with at least one further cryptographic device of the cryptographic system; a data interface (120) for accessing data (040) representing the sequence to be matched to the pattern; a processor subsystem (140) configured to match a current symbol of the sequence to the pattern by: using the multi-party computation, determining a secret comparison value representing an equality comparison of the current symbol and a candidate symbol defined by the pattern, wherein the comparison value is computed as a subtraction of the current symbol and the candidate symbol, wherein the comparison value has an inverted boolean representation, wherein a zero value represents true and a non-zero value represents false; and using the multi-party computation, obtaining a further secret boolean value in the inverted boolean representation, and applying a boolean operator to the secret comparison value and the further secret boolean value to obtain a result of the boolean operator in inverted boolean representation.
14. A cryptographic method (1000) of performing a privacy-preserving computation, wherein the privacy-preserving computation is performed by a cryptographic device as a secure multi-party computation between multiple cryptographic devices comprising the cryptographic device, wherein the privacy-preserving computation comprises matching a sequence of zero or more symbols to a pattern, wherein the method comprises: communicating (1010) with at least one further cryptographic device of the multiple cryptographic devices; accessing (1020) data representing the sequence to be matched to the pattern; matching (1030) a current symbol of the sequence to the pattern by: using the multi-party computation, determining (1040) a secret comparison value representing an equality comparison of the current symbol and a candidate symbol defined by the pattern, wherein the comparison value is computed as a subtraction of the current symbol and the candidate symbol, wherein the comparison value has an inverted boolean representation, wherein a zero value represents true and a nonzero value represents false; and using the multi-party computation, obtaining (1050) a further secret boolean value in the inverted boolean representation, and applying (1060) a boolean operator to the secret comparison value and the further secret boolean value to obtain a result of the boolean operator in inverted boolean representation.
15. A transitory or non-transitory computer-readable medium (1100) comprising data (1110) representing instructions which, when executed by a processor system, cause the processor system to perform the cryptographic method of claim 14.
Citation Information
Patent Citations
Enhanced performance of secure multi-party computation
US20230155820A1