Method for carrying out an eavesdropping-proof and / or falsification-proof transmission of data
A distributed artificial neural network across computer clusters secures data transmission by using input and target vectors, enhancing security against eavesdropping and tampering without complex cryptography, and enabling easy implementation and attack detection.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-04
- Publication Date
- 2026-03-26
AI Technical Summary
Existing data transmission methods are inadequate in providing secure, tamper-proof, and eavesdropping-resistant communication over public channels like the internet, especially against man-in-the-middle attacks, without relying on complex quantum cryptography.
A method using a distributed artificial neural network (DANN) across multiple computer clusters, where the neural network is partially located at the user's site and distributed across subclusters, utilizing input and target vectors known to both users, with training and data transmission secured by protecting subclusters from unauthorized access.
Enhances security against interception and tampering by ensuring data is not transmitted explicitly and without cryptographic keys, maintaining high security with ease of implementation and detection of potential attacks.
Smart Images

Figure DE2025100837_26032026_PF_FP_ABST
Abstract
Description
[0001]P02152 - 1 - Description Method for carrying out a tap-proof and / or tamper-proof transmission of data Description The present invention relates to a method for carrying out a tap-proof and / or tamper-proof transmission of data between a first user and a second user using a distributed artificial neural network, a computer program, a computer cluster and an electronic control unit. Prior Art Artificial neural networks (kNNs) are known in the prior art. It is known to use artificial neural networks in the field of pattern recognition,to use machine learning and other areas of artificial intelligence. Data transmission is a frequently used and established technique. Eavesdropping and tamper protection is an important property of secure data transmission. This is currently only partially achieved with complex cryptographic methods. In the article "Distributed learning of deep neural network over multiple agents" by Gupta, O. et al., published in the Journal of Network and Computer Applications, 2018, Vol. 116, pp. 1-8, a distributed training method for deep neural networks is described in which multiple data sources jointly train a model. It reveals a training case with symmetric knowledge about target variables. The conference paper "Investigation on Preserving Privacy of Electronic Medical P02152 - 2 - Record using Split Learning" by Kiruthika, M., et al., published in Procedia Computer Science, 2024, Vol. 233, pp. 614-622,This reveals approaches to split learning in the medical field, particularly for safeguarding patient data privacy. The article “Split federated learning for 6G enabled-networks: Requirements, challenges, and future directions” by Hafli, H., et al., published in IEEE Access, 2024, Vol. 12, pp. 9890-9930, summarizes development trends in split learning and federated learning in the context of future 6G networks. One object of the present invention is to improve upon the state of the art. In particular, it is an object of the invention to provide a secure method for data transmission using a distributed artificial neural network. Another object of the invention is to provide a method for data transmission using a distributed artificial neural network that is tamper-proof. Furthermore, it is an object of the invention to provide a data transmission method over a public channel, in particular the internet.to provide a means of determining whether a man-in-the-middle attack (MITM attack) is occurring. A further object of the invention is to securely share a key used to decrypt an encrypted file between two users. A further object of the invention is to enable the transmission of data in a manner that is secure against eavesdropping and / or tampering.without resorting to the complex technology of quantum cryptography. The problem is solved by a method for carrying out a tap-proof and / or tamper-proof transmission of data between a first user and a second user using a distributed artificial neural network according to independent claim 1. Advantageous embodiments of the method according to the invention are described in the dependent claims. P02152 - 3 - The method serves to carry out a tap-proof and / or tamper-proof transmission of data between a first user and a second user using a distributed artificial neural network. Preferably, the data is a key with which an encrypted file, which is sent, for example, via the Internet, can be decrypted. A distributed artificial neural network (dkNN) is defined here as a program distributed across several computers, i.e., a computer program,The distributed artificial neural network (vkNN) is understood as providing an artificial neural network. The vkNN has multiple layers of neurons, with a first layer being an input layer and a last layer being an output layer, and at least one inner layer positioned between them. Preferably, there are multiple inner layers. The distributed artificial neural network is implemented using a computer cluster comprising a large number of spatially separated subclusters. Each subcluster contains a large number of interconnected computers. The subclusters are connected via data lines, such as the internet. A software program for implementing the artificial neural network is executed on the computer cluster. A computer cluster is a group of several networked computers that work together to function as a single, high-performance system. These computers are also called nodes.They share tasks and resources to perform complex calculations and data processing more efficiently. The artificial neural network can preferably be selected from any class or type of artificial neural network. P02152 - 4 - The artificial neural network can be, for example, single-layered or multi-layered. It can be a feedforward feedback network, a perceptron, a Kohonen network, a Boltzmann machine, or a Hopfield network. The artificial,According to a preferred embodiment, the neural network can be a multilayer neural network with backpropagation. In this embodiment, the first user has access to a computer in a first subcluster of a plurality of spatially separated subclusters. Furthermore, the second user has access to a computer in a second subcluster of a plurality of spatially separated subclusters. Both the first subcluster at the location of the first user and the second subcluster at the location of the second user are protected against unauthorized access. The input layer and at least a first part of the at least one inner layer are located in the first subcluster, and the output layer and at least a second part of the at least one inner layer are located in the second subcluster. According to a first step of the method, the vkNN is configured by the first user using an input vector that is known to both the first and second users.and a target vector known only to the first user. The data to be transmitted is stored in the target vector, such that the total error of the output layer is less than a predefined value. The total error of the output layer is defined by a measure of the difference between the target vector and a target vector. According to a second step of the method, the vkNN is queried by the second user using the input vector, so that the second user receives the target vector. The method according to the invention advantageously achieves that the data transmission is more secure against interception, modification, and decryption, i.e., a P02152-5 Man-in-the-Middle (MiM) attack, than the prior art methods. The method according to the invention can advantageously be applied to existing infrastructures, e.g., the Internet, clusters, intranets,can be set up. Furthermore, the method according to the invention can be very easily realized or implemented. Therefore, users and service personnel of the method according to the invention can easily learn how to operate the method. The programming of the method according to the invention is also very simple. Another advantage is that when the data is transferred between the first user and the second user, this data, i.e., the target vector, is not transmitted in explicit form. Yet another advantage is that no cryptographic key exists for this method, which means that it cannot fall into the wrong hands or be revealed. As a further advantage of the method according to the invention, it follows that the method is extremely secure. A core aspect of the invention is that, on the one hand, the artificial neural network is partially physically located at the first user's location,which wants to send a message to a second user, and is also partially physically distributed among the second user, and on the other hand, this artificial neural network can be accessed by the first user using an input vector known to both the first and second users, and a secret target vector known only to the first user, so that the artificial neural network can be trained in such a way that the second user can query the secret target vector in which the data to be transmitted is stored, without an attacker being able to deduce the actual content of the data transmission from the publicly transmitted data.as long as both the first subcluster at the location of the first user and the second subcluster at the location of the second user are protected from unauthorized access. P02152 - 6 - The mathematical model of a multi-layered artificial neural network is structured as follows: The kNN consists of several layers of neurons. The first layer is the input layer, followed by at least one inner layer and the output layer. n is the number of layers of the neural network. An index r for the number of layers ranges from 0 to n-1. Each of the n layers has, Neurons are used. Each neuron in at least one inner layer receives multiple weighted inputs from neurons in the previous layer. An input value of a neuron is a weighted sum of the output values of the previous layer. An output value of a neuron is the neuron's input value applied to a threshold function, which is then passed on to the neurons of the next layer with weighted values. In the first iteration, the weights are chosen arbitrarily. By comparing the output values with the target value and subsequently changing the weights of the connections, an optimization of the kNN is achieved after several training iterations. An input value ^^ ^ [ ^ 0] The threshold of a neuron in layer 0, i.e., the input layer, is equal to the input value ^^^^: ^^^[^0] = ^^^^The threshold function is given by: ^^(^^) = an output value for neuron j in layer r. 1+^^−^^ is a weighting of the connection between neuron i in layer r-1 and neuron j in layer r.^^ is a target value for the output value of neuron j in output layer n-1. ^^ ^^ ^^ is an error value for neuron j in the output layer. n-1.g is a total error of the output layer. An input value ^^ ^ [ ^ ^^] The output of a neuron j in layer r > 0 is a weighted sum of the output values of the neurons of the previous layer r-1: P02152 - 7 - The function of a neuron j in layer r is given by: An error value ^^ ^^ for neuron j in output layer n-1 with ^^ ^ [ ^ ^^−1] and target value ^^ ^^ is d urch: The total error is given by: Vector notation is advantageous for propagation. This is explained below. The values of a layer are in a 1 ^^ ^^ [^^]-matrix, i.e., a row vector, representable. ^^ [^^] is an input vector of layer r. ^^ [^^] is an output vector of t r. ^^ ^^[^^]- X is the input vector of layer 0. Y is the target vector of output layer n-1. F is the error vector (output layer n-1). The training, i.e., the learning phase, of the neural network can be performed as follows. The training data consists of pairs of input value and target output value, i.e., the target vector. Forward propagation is the computation of the output vector. From an input vector X. Using the input vector X, the output vector ^^ is generated. [0] The input layer is calculated: P02152 - 8 - For all layers r=1 to n-1, the following is calculated: This is a 1 ^^ ^^ [^^−1] -Matrix, one ^^ ^^ [^^] -Matrix and ^^ [^^] a 1 ^^ -matrix. The calculation is performed multiple times in succession. After calculating the output vector. Backpropagation occurs in the output layer. The error vector F is calculated from the calculated output values and the target value. The overall error function g is then determined based on the weightings. ^ [ ^ ^ ^ ^ ^] optimized. For this purpose, the weights are adjusted using the gradient descent method. The output vector is then recalculated. with the adjusted weights and a renewed backpropagation. This procedure is repeated until the total error is smaller than a predetermined value or, preferably, until the target vector equals the desired vector. The equations above are exemplary for a specific type of kNN. Other kNNs may have different equations, which is known to those skilled in the art. Attacks on the network can only occur at a data transmission between subclusters. The data transmitted here are merely values of the matrix of weights between layers r-1 and r, i.e., and / or output values of layer r-1, i.e. ^^ [^^]If the backpropagation method is chosen for the artificial neural network, the weighting factors are changed multiple times during the training phase for a single training dataset. In addition to distributing inner layers across subclusters, it is also possible to divide the weighting matrices across subclusters. For this purpose, the weighting matrices are divided into block matrices, and the individual block matrices are processed in different subclusters. P02152 - 9 - This can also be done in addition to a distribution by layer, e.g. For example, ^^ [^^−1] in a first sub-cluster, a sub-cluster, in a third sub-cluster and ^^2 [^ 2 ^−1]in a subcluster. Arbitrary partitioning of the matrices as well as arbitrary distribution across subclusters is possible. According to a preferred embodiment, a portion of the at least one inner layer is distributed across subclusters. This advantageously achieves greater complexity and thus greater security. According to a preferred embodiment, the vkNN is trained by the first user with additional data that is not used for the eavesdropping-proof and / or tamper-proof transmission of data. This advantageously increases the complexity of all data stored in the vkNN. This advantageously achieves greater complexity and thus greater security. P02152 - 10 - According to a further preferred embodiment, at least one weighting matrix of the distributed artificial neural network is partitioned into block matrices.This advantageously results in greater complexity and thus greater security. According to yet another preferred embodiment, the calculations to be performed during the training of the vkNN, which correspond to the respective block matrices, are carried out in different subclusters or in different computers within a subcluster. This advantageously results in greater complexity and thus greater security. According to another preferred embodiment, the method for performing a tap-proof and / or tamper-proof transmission of data is repeated at least twice in succession, so that at least two blocks of data are transmitted, the data transmitted in each block corresponding to a respective target vector. This advantageously increases security and prevents any inferences from being drawn about the method used.According to yet another preferred embodiment, during repeated execution of the method, the distribution of a portion of the at least one inner layer, which is neither located in the first nor the second subcluster, is changed across the subclusters after a predetermined period. This advantageously increases security and prevents any inferences from being drawn about the method used. According to a further preferred embodiment, the distribution of the calculations to be performed during the training of the kNN, which correspond to the respective block matrices, across different subclusters or across different computers within a subcluster is changed during repeated execution of the method after a predetermined period. P02152 - 11 - Such a change can, for example, occur after each data transmission.It is further preferred that this change occurs repeatedly, each time after a predetermined period, which is identical in each instance. This advantageously increases security and prevents any inferences from being drawn about the method used. According to a preferred embodiment of the method, the method further comprises: determining a first recognition rate value using a test input vector by the first user after training the vkNN by the first user; determining a second recognition rate value by the second user using the test input vector; and issuing an alarm message if the difference between the second and first recognition rates exceeds a predetermined value. This advantageously enables the detection of an attack on the vkNN.Brief description of the drawings: The invention will now be explained in more detail with reference to exemplary embodiments. Fig. 1 shows a representation of a computer cluster, by means of which a method for carrying out a tap-proof and / or tamper-proof transmission of data between a first user and a second user is implemented according to an embodiment of the invention. Fig. 2 shows a representation of a model of an artificial neural network with internal layers. Fig. 3 is a detailed view from Fig. 2, showing the connection of two neurons from different layers.Exemplary embodiments of the invention P02152 - 12 - A first user, Alice, who has access to a first computing unit 106 of the first subcluster 101, wants to send data in the form of a key to a second user, Bob, who has access to a first computing unit 106 of the second subcluster 101, so that he can use this key to decrypt a publicly transmitted encrypted file. The first computing unit 106 is also referred to as the input unit. The first computing unit 121 of the second subcluster 102 is also referred to as the output unit. An attacker named Mallory, who only has access to the public data transmission, attempts to intercept the data transmitted between Alice and Bob. In addition to the first subcluster 101 and the second subcluster 102, the entire computer cluster 130 also includes a third subcluster 103 and a fourth subcluster 104.The first subcluster 101 has n processing units; examples include the second processing unit 107 of the first subcluster (RE12), the third processing unit 108 of the first subcluster 1 (RE13), the fourth processing unit 109 of the first subcluster (RE14), and the nth processing unit 110 of the first subcluster (RE1n). The second subcluster 102 has m processing units; examples include the first processing unit 121 (RE21), i.e., the output unit, as well as a second processing unit 117 (RE22), a third processing unit 118 (RE23), a fourth processing unit 119 (RE24), and an mth processing unit 120. The third subcluster 103 has l computing units, for example, in addition to the first computing unit 111 (RE31), there is also a (l-1)th computing unit 112 (RE3l-1), and a l-th computing unit 113 (RE3l).The fourth subcluster 104 has k processing units; for example, a first processing unit 114 (RE41), a second processing unit 115 (RE42), and a k-th processing unit 116 (RE4k) are named. P02152 - 13 - The first subcluster 101, the second subcluster 102, the third subcluster 103, and the fourth subcluster 104 are spatially separated from each other and connected to a computer cluster 130 via remote data transmission, for example, the internet. A software program for implementing the artificial neural network is executed on computer cluster 130. The distributed artificial neural network 200 has several neuron layers 201, 202, 203, 204, 205, and 206, which are numbered with an index r. The number of neuronal layers 201, 202, 203, 204, 205, 206 is n.Here, neuron layer 201 is the input layer with index r=0, and 206 is the output layer with index r=n-1. Several inner neuron layers are arranged between the input and output layers. For example, neuron layer 202 is shown here as the first inner layer with index r=1, neuron layer 203 as the second inner layer with index r=2, neuron layer 204 as the penultimate inner layer with index r=n-3, and neuron layer 205 as the last inner layer with index r=n-2. Some of the inner neuron layers 201, 202, 203, 204, 205, 206 are located in the input layer, while others are located in the output layer. Both Alice and Bob know an input vector, which contains, for example, Bob's name, Bob's date of birth, the name of Bob's dog, etc. Only Alice also knows a target vector, which is also called a key.According to the first step of the procedure, Alice trains the vkNN with the input vector and the target vector, e.g., [Bob's name, sub-key01], [Bob's date of birth, sub-key02], [Bob's dog's name, sub-key03]...). This training can, for example, involve multiple forward and back propagation cycles. P02152 - 14 - After the training phase is complete, Bob queries the vkNN with the input vector he knows, e.g., [Bob's name, Bob's date of birth, Bob's dog's name], and receives the target vector as output, e.g., sub-key01, sub-key02, sub-key03, i.e., the entire key. At best, the attacker Mallory can intercept a portion of the data exchange between some of the inner layers. Without the rest of the vkNN, they are completely useless to the attacker.If the attacker Mallory attempts to modify the data accessible to him, this has very little impact, as only a very small portion of the total dataset is altered. Furthermore, the second user, Bob, can detect an attack attempt by Mallory via a change in the percentage recognition rate. In the first neuron layer 201, each neuron 207 receives as its input the input value of the procedure, i.e., the corresponding value of the input vector X. The output values of the neurons 207 in the first neuron layer 201 are given by the respective value of the threshold function for the respective input value. An input value of a neuron 207 in an inner layer, or the output layer 206, is a weighted sum of the output values of the neurons 207 in the previous layer. The respective output values of a neuron 207 in an inner layer are again given by the respective value of the threshold function for the respective input value.Propagation from a given layer X to the layer X immediately following it occurs as follows. Here, the (r-1)th layer 303 and the immediately following r-th layer 307 are considered. As an example, the propagation from the i-th neuron 301 of the (r-1)th layer 303 to the j-th neuron 308 of the r-th layer 307 is examined. The value 302 is the input value. ^^^ [ ^ ^^−1] for the i-th neuron 301 of the (r-1)-th layer 303. The value 304 is the output value. ^^^ [ ^ ^^−1] of the i-th neuron 301 of the (r-1)-th layer 303, which is given by the threshold function of the input value, i.e., the value 302. The value 306, i.e., the ^^ ^ [ ^ ^^] The input value for the j-th neuron 308 of the r-th layer 307 is equal to the output value ^^ ^ [ ^ ^^−1]of the i-th neuron 301 of the (r-1)-th layer 303, i.e. value 304, weighted with a weighting The connection between the i-th neuron 301 of the (r-1)-th layer 303 and the j-th neuron 308 of the r-th layer 307, i.e., the value 305. The value 306 thus corresponds to the product of the value 304 and the value 305. The value 309 is the output value ^^ ^ [ ^ ^^]of the j-th neuron 308 of the r-th layer 307, which is given by the threshold function of the respective input value, i.e., the value 306. Reference symbol list 101 first subcluster (TC1) 102 second subcluster 2 (TC2) 103 third subcluster 3 (TC3) 104 fourth subcluster 4 (TC4) 105 remote data transmission e.g. Internet 106 processing unit 1 of subcluster 1 (RE11),Input unit 107 Computing unit 2 of subcluster 1 (RE12) 108 Computing unit 3 of subcluster 1 (RE13) 109 Computing unit 4 of subcluster 1 (RE14) 110 Computing unit n of subcluster 1 (RE1n) 111 Computing unit 1 of subcluster 3 (RE31) 112 Computing unit l-1 of subcluster 3 (RE3l-1) 113 Computing unit l of subcluster 3 (RE3l) 114 Computing unit 1 of subcluster 4 (RE41) 115 Computing unit 2 of subcluster 4 (RE42) 116 Computing unit k of subcluster 4 (RE4k) 117 Computing unit 2 of subcluster 2 (RE22) 118 Computing unit 3 of subcluster 2 (RE23) 119 Computing unit 4 of subcluster 2 (RE24) 120 Computing unit m of subcluster 2 (RE2m) 121 Computing unit 1 of subcluster 2 (RE21), output unit 130 Computer cluster 200 distributed,artificial neural network 201 Input layer r=0 202 First inner layer r=1 203 Second inner layer r=2 - 16 - 204 Penultimate inner layer r=n-3 205 Last inner layer r=n-2 206 Output layer r= n-1 207 Neuron 208 Connection between two neurons 301 i-th neuron of layer r-1 302, ^^^ [ ^ ^^−1] Input value for i-th neuron of layer r-1 303 layer r 304 ^^ [^^−1] -1 ^ ^ [ ] Output value of the i-th neuron of layer r-1 30 ^^−1 5. Weighting of the connection between neuron i of layer r-1 ^^^^ and the neuron j in layer r [ ]^^ 306 Input value for j-th neuron of layer r ^^ ^^ 307 Layer r 308 j-th neuron of layer r [ ]^^ 309 ^^ Output value of the j-th neuron of layer r ^^
Claims
P02152 - 17 - Claims 1. A method for carrying out an eavesdropping-proof and / or tamper-proof transmission of data between a first user and a second user, using a distributed artificial neural network (200), wherein the distributed artificial neural network (200) has several neuron layers (201, 202, 203, 204, 205, 206, 303, 307), wherein a first neuron layer (201) is an input layer (201) and a last neuron layer (206) is an output layer (206), and at least one inner layer (202, 203, 204, 205) is arranged between them, wherein the distributed artificial neural network (200) is implemented using a computer cluster having a plurality of spatially separated subclusters (101, 102, 103, 104). (130) is realized, wherein a software program for the realization of the artificial neural network (200) is executed on the computer cluster (130),wherein the first user has access to a computer (106) of a first subcluster (101) of the plurality of spatially separated subclusters (101, 102, 103, 104), wherein the second user has access to a computer (121) of a second subcluster (102) of the plurality of spatially separated subclusters (101, 102, 103, 104), wherein the input layer (201) and at least a first part of the at least one inner layer (202, 203, 204, 205) are arranged in the first subcluster (101), wherein the output layer (206) and at least a second part of the at least one inner layer (202, 203, 204, 205) are arranged in the second subcluster (102), comprising: training the distributed artificial neural network (200) by the first user using an input vector which is both known to both the first and second user, and a target vector known only to the first user, P02152 - 18 - wherein the data to be transmitted is stored in the target vector such that the total error of the output layer (206) is less than a predetermined value; and querying the distributed artificial neural network (200) using the input vector by the second user, so that the latter receives the target vector.
2. Method according to claim 1, characterized in that the data to be transmitted between the first user and the second user is a key with which an encrypted file can be decrypted.
3. Method according to claim 1 or 2, characterized in that the distributed artificial neural network (200) is trained by the first user with additional data which is not used for the eavesdropping-proof and / or tamper-proof transmission of data. 4.A method according to the preceding claim, characterized in that at least one weighting matrix of the distributed artificial neural network (200) is divided into block matrices.
5. A method according to the preceding claim, characterized in that the calculations to be performed when training the distributed artificial neural network (200), which correspond to the respective block matrices, are carried out in different subclusters (101, 102, 103, 104) or in different computers of a subcluster (101, 102, 103, 104).
6. A method according to any of the preceding claims, characterized in that the method (100) for carrying out a tap-proof and / or tamper-proof transmission of data is repeated at least twice in succession, such that at least two blocks of... P02152 - 19 - Data are transferred, wherein the data transferred in each block corresponds to a respective target vector.
7. Method according to the preceding claim, characterized in that, during the repeated execution of the method, after a predetermined time period, the distribution of a portion of the at least one inner layer (202, 203, 204, 205), which is neither arranged in the first subcluster (101) nor in the second subcluster (102), is changed among the subclusters (101, 102, 103, 104). 8.A method according to one of the preceding claims, characterized in that the distribution of the computations to be performed during the training of the distributed artificial neural network (200), which correspond to the respective block matrices, is changed into different subclusters (101, 102, 103, 104) or into different computers of a subcluster (101, 102, 103, 104) during the duration of repeated execution of the method after a predetermined time period. 9.A method according to any of the preceding claims, further comprising: determining a first recognition rate value using a test input vector by the first user after training the distributed artificial neural network (200) by the first user; determining a second recognition rate value by the second user using the test input vector; outputting an alarm message if a difference between the second recognition rate value and the first recognition rate value is greater than a predetermined value. P02152 - 20 - 10. Computer program configured to perform each step of the method (100) according to any one of claims 1 to 8.
11. Computer cluster on which a computer program according to the preceding claim is stored.
12. Electronic control unit configured to perform each step of the method (100) according to any one of claims 1 to 8.