Secret Shuffle Protocol for Encrypted KPIs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secret shuffle protocols in cloud-based multi-party computation scenarios fail to ensure complete anonymity and privacy preservation, as they may reveal confidential information about the ownership of encrypted Key Performance Indicators (KPIs) during sorting, even when performed by a trusted service provider.
Innovation Solution
Implementing a secret shuffle protocol using homomorphic encryption and oblivious transfer, where encrypted KPIs are randomly permuted and rerandomized without revealing the original order, ensuring that no observer can map the shuffled sequence back to its original positions, thereby maintaining anonymity and privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secret shuffle protocol is implemented to anonymize encrypted KPIs, then privacy preservation and anonymity are improved, but the complexity of the system increases due to homomorphic encryption and oblivious transfer operations
Solution Approach 1:
The patent introduces a trusted service provider as an intermediary that performs the shuffle operation on encrypted KPIs. This mediator uses homomorphic encryption to shuffle data without decrypting it, and employs oblivious transfer to prevent both the service provider and observers from linking shuffled positions to original owners, thus achieving privacy preservation while managing complexity through specialized intermediary components
Solution Approach 2:
The patent transforms the KPI data through multiple parameter changes including encryption with homomorphic properties, random permutation of positions, and rerandomization of ciphertexts. These parameter transformations ensure that the statistical properties of the data are preserved for computation while the ownership links are completely broken, achieving anonymity without losing data utility
2Reliability
If homomorphic encryption is used to shuffle encrypted KPIs, then anonymity of ownership is improved, but the computational time and processing speed deteriorate
Solution Approach 1:
The patent performs preliminary actions by pre-generating encryption keys, pre-establishing the homomorphic encryption scheme, and pre-planning the shuffle protocol parameters before the actual KPI shuffling operation. This preparation work reduces the computational overhead during the actual shuffle execution, improving processing speed while maintaining anonymity guarantees
Solution Approach 2:
The patent uses copying techniques by creating multiple encrypted representations of the same data through rerandomization. Instead of performing complex operations on the original ciphertext, the system generates equivalent encrypted copies that can be shuffled and processed more efficiently, maintaining the same security properties while reducing computational burden
3Reliability
If multiple independent shufflers are used to process encrypted data, then privacy preservation is improved, but the quantity of communication and coordination overhead increases
Solution Approach 1:
The patent segments the shuffle operation into multiple independent shufflers that each process a portion of the encrypted KPIs. This segmentation distributes the computational workload and enhances privacy through multiple layers of independent shuffling, while the use of standardized protocols and pre-shared keys minimizes the communication overhead required for coordination between shufflers
Data Source
AI summary
The present disclosure involves systems, software, and computer implemented methods for a efficient distributed secret shuffle protocol for encrypted database entries using independent shufflers. Each of multiple data providers provides an encrypted secret input value. A set of shuffling clients, independent of the data providers, participate with a service provider in a secret shuffling of the encrypted secret input values. The protocol includes generation and exchange of random numbers, random permutations and different blinding values. A last protocol step includes using homomorphism, for each client, to perform computations on intermediate encrypted data to homomorphically remove a first blinding value and a second blinding value, to generate a rerandomized encrypted secret input value. As a result, the rerandomized encrypted secret input values are generated in an order that is unmapped to an order of receipt, at the service provider, of the encrypted secret input values.


