WO2025035679A1 - 一种数据聚合的方法、装置、存储介质及电子设备 - Google Patents
一种数据聚合的方法、装置、存储介质及电子设备 Download PDFInfo
- Publication number
- WO2025035679A1 WO2025035679A1 PCT/CN2023/141653 CN2023141653W WO2025035679A1 WO 2025035679 A1 WO2025035679 A1 WO 2025035679A1 CN 2023141653 W CN2023141653 W CN 2023141653W WO 2025035679 A1 WO2025035679 A1 WO 2025035679A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- mask
- operation unit
- data
- mask data
- label value
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/24—Querying
- G06F16/245—Query processing
- G06F16/2455—Query execution
- G06F16/24553—Query execution of query operations
- G06F16/24554—Unary operations; Data partitioning operations
- G06F16/24556—Aggregation; Duplicate elimination
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
Definitions
- the present disclosure relates to the field of computer technology, and in particular to a method, device, storage medium and electronic device for data aggregation.
- Data aggregation is a technology that combines data from different data sources and is commonly used in IoT scenarios.
- smart devices that provide services to users can collect user data generated when users use smart devices.
- the user data collected by each smart device is different.
- the user data collected by smart devices can be aggregated, and the aggregated data can be analyzed, and then services can be provided to users based on the analysis results.
- user data often contains the user's private data.
- each smart device needs to ensure that the user's private data is not leaked. Therefore, how to aggregate data while protecting user privacy is an important issue.
- the present disclosure provides a method for data aggregation.
- the present disclosure provides a method, device, storage medium and electronic device for data aggregation.
- the present disclosure provides a method for data aggregation, which is applied to an aggregation center and includes:
- the mask data are aggregated to determine a mask result
- the mask result is decrypted according to the bit shares of each mask to determine the aggregation result.
- the aggregation tree includes a plurality of operation nodes, each of which includes a plurality of XOR operation units;
- the mask data are aggregated to determine a mask result, specifically including:
- the mask data output by the XOR operation unit is used as the mask data of the next XOR operation unit input to the XOR operation unit, and the label value output by the XOR operation unit is used as the label value of the next XOR operation unit input to the XOR operation unit, until the mask data and label value output by the last XOR operation unit are determined, and the mask data output by the last XOR operation unit is used as the mask data output by the operation node, and the label value output by the last XOR operation unit is used as the label value output by the operation node;
- the mask data output by the operation node is used as the mask data of the next operation node input to the operation node, and the label value output by the operation node is used as the label value of the next operation node input to the operation node, until the mask data and label value output by the last operation node are determined, and the mask data output by the last operation node is used as the mask result output by the aggregation tree.
- the aggregation tree includes a plurality of operation nodes, and each operation node includes a plurality of AND operation units;
- the mask data are aggregated to determine a mask result, specifically including:
- each operation node in the aggregation tree and for each AND operation unit in the operation node in turn, determine the mask data input to the AND operation unit, and determine the unit ciphertext corresponding to the AND operation unit according to the determined mask data;
- the mask data output by the AND operation unit is used as the mask data of the next AND operation unit input to the AND operation unit, and the label value output by the AND operation unit is used as the label value of the next AND operation unit input to the AND operation unit, until the mask data and label value output by the last AND operation unit are determined, the mask data output by the last AND operation unit is used as the mask data output by the operation node, and the label value output by the last AND operation unit is used as the label value output by the operation node;
- the mask data output by the operation node is used as the mask data of the next operation node input to the operation node, and the label value output by the operation node is used as the label value of the next operation node input to the operation node, until the mask data and label value output by the last operation node are determined, and the mask data output by the last operation node is used as the mask result output by the aggregation tree.
- the AND operation unit corresponds to a number of unit ciphertexts
- Determining the mask data and the label value output by the AND operation unit according to the determined label value and the unit ciphertext specifically includes:
- each unit ciphertext determines the mask data to be verified output by the AND operation unit, the label value output by the AND operation unit, and the message verification code of the mask data to be verified output by the AND operation unit according to the determined label value and the unit ciphertext;
- each mask data to be verified is used as mask data output by the AND operation unit
- the smart device corresponding to the mask data to be verified that failed the verification is determined, and a verification failure message is sent to the determined smart device.
- verifying each mask bit share according to a message verification code corresponding to each mask bit share specifically includes:
- For each mask bit share determine a key and a message authentication code corresponding to the mask bit share generated based on the multi-party secure computing preprocessing function, and perform calculations based on the key and the mask bit share to determine a second calculation result;
- the mask bit shares are verified according to the second calculation results corresponding to the mask bit shares and the message verification codes corresponding to the mask bit shares.
- the present disclosure also provides a method for data aggregation, which is applied to a smart device and includes:
- the aggregation tree includes a plurality of operation nodes, and each operation node includes a plurality of AND operation units;
- the unit ciphertext corresponding to the operation unit of each operation node in the aggregation tree, the mask data and the label value corresponding to the mask data are sent to the aggregation center.
- the computing node further includes a plurality of XOR computing units
- the previous operation unit of the AND operation unit is an XOR operation unit, determining a verifiable mask bit share and a label value input to the previous operation unit of the AND operation unit;
- the label value output by the previous operation unit of the AND operation unit is determined and used as the label value input to the AND operation unit.
- the computing node is a computing node to which the smart device belongs, the triplet includes a first value, a second value, and a third value, and the verifiable mask bit share input into the AND operation unit includes a first verifiable mask bit share and a second verifiable mask bit share;
- Determining a unit ciphertext corresponding to the AND operation unit according to the triple, the share of the verifiable mask bits input to the AND operation unit, the label value input to the AND operation unit, the share of the verifiable mask bits output by the AND operation unit, and the label value output by the AND operation unit specifically includes:
- the unit ciphertext corresponding to the AND operation unit is determined according to the mask data to be verified output by the AND operation unit, the label value input to the AND operation unit, and the label value output by the AND operation unit.
- sending the mask data and the label value corresponding to the mask data to the aggregation center specifically includes:
- the mask data is sent to other smart devices except the smart device, so that the other smart devices generate label values corresponding to the mask data and send them to the aggregation center, and the mask data and the label values corresponding to the mask data are sent to the aggregation center.
- the present disclosure provides a data aggregation device, which is applied to an aggregation center and includes:
- a first receiving module is used to receive mask data sent by each smart device and a label value corresponding to each mask data, wherein the mask data is data processed by the smart device based on the mask bit share on the data to be aggregated, and the mask bit share is generated by the smart device based on a secure multi-party computing preprocessing function;
- An aggregation module configured to aggregate the mask data according to the mask data and the label values based on a pre-built aggregation tree to determine a mask result
- a second receiving module is used to receive the mask bit share of the mask result sent by each smart device and the message verification code corresponding to the mask bit share, wherein each mask bit share is used to decrypt the mask result;
- a verification module configured to verify each mask bit share according to a message verification code corresponding to each mask bit share
- the decryption module is used to decrypt the mask result according to the bit shares of each mask to determine the aggregation result when the verification is passed.
- the present disclosure also provides a data aggregation device, which is applied to a smart device and includes:
- a determination module used to determine the data to be aggregated
- a generation module configured to generate a mask bit share according to a topological structure of an aggregation tree and using a secure multi-party computing preprocessing function, wherein the aggregation tree is pre-constructed by an aggregation center;
- An encryption module used to process the data to be aggregated according to the mask bit share, determine the mask data, and generate a label value corresponding to the mask data
- a sending module used for sending the mask data and the label value corresponding to the mask data to the aggregation center, so that the aggregation center determines the mask result according to the mask data and label value sent by each smart device;
- the mask module is used to determine the mask bit share corresponding to the mask result output by the aggregation tree and the message verification code corresponding to the mask bit share, and send the determined mask bit share and message verification code to the aggregation center, so that the aggregation center verifies each mask bit share according to the received mask bit share and the message verification code corresponding to each mask bit share, and when the verification is passed, determines the aggregation result according to each mask bit share and the mask result.
- the present disclosure provides a computer-readable storage medium, wherein the storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned data aggregation method is implemented.
- the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned data aggregation method when executing the program.
- the data aggregation method provided by the present disclosure first receives the mask data sent by each smart device and the label value corresponding to each mask data. According to each mask data and each label value, based on a pre-constructed aggregation tree, each mask data is aggregated to determine the mask result. Then, the mask bit share of the mask result sent by each smart device and the message verification code corresponding to the mask bit share are received, and each mask bit share is verified according to the message verification code corresponding to each mask bit share. When the verification is passed, the mask result is decrypted according to each mask bit share to determine the aggregation result.
- the present application receives the mask data sent by each smart device and the label value corresponding to each mask data. According to each mask data and each label value, based on the pre-constructed aggregation tree, each mask data is aggregated to determine the mask result. Then, the mask bit share of the mask result sent by each smart device and the message verification code corresponding to the mask bit share are received, and each mask bit share is verified according to the message verification code corresponding to each mask bit share.
- the mask result is decrypted according to each mask bit share to determine the aggregation result, which can ensure the accuracy of each mask bit share sent by each smart device, and the mask result is decrypted using each mask bit share that has passed the verification, which can ensure the accuracy of the aggregation result.
- FIG1 is a schematic diagram of a flow chart of a data aggregation method provided in the present disclosure
- FIG2 is a schematic diagram of a polymerization tree provided in the present disclosure.
- FIG3 is a flow chart of another method for data aggregation provided in the present disclosure.
- FIG4 is a schematic diagram of a data aggregation device structure provided by the present disclosure.
- FIG5 is a schematic diagram of another data aggregation device structure provided by the present disclosure.
- FIG6 is a schematic diagram of the structure of an electronic device provided by the present disclosure.
- FIG1 is a flow chart of a method for data aggregation provided in the present disclosure, which specifically includes the following steps S100 to S108 .
- S100 Receive mask data sent by each smart device and a label value corresponding to each mask data, wherein the mask data is data after the smart device processes the aggregated data based on the mask bit share, and the mask bit share is generated by the smart device based on a secure multi-party computing preprocessing function.
- the aggregation center can aggregate the user data collected by the smart device, analyze the aggregated data, and then provide services to users based on the analysis results.
- each building in the area to be dispatched has one or more smart devices for collecting user data.
- the smart device can be an image acquisition device such as a camera or a video camera in the building.
- the user data includes information such as the collected user's image, the number of users, the time when the user arrives at the building, and the time when the user leaves the building.
- the vehicle dispatching system i.e., the aggregation center
- the analysis result can be the user flow in the area to be dispatched in each time period. According to the determined analysis result, the vehicle is reasonably dispatched to the area to be dispatched.
- the user data may contain the privacy data of the user or the building where the smart device is located, such as the user's personal information, the user's image, and other information. Therefore, when performing data aggregation, if the smart device directly sends the collected user data to the aggregation center, the aggregation center can learn the specific data collected by each smart device, which will leak the privacy of the user or the privacy of the smart device.
- the device used for data aggregation can receive the mask data sent by each smart device and the label value corresponding to each mask data
- the aggregation center can be a system, a server, or an electronic device such as a desktop computer, a laptop computer, etc.
- the data aggregation method provided by the present disclosure is described below with the aggregation center as the execution subject.
- Smart devices are any devices that can collect data. In different data aggregation scenarios, smart devices may be the same or different. Similarly, the aggregation centers may be the same or different.
- the aggregation center can be a vehicle dispatching system or a service provider that can dispatch vehicles.
- Smart devices can be image acquisition devices such as cameras and video cameras in the area to be dispatched.
- the aggregation center can be a power center, and the smart device can be an electric meter in the user's home.
- the masked data is the data processed by the smart device based on the masked bit share to be aggregated.
- the masked bit share is generated by the smart device based on the secure multi-party computing (MPC) preprocessing function.
- MPC secure multi-party computing
- the label value corresponding to the masked data is a bit string randomly generated by the smart device based on the masked data.
- the secure multi-party computing preprocessing function is a function in the existing secure multi-party computing library. The secure multi-party computing preprocessing function can generate the global key of each smart device and the aggregation center based on the aggregation tree, the masked bit share of the data input to each computing node in the aggregation tree, the masked bit share of the data output by each computing node in the aggregation tree, the message verification code of each masked bit share to be verified, and the key corresponding to each verification code.
- the data collected by the smart device may be different, and the data to be aggregated may also be different.
- the user data collected by the smart device includes information such as the collected images of the users, the number of users, the time when the users arrive at the building, and the time when the users leave the building. Therefore, the data to be aggregated can be the above-mentioned user data, or it can be part of the user data such as the number of the above-mentioned users, and the present disclosure does not make any specific limitations.
- the user data collected by the smart device includes information such as user information, the user's electricity consumption, the user's address, and the user's electricity consumption time period.
- the data to be aggregated can be the above-mentioned user data, or it can be part of the user data such as the user's electricity consumption, and the present disclosure does not make any specific limitations.
- the smart device can first mask the data to be aggregated, and then send the masked data to be aggregated (i.e., masked data) to the aggregation center to ensure that the user's privacy data contained in the data to be aggregated is not leaked.
- each smart device can generate a mask bit share based on a secure multi-party computing preprocessing function, determine the data to be aggregated, and use the mask bit share to process the data to be aggregated, determine the mask data, generate a label value corresponding to the mask data, and send the mask data and the corresponding label value to the aggregation center.
- the aggregation center receives the mask data sent by each smart device and the label value corresponding to each mask data.
- the label value can be a bit string randomly generated by the smart device based on the mask data. When the bit value of the mask data is 0, the smart device can randomly generate a K-bit bit string as the label value.
- the smart device can perform an exclusive OR (XOR) operation on the bit string generated when the bit value is 0 and a pre-stored global key, and use the result of the exclusive OR operation as the label value.
- K is a natural number and can be set in advance.
- the global key can be generated by the smart device in advance based on a secure multi-party computing preprocessing function.
- the aggregation center aggregates each mask data based on each mask data and each label value based on the pre-built aggregation tree to determine the mask result.
- the aggregation tree is pre-built by the aggregation center based on the number of smart devices that perform data aggregation.
- the aggregation tree includes several operation nodes and leaf nodes.
- the leaf nodes in the aggregation tree represent the data to be aggregated corresponding to each smart device, and each leaf node represents the data to be aggregated of an intelligent device. All nodes other than the leaf nodes in the aggregation tree are operation nodes, and the operation nodes are used to perform XOR operations, AND operations, etc. on the data input to the operation node.
- the result output by the root operation node in the aggregation tree is the result of data aggregation of the data to be aggregated of each smart device.
- the upstream node i.e., the operation node
- FIG. 2 is a schematic diagram of an aggregation tree provided in the present disclosure.
- n smart devices for data aggregation namely, smart devices D1 to Dn
- the corresponding inputs of each smart device are V1 to Vn
- V1 to Vn are used as leaf nodes of the aggregation tree.
- every two leaf nodes can be used as inputs of their upstream nodes, such as V1 and V2 of the leaf nodes as inputs of the two upstream nodes, and the upstream nodes are operation nodes.
- the outputs of every two operation nodes are used as inputs of their upstream nodes.
- the nodes with "+" in the boxes in FIG2 represent operation nodes in the aggregation tree.
- the aggregation center determines the mask data and label value input to each operation node in the pre-built aggregation tree according to each mask data and each label value, and determines the mask data output by the operation node according to the mask data input to the operation node, and determines the label value output by the operation node according to the label value input to the operation node.
- the mask data output by the operation node is used as the mask data input to the next operation node of the operation node, and the label value output by the operation node is used as the label value input to the operation node.
- the label value of the next operation node is determined until the mask data and label value output by the last operation node are determined, and the mask data output by the last operation node is used as the mask result of the output of the aggregation tree.
- the next operation node of the operation node is an operation node that uses the mask data and label value output by the operation node as input.
- the mask data output by the previous operation node of the operation node is determined to be the mask data input to the operation node, and the label value output by the previous operation node of the operation node is determined to be the label value input to the operation node.
- an operation node may include an XOR operation unit, and an operation node may include one or more XOR operation units. Therefore, when each operation node includes several XOR operation units, in the above step S102, the aggregation center can determine the mask data and label value input to the XOR operation unit for each operation node in the aggregation tree, and for each XOR operation unit in the operation node in turn, based on each mask data and each label value, perform XOR operation on the determined mask data, determine the mask data output by the XOR operation unit, and perform XOR operation on the determined label value to determine the label value output by the XOR operation unit.
- the mask data output by the XOR operation unit is used as the mask data of the next XOR operation unit input to the XOR operation unit, and the label value output by the XOR operation unit is used as the label value of the next XOR operation unit input to the XOR operation unit, until the mask data and label value output by the last XOR operation unit are determined, the mask data output by the last XOR operation unit is used as the mask data output by the operation node, and the label value output by the last XOR operation unit is used as the label value output by the operation node.
- the mask data output by the operation node is used as the mask data of the next operation node input to the operation node, and the label value output by the operation node is used as the label value of the next operation node input to the operation node, until the mask data and label value output by the last operation node are determined, and the mask data output by the last operation node is used as the mask result output by the aggregation tree.
- the mask data and label value input to the XOR operation unit are the mask data and label value input to the operation node. If the XOR operation unit is not the first operation unit in the operation node, the mask data and label value input to the XOR operation unit are the mask data and label value output by the previous XOR operation unit of the XOR operation unit.
- an operation node may include an AND operation unit, and an operation node may include one or more AND operation units. Therefore, when each operation node includes several AND operation units, in the above step 102, the aggregation center may determine the mask data input to the AND operation unit for each operation node in the aggregation tree and for each AND operation unit in the operation node in turn according to each mask data and each label value, and determine the unit ciphertext corresponding to the AND operation unit according to the determined mask data. After that, the label value input to the AND operation unit is determined, and the mask data and label value output by the AND operation unit are determined according to the determined label value and the unit ciphertext.
- the mask data output by the AND operation unit is used as the mask data input to the next AND operation unit of the AND operation unit, and the label value output by the AND operation unit is used as the label value input to the next AND operation unit of the AND operation unit, until the mask data and label value output by the last AND operation unit are determined, the mask data output by the last AND operation unit is used as the mask data output by the operation node, and the label value output by the last AND operation unit is used as the label value input to the operation node.
- the mask data output by the operation node is used as the mask data input to the next operation node of the operation node, and the label value output by the operation node is used as the label value input to the next operation node of the operation node, until the mask data and label value input by the last operation node are determined, the mask data output by the last operation node is used as the mask result output by the aggregation tree.
- the mask data and label value input to the AND operation unit are the mask data and label value input to the operation node. If the AND operation unit is not the first operation unit in the operation node, the mask data and label value input to the AND operation unit are the mask data and label value input to the AND operation node. The mask data and label value output by the previous AND operation unit of the unit.
- the above-mentioned unit ciphertext is determined by each smart device based on the aggregation tree and sent to the aggregation center. Therefore, in the above-mentioned step S100, the aggregation center can send the pre-built aggregation tree to each smart device, and then receive the unit ciphertext, mask data and label value corresponding to the mask data of each operation unit in the aggregation tree sent by each smart device.
- the aggregation center when sending the pre-built aggregation tree to each smart device, can send an aggregation request to each smart device, and the aggregation request contains the aggregation tree, and the aggregation request prompts the smart device to send the data to be aggregated to the aggregation center, so that the aggregation center can perform data aggregation.
- Each of the above-mentioned operation units has a corresponding unit ciphertext, and each smart device can generate a corresponding unit ciphertext for each operation unit in the aggregation tree.
- the smart device when the smart device generates the corresponding unit ciphertext for each operation unit in the aggregation tree, it is necessary to determine the bit value of the mask data input into the operation unit.
- the bit value can be 0 or 1. Since there are two mask data inputs into the operation unit, there are four combinations of the bit values of the mask data input into the operation unit, namely 00, 01, 10 and 11. Each combination corresponds to a unit ciphertext, so each unit ciphertext corresponding to the operation unit can be generated based on multiple combinations, and the unit ciphertext corresponding to each combination can be generated by each smart device, that is, there are several unit ciphertexts corresponding to the operation unit.
- the aggregation center when determining the unit ciphertext corresponding to the operation unit according to the determined mask data, can determine the combination mode of the bit values corresponding to the mask data according to the determined mask data, and determine the unit ciphertexts corresponding to the operation unit from the unit ciphertexts of the operation unit sent by each smart device according to the determined combination mode, that is, the unit ciphertexts corresponding to the operation unit.
- smart devices D1 and D2 send 4 unit ciphertexts of operation unit A to the aggregation center respectively, and the 4 unit ciphertexts are determined based on 4 combinations (i.e., 00, 01, 10, and 11), so the aggregation center can receive a total of 8 unit ciphertexts of operation unit A.
- the bit values corresponding to the determined mask data are 0 and 1 respectively
- the combination mode of the bit values is 01
- the aggregation center can determine the unit ciphertext corresponding to the combination mode 01 from the 8 unit ciphertexts of operation unit A sent by smart devices D1 and D2 , so the aggregation center can determine the two unit ciphertexts corresponding to operation unit A.
- the aggregation center can determine the first mask data and the first label value output by the AND operation unit corresponding to each unit ciphertext according to the determined label value and the unit ciphertext. Afterwards, each first mask data is used as the mask data output by the AND operation unit, and each first label value is used as the label value output by the AND operation unit.
- the operation node may also include several AND operation units and several XOR operation units, so in the above step S102, the aggregation center can determine the type of the operation unit for each operation node in the aggregation tree and for each operation unit in the operation node in turn according to each mask data and each label value.
- the operation unit is an XOR operation unit
- the mask data and label value output by the XOR operation unit are determined according to the above process, which will not be repeated here, and the determined mask data and label value are used as the mask data and label value of the next operation unit input to the XOR operation unit.
- the mask data and label value output by the AND operation unit are determined according to the above process, which will not be repeated here, and the determined mask data and label value are used as the mask data and label value of the next operation unit input to the AND operation unit, until the mask data and label value output by the last operation unit are determined, the mask data output by the last operation unit is used as the mask data output by the operation node, and the label value output by the last operation unit is used as the label value output by the operation node.
- the mask data output by the operation node is used as the mask data of the next operation node input to the operation node, and the label value output by the operation node is used as the label value of the next operation node input to the operation node, until the mask data and label value output by the last operation node are determined, and the mask data output by the last operation node is used as the mask result output by the aggregation tree.
- S104 Receive the mask bit share of the mask result and the message verification code corresponding to the mask bit share sent by each smart device, wherein each bit share is used to decrypt the mask result.
- the aggregation center can receive the mask bit share of the mask result sent by each smart device and the message verification code corresponding to the mask bit share. Afterwards, each mask bit share is verified according to the message verification code corresponding to each mask bit share. When the verification passes, the mask result is decrypted according to each mask bit share to determine the aggregation result. Among them, each smart device will send the mask bit share corresponding to the mask result to the aggregation center, and the mask bit share is used to decrypt the mask result finally output by the aggregation tree.
- the message verification code corresponding to the mask bit share is generated by the smart device based on the secure multi-party computing preprocessing function, and is used to verify whether the mask bit share sent by the smart device is accurate.
- each smart device can send a mask bit share to the aggregation center.
- Each mask bit share is a key generated by the smart device for the mask result output by the aggregation tree. Therefore, the aggregation center can decrypt the mask result output by the aggregation tree according to each mask bit share.
- the aggregation center can determine, for each mask bit share, the key and message verification code corresponding to the mask bit share generated based on the multi-party secure computing preprocessing function, and perform calculations based on the key and the mask bit share to determine the second calculation result. Afterwards, verify each mask bit share according to the second calculation result corresponding to each mask bit share and the message verification code corresponding to each mask bit share.
- the aggregation center when calculating according to the key and the mask bit share to determine the second calculation result, can determine the global key generated based on the secure multi-party computing preprocessing function, and use the global key to encrypt the mask bit share, and then perform an XOR operation on the encrypted result and the key determined in the above process, and use the result after the XOR operation as the second calculation result.
- z w represents the aggregation result
- z′ w represents the mask result
- the exclusive OR operation represents the share of each mask bit sent by the smart device Di
- n represents the number of smart devices.
- the aggregation center first receives the mask data sent by each smart device and the label value corresponding to each mask data.
- the mask data is the data after the smart device has masked the data to be aggregated, so that the privacy contained in the data to be aggregated of each smart device can be protected.
- each mask data is aggregated to determine the mask result.
- the mask data of each smart device is aggregated through the aggregation tree to determine the mask result, which protects the privacy contained in the data to be aggregated of each smart device, and the aggregation center only knows the mask result, but not the specific data to be aggregated of each smart device. In addition, the speed of data aggregation is accelerated and the time cost is reduced. Then, the mask bit share of the mask result sent by each smart device and the message verification code corresponding to the mask bit share are received, The aggregation center can verify each mask bit share according to the message verification code corresponding to each mask bit share, and ensure the accuracy of each mask bit share sent by each smart device.
- the mask result is decrypted according to each mask bit share to determine the aggregation result, so that the aggregation center uses each mask bit share that has passed the verification to decrypt the mask result to ensure the accuracy of the aggregation result.
- the aggregation center can only know the aggregation results of each smart device, but cannot know the specific data to be aggregated of each smart device, which ensures the privacy of the data to be aggregated of each smart device.
- the aggregation center in order to ensure the accuracy of the aggregation result, can verify whether the mask data output by the AND operation unit is accurate during the data aggregation based on the aggregation number. Therefore, in the above step S102, when the mask data and label value output by the AND operation unit are determined according to the determined label value and the unit ciphertext, the aggregation center can determine the mask data to be verified (i.e., the above-mentioned first mask data) output by the AND operation unit, the label value output by the AND operation unit, and the message verification code of the mask data to be verified output by the AND operation unit for each unit ciphertext according to the determined label value and the unit ciphertext.
- the mask data to be verified i.e., the above-mentioned first mask data
- each first calculation result is consistent with the message verification code corresponding to each mask data to be verified. If so, use each mask data to be verified as the mask data output by the AND operation unit. If not, determine the smart device corresponding to the mask data to be verified that failed the verification, and send a verification failure message to the determined smart device.
- the AND operation unit corresponds to a number of unit ciphertexts. The process of determining the first calculation result is similar to that of determining the second calculation result, which will not be repeated here.
- the message verification code representing the mask data to be verified of other smart devices Dj determined by the smart device D i is determined by the aggregation center according to the determined label value and the unit ciphertext.
- ⁇ i represents the global key of the smart device Di
- H(x) represents the hash function
- ⁇ represents the output of the AND operation unit
- s and t represent the two inputs of the AND operation unit respectively.
- the smart device after determining the mask data, can send the mask data to other smart devices other than itself and the aggregation center, and other smart devices can send the label value corresponding to the received mask data to the aggregation center.
- the label value is a K-bit bit string randomly generated by other smart devices based on the mask data, so one mask data corresponds to the label value generated by multiple smart devices. Therefore, in the above step S102, the aggregation center can receive each mask data sent by each smart device, and for each mask data, the aggregation center can receive the label value corresponding to the mask data sent by each smart device.
- the aggregation center can aggregate the mask data based on the pre-built aggregation tree according to the mask data and the label values corresponding to the mask data, and determine the aggregation tree output.
- the specific process is similar to the process in which each mask data corresponds to a label value, except that each mask data corresponds to multiple label values, and the label value output by each XOR operation unit and each AND operation unit is a set containing multiple label values. The specific process will not be repeated here.
- the aggregation center can be a power center, and the smart device can be an electric meter at a user's residence.
- the data to be aggregated can be the electricity consumption of the user's residence.
- the aggregation center can build an aggregation tree based on the number of smart devices, that is, the number of electric meters of the residents in the area to be aggregated (such as a community), and send it to each smart device. Afterwards, each electric meter masks the collected user's electricity consumption, determines the mask data, generates a corresponding label value based on the mask data, and sends the mask data and label value to the aggregation center.
- the aggregation center determines the mask result based on the aggregation tree according to the received mask data and label values. The aggregation center then decrypts the mask result according to the mask bit share corresponding to the mask result sent by each smart device, determines the aggregation result, that is, the overall electricity consumption of the area to be aggregated, and allocates electricity according to the overall electricity consumption of the area to be aggregated.
- the above-mentioned use of the aggregation tree for data aggregation speeds up the data aggregation, and the data input into the aggregation tree is masked data (that is, the user's electricity consumption is obtained by masking), so that the aggregation center cannot know the specific user's electricity consumption collected by each meter, thereby protecting the user's privacy.
- the mask result can be decrypted according to the mask bit share corresponding to the mask result sent by the meter to determine the aggregation result, that is, the overall electricity consumption of the area to be aggregated.
- the above-mentioned aggregation center can be a vehicle dispatching system
- the smart device can be an image acquisition device in the area to be dispatched
- the data to be aggregated can be the number of users.
- the specific data aggregation process is similar to the above-mentioned data aggregation process in the smart grid scenario, so it will not be repeated here.
- FIG3 is a flow chart of another method for data aggregation provided in the present disclosure, which specifically includes the following steps S200 to S208 .
- S202 Generate mask bit shares using a secure multi-party computing preprocessing function according to a topological structure of an aggregation tree, wherein the aggregation tree is pre-constructed by an aggregation center.
- S204 Process the data to be aggregated according to the mask bit share, determine mask data, and generate a label value corresponding to the mask data.
- the smart device can determine the data to be aggregated, and according to the topological structure of the aggregation tree, use the secure multi-party computing preprocessing function to generate a mask bit share, and then process the data to be aggregated according to the mask bit share, determine the mask data, and generate a label value corresponding to the mask data.
- the aggregation tree is constructed by the aggregation center according to the number of each smart device, and the leaf nodes in the aggregation tree represent the data to be aggregated corresponding to each smart device.
- All nodes except the leaf nodes in the aggregation tree are operation nodes, and the result output by the root operation node in the aggregation tree is the result of data aggregation of the data to be aggregated of each smart device.
- the data to be aggregated is the data collected by the smart device.
- the application scenario of data aggregation is different, the smart device may be different, and the data to be aggregated may also be different.
- the specific data of the smart device and the data to be aggregated in different scenarios is as described in the above step S100, which will not be repeated here.
- the secure multi-party computing preprocessing function is a function in the existing secure multi-party computing library, and the label value corresponding to the mask data generated above can be a label value randomly generated by the smart device based on the mask data.
- the smart device can respond to the aggregation request sent by the aggregation center, determine the aggregation tree pre-built by the aggregation center, and determine the data to be aggregated. Then, based on the topological structure of the aggregation tree, a secure multi-party computing preprocessing function is used to generate a mask bit share, and then based on the mask bit share, the data to be aggregated is processed to determine the mask data and generate a label value corresponding to the mask data.
- the smart device can be an electric meter at a user's residence in a community, and the data to be aggregated can be the electricity consumption of the user's residence.
- the electric meter can determine the electricity consumption of the user's residence, and based on the topological structure of the aggregation tree, a secure multi-party computing preprocessing function is used to generate a mask bit share, and then based on the mask bit share, the smart device can determine the electricity consumption of the user's residence.
- the power consumption is processed according to the mask bit share, the masked power consumption is determined, and a label value corresponding to the masked power consumption is generated.
- steps S200 and S202 may be performed in any order or simultaneously.
- S206 Send the mask data and the label value corresponding to the mask data to the aggregation center, so that the aggregation center determines the mask result according to the received mask data and label value sent by each smart device.
- the smart center can send the mask data and the label value corresponding to the mask data to the aggregation center, so that the aggregation center determines the mask result according to the mask data and label value received from each smart device.
- the aggregation tree includes several operation nodes, and the operation nodes may include AND operation units.
- One operation node may include one or more AND operation units. Therefore, when each operation node includes several AND operation units, when sending the mask data and the label value corresponding to the mask data to the aggregation center, the intelligent device needs to send the unit ciphertext corresponding to the AND operation unit in the aggregation tree to the aggregation center in addition to sending the mask data and the label value corresponding to the mask data to the aggregation center.
- the intelligent device can determine the verifiable mask bit share and label value input to the AND operation unit for each operation node in the aggregation tree, and for each AND operation unit in the operation node in turn, and use the secure multi-party computing preprocessing function to determine the triple of the AND operation unit, the verifiable mask bit share output by the AND operation unit, and the label value output by the AND operation unit. Then, according to the triple, the verifiable mask bit share input to the AND operation unit, the label value input to the AND operation unit, the verifiable mask bit share output by the AND operation unit, and the label value output by the AND operation unit, determine the unit ciphertext corresponding to the AND operation unit. Then, the unit ciphertext, mask data and label value corresponding to the mask data in each operation unit in the aggregation tree are sent to the aggregation center.
- the above-mentioned verifiable mask bit share includes the mask bit share, the message verification code corresponding to the mask bit share and the key of the message verification code corresponding to the mask bit share of other smart devices, and the other smart devices are devices other than the smart device itself.
- the verifiable mask bit share input to the operation node is generated by the smart device using a secure multi-party computing preprocessing function, and the label value input to the operation node is a K-bit bit string randomly generated by the smart device or the result of an XOR operation between a randomly generated K-bit bit string and a global key.
- the verifiable mask bit share output by the previous operation node of the operation node is determined to be the verifiable mask bit share input to the operation node, and the label value output by the previous operation node of the operation node is determined to be the label value input to the operation node.
- the verifiable mask bit share and label value input to the AND operation unit are the verifiable mask bit share and label value input to the operation node. If the AND operation unit is not the first operation unit in the operation node, the verifiable mask bit share and label value input to the AND operation unit are the verifiable mask bit share and label value output by the previous operation unit of the AND operation unit.
- a secure multi-party computation preprocessing function is used to determine the verifiable mask bit share and label value output by the previous operation unit of the AND operation unit, and the verifiable mask bit share output by the previous operation unit of the AND operation unit is used as the verifiable mask bit share input to the AND operation unit, and the label value output by the previous operation unit of the AND operation unit is used as the label value input to the AND operation unit.
- the operation node may also include a plurality of XOR operation units, and the previous operation unit of the AND operation unit may also be an XOR operation unit. Therefore, when determining the verifiable mask bit share and label value input to the AND operation unit, when the previous operation unit of the AND operation unit is an XOR operation unit, the verifiable mask bit share and label value of the previous operation unit (i.e., the XOR operation unit) input to the AND operation unit are determined. The verifiable mask bit share of the previous operation unit of the AND operation unit is determined, and the verifiable mask bit share output by the previous operation unit of the AND operation unit is used as the verifiable mask bit share output by the AND operation unit.
- the label value output by the previous operation unit of the AND operation unit is determined, and the label value output by the previous operation unit of the AND operation unit is used as the label value output by the AND operation unit.
- the smart device when determining the verifiable mask bit share output by the previous operation unit of the AND operation unit according to the verifiable mask bit share input to the previous operation unit of the AND operation unit, the smart device can perform an XOR operation on the verifiable mask bit share input to the previous operation unit of the AND operation unit to determine the verifiable mask bit share output by the previous operation unit of the AND operation unit.
- the smart device when determining the label value output by the previous operation unit of the AND operation unit according to the label value input to the previous operation unit of the AND operation unit, the smart device can perform an XOR operation on the label value input to the previous operation unit of the AND operation unit to determine the label value output by the previous operation unit of the AND operation unit.
- the above triplet is three parameters generated by using a secure multi-party computation preprocessing function, and the triplet includes a first value, a second value, and a third value.
- the verifiable mask bit share input to the AND operation unit includes a first verifiable mask bit share and a second verifiable mask bit share.
- operation nodes to which the smart device belongs there are operation nodes to which the smart device belongs and operation nodes unrelated to the smart device in the aggregation tree.
- the smart device directly inputs data or indirectly inputs data to a certain operation node in the aggregation tree, then the operation node is the operation node to which the smart device belongs, and the operation nodes other than the operation node to which the smart device belongs are operation nodes unrelated to the smart device.
- the smart devices D1 and D2 in Figure 2 both input data to a certain operation node in the upstream operation node, the smart devices D1 and D2 both belong to the operation node, and the operation node that uses the data output by the operation node as input (i.e., indirect input) is also the operation node to which the smart devices D1 and D2 belong.
- the above-mentioned operation node may be an operation node to which the smart device belongs.
- the smart device may determine the first value according to the first numerical value in the triple and the first verifiable mask bit share input to the AND operation unit, and determine the second value according to the second numerical value in the triple and the second verifiable mask bit share input to the AND operation unit.
- the following formulas (3) to (4) may be used for calculation:
- the AND operation unit is the first operation unit in the operation node, and the operation node is the upstream operation node of the leaf node in the aggregation tree
- the first verifiable mask bit share and the second verifiable mask bit share represent the verifiable mask bit shares of different smart devices input into the AND operation unit.
- the smart device can generate a verifiable mask bit share input into the AND operation unit, and another verifiable mask bit share input into the AND operation unit can be directly set to 0.
- the verifiable mask bit share of the AND operation unit to the smart device Di if the above Input the verifiable mask bit share of the AND operation unit to the smart device Di, then The verifiable mask bit share for processing the aggregated data generated by the smart device Di based on the secure multi-party computing preprocessing function, The default value is 0; if the above Input the verifiable mask bit share of the AND operation unit to the smart device Di , then the above It can also default to 0.
- the aggregate data generated by the secure multi-party computing preprocessing function can be used for the smart device Di The share of verifiable masked bits that are processed.
- the corresponding message verification code, represents the key corresponding to the message authentication code corresponding to the mask bit share of the input computing node or the AND computing unit generated by other smart devices D j . or is only generated by the smart device Di and has nothing to do with other smart devices.
- the smart device Di cannot or Inform other smart devices, and there is no need for mutual verification between smart devices. Based on this, in order to save the storage cost and communication overhead of each smart device, each smart device does not need to store the data generated by other smart devices. or The corresponding message authentication code corresponds to the key, so the above Can default to 0.
- the other smart devices are smart devices that belong to the computing node together with the smart device, that is, the other smart devices are smart devices other than the smart device (that is, the smart device Di, that is, the smart device as the execution subject) among the smart devices that input data to the computing node.
- the third value and the fourth value sent by other smart devices are received, and the received third value and the first value are aggregated to determine the first total value, and the received fourth value and the second value are aggregated to determine the second total value.
- the following formulas (6) to (7) can be used for calculation:
- d ⁇ represents the first total value determined by the smart device Di
- n represents the number of smart devices
- e ⁇ represents the second total value determined by the smart device Di.
- the second value is determined similarly to the fourth value, but is determined locally by different smart devices.
- the mask data to be verified output by the AND operation unit is determined according to the first total value, the second total value, the triplet, the share of the verifiable mask bits output by the AND operation unit, and the share of the verifiable mask bits input to the AND operation unit.
- the following formulas (8) to (9) can be used for calculation:
- the key corresponding to the message authentication code of other smart devices stored in the verifiable mask bit share output by the AND operation unit can only be the key corresponding to the message authentication code of the other smart devices determined above, that is, the key corresponding to the message authentication code of the other smart devices output by the AND operation unit.
- the verification mask bit share stores the keys corresponding to the message verification codes of the smart devices other than the smart devices (i.e., the smart devices serving as the execution subject) among the smart devices that input data to the AND operation node.
- the keys corresponding to the message verification codes of the smart devices that do not input data to the AND operation node do not need to be stored and are directly defaulted to 0.
- t and s are bit values, and each t, s ⁇ 0,1 ⁇ .
- the unit ciphertext corresponding to the AND operation unit is determined according to the mask data to be verified output by the AND operation unit, the label value input to the AND operation unit, and the label value output by the AND operation unit. Specifically, the following formula (10) can be used for calculation:
- ⁇ represents the output of the AND operation unit
- the message verification code representing the mask data to be verified output by the AND operation unit represents the label value output by the AND operation unit when the bit value determined by the smart device Di is 0
- ⁇ i represents the global key of the smart device Di
- It represents the key corresponding to the message verification code of the mask data to be verified output by the operation unit and determined by other smart devices Dj and stored in the smart device D i .
- the AND operation unit is the first operation unit in the operation node, and the operation node is the upstream operation node of the leaf node in the aggregation tree, the above and They are all K-bit bit strings randomly generated by the smart device Di , but the bit values are t and s respectively.
- the operation node mentioned above can also be an operation node unrelated to the smart device, so the verifiable mask bit share input to the operation node is 0, the generated triples of the AND operation unit are also 0, and the verifiable mask bit share output by the AND operation unit is also 0.
- the smart device can determine the first value according to the first value in the triple and the first verifiable mask bit share input to the AND operation unit, and determine the second value according to the second value in the triple and the verifiable mask bit share input to the AND operation unit.
- the mask data to be verified output by the AND operation unit is determined.
- the unit ciphertext corresponding to the AND operation unit is determined according to the mask data to be verified output by the AND operation unit, the label value input to the AND operation unit, and the label value output by the AND operation unit.
- the smart device can also send the mask data to other smart devices other than the smart device, so that the other smart devices generate the label value corresponding to the mask data and send it to the aggregation center. And, the masked data and the label value corresponding to the masked data are sent to the aggregation center.
- other smart devices other than the smart device can determine the label value corresponding to the mask data based on the received mask data, and send it to the aggregation center.
- the label value corresponding to the mask data is a K-bit bit string randomly generated by the other smart device based on the bit value of the mask data.
- the specific process is similar to the process of generating the label value in the above step S202, and will not be repeated here.
- the aggregation center can receive the mask data sent by each smart device, as well as each label value corresponding to each mask data.
- S208 Determine the mask bit share corresponding to the mask result output by the aggregation tree and the message verification code corresponding to the mask bit share, and send the determined mask bit share and message verification code to the aggregation center, so that the aggregation center verifies the mask bit shares according to the received mask bit shares and the message verification code corresponding to the mask bit shares, and when the verification passes, the aggregation center verifies the mask bit shares according to the mask bit shares. and the mask result to determine the aggregation result.
- the smart device can determine the mask bit share corresponding to the mask result output by the aggregation tree and the message verification code corresponding to the mask bit share, and send the determined mask bit share and message verification code to the aggregation center, so that the aggregation center verifies each mask bit share according to the received mask bit share and the message verification code corresponding to each mask bit share, and when the verification passes, determines the aggregation result according to each mask bit share and the mask result.
- the mask bit share is used to decrypt the mask result.
- the message verification code corresponding to the mask bit share is generated by the smart device based on the secure multi-party computing preprocessing function, and is used to verify whether the mask bit share sent by the smart device is accurate.
- the smart device can determine the verifiable mask bit share output by the XOR operation unit according to the verifiable mask bit share input to the XOR operation unit, and send the mask bit share stored in the verifiable mask bit share and the message verification code corresponding to the mask bit share to the aggregation center.
- the smart device can use a secure multi-party computing preprocessing function to generate the verifiable mask bit share output by the AND operation unit, and send the mask bit share stored in the verifiable mask bit share and the message verification code corresponding to the mask bit share to the aggregation center.
- the present disclosure also provides a data aggregation device, which is applied to an aggregation center, as shown in FIG4 .
- FIG4 is a schematic diagram of a data aggregation device provided by the present disclosure, including:
- a first receiving module 300 is used to receive mask data sent by each smart device and a label value corresponding to each mask data, wherein the mask data is data processed by the smart device based on the mask bit share to be aggregated, and the mask bit share is generated by the smart device based on a secure multi-party computing preprocessing function;
- Aggregation module 302 configured to aggregate the mask data according to the mask data and the label values based on a pre-built aggregation tree to determine a mask result
- a second receiving module 304 is used to receive the mask bit share of the mask result and the message verification code corresponding to the mask bit share sent by each smart device, wherein each mask bit share is used to decrypt the mask result;
- a verification module 306 configured to verify each mask bit share according to a message verification code corresponding to each mask bit share
- the decryption module 308 is used to decrypt the mask result according to the mask bit shares to determine the aggregation result when the verification is passed.
- the aggregation tree includes a plurality of operation nodes, each of which includes a plurality of XOR operation units;
- the aggregation module 302 is specifically used to, according to the mask data and the label values, determine the mask data and the label value input to each operation node in the pre-constructed aggregation tree, and in turn for each XOR operation unit in the operation node; perform XOR operation on the determined mask data to determine the mask data output by the XOR operation unit; and perform XOR operation on the determined label value to determine the label value output by the XOR operation unit; use the mask data output by the XOR operation unit as the mask data input to the next XOR operation unit of the XOR operation unit, and use the label value output by the XOR operation unit as the label value input to the next XOR operation unit of the XOR operation unit, until the mask data and label value output by the last XOR operation unit are determined, use the mask data output by the last XOR operation unit as the mask data output by the operation node, and use the label value output by the last XOR operation unit as the label value output by the operation node; use the mask data output by
- the aggregation tree includes a plurality of operation nodes, and each operation node includes a plurality of AND operation units;
- the first receiving module 300 is specifically used to send the pre-built aggregation tree to each smart device; receive the unit ciphertext of each operation unit in the aggregation tree, the mask data and the label value corresponding to the mask data sent by each smart device;
- the aggregation module 302 is specifically used to, according to the mask data and the label values, determine the mask data input to the AND operation unit for each operation node in the aggregation tree and, in turn, for each AND operation unit in the operation node, and determine the unit ciphertext corresponding to the AND operation unit according to the determined mask data; determine the label value input to the AND operation unit, and determine the mask data and label value output by the AND operation unit according to the determined label value and the unit ciphertext; use the mask data output by the AND operation unit as the mask data input to the next AND operation unit of the AND operation unit, and use the label value output by the AND operation unit as the label value input to the next AND operation unit of the AND operation unit.
- the label value of the operation unit is determined until the mask data and the label value output by the last operation unit are determined, and the mask data output by the last operation unit is used as the mask data output by the operation node, and the label value output by the last operation unit is used as the label value output by the operation node; the mask data output by the operation node is used as the mask data of the next operation node input to the operation node, and the label value output by the operation node is used as the label value of the next operation node input to the operation node, until the mask data and the label value output by the last operation node are determined, and the mask data output by the last operation node is used as the mask result output by the aggregation tree.
- the AND operation unit corresponds to a number of unit ciphertexts
- the aggregation module 302 is specifically used to determine, for each unit ciphertext, the mask data to be verified output by the AND operation unit, the label value output by the AND operation unit, and the message verification code of the mask data to be verified output by the AND operation unit according to the determined label value and the unit ciphertext; determine the key of the message verification code of the mask data to be verified output by the AND operation unit generated based on the secure multi-party computing preprocessing function, and perform calculations based on the key and the mask data to be verified output by the AND operation unit to determine a first calculation result; determine whether each first calculation result is consistent with the message verification code corresponding to each mask data to be verified; if so, use each mask data to be verified as the mask data output by the AND operation unit; if not, determine the smart device corresponding to the mask data to be verified that failed the verification, and send a verification failure message to the determined smart device.
- the verification module 306 is specifically used to determine, for each mask bit share, a key and a message verification code corresponding to the mask bit share generated based on the multi-party secure computing preprocessing function, perform calculations based on the key and the mask bit share to determine a second calculation result; and verify each mask bit share based on the second calculation result corresponding to each mask bit share and the message verification code corresponding to each mask bit share.
- the present disclosure also provides a data aggregation device, which is applied to a smart device, as shown in FIG5 , which is a schematic diagram of the structure of another data aggregation device provided by the present disclosure, including:
- a determination module 400 is used to determine the data to be aggregated
- a generating module 402 is used to generate a mask bit share according to a topological structure of an aggregation tree by using a secure multi-party computing preprocessing function, wherein the aggregation tree is pre-constructed by an aggregation center;
- the encryption module 404 is used to process the data to be aggregated according to the mask bit share, determine the mask data, and generate a label value corresponding to the mask data;
- the sending module 406 is used to send the mask data and the label value corresponding to the mask data to the aggregate
- the aggregation center determines the mask result according to the mask data and label value received from each smart device
- the mask module 408 is used to determine the mask bit share corresponding to the mask result output by the aggregation tree and the message verification code corresponding to the mask bit share, and send the determined mask bit share and message verification code to the aggregation center, so that the aggregation center verifies each mask bit share according to the received mask bit share and the message verification code corresponding to each mask bit share, and when the verification passes, determines the aggregation result according to each mask bit share and the mask result.
- the aggregation tree includes a plurality of operation nodes, and each operation node includes a plurality of AND operation units;
- the sending module 406 is specifically used to determine, for each operation node in the aggregation tree, and for each AND operation unit in the operation node in turn, the verifiable mask bit share and the label value input to the AND operation unit; using the secure multi-party computation preprocessing function to determine the triple of the AND operation unit, the verifiable mask bit share output by the AND operation unit, and the label value output by the AND operation unit; determine the unit ciphertext corresponding to the AND operation unit according to the triple, the verifiable mask bit share input to the AND operation unit, the label value input to the AND operation unit, the verifiable mask bit share output by the AND operation unit, and the label value output by the AND operation unit; and send the unit ciphertext corresponding to each AND operation unit of each operation node in the aggregation tree, the mask data, and the label value corresponding to the mask data to the aggregation center.
- the computing node further includes a plurality of XOR computing units
- the sending module 406 is specifically used to, when the previous operation unit of the AND operation unit is an XOR operation unit, determine the verifiable mask bit share and label value of the previous operation unit input into the AND operation unit; determine the verifiable mask bit share output by the previous operation unit of the AND operation unit according to the verifiable mask bit share of the previous operation unit input into the AND operation unit, and use it as the verifiable mask bit share input into the AND operation unit; determine the label value output by the previous operation unit of the AND operation unit according to the label value of the previous operation unit input into the AND operation unit, and use it as the label value input into the AND operation unit.
- the computing node is a computing node to which the smart device belongs, the triplet includes a first value, a second value, and a third value, and the verifiable mask bit share input into the AND operation unit includes a first verifiable mask bit share and a second verifiable mask bit share;
- the sending module 406 is specifically used to determine a first value according to the first numerical value in the triplet and the first verifiable mask bit share input to the AND operation unit, and determine a second value according to the second numerical value in the triplet and the second verifiable mask bit share input to the AND operation unit, and send the first value and the second value to other intelligent devices, wherein the other intelligent devices are intelligent devices other than the intelligent device among the intelligent devices that input data to the operation node; receive a third value and a fourth value sent by the other intelligent devices, aggregate the received third value and the first value to determine a first total value, and aggregate the received fourth value and the second value to determine a second total value; determine the mask data to be verified output by the AND operation unit according to the first total value, the second total value, the triplet, the verifiable mask bit share output by the AND operation unit, and the verifiable mask bit share input to the AND operation unit; determine the unit ciphertext corresponding to the AND operation unit according to the mask data to be verified output by the AND operation
- the sending module 406 is specifically used to send the mask data to other smart devices other than the smart device, so that the other smart devices generate label values corresponding to the mask data and send them to the aggregation center, and send the mask data and the label values corresponding to the mask data to the aggregation center.
- the present disclosure also provides a computer-readable storage medium, which stores a computer program.
- the computer program is executed by a processor, the above-mentioned data aggregation method is implemented.
- the present disclosure also provides an electronic device.
- the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include hardware required for other services.
- the processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the above-mentioned data aggregation method.
- a programmable logic device such as a field programmable gate array (FPGA)
- FPGA field programmable gate array
- HDL Hardware Description Language
- HDL Very-High-Speed Integrated Circuit Hardware Description Language
- ABEL Advanced Boolean Expression Language
- AHDL Altera Hardware Description Language
- HDCal Joint CHDL
- JHDL Java Hardware Description Language
- Lava Lava
- Lola MyHDL
- PALASM RHDL
- VHDL Very-High-Speed Integrated Circuit Hardware Description Language
- Verilog Verilog
- the controller may be implemented in any suitable manner, for example, the controller may take the form of a microprocessor or processor and a computer readable medium storing a computer readable program code (e.g., software or firmware) executable by the (micro)processor, a logic gate, a switch, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320, and the memory controller may also be implemented as part of the control logic of the memory.
- a computer readable program code e.g., software or firmware
- the controller may be implemented in the form of a logic gate, a switch, an application specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, such a controller may be considered as a hardware component, and the means for implementing various functions included therein may also be considered as a structure within the hardware component. Or even, the means for implementing various functions may be considered as both a software module for implementing the method and a structure within the hardware component.
- a typical implementation device is a computer.
- the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
- the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
- computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
- These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.
- These computer program instructions may also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.
- a computing device includes one or more processors (CPU), input/output interfaces, network interfaces, and memory.
- processors CPU
- input/output interfaces network interfaces
- memory volatile and non-volatile memory
- Memory may include non-permanent storage in a computer-readable medium, in the form of random access memory (RAM) and/or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
- RAM random access memory
- ROM read-only memory
- flash RAM flash random access memory
- Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information.
- Information can be computer readable instructions, data structures, program modules or other data.
- Examples of computer storage media include, but are not limited to, Phase Change RAM (PRAM), Static Random-Access Memory (SRAM), Dynamic Random Access Memory (DRAM), other types of random access memory (RAM), Read Only Memory (ROM), Electrically Erasable Programmable Read Only Memory (EEPROM), Flash Memory or other memory technology, Compact Disc Read Only Memory (CD-ROM), Digital Versatile Disc (DVD) or other optical storage, magnetic cassettes, tape and disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
- computer-readable media does not include transitory media such as modulated data signals and carrier waves.
- program modules include routines, programs, objects, and programs that perform specific tasks or implement specific abstract data types. Components, data structures, etc.
- the present disclosure can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network.
- program modules can be located in local and remote computer storage media including storage devices.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Computational Linguistics (AREA)
- Data Mining & Analysis (AREA)
- Databases & Information Systems (AREA)
- Storage Device Security (AREA)
Abstract
本公开提供了一种数据聚合的方法、装置、存储介质及电子设备,所述方法包括:接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值。根据各掩码数据以及各标签值,基于预先构建的聚合树,对各掩码数据进行聚合,确定掩码结果。然后,接收各智能设备发送的掩码结果的掩码比特份额以及掩码比特份额对应的消息验证码,根据各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证。在验证通过时,根据各掩码比特份额对掩码结果进行解密,确定聚合结果,保证各智能设备发送的各掩码比特份额的准确性,并采用验证通过的各掩码比特份额对掩码结果进行解密,保证聚合结果的准确性。
Description
本公开涉及计算机技术领域,尤其涉及一种数据聚合的方法、装置、存储介质及电子设备。
随着科技的不断发展,数据聚合得到了广泛的关注。数据聚合是将不同数据源的数据合并起来的技术,常见于物联网场景中。
目前,为用户提供服务的智能设备,比如智能手机、智能电表以及智能手表等智能设备,可以收集用户使用智能设备时产生的用户数据,但每一个智能设备收集到的用户数据不同,为了更好地为用户提供服务,可以将智能设备收集到的用户数据进行聚合,并对聚合后的数据进行分析,再根据分析结果,对用户提供服务。但是,用户数据往往会包含用户的隐私数据,各智能设备在基于收集到的用户数据进行聚合时,需要保证不泄露用户的隐私数据。因此,如何在保护用户隐私的前提下进行数据聚合是一个重要的问题。
基于此,本公开提供一种数据聚合的方法。
发明内容
本公开提供一种数据聚合的方法、装置、存储介质及电子设备。
本公开采用下述技术方案:
本公开提供了一种数据聚合的方法,所述方法应用于聚合中心,所述方法包括:
接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,其中,所述掩码数据为所述智能设备基于掩码比特份额对待聚合数据进行处理后的数据,所述掩码比特份额是所述智能设备基于安全多方计算预处理函数生成的;
根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果;
接收所述各智能设备发送的所述掩码结果的掩码比特份额以及所述掩码比特份额对应的消息验证码,其中,各掩码比特份额用于对所述掩码结果进行解密;
根据所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证;
在验证通过时,根据所述各掩码比特份额对所述掩码结果进行解密,确定聚合结果。
可选地,所述聚合树包括若干运算节点,各运算节点分别包括若干异或运算单元;
根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果,具体包括:
根据所述各掩码数据以及各标签值,针对预先构建的聚合树中的每一个运算节点,且依次针对该运算节点中的每一个异或运算单元,确定输入该异或运算单元的掩码数据以及标签值;
将确定出的掩码数据进行异或运算,确定该异或运算单元输出的掩码数据;以及将确定出的标签值进行异或运算,确定该异或运算单元输出的标签值;
将该异或运算单元输出的掩码数据作为输入该异或运算单元的下一个异或运算单元的掩码数据,以及将该异或运算单元输出的标签值作为输入该异或运算单元的下一个异或运算单元的标签值,直到确定出最后一个异或运算单元输出的掩码数据以及标签值时,将所述最后一个异或运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将所述最后一个异或运算单元输出的标签值作为该运算节点输出的标签值;
将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值时,将所述最后一个运算节点输出的掩码数据作为所述聚合树输出的掩码结果。
可选地,所述聚合树包括若干运算节点,各运算节点分别包括若干与运算单元;
接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,具体包括:
将预先构建的聚合树发送给各智能设备;
接收所述各智能设备发送的所述聚合树中各与运算单元的单元密文、掩码数据以及所述掩码数据对应的标签值;
根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果,具体包括:
根据所述各掩码数据以及各标签值,针对所述聚合树中的每一个运算节点,且依次针对该运算节点中的每一个与运算单元,确定输入该与运算单元的掩码数据,并根据确定出的掩码数据,确定该与运算单元对应的单元密文;
确定输入该与运算单元的标签值,并根据确定出的标签值以及所述单元密文,确定该与运算单元输出的掩码数据以及标签值;
将该与运算单元输出的掩码数据作为输入该与运算单元的下一个与运算单元的掩码数据,以及将该与运算单元输出标签值作为输入该与运算单元的下一个与运算单元的标签值,直到确定出最后一个与运算单元输出的掩码数据以及标签值时,将所述最后一个与运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将所述最后一个与运算单元输出的标签值作为该运算节点输出的标签值;
将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值时,将所述最后一个运算节点输出的掩码数据作为所述聚合树输出的掩码结果。
可选地,该与运算单元对应若干单元密文;
根据确定出的标签值以及所述单元密文,确定该与运算单元输出的掩码数据以及标签值,具体包括:
针对每一个单元密文,根据确定出的标签值以及该单元密文,确定该与运算单元输出的待验证掩码数据、该与运算单元输出的标签值以及该与运算单元输出的待验证掩码数据的消息验证码;
确定基于所述安全多方计算预处理函数生成的该与运算单元输出的待验证掩码数据的消息验证码的密钥,并根据所述密钥以及该与运算单元输出的待验证掩码数据,进行计算,确定第一计算结果;
判断各第一计算结果与各待验证掩码数据对应的消息验证码是否一致;
若是,将各待验证掩码数据作为该与运算单元输出的掩码数据;
若否,确定验证不通过的待验证掩码数据对应的智能设备,并向确定出的智能设备发送验证不通过的消息。
可选地,根据所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证,具体包括:
针对每一个掩码比特份额,确定基于所述多方安全计算预处理函数生成的该掩码比特份额对应的密钥以及消息验证码,根据所述密钥以及该掩码比特份额,进行计算,确定第二计算结果;
根据所述各掩码比特份额对应的第二计算结果以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证。
本公开还提供了一种数据聚合的方法,所述方法应用于智能设备,所述方法包括:
确定待聚合数据;
根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,其中,所述聚合树为聚合中心预先构建的;
根据所述掩码比特份额,对所述待聚合数据进行处理,确定掩码数据,并生成所述掩码数据对应的标签值;
将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,使所述聚合中心根据接收到的各智能设备发送的掩码数据和标签值,确定掩码结果;
确定所述聚合树输出的掩码结果对应的掩码比特份额以及所述掩码比特份额对应的消息验证码,并将确定出的掩码比特份额以及消息验证码发送给所述聚合中心,使所述聚合中心根据接收到的各掩码比特份额以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证,并在验证通过时,根据所述各掩码比特份额以及所述掩码结果,确定聚合结果。
可选地,所述聚合树包括若干运算节点,各运算节点分别包括若干与运算单元;
将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,具体包括:
针对所述聚合树中的每一个运算节点,且依次针对该运算节点中的每一个与运算单元,确定输入该与运算单元的可验证掩码比特份额以及标签值;
采用所述安全多方计算预处理函数,确定该与运算单元的三元组、该与运算单元输出的可验证掩码比特份额以及该与运算单元输出的标签值;
根据所述三元组、所述输入该与运算单元的可验证掩码比特份额、所述输入该与运算单元的标签值、所述该与运算单元输出的可验证掩码比特份额以及所述该与运算单元输出的标签值,确定该与运算单元对应的单元密文;
将所述聚合树中各运算节点的各与运算单元对应的单元密文、所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心。
可选地,所述运算节点还包括若干异或运算单元;
确定输入该与运算单元的可验证掩码比特份额以及标签值,具体包括:
当该与运算单元的上一个运算单元为异或运算单元时,确定输入该与运算单元的上一个运算单元的可验证掩码比特份额以及标签值;
根据所述输入该与运算单元的上一个运算单元的可验证掩码比特份额,确定该与运算单元的上一个运算单元输出的可验证掩码比特份额,并作为输入该与运算单元的可验证掩码比特份额;
根据所述输入该与运算单元的上一个运算单元的标签值,确定该与运算单元的上一个运算单元输出的标签值,并作为输入该与运算单元的标签值。
可选地,该运算节点为所述智能设备所属的运算节点,所述三元组包括第一数值、第二数值以及第三数值,所述输入该与运算单元的可验证掩码比特份额包括第一可验证掩码比特份额以及第二可验证掩码比特份额;
根据所述三元组、所述输入该与运算单元的可验证掩码比特份额、所述输入该与运算单元的标签值、所述该与运算单元输出的可验证掩码比特份额以及所述该与运算单元输出的标签值,确定该与运算单元对应的单元密文,具体包括:
根据所述三元组中的第一数值以及所述输入该与运算单元的第一可验证掩码比特份额,确定第一值,以及根据所述三元组中的第二数值以及所述输入该与运算单元的第二可验证掩码比特份额,确定第二值,并将所述第一值以及所述第二值发送给其他智能设备,其中,所述其他智能设备为向该运算节点输入数据的智能设备中除所述智能设备之外的智能设备;
接收所述其他智能设备发送的第三值以及第四值,并将接收到的第三值以及所述第一值聚合,确定第一总值,以及将接收到的第四值以及所述第二值聚合,确定第二总值;
根据所述第一总值、所述第二总值、所述三元组、所述该与运算单元输出的可验证掩码比特份额以及所述输入该与运算单元的可验证掩码比特份额,确定该与运算单元输出的待验证掩码数据;
根据该与运算单元输出的待验证掩码数据、所述输入该与运算单元的标签值以及所述该与运算单元输出的标签值,确定该与运算单元对应的单元密文。
可选地,将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,具体包括:
将所述掩码数据发送给除所述智能设备之外的其他智能设备,使所述其他智能设备生成所述掩码数据对应的标签值并发送给所述聚合中心,以及将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心。
本公开提供了一种数据聚合的装置,所述装置应用于聚合中心,所述装置包括:
第一接收模块,用于接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,其中,所述掩码数据为所述智能设备基于掩码比特份额对待聚合数据进行处理后的数据,所述掩码比特份额是所述智能设备基于安全多方计算预处理函数生成的;
聚合模块,用于根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果;
第二接收模块,用于接收所述各智能设备发送的所述掩码结果的掩码比特份额以及所述掩码比特份额对应的消息验证码,其中,各掩码比特份额用于对所述掩码结果进行解密;
验证模块,用于根据所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证;
解密模块,用于在验证通过时,根据所述各掩码比特份额对所述掩码结果进行解密,确定聚合结果。
本公开还提供的一种的数据聚合的装置,所述装置应用于智能设备,所述装置包括:
确定模块,用于确定待聚合数据;
生成模块,用于根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,其中,所述聚合树为聚合中心预先构建的;
加密模块,用于根据所述掩码比特份额,对所述待聚合数据进行处理,确定掩码数据,并生成所述掩码数据对应的标签值;
发送模块,用于将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,使所述聚合中心根据接收到的各智能设备发送的掩码数据和标签值,确定掩码结果;
掩码模块,用于确定所述聚合树输出的掩码结果对应的掩码比特份额以及所述掩码比特份额对应的消息验证码,并将确定出的掩码比特份额以及消息验证码发送给所述聚合中心,使所述聚合中心根据接收到的各掩码比特份额以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证,并在验证通过时,根据所述各掩码比特份额以及所述掩码结果,确定聚合结果。
本公开提供了一种计算机可读存储介质,所述存储介质存储有计算机程序,所述计算机程序被处理器执行时实现上述数据聚合的方法。
本公开提供了一种电子设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现上述数据聚合的方法。
本公开采用的上述至少一个技术方案能够达到以下有益效果:
本公开提供的数据聚合的方法,先接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值。根据各掩码数据以及各标签值,基于预先构建的聚合树,对各掩码数据进行聚合,确定掩码结果。然后,接收各智能设备发送的掩码结果的掩码比特份额以及掩码比特份额对应的消息验证码,根据各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证。在验证通过时,根据各掩码比特份额对掩码结果进行解密,确定聚合结果。
从上述方法中可以看出,本申请在进行数据聚合时,接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值。根据各掩码数据以及各标签值,基于预先构建的聚合树,对各掩码数据进行聚合,确定掩码结果。然后,接收各智能设备发送的掩码结果的掩码比特份额以及掩码比特份额对应的消息验证码,根据各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证。在验证通过时,根据各掩码比特份额对掩码结果进行解密,确定聚合结果,可以保证各智能设备发送的各掩码比特份额的准确性,并采用验证通过的各掩码比特份额对掩码结果进行解密,可以保证聚合结果的准确性。
此处所说明的附图用来提供对本公开的进一步理解,构成本公开的一部分,本公开的示意性实施例及其说明用于解释本公开,并不构成对本公开的不当限定。在附图中:
图1为本公开中提供的一种数据聚合的方法的流程示意图;
图2为本公开中提供的一种聚合树的示意图;
图3为本公开中提供的另一种数据聚合的方法的流程示意图;
图4为本公开提供的一种数据聚合的装置结构的示意图;
图5为本公开提供的另一种数据聚合的装置结构的示意图;
图6为本公开提供的一种电子设备的结构示意图。
为使本公开的目的、技术方案和优点更加清楚,下面将结合本公开具体实施例及相应的附图对本公开技术方案进行清楚、完整地描述。显然,所描述的实施例仅是本公开一部分实施例,而不是全部的实施例。基于本公开中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本公开保护的范围。
以下结合附图,详细说明本公开各实施例提供的技术方案。
本公开提供了一种数据聚合的方法,所述方法应用于聚合中心,如图1所示,图1为本公开中提供的一种数据聚合的方法的流程示意图,具体包括以下步骤S100~S108。
S100:接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,其中,所述掩码数据为所述智能设备基于掩码比特份额对待聚合数据进行处理后的数据,所述掩码比特份额是所述智能设备基于安全多方计算预处理函数生成的。
本公开中,为了更好地为用户提供服务,聚合中心可以将智能设备收集到的用户数据进行聚合,并对聚合后的数据进行分析,再根据分析结果,为用户提供服务。比如,在车辆调度场景中,待调度区域中每一个建筑物中均有一个或者多个用于收集用户数据的智能设备,该智能设备可以是建筑物中的照相机、摄像机等图像采集设备,该用户数据包括采集到的用户的图像、用户的数量、用户到达建筑物的时间以及用户离开建筑物的时间等信息。车辆调度系统(即聚合中心)可以将每一个智能设备收集到的用户数据进行聚合,并对聚合后的数据进行分析,确定分析结果,该分析结果可以为每一个时间段在待调度区域的用户流量,根据确定出的分析结果,合理调度车辆前往待调度区域。但是,用户数据中可能包含用户或者智能设备所在的建筑物的隐私数据,比如用户的个人信息、用户的图像等信息,故在进行数据聚合时,若智能设备直接将收集到的用户数据给聚合中心,聚合中心可以获知每一个智能设备收集到的具体的数据,会泄露用户的隐私或者智能设备的隐私。
基于此,在数据聚合中,用于数据聚合的设备,即聚合中心,可以接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,其中,聚合中心可以是系统、服务器,也可以是诸如台式电脑、笔记本电脑等电子设备。为了便于描述,下面以聚合中心为执行主体,对本公开提供的数据聚合的方法进行说明。智能设备为任意可以收集数据的设备。不同数据聚合场景下,智能设备可能相同,也可能不同。同理,聚合中心也可能相同,也可能不同。在车辆调度场景下,聚合中心可以为车辆调度系统,也可以为能够调度车辆的服务提供方。智能设备可以是待调度区域中的照相机、摄像机等图像采集设备。在智能电网场景下,聚合中心可以为电力中心,智能设备可以为用户的住宅的电表。为了便于说明,以下均以聚合中心以及智能设备为例进行说明。掩码数据为智能设备基于掩码比特份额对待聚合数据进行处理后的数据,掩码比特份额是智能设备基于安全多方计算(Secure Multi-party Computation,MPC)预处理函数生成的,掩码数据对应的标签值为智能设备基于掩码数据随机生成的比特串。安全多方计算预处理函数为已有的安全多方计算库中的函数,该安全多方计算预处理函数可以基于聚合树生成各智能设备以及聚合中心的全局密钥、输入聚合树中各运算节点的数据的掩码比特份额、聚合树中各运算节点输出的数据的掩码比特份额、所需验证的各掩码比特份额的消息验证码以及各验证码对应的密钥。
在本公开中,由于数据聚合应用的场景不同,智能设备收集到的数据可能不同,待聚合数据也可能不同。在车辆调度场景下,智能设备收集到的用户数据包括采集到的用户的图像、用户的数量、用户到达建筑物的时间以及用户离开建筑物的时间等信息,故待聚合数据可以为上述用户数据,也可以为上述用户的数量等部分用户数据,本公开不做限定。在智能电网场景下,智能设备收集到的用户数据包括用户信息、用户的用电量、用户的住址以及用户的用电时间段等信息,故待聚合数据可以为上述用户数据,也可以为用户的用电量等部分用户数据,本公开不做具体限定。另外,由于待聚合数据中包含用户的隐私数据,故智能设备可以先对待聚合数据进行掩码处理,再将掩码后的待聚合数据(即掩码数据)发送给聚合中心,以保证待聚合数据中包含的用户的隐私数据不泄露。
具体的,每一个智能设备可以基于安全多方计算预处理函数生成掩码比特份额,确定待聚合数据,并采用掩码比特份额对待聚合数据进行处理,确定掩码数据,生成掩码数据对应的标签值,将掩码数据以及相应的标签值发送给聚合中心。聚合中心接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值。其中,标签值可以为智能设备基于掩码数据随机生成的比特串,当掩码数据的比特值为0时,智能设备可以随机生成K比特的比特串作为标签值,当掩码数据的比特值为1时,智能设备可以将比特值为0时生成的比特串与预先存储的全局密钥进行异或(XOR)运算,将异或运算后的结果作为标签值。K为自然数,可以预先设置。该全局密钥可以为智能设备预先基于安全多方计算预处理函数生成的。
S102:根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果。
聚合中心根据各掩码数据以及各标签值,基于预先构建的聚合树,对各掩码数据进行聚合,确定掩码结果。其中,聚合树为聚合中心基于进行数据聚合的智能设备的数量预先构建的。聚合树包括若干运算节点以及叶子节点,聚合树中的叶子节点表示各智能设备对应的待聚合数据,每一个叶子节点表征一个智能设备的待聚合数据。聚合树中除叶子节点之外的其他节点均为运算节点,运算节点用于对输入该运算节点的数据进行异或运算、与(AND)运算等。聚合树中的根运算节点输出的结果为对各智能设备的待聚合数据进行数据聚合后的结果。在一实施例中,对于聚合树中的叶子节点的上游节点(即运算节点)来说,有两个智能设备的待聚合数据输入该上游节点,对于该上游节点的上游节点来说,可以有四个智能设备向该上游节点的上游节点中输入数据。故聚合树中,至少有两个智能设备向运算节点中输入数据。
例如,如图2所示,图2为本公开中提供的一种聚合树的示意图,假设进行数据聚合的智能设备有n个,分别是智能设备D1~智能设备Dn,各智能设备对应的输入为V1~Vn,将V1~Vn作为聚合树的叶子节点。由于数据聚合过程可以为V1+V2+V3+V4+...+Vn,也可以表示为(V1+V2)+(V3+V4)+...+(Vn-1+Vn)=[(V1+V2)+(V3+V4)]+...+(Vn-1+Vn)],故在聚合树的底层,可以将每两个叶子节点作为其上游节点的输入,比如叶子节点的V1和V2作为二者上游节点的输入,该上游节点为运算节点。从聚合树的叶子节点的上游节点到顶层的过程中,每两个运算节点的输出作为其上游节点的输入。在图2中方框中有“+”的节点表示聚合树中的运算节点。
具体的,聚合中心根据各掩码数据以及各标签值,依次针对预先构建的聚合树中的每一个运算节点,确定输入该运算节点的掩码数据以及标签值,并根据输入该运算节点的掩码数据,确定该运算节点输出的掩码数据,以及根据输入该运算节点的标签值,确定该运算节点输出的标签值。之后,将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的
下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值,将最后一个运算节点输出的掩码数据作为聚合树的输出的掩码结果。其中,该运算节点的下一个运算节点为以该运算节点输出的掩码数据以及标签值作为输入的运算节点。在确定输入该运算节点的掩码数据以及标签值时,若该运算节点为聚合树中叶子节点的上游运算节点时,从接收到的各掩码数据以及各标签值中,确定输入该运算节点的掩码数据以及标签值。若该运算节点不为聚合树中叶子节点的上游运算节点时,确定该运算节点的上一个运算节点输出的掩码数据为输入该运算节点的掩码数据,确定该运算节点的上一个运算节点输出的标签值为输入该运算节点的标签值。
在本公开中,运算节点中可以包含异或运算单元,一个运算节点中可以包括一个或者多个异或运算单元,故当各运算节点分别包括若干异或运算单元时,在上述步骤S102中,聚合中心可以根据各掩码数据以及各标签值,针对聚合树中的每一个运算节点,且依次针对该运算节点中的每一个异或运算单元,确定输入该异或运算单元的掩码数据以及标签值,将确定出的掩码数据进行异或运算,确定该异或运算单元输出的掩码数据,以及将确定出的标签值进行异或运算,确定该异或运算单元输出的标签值。之后,将该异或运算单元输出的掩码数据作为输入该异或运算单元的下一个异或运算单元的掩码数据,以及将该异或运算单元输出的标签值作为输入该异或运算单元的下一个异或运算单元的标签值,直到确定出最后一个异或运算单元输出的掩码数据以及标签值时,将最后一个异或运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将最后一个异或运算单元输出的标签值作为该运算节点输出的标签值。之后,将该运算节点输出掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值,将最后一个运算节点输出的掩码数据作为聚合树输出的掩码结果。
其中,若该异或运算单元为该运算节点中的第一个运算单元时,输入该异或运算单元的掩码数据以及标签值为输入该运算节点的掩码数据以及标签值。若该异或运算单元不为该运算节点中的第一个运算单元时,输入该异或运算单元的掩码数据以及标签值为该异或运算单元的上一个异或运算单元输出的掩码数据以及标签值。
在本公开中,运算节点中可以包含与运算单元,一个运算节点中可以包括一个或者多个与运算单元,故当各运算节点分别包括若干与运算单元时,在上述步骤102中,聚合中心可以根据各掩码数据以及各标签值,针对聚合树中的每一个运算节点,且依次针对该运算节点中的每一个与运算单元,确定输入该与运算单元的掩码数据,并根据确定出的掩码数据,确定该与运算单元对应的单元密文。之后,确定输入该与运算单元的标签值,并根据确定出的标签值以及单元密文,确定该与运算单元输出的掩码数据以及标签值。再将该与运算单元输出的掩码数据作为输入该与运算单元的下一个与运算单元的掩码数据,以及将该与运算单元输出的标签值作为输入该与运算单元的下一个与运算单元的标签值,直到确定出最后一个与运算单元输出的掩码数据以及标签值时,将最后一个与运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将最后一个与运算单元输出的标签值作为输入该运算节点输出的标签值。之后,将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输的掩码数据以及标签值时,将最后一个运算节点输出的掩码数据作为聚合树输出的掩码结果。
其中,若该与运算单元为该运算节点中的第一个运算单元时,输入该与运算单元的掩码数据以及标签值为输入该运算节点的掩码数据以及标签值。若该与运算单元不为该运算节点中的第一个运算单元时,输入该与运算单元的掩码数据以及标签值为该与运算
单元的上一个与运算单元输出的掩码数据以及标签值。
上述单元密文为各智能设备基于聚合树确定的,并发送给聚合中心。故在上述步骤S100中,聚合中心可以将预先构建的聚合树发送给各智能设备,之后,接收各智能设备发送的聚合树中各与运算单元的单元密文、掩码数据以及掩码数据对应的标签值。其中,在将预先构建的聚合树发送给各智能设备时,聚合中心可以向各智能设备发送聚合请求,该聚合请求中包含聚合树,并且该聚合请求提示智能设备可以将待聚合数据发送给聚合中心,以使聚合中心进行数据聚合。上述每一个与运算单元均有对应的单元密文,每一个智能设备可以为聚合树中的每一个与运算单元生成对应的单元密文。
另外,智能设备在为聚合树中的每一个与运算单元生成对应的单元密文时,需要确定输入与运算单元的掩码数据的比特值,该比特值可以为0,也可以为1,由于有两个掩码数据输入与运算单元,故输入该与运算单元的掩码数据的比特值有4种组合方式,分别是00、01、10以及11,每一种组合方式对应一个单元密文,故每一个与运算单元对应的单元密文可基于多种组合生成,且每一种组合对应的单元密文可以由每一个智能设备生成,即与运算单元对应若干单元密文。
基于此,在上述根据确定出的掩码数据,确定该与运算单元对应的单元密文时,聚合中心可以根据确定出的掩码数据,确定掩码数据对应的比特值的组合方式,并根据确定出的组合方式,从各智能设备发送的该与运算单元的各单元密文中,确定该与运算单元对应的各单元密文,即该与运算单元对应若干单元密文。比如智能设备D1和D2分别向聚合中心发送了与运算单元A的4个单元密文,4个单元密文分别为基于4种组合方式(即00、01、10以及11)确定的,故聚合中心一共可以接收到8个与运算单元A的单元密文。假设确定出的掩码数据对应的比特值分别为0和1,故比特值的组合方式为01,聚合中心可以从智能设备D1和D2发送的与运算单元A的8个单元密文中,确定组合方式01对应的单元密文,故聚合中心可以确定出与运算单元A对应的两个单元密文。
上述在根据确定出的标签值以及单元密文,确定该与运算单元输出的掩码数据以及标签值时,聚合中心可以针对每一个单元密文,根据确定出的标签值以及该单元密文,确定该单元密文对应的该与运算单元输出的第一掩码数据以及第一标签值。之后,将各第一掩码数据作为该与运算单元输出的掩码数据,以及将各第一标签值作为该与运算单元输出的标签值。
在本公开,运算节点还可以包括若干与运算单元和若干异或运算单元,故在上述步骤S102中,聚合中心可以根据各掩码数据以及各标签值,针对聚合树中的每一个运算节点,且依次针对该运算节点中的每一个运算单元,确定该运算单元的类型,当该运算单元为异或运算单元时,按照上述过程确定该异或运算单元输出的掩码数据以及标签值,在此就不再赘述,并将确定出的掩码数据以及标签值作为输入该异或运算单元的下一个运算单元的掩码数据以及标签值。当该运算单元为与运算单元时,按照上述过程确定该与运算单元输出的掩码数据以及标签值,在此就不再赘述,并将确定出的掩码数据以及标签值作为输入该与运算单元的下一个运算单元的掩码数据以及标签值,直到确定出最后一个运算单元输出的掩码数据以及标签值时,将最后一个运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将最后一个运算单元输出的标签值作为该运算节点输出的标签值。之后,将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值时,将最后一个运算节点输出的掩码数据作为聚合树输出的掩码结果。
S104:接收所述各智能设备发送的所述掩码结果的掩码比特份额以及所述掩码比特份额对应的消息验证码,其中,各比特份额用于对所述掩码结果进行解密。
S106:根据所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证。
S108:在验证通过时,根据所述各掩码比特份额对所述掩码结果进行解密,确定聚合结果。
聚合中心可以接收各智能设备发送的掩码结果的掩码比特份额以及掩码比特份额对应的消息验证码。之后,根据各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证。在验证通过时,根据各掩码比特份额对掩码结果进行解密,确定聚合结果。其中,每一个智能设备均会向聚合中心发送掩码结果对应的掩码比特份额,该掩码比特份额用于对聚合树最终输出的掩码结果进行解密。掩码比特份额对应的消息验证码为智能设备基于安全多方计算预处理函数生成的,并且用于验证智能设备发送的掩码比特份额是否准确。
另外,由于掩码结果是聚合中心将各智能设备的掩码数据按照聚合树中的运算节点进行数据聚合得到的,故每一个智能设备可以向聚合中心发送掩码比特份额,每一个掩码比特份额均为智能设备为聚合树输出的掩码结果生成的密钥,故聚合中心可以根据各掩码比特份额,对聚合树输出的掩码结果进行解密。
在上述根据各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证时,聚合中心可以针对每一个掩码比特份额,确定基于多方安全计算预处理函数生成的该掩码比特份额对应的密钥以及消息验证码,根据密钥以及该掩码比特份额,进行计算,确定第二计算结果。之后,根据各掩码比特份额对应的第二计算结果以及各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证。
其中,在根据密钥以及该掩码比特份额,进行计算,确定第二计算结果时,聚合中心可以确定基于安全多方计算预处理函数生成的全局密钥,并采用全局密钥对该掩码比特份额进行加密,再对加密后的结果与上述过程中确定出的密钥进行异或运算,将进行异或运算后的结果作为第二计算结果。
在上述根据各掩码比特份额对应的第二计算结果以及各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证时,当各掩码比特份额对应的第二计算结果以及各掩码比特份额对应的消息验证码一致时,确定各掩码比特份额验证通过。当存在掩码比特份额对应的第二计算结果与掩码比特份额对应的消息验证码不一致时,确定掩码比特份额验证不通过,向发送验证不通过的掩码比特份额的智能设备发送验证不通过的消息。
在上述根据各掩码比特份额对掩码结果进行解密,确定聚合结果时,可以采用下述公式(1)进行计算:
其中,zw表示聚合结果,z′w表示掩码结果,表示异或运算,表示智能设备Di发送的各掩码比特份额,n表示智能设备的数量。
从上述方法中可以看出,本公开在进行数据聚合时,聚合中心先接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,掩码数据为智能设备对待聚合数据进行掩码处理后的数据,使得可以保护各智能设备的待聚合数据中包含的隐私。之后,根据各掩码数据以及各标签值,基于预先构建的聚合树,对各掩码数据进行聚合,确定掩码结果。通过聚合树对各智能设备的掩码数据进行聚合,确定掩码结果,保护了每一个智能设备的待聚合数据中包含的隐私,并且聚合中心只知道掩码结果,不知道每一个智能设备具体的待聚合数据。另外,还加快了数据聚合的速度,降低了时间成本。然后,接收各智能设备发送的掩码结果的掩码比特份额以及掩码比特份额对应的消息验证码,
使得聚合中心可以根据各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证,保证各智能设备发送的各掩码比特份额的准确性。在验证通过时,根据各掩码比特份额对掩码结果进行解密,确定聚合结果,使得聚合中心采用验证通过的各掩码比特份额对掩码结果进行解密,保证聚合结果的准确性,并且聚合中心只能够获知各智能设备的聚合结果,而无法获知每一个智能设备具体的待聚合数据,保证了每一个智能设备的待聚合数据的隐私。
在本公开中,为了保证聚合结果的准确性,聚合中心可以在基于聚合数进行数据聚合的过程中,验证与运算单元输出的掩码数据是否准确。故在上述步骤S102根据确定出的标签值以及单元密文,确定该与运算单元输出的掩码数据以及标签值时,聚合中心可以针对每一个单元密文,根据确定出的标签值以及该单元密文,确定该与运算单元输出的待验证掩码数据(即上述第一掩码数据)、该与运算单元输出的标签值以及该与运算单元输出的待验证掩码数据的消息验证码。再确定基于安全多方计算预处理函数生成的该与运算单元输出的待验证掩码数据的消息验证码的密钥,并根据密钥以及该与运算单元输出的待验证掩码数据,进行计算,确定第一计算结果。之后,判断各第一计算结果与各待验证掩码数据对应的消息验证码是否一致。若是,将各待验证掩码数据作为该与运算单元输出的掩码数据。若否,确定验证不通过的待验证掩码数据对应的智能设备,并向确定出的智能设备发送验证不通过的消息。其中,该与运算单元对应若干单元密文。确定第一计算结果与确定第二计算结果的过程类似,在此就不再赘述。
上述在根据确定出的标签值以及该单元密文,确定该与运算单元输出的待验证掩码数据、该与运算单元输出的标签值以及该与运算单元输出的待验证掩码数据的消息验证码时,可以采用下述公式(2)进行计算:
其中,表示智能设备Di发送给聚合中心的该与运算单元对应的单元密文,t=z′α,z′α表示输入该与运算单元的掩码数据,s=z′β,z′β表示输入该与运算单元的掩码数据,表示输入该与运算单元的标签值,表示输入该与运算单元的标签值,表示该与运算单元输出的待验证掩码数据,表示待验证掩码数据对应的消息验证码,也就是该与运算单元输出的待验证掩码数据的消息验证码,表示该与运算单元输出的中间标签值,表示智能设备Di确定出的其他智能设备Dj的待验证掩码数据的消息验证码,该消息验证码为聚合中心根据确定出的标签值以及该单元密文确定出的,表示智能设备Di存储的其他智能设备Dj确定出的该与运算单元输出的待验证掩码数据的消息验证码的密钥,表示其他智能设备Dj确定出的该与运算单元输出的待验证掩码数据,Δi表示智能设备Di的全局密钥,表示该与运算单元输出的标签值。H(x)表示哈希函数,γ表示该与运算单元的输出,s,t分别表示该与运算单元的两个输入。
在本公开中,智能设备在确定掩码数据后,可以将该掩码数据发送给除自身之外的其他智能设备以及聚合中心,其他智能设备可以将接收到的掩码数据对应的标签值发送给聚合中心,该标签值为其他智能设备基于掩码数据随机生成的K比特的比特串,故一个掩码数据对应多个智能设备生成的标签值。因此在上述步骤S102中聚合中心可以接收到各智能设备发送的各掩码数据,并且针对每一个掩码数据,聚合中心可以接收到各智能设备发送的该掩码数据对应的标签值。
基于此,在上述步骤S102中,聚合中心可以根据各掩码数据以及各掩码数据分别对应的各标签值,基于预先构建的聚合树,对各掩码数据进行数据聚合,确定聚合树输
出的掩码结果。具体的过程与上述每一个掩码数据均对应一个标签值的过程类似,只是每一个掩码数据均对应多个标签值而已,并且每一个异或运算单元和每一个与运算单元输出的标签值为包含多个标签值的集合,具体过程在此就不再赘述。
在本公开中,在智能电网场景下,聚合中心可以为电力中心,智能设备可以为用户住宅的电表。待聚合数据可以为用户的住宅的用电量。聚合中心可以根据智能设备的数量,也就是待聚合区域(比如小区)中住户的电表的数量,构建聚合树,并发送给各智能设备。之后,各电表分别把收集到的用户的用电量进行掩码处理,确定掩码数据,并基于掩码数据生成对应的标签值,将掩码数据以及标签值发送给聚合中心。聚合中心根据接收到的各掩码数据以及各标签值,基于聚合树,确定掩码结果。聚合中心再根据各智能设备发送的掩码结果对应的掩码比特份额,对掩码结果进行解密,确定聚合结果,即待聚合区域整体的用电量,根据待聚合区域整体的用电量,聚合中心分配电量。
上述采用聚合树进行数据聚合加快了数据聚合的速度,并且输入聚合树的数据为掩码数据(即对用户的用电量进行掩码处理得到的),使得聚合中心无法获知每一个电表收集到的具体的用户的用电量,保护了用户的隐私。后续可以根据电表发送的掩码结果对应的掩码比特份额,对掩码结果进行解密,确定聚合结果,即待聚合区域整体的用电量。
当然,在车辆调度场景下,上述聚合中心可以为车辆调度系统,智能设备可以是待调度区域中的图像采集设备,待聚合数据可以为用户的数量,具体的数据聚合的过程与上述在智能电网场景下数据聚合的过程类似,在此就不再赘述。
本公开中还提供一种数据聚合的方法,所述方法应用于智能设备,如图3所示,图3为本公开中提供的另一种数据聚合的方法的流程示意图,具体包括以下步骤S200~S208。
S200:确定待聚合数据。
S202:根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,其中,所述聚合树为聚合中心预先构建的。
S204:根据所述掩码比特份额,对所述待聚合数据进行处理,确定掩码数据,并生成所述掩码数据对应的标签值。
为了保护待聚合数据中包含的隐私,智能设备可以确定待聚合数据,根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,再根据掩码比特份额,对待聚合数据进行处理,确定掩码数据,并生成掩码数据对应的标签值。其中,聚合树为聚合中心根据各智能设备的数量构建的,聚合树中的叶子节点表示各智能设备对应的待聚合数据,聚合树中除叶子节点之外的其他节点均为运算节点,聚合树中的根运算节点输出的结果为对各智能设备的待聚合数据进行数据聚合后的结果。待聚合数据为智能设备收集的数据,数据聚合的应用场景不同,智能设备可能不同,待聚合数据也可能不同,具体的不同场景下智能设备以及待聚合数据可以为何种数据如上述步骤S100中所述,在此就不再赘述。安全多方计算预处理函数为已有的安全多方计算库中的函数,上述生成掩码数据对应的标签值可以为智能设备基于掩码数据随机生成标签值。
具体的,智能设备可以响应于聚合中心发送的聚合请求,确定聚合中心预先构建的聚合树,以及确定待聚合数据。再根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,再根据掩码比特份额,对待聚合数据进行处理,确定掩码数据,并生成掩码数据对应的标签值。比如在智能电网场景下,智能设备可以为小区中用户的住宅的电表,待聚合数据可以为用户的住宅的用电量。电表可以确定用户的住宅的用电量,根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,再根
据掩码比特份额,对用电量进行处理,确定掩码后的用电量,并生成掩码后的用电量对应的标签值。
在本公开中,上述步骤S200以及步骤S202的过程的执行可以不分先后顺序,也可以同时执行。
S206:将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,使所述聚合中心根据接收到的各智能设备发送的掩码数据和标签值,确定掩码结果。
智能中心可以将掩码数据以及掩码数据对应的标签值发送给聚合中心,使聚合中心根据接收到的各智能设备发送的掩码数据和标签值,确定掩码结果。
在本公开中,聚合树包括若干运算节点,运算节点中可以包含与运算单元,一个运算节点中可以包括一个或者多个与运算单元,故当各运算节点分别包括若干与运算单元时,在将掩码数据以及掩码数据对应的标签值发送给聚合中心时,智能设备除了将掩码数据以及掩码数据对应的标签值发送给聚合中心之外,还需要将聚合树中的与运算单元对应的单元密文发送给聚合中心。因此,智能设备可以针对聚合树中的每一个运算节点,且依次针对该运算节点中的每一个与运算单元,确定输入该与运算单元的可验证掩码比特份额以及标签值,采用安全多方计算预处理函数,确定该与运算单元的三元组、该与运算单元输出的可验证掩码比特份额以及该与运算单元输出的标签值。然后,根据三元组、输入该与运算单元的可验证掩码比特份额、输入该与运算单元的标签值、该与运算单元输出的可验证掩码比特份额以及该与运算单元输出的标签值,确定该与运算单元对应的单元密文。然后,将聚合树中各与运算单元对应的单元密文、掩码数据以及掩码数据对应的标签值发送给聚合中心。
其中,上述可验证掩码比特份额包括掩码比特份额、掩码比特份额对应的消息验证码以及其他智能设备的掩码比特份额对应的消息验证码的密钥,其他智能设备为除智能设备自身之外的设备。
若该运算节点为聚合树中叶子节点的上游运算节点时,输入该运算节点的可验证掩码比特份额为智能设备采用安全多方计算预处理函数生成的,输入该运算节点的标签值为智能设备随机生成的K比特的比特串或者随机生成的K比特的比特串与全局密钥进行异或运算后的结果。若该运算节点不为聚合树中叶子节点的上游运算节点时,确定该运算节点的上一个运算节点输出的可验证掩码比特份额为输入该运算节点的可验证掩码比特份额,确定该运算节点的上一个运算节点输出的标签值为输入该运算节点的标签值。
若该与运算单元为该运算节点中的第一个运算单元时,输入该与运算单元的可验证掩码比特份额以及标签值为输入该运算节点的可验证掩码比特份额以及标签值。若该与运算单元不为该运算节点中的第一个运算单元时,输入该与运算单元的可验证掩码比特份额以及标签值为该与运算单元的上一个运算单元输出的可验证掩码比特份额以及标签值。另外,当该与运算单元的上一个运算单元为与运算单元时,采用安全多方计算预处理函数,确定该与运算单元的上一个运算单元输出的可验证掩码比特份额以及标签值,将该与运算单元的上一个运算单元输出的可验证掩码比特份额作为输入该与运算单元的可验证掩码比特份额,以及将该与运算单元的上一个运算单元输出的标签值作为输入该与运算单元的标签值。
另外,运算节点还可以包括若干异或运算单元,则该与运算单元的上一个运算单元还可以为异或运算单元,故在确定输入该与运算单元的可验证掩码比特份额以及标签值时,当该与运算单元的上一个运算单为异或运算单元时,确定输入该与运算单元的上一个运算单元(即异或运算单元)的可验证掩码比特份额以及标签值,根据输入该与运算
单元的上一个运算单元的可验证掩码比特份额,确定该与运算单元的上一个运算单元输出的可验证掩码比特份额,作为该与运算单元输出的可验证掩码比特份额。以及,根据输入该与运算单元的上一个运算单元的标签值,确定该与运算单元的上一个运算单元输出的标签值,作为该与运算单元输出的标签值。
其中,在根据输入该与运算单元的上一个运算单元的可验证掩码比特份额,确定该与运算单元的上一个运算单元输出的可验证掩码比特份额时,智能设备可以将输入该与运算单元的上一个运算单元的可验证掩码比特份额进行异或运算,确定该与运算单元的上一个运算单元输出的可验证掩码比特份额。同理,在根据输入该与运算单元的上一个运算单元的标签值,确定该与运算单元的上一个运算单元输出的标签值时,智能设备可以将输入该与运算单元的上一个运算单元的标签值进行异或运算,确定该与运算单元的上一个运算单元输出的标签值。
上述三元组为采用安全多方计算预处理函数生成的三个参数,该三元组包含第一数值、第二数值以及第三数值,输入该与运算单元的可验证掩码比特份额包括第一可验证掩码比特份额以及第二可验证掩码比特份额。另外,对于每一个智能设备来说,在聚合树中存在该智能设备所属的运算节点以及与该智能设备无关的运算节点,该智能设备向聚合树中的某一运算节点直接输入数据或者间接输入数据,则该运算节点为该智能设备所属的运算节点,除上述该智能设备所属的运算节点之外的运算节点为与该智能设备无关的运算节点。继续沿用上例,假设图2中的智能设备D1和D2均向上游运算节点中的某一运算节点输入数据,故智能设备D1和D2都属于该运算节点,并且以该运算节点输出的数据作为输入(即间接输入)的运算节点也为智能设备D1和D2所属的运算节点。
基于此,上述该运算节点可以为智能设备所属的运算节点,在根据三元组、输入该与运算单元的可验证掩码比特份额、输入该与运算单元的标签值、该与运算单元输出的可验证掩码比特份额以及该与运算单元输出的标签值,确定该与运算单元对应的单元密文时,智能设备可以根据三元组中的第一数值以及输入该与运算单元的第一可验证掩码比特份额,确定第一值,以及根据三元组中的第二数值以及输入该与运算单元的第二可验证掩码比特份额,确定第二值,具体可以采用下述公式(3)~(4)进行计算:
其中,表示智能设备Di确定出的第一值,表示智能设备Di确定出的输入该与运算单元的第一可验证掩码比特份额,表示智能设备Di确定出的三元组中的第一数值。表示智能设备Di确定出的第二值,表示智能设备Di确定出的输入该与运算单元的第二可验证掩码比特份额,表示智能设备Di确定出的三元组中的第二数值。
若该与运算单元为该运算节点中第一个运算单元,并且该运算节点为聚合树中叶子节点的上游运算节点时,第一可验证掩码比特份额与第二可验证掩码比特份额表征不同智能设备输入该与运算单元的可验证掩码比特份额,对于输入该与运算单元的某一智能设备,该智能设备可以生成输入该与运算单元的可验证掩码比特份额,对于输入该与运算单元的另一个可验证掩码比特份额可以直接设置为0。故若上述为智能设备Di输入该与运算单元的可验证掩码比特份额,则为智能设备Di基于安全多方计算预处理函数生成的对待聚合数据进行处理的可验证掩码比特份额,默认为0;若上述为智能设备Di输入该与运算单元的可验证掩码比特份额,则上述还可以默认为0,可以为智能设备Di基于安全多方计算预处理函数生成的对待聚合数
据进行处理的可验证掩码比特份额。
上述或者在不为0时,即或者为智能设备Di基于安全多方计算预处理函数生成的对待聚合数据进行处理的可验证掩码比特份额时,可以采用下述公式(5)进行表示:
其中,表示智能设备Di生成的输入该运算节点或者该与运算单元的可验证掩码比特份额,表示智能设备Di生成的掩码比特份额,表示对应的消息验证码,表示其他智能设备Dj生成的输入该运算节点或者与运算单元的掩码比特份额对应的消息验证码对应的密钥。由于输入该运算节点或者该与运算单元的或者仅由智能设备Di生成,与其他智能无关。另外,为了保护隐私,智能设备Di无法将或者告知其他智能设备,并且各智能设备之间也无需相互验证。基于此,为了节省每一个智能设备的存储成本以及通讯开销,每一个智能设备无需存储其他智能设备生成的或者对应的消息验证码对应的密钥,故上述可以默认为0。
然后,将第一值以及第二值发送给其他智能设备。该其他智能设备为与智能设备共同属于该运算节点的智能设备,也就是该其他智能设备为向该运算节点输入数据的智能设备中除智能设备(即上述智能设备Di,也就是作为执行主体的智能设备)之外的智能设备。接收其他智能设备发送的第三值以及第四值,并将接收到的第三值以及第一值聚合,确定第一总值,以及将接收到的第四值以及第二值聚合,确定第二总值,具体可以采用下述公式(6)~(7)进行计算:
其中,dγ表示智能设备Di确定出的第一总值,n表示智能设备的数量,表示智能设备Di确定出的第一值,表示智能设备Dn确定出的第三值,并将第三值发送给智能设备Di,第一值与第三值的确定过程类似,只是由不同智能设备在本地确定出的。eγ表示智能设备Di确定出的第二总值,表示智能设备Di确定出的第二值。表示智能设备Dn确定出的第四值,并将第三值发送给智能设备Di,第二值与第四值的确定过程类似,只是由不同智能设备在本地确定出的。
之后,根据第一总值、第二总值、三元组、该与运算单元输出的可验证掩码比特份额以及输入该与运算单元的可验证掩码比特份额,确定该与运算单元输出的待验证掩码数据,具体可以采用下述公式(8)~(9)进行计算:
其中,表示智能设备Di确定出的三元组中的第三数值,表示智能设备Di确定出的该与运算单元输出的待验证掩码数据,表示智能设备Di确定出的该与运算单元输出的可验证掩码比特份额,该与运算单元输出的可验证掩码比特份额为智能设备Di采用安全多方计算预处理函数生成的,为了节省存储成本,该与运算单元输出的可验证掩码比特份额中存储的其他智能设备的消息验证码对应的密钥可以仅为上述确定出的其他智能设备的消息验证码对应的密钥,也就是该与运算单元输出的可
验证掩码比特份额中存储向该与运算节点输入数据的智能设备中除智能设备(即作为执行主体的智能设备)之外的其他智能设备的消息验证码对应的密钥,对于未向该与运算节点输入数据的智能设备的消息验证码对应的密钥可以不用存储,直接默认为0,t,s为比特值,每个t,s∈{0,1}。
之后,根据该与运算单元输出的待验证掩码数据、输入该与运算单元的标签值以及该与运算单元输出的标签值,确定该与运算单元对应的单元密文,具体可以采用下述公式(10)进行计算:
其中,表示智能设备Di确定出的该与运算单元对应的单元密文,由于t可以为0,也可以为1,s可以为0,也可以为1,故t和s一共有4种组合方式,即00、01、10以及11,每一种组合方式对应一个单元密文,故该与运算单元对应的单元密文有4个。:=为赋值符号,表示智能设备Di确定出的比特值为t时输入该与运算单元的标签值,表示智能设备Di确定出的比特值为t时输入该与运算单元的标签值,γ表示该与运算单元的输出,表示该与运算单元输出的待验证掩码数据的消息验证码,表示智能设备Di确定出的比特值为0时该与运算单元输出的标签值,Δi表示智能设备Di的全局密钥,表示智能设备Di存储的其他智能设备Dj确定出的该与运算单元输出的待验证掩码数据的消息验证码对应的密钥。
若该与运算单元为该运算节点中第一个运算单元,并且该运算节点为聚合树中叶子节点的上游运算节点时,上述和均为智能设备Di随机生成的K比特的比特串,只是比特值分别为t以及s。
另外,上述该运算节点还可以为智能设备无关的运算节点,故上述输入该运算节点的可验证掩码比特份额为0,生成的该与运算单元的三元组也分别为0,该与运算单元输出的可验证掩码比特份额也为0。并且在根据三元组、输入该与运算单元的可验证掩码比特份额、输入该与运算单元的标签值、该与运算单元输出的可验证掩码比特份额以及该与运算单元输出的标签值,确定该与运算单元对应的单元密文时,智能设备可以根据三元组中的第一数值以及输入该与运算单元的第一可验证掩码比特份额,确定第一值,以及根据三元组中的第二数值以及输入该与运算单元的可验证掩码比特份额,确定第二值。然后,根据第一值、第二值、三元组、该与运算单元输出的可验证掩码比特份额以及输入该与运算单元的可验证掩码比特份额,确定该与运算单元输出的待验证掩码数据。根据该与运算单元输出的待验证掩码数据、输入该与运算单元的标签值以及该与运算单元输出的标签值,确定该与运算单元对应的单元密文。
另外,智能设备还可以将掩码数据发送给除智能设备之外的其他智能设备,使其他智能设备生成掩码数据对应的标签值并发送给聚合中心。以及,将掩码后的数据以及掩码后的数据对应的标签值发送给聚合中心。其中,除智能设备之外的其他智能设备可以根据接收到的掩码数据,确定掩码数据对应的标签值,并发送给聚合中心,该掩码数据对应的标签值为该其他智能设备基于掩码数据的比特值随机生成的K比特的比特串,具体过程与上述步骤S202生成标签值的过程类似,在此就不再赘述。基于此,聚合中心可以接收到各智能设备发送的掩码数据,以及每一个掩码数据对应的各标签值。
S208:确定所述聚合树输出的掩码结果对应的掩码比特份额以及所述掩码比特份额对应的消息验证码,并将确定出的掩码比特份额以及消息验证码发送给所述聚合中心,使所述聚合中心根据接收到的各掩码比特份额以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证,并在验证通过时,根据所述各掩码比特份额以
及所述掩码结果,确定聚合结果。
智能设备可以确定聚合树输出的掩码结果对应的掩码比特份额以及掩码比特份额对应的消息验证码,并将确定出的掩码比特份额以及消息验证码发送给聚合中心,使聚合中心根据接收到的各掩码比特份额以及各掩码比特份额对应的消息验证码,对各掩码比特份额进行验证,并在验证通过时,根据各掩码比特份额以及掩码结果,确定聚合结果。其中,掩码比特份额用于对掩码结果进行解密。掩码比特份额对应的消息验证码为智能设备基于安全多方计算预处理函数生成的,并且用于验证智能设备发送的掩码比特份额是否准确。
若上述聚合树输出的掩码结果为聚合树中最后一个异或运算单元输出的可验证掩码比特份额中存储的掩码比特份额时,智能设备可以根据输入该异或运算单元的可验证掩码比特份额,确定该异或运算单元输出的可验证掩码比特份额,并将该可验证掩码比特份额中存储的掩码比特份额以及掩码比特份额对应的消息验证码发送给聚合中心。若上述聚合树输出的掩码结果为聚合树中最后一个与运算单元输出的可验证掩码比特份额中存储的掩码比特份额时,智能设备可以采用安全多方计算预处理函数,生成该与运算单元输出的可验证掩码比特份额,并将该可验证掩码比特份额中存储的掩码比特份额以及掩码比特份额对应的消息验证码发送给聚合中心。
以上为本公开提供的数据聚合的方法,基于同样的思路,本公开还提供了一种数据聚合的装置,所述装置应用于聚合中心,如图4所示。
图4为本公开提供的一种的数据聚合的装置的示意图,包括:
第一接收模块300,用于接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,其中,所述掩码数据为所述智能设备基于掩码比特份额对待聚合数据进行处理后的数据,所述掩码比特份额是所述智能设备基于安全多方计算预处理函数生成的;
聚合模块302,用于根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果;
第二接收模块304,用于接收所述各智能设备发送的所述掩码结果的掩码比特份额以及所述掩码比特份额对应的消息验证码,其中,各掩码比特份额用于对所述掩码结果进行解密;
验证模块306,用于根据所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证;
解密模块308,用于在验证通过时,根据所述各掩码比特份额对所述掩码结果进行解密,确定聚合结果。
可选地,所述聚合树包括若干运算节点,各运算节点分别包括若干异或运算单元;
所述聚合模块302具体用于,根据所述各掩码数据以及各标签值,针对预先构建的聚合树中的每一个运算节点,且依次针对该运算节点中的每一个异或运算单元,确定输入该异或运算单元的掩码数据以及标签值;将确定出的掩码数据进行异或运算,确定该异或运算单元输出的掩码数据;以及将确定出的标签值进行异或运算,确定该异或运算单元输出的标签值;将该异或运算单元输出的掩码数据作为输入该异或运算单元的下一个异或运算单元的掩码数据,以及将该异或运算单元输出的标签值作为输入该异或运算单元的下一个异或运算单元的标签值,直到确定出最后一个异或运算单元输出的掩码数据以及标签值时,将所述最后一个异或运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将所述最后一个异或运算单元输出的标签值作为该运算节点输出的标签值;将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,
以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值时,将所述最后一个运算节点输出的掩码数据作为所述聚合树输出的掩码结果。
可选地,所述聚合树包括若干运算节点,各运算节点分别包括若干与运算单元;
所述第一接收模块300具体用于,将预先构建的聚合树发送给各智能设备;接收所述各智能设备发送的所述聚合树中各与运算单元的单元密文、掩码数据以及所述掩码数据对应的标签值;
所述聚合模块302具体用于,根据所述各掩码数据以及各标签值,针对所述聚合树中的每一个运算节点,且依次针对该运算节点中的每一个与运算单元,确定输入该与运算单元的掩码数据,并根据确定出的掩码数据,确定该与运算单元对应的单元密文;确定输入该与运算单元的标签值,并根据确定出的标签值以及所述单元密文,确定该与运算单元输出的掩码数据以及标签值;将该与运算单元输出的掩码数据作为输入该与运算单元的下一个与运算单元的掩码数据,以及将该与运算单元输出标签值作为输入该与运算单元的下一个与运算单元的标签值,直到确定出最后一个与运算单元输出的掩码数据以及标签值时,将所述最后一个与运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将所述最后一个与运算单元输出的标签值作为该运算节点输出的标签值;将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值时,将所述最后一个运算节点输出的掩码数据作为所述聚合树输出的掩码结果。
可选地,该与运算单元对应若干单元密文;
所述聚合模块302具体用于,针对每一个单元密文,根据确定出的标签值以及该单元密文,确定该与运算单元输出的待验证掩码数据、该与运算单元输出的标签值以及该与运算单元输出的待验证掩码数据的消息验证码;确定基于所述安全多方计算预处理函数生成的该与运算单元输出的待验证掩码数据的消息验证码的密钥,并根据所述密钥以及该与运算单元输出的待验证掩码数据,进行计算,确定第一计算结果;判断各第一计算结果与各待验证掩码数据对应的消息验证码是否一致;若是,将各待验证掩码数据作为该与运算单元输出的掩码数据;若否,确定验证不通过的待验证掩码数据对应的智能设备,并向确定出的智能设备发送验证不通过的消息。
可选地,所述验证模块306具体用于,针对每一个掩码比特份额,确定基于所述多方安全计算预处理函数生成的该掩码比特份额对应的密钥以及消息验证码,根据所述密钥以及该掩码比特份额,进行计算,确定第二计算结果;根据所述各掩码比特份额对应的第二计算结果以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证。
本公开还提供的一种数据聚合的装置,所述装置应用于智能设备,如图5所示,图5为本公开提供的另一种数据聚合的装置的结构示意图,包括:
确定模块400,用于确定待聚合数据;
生成模块402,用于根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,其中,所述聚合树为聚合中心预先构建的;
加密模块404,用于根据所述掩码比特份额,对所述待聚合数据进行处理,确定掩码数据,并生成所述掩码数据对应的标签值;
发送模块406,用于将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚
合中心,使所述聚合中心根据接收到的各智能设备发送的掩码数据和标签值,确定掩码结果;
掩码模块408,用于确定所述聚合树输出的掩码结果对应的掩码比特份额以及所述掩码比特份额对应的消息验证码,并将确定出的掩码比特份额以及消息验证码发送给所述聚合中心,使所述聚合中心根据接收到的各掩码比特份额以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证,并在验证通过时,根据所述各掩码比特份额以及所述掩码结果,确定聚合结果。
可选地,所述聚合树包括若干运算节点,各运算节点分别包括若干与运算单元;
所述发送模块406具体用于,针对所述聚合树中的每一个运算节点,且依次针对该运算节点中的每一个与运算单元,确定输入该与运算单元的可验证掩码比特份额以及标签值;采用所述安全多方计算预处理函数,确定该与运算单元的三元组、该与运算单元输出的可验证掩码比特份额以及该与运算单元输出的标签值;根据所述三元组、所述输入该与运算单元的可验证掩码比特份额、所述输入该与运算单元的标签值、所述该与运算单元输出的可验证掩码比特份额以及所述该与运算单元输出的标签值,确定该与运算单元对应的单元密文;将所述聚合树中各运算节点的各与运算单元对应的单元密文、所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心。
可选地,所述运算节点还包括若干异或运算单元;
所述发送模块406具体用于,当该与运算单元的上一个运算单元为异或运算单元时,确定输入该与运算单元的上一个运算单元的可验证掩码比特份额以及标签值;根据所述输入该与运算单元的上一个运算单元的可验证掩码比特份额,确定该与运算单元的上一个运算单元输出的可验证掩码比特份额,并作为输入该与运算单元的可验证掩码比特份额;根据所述输入该与运算单元的上一个运算单元的标签值,确定该与运算单元的上一个运算单元输出的标签值,并作为输入该与运算单元的标签值。
可选地,该运算节点为所述智能设备所属的运算节点,所述三元组包括第一数值、第二数值以及第三数值,所述输入该与运算单元的可验证掩码比特份额包括第一可验证掩码比特份额以及第二可验证掩码比特份额;
所述发送模块406具体用于,根据所述三元组中的第一数值以及所述输入该与运算单元的第一可验证掩码比特份额,确定第一值,以及根据所述三元组中的第二数值以及所述输入该与运算单元的第二可验证掩码比特份额,确定第二值,并将所述第一值以及所述第二值发送给其他智能设备,其中,所述其他智能设备为向该运算节点输入数据的智能设备中除所述智能设备之外的智能设备;接收所述其他智能设备发送的第三值以及第四值,并将接收到的第三值以及所述第一值聚合,确定第一总值,以及将接收到的第四值以及所述第二值聚合,确定第二总值;根据所述第一总值、所述第二总值、所述三元组、所述该与运算单元输出的可验证掩码比特份额以及所述输入该与运算单元的可验证掩码比特份额,确定该与运算单元输出的待验证掩码数据;根据该与运算单元输出的待验证掩码数据、所述输入该与运算单元的标签值以及所述该与运算单元输出的标签值,确定该与运算单元对应的单元密文。
可选地,所述发送模块406具体用于,将所述掩码数据发送给除所述智能设备之外的其他智能设备,使所述其他智能设备生成所述掩码数据对应的标签值并发送给所述聚合中心,以及将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心。
本公开还提供了一种计算机可读存储介质,该存储介质存储有计算机程序,计算机程序被处理器执行时实现上述数据聚合的方法。
本公开还提供了一种电子设备。如图6所示,在硬件层面,该电子设备包括处理器、内部总线、网络接口、内存以及非易失性存储器,当然还可能包括其他业务所需要的硬件。处理器从非易失性存储器中读取对应的计算机程序到内存中然后运行,以实现上述数据聚合的方法。
当然,除了软件实现方式之外,本公开并不排除其他实现方式,比如逻辑器件抑或软硬件结合的方式等等,也就是说以下处理流程的执行主体并不限定于各个逻辑单元,也可以是硬件或逻辑器件。
在20世纪90年代,对于一个技术的改进可以很明显地区分是硬件上的改进(例如,对二极管、晶体管、开关等电路结构的改进)还是软件上的改进(对于方法流程的改进)。然而,随着技术的发展,当今的很多方法流程的改进已经可以视为硬件电路结构的直接改进。设计人员几乎都通过将改进的方法流程编程到硬件电路中来得到相应的硬件电路结构。因此,不能说一个方法流程的改进就不能用硬件实体模块来实现。例如,可编程逻辑器件(Programmable Logic Device,PLD)(例如现场可编程门阵列(Field Programmable Gate Array,FPGA))就是这样一种集成电路,其逻辑功能由用户对器件编程来确定。由设计人员自行编程来把一个数字系统“集成”在一片PLD上,而不需要请芯片制造厂商来设计和制作专用的集成电路芯片。而且,如今,取代手工地制作集成电路芯片,这种编程也多半改用“逻辑编译器(logic compiler)”软件来实现,它与程序开发撰写时所用的软件编译器相类似,而要编译之前的原始代码也得用特定的编程语言来撰写,此称之为硬件描述语言(Hardware Description Language,HDL),而HDL也并非仅有一种,而是有许多种,如ABEL(Advanced Boolean Expression Language)、AHDL(Altera Hardware Description Language)、Confluence、CUPL(Cornell University Programming Language)、HDCal、JHDL(Java Hardware Description Language)、Lava、Lola、MyHDL、PALASM、RHDL(Ruby Hardware Description Language)等,目前最普遍使用的是VHDL(Very-High-Speed Integrated Circuit Hardware Description Language)与Verilog。本领域技术人员也应该清楚,只需要将方法流程用上述几种硬件描述语言稍作逻辑编程并编程到集成电路中,就可以很容易得到实现该逻辑方法流程的硬件电路。
控制器可以按任何适当的方式实现,例如,控制器可以采取例如微处理器或处理器以及存储可由该(微)处理器执行的计算机可读程序代码(例如软件或固件)的计算机可读介质、逻辑门、开关、专用集成电路(Application Specific Integrated Circuit,ASIC)、可编程逻辑控制器和嵌入微控制器的形式,控制器的例子包括但不限于以下微控制器:ARC 625D、Atmel AT91SAM、Microchip PIC18F26K20以及Silicone Labs C8051F320,存储器控制器还可以被实现为存储器的控制逻辑的一部分。本领域技术人员也知道,除了以纯计算机可读程序代码方式实现控制器以外,完全可以通过将方法步骤进行逻辑编程来使得控制器以逻辑门、开关、专用集成电路、可编程逻辑控制器和嵌入微控制器等的形式来实现相同功能。因此这种控制器可以被认为是一种硬件部件,而对其内包括的用于实现各种功能的装置也可以视为硬件部件内的结构。或者甚至,可以将用于实现各种功能的装置视为既可以是实现方法的软件模块又可以是硬件部件内的结构。
上述实施例阐明的系统、装置、模块或单元,具体可以由计算机芯片或实体实现,或者由具有某种功能的产品来实现。一种典型的实现设备为计算机。具体的,计算机例如可以为个人计算机、膝上型计算机、蜂窝电话、相机电话、智能电话、个人数字助理、媒体播放器、导航设备、电子邮件设备、游戏控制台、平板计算机、可穿戴设备或者这些设备中的任何设备的组合。
为了描述的方便,描述以上装置时以功能分为各种单元分别描述。当然,在实施本公开时可以把各单元的功能在同一个或多个软件和/或硬件中实现。
本领域内的技术人员应明白,本公开的实施例可提供为方法、系统、或计算机程序产品。因此,本公开可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本公开可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本公开是参照根据本公开实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
在一个典型的配置中,计算设备包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。
内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器((Random Access Memory,RAM)和/或非易失性内存等形式,如只读存储器(Read-Only Memory,ROM)或闪存(flash RAM)。内存是计算机可读介质的示例。
计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(Phase Change RAM,PRAM)、静态随机存取存储器(Static Random-Access Memory,SRAM)、动态随机存取存储器(Dynamic Random Access Memory,DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(Electrically Erasable Programmable Read Only Memory,EEPROM)、快闪记忆体(Flash Memory)或其他内存技术、只读光盘只读存储器(Compact Disc Read Only Memory,CD-ROM)、数字多功能光盘(Digital Versatile Disc,DVD)或其他光学存储、磁盒式磁带,磁带及磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体(transitory media),如调制的数据信号和载波。
还需要说明的是,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、商品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、商品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、商品或者设备中还存在另外的相同要素。
本公开可以在由计算机执行的计算机可执行指令的一般上下文中描述,例如程序模块。一般地,程序模块包括执行特定任务或实现特定抽象数据类型的例程、程序、对象、
组件、数据结构等等。也可以在分布式计算环境中实践本公开,在这些分布式计算环境中,由通过通信网络而被连接的远程处理设备来执行任务。在分布式计算环境中,程序模块可以位于包括存储设备在内的本地和远程计算机存储介质中。
本公开中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于系统实施例而言,由于其基本相似于方法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
以上所述仅为本公开的实施例而已,并不用于限制本公开。对于本领域技术人员来说,本公开可以有各种更改和变化。凡在本公开的精神和原理之内所作的任何修改、等同替换、改进等,均应包含在本公开的权利要求范围之内。
Claims (14)
- 一种数据聚合的方法,其特征在于,所述方法应用于聚合中心,所述方法包括:接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,其中,所述掩码数据为所述智能设备基于掩码比特份额对待聚合数据进行处理后的数据,所述掩码比特份额是所述智能设备基于安全多方计算预处理函数生成的;根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果;接收所述各智能设备发送的所述掩码结果的掩码比特份额以及所述掩码比特份额对应的消息验证码,其中,各掩码比特份额用于对所述掩码结果进行解密;根据所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证;在验证通过时,根据所述各掩码比特份额对所述掩码结果进行解密,确定聚合结果。
- 如权利要求1所述的方法,其特征在于,所述聚合树包括若干运算节点,各运算节点分别包括若干异或运算单元;根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果,具体包括:根据所述各掩码数据以及各标签值,针对预先构建的聚合树中的每一个运算节点,且依次针对该运算节点中的每一个异或运算单元,确定输入该异或运算单元的掩码数据以及标签值;将确定出的掩码数据进行异或运算,确定该异或运算单元输出的掩码数据;以及将确定出的标签值进行异或运算,确定该异或运算单元输出的标签值;将该异或运算单元输出的掩码数据作为输入该异或运算单元的下一个异或运算单元的掩码数据,以及将该异或运算单元输出的标签值作为输入该异或运算单元的下一个异或运算单元的标签值,直到确定出最后一个异或运算单元输出的掩码数据以及标签值时,将所述最后一个异或运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将所述最后一个异或运算单元输出的标签值作为该运算节点输出的标签值;将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值时,将所述最后一个运算节点输出的掩码数据作为所述聚合树输出的掩码结果。
- 如权利要求1所述的方法,其特征在于,所述聚合树包括若干运算节点,各运算节点分别包括若干与运算单元;接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,具体包括:将预先构建的聚合树发送给各智能设备;接收所述各智能设备发送的所述聚合树中各与运算单元的单元密文、掩码数据以及所述掩码数据对应的标签值;根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果,具体包括:根据所述各掩码数据以及各标签值,针对所述聚合树中的每一个运算节点,且依次针对该运算节点中的每一个与运算单元,确定输入该与运算单元的掩码数据,并根据确定出的掩码数据,确定该与运算单元对应的单元密文;确定输入该与运算单元的标签值,并根据确定出的标签值以及所述单元密文,确定该与运算单元输出的掩码数据以及标签值;将该与运算单元输出的掩码数据作为输入该与运算单元的下一个与运算单元的掩码数据,以及将该与运算单元输出标签值作为输入该与运算单元的下一个与运算单元的标签值,直到确定出最后一个与运算单元输出的掩码数据以及标签值时,将所述最后一个与运算单元输出的掩码数据作为该运算节点输出的掩码数据,以及将所述最后一个与 运算单元输出的标签值作为该运算节点输出的标签值;将该运算节点输出的掩码数据作为输入该运算节点的下一个运算节点的掩码数据,以及将该运算节点输出的标签值作为输入该运算节点的下一个运算节点的标签值,直到确定出最后一个运算节点输出的掩码数据以及标签值时,将所述最后一个运算节点输出的掩码数据作为所述聚合树输出的掩码结果。
- 如权利要求3所述的方法,其特征在于,该与运算单元对应若干单元密文;根据确定出的标签值以及所述单元密文,确定该与运算单元输出的掩码数据以及标签值,具体包括:针对每一个单元密文,根据确定出的标签值以及该单元密文,确定该与运算单元输出的待验证掩码数据、该与运算单元输出的标签值以及该与运算单元输出的待验证掩码数据的消息验证码;确定基于所述安全多方计算预处理函数生成的该与运算单元输出的待验证掩码数据的消息验证码的密钥,并根据所述密钥以及该与运算单元输出的待验证掩码数据,进行计算,确定第一计算结果;判断各第一计算结果与各待验证掩码数据对应的消息验证码是否一致;若是,将各待验证掩码数据作为该与运算单元输出的掩码数据;若否,确定验证不通过的待验证掩码数据对应的智能设备,并向确定出的智能设备发送验证不通过的消息。
- 如权利要求1所述的方法,其特征在于,根据所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证,具体包括:针对每一个掩码比特份额,确定基于所述多方安全计算预处理函数生成的该掩码比特份额对应的密钥以及消息验证码,根据所述密钥以及该掩码比特份额,进行计算,确定第二计算结果;根据所述各掩码比特份额对应的第二计算结果以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证。
- 一种数据聚合的方法,其特征在于,所述方法应用于智能设备,所述方法包括:确定待聚合数据;根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,其中,所述聚合树为聚合中心预先构建的;根据所述掩码比特份额,对所述待聚合数据进行处理,确定掩码数据,并生成所述掩码数据对应的标签值;将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,使所述聚合中心根据接收到的各智能设备发送的掩码数据和标签值,确定掩码结果;确定所述聚合树输出的掩码结果对应的掩码比特份额以及所述掩码比特份额对应的消息验证码,并将确定出的掩码比特份额以及消息验证码发送给所述聚合中心,使所述聚合中心根据接收到的各掩码比特份额以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证,并在验证通过时,根据所述各掩码比特份额以及所述掩码结果,确定聚合结果。
- 如权利要求6所述的方法,其特征在于,所述聚合树包括若干运算节点,各运算节点分别包括若干与运算单元;将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,具体包括:针对所述聚合树中的每一个运算节点,且依次针对该运算节点中的每一个与运算单元,确定输入该与运算单元的可验证掩码比特份额以及标签值;采用所述安全多方计算预处理函数,确定该与运算单元的三元组、该与运算单元输出的可验证掩码比特份额以及该与运算单元输出的标签值;根据所述三元组、所述输入该与运算单元的可验证掩码比特份额、所述输入该与运 算单元的标签值、所述该与运算单元输出的可验证掩码比特份额以及所述该与运算单元输出的标签值,确定该与运算单元对应的单元密文;将所述聚合树中各运算节点的各与运算单元对应的单元密文、所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心。
- 如权利要求7所述的方法,其特征在于,所述运算节点还包括若干异或运算单元;确定输入该与运算单元的可验证掩码比特份额以及标签值,具体包括:当该与运算单元的上一个运算单元为异或运算单元时,确定输入该与运算单元的上一个运算单元的可验证掩码比特份额以及标签值;根据所述输入该与运算单元的上一个运算单元的可验证掩码比特份额,确定该与运算单元的上一个运算单元输出的可验证掩码比特份额,并作为输入该与运算单元的可验证掩码比特份额;根据所述输入该与运算单元的上一个运算单元的标签值,确定该与运算单元的上一个运算单元输出的标签值,并作为输入该与运算单元的标签值。
- 如权利要求7所述的方法,其特征在于,该运算节点为所述智能设备所属的运算节点,所述三元组包括第一数值、第二数值以及第三数值,所述输入该与运算单元的可验证掩码比特份额包括第一可验证掩码比特份额以及第二可验证掩码比特份额;根据所述三元组、所述输入该与运算单元的可验证掩码比特份额、所述输入该与运算单元的标签值、所述该与运算单元输出的可验证掩码比特份额以及所述该与运算单元输出的标签值,确定该与运算单元对应的单元密文,具体包括:根据所述三元组中的第一数值以及所述输入该与运算单元的第一可验证掩码比特份额,确定第一值,以及根据所述三元组中的第二数值以及所述输入该与运算单元的第二可验证掩码比特份额,确定第二值,并将所述第一值以及所述第二值发送给其他智能设备,其中,所述其他智能设备为向该运算节点输入数据的智能设备中除所述智能设备之外的智能设备;接收所述其他智能设备发送的第三值以及第四值,并将接收到的第三值以及所述第一值聚合,确定第一总值,以及将接收到的第四值以及所述第二值聚合,确定第二总值;根据所述第一总值、所述第二总值、所述三元组、所述该与运算单元输出的可验证掩码比特份额以及所述输入该与运算单元的可验证掩码比特份额,确定该与运算单元输出的待验证掩码数据;根据该与运算单元输出的待验证掩码数据、所述输入该与运算单元的标签值以及所述该与运算单元输出的标签值,确定该与运算单元对应的单元密文。
- 如权利要求6所述的方法,其特征在于,将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,具体包括:将所述掩码数据发送给除所述智能设备之外的其他智能设备,使所述其他智能设备生成所述掩码数据对应的标签值并发送给所述聚合中心,以及将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心。
- 一种数据聚合的装置,其特征在于,所述装置应用于聚合中心,所述装置包括:第一接收模块,用于接收各智能设备发送的掩码数据以及各掩码数据分别对应的标签值,其中,所述掩码数据为所述智能设备基于掩码比特份额对待聚合数据进行处理后的数据,所述掩码比特份额是所述智能设备基于安全多方计算预处理函数生成的;聚合模块,用于根据所述各掩码数据以及各标签值,基于预先构建的聚合树,对所述各掩码数据进行聚合,确定掩码结果;第二接收模块,用于接收所述各智能设备发送的所述掩码结果的掩码比特份额以及所述掩码比特份额对应的消息验证码,其中,各掩码比特份额用于对所述掩码结果进行解密;验证模块,用于根据所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证;解密模块,用于在验证通过时,根据所述各掩码比特份额对所述掩码结果进行解密,确定聚合结果。
- 一种数据聚合的装置,其特征在于,所述装置应用于智能设备,所述装置包括:确定模块,用于确定待聚合数据;生成模块,用于根据聚合树的拓扑结构,采用安全多方计算预处理函数,生成掩码比特份额,其中,所述聚合树为聚合中心预先构建的;加密模块,用于根据所述掩码比特份额,对所述待聚合数据进行处理,确定掩码数据,并生成所述掩码数据对应的标签值;发送模块,用于将所述掩码数据以及所述掩码数据对应的标签值发送给所述聚合中心,使所述聚合中心根据接收到的各智能设备发送的掩码数据和标签值,确定掩码结果;掩码模块,用于确定所述聚合树输出的掩码结果对应的掩码比特份额以及所述掩码比特份额对应的消息验证码,并将确定出的掩码比特份额以及消息验证码发送给所述聚合中心,使所述聚合中心根据接收到的各掩码比特份额以及所述各掩码比特份额对应的消息验证码,对所述各掩码比特份额进行验证,并在验证通过时,根据所述各掩码比特份额以及所述掩码结果,确定聚合结果。
- 一种计算机可读存储介质,其特征在于,所述存储介质存储有计算机程序,所述计算机程序被处理器执行时实现上述权利要求1~10任一项所述的方法。
- 一种电子设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,其特征在于,所述处理器执行所述计算机程序时实现上述权利要求1~10任一项所述的方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202311035190.6A CN117033442B (zh) | 2023-08-16 | 2023-08-16 | 一种数据聚合的方法、装置、存储介质及电子设备 |
| CN202311035190.6 | 2023-08-16 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025035679A1 true WO2025035679A1 (zh) | 2025-02-20 |
Family
ID=88624195
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/141653 Pending WO2025035679A1 (zh) | 2023-08-16 | 2023-12-25 | 一种数据聚合的方法、装置、存储介质及电子设备 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN117033442B (zh) |
| WO (1) | WO2025035679A1 (zh) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN117033442B (zh) * | 2023-08-16 | 2025-02-11 | 之江实验室 | 一种数据聚合的方法、装置、存储介质及电子设备 |
| CN117218758B (zh) * | 2023-08-23 | 2025-12-09 | 之江实验室 | 一种电子投票的方法、装置、存储介质及电子设备 |
| CN118101181B (zh) * | 2024-02-21 | 2024-08-30 | 之江实验室 | 一种风险识别的方法、装置、存储介质及电子设备 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113691380A (zh) * | 2021-10-26 | 2021-11-23 | 西南石油大学 | 一种智能电网中多维隐私数据聚合方法 |
| WO2023023281A1 (en) * | 2021-08-19 | 2023-02-23 | University Of Southern California | Systems and methods for secure aggregation in federated learning |
| CN117033442A (zh) * | 2023-08-16 | 2023-11-10 | 之江实验室 | 一种数据聚合的方法、装置、存储介质及电子设备 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10871947B2 (en) * | 2016-03-03 | 2020-12-22 | Cryptography Research, Inc. | Converting a boolean masked value to an arithmetically masked value for cryptographic operations |
-
2023
- 2023-08-16 CN CN202311035190.6A patent/CN117033442B/zh active Active
- 2023-12-25 WO PCT/CN2023/141653 patent/WO2025035679A1/zh active Pending
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2023023281A1 (en) * | 2021-08-19 | 2023-02-23 | University Of Southern California | Systems and methods for secure aggregation in federated learning |
| CN113691380A (zh) * | 2021-10-26 | 2021-11-23 | 西南石油大学 | 一种智能电网中多维隐私数据聚合方法 |
| CN117033442A (zh) * | 2023-08-16 | 2023-11-10 | 之江实验室 | 一种数据聚合的方法、装置、存储介质及电子设备 |
Non-Patent Citations (2)
| Title |
|---|
| GUO, JUANJUAN: "Secure Multiparty Computation and Application in Machine Learning", JOURNAL OF COMPUTER RESEARCH AND DEVELOPMENT, vol. 58, no. 10, 31 October 2021 (2021-10-31), XP093278932 * |
| LIU ZHUSEN; CAO ZHENFU; DONG XIAOLEI; ZHAO XIAOPENG; BAO HAIYONG; SHEN JIACHEN: "A verifiable privacy-preserving data collection scheme supporting multi-party computation in fog-based smart grid", FRONTIERS OF COMPUTER SCIENCE, HIGHER EDUCATION PRESS, BEIJING, vol. 16, no. 1, 19 October 2021 (2021-10-19), Beijing, XP037593173, ISSN: 2095-2228, DOI: 10.1007/s11704-021-0410-0 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN117033442A (zh) | 2023-11-10 |
| CN117033442B (zh) | 2025-02-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11784801B2 (en) | Key management method and related device | |
| US10880100B2 (en) | Apparatus and method for certificate enrollment | |
| US20210328786A1 (en) | Blockchain integrated station and cryptographic acceleration card, key management methods and apparatuses | |
| CN109361644B (zh) | 一种支持快速搜索和解密的模糊属性基加密方法 | |
| CN117033442B (zh) | 一种数据聚合的方法、装置、存储介质及电子设备 | |
| CN111639362B (zh) | 区块链中实现隐私保护的方法、节点和存储介质 | |
| WO2025039447A1 (zh) | 一种电子投票的方法、装置、存储介质及电子设备 | |
| CN110611568A (zh) | 基于多种加解密算法的动态加解密方法、装置、及设备 | |
| CN117201034A (zh) | 一种数字签名的方法、装置、存储介质及电子设备 | |
| WO2020073712A1 (zh) | 一种移动终端中共享安全应用的方法及移动终端 | |
| CN114638005A (zh) | 基于区块链的数据处理方法、装置及系统、存储介质 | |
| WO2024187902A1 (zh) | 一种模型训练方法、装置、存储介质以及电子设备 | |
| WO2025039934A1 (zh) | 业务处理 | |
| CN118445855A (zh) | 基于区块链的隐私数据处理方法、装置、设备及介质 | |
| CN116257303B (zh) | 一种数据安全处理的方法、装置、存储介质及电子设备 | |
| WO2024152798A1 (zh) | 一种数据风险评估的方法、装置、存储介质及电子设备 | |
| CN118611927A (zh) | 一种数据传输方法、装置、存储介质及电子设备 | |
| CN113792346A (zh) | 一种可信数据处理方法、装置及设备 | |
| WO2025060249A1 (zh) | 用于隐私保护的数据使用方法和服务器 | |
| CN113312637B (zh) | 代理服务器及其对加密的订阅与事件进行匹配的方法 | |
| CN116527249A (zh) | 基于区块链和国密算法的虚拟电厂邀约方法、装置和设备 | |
| CN118764170B (zh) | 数据处理方法、系统、设备、存储介质和程序产品 | |
| CN114301710A (zh) | 确定报文是否被篡改的方法、密管平台和密管系统 | |
| CN116318621B (zh) | 一种基于同态加密的产业物联数据隐私保护系统 | |
| CN116821936B (zh) | 一种数据交集的确定方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23949095 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |