IP Library Granted Patent US 11,228,423
Granted Patent B2
US 11,228,423 · App. 16/836,725 · Granted Jan 18, 2022

Method and device for security assessment of encryption models

Inventor: Fangyuan Ruan (Hangzhou, CN)
Assignee: ADVANCED NEW TECHNOLOGIES CO., LTD.
H04L9/0618G06K9/6256H04L9/008H04L9/0825H04L9/0869H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,228,423
App. No.
16/836,725
Granted
Jan 18, 2022
Kind
B2
Abstract

A method includes: a first device sending to a second device a deployment request for deploying a homomorphically-encrypted data model on the second device, wherein the deployment request comprises ciphertext model parameters and a public key for the homomorphic encryption; the second device obtaining a first ciphertext security assessment index through computation using the ciphertext model parameters, and sending the same to the first device; the first device decrypting the received first ciphertext security assessment index using a private key corresponding to the public key to generate a plaintext security assessment index, and forwarding the plaintext security assessment index to the second device; and the second device encrypting the plaintext security assessment index using the public key to generate a second ciphertext security assessment index, comparing both indices to determine consistency for determining whether to deploy the homomorphically-encrypted data model.

Claims (40)

1. A method for security assessment of encryption models, the method comprising:

a first device training a data model and performing homomorphic encryption on one or more plaintext model parameters of the data model to obtain ciphertext model parameters of the data model, and shuffling the ciphertext model parameters of the data model to change an order of the ciphertext model parameters of the data model;

the first device sending to a second device a deployment request for deploying a homomorphically-encrypted data model on the second device, wherein the deployment request comprises the shuffled ciphertext model parameters of the data model and a public key for the homomorphic encryption;

the second device obtaining a first ciphertext security assessment index through computation using the shuffled ciphertext model parameters, wherein the first ciphertext security assessment index is obtained by calculating a variance of the shuffled ciphertext model parameters, and sending the first ciphertext security assessment index to the first device;

the first device decrypting the received first ciphertext security assessment index using a private key corresponding to the public key to generate a plaintext security assessment index, and forwarding the plaintext security assessment index to the second device; and

the second device encrypting the plaintext security assessment index using the public key to generate a second ciphertext security assessment index, comparing the first ciphertext security assessment index with the second ciphertext security assessment index to determine consistency thereof, and determining whether to deploy the homomorphically-encrypted data model according to the comparing.

2. The method according to claim 1 , further comprising:

the second device generating a model security assessment report for determining whether to deploy the homomorphically-encrypted data model based on comparison results of a plurality of first ciphertext security assessment indices and a plurality of second ciphertext security assessment indices.

3. The method according to claim 1 , wherein the deployment request further comprises a random number such that using the public key with the random number results in a consistent encryption result for the same data.

4. The method according to claim 1 , further comprising:

the second device denying the deployment request in response to determining that the first ciphertext security assessment index and the second ciphertext security assessment index are not consistent.

5. The method according to claim 1 , further comprising:

the second device deploys the homomorphically-encrypted data model in response to determining that the first ciphertext security assessment index and the second ciphertext security assessment index are consistent.

6. A method for security assessment of encryption models, the method comprising:

a first device training a data model and performing homomorphic encryption on one or more plaintext model parameters of the data model to obtain ciphertext model parameters of the data model, and shuffling the ciphertext model parameters of the data model to change an order of the ciphertext model parameters of the data model;

the first device sending to a second device a deployment request for deploying a homomorphically-encrypted data model on the second device, wherein the deployment request comprises the shuffled ciphertext model parameters of the data model and a public key for the homomorphic encryption;

the second device forwarding the shuffled ciphertext model parameters and the public key to a security assessment device;

the first device obtaining a first ciphertext security assessment index that is generated by the security assessment device using the shuffled ciphertext model parameters and the public key, wherein the first ciphertext security assessment index is obtained by calculating a variance of the shuffled ciphertext model parameters, decrypting the first ciphertext security assessment index using a private key corresponding to the public key to generate a plaintext security assessment index, and forwarding the plaintext security assessment index to the security assessment device;

the second device obtaining a model security assessment report from the security assessment device, wherein the model security assessment report is generated by the security assessment device encrypting the plaintext security assessment index using the public key to generate a second ciphertext security assessment index and comparing the first ciphertext security assessment index with the second ciphertext security assessment index to determine consistency thereof; and

the second device determining whether to deploy the homomorphically-encrypted data model according to the model security assessment report.

7. The method according to claim 6 , wherein:

the security assessment device is configured for generating a comprehensive model security assessment report for the second device to determine whether to deploy the homomorphically-encrypted data model by considering comparison results of a plurality of first ciphertext security assessment indices and a plurality of second ciphertext security assessment indices.

8. The method according to claim 6 , wherein the deployment request further comprises a random number such that using the public key with the random number results in a consistent encryption result for the same data.

9. The method according to claim 6 , further comprising:

the second device denying the deployment request in response to that the model security assessment report indicates that the first ciphertext security assessment index and the second ciphertext security assessment index are not consistent.

10. The method according to claim 6 , further comprising:

the second device deploys the homomorphically-encrypted data model in response to that the model security assessment report indicates that the first ciphertext security assessment index and the second ciphertext security assessment index are consistent.

11. One or more non-transitory computer-readable storage media storing instructions executable by one or more processors to cause the one or more processors to perform operations including:

a first device training a data model and performing homomorphic encryption on one or more plaintext model parameters of the data model to obtain ciphertext model parameters of the data model, and shuffling the ciphertext model parameters of the data model to change an order of the ciphertext model parameters of the data model;

the first device sending to a second device a deployment request for deploying a homomorphically-encrypted data model on the second device, wherein the deployment request comprises the shuffled ciphertext model parameters of the data model and a public key for the homomorphic encryption;

the second device obtaining a first ciphertext security assessment index through computation using the shuffled ciphertext model parameters, wherein the first ciphertext security assessment index is obtained by calculating a variance of the shuffled ciphertext model parameters, and sending the first ciphertext security assessment index to the first device;

the first device decrypting the received first ciphertext security assessment index using a private key corresponding to the public key to generate a plaintext security assessment index, and forwarding the plaintext security assessment index to the second device; and

the second device encrypting the plaintext security assessment index using the public key to generate a second ciphertext security assessment index, comparing the first ciphertext security assessment index with the second ciphertext security assessment index to determine consistency thereof, and determining whether to deploy the homomorphically-encrypted data model according to the comparing.

12. The one or more non-transitory computer-readable storage media according to claim 11 , wherein the operations further comprise:

the second device generating a comprehensive model security assessment report for determining whether to deploy the homomorphically-encrypted data model by comprehensively considering comparison results of a plurality of first ciphertext security assessment indices and a plurality of second ciphertext security assessment indices.

13. The one or more non-transitory computer-readable storage media according to claim 11 , wherein the deployment request further comprises a random number such that using the public key with random number results in a consistent encryption result for the same data.

14. The one or more non-transitory computer-readable storage media according to claim 11 , wherein the operations further comprise:

the second device denying the deployment request in response to that the model security assessment report indicates that the first ciphertext security assessment index with the second ciphertext security assessment index are not consistent.

15. The one or more non-transitory computer-readable storage media according to claim 11 , wherein the operations further comprise:

the second device deploys the homomorphically-encrypted data model in response to that the model security assessment report indicates that the first ciphertext security assessment index and the second ciphertext security assessment index are consistent.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053796/0281 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053702/0392 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2020
From: RUAN, FANGYUAN
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 052641/0558 →