Skip to main content
QUICK REVIEW

[论文解读] A Secure Multi-Party Computation Protocol for Malicious Computation Prevention for preserving privacy during Data Mining

Durgesh Kumar Mishra, Neha Koria|ArXiv.org|Aug 7, 2009
Cryptography and Data Security参考文献 13被引用 8
一句话总结

本文提出了一种增强的隐私保护数据挖掘安全多方计算(SMPC)协议,以防止恶意行为,扩展了先前的Encrytpo_Random协议。该协议引入了一套稳健的架构,结合可信第三方和密码学技术,确保数据机密性和完整性,在协作式数据挖掘场景中显著提升了对恶意对手的安全防护能力。

ABSTRACT

Secure Multi-Party Computation (SMC) allows parties with similar background to compute results upon their private data, minimizing the threat of disclosure. The exponential increase in sensitive data that needs to be passed upon networked computers and the stupendous growth of internet has precipitated vast opportunities for cooperative computation, where parties come together to facilitate computations and draw out conclusions that are mutually beneficial; at the same time aspiring to keep their private data secure. These computations are generally required to be done between competitors, who are obviously weary of each-others intentions. SMC caters not only to the needs of such parties but also provides plausible solutions to individual organizations for problems like privacy-preserving database query, privacy-preserving scientific computations, privacy-preserving intrusion detection and privacy-preserving data mining. This paper is an extension to a previously proposed protocol Encrytpo_Random, which presented a plain sailing yet effective approach to SMC and also put forward an aptly crafted architecture, whereby such an efficient protocol, involving the parties that have come forward for joint-computations and the third party who undertakes such computations, can be developed. Through this extended work an attempt has been made to further strengthen the existing protocol thus paving the way for a more secure multi-party computational process.

研究动机与目标

  • 解决互不信任的各方在数据挖掘中日益增长的隐私保护计算需求。
  • 增强现有Encrytpo_Random协议,以抵御可能偏离协议的恶意对手。
  • 设计一种安全且可扩展的架构,引入第三方可信方,以促进联合计算而不暴露私有数据。
  • 确保敏感数据保持机密性,同时实现准确可靠的协作式数据挖掘结果。
  • 为现实世界应用(如隐私保护数据库查询和入侵检测)提供实用且高效的解决方案。

提出的方法

  • 通过引入检测和防止恶意行为的机制,扩展Encrytpo_Random协议,以应对多方计算过程中的安全威胁。
  • 提出一种包含数据拥有者和可信第三方(TTP)的三方架构,由TTP负责中介和验证计算过程。
  • 采用秘密共享和零知识证明等密码学技术,确保计算的正确性和数据的隐私性。
  • 实施输入验证和一致性检查,以检测任何参与方对协议的偏离行为。
  • 采用结构化的协议流程,确保仅处理有效输入,并保证输出可验证。
  • 复用现有的安全计算原 primitive,以在提升对恶意参与者的抗性的同时保持计算效率。

实验结果

研究问题

  • RQ1如何增强安全多方计算协议,以在隐私保护数据挖掘过程中抵御恶意行为?
  • RQ2在涉及互不信任的各方的协作式数据挖掘中,需要哪些架构改进以确保可信性?
  • RQ3如何扩展现有的Encrytpo_Random协议,以对恶意对手提供更强的安全保障?
  • RQ4可集成哪些密码学机制,以在不泄露私有数据的前提下验证输入完整性和计算正确性?
  • RQ5在现实世界的数据挖掘场景中,所提出的协议在确保强安全性的同时,其效率能维持到何种程度?

主要发现

  • 所提出的协议通过引入检测和防止恶意行为的机制,成功增强了Encrytpo_Random协议的安全性。
  • 该架构通过输入验证和验证步骤,有效隔离并缓解了恶意参与方带来的风险。
  • 协议在显著提升对恶意方攻击的抵抗能力的同时,保持了计算效率。
  • 密码学技术的集成确保了在整个计算过程中私有数据的机密性。
  • 该协议为涉及竞争对手或互不信任实体的隐私保护数据挖掘提供了实用的框架。
  • 该解决方案适用于现实世界用例,如隐私保护数据库查询和入侵检测系统。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。