| 研究生: |
孫祥恩 Sun, Hsiang-En |
|---|---|
| 論文名稱: |
基於多鑰代理同態加密的隱私保護資料分析平台 A Privacy-Preserving Data Analytics Platform using Delegate Multi-key Homomorphic Encryption |
| 指導教授: |
郭耀煌
Kuo, Yau-Hwang |
| 學位類別: |
碩士 Master |
| 系所名稱: |
電機資訊學院 - 資訊工程學系 Department of Computer Science and Information Engineering |
| 論文出版年: | 2021 |
| 畢業學年度: | 109 |
| 語文別: | 英文 |
| 論文頁數: | 73 |
| 中文關鍵詞: | 隱私保護 、同態加密 、多鑰匙 、資料分析 |
| 外文關鍵詞: | Privacy-preserving, Homomorphic Encryption, Multi-key, Data Analytics |
| 相關次數: | 點閱:175 下載:0 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
近年來,由物聯網設備取得的大量資料有效提升了資料分析服務的品質,然而,如何保護好資料隱私的議題卻也隨之浮上檯面。為此,各國紛紛頒布隱私保護相關的法規,如歐盟的 General Data Protection Regulation (GDPR),明確規範服務提供商在收集與使用客戶個人資料時的限制。不過,除了客戶個人資料的隱私需要確保之外,服務提供商的分析模型亦是需要被保護的關鍵資產。所以,建構一個能同時兼顧客戶與服務提供商雙方需求的資料分析平台是刻不容緩的任務。
為此,本論文提出一個基於同態加密技術的隱私保護資料分析平台,客戶將其個人資料加密後上傳,服務提供商會進一步利用本平台對加密的個人資料進行分析運算,最後再將加密的分析結果回傳給客戶。此舉不但保護客戶資料的實際內容不被服務提供商得知,服務提供商的分析模型亦不會洩漏給客戶知道。然而,傳統的同態加密技術採用單鑰加密,每次僅能分析單一客戶的資料,不符合資料分析服務得同時分析多個客戶資料的需求。因此,本論文提出多鑰代理同態加密方法,除了在多客戶的資料分析應用情境中保護客戶的個人資料與服務提供商的分析模組不被對方取得,客戶亦無法得知其他客戶的個人資料,藉此提供完整的隱私保護資料分析服務。此外,有別於其他多鑰同態加密方法,本論文所提出之方法能有效地支援客戶動態地參與分析服務,並忍受這些參與服務的客戶可能發生的斷線問題,因此更能符合物聯網應用情境的實際需求。
最後,本論文提出理論方法的正確性、安全性與效能分析,再結合實驗結果,足以說明所提出的多鑰代理同態加密法明顯優於其他現有方法。由此可知,本平台可作為物聯網應用情境中有效可靠的隱私保護資料分析解決方案。
Recently, massive data acquired by IoT devices improve the quality of data analytics services. However, the issue that how to protect data privacy also emerges. Regulations for data privacy-preserving, such as General Data Protection Regulation (GDPR) of European Union, have been published to regulate service providers when acquiring and processing client data. However, analysis models derived by service providers also are valuable assets and need to be protected. Hence, to establish a data analytics platform which satisfies the requirements of both client and service provider becomes a critical issue.
This thesis proposes a privacy-preserving data analytics platform based on the Homomorphic Encryption (HE) technique. That is, after clients encrypt their data and deliver them to the proposed platform, service providers perform analytics operations on this platform referring to these encrypted data and then return encrypted analysis results to clients. Thereby, client data will not be discovered by service providers, and analysis models will not be leaked to clients. Generally, data analytics services require data from multiple clients. However, traditional HE methods utilize a single-key to encrypt, which can only analyze the data of a single client and thus fail to fit the requirement of data analytics services. Thus, this thesis proposes a Delegate multi-key HE (DLHE) method to protect analysis model privacy and prevent client data from exposing to service providers and other clients. After that, data privacy of both sides can be ensured completely. Compared to other multi-key HE methods, the proposed method allows clients to dynamically join and leave without interrupting the analytics services, which is more practical in various IoT applications.
Finally, based on the analyses of correctness, security, and performance, as well as the experiment results, the proposed DLHE method outperforms other existing multi-key HE methods. That is, the proposed platform can be applied as a practical solution to provide privacy-preserving data analytics services in IoT environments.
[ABA 16] Abadi, Martin, et al. "Deep learning with differential privacy." Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. 2016.
[AI 20] Al Badawi, Ahmad, et al. "Towards the AlexNet Moment for Homomorphic Encryption: HCNN, the First Homomorphic CNN on Encrypted Data with GPUs." (2020).
[ALB 19] Albrecht, Martin R., et al. "Homomorphic Encryption Standard." IACR Cryptol. ePrint Arch. 2019 (2019): 939.
[ALO 20] Aloufi, Asma, et al. "Computing blindfolded on data homomorphically encrypted under multiple keys: An extended survey." arXiv preprint arXiv:2007.09270 (2020).
[ASH 12] Asharov, Gilad, et al. "Multiparty computation with low communication, computation and interaction via threshold FHE." Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, Berlin, Heidelberg, 2012.
[BON 18] Boneh, Dan, et al. "Threshold cryptosystems from threshold fully homomorphic encryption." Annual International Cryptology Conference. Springer, Cham, 2018.
[BOU 18] Bourse, Florian, et al. "Fast homomorphic evaluation of deep discretized neural networks." Annual International Cryptology Conference. Springer, Cham, 2018.
[BRA 11] Brakerski, Zvika, and Vinod Vaikuntanathan. "Fully homomorphic encryption from ring-LWE and security for key dependent messages." Annual cryptology conference. Springer, Berlin, Heidelberg, 2011.
[BRA 12] Brakerski, Zvika. "Fully homomorphic encryption without modulus switching from classical GapSVP." Annual Cryptology Conference. Springer, Berlin, Heidelberg, 2012.
[BRA 14] Brakerski, Zvika, Craig Gentry, and Vinod Vaikuntanathan. "(Leveled) fully homomorphic encryption without bootstrapping." ACM Transactions on Computation Theory (TOCT) 6.3 (2014): 1-36.
[CHE 17] Chen, Long, Zhenfeng Zhang, and Xueqing Wang. "Batched multi-hop multi-key FHE from ring-LWE with compact ciphertext extension." Theory of Cryptography Conference. Springer, Cham, 2017.
[CHE 17] Cheon, Jung Hee, et al. "Homomorphic encryption for arithmetic of approximate numbers." International Conference on the Theory and Application of Cryptology and Information Security. Springer, Cham, 2017.
[COS 16] Costan, Victor, and Srinivas Devadas. "Intel sgx explained." IACR Cryptol. ePrint Arch. 2016.86 (2016): 1-118.
[COS 16] Costache, Ana, and Nigel P. Smart. "Which ring based somewhat homomorphic encryption scheme is best?." Cryptographers’ Track at the RSA Conference. Springer, Cham, 2016.
[DWO 14] Dwork, Cynthia, and Aaron Roth. "The algorithmic foundations of differential privacy." Found. Trends Theor. Comput. Sci. 9.3-4 (2014): 211-407.
[ELG 85] ElGamal, Taher. "A public key cryptosystem and a signature scheme based on discrete logarithms." IEEE transactions on information theory 31.4 (1985): 469-472.
[EUR 16] European Union, "General Data Protection Regulation", 2016. Available: https://gdpr-info.eu/
[EVE 85] Even, Shimon, Oded Goldreich, and Abraham Lempel. "A randomized protocol for signing contracts." Communications of the ACM 28.6 (1985): 637-647.
[FAN 12] Fan, Junfeng, and Frederik Vercauteren. "Somewhat practical fully homomorphic encryption." IACR Cryptol. ePrint Arch. 2012 (2012): 144.
[FOR 21] Fortune Business Insights, "Prefilled Syringes Market Size, Share & COVID-19 Impact Analysis, By Material (Glass and Plastic) By Closing System (Staked Needle System, Luer Cone System, and Luer Lock Form System) By Product (Complete Syringe Set and Components & Accessories); By Design (Double-chamber, Multiple-chamber, and Single-chamber); By End-user (Pharmaceutical & Biotechnology Companies), and Regional Forecast, 2021-2028", 2021. Available: https://www.fortunebusinessinsights.com/industry-reports/prefilled-syringes-market-101946
[GEN 09] Gentry, Craig. "Fully homomorphic encryption using ideal lattices." Proceedings of the forty-first annual ACM symposium on Theory of computing. 2009.
[GEN 13] Gentry, Craig, Amit Sahai, and Brent Waters. "Homomorphic encryption from learning with errors: Conceptually-simpler, asymptotically-faster, attribute-based." Annual Cryptology Conference. Springer, Berlin, Heidelberg, 2013.
[GIL 16] Gilad-Bachrach, Ran, et al. "Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy." International conference on machine learning. PMLR, 2016.
[GOO 17] Google AI, "Federated Learning: Collaborative Machine Learning without Centralized Training Data", 2017. Available: https://ai.googleblog.com/2017/04/federated-learning-collaborative.html
[GOO 21] Google. "Google Health", 2021. Available: https://health.google/
[HES 17] Hesamifard, Ehsan, Hassan Takabi, and Mehdi Ghasemi. "Cryptodl: Deep neural networks over encrypted data." arXiv preprint arXiv:1711.05189 (2017).
[IBM 21] IBM, "Watson Helath", 2021. Available: https://www.ibm.com/watson-health
[JER 20] Jere, Malhar S., Tyler Farnan, and Farinaz Koushanfar. "A taxonomy of attacks on federated learning." IEEE Security & Privacy 19.2 (2020): 20-28.
[JUV 18] Juvekar, Chiraag, Vinod Vaikuntanathan, and Anantha Chandrakasan. "{GAZELLE}: A low latency framework for secure neural network inference." 27th {USENIX} Security Symposium ({USENIX} Security 18). 2018.
[KAM 11] Kamara, Seny, Payman Mohassel, and Mariana Raykova. "Outsourcing Multi-Party Computation." IACR Cryptol. Eprint Arch. 2011 (2011): 272.
[KIM 20] Kim, Eunkyung, et al. "How to securely collaborate on data: Decentralized threshold he and secure key update." IEEE Access 8 (2020): 191319-191329.
[LIU 17] Liu, Jian, et al. "Oblivious neural network predictions via minionn transformations." Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. 2017.
[LOP 12] López-Alt, Adriana, Eran Tromer, and Vinod Vaikuntanathan. "On-the-fly multiparty computation on the cloud via multikey fully homomorphic encryption." Proceedings of the forty-fourth annual ACM symposium on Theory of computing. 2012.
[LYU 10] Lyubashevsky, Vadim, Chris Peikert, and Oded Regev. "On ideal lattices and learning with errors over rings." Annual international conference on the theory and applications of cryptographic techniques. Springer, Berlin, Heidelberg, 2010.
[MO 21] Mo, Fan, et al. "PPFL: privacy-preserving federated learning with trusted execution environments." arXiv preprint arXiv:2104.14380 (2021).
[MOH 17] Mohassel, Payman, and Yupeng Zhang. "Secureml: A system for scalable privacy-preserving machine learning." 2017 IEEE symposium on security and privacy (SP). IEEE, 2017.
[NGA 16] Ngabonziza, Bernard, et al. "Trustzone explained: Architectural features and use cases." 2016 IEEE 2nd International Conference on Collaboration and Internet Computing (CIC). IEEE, 2016.
[PAI 99] Paillier, Pascal. "Public-key cryptosystems based on composite degree residuosity classes." International conference on the theory and applications of cryptographic techniques. Springer, Berlin, Heidelberg, 1999.
[PCL 21] pCloud, "Invasive Apps", 2021. Available: https://blog.pcloud.com/invasive-apps/
[REG 09] Regev, Oded. "On lattices, learning with errors, random linear codes, and cryptography." Journal of the ACM (JACM) 56.6 (2009): 1-40.
[RIV 78] Rivest, Ronald L., Len Adleman, and Michael L. Dertouzos. "On data banks and privacy homomorphisms." Foundations of secure computation 4.11 (1978): 169-180.
[ROU 18] Rouhani, Bita Darvish, M. Sadegh Riazi, and Farinaz Koushanfar. "Deepsecure: Scalable provably-secure deep learning." Proceedings of the 55th Annual Design Automation Conference. 2018.
[SHA 79] Shamir, Adi. "How to share a secret." Communications of the ACM 22.11 (1979): 612-613.
[STA 18] State of California Department of Justice, "California Consumer Privacy Act (CCPA)", 2018. Available: https://oag.ca.gov/privacy/ccpa
[US 20] U.S. Department of Health and Human Services (HSS), "The HIPAA Privacy Rule", 2020. Available: https://www.hhs.gov/hipaa/for-professionals/privacy/index.html
[WAN 19] Wang, Wenhao, et al. "Toward scalable fully homomorphic encryption through light trusted computing assistance." arXiv preprint arXiv:1905.07766 (2019).
[YAO 86] Yao, Andrew Chi-Chih. "How to generate and exchange secrets." 27th Annual Symposium on Foundations of Computer Science (sfcs 1986). IEEE, 1986.