Secure and Privacy-Preserving Consensus

Secure and Privacy-Preserving Consensus
复制标题

DOI:
10.1109/tac.2019.2890887
复制
发表时间:
2017-07
影响因子:
6.8
通讯作者:
Minghao Ruan;Huan Gao;Yongqiang Wang
Minghao Ruan;Huan Gao;Yongqiang Wang
中科院分区:
计算机科学2区
文献类型:
--
作者:
Minghao Ruan;Huan Gao;Yongqiang Wang

文献摘要

被引文献

相似文献

共识是分布式系统的基础,因为它支撑着此类系统的关键功能,从分布式信息融合、决策到分散控制。为了达成协议,现有的共识算法要求每个代理与其邻居交换显式的状态信息。这会导致私人国家信息的泄露,这在涉及隐私的情况下是不可取的。在本文中,我们提出了一种用于无向网络的新颖方法,该方法可以在没有聚合器或第三方的情况下在去中心化架构中实现安全且保护隐私的平均共识。通过利用部分同态密码学在成对交互动态中嵌入保密性,我们的方法可以保证以确定性方式收敛到共识值(受到量化误差的影响),而无需向邻居公开节点的状态。我们为动态系统提供了一种新的隐私定义,并给出了一个新的框架来严格证明节点的隐私可以得到保护,只要它至少有一个合法的邻居,它忠实地遵循共识协议,而不试图推断其他节点的状态。除了能够抵御旨在窃取状态信息的被动攻击者之外,该方法还可以轻松结合防御机制,以抵御试图更改交换消息内容的主动攻击者。此外,与现有的基于噪声注入的隐私保护机制(当拓扑或节点数量变化时必须重新配置整个网络)相比,我们的方法适用于具有时变耦合拓扑的动态环境。这种安全且保护隐私的方法也适用于加权平均共识以及新更新规则下的最大/最小共识。数值模拟以及与现有方法的比较证实了理论结果。还提供了基于 Raspberry-Pi 板的微控制器网络的实验结果,以验证该方法的有效性和效率。
Consensus is fundamental for distributed systems since it underpins key functionalities of such systems ranging from distributed information fusion, decision making, to decentralized control. In order to reach an agreement, existing consensus algorithms require each agent to exchange explicit state information with its neighbors. This leads to the disclosure of private state information, which is undesirable in cases where privacy is of concern. In this paper, we propose a novel approach for undirected networks, which can enable secure and privacy-preserving average consensus in a decentralized architecture in the absence of an aggregator or third party. By leveraging partial homomorphic cryptography to embed secrecy in pairwise interaction dynamics, our approach can guarantee convergence to the consensus value (subject to a quantization error) in a deterministic manner without disclosing a node's state to its neighbors. We provide a new privacy definition for dynamical systems, and give a new framework to rigorously prove that a node's privacy can be protected as long as it has at least one legitimate neighbor, which follows the consensus protocol faithfully without attempts to infer other nodes’ states. In addition to enabling resilience to passive attackers aiming to steal state information, the approach also allows easy incorporation of defending mechanisms against active attackers who try to alter the content of exchanged messages. Furthermore, in contrast to existing noise-injection-based privacy-preserving mechanisms that have to reconfigure the entire network when the topology or number of nodes varies, our approach is applicable to dynamic environments with time-varying coupling topologies. This secure and privacy-preserving approach is also applicable to weighted average consensus as well as maximum/minimum consensus under a new update rule. Numerical simulations and comparison with existing approaches confirm the theoretical results. Experimental results on a Raspberry-Pi board based microcontroller network are also presented to verify the effectiveness and efficiency of the approach.