Efficient communication data opening and sharing method and system based on privacy set intersection
By improving the combination of obfuscated Bloom filter and star topology, the communication overhead problem in privacy computing of multiple participants is solved, and efficient privacy collection requests are achieved to ensure the security of privacy information.
Patent Information
- Application Number
- CN202510777397.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-08-15
AI Technical Summary
In the privacy computing scenario of multiple participants, the communication overhead of the existing privacy set request protocol increases linearly with the increase in the number of participants, resulting in bandwidth limitations and risk of privacy information leakage.
The improved obfuscation Blonde filter and star topology are adopted to assist in searching the optimal element insertion order by counting Blonde filters, combined with the threshold public key encryption system that satisfies the addition homomorphism, and a multi-party security comparison protocol is used to determine the existence of elements, reducing the number of communications.
Significantly reduce storage space overhead, ensure that private information is not leaked, and keep communication overhead unchanged, improving the efficiency and accuracy of privacy computing.
Smart Images

Figure CN120498648A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data security, and in particular relates to a method and system for openly sharing communication-efficient data based on privacy set intersection. Background Art
[0002] In recent years, with the rapid development of technologies such as the Internet of Things, 5G, and cloud computing, businesses and individuals can exchange massive amounts of data efficiently, conveniently, and at low cost over the internet. In the era of open, circulated, and shared big data, companies from different industries and regions are attempting to share private user data for joint modeling and statistical analysis to improve existing business models and unlock additional revenue. However, excessive collection, indiscriminate sharing, and illegal misuse of user data can lead to the leakage of user privacy. Privacy computing technology enables cross-domain data value mining while protecting user privacy and company trade secrets. Private Set Intersection (PSI) is a specialized privacy computing protocol that allows two or more participants to collaboratively compute the intersection of local datasets without disclosing any private information beyond the elements in the intersection. PSI protocols play a crucial role in privacy computing scenarios and serve as the foundation for privacy-preserving machine learning and data mining algorithms, making them a significant research topic. However, as the number of participants increases, the communication overhead of existing PSI protocols increases linearly, and the overall performance of the protocols is limited by the communication bandwidth available to the participants. Summary of the Invention
[0003] The purpose of this invention is to provide a method and system for efficient data open sharing based on privacy set intersection, while meeting regulatory compliance requirements. This method is capable of addressing privacy computing scenarios involving a large number of participants. While ensuring that the user privacy information of all participants' local datasets is not leaked, it can securely and efficiently calculate the intersection of multiple datasets, thereby facilitating data preprocessing for subsequent machine learning and data mining algorithms. This solution is based on a threshold public-key cryptography scheme that satisfies additive homomorphism, and utilizes an improved obfuscated Bloom filter and a star-topology communication network to reduce communication overhead.
[0004] In order to achieve the above object, the present invention adopts the following technical solutions:
[0005] A communication-efficient data open sharing method based on privacy set intersection, comprising:
[0006] Determine several participants and their corresponding private data sets and configuration parameters, randomly select one participant as the server, and the remaining participants as clients. The configuration parameters include: the upper limit of the participant's private data set size, the hash function used to count the Bloom filter, and a custom threshold. Each participant generates a pair of public and private keys based on the corresponding hash function.
[0007] Each client searches for an optimal element insertion order and encodes the local private dataset into an improved obfuscated Bloom filter;
[0008] Based on the public key, each client confuses the improved obfuscated Bloom filter to hide the private information inserted into the local private dataset, and sends the obfuscated and encrypted local private dataset to the participant acting as the server;
[0009] For any element and a participant acting as a client, the server determines whether the element is in the participant's private data set according to the multi-party security comparison protocol; if so, the number of occurrences of the element is increased by 1, otherwise it is increased by 0;
[0010] The server uses a multi-party secure comparison protocol to determine whether the number of occurrences of each element exceeds the custom threshold, and outputs the elements whose occurrences exceed the custom threshold as a multi-party intersection, thereby realizing open data sharing.
[0011] As a preferred solution, the method of determining several participants and their corresponding privacy data sets and configuration parameters, randomly selecting one participant as the server, and using the remaining participants as clients, specifically includes:
[0012] Before starting to calculate the multi-party intersection, determine the number of participants n, the upper limit m of the size of the participant data set, the custom threshold t for the multi-party intersection calculation, and the use of k independent hash functions h0,h1,…,h with uniformly distributed calculation results. k-1 ; Wherein, the custom threshold, the upper limit of the participant data set size and the hash function do not change during the operation of the protocol;
[0013] A participant P0 is randomly selected as the server, and a pair of public and private keys (pk, sk) is generated using a threshold public key encryption system that satisfies additive homomorphism, and the remaining participants are used as clients.
[0014] As a preferred solution, the randomly selected party acting as the server needs to use a threshold public key encryption system that satisfies additive homomorphism and sets the decryption threshold to n, thereby resisting up to n-1 collusion and corruption parties.
[0015] As a preferred solution, each client searches for an optimal element insertion order and encodes the local privacy dataset into an improved obfuscated Bloom filter, specifically including:
[0016] Each client searches for an optimal element insertion order and successfully inserts all elements in the private dataset into the improved obfuscated Bloom filter based on the optimal element insertion order.
[0017] Among them, the method of searching for the optimal element insertion order includes:
[0018] Put the private dataset into a counting bloom filter;
[0019] If any element has a value of 1 at any position in the counting bloom filter, the element is listed as an object that can be successfully inserted into the improved obfuscated bloom filter and can be deleted from the data set and placed in the stack;
[0020] When all elements are placed in the stack, an optimal element insertion order is taken out, and all elements are successfully encoded and inserted into the improved confusion Bloom filter.
[0021] As a preferred solution, each client obfuscates the improved obfuscated Bloom filter based on the public key, thereby hiding the private information inserted into the local private data set, and sends the obfuscated and encrypted local private data set to the participant acting as the server, specifically including:
[0022] After inserting all elements, each client party obfuscates the improved obfuscated Bloom filter and uses public key encryption to hide the private information of the inserted dataset. The obfuscated encrypted local private dataset is then sent to the party acting as the server.
[0023] Among them, when located in the inserted private dataset, the element x satisfies the condition:
[0024] LGBF[h0(x)]+LGBF[h1(x)]+…+LGBF[h k-1 (x)]=0
[0025] Among them, LGBF is an improved confusion Bloom filter.
[0026] As a preferred solution, for any element and a participant acting as a client, the server determines whether the element is located in the participant's private data set according to a multi-party security comparison protocol, specifically including:
[0027] The server uses a multi-party secure comparison protocol to determine whether the element is located in the private data sets of different participants without obtaining the private information of the corresponding participants.
[0028] Accordingly, the present invention also provides a communication-efficient data open sharing system based on privacy set intersection, comprising:
[0029] A parameter confirmation module is used to determine several participants and their corresponding private data sets and configuration parameters, and randomly select one participant as the server and the remaining participants as clients. The configuration parameters include: the upper limit of the participant's private data set size, the hash function used to count the Bloom filter, and a custom threshold. Each participant generates a pair of public and private keys based on the corresponding hash function;
[0030] The first one acts as a client processing module, which is used by each client to search for an optimal element insertion order and encode the local privacy dataset into an improved obfuscated Bloom filter;
[0031] a second client-acting processing module, configured to, based on the public key, cause each client to obfuscate the improved obfuscated Bloom filter, thereby hiding the private information inserted into the local private data set, and send the obfuscated and encrypted local private data set to the participant acting as the server;
[0032] The first server processing module is used to determine, for any element and a participant acting as a client, whether the element is in the participant's private data set according to the multi-party security comparison protocol; if so, the number of occurrences of the element is increased by 1, otherwise it is increased by 0;
[0033] The second server processing module is used for the server to use a multi-party security comparison protocol to determine whether the number of occurrences of each element exceeds the custom threshold, and to output the elements whose number of occurrences exceeds the custom threshold as a multi-party intersection, thereby realizing data openness and sharing.
[0034] As a preferred solution, the parameter confirmation module is used to determine several participants and their corresponding privacy data sets and configuration parameters, and randomly select one participant as the server and the remaining participants as clients, specifically including:
[0035] Before starting to calculate the multi-party intersection, determine the number of participants n, the upper limit m of the size of the participant data set, the custom threshold t for the multi-party intersection calculation, and the use of k independent hash functions h0,h1,…,h with uniformly distributed calculation results. k-1 ; Wherein, the custom threshold, the upper limit of the participant data set size and the hash function do not change during the operation of the protocol;
[0036] A participant P0 is randomly selected as the server, and a pair of public and private keys (pk, sk) is generated using a threshold public key encryption system that satisfies additive homomorphism, and the remaining participants are used as clients.
[0037] Correspondingly, the present invention also provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements the communication efficient data open sharing method based on privacy set intersection as described in any one of the above items.
[0038] Correspondingly, the present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the communication efficient data open sharing method based on privacy set intersection as described in any one of the above.
[0039] Compared with the prior art, the present invention has at least the following beneficial technical effects:
[0040] This invention provides a method and system for efficient data open sharing based on private set intersection. An improved obfuscated Bloom filter is designed. By using a counting Bloom filter to assist in searching for an optimal element insertion order, this method ensures that all elements are successfully inserted into the improved obfuscated Bloom filter while significantly reducing array length and storage overhead. Existing private set intersection protocols, which all use obfuscated Bloom filters, suffer from partial intersection loss due to element insertion failures, which in turn affects the accuracy and effectiveness of privacy calculation results.
[0041] Furthermore, in a communication method and system based on a privacy set intersection protocol, the present invention changes the secret sharing principle of the obfuscated Bloom filter from addition to exclusive-OR calculation, enabling homomorphism to be maintained after encryption using a threshold public-key cryptography that satisfies additive homomorphism. Furthermore, using a star-topology communication network, all parties acting as clients only need to perform a single round of communication with the party acting as the server. Therefore, as the number of parties increases, the communication overhead for the parties remains constant. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 The figure is a flow chart of the steps of the method of the present invention.
[0044] Figure 2 Schematic diagram of an application scenario using the method of the present invention.
[0045] Figure 3 The figure is a logical structure and flow chart of the method of the present invention.
[0046] Figure 4 This is a structural block diagram of a communication-efficient data open sharing system based on privacy set intersection of the present invention. DETAILED DESCRIPTION
[0047] Hereinafter, only certain exemplary embodiments are briefly described. As will be appreciated by those skilled in the art, the described embodiments may be modified in various ways without departing from the spirit or scope of the present invention. Therefore, the drawings and description are to be considered as illustrative in nature and not restrictive.
[0048] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0049] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0050] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0051] The accompanying drawings illustrate various schematic diagrams of structures according to embodiments disclosed herein. These figures are not drawn to scale; for clarity, some details are exaggerated and some details may be omitted. The shapes of the various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary and may deviate in practice due to manufacturing tolerances or technical limitations. Those skilled in the art may design regions / layers with different shapes, sizes, and relative positions as needed.
[0052] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0053] Example 1
[0054] See also Figure 1, which is a communication efficient data open sharing method based on privacy set intersection provided by the present invention, comprising the following steps S101-S105:
[0055] S101: Determine several participants and their corresponding privacy data sets and configuration parameters, and randomly select one participant as the server and the remaining participants as clients; wherein the configuration parameters include: the upper limit of the size of the participant's privacy data set, the hash function used to count the Bloom filter, and the custom threshold. Each participant generates a pair of public and private keys according to the corresponding hash function.
[0056] As a preferred solution, the method of determining several participants and their corresponding privacy data sets and configuration parameters, randomly selecting one participant as the server, and using the remaining participants as clients, specifically includes:
[0057] Before starting to calculate the multi-party intersection, determine the number of participants n, the upper limit m of the size of the participant data set, the custom threshold t for the multi-party intersection calculation, and the use of k independent hash functions h0,h1,…,h with uniformly distributed calculation results. k-1 ; Wherein, the custom threshold, the upper limit of the participant data set size and the hash function do not change during the operation of the protocol; a participant P0 is randomly selected as the server, and a pair of public and private keys (pk, sk) is generated using a threshold public key encryption system that satisfies additive homomorphism, and the remaining participants are used as clients.
[0058] In this embodiment, n participants P i Input privacy dataset S respectively i , determine the upper limit m of the size of the data set of the participants, and improve the k hash functions h0,h1,…,h used by the obfuscated Bloom filter k-1 and a custom threshold t, that is, before starting to calculate the multi-party intersection, determine the number of participants n, the upper limit m of the size of the participant data set, the threshold t of the multi-party intersection to be calculated, and use k independent hash functions h0,h1,…,h with uniformly distributed calculation results. k-1 , the parameters do not change during the protocol. Then, a participant P0 is randomly selected to act as the server, and a pair of public and private keys (pk, sk) is generated using a threshold public key encryption system that satisfies additive homomorphism. The remaining participants act as clients.
[0059] As a preferred solution, the randomly selected party acting as the server needs to use a threshold public key encryption system that satisfies additive homomorphism and sets the decryption threshold to n, thereby resisting up to n-1 collusion and corruption parties.
[0060] S102: Each client searches for an optimal element insertion order and encodes the local private dataset into an improved obfuscated Bloom filter.
[0061] As a preferred solution, each client searches for an optimal element insertion order and encodes the local privacy dataset into an improved obfuscated Bloom filter, specifically including:
[0062] Each client searches for an optimal element insertion order and successfully inserts all elements in the private dataset into the improved obfuscated Bloom filter based on the optimal element insertion order.
[0063] Among them, the method of searching for the optimal element insertion order includes:
[0064] Put the private dataset into a counting bloom filter;
[0065] If any element has a value of 1 at any position in the counting bloom filter, the element is listed as an object that can be successfully inserted into the improved obfuscated bloom filter and can be deleted from the data set and placed in the stack;
[0066] When all elements are placed in the stack, an optimal element insertion order is taken out, and all elements are successfully encoded and inserted into the improved confusion Bloom filter.
[0067] In this embodiment, each participant acting as a client searches for an optimal element insertion order to successfully insert all elements in the private data set into the improved obfuscated Bloom filter. The search method is to first place the data set into a counting Bloom filter. If a certain position of an element in the counting Bloom filter corresponds to 1, it means that the element can be successfully inserted into the improved obfuscated Bloom filter, and can be deleted from the data set and placed in the stack. When all elements are placed in the stack, an optimal element insertion order is taken out and all elements are successfully inserted into the improved obfuscated Bloom filter.
[0068] S103: Based on the public key, each client obfuscates the improved obfuscated Bloom filter to hide the private information inserted into the local private data set, and sends the obfuscated and encrypted local private data set to the participant acting as the server.
[0069] As a preferred solution, each client obfuscates the improved obfuscated Bloom filter based on the public key, thereby hiding the private information inserted into the local private data set, and sends the obfuscated and encrypted local private data set to the participant acting as the server, specifically including:
[0070] After inserting all elements, each client party obfuscates the improved obfuscated Bloom filter and uses public key encryption to hide the private information of the inserted dataset. The obfuscated encrypted local private dataset is then sent to the party acting as the server.
[0071] Among them, when located in the inserted private dataset, the element x satisfies the condition:
[0072] LGBF[h0(x)]+LGBF[h1(x)]+…+LGBF[h k-1 (x)]=0
[0073] Among them, LGBF is an improved confusion Bloom filter.
[0074] In this embodiment, each participant acting as a client obfuscates the improved obfuscated Bloom filter after inserting all elements, and then uses public key encryption to hide the private information of the inserted data set; for the queried element x, when it is in the inserted data set, the following conditions are met:
[0075] LGBF[h0(x)]+LGBF[h1(x)]+…+LGBF[h k-1 (x)]=0
[0076] Where LGBF is the improved confusion Bloom filter.
[0077] S104: For any element and participant acting as a client, the server determines whether the element is located in the participant's private data set according to the multi-party security comparison protocol; if so, the number of occurrences of the element is increased by 1, otherwise it is increased by 0.
[0078] As a preferred solution, for any element and a participant acting as a client, the server determines whether the element is located in the participant's private data set according to a multi-party security comparison protocol, specifically including:
[0079] The server uses a multi-party secure comparison protocol to determine whether the element is located in the private data sets of different participants without obtaining the private information of the corresponding participants.
[0080] In this embodiment, the participant P0 acting as the server uses a multi-party secure comparison protocol to determine whether an element is in a specific participant's data set. For an element x that has been inserted into the data set, the query on the obfuscated Bloom filter satisfies the following conditions:
[0081]
[0082] In order to ensure that the properties of the secret sharing algorithm do not change after public key encryption, the improved obfuscated Bloom filter changes the principle of the secret sharing algorithm from XOR calculation to addition calculation. For an element x inserted into the data set, the query of the obfuscated Bloom filter satisfies the following conditions:
[0083] LGBF[h0(x)]+LGBF[h1(x)]+…+LGBF[h k-1 (x)]=0
[0084] Use the public key pk of a threshold public key encryption system that satisfies additive homomorphism to encrypt the secret shares in the array of the improved obfuscated Bloom filter one by one. Then the participant P0 acting as the server sends the public key encrypted improved obfuscated Bloom filter query to the participant acting as the client to query the elements inserted into the data set. According to the definition of additive homomorphism, we can get:
[0085] ELGBF[h0(x)]+ELGBF[h1(x)]+…+ELGBF[h k-1 (x)]=Enc(pk,0)
[0086] Participant P0, acting as the server, uses a multi-party secure comparison protocol to determine whether the plaintexts corresponding to the ciphertexts on both sides of the equation are identical. If so, it returns Enc(pk, 1); otherwise, it returns Enc(pk, 0). The plaintext corresponding to the ciphertext output by the multi-party secure comparison protocol represents whether the element appears in the data set of the participant corresponding to the improved obfuscated Bloom filter encrypted with the public key.
[0087] S105: The server uses a multi-party security comparison protocol to determine whether the number of occurrences of each element exceeds the custom threshold, and outputs the elements whose number of occurrences exceeds the custom threshold as a multi-party intersection, thereby realizing open data sharing.
[0088] In this embodiment, the participant P0 acting as the server uses a multi-party security comparison protocol to determine whether the number of occurrences of an element exceeds a custom threshold t, and then outputs a multi-party intersection. The participant P0 acting as the server initiates a query to the received n public key encrypted improved obfuscated Bloom filters for each element in the local data set. The query result is determined using the multi-party security comparison protocol to determine whether the element appears in the data set of a specific participant. At the same time, the n output ciphertexts of the multi-party security comparison protocol for the same element are added together, and the corresponding plaintext is the number of times the element appears in the data sets of the n participants. Therefore, this ciphertext can be compared with the custom threshold t for multi-party security. If the plaintext corresponding to the protocol output ciphertext is 1, it means that this element is in the multi-party intersection output by the privacy set intersection protocol.
[0089] Example 2
[0090] The present invention provides a method for efficient data open sharing based on the intersection of private sets. Each participant acting as a client only needs to send a public key-encrypted improved obfuscated Bloom filter to the participant acting as a server. As the number of participants increases, the communication overhead of the participants remains unchanged. Specifically, this method proposes for the first time a solution to the element insertion failure problem of the obfuscated Bloom filter by modifying the element insertion order, and proposes an optimal element insertion order search algorithm based on a greedy strategy, reducing the array length by 65%. At the same time, the secret sharing principle of the obfuscated Bloom filter is modified, and a threshold public key encryption system that satisfies additive homomorphism is used to achieve efficient intersection. This method can be used for the intersection of multi-party data sets when the number of participants is large.
[0091] like Figure 2 The figure shows an application scenario for the method of the present invention. This scenario involves multiple participants, each client holding a private dataset of no more than m elements. The elements and size of each participant's dataset are private information. For privacy protection purposes, participants cannot directly exchange raw datasets to calculate the multi-party intersection, nor can they find a third party fully trusted by all participants to perform the intersection calculation. The method described in this invention is used to efficiently calculate the multi-party intersection in this scenario without directly transferring raw data.
[0092] like Figure 3 The logical architecture and flow chart of the present invention are shown below. The communication-efficient privacy set intersection protocol of the present invention includes the following steps:
[0093] Step 1: n participants P i Input privacy dataset S respectively i , determine the upper limit m of the size of the data set of the participants, and improve the k hash functions h0,h1,…,h used by the obfuscated Bloom filter k-1 and a custom threshold t; the upper limit of the dataset size m and the number of hash functions k are used to calculate the appropriate length of the improved obfuscated Bloom filter array, while the custom threshold t is used to ensure that the protocol outputs elements that appear in the datasets of at least t participants.
[0094] Step 2: Randomly select a participant P0 to act as the server and use the threshold public key encryption system that satisfies additive homomorphism to generate a pair of public and private keys (pk, sk). The remaining participants P1, P2, ..., P n-1 Acting as a client; the present invention uses a star topology communication network, the participant P0 acting as the server is located at the central node, and the participants P1, P2, ..., P acting as the client n-1 It is located at the edge node, so the participant who plays the role of client only communicates with the participant who plays the role of server.
[0095] Step 3: Each participant acting as a client searches for an optimal element insertion order to encode the local private dataset into an improved obfuscated Bloom filter. Assuming that the participant has a dataset of size m to be inserted into an improved obfuscated Bloom filter with an array length of l, the dataset {x0, x1, ..., x m-1} is inserted into a counting Bloom filter with the same data length of l, and the k hash functions h0,h1,…,h used by both are k-1 The calculation results are exactly the same, if the element x j The calculated array subscript meets the conditions:
[0096]
[0097] It means that the array subscripts calculated by the other m-1 elements will not be mapped to this position, where CBF[h j (x)] is the hth element in the Counting Bloom Filter. j (X) position.
[0098] Therefore, when the data set {X0,X1,…,x m-1}\x j has been inserted into the improved obfuscated Bloom filter, the element x j Can be successfully inserted into the improved confusion bloom filter. j Remove from the counting bloom filter and add the element X j Put it into a stack, then you can continue to use the counting Bloom filter to filter the data set {X0,X1,…,X m-1}\X j Find the element that can be successfully inserted into the confusion Bloom filter. Wait until the data set {X0,X1,…,x m-1} are put into the stack, and then an optimal element insertion order for improving the confusion Bloom filter can be taken from the top of the stack.
[0099] It is worth noting that, unlike the existing algorithms that try to insert the elements of the dataset into the obfuscated Bloom filter one by one, the new algorithm needs to insert the entire dataset into the improved obfuscated Bloom filter at one time. Therefore, the algorithm may be deadlocked, that is, it is impossible to find a feasible optimal order of element insertion. In this case, a dataset of size m {x0,x1,…,x m-1 When inserting into a counting Bloom filter with k hash functions, the following situations may occur:
[0100]
[0101] At this point, any element cannot be successfully inserted into the improved confusion Bloom filter.
[0102] There are two ways to solve this problem: first, ensure that the k hash functions used by the counting Bloom filter are independent of each other, and the calculation results are evenly distributed to avoid a large number of hash values aggregating in a certain part of the counting Bloom filter; second, the length of the counting Bloom filter can be increased to reduce the expected value of any counter in the counting Bloom filter array.
[0103] Step 5: The participant P0 acting as the server uses a multi-party secure comparison protocol to determine whether the element is in the dataset of a specific participant; for an element x that has been inserted into the dataset, the query of the obfuscated Bloom filter satisfies the condition:
[0104]
[0105] In order to ensure that the properties of the secret sharing algorithm do not change after public key encryption, the improved obfuscated Bloom filter changes the principle of the secret sharing algorithm from XOR calculation to addition calculation. For an element x inserted into the data set, the query of the obfuscated Bloom filter satisfies the following conditions:
[0106] LGBF[h0(x)]+LGBF[h1(x)]+…+LGBF[h k-1 (x)]=0
[0107] Among them, LGBF is an improved confusion bloom filter;
[0108] Use the public key pk of a threshold public key encryption system that satisfies additive homomorphism to encrypt the secret shares in the array of the improved obfuscated Bloom filter one by one. Then the participant P0 acting as the server sends the public key encrypted improved obfuscated Bloom filter query to the participant acting as the client to query the elements inserted into the data set. According to the definition of additive homomorphism, we can get:
[0109] ELGBF[h0(X)]+ELGBF[h1(x)]+…+ELGBF[h k-1 (x)]=Enc(pk,0)
[0110] Among them, ELGBF is an improved obfuscated Bloom filter for homomorphic encryption, and Enc represents the public key encryption function.
[0111] Participant P0, acting as the server, uses a multi-party secure comparison protocol to determine whether the plaintexts corresponding to the ciphertexts on both sides of the equation are identical. If so, it returns Enc(pk, 1); otherwise, it returns Enc(pk, 0). The plaintext corresponding to the ciphertext output by the multi-party secure comparison protocol represents whether the element appears in the data set of the participant corresponding to the improved obfuscated Bloom filter encrypted with the public key.
[0112] Step 6: Participant P0, acting as the server, uses a multi-party secure comparison protocol to determine whether the element's occurrence count exceeds a custom threshold t and then outputs the multi-party intersection. For each element in the local dataset, participant P0 queries the n public-key-encrypted modified obfuscated Bloom filters. The query results are compared using the multi-party secure comparison protocol to determine whether the element appears in the dataset of a specific participant.
[0113] The sum of the n ciphertext outputs of the same element in the multi-party secure comparison protocol is the number of times the element appears in the datasets of the n participants. Therefore, this ciphertext can be compared with a custom threshold t for multi-party secure comparison. If the plaintext corresponding to the protocol output ciphertext is 1, it means that the element is in the multi-party intersection set output by the privacy set intersection protocol.
[0114] Example 3
[0115] This invention was implemented on real power grid and bank user data, where the power grid and bank data serve as user identifiers. The intersection objective was to obtain the intersection of the two user sets. In this case study, we set the number of hash functions used to be k = 10 and the length of the counting Bloom filter to be l = 1.44 km. When the size of the participating datasets grows linearly, the computational overhead of different multi-party privacy set intersection protocols is shown in Table 1. ECDH is an intersection protocol based on the discrete elliptic curve cryptography algorithm, KMPRT is designed based on oblivious transfer and symmetric encryption techniques, and BEHSV is constructed based on the threshold addition homomorphic public key cryptography.
[0116] Table 1. Client computational overhead of the multi-party private set intersection protocol for different dataset sizes (unit: seconds)
[0117]
[0118] As shown in Table 1, the computational overhead of the client in each of the four multi-party privacy set intersection protocols increases linearly with the linear growth of the dataset size. Specifically, the proposed method has the lowest computational overhead, as it uses homomorphic addition and a re-randomization algorithm, and the average time required to intersect a single element is only 0.7ms. The KMPRT protocol is second, due to its use of symmetric encryption technology, with an average time of 2ms for intersects. The ECDH protocol, third due to its use of elliptic curve cryptography, takes an average of 8ms for intersects. Finally, the BEHSV protocol, due to the large number of public key encryptions, takes an average of 570ms for intersects.
[0119] Example 4
[0120] like Figure 4 As shown, the present invention provides a communication-efficient data open sharing system based on privacy set intersection, comprising:
[0121] A parameter confirmation module is used to determine several participants and their corresponding private data sets and configuration parameters, and randomly select one participant as the server and the remaining participants as clients. The configuration parameters include: the upper limit of the participant's private data set size, the hash function used to count the Bloom filter, and a custom threshold. Each participant generates a pair of public and private keys based on the corresponding hash function;
[0122] The first one acts as a client processing module, which is used by each client to search for an optimal element insertion order and encode the local privacy dataset into an improved obfuscated Bloom filter;
[0123] a second client-acting processing module, configured to, based on the public key, cause each client to obfuscate the improved obfuscated Bloom filter, thereby hiding the private information inserted into the local private data set, and send the obfuscated and encrypted local private data set to the participant acting as the server;
[0124] The first server processing module is used to determine, for any element and a participant acting as a client, whether the element is in the participant's private data set according to the multi-party security comparison protocol; if so, the number of occurrences of the element is increased by 1, otherwise it is increased by 0;
[0125] The second server processing module is used for the server to use a multi-party security comparison protocol to determine whether the number of occurrences of each element exceeds the custom threshold, and to output the elements whose number of occurrences exceeds the custom threshold as a multi-party intersection, thereby realizing data openness and sharing.
[0126] As a preferred solution, the method of determining several participants and their corresponding privacy data sets and configuration parameters, randomly selecting one participant as the server, and using the remaining participants as clients, specifically includes:
[0127] Before starting to calculate the multi-party intersection, determine the number of participants n, the upper limit m of the size of the participant data set, the custom threshold t for the multi-party intersection calculation, and the use of k independent hash functions h0,h1,…,h with uniformly distributed calculation results. k-1 ; Wherein, the custom threshold, the upper limit of the participant data set size and the hash function do not change during the operation of the protocol;
[0128] A participant P0 is randomly selected as the server, and a pair of public and private keys (pk, sk) is generated using a threshold public key encryption system that satisfies additive homomorphism, and the remaining participants are used as clients.
[0129] As a preferred solution, the randomly selected party acting as the server needs to use a threshold public key encryption system that satisfies additive homomorphism and sets the decryption threshold to n, thereby resisting up to n-1 collusion and corruption parties.
[0130] As a preferred solution, each client searches for an optimal element insertion order and encodes the local privacy dataset into an improved obfuscated Bloom filter, specifically including:
[0131] Each client searches for an optimal element insertion order and successfully inserts all elements in the private dataset into the improved obfuscated Bloom filter based on the optimal element insertion order.
[0132] Among them, the method of searching for the optimal element insertion order includes:
[0133] Put the private dataset into a counting bloom filter;
[0134] If any element has a value of 1 at any position in the counting bloom filter, the element is listed as an object that can be successfully inserted into the improved obfuscated bloom filter and can be deleted from the data set and placed in the stack;
[0135] When all elements are placed in the stack, an optimal element insertion order is taken out, and all elements are successfully encoded and inserted into the improved confusion Bloom filter.
[0136] As a preferred solution, each client obfuscates the improved obfuscated Bloom filter based on the public key, thereby hiding the private information inserted into the local private data set, and sends the obfuscated and encrypted local private data set to the participant acting as the server, specifically including:
[0137] After inserting all elements, each client party obfuscates the improved obfuscated Bloom filter and uses public key encryption to hide the private information of the inserted dataset. The obfuscated encrypted local private dataset is then sent to the party acting as the server.
[0138] Among them, when located in the inserted private dataset, the element x satisfies the condition:
[0139] LGBF[h0(x)]+LGBF[h1(x)]+…+LGBF[h k-1 (x)]=0
[0140] Among them, LGBF is an improved confusion Bloom filter.
[0141] As a preferred solution, for any element and a participant acting as a client, the server determines whether the element is located in the participant's private data set according to a multi-party security comparison protocol, specifically including:
[0142] The server uses a multi-party secure comparison protocol to determine whether the element is located in the private data sets of different participants without obtaining the private information of the corresponding participants.
[0143] Example 5
[0144] The present invention provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the steps of the method for efficient communication and open sharing of data based on privacy set intersection.
[0145] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0146] The present application is described with reference to the flowcharts and / or block diagrams of the methods, systems, and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A system that specifies the functions of a box or boxes.
[0147] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0148] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0149] The above shows and describes the basic principles and main features of the present invention and the advantages of the present invention. It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. Therefore, from all points of view, the embodiments should be regarded as illustrative and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description, and it is intended that all changes that fall within the meaning and range of equivalents of the claims be included in the present invention. Any reference signs in the claims should not be construed as limiting the claim to which they relate.
[0150] In addition, it should be understood that although this specification describes the embodiments, not every embodiment contains only one independent technical solution. This description is for clarity only. Those skilled in the art should consider the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art. The above content is only for the purpose of illustrating the technical concept of the present invention and cannot be used to limit the scope of protection of the present invention. Any changes made based on the technical solution in accordance with the technical concept proposed by the present invention fall within the scope of protection of the claims of the present invention.
Claims
1. A communication-efficient data open sharing method based on privacy set intersection, characterized in that: include: Determine several participants and their corresponding private data sets and configuration parameters, randomly select one participant as the server, and the remaining participants as clients. The configuration parameters include: the upper limit of the participant's private data set size, the hash function used to count the Bloom filter, and a custom threshold. Each participant generates a pair of public and private keys based on the corresponding hash function. Each client searches for an optimal element insertion order and encodes the local private dataset into an improved obfuscated Bloom filter; Based on the public key, each client confuses the improved obfuscated Bloom filter to hide the private information inserted into the local private dataset, and sends the obfuscated and encrypted local private dataset to the participant acting as the server; For any element and a participant acting as a client, the server determines whether the element is in the participant's private data set according to the multi-party security comparison protocol; if so, the number of occurrences of the element is increased by 1, otherwise it is increased by 0; The server uses a multi-party secure comparison protocol to determine whether the number of occurrences of each element exceeds the custom threshold, and outputs the elements whose occurrences exceed the custom threshold as a multi-party intersection, thereby realizing open data sharing.
2. The method for efficient communication data open sharing based on privacy set intersection according to claim 1, characterized in that: The process of determining several participants and their corresponding privacy data sets and configuration parameters, randomly selecting one participant as the server, and using the remaining participants as clients, specifically includes: Before starting to calculate the multi-party intersection, determine the number of participants n, the upper limit m of the size of the participant data set, the custom threshold t for the multi-party intersection calculation, and the use of k independent hash functions h0,h1,…,h with uniformly distributed calculation results. k-1 ; Wherein, the custom threshold, the upper limit of the participant data set size and the hash function do not change during the operation of the protocol; A participant P0 is randomly selected as the server, and a pair of public and private keys (pk, sk) is generated using a threshold public key encryption system that satisfies additive homomorphism, and the remaining participants are used as clients.
3. The communication-efficient data open sharing method based on privacy set intersection according to claim 2 is characterized in that: The randomly selected party acting as the server needs to use a threshold public key encryption system that satisfies additive homomorphism and set the decryption threshold to n, thereby resisting up to n-1 collusion and corruption parties.
4. The method for efficient communication data open sharing based on privacy set intersection according to claim 1, characterized in that: Each client searches for an optimal element insertion order and encodes the local privacy dataset into an improved obfuscated Bloom filter, specifically including: Each client searches for an optimal element insertion order and successfully inserts all elements in the private dataset into the improved obfuscated Bloom filter based on the optimal element insertion order. Among them, the method of searching for the optimal element insertion order includes: Put the private dataset into a counting bloom filter; If any element has a value of 1 at any position in the counting bloom filter, the element is listed as an object that can be successfully inserted into the improved obfuscated bloom filter and can be deleted from the data set and placed in the stack; When all elements are placed in the stack, an optimal element insertion order is taken out, and all elements are successfully encoded and inserted into the improved confusion Bloom filter.
5. The method for efficient communication data open sharing based on privacy set intersection according to claim 4, characterized in that: According to the public key, each client obfuscates the improved obfuscated Bloom filter to hide the private information inserted into the local private data set, and sends the obfuscated and encrypted local private data set to the participant acting as the server, specifically including: After inserting all elements, each client party obfuscates the improved obfuscated Bloom filter and uses public key encryption to hide the private information of the inserted dataset. The obfuscated encrypted local private dataset is then sent to the party acting as the server. Among them, when located in the inserted private dataset, the element x satisfies the condition: LGBF[h0(x)]+LGBF[h1(x)]+…+LGBF[h k-1 (x)]=0 Among them, LGBF is an improved confusion Bloom filter.
6. The method for efficient communication data open sharing based on privacy set intersection according to claim 1, characterized in that: For any element and a participant acting as a client, the server determines whether the element is located in the participant's private data set according to the multi-party security comparison protocol, specifically including: The server uses a multi-party secure comparison protocol to determine whether the element is located in the private data sets of different participants without obtaining the private information of the corresponding participants.
7. A communication-efficient data open sharing system based on privacy set intersection, characterized in that: include: A parameter confirmation module is used to determine several participants and their corresponding private data sets and configuration parameters, and randomly select one participant as the server and the remaining participants as clients. The configuration parameters include: the upper limit of the participant's private data set size, the hash function used to count the Bloom filter, and a custom threshold. Each participant generates a pair of public and private keys based on the corresponding hash function; The first one acts as a client processing module, which is used by each client to search for an optimal element insertion order and encode the local privacy dataset into an improved obfuscated Bloom filter; a second client-acting processing module, configured to, based on the public key, cause each client to obfuscate the improved obfuscated Bloom filter, thereby hiding the private information inserted into the local private data set, and send the obfuscated and encrypted local private data set to the participant acting as the server; The first server processing module is used to determine, for any element and a participant acting as a client, whether the element is in the participant's private data set according to the multi-party security comparison protocol; if so, the number of occurrences of the element is increased by 1, otherwise it is increased by 0; The second server processing module is used for the server to use a multi-party security comparison protocol to determine whether the number of occurrences of each element exceeds the custom threshold, and to output the elements whose number of occurrences exceeds the custom threshold as a multi-party intersection, thereby realizing data openness and sharing.
8. The communication-efficient data open sharing system based on privacy set intersection according to claim 7, characterized in that: The parameter confirmation module is used to determine several participants and their corresponding privacy data sets and configuration parameters, and randomly select one participant as the server and the remaining participants as clients. Specifically, it includes: Before starting to calculate the multi-party intersection, determine the number of participants n, the upper limit m of the size of the participant data set, the custom threshold t for the multi-party intersection calculation, and the use of k independent hash functions h0,h1,…,h with uniformly distributed calculation results. k-1 ; Wherein, the custom threshold, the upper limit of the participant data set size and the hash function do not change during the operation of the protocol; A participant P0 is randomly selected as the server, and a pair of public and private keys (pk, sk) is generated using a threshold public key encryption system that satisfies additive homomorphism, and the remaining participants are used as clients.
9. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the method for efficient communication and open sharing of data based on privacy set intersection as described in any one of claims 1 to 6 is implemented.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the communication efficient data open sharing method based on privacy set intersection as described in any one of claims 1 to 6.
Citation Information
Cited By
Fast threshold multi-party privacy set intersection method
CN121173469A
A fast threshold multi-party privacy set intersection method
CN121173469B