Method for calculating threshold multi-party privacy set intersection based on security comparison
Through homomorphic encryption and secure comparison protocols, the PaillierTD cryptographic system is used to distribute private keys, reducing client computing and communication volume, solving the problems of large computational complexity and insufficient privacy protection in existing technologies, and realizing efficient multi-party privacy set intersection calculation.
Patent Information
- Application Number
- CN202510784744.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-09-19
AI Technical Summary
Existing methods for calculating threshold multi-party privacy set intersection have problems such as large client computational workload, high hardware requirements, low private data protection, low computational efficiency, and high communication overhead.
Homomorphic encryption technology and secure comparison protocol are adopted, and the PaillierTD cryptographic system is used to divide the private key into two parts, one for the cloud server and the other for the client. The data is encrypted through a Bloom filter and homomorphic summation and secure comparison are performed on the cloud server, reducing client computing and communication volume and ensuring privacy protection.
It improves computing efficiency and data privacy protection, reduces the risk of personal privacy leakage, reduces communication overhead, and realizes set intersection calculation that meets threshold conditions.
Smart Images

Figure CN120675706A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of privacy protection of information security, and in particular to a method for calculating the intersection of threshold multi-party privacy sets based on security comparison. Background Art
[0002] Homomorphic encryption is a type of encryption method with a unique property: the decrypted data obtained after homomorphic encryption is processed is identical to the original, unencrypted data processed using the same method. Homomorphic encryption not only provides security but also ensures the availability of encrypted data to a certain extent.
[0003] Private set intersection is a technique that allows two or more parties to securely compute the intersection of their datasets without disclosing the non-intersecting elements in their respective sets. Its core goal is to enable cross-institutional collaboration while protecting data privacy. It is currently widely used in fields such as financial risk management, advertising analysis, and medical research. In the case of calculating the union of sets, participants only know the data shared by all individuals; no additional information is disclosed.
[0004] Combining the threshold concept with homomorphic encryption technology, participants can securely access aggregate information that meets threshold conditions. This means that data shared by some participants is not necessarily shared by all. For example, in a voting scenario, each voter independently controls their voting information. After voting, they hope to obtain a final voting result that exceeds a certain percentage and perform relevant statistical calculations based on the voting results. This percentage can be considered a threshold condition. Furthermore, to protect each participant's voting information, no participant wants their private voting information to be known by others.
[0005] Existing methods for computing the intersection of thresholded multi-party private sets have several problems: 1. The client's local computational effort is high, placing high demands on device hardware; 2. Private data protection is weak, often leaking relationships between values during calculations or comparisons; 3. The computational reasoning process is inefficient, often requiring multiple rounds of communication between the client and server, resulting in high computational time and communication overhead. These issues need to be addressed through continuous algorithm refinement, enhanced data protection, and optimized computational efficiency. Summary of the Invention
[0006] In order to solve the above problems, the present invention proposes a method for calculating the intersection of threshold multi-party private sets based on secure comparison. By adopting homomorphic encryption technology and a secure comparison protocol based on it, the method completes the statistical calculation of set operations and related data in multi-party scenarios without leaking any private information of the participants except the results. It improves the computing efficiency and data privacy protection level, reduces the risk of personal privacy leakage, and provides a higher degree of privacy protection. It has high application flexibility and can adapt to the needs of different application scenarios.
[0007] To achieve the above objectives, the present invention provides a technical solution: a method for calculating the intersection of threshold multi-party private sets based on secure comparison, which is applied to two cloud servers (CP and CSP) that provide powerful computing power and store encrypted data, and multiple clients that perform threshold private set intersection calculations, and includes the following steps:
[0008] Step 1. The task requester initializes the PaillierTD cryptographic system and generates a key pair (pk, sk), where pk is the public key and sk is the private key. The private key sk is then divided into two parts, denoted as partial private keys sk1 and sk2. The partial private keys sk1 and sk2 meet the following requirements: sk1+sk2≡0 (mod sk), sk1+sk2≡1 (mod N), and a set of keys (pk, sk1, sk2) is obtained by solving the Chinese remainder theorem. Only the split partial private keys sk1 or sk2 cannot completely decrypt the data encrypted with the public key pk. Then sk1 and sk2 are sent to the cloud servers SP and CSP respectively, and the public key pk is made public to all task participants;
[0009] Step 2: Each task participant locally computes the Bloom filter BF of the client's private data set, which contains parameters m and k, indicating that the Bloom filter bit array length is m bits and that k independent hash functions are used to map each element in each task participant's private set into the bit array. Then, the encrypted Bloom filter EBF is obtained using the Paillier cryptosystem with threshold decryption. Finally, each task participant sends its own encrypted Bloom filter EBFi to the CP.
[0010] Step 3. For each element of the local private set, CP calculates k corresponding hash values based on the selected k hash functions, and then uses these hash values as indexes to retrieve the encrypted values in the Bloom filter of each client. For each client, CP independently and homomorphically sums the obtained encrypted values, and then uses the Paillier cryptographic system with threshold decryption to perform a secure comparison operation with the cloud server CSP to ensure that no information is leaked during the comparison process. The values for the comparison operation are the homomorphic sum of the encrypted values obtained from the Paillier encryption and the Bloom filter. The comparison results will be stored in CP;
[0011] Step 4: After obtaining the comparison result, the CP knows whether each element yj in its private set appears in each client. In order to obtain a set that meets the threshold condition, the CP continues to homomorphically sum the values of whether each element yj appears in each client set;
[0012] In step 5, the CP and CSP perform interactive calculations to securely compare the number of element occurrences against the threshold condition. This comparison is also performed on the Paillier ciphertext space used for threshold decryption. Finally, the CP decrypts the set of elements whose number of occurrences is greater than or equal to the threshold condition and returns the resulting set to each task participant.
[0013] Furthermore, in step 1, the key generation process of the PaillierTD threshold cryptosystem is as follows: First, two large prime numbers p' and q' need to be found. They have Len bits in binary representation. The longer the Len is, the more difficult it is to crack, which means the security factor is higher. Then, the mask values p = 2p' + 1 and q = 2q' + 1 are calculated to hide the true values of p and q, and the Paillier modulus N = p·q and the generator g = N+1, as well as λ = lcm(p-1,q-1), are calculated. Among them, lcm() represents the least common multiple, and the inverse of the least common multiple of p-1 and q-1 to N is calculated as μ = λ. -1 mod N, set and publish the public key pk = (g, N) and private key sk = λ of the PaillierTD cryptosystem.
[0014] Furthermore, in step 1, the PaillierTD cryptosystem splits the private key λ into two partial private keys sk1 and sk2, which satisfy the following requirements: sk1 + sk2 ≡ 0 (mod sk) and sk1 + sk2 ≡ 1 (mod N). The specific generation process is as follows: Based on the operational properties of congruence equations, the above two equations are multiplied to obtain the characteristic equation δ = sk1 + sk2 = sk·μ mod (sk·N). Then, according to the Chinese Remainder Theorem, δ ≡ 0 (mod sk) and δ ≡ 1 (mod N) are required to simultaneously hold. Then, sk1 is set to a σ-bit random positive integer R, that is, sk1 = R. The Chinese Remainder Theorem shows that sk2 = sk·μ + η·sk·N - sk1, where η is a non-negative integer.
[0015] Further, in step 2, the server CP generates k random hash functions using MurmurHash and sends them to each participant. i , P i First, calculate your own Bloom filter BF locally. Specifically, when adding any element x in the data set, use k hash functions to obtain k hash values, and then set the corresponding bit in the Bloom filter bit array to 1, that is, the position h mapped by the i-th hash function d (x) will be set to 1 (1≤i≤k). If a position is set to 1 multiple times, only the first time will take effect, and the subsequent times will have no effect. Then use the server's public key pk to encrypt each element of the bit array BF i [j], get the encrypted Bloom filter EBF i Finally, each client calculates the EBF locally i Sent to the server CP.
[0016] Furthermore, in step 3, the server CP uses a randomly selected hash function for each server set element Calculate k hash values. Then use these hash values as indices to extract the element on the i-th client P i The encrypted value in the encrypted Bloom filter is ,in , , is the size of the server set, and d represents the dth hash function. Then the extracted encrypted value is homomorphically summed in the Paillier ciphertext space, and the result is re-randomized to obtain ,in ReRand is a re-randomization function, which is implemented by adding an encrypted zero value to the ciphertext. Indicates that this ciphertext is the jth element on the server side about the i-th client. According to the principle of Bloom filter, if the server side element Belongs to client P i , then the ciphertext The corresponding plaintext must be k. The k hash values of the index in the encrypted Bloom filter of the client are all 1 in the ciphertext state, and the k in the ciphertext state can be obtained by homomorphic summation. By performing a security comparison with k in the Paillier ciphertext space, it can be determined whether the server element appears in the client.
[0017] Furthermore, in step 3, the specific implementation of the secure comparison operation SCMP based on PaillierTD used by the cloud server CP and CSP for interactive calculation is as follows: First, CP generates a random number π, which takes a value of 0 or 1; the original comparison data is masked by calculating the difference D between the two numbers r1 and r2; if π = 0, then D = r1-r2, otherwise D = r2-r1; the difference D calculated by the secure comparison is partially decrypted using the partial private key sk1 to obtain the decryption result D1, and CP sends (D, D1) to CSP; second, CSP uses sk2 to partially decrypt D to obtain D2, and uses the partial decryption results D1 and D2 to perform the final decryption to obtain the plaintext of D d = D1*D2 mod N2, and compares d with N / 2. If d>N / 2, then d = 1, otherwise d = 0, and returns it to CP; third, the comparison result is calculated. If the return value of SCMP is an encrypted 1, then the encrypted value of the Bloom filter obtained is greater than or equal to k, indicating that the server element appears in the corresponding client set. Otherwise, an encrypted 0 will be returned.
[0018] Further, in step 4, the server CP sends each server element y j Whether the values appearing in each client set are homomorphically summed. The specific operation of homomorphic summation is modular multiplication, which is to multiply the ciphertext and then square the Paillier modulus N. 2 Modulo. Repeat the homomorphic summation until you get the sum of the number of times each server element appears in the client set.
[0019] Furthermore, in step 5, the server CP and the CSP continue to perform interactive calculations to complete the secure comparison SCMP, comparing the encrypted server element occurrence count sum and the encrypted threshold condition T. Based on the comparison result, the CP decrypts the obtained set of elements that satisfy the threshold condition T and returns the generated set to each task participant.
[0020] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0021] The present invention proposes a secure calculation method for finding the intersection of multiple private sets that combines thresholds with secure comparisons. By using two non-colluding cloud servers for auxiliary calculations, the computing and storage resource consumption of the participating entities is reduced, while avoiding the communication overhead caused by multiple rounds of communication between the server and the client in the existing technical solutions. The present invention successfully allows multiple participants to use their own private data for calculations to obtain set intersection information that meets the threshold condition, and will not disclose any private information of the participants except the results, thereby protecting the privacy of the participants in the multi-party scenario. Specifically, the method of the present invention adopts full ciphertext data transmission and calculations, and realizes secure comparison and secure calculation of private sets through the homomorphism of PaillierTD.
[0022] Advantages of additional aspects of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0024] Figure 1 This is a flow chart of the method for calculating the intersection of threshold multi-party privacy sets based on security comparison provided by the present invention.
[0025] Figure 2 Schematic diagram of the framework of the method for calculating the intersection of threshold multi-party privacy sets based on security comparison provided by the present invention. DETAILED DESCRIPTION
[0026] The present invention will be described in further detail below with reference to the following examples and accompanying drawings, but the embodiments of the present invention are not limited thereto. It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for calculation and analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of the relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.
[0027] like Figure 1 and Figure 2As shown, this embodiment provides a method for calculating the intersection of multiple private sets with a threshold value based on secure comparison. This method uses a Bloom filter to represent and encrypt set elements locally on the user's computer. The intersection of the private sets is then calculated and compared on the cloud through data outsourcing. The threshold comparison results are then obtained and the set calculation results are returned. This method involves two cloud servers (CP and CSP) that provide powerful computing power and store encrypted data, and multiple client devices that perform private set calculations. To facilitate understanding of the implementation of the technical solution, this embodiment uses specific data for demonstration.
[0028] Step 1: Initialize the PaillierTD cryptosystem to generate a PaillierTD key pair (pk, sk), select p = 2293860749, q = 3276141289, and calculate n = 7515011911015365461. Where pk=(7515011911015365461,7515011911015365462), sk=7515011905445363424; split the private key sk into partial private key sk1=14899335598462580858082299688271082824 and partial private key sk2=21095095585612241498107814197332700952, send partial private key sk1 to CP and partial private key sk2 to CSP respectively, and send the public key pk to each client that performs the intersection calculation of the privacy sets.
[0029] Step 2: In this embodiment, client C1 owns the set {1, 3, 5, 7}, client C2 owns the set {2, 3, 4, 5}, and server CP owns the set {6, 5, 2, 1}. The Bloom filter's bit array length is m = 16 bits, and k = 4 independent hash functions are used to map each element in each client's private set into the bit array. The unencrypted Bloom filter constructed by client C1 for its own set is {0,0,1,1,1,1,0,0,1,1,1,1,1,1,1,0}. After encrypting each element with pk, the encrypted Bloom filter is {6049992256097850418755033020613428793622731385237136373306733185775656293567407005720209002177286078709274335433 647769962748880444151141505121,6518007646501971481372430886460043506721234007313523747495049589789123814837102505423991310004218945740668175306219049927409167636588151376583,288640102700338617498068847 3767048437568418627393462687568618325851013520622595276862755524174960109535420686800433319205303286838379041120803,2717982632316266743374112505337349249017327206710413210007250671147857671200901661237 557420520665204505686553317438470838424597108564937935434,2893142307793627257315391626484839610347183872023189461134565097289778749781759967717603566684940065203202966656555027545308733004169842555710,2485612618546533794212990878685051169451891232887321264435856311245916644996862664338135899349536576972192116395617509947820795499939467025639,2249201157741507037594617077472101325680854555084782156339028502282396631941530671870761030399418568824108584099835895909042873398263399810522,3067133103885268371491460183004500141328890242657390727080480671580799106035285036511727909105477583486714777188536936196094324325399085287304,6611214259305554343884452154406204443261634837686314979994802936180689101453275125164224971030107428299707886754245808216949181230350285387774,1075787286480535611982854119686366705810622267831182544303552431378399237562922434622820989087306403978136137069315204435391371948454403159445,1438003666758128261608179981025461299094914529606353576057896752994971877687253016684032902277798674141082511094224255887741990425202652639268,6282160574751259805429022728927847213999982986383167090588889989013890206235851202349028463610323378406731675033505681979347549269355650834885,7884878288604266854898357767548273740628549123806948508776072534720208608568630213790383490193989976174535110539269876178546046981135683543382,4755312788779086734451388484627551704418413329647578786919515824057365944953728432788643 823620950201258331562826789992922728493163375981203299,3637362690662199943998777841487866209832039127044012297004203446930836177886083687224167248622979673068197842074677170725529540836880154816286,4522510861310104702074447426127173 502857056319757709867704295681762812917895219768750614253602280065664748270361324952921745388339451029509105}; the unencrypted Bloom filter constructed by client C2 for its own set is {0,1,1,1,1,1,0,0,1,0,1,1,1,0,1,0}, which becomes {563693189616910807544867600538947952351666863183418726 3202273289287472877109644863823932081156055469746569712145843476094949847560392425702792,5249860600981008093650748931370606483589615638265780708408353485402480204271028020365142727471660471784048838589435435202017956185212538687035,2633967235941292732658193819137784960930741137598645175601074758065824362211850748485420328866873874303531795532333233458732555358806682440201,7581398555215291730906710343901540928181151871415034798992557036095748412334500638776287286996744578560480115450695262596360346816068422512970,5946724138515992124432978362051130537000923124663876828258868536297821963435033214941294656692412958154892301742609211236646341177595781803164,2337859774405094790112919289728840907043057833338030565914924781952902147841538158614387073842198407557842425451292758247862608238653081774578,3140850364602305601402794350734754430769611793114463952189719630980855477821380361038366664491603393572599430375279615970355182738065680235077,5599374887753225450528837476420824237548742257348000511878925159719820194117768337784921882247420085275951226940517063063296770094729287894189,3201461338082684014209747241895838981307418121262181172665050210831668187401310328328079189469352986850968359127192905262348478277685585253639,6660839338222364905109009723475971499683631682271912099399785089321389828584886102874208003424743339058431633973832110752336533453004837050922,8027814546167102147845324645545670789277284550434209117563737079393071217891078568433065960113709115230459564598235177590319011423925950620968,7615402491456534737857723502663632068813795453446357819910136331750045318207062141061277435528473754179401524533899006299229014432854185207887,7373962466275699811291023755374413559581540099496486744188396867713598306416200817141697735792844367195422800588603585731514510953603079282465,5145780366467156223016075323967745847830211336250815173166645311964133222971182747411240036113780218923370990546214761724607240603218013727311,3098858385444390276801867372874200226343770463599236903122282047229747950715907944792252448066644003008837516041111417134821265166751885168656,After completing the local encryption, the two clients send their encrypted Bloom filters to the server CP.
[0030]
[0031] Step 4: The server CP continues to homomorphically sum the comparison results of each element to obtain the elements that meet the threshold condition. The sum of the comparison results of element 6 is 6957615710466611639544410185394344323805551196114185479339085525033228686070249476311247457768385120413027785560332437239424810517985180751977. The sum of the comparison results of element 5 is 2312082282195293285989518480063546182918951657418595832088077725534998903648609420877977418925338830870826226749142955789658866790993879024816; The sum of the comparison results of element 2 is 4197271794442125932573122368914117262319926410088847952820167472885214227641776636225421974604015119569788608725491394603106029882722070993232; The sum of the comparison results for element 1 is 3877426247612791664354503898672714225387505624886054756243914695559168437576888068925129014051724154232144927492620296549023733006280898176219.
[0032] Step 5. CP and CSP perform interactive calculations to complete further security comparisons. The sum of the comparison results of element 6 and the threshold T is 3753436437211603211344113263491585724055539556681127072827433088400166718248821781270305990097519513915851765534939025107406297578526346751210. The result is decrypted to obtain The value is 0, indicating that the number of occurrences of element 6 does not meet the threshold condition; the comparison result of the sum of the comparison results of element 5 and the threshold T is 2116647278136293182410918194167948807344728121854898844663625905692358287389323990419197568611704554688818786050570637223163919905650503860199, and the result is decrypted to get the value 1, indicating that The number of occurrences of element 5 meets the threshold condition; the comparison result of the sum of the comparison results of element 2 and the threshold T is 7009870476559983189977849967967988049352936855886697308415911179730438180336063302930073477413043237942918064956031638572477420995309611894734, and the result is decrypted to get the value 1, indicating that the number of occurrences of element 2 is 1. The sum of the comparison results for element 1 and the threshold T is 5749373953891765978316255449433602678411006237149203844893887433815690642413135890438119145503601597405555654158859435091515622059514419225976. Decrypting the result yields the value 1, indicating that the number of occurrences of element 1 meets the threshold. In summary, the CP obtains the set of elements that meet the threshold as {5, 2, 1} and returns the set to each client.
[0033] The above embodiments are preferred implementation modes of the present invention, but the implementation modes of the present invention are not limited to the above embodiments. Any other changes, modifications, substitutions, combinations, and simplifications that do not deviate from the spirit and principles of the present invention should be considered as equivalent replacement methods and are included in the scope of protection of the present invention.
Claims
1. A method for calculating the intersection of threshold multi-party privacy sets based on security comparison, including a task requester, two cloud servers (CP and CSP) that provide powerful computing power and store encrypted data, and multiple task participants; characterized by: The task requester creates a task to calculate the intersection of multi-party privacy sets under a threshold condition and sends it to the cloud server CP. The server calls the security comparison protocol based on the calculation task, the local private element space, and the private element space of each task participant, calculates whether each server element appears in the set of each task participant, and counts the cumulative number of occurrences. It then performs a security comparison with the threshold condition of the calculation task, and finally obtains the set of server elements that meet the condition that the number of occurrences is greater than or equal to the threshold condition. In order to protect the privacy of the private data of the calculation task and task participants, the task requester and task participants use the Paillier cryptographic system with threshold decryption to protect their respective private data information and send it to the cloud server CP. The cloud server CP and CSP jointly execute the security comparison protocol to ensure that all operations on private data are performed in the ciphertext space, and complete the calculation of the threshold multi-party set intersection without leaking private data.
2. The method for calculating the intersection of threshold multi-party privacy sets based on secure comparison according to claim 1, characterized in that: The following steps are involved: Step 1. The task requester initializes the PaillierTD cryptosystem and generates a key pair (pk, sk), where pk is the public key and sk is the private key. The private key sk is then split into two parts, denoted as partial private keys sk1 and sk2, which meet the following requirements: sk1+sk2≡0 (mod sk), sk1+sk2≡1 (mod N). The Chinese remainder theorem is used to solve the problem and obtain a pair of keys (pk, sk1, sk2). Only the split partial private keys sk1 or sk2 cannot completely decrypt the data encrypted with the public key pk. sk1 and sk2 are then sent to the cloud servers SP and CSP, respectively, and the public key pk is made public to all task participants. Step 2: Each task participant calculates the Bloom filter BF of the client's private data set locally, which contains parameters m and k, indicating that the length of the Bloom filter bit array is m bits, and uses k independent hash functions to map each element in each task participant's private set to the bit array; then, the Paillier cryptosystem with threshold decryption is used to encrypt the data to obtain the encrypted Bloom filter EBF. Finally, each task participant uses its own encrypted Bloom filter EBF i Issued to CP; Step 3: For each element of the local private set, the CP calculates k corresponding hash values based on the k selected hash functions. Using these hash values as indexes, the CP retrieves the encrypted values from each client's Bloom filter. For each client, the CP independently and homomorphically sums the obtained encrypted values. Then, the CP uses the Paillier cryptosystem with threshold decryption to perform a secure comparison operation with the cloud server CSP, ensuring that no information is leaked during the comparison process. The comparison operation values are the homomorphic sum of the Paillier-encrypted k and the encrypted value obtained from the Bloom filter. The comparison results are stored in the CP. Step 4: After getting the comparison result, CP knows each element y in its private set j In order to obtain a set that satisfies the threshold condition, CP continues to convert each element y j Whether the values appearing in each client set are summed homomorphically; Step 5: The CP and CSP perform interactive calculations to complete a secure comparison of the number of element occurrences and the threshold condition. The comparison is also performed on the Paillier ciphertext space of the threshold decryption. Finally, the CP decrypts the set of elements that meet the threshold condition and the number of occurrences greater than or equal to the threshold condition, and returns the generated set to each task participant.
3. The method for calculating the intersection of threshold multi-party privacy sets based on secure comparison according to claim 2, characterized in that: In step 1, the key generation process of the PaillierTD threshold cryptosystem is as follows: first, two large prime numbers p' and q' need to be found. They have Len bits in binary representation. The longer the Len is, the more difficult it is to crack, which means the higher the security factor is. Then, the mask values p = 2p' + 1 and q = 2q' + 1 are calculated to hide the true values of p and q. The Paillier modulus N = p·q and the generator g = N+1, as well as λ = lcm(p-1,q-1), are calculated. Where lcm() represents the least common multiple, and the inverse μ = λ of the least common multiple of p-1 and q-1 to N is calculated. -1 mod N, set and publish the public key pk = (g, N) and private key sk = λ of the PaillierTD cryptosystem.
4. The method for calculating the intersection of threshold multi-party privacy sets based on secure comparison according to claim 3, characterized in that: In step 1, the PaillierTD cryptosystem divides the private key λ into two partial private keys sk1 and sk2, which satisfy the following requirements: sk1+sk2≡0(mod sk), sk1+sk2≡1(mod N); the specific generation process is: according to the operational properties of congruence equations, multiplying the above two equations to obtain the characteristic equation δ=sk1+sk2=sk·μ mod (sk·N), and then according to the Chinese remainder theorem, it is required that δ≡0(mod sk) and δ≡1(mod N) hold simultaneously, and then sk1 is set to a σ-bit random positive integer R, that is, sk1=R. According to the Chinese remainder theorem, sk2=sk·μ+η·sk·N-sk1 can be obtained, where η is a non-negative integer.
5. The method for calculating the intersection of threshold multi-party privacy sets based on secure comparison according to claim 4, characterized in that: In step 2, the server CP uses MurmurHash to generate k random hash functions and sends them to each participant; for the i-th participant P i , P i First, calculate your own Bloom filter BF locally. Specifically, when adding any element x in the data set, use k hash functions to obtain k hash values, and then set the corresponding bit in the Bloom filter bit array to 1, that is, the position h mapped by the i-th hash function d (x) will be set to 1 (1≤i≤k); if a position is set to 1 multiple times, only the first time will work, and the subsequent times will have no effect. Then use the server's public key pk to encrypt each element of the bit array BF i [j], get the encrypted Bloom filter EBF i Finally, each client will calculate the EBF locally i Sent to the server CP.
6. The method for calculating the intersection of threshold multi-party private sets based on secure comparison according to claim 5, characterized in that: In step 3, the server CP uses a randomly selected hash function for each server set element Calculate k hash values; then use these hash values as indices to extract the element on the i-th client P i The encrypted value in the encrypted Bloom filter is ,in , , is the size of the server set, d represents the dth hash function; then the extracted encrypted value is homomorphically summed in the Paillier ciphertext space, and the result is re-randomized to obtain ,in ReRand is a re-randomization function, which is implemented by adding an encrypted zero value to the ciphertext. Indicates that this ciphertext is the jth element on the server side about the i-th client; according to the principle of Bloom filter, if the server side element Belongs to client P i , then the ciphertext The corresponding plaintext must be k; because The k hash values of the index in the encrypted Bloom filter of the client are all 1 in the ciphertext state, and the k in the ciphertext state can be obtained by homomorphic summation. Therefore, it is only necessary to By performing a security comparison with k in the Paillier ciphertext space, it can be determined whether the server element appears in the client.
7. The method for calculating the intersection of threshold multi-party privacy sets based on secure comparison according to claim 6, characterized in that: In step 3, the specific implementation of the secure comparison operation SCMP based on PaillierTD used by the cloud server CP and CSP for interactive calculation is as follows: First, CP generates a random number π, which takes the value of 0 or 1; the original comparison data is masked by calculating the difference D between the two numbers r1 and r2; if π = 0, then D = r1-r2, otherwise D = r2-r1; the difference D calculated by the secure comparison is partially decrypted using the partial private key sk1 to obtain the decryption result D1, and CP sends (D, D1) to CSP; second, CSP uses sk2 to partially decrypt D to obtain D2, and uses the partial decryption results D1 and D2 to perform the final decryption to obtain the plaintext of D d = D1*D2 mod N2, and compares d with N / 2. If d>N / 2, then d = 1, otherwise d = 0, and returns it to CP; third, the comparison result is calculated. ; If the return value of SCMP is an encrypted 1, then the obtained Bloom filter encrypted value is greater than or equal to k, indicating that this server element appears in the corresponding client set, otherwise an encrypted 0 will be returned.
8. The method for calculating the intersection of threshold multi-party privacy sets based on secure comparison according to claim 7, characterized in that: In step 4, the server CP sends each server element y j Whether the values appearing in each client set are homomorphically summed. The specific operation of homomorphic summation is modular multiplication, which is to multiply the ciphertext and then square the Paillier modulus N. 2 Modulo; then repeat the homomorphic summation until the sum of the number of times each server element appears in the client set is obtained.
9. The method for calculating the intersection of threshold multi-party privacy sets based on secure comparison according to claim 8, characterized in that: In step 5, the server CP and CSP continue to perform interactive calculations to complete the security comparison SCMP, where the comparison objects are the encrypted server element occurrence count sum and the encrypted threshold condition T; The CP decrypts the comparison result to obtain a set of elements that meet the condition that the number of occurrences is greater than or equal to the threshold condition T, and returns the generated set to each task participant.
Citation Information
Cited By
Fast threshold multi-party privacy set intersection method
CN121173469A