Privacy intersection method and device, electronic equipment and storage medium

By using pre-defined elliptic curve base points and parameter factors to process the data of the participants, and employing base point multiplication, the large computational load in existing technologies is solved, thus improving the universality and accuracy of the method.

CN121098524APending Publication Date: 2025-12-09JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410733228.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-06-06
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Existing privacy-preserving intersection methods involve computationally intensive elliptic curve mapping, poor universality, and low accuracy. In particular, differences exist between different elliptic curve types, leading to incorrect determination of intersection data.

Method used

By using pre-defined elliptic curve base points and parameter factors to process the participants' data, the base point multiplication operation is used to map the data onto the elliptic curve, and the parameter factors are determined through random factor bit operations to avoid the influence of auxiliary factors and ensure that the data is mapped in the same elliptic curve point group.

Benefits of technology

This reduces the computational load in the privacy intersection process, improves the universality and accuracy of the method, and enhances the efficiency and accuracy of the privacy intersection process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098524A_ABST
    Figure CN121098524A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a privacy intersection method and device, electronic equipment and a storage medium. The method comprises the following steps: receiving first privacy intersection data sent by a first participant; receiving second to-be-privately-exchanged data fed back by the first participant; processing the second to-be-used privacy intersection data based on the second parameter factor to obtain to-be-used privacy intersection data corresponding to the current participant; and based on the first privacy intersection data and the to-be-used privacy intersection data, determining target common data shared by the current participant and the first participant. According to the technical scheme, the problems of complicated data operation process, poor universality and low accuracy of the privacy intersection method based on the elliptic curve are solved, the data operation amount of privacy intersection is reduced, the universality of the privacy intersection method based on the elliptic curve is enhanced, and the privacy intersection efficiency and accuracy are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and storage medium for privacy intersection. Background Technology

[0002] Privacy intersection, also known as privacy set intersection, allows multiple participants to calculate the intersection set among themselves without revealing any information beyond the intersection itself. A commonly used privacy intersection method involves determining the hash values ​​corresponding to all intersection data, mapping these hash values ​​to an elliptic curve to obtain transformed intersection data, and then performing privacy intersection on these transformed intersection data.

[0003] When implementing this technical solution based on the above method, the inventors discovered the following problems:

[0004] The aforementioned privacy-preserving intersection methods, when mapping intersection data onto elliptic curves, can utilize various types of elliptic curves. Regardless of the type of elliptic curve used, the process of mapping intersection data onto an elliptic curve involves complex data operations and a large computational load. Moreover, the computational load varies significantly depending on the type of elliptic curve, resulting in poor universality of privacy-preserving intersection methods based on elliptic curves. Furthermore, since the order of the elliptic curve point group is finite, while the amount of intersection data may exceed the order of the elliptic curve point group, different intersection data may map to the same points on the elliptic curve. This can lead to non-intersecting data being incorrectly identified as intersecting data, resulting in low accuracy of privacy-preserving intersection methods. Summary of the Invention

[0005] This invention provides a method, apparatus, electronic device, and storage medium for privacy intersection, which reduces the amount of data computation required for privacy intersection, enhances the universality of privacy intersection methods based on elliptic curves, and improves the efficiency and accuracy of privacy intersection.

[0006] Improve the universality of privacy-preserving intersection methods based on elliptic curves, optimize the data computation process in privacy-preserving intersection, reduce the time consumption of privacy-preserving intersection, and improve the efficiency of privacy-preserving intersection.

[0007] In a first aspect, embodiments of the present invention provide a privacy-preserving intersection method, the method comprising:

[0008] Receive first privacy intersection data sent by the first participant, wherein the first privacy intersection data is data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point, and the first data to be intersected is obtained after processing the data corresponding to the first participant using a first parameter factor;

[0009] Receive the second privacy-requesting data fed back by the first participant, wherein the second privacy-requesting data corresponds to the current participant, and the second privacy-requesting data is the data obtained by the first participant after processing the second privacy-requesting data sent by the current participant using the first parameter factor;

[0010] The second privacy-defining intersection data is processed based on the second parameter factor to obtain privacy-defining intersection data corresponding to the current participant; wherein, the second participation factor corresponds to the current participant;

[0011] Based on the first privacy intersection data and the privacy intersection data to be used, the target shared data shared by the current participant and the first participant is determined.

[0012] Furthermore, the method further includes: determining privacy intersection data corresponding to the participating parties, wherein the participating parties include a first participating party and / or the current participating party, and the privacy intersection data includes first privacy intersection data corresponding to the first participating party and / or second privacy intersection data corresponding to the current participating party;

[0013] Furthermore, the method also includes:

[0014] The unprocessed data owned by the participating parties is hashed to obtain the hash value of the unprocessed data;

[0015] Based on the parameter factors corresponding to the participants and the predetermined elliptic curve base points, the hash value of the data to be processed is processed to obtain the data to be extracted corresponding to the data to be processed; wherein, the elliptic curve base points corresponding to the current participant and the first participant are the same;

[0016] The data to be extracted is processed according to a pre-set extraction method to obtain the privacy intersection data.

[0017] Furthermore, the method also includes:

[0018] Determine the random factor corresponding to the participating party;

[0019] By performing bitwise operations on the random factor, the parameter factor corresponding to the participating party is determined.

[0020] Furthermore, the data to be extracted includes horizontal and vertical coordinates corresponding to the data to be processed, and the method further includes:

[0021] The data to be extracted includes horizontal and vertical coordinates corresponding to the data to be processed. The extraction and processing of the data to be extracted according to a pre-set extraction method to obtain the privacy intersection data includes:

[0022] Based on the elliptic curve processing method corresponding to the base point of the elliptic curve, the horizontal or vertical coordinates of the data to be extracted are obtained to obtain the privacy intersection data.

[0023] Furthermore, the method also includes:

[0024] The first participant compresses the first privacy intersection data using a preset compression method to update the first privacy intersection data.

[0025] Furthermore, the method also includes:

[0026] The second privacy intersection data is sent to the first participant, so that the first participant processes the second privacy intersection data using the first parameter factor and the elliptic curve base point to obtain the second privacy intersection data, and then feeds it back.

[0027] Furthermore, the method also includes:

[0028] Based on the elliptic curve base points, the second privacy intersection data is recovered to obtain data to be processed again.

[0029] The data to be processed again is processed based on the first parameter factor to obtain the data to be applied;

[0030] Extract data from the data to be applied to obtain the second privacy-sensitive intersection data.

[0031] Furthermore, the method also includes:

[0032] After the second privacy-defining intersection data is restored, the second parameter factor is used to process the restored second privacy-defining intersection data to obtain privacy-defining intersection data to be used.

[0033] Furthermore, the method also includes:

[0034] If the first privacy intersection data contains data identical to the privacy intersection data to be used, then the privacy intersection data to be used is determined to be data from the target shared data; or,

[0035] If the privacy intersection data to be used contains data that is identical to the first privacy intersection data, then the privacy intersection data to be used is determined to be data in the target shared data.

[0036] Furthermore, the method also includes: the amount of data in the privacy intersection of the first participant is greater than the amount of data in the privacy intersection of the current participant.

[0037] Secondly, embodiments of the present invention also provide a privacy intersection apparatus, the apparatus comprising:

[0038] The first data receiving module is used to receive the first privacy intersection data sent by the first participant, wherein the first privacy intersection data is the data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point, and the first data to be intersected is obtained after processing the data corresponding to the first participant using a first parameter factor.

[0039] The second data receiving module is used to receive the second privacy-defining intersection data fed back by the first participant, wherein the second privacy-defining intersection data corresponds to the current participant, and the second privacy-defining intersection data is the data obtained by the first participant after processing the second privacy-defining intersection data sent by the current participant using the first parameter factor;

[0040] The data to be used determination module is used to process the second privacy intersection data based on the second parameter factor to obtain the privacy intersection data to be used corresponding to the current participant; wherein, the second participation factor corresponds to the current participant;

[0041] The shared data determination module is used to determine the target shared data shared by the current participant and the first participant based on the first privacy intersection data and the privacy intersection data to be used.

[0042] Thirdly, embodiments of the present invention also provide an electronic device, the electronic device comprising:

[0043] One or more processors;

[0044] Storage device for storing one or more programs.

[0045] When one or more programs are executed by one or more processors, the one or more processors implement a privacy intersection method as described in any of the embodiments of the present invention.

[0046] Fourthly, embodiments of the present invention also provide a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform a privacy intersection method as described in any of the embodiments of the present invention.

[0047] The technical solution of this invention involves processing the original data held by the first participant using a first parameter factor and a pre-set elliptic curve base point to obtain first privacy intersection data; processing the original data held by the current participant using a second parameter factor and a pre-set elliptic curve base point to obtain second privacy intersection data; when determining the target shared data between the first participant and the current participant, the current participant receives the first privacy intersection data sent by the first participant, and the second privacy intersection data to be processed based on the first parameter factor and fed back by the first participant; furthermore, the second privacy intersection data to be processed based on the second parameter factor is used to obtain privacy intersection data to be used corresponding to the current participant; thus, based on the first privacy intersection data and the privacy intersection data to be used, the target shared data between the current participant and the first participant is determined. This scheme maps the data onto an elliptic curve by performing dot product operations on the original data after parameter factoring using pre-defined elliptic curve base points. Since the dot product operation is relatively simple, it significantly reduces the amount of data computation, decreases the time consumed in the privacy intersection process, and improves the efficiency of privacy intersection. Furthermore, the amount of data computation does not differ significantly for different types of elliptic curves, thus improving the universality of the privacy intersection method based on elliptic curves. In addition, the parameter factors used in this scheme are determined by bitwise operations on random factors using auxiliary factors, avoiding the influence of auxiliary factors in the elliptic curve. This maps all the original data after parameter factoring to the same elliptic curve point group (and a large prime point group without auxiliary factors), ensuring that different original data are mapped to different points on the elliptic curve. This avoids the problem of incorrectly identifying non-intersecting data as intersecting data, improving the accuracy of privacy intersection.

[0048] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0049] To more clearly illustrate the technical solutions of exemplary embodiments of the present invention, the accompanying drawings used in describing the embodiments are briefly introduced below. Obviously, the accompanying drawings described are only a portion of the drawings of the embodiments to be described in this invention, and not all of the drawings. For those skilled in the art, other drawings can be obtained from these drawings without any creative effort.

[0050] Figure 1 This is a flowchart illustrating a privacy-preserving intersection method provided in an embodiment of the present invention.

[0051] Figure 2This is a schematic diagram of a classic elliptic curve shape provided in an embodiment of the present invention;

[0052] Figure 3 This is a flowchart illustrating another privacy-preserving intersection method provided in an embodiment of the present invention;

[0053] Figure 4 This is a schematic diagram illustrating the implementation steps for determining the first privacy intersection data according to an embodiment of the present invention;

[0054] Figure 5 This is a schematic diagram illustrating the implementation steps for determining the second privacy intersection data according to an embodiment of the present invention;

[0055] Figure 6 This is a schematic diagram of another privacy-preserving intersection method provided in an embodiment of the present invention;

[0056] Figure 7 This is a schematic diagram illustrating the data processing procedure for determining the second privacy-sensitive data to be submitted by the first participating party in an embodiment of the present invention.

[0057] Figure 8 This is a schematic diagram illustrating the data processing procedure for determining the privacy-sensitive intersection data to be used by the current participants in an embodiment of the present invention.

[0058] Figure 9 This refers to the data flow process for determining shared target data as described in the embodiments of the present invention.

[0059] Figure 10 A schematic diagram of a privacy intersection apparatus provided in an embodiment of the present invention;

[0060] Figure 11 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0061] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the drawings, not the entire structure.

[0062] Before introducing this technical solution, the application scenario can be explained first. The technical solution provided in this embodiment of the invention can be applied to scenarios in which multiple parties participate in privacy intersection. Privacy intersection refers to obtaining the intersection of the data held by multiple parties without disclosing any additional information. Here, additional information refers to any information other than the data intersection of the participating parties. This embodiment uses two parties as an example for explanation, such as the first party and the current party. For example, the data held by the first participant and the current participant are user data corresponding to their respective business domains. The first participant processes its original data using a first factor and a pre-set elliptic curve base point to obtain first privacy intersection data. The current participant processes its original data using a second factor and a pre-set elliptic curve base point to obtain second privacy intersection data, and sends the second privacy intersection data to the first participant. The first participant processes the received second privacy intersection data based on the first parameter factor to obtain second privacy intersection data to be intersected, and feeds it back to the current participant. Subsequently, the current participant receives the second privacy intersection data to be intersected, processes it based on the second parameter factor, and obtains privacy intersection data to be used corresponding to the current participant. Thus, by querying data that is consistent between the first privacy intersection data and the privacy intersection data to be used, the target shared data between the current participant and the first participant is determined. In practical applications, there can be multiple first participants.

[0063] Figure 1 This is a flowchart illustrating a privacy intersection method provided in an embodiment of the present invention. This embodiment is applicable to situations where multiple parties participate in privacy intersection. The method can be executed by a privacy intersection device, which can be implemented in the form of software and / or hardware. The hardware can be an electronic device, such as a mobile terminal, a PC, or a server.

[0064] like Figure 1 As shown, the method includes:

[0065] S110, Receive the first privacy request data sent by the first participating party.

[0066] The first privacy intersection data is the data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point. The first data to be intersected is obtained by processing the data corresponding to the first participant using a first parameter factor.

[0067] In this embodiment, the first participant is the participant about to perform a privacy intersection. Specifically, the number of first participants can be one or more. The original data held by the first participant for which the privacy intersection will be performed can be referred to as the first original data. The first original data can be any data type such as numbers, strings of arbitrary length, or boolean values.

[0068] In this context, the base point of the elliptic curve is a concept involved in elliptic curve cryptography. For example, the elliptic curve used in an elliptic curve cryptography system is y = 0. 2 =x 3 The curve represented by the equation +ax+b is an elliptic curve that is symmetric about the x-axis and satisfies constraint 4a. 3 +27b 2 ≠0, where the values ​​of a and b are different, the shape of the elliptic curve will change. A classic diagram of the shape of an elliptic curve is shown below. Figure 2 As shown. A point is selected on an elliptic curve as a base point. This point must meet certain conditions, such as being a point on the curve, not being at infinity, and being a generator—meaning that a series of finite addition operations on the base point can cover all points on the curve. This selected point is called the base point of the elliptic curve set. The selection of the base point is not unique; there can be multiple base points. Base points play a crucial role in encryption algorithms; they can be used to generate key pairs and perform encryption and decryption operations.

[0069] The first parameter factor can be a random number or a random operation formula, etc. The first parameter factor corresponds to the first participant. The first parameter factor can be understood as the temporary key corresponding to the first participant. The data corresponding to the first participant can be the original first data; or it can be data obtained after performing a specific operation on the original first data. In particular, because the data type of the original first data is not uniform, it can be standardized to make it data with a uniform data type or format. For example, a hash operation can be performed on the original first data.

[0070] Specifically, the first participant and the current participant are the two parties about to conduct a privacy intersection. The first participant can determine, in advance or in real time, the first privacy intersection data corresponding to all the first original data held by the first participant, and store this first privacy intersection data. When conducting a privacy intersection between the first participant and the current participant, the first participant can send the first privacy intersection data to the current participant, and the current participant receives the first privacy intersection data sent by the first participant.

[0071] For example, Company A is the first participant, and Company B is the current participant. All user data held by Company A is the first raw data. First privacy intersection data corresponding to each piece of first raw data is pre-determined, and this first privacy intersection data is stored in a preset storage unit. When shared user data (privacy intersection data) between Company A and Company B is determined, Company A can send this first privacy intersection data to Company B, so that Company B can determine the shared user data between Company A and Company B based on the received first privacy intersection data.

[0072] For another example, Company A, Company X, and Company Y are the first participants, and Company B is the current participant. Company A can send the corresponding first privacy request data A to Company B, Company X can send the corresponding first privacy request data X to Company B, and Company Y can send the corresponding first privacy request data Y to Company B. Based on receiving the first privacy request data A, the first privacy request data X, and / or the first privacy request data Y, Company B can determine the shared user data of Company A and Company B, the shared user data of Company X and Company B, and / or the shared user data of Company Y and Company B.

[0073] Based on the above embodiments, after determining the first privacy intersection data, the first participant can compress the first privacy intersection data to reduce the communication volume between the first participant and the current participant in subsequent data transmission. Optionally, the first participant can compress the first privacy intersection data using a preset compression method to update the first privacy intersection data.

[0074] The preset compression algorithm is a pre-specified data compression algorithm used to compress the initially determined first privacy intersection data, thereby reducing the data volume. For example, the preset compression algorithm can be a Bloom filter-based compression algorithm, a Cuckoo filter-based compression algorithm, an XOR filter-based compression algorithm, a hash operation-based compression algorithm, an unintentional pseudo-random function-based compression algorithm, or a compression algorithm that directly truncates a portion, etc.

[0075] In this embodiment, after the first participant initially determines the first privacy intersection data, it uses a preset compression algorithm to compress these initial first privacy intersection data to obtain a compressed value corresponding to each initial first privacy intersection data. Then, based on the compressed value, the initially determined first privacy intersection data is updated to obtain the final first privacy intersection data.

[0076] S120. Receive the second privacy request data fed back by the first participant, wherein the second privacy request data corresponds to the current participant.

[0077] The second privacy-sensitive intersection data is the data obtained by the first participant after processing the second privacy-sensitive intersection data sent by the current participant using the first parameter factor.

[0078] In this embodiment, the original data held by the current participant for privacy intersection is referred to as the second original data. Similarly, the second original data can be any data type, such as numbers, strings of arbitrary length, or Boolean values. The second privacy intersection data is the data extracted by the current participant after processing the second data to be intersected using a pre-defined elliptic curve base point. The second data to be intersected is obtained by processing the data corresponding to the current participant using a second parameter factor. The second privacy intersection data is the data after processing the second privacy intersection data using a first parameter factor.

[0079] Specifically, when the first participant and the current participant perform a privacy intersection, the current participant can first hash its second original data to obtain initial encrypted data; then, it processes the initial encrypted data using a second parameter factor to obtain second data to be intersected; further, it performs a base-point multiplication operation on the second data to be intersected using a pre-defined elliptic curve base point to obtain coordinate data including an x-coordinate and a y-coordinate, and then extracts data based on pre-defined rules, extracting target data from the coordinate data, which is the second privacy intersection data; finally, the second privacy intersection data is sent to the first participant. After receiving the second privacy intersection data, the first participant processes the second privacy intersection data using a first parameter factor to obtain second data to be intersected; subsequently, it feeds back this second data to be intersected to the current participant. At this time, the current participant receives the second data to be intersected.

[0080] Based on the above example, Company B first encrypts the second original data it holds to obtain second privacy-sensitive intersection data, and sends the second privacy-sensitive intersection data to Company A. After receiving the second privacy-sensitive intersection data, the first participant processes the second privacy-sensitive intersection data using a first parameter factor to obtain second privacy-sensitive intersection data; subsequently, this second privacy-sensitive intersection data is fed back to Company B. At this point, Company B receives the second privacy-sensitive intersection data.

[0081] It should be noted that there is no necessary order of execution for S110 and S120.

[0082] Based on the above examples, when requesting shared user data of Company A and Company B, one can first receive the first privacy request data sent by Company A, and then receive the second privacy request data to be requested in response to Company A; or one can first receive the second privacy request data to be requested in response to Company A, and then receive the first privacy request data sent by Company A; or one can simultaneously receive the first privacy request data sent by Company A and the second privacy request data to be requested in response to Company A.

[0083] S130. Process the second privacy intersection data based on the second parameter factor to obtain the privacy intersection data to be used corresponding to the current participant.

[0084] The second parameter factor can be a random number or a random operation formula, and it is distinct from the first parameter factor. The second parameter factor corresponds to the current participant and can be understood as the temporary key associated with that participant. The second privacy intersection data sent by the current participant to the first participant is the data processed using the second parameter factor.

[0085] Specifically, upon receiving the second privacy-sensitive intersection data, the current participant processes it using the reciprocal of the second parameter factor to obtain the privacy-sensitive intersection data to be used. This is because, before sending its data to the first participant, the current participant first encrypts its data based on the second parameter factor to ensure data privacy. In this step, the reciprocal of the second parameter factor is used to process the second privacy-sensitive intersection data, the purpose of which is to decrypt the data after the initial encryption.

[0086] S140. Based on the first privacy intersection data and the privacy intersection data to be used, determine the target shared data shared by the current participants and the first participant.

[0087] The target shared data is the intersection of the data held by the first participant and the data held by the current participant.

[0088] In this embodiment, the first privacy intersection data is data processed by applying a first parameter factor and a pre-defined elliptic curve base point to the data held by the first participant. The privacy intersection data to be used is data processed by applying the first parameter factor and the pre-defined elliptic curve base point to the data held by the second participant. Therefore, the first privacy intersection data and the privacy intersection data to be used are comparable. Specifically, the target shared data between the current participant and the first participant can be determined by querying whether the first privacy intersection data contains the privacy intersection data to be used. Similarly, the target shared data can be determined by querying whether the privacy intersection data to be used contains the first privacy intersection data.

[0089] It should be noted that if the first privacy intersection data is data that has been compressed and updated using a preset compression method, then the privacy intersection data to be used will also be compressed using the same preset compression method, and the privacy intersection data to be used will be updated based on the compression result. Then, based on the updated first privacy intersection data and the updated privacy intersection data to be used, the target shared data will be determined.

[0090] Furthermore, based on the above technical solution, after determining the target shared data, the target shared data can be fed back to the first participating party so that the first participating party can obtain the target shared data, thereby achieving the effect of sharing the target shared data. The first participating party does not need to repeat the step of determining privacy data, which can save service resources.

[0091] It should be noted that the acquisition, storage, use, and processing of data in this application's technical solution all comply with relevant national laws and regulations. For example, network requests are intercepted and processed with user authorization.

[0092] The technical solution of this invention involves processing the original data held by the first participant using a first parameter factor and a pre-set elliptic curve base point to obtain first privacy intersection data; processing the original data held by the current participant using a second parameter factor and a pre-set elliptic curve base point to obtain second privacy intersection data; when determining the target shared data between the first participant and the current participant, the current participant receives the first privacy intersection data sent by the first participant, and the second privacy intersection data to be processed based on the first parameter factor and fed back by the first participant; furthermore, the second privacy intersection data to be processed based on the second parameter factor is used to obtain privacy intersection data to be used corresponding to the current participant; thus, based on the first privacy intersection data and the privacy intersection data to be used, the target shared data between the current participant and the first participant is determined. This scheme maps the data onto an elliptic curve by performing dot product operations on the original data after parameter factoring using pre-defined elliptic curve base points. Since the dot product operation is relatively simple, it significantly reduces the amount of data computation, decreases the time consumed in the privacy intersection process, and improves the efficiency of privacy intersection. Furthermore, the amount of data computation does not differ significantly for different types of elliptic curves, thus improving the universality of the privacy intersection method based on elliptic curves. In addition, the parameter factors used in this scheme are determined by bitwise operations on random factors using auxiliary factors, avoiding the influence of auxiliary factors in the elliptic curve. This maps all the original data after parameter factoring to the same elliptic curve point group (and a large prime point group without auxiliary factors), ensuring that different original data are mapped to different points on the elliptic curve. This avoids the problem of incorrectly identifying non-intersecting data as intersecting data, improving the accuracy of privacy intersection.

[0093] Figure 3 This is a schematic diagram of a privacy intersection method provided by an embodiment of the present invention. Based on the foregoing embodiments, before receiving the first privacy intersection data sent by the first participant, the privacy intersection data corresponding to the participant can be determined first. Specific implementation details can be found in the technical solution of this embodiment. Technical terms that are the same as or corresponding to those in the above embodiments will not be repeated here.

[0094] like Figure 3 As shown, the method specifically includes the following steps:

[0095] S210. Determine the privacy request data corresponding to the participating parties.

[0096] The participants include the first participant and / or the current participant, and the privacy intersection data includes the first privacy intersection data corresponding to the first participant and / or the second privacy intersection data corresponding to the current participant.

[0097] In this embodiment, the first participant can determine its corresponding first privacy intersection data; the current participant can determine its corresponding second privacy intersection data. The process of determining the privacy intersection data of both participants in S210 can be determined offline. The process of determining the target shared data between the first participant and the current participant in S220-S250 can be determined online. In this way, since the privacy intersection data of both participants is determined offline, the first privacy intersection data and / or the second privacy intersection data can be quickly obtained when determining the target shared data online. This greatly reduces the latency of intersection calculation in the online stage, enabling fast privacy intersection calculation even under resource-constrained device or network conditions, thereby reducing the time consumption of privacy intersection calculation and achieving the goal of fast and secure calculation of intersection data.

[0098] Specifically, the specific implementation method for determining the privacy intersection data corresponding to the participants may include: hashing the data to be processed owned by the participants to obtain the hash value of the data to be processed; processing the hash value of the data to be processed based on the parameter factors corresponding to the participants and the pre-determined elliptic curve base points to obtain the data to be extracted corresponding to the data to be processed; and extracting and processing the data to be extracted according to the pre-set extraction method to obtain the privacy intersection data.

[0099] The data to be processed consists of the original data held by the participating parties. The base points of the elliptic curves corresponding to the current participating party and the first participating party are the same. The data to be extracted is the data obtained after mapping the data to be processed onto the elliptic curve.

[0100] In this embodiment, the parameter factors corresponding to the first participant and the current participant are different. The first participant corresponds to the first parameter factor, and the second participant corresponds to the second parameter factor.

[0101] The following details how to determine the parameter factors. The first participant can randomly select one factor from the factor set that includes multiple factors as the first parameter factor, and the current participant can randomly select one factor from the factor set that includes multiple factors as the second parameter factor.

[0102] Optionally, the specific implementation of determining the parameter factor may also include: determining the random factor corresponding to the participant; and determining the parameter factor corresponding to the participant by performing bit operations on the random factor.

[0103] In this embodiment, various types of elliptic curves are included, and the order of some elliptic curve point groups is n = m × L (where L is a large prime number and m is a small integer), and m is a cofactor. If an elliptic curve with a cofactor is selected, the results obtained by processing different data based on the elliptic curve base points are the same, resulting in a high error rate in the final determined target common data.

[0104] To effectively address the above issues, this embodiment can perform bitwise operations on the random factor using an auxiliary factor, which corresponds to the type of elliptic curve to be used. For example, if the auxiliary factor for a certain type of elliptic curve is 8; and the first random factor for the first participant is determined to be α, and the second random factor for the second participant is determined to be β, then bitwise operations (e.g., using clamp bitwise operations) are performed on the first random factor α using the auxiliary factor 8 to determine the first parameter factor α corresponding to the first participant. c The second parameter factor β corresponding to the current participant is determined by performing bitwise operations on the second random factor β using the auxiliary factor 8 (for example, using the clamp bitwise operation). c The advantages of this approach are as follows: by performing bitwise operations on the random factors, the influence of auxiliary factors in certain special elliptic curves is avoided, thus mapping all data to the same elliptic curve point group (and a large prime point group without auxiliary factors), preserving the additive homomorphic property of elliptic curves, satisfying all types of elliptic curves, and possessing universality and applicability; moreover, it avoids the situation where the elliptic curve base points produce the same results when processing different data to be processed, thereby improving the accuracy of the final determined target common data.

[0105] It should be noted that bitwise operations are for cases where the order of the elliptic curve point group has an auxiliary factor. If the order of the elliptic curve point group is a prime number, this step can be ignored, and the random factor corresponding to the participant can be determined as the parameter factor corresponding to the participant.

[0106] In this embodiment, the method for determining privacy-preserving intersection data is the same for each piece of data to be processed held by any participating party.

[0107] For a detailed diagram illustrating the steps involved in determining the first privacy intersection data, please refer to [link / reference needed]. Figure 4 First, a preset hash algorithm can be used to hash the data to be processed X (the first original data) to obtain the hash value x of the data to be processed X. i This transforms the original data in string format of arbitrary length into a hash value of 256 bits; simultaneously, bitwise operations are performed on the first random factor α corresponding to the first participant to determine the first parameter factor α corresponding to the first participant.c (Temporary key), α c It is also a hash value with a data size of 256 bits; then, the first parameter factor α is... c With hash value x i Performing modular multiplication (modulo L) yields the scalar p = α. c ·x i ; thus the scalar p = α c ·x i Perform an elliptic curve base point multiplication operation with the predetermined elliptic curve base point B to determine the data to be extracted corresponding to the data to be processed, P = p × B (data in coordinate form); further, extract and process the data to be extracted according to the preset extraction method to obtain the privacy intersection data u corresponding to the data to be processed, X.

[0108] See the diagram illustrating the steps for determining the second privacy intersection data. Figure 5 First, a preset hash algorithm can be used to hash the data Y (the second original data) to obtain the hash value y of the data Y. i This transforms data in string format of arbitrary length into a hash value of 256 bits; simultaneously, bitwise operations are performed on the second random factor β corresponding to the second participant to determine the second parameter factor β corresponding to the second participant. c (Temporary key), β c It is also a hash value with a data size of 256 bits; then, the first parameter factor β is... c With hash value y i Performing modular multiplication (modulo L) yields the scalar q = β. c ·y i Thus, the scalar q = β c ·y i Perform an elliptic curve base point multiplication operation with the predetermined elliptic curve base point B to determine the data to be extracted, Q = q × B (data in coordinate form), corresponding to the data to be processed X; further, extract and process the data to be extracted according to the preset extraction method to obtain the second privacy intersection data v corresponding to the data to be processed Y.

[0109] In this embodiment, the original data after parameter factoring is multiplied by a base point of a pre-defined elliptic curve, mapping the data onto the elliptic curve. Since the base point multiplication operation is relatively simple, it can greatly reduce the amount of data computation, optimize the data computation process in privacy intersection, reduce the time consumption of the privacy intersection process, and improve the efficiency of privacy intersection. In addition, the amount of data computation does not differ significantly for different types of elliptic curves, thus improving the universality of the privacy intersection method based on elliptic curves.

[0110] Based on the above embodiments, optionally, the data to be extracted includes the horizontal and vertical coordinates corresponding to the data to be processed. The data to be extracted is processed according to a pre-set extraction method to obtain privacy intersection data. Specifically, the implementation method may include: extracting the horizontal or vertical coordinates of the data to be extracted according to the elliptic curve processing method corresponding to the elliptic curve base point to obtain privacy intersection data.

[0111] Elliptic curve processing methods can include the Montgomery gradient algorithm, the sliding window algorithm, and the doubling method, among others. Different elliptic curve processing methods extract data in different ways. For example, if the elliptic curve processing method corresponding to the base point is the Montgomery gradient algorithm, then the x-coordinate is extracted from the data; if the elliptic curve processing method corresponding to the base point is the sliding window algorithm or the doubling method, then the y-coordinate is extracted from the data.

[0112] Specifically, the elliptic curve processing method corresponding to the elliptic curve base point can be predetermined. For example, the Montgomery gradient algorithm, sliding window algorithm, and doubling method can be used. If the specific implementation of the elliptic curve processing method corresponding to the elliptic curve base point is to extract the x-coordinate from the data to be extracted, then the x-coordinate is extracted to obtain the privacy-preserving intersection data. If the specific implementation of the elliptic curve processing method corresponding to the elliptic curve base point is to extract the y-coordinate from the data to be extracted, then the y-coordinate is extracted to obtain the privacy-preserving intersection data. The advantage of this setup is that privacy-preserving intersection data can be determined through multiple data extraction methods, increasing the selectivity of privacy-preserving intersection data extraction.

[0113] S220. Receive the first privacy intersection data sent by the first participant, wherein the first privacy intersection data is the data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point, and the first data to be intersected is obtained after processing the data corresponding to the first participant using a first parameter factor.

[0114] S230. Receive the second privacy-requesting data fed back by the first participant, wherein the second privacy-requesting data corresponds to the current participant and is the data obtained by the first participant after processing the second privacy-requesting data sent by the current participant using the first parameter factor.

[0115] S240. Process the second privacy-to-intercept data based on the second parameter factor to obtain privacy-to-intercept data corresponding to the current participant; wherein, the second participation factor corresponds to the current participant.

[0116] S250. Based on the first privacy intersection data and the privacy intersection data to be used, determine the target shared data shared by the current participants and the first participant.

[0117] The technical solution of this invention determines the privacy intersection data corresponding to each participant offline before determining the target shared data between the first participant and the current participant online. When determining the target privacy intersection data online, the privacy intersection data can be quickly obtained, which greatly reduces the latency of the online intersection calculation. This allows for rapid large-scale set intersection calculations even under resource-constrained device or network conditions, thereby reducing the time consumption of privacy intersection calculations and achieving the goal of fast and secure calculation of intersection data. Furthermore, this embodiment performs base-point multiplication on the original data after parameter factorization using pre-defined elliptic curve base points, mapping the data onto an elliptic curve. Since the base-point multiplication operation is relatively simple, it greatly reduces the amount of data computation, optimizes the data computation process in privacy intersection, reduces the time consumption of the privacy intersection process, and improves the efficiency of privacy intersection calculations. In addition, the amount of data computation does not differ significantly for different types of elliptic curves, thus improving the universality of the privacy intersection method based on elliptic curves.

[0118] Figure 6 This is a schematic diagram of a privacy intersection method provided by an embodiment of the present invention. Based on the aforementioned embodiments, after the current participant determines the second privacy intersection data, it sends the second privacy intersection data to the first participant. The first participant then processes the second privacy intersection data using a first parameter factor and an elliptic curve base point to obtain the second privacy intersection data to be obtained, and feeds it back to the current participant. In addition, this embodiment provides a detailed description of step S130. For specific implementation details, please refer to the technical solution of this embodiment. Technical terms that are the same as or corresponding to those in the above embodiments will not be repeated here.

[0119] like Figure 6 As shown, the method specifically includes the following steps:

[0120] S310. Determine the privacy request data corresponding to the participating parties.

[0121] In this embodiment, the first privacy intersection data corresponding to the first participant can be predetermined. For details, please refer to [link to implementation details]. Figure 4 ; and, determine the second privacy intersection data corresponding to the current participant, see [link to implementation details] Figure 5 .

[0122] S320. Receive the first privacy intersection data sent by the first participant, wherein the first privacy intersection data is the data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point, and the first data to be intersected is obtained after processing the data corresponding to the first participant using a first parameter factor.

[0123] S330. Send the second privacy intersection data to the first participant, so that the first participant can process the second privacy intersection data using the first parameter factor and the elliptic curve base point to obtain the second privacy intersection data, and then provide feedback.

[0124] In this embodiment, after determining the second privacy intersection data, the current participant sends the second privacy intersection data to the first participant. The purpose is for the first participant to process the second privacy intersection data using a first parameter factor and elliptic curve base points to determine the second privacy intersection data to be used. Then, the first participant feeds back the second privacy intersection data to the current participant. In this embodiment, since the subsequent process of finding the target shared data requires the first privacy intersection data, and the first privacy intersection data is data processed by the first participant using the first parameter factor, the first participant must also process the second privacy intersection data using the first parameter factor to ensure comparability between the first privacy intersection data and the privacy intersection data to be used.

[0125] Based on the above embodiments, optionally, the first participant processes the second privacy intersection data using a first parameter factor and an elliptic curve base point to obtain the second privacy intersection data. Specifically, the implementation includes: restoring the second privacy intersection data based on the elliptic curve base point to obtain data to be processed again; processing the data to be processed again based on the first parameter factor to obtain data to be applied; and extracting data from the data to be applied to obtain the second privacy intersection data.

[0126] In this embodiment, the recovery process is relative to data extraction. See the example above. Figure 5 The data extraction process is as follows: Based on a pre-defined extraction method, the data to be extracted, Q = q × B (data in the form of a pair of coordinate values, i.e., including the x-coordinate and y-coordinate), is processed to obtain the second privacy intersection data v (data in the form of a single coordinate value, i.e., the x-coordinate or y-coordinate). Correspondingly, the data recovery process is as follows: Given the second privacy intersection data v, based on the elliptic curve base point and the second privacy intersection data v (x-coordinate or y-coordinate value), the y-coordinate value corresponding to the x-coordinate value, or the x-coordinate value corresponding to the y-coordinate value, is recovered, thus obtaining a pair of coordinate values.

[0127] In this embodiment, the data to be processed again is a pair of coordinate values, i.e., Q in the example above. The second privacy intersection data is the x-coordinate or y-coordinate value. By restoring the second privacy intersection data based on the elliptic curve base points, the y-coordinate value corresponding to the x-coordinate, or the x-coordinate value corresponding to the y-coordinate, can be obtained, thus obtaining the data to be processed again (including the x-coordinate and y-coordinate). Then, the first parameter factor is used to perform an elliptic curve random dot product operation on the data to be processed again to obtain the data to be applied; further, the data to be applied is extracted according to a pre-set extraction method to extract the x-coordinate or y-coordinate of the data to be applied, thus obtaining the second privacy intersection data. In this embodiment, to prevent the data held by the current participant from being leaked, before the current participant sends its data to the first participant, the data is encrypted (i.e., the data held by the current participant is processed using the second parameter factor) to obtain the second privacy intersection data. The first participant encrypts the second privacy intersection data of the current participant again, ensuring the privacy and security of the data held by the current participant.

[0128] Based on the above example, the current participant sends the second privacy request data v to the first participant; after receiving the second privacy request data v, the first participant determines the second privacy request data to be requested. See the diagram illustrating the data processing procedure for the first participant to determine the second privacy request data. Figure 7 First, the second privacy intersection data v (e.g., the second privacy intersection data v is the x-coordinate x0) is restored based on the elliptic curve base points to obtain the data to be processed again, Q = q × B. Then, the first parameter factor α is used... c Performing an elliptic curve random dot product on the data Q = q × B to be processed again yields the data R = α to be applied. c ×Q=(α c ·β c )×(y i ·B) i Furthermore, the data to be applied is processed according to a pre-defined extraction method, extracting the horizontal or vertical coordinates of the data to be applied (for example, extracting the horizontal coordinates) to obtain the second privacy-sensitive intersection data w.

[0129] S340. Receive the second privacy-requesting data fed back by the first participant, wherein the second privacy-requesting data corresponds to the current participant and is the data obtained by the first participant after processing the second privacy-requesting data sent by the current participant using the first parameter factor.

[0130] S350. After restoring the second privacy-defining intersection data, the second parameter factor is used to process the restored second privacy-defining intersection data to obtain the privacy-defining intersection data to be used.

[0131] In this embodiment, a schematic diagram of the data processing procedure for determining the privacy-sensitive intersection data to be used by the current participants is shown below. Figure 8 First, based on the elliptic curve base points, the second privacy-sensitive intersection data w is restored to obtain R = (α c ·β c )×(y i ×B). Furthermore, the second parameter factor β is used. c The corresponding reciprocal β c -1 For R = (α) c ·β c )×(y i ×B) Perform elliptic curve random dot product operation to obtain P'=β c -1 ×R=α c ·y i ×B; Further, P' is extracted according to a pre-set extraction method to obtain the privacy intersection data u' to be used. In this embodiment, before the current participant sends its data to the first participant, in order to ensure data privacy, the current participant first performs initial encryption processing on its data based on the second parameter factor. In this step, the reciprocal of the second parameter factor is used to process the second privacy intersection data to be used. The purpose is to decrypt the data after the initial encryption processing, so that the privacy intersection data to be used is comparable to the first privacy intersection data.

[0132] S360. Based on the first privacy intersection data and the privacy intersection data to be used, determine the target shared data shared by the current participants and the first participant.

[0133] Optionally, the specific implementation of determining the target shared data between the current participant and the first participant based on the first privacy intersection data and the privacy intersection data to be used can be as follows: when there is data in the first privacy intersection data that is the same as the privacy intersection data to be used, the privacy intersection data to be used is determined to be data in the target shared data; or, when there is data in the privacy intersection data to be used that is the same as the first privacy intersection data, the privacy intersection data to be used is determined to be data in the target shared data.

[0134] In this embodiment, the target shared data between the current participant and the first participant can be determined by querying whether the first privacy intersection data contains the privacy intersection data to be used. Specifically, if the first privacy intersection data contains data identical to the privacy intersection data to be used, the privacy intersection data to be used is determined to be data in the target shared data. Alternatively, the target shared data can also be determined by querying whether the privacy intersection data to be used contains the privacy intersection data to be used. Specifically, if the privacy intersection data to be used contains data identical to the first privacy intersection data, the privacy intersection data to be used is determined to be data in the target shared data. In this way, multiple query methods can be used to determine the target shared data, increasing the diversity of methods for determining the target shared data.

[0135] In this embodiment of the invention, after determining the second privacy intersection data, the current participant sends the second privacy intersection data to the first participant. The first participant then processes the second privacy intersection data using a first parameter factor and elliptic curve base points to obtain the second privacy intersection data to be used, and feeds it back to the current participant. In this embodiment, since the subsequent process of finding the target shared data requires the first privacy intersection data, and the first privacy intersection data is data processed by the first participant using the first parameter factor, the first participant must also process the second privacy intersection data using the first parameter factor to ensure comparability between the first privacy intersection data and the privacy intersection data to be used.

[0136] The following is a concrete example illustrating the data flow process for determining the shared target data. (See [link to relevant documentation]). Figure 9 .like Figure 9 As shown, the first participant and the current participant are the two parties about to perform a privacy intersection. The first participant holds the first original data, and the current participant holds the second original data. The first participant uses the first parameter factor α. c The first original data is processed using the elliptic curve base points to obtain the first privacy intersection data u. Optionally, the first privacy intersection data u can be compressed, and the first privacy intersection data tx can be updated based on the compressed result. i The process of determining the first privacy intersection data u can be determined offline; see [link to implementation details] for details. Figure 4 This will not be elaborated upon further. The current participants use the second parameter factor β. c The second original data is processed using the elliptic curve base points to obtain the second privacy intersection data v. The implementation process for determining the second privacy intersection data v is described in [link to documentation]. Figure 6This will not be elaborated further. Specifically, the process of determining the second privacy intersection data can be determined offline or online; here, we will take online determination as an example. When determining the shared data between the first participant and the current participant, the first participant sends the first privacy intersection data u to the current participant. After receiving the first privacy intersection data u, the current participant temporarily stores it. The current participant then sends the second privacy intersection data v to the first participant. The first participant uses the first parameter factor α. c The second privacy-preserving intersection data v is processed with the elliptic curve base points to obtain the second privacy-preserving intersection data w, which is then fed back to the current participants. The process of determining the second privacy-preserving intersection data w is described in [link to relevant documentation]. Figure 7 This will not be elaborated further here. Based on the second privacy-sensitive intersection data w received, the current participating party performs recovery processing on the second privacy-sensitive intersection data w, and then uses the second parameter factor β. c The second privacy intersection data after recovery is processed to obtain the privacy intersection data u' to be used. The implementation process for determining the privacy intersection data u' to be used is described in [link to documentation]. Figure 8 This will not be elaborated further here. Optionally, if the first privacy intersection data u is compressed, the same compression algorithm is also used to compress the privacy intersection data u' to be used, and the privacy intersection data to be used is updated to ty based on the compressed result. i Finally, the current participants determine the target shared data by comparing whether there are any identical elements between the privacy-adjusted intersection data u' and the first privacy-adjusted intersection data u.

[0137] Understandably, this embodiment can be applied to real-world business scenarios involving unbalanced privacy intersection. Unbalanced privacy intersection refers to a situation in privacy-preserving computation where there is an imbalance in data and computing power among the participating parties. One party possesses more data or computing power, while the other party has relatively less. Optionally, the amount of data the first participating party contributes to the privacy intersection is greater than the amount of data the current participating party contributes. For example, the amount of data the first participating party contributes to the privacy intersection is on the order of 1 billion, while the amount of data the current participating party contributes is on the order of tens of millions.

[0138] The following example illustrates the improvement in computational efficiency of this scheme compared to the original scheme, using a case where the first participant holds 1 billion data points and the current participant holds 10 million data points for a non-equilibrium privacy intersection.

[0139] A comparison of the main computational loads between this scheme and the original scheme is shown in Table 1. As shown in Table 1, the original scheme requires 1 billion hash-to-curve calculations and 1 billion elliptic curve random dot product operations when the first participant determines the first privacy intersection data; and 10 million hash-to-curve calculations and 30 million elliptic curve random dot product operations when determining the target shared data. In contrast, this scheme requires 1 billion hash operations, 1 billion modular multiplications (MLM), and 1 billion elliptic curve base-point multiplication operations when the first participant determines the first privacy intersection data; and 10 million hash operations, 10 million MLM multiplications, 10 million elliptic curve base-point multiplication operations, and 20 million elliptic curve random dot product operations when determining the target shared data.

[0140] Comparison of main calculation quantities between this scheme and the original scheme (Table)

[0141]

[0142] It should be noted that in Table 1, PointMult represents the elliptic curve random point multiplication operation, ModMult represents the finite field modular multiplication operation, and BaseMult represents the elliptic curve base point multiplication operation.

[0143] Taking a specific type of elliptic curve as an example, one hash to curve calculation is equivalent to one hash operation; the fastest elliptic curve random dot product operation is the Montgomery gradient algorithm; and the fastest elliptic curve base point dot product operation is the Comb algorithm. Since the time overhead of one Montgomery gradient operation, one Comb base point dot product operation, and one modular L multiplication operation is approximately 60:10:1, and given the massive amount of data from the first participant, most of the computation time is spent determining the first privacy intersection data. Based on this, this scheme offers approximately a 5-fold performance improvement compared to the original scheme. For a typical 8-core CPU, the original scheme requires 6 to 7 hours to complete all calculations for a privacy intersection involving 1 billion data points; while this scheme can complete all calculations for a privacy intersection involving 1 billion data points within 1 hour; when using high-performance microprocessors, this scheme can complete all calculations for a privacy intersection involving 1 billion data points within 10 minutes. Therefore, compared to the original scheme, this scheme significantly reduces the amount of data computation, reduces the total time spent on privacy intersections, and improves the computational efficiency of privacy intersections.

[0144] Figure 10 This is a schematic diagram of a privacy intersection device provided in an embodiment of the present invention. The device includes: a first data receiving module 410, a second data receiving module 420, a data to be used determination module 430, and a shared data determination module 440.

[0145] The first data receiving module 410 is used to receive the first privacy intersection data sent by the first participant. The first privacy intersection data is the data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point. The first data to be intersected is obtained by processing the data corresponding to the first participant using a first parameter factor.

[0146] The second data receiving module 420 is used to receive the second privacy-defining intersection data fed back by the first participant. The second privacy-defining intersection data corresponds to the current participant and is the data obtained by the first participant after processing the second privacy-defining intersection data sent by the current participant using a first parameter factor.

[0147] The data to be used determination module 430 is used to process the second privacy intersection data based on the second parameter factor to obtain the privacy intersection data to be used corresponding to the current participant; wherein, the second participation factor corresponds to the current participant;

[0148] The shared data determination module 440 is used to determine the target shared data shared by the current participant and the first participant based on the first privacy intersection data and the privacy intersection data to be used.

[0149] Optionally, based on the above-described apparatus, the apparatus may further include: an intersection data determination module, used for...

[0150] Determine privacy intersection data corresponding to the participating parties, wherein the participating parties include the first participating party and / or the current participating party, and the privacy intersection data includes the first privacy intersection data corresponding to the first participating party and / or the second privacy intersection data corresponding to the current participating party;

[0151] Based on the above-mentioned device, optionally, the intersection data determination module includes: a hash value determination unit, a base point multiplication processing unit, and a data extraction unit;

[0152] The hash value determination unit is used to perform hash processing on the data to be processed owned by the participants to obtain the hash value of the data to be processed.

[0153] The base point multiplication processing unit is used to process the hash value of the data to be processed based on the parameter factors corresponding to the participants and the pre-determined elliptic curve base points to obtain the data to be extracted corresponding to the data to be processed; wherein, the elliptic curve base points corresponding to the current participant and the first participant are the same;

[0154] The data extraction unit is used to extract and process the data to be extracted according to a pre-set extraction method to obtain privacy-preserving intersection data.

[0155] Based on the above-mentioned device, optionally, the intersection data determination module further includes: a parameter factor determination unit;

[0156] The parameter factor determination unit is used to determine the random factor corresponding to the participant; by performing bit operations on the random factor, the parameter factor corresponding to the participant is determined.

[0157] Based on the above device, optionally, the data to be extracted includes the horizontal and vertical coordinates corresponding to the data to be processed. The data extraction unit is specifically used to extract the horizontal or vertical coordinates from the data to be extracted according to the elliptic curve processing method corresponding to the base point of the elliptic curve, so as to obtain privacy intersection data.

[0158] Optionally, based on the above-mentioned device, the device may further include: a first data compression module, used to compress the first privacy intersection data based on a preset compression method adopted by the first participant, so as to update the first privacy intersection data.

[0159] Optionally, based on the above-mentioned device, the device may further include: a second data encryption module, used to send the second privacy intersection data to the first participant, so that the first participant processes the second privacy intersection data using the first parameter factor and the elliptic curve base point to obtain the second privacy intersection data, and then feeds it back.

[0160] Based on the above-mentioned device, optionally, the second data encryption module includes: a data recovery unit, a data determination unit for the data to be used, and a data extraction unit;

[0161] The data recovery unit is used for data recovery processing based on the intersection of the second privacy with the base points of the elliptic curve to obtain the data to be processed again.

[0162] The data to be applied determination unit is used to process the data to be processed again based on the first parameter factor to obtain the data to be applied.

[0163] The data extraction unit is used to extract data from the data to be applied to obtain the second privacy-sensitive intersection data.

[0164] Based on the above-mentioned device, optionally, the data to be used determination module 430 is specifically used to process the recovered second privacy intersection data after the second privacy intersection data is restored, and then to process the restored second privacy intersection data using a second parameter factor to obtain the privacy intersection data to be used.

[0165] Based on the above-mentioned device, optionally, the shared data determination module 440 is specifically used to determine the privacy intersection data to be used as data in the target shared data when there is data in the first privacy intersection data that is the same as the privacy intersection data to be used; or, when there is data in the privacy intersection data to be used that is the same as the first privacy intersection data, determine the privacy intersection data to be used as data in the target shared data.

[0166] Based on the above-mentioned device, optionally, the amount of data in the privacy intersection of the first participant is greater than the amount of data in the privacy intersection of the current participant.

[0167] The technical solution of this invention involves processing the original data held by the first participant using a first parameter factor and a pre-set elliptic curve base point to obtain first privacy intersection data; processing the original data held by the current participant using a second parameter factor and a pre-set elliptic curve base point to obtain second privacy intersection data; when determining the target shared data between the first participant and the current participant, the current participant receives the first privacy intersection data sent by the first participant, and the second privacy intersection data to be processed based on the first parameter factor and fed back by the first participant; furthermore, the second privacy intersection data to be processed based on the second parameter factor is used to obtain privacy intersection data to be used corresponding to the current participant; thus, based on the first privacy intersection data and the privacy intersection data to be used, the target shared data between the current participant and the first participant is determined. This scheme maps the data onto an elliptic curve by performing dot product operations on the original data after parameter factoring using pre-defined elliptic curve base points. Since the dot product operation is relatively simple, it significantly reduces the amount of data computation, decreases the time consumed in the privacy intersection process, and improves the efficiency of privacy intersection. Furthermore, the amount of data computation does not differ significantly for different types of elliptic curves, thus improving the universality of the privacy intersection method based on elliptic curves. In addition, the parameter factors used in this scheme are determined by bitwise operations on random factors using auxiliary factors, avoiding the influence of auxiliary factors in the elliptic curve. This maps all the original data after parameter factoring to the same elliptic curve point group (and a large prime point group without auxiliary factors), ensuring that different original data are mapped to different points on the elliptic curve. This avoids the problem of incorrectly identifying non-intersecting data as intersecting data, improving the accuracy of privacy intersection.

[0168] The privacy intersection apparatus provided in the embodiments of the present invention can execute the privacy intersection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.

[0169] It is worth noting that the various units and modules included in the above system are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the protection scope of the embodiments of the present invention.

[0170] Figure 11 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Figure 11 A block diagram is shown of an exemplary electronic device 50 suitable for implementing embodiments of the present invention.

[0171] Figure 11 The electronic device 50 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present invention.

[0172] like Figure 11 As shown, the electronic device 50 is represented in the form of a general-purpose computing device. The components of the electronic device 50 may include, but are not limited to: one or more processors or processing units 501, system memory 502, and bus 503 connecting different system components (including system memory 502 and processing unit 501).

[0173] Bus 503 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0174] Electronic device 50 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 50, including volatile and non-volatile media, removable and non-removable media.

[0175] System memory 502 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 504 and / or cache memory 505. Electronic device 50 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 506 may be used to read and write non-removable, non-volatile magnetic media (… Figure 11 Not shown; usually referred to as a "hard drive"). Although Figure 11Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 503 via one or more data media interfaces. Memory 502 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.

[0176] A program / utility 508 having a set (at least one) of program modules 507 may be stored, for example, in memory 502. Such program modules 507 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 507 typically perform the functions and / or methods described in the embodiments of the present invention.

[0177] Electronic device 50 can also communicate with one or more external devices 509 (e.g., keyboard, pointing device, display 510, etc.), and with one or more devices that enable a user to interact with the electronic device 50, and / or with any device that enables the electronic device 50 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 511. Furthermore, electronic device 50 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 512. As shown, network adapter 512 communicates with other modules of electronic device 50 via bus 503. It should be understood that, although... Figure 11 As not shown, other hardware and / or software modules may be used in conjunction with electronic device 50, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0178] The processing unit 501 executes various functional applications and page processing by running programs stored in the system memory 502, such as implementing the privacy intersection method provided in the embodiments of the present invention.

[0179] This invention also provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform a privacy intersection method, the method comprising:

[0180] Receive first privacy intersection data sent by the first participant, wherein the first privacy intersection data is data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point, and the first data to be intersected is obtained after processing the data corresponding to the first participant using a first parameter factor;

[0181] Receive the second privacy-requesting data fed back by the first participant, wherein the second privacy-requesting data corresponds to the current participant, and the second privacy-requesting data is the data obtained by the first participant after processing the second privacy-requesting data sent by the current participant using the first parameter factor;

[0182] The second privacy-defining intersection data is processed based on the second parameter factor to obtain privacy-defining intersection data corresponding to the current participant; wherein, the second participation factor corresponds to the current participant;

[0183] Based on the first privacy intersection data and the privacy intersection data to be used, the target shared data shared by the current participant and the first participant is determined.

[0184] The computer storage medium of this invention can be any combination of one or more computer-readable media. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0185] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.

[0186] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including—but not limited to—wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0187] Computer program code for performing the operations of embodiments of the present invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages—such as Java, Smalltalk, and C++—as well as conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0188] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A privacy-preserving intersection method, characterized in that, include: Receive first privacy intersection data sent by the first participant, wherein the first privacy intersection data is data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point, and the first data to be intersected is obtained after processing the data corresponding to the first participant using a first parameter factor; Receive the second privacy-requesting data fed back by the first participant, wherein the second privacy-requesting data corresponds to the current participant, and the second privacy-requesting data is the data obtained by the first participant after processing the second privacy-requesting data sent by the current participant using the first parameter factor; The second privacy-defining intersection data is processed based on the second parameter factor to obtain privacy-defining intersection data corresponding to the current participant; wherein, the second participation factor corresponds to the current participant; Based on the first privacy intersection data and the privacy intersection data to be used, the target shared data shared by the current participant and the first participant is determined.

2. The method according to claim 1, characterized in that, Also includes: Determine privacy intersection data corresponding to the participating parties, wherein the participating parties include a first participating party and / or the current participating party, and the privacy intersection data includes first privacy intersection data corresponding to the first participating party and / or second privacy intersection data corresponding to the current participating party.

3. The method according to claim 2, characterized in that, The determination of privacy-related intersection data corresponding to the participating parties includes: The unprocessed data owned by the participating parties is hashed to obtain the hash value of the unprocessed data; Based on the parameter factors corresponding to the participants and the predetermined elliptic curve base points, the hash value of the data to be processed is processed to obtain the data to be extracted corresponding to the data to be processed; wherein, the elliptic curve base points corresponding to the current participant and the first participant are the same; The data to be extracted is processed according to a pre-set extraction method to obtain the privacy intersection data.

4. The method according to claim 3, characterized in that, Also includes: Determine the random factor corresponding to the participating party; By performing bitwise operations on the random factor, the parameter factor corresponding to the participating party is determined.

5. The method according to claim 3, characterized in that, The data to be extracted includes horizontal and vertical coordinates corresponding to the data to be processed. The extraction and processing of the data to be extracted according to a pre-set extraction method to obtain the privacy intersection data includes: Based on the elliptic curve processing method corresponding to the base point of the elliptic curve, the horizontal or vertical coordinates of the data to be extracted are obtained to obtain the privacy intersection data.

6. The method according to claim 1, characterized in that, The method further includes: The first participant compresses the first privacy intersection data using a preset compression method to update the first privacy intersection data.

7. The method according to claim 1, characterized in that, After the current participant obtains the second privacy intersection data, the method further includes: The second privacy intersection data is sent to the first participant, so that the first participant processes the second privacy intersection data using the first parameter factor and the elliptic curve base point to obtain the second privacy intersection data, and then feeds it back.

8. The method according to claim 7, characterized in that, The first participant processes the second privacy intersection data using the first parameter factor and the elliptic curve base point to obtain the second privacy intersection data, including: Based on the elliptic curve base points, the second privacy intersection data is recovered to obtain data to be processed again. The data to be processed again is processed based on the first parameter factor to obtain the data to be applied; Extract data from the data to be applied to obtain the second privacy-sensitive intersection data.

9. The method according to claim 1, characterized in that, The process of processing the second privacy-sensitive intersection data based on the second parameter factor to obtain privacy-sensitive intersection data corresponding to the current participant includes: After the second privacy-defining intersection data is restored, the second parameter factor is used to process the restored second privacy-defining intersection data to obtain privacy-defining intersection data to be used.

10. The method according to claim 1, characterized in that, The step of determining the target shared data between the current participant and the first participant based on the first privacy intersection data and the privacy intersection data to be used includes: If the first privacy intersection data contains data identical to the privacy intersection data to be used, then the privacy intersection data to be used is determined to be data from the target shared data; or, If the privacy intersection data to be used contains data that is identical to the first privacy intersection data, then the privacy intersection data to be used is determined to be data in the target shared data.

11. The method according to claim 1, characterized in that, The amount of data involved in the privacy request by the first participant is greater than the amount of data involved in the privacy request by the current participant.

12. A privacy-based intersection device, characterized in that, include: The first data receiving module is used to receive the first privacy intersection data sent by the first participant, wherein the first privacy intersection data is the data extracted by the first participant after processing the first data to be intersected using a pre-set elliptic curve base point, and the first data to be intersected is obtained after processing the data corresponding to the first participant using a first parameter factor. The second data receiving module is used to receive the second privacy-defining intersection data fed back by the first participant, wherein the second privacy-defining intersection data corresponds to the current participant, and the second privacy-defining intersection data is the data obtained by the first participant after processing the second privacy-defining intersection data sent by the current participant using the first parameter factor; The data to be used determination module is used to process the second privacy intersection data based on the second parameter factor to obtain the privacy intersection data to be used corresponding to the current participant; wherein, the second participation factor corresponds to the current participant; The shared data determination module is used to determine the target shared data shared by the current participant and the first participant based on the first privacy intersection data and the privacy intersection data to be used.

13. An electronic device, characterized in that, The electronic device includes: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the privacy intersection method as described in any one of claims 1-11.

14. A storage medium comprising computer-executable instructions, which, when executed by a computer processor, are used to perform the privacy intersection method as described in any one of claims 1-11.