Data processing system and method
Through secret sharing and modular exponential technology, the problem of privacy leakage of intersection calculation in secure multi-party computing is solved, and data equality judgment and subsequent calculation are achieved without leaking intersection content, protecting user privacy.
Patent Information
- Application Number
- CN202011228474.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-06
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2040-11-06
AI Technical Summary
In the prior art, in the security multi-party computing, there is a risk of leaking the privacy of a single user when calculating intersections, resulting in security problems.
Through secret sharing and modular exponentiation technology, both parties A and B use secret sharing and segmentation of data, and use the same private key to perform modular exponentiation to determine whether the data is equal. The intersection calculation results are expressed in the form of secret sharing to ensure that both parties do not know the intersection content.
Without revealing the intersection content, the determination and subsequent calculation of the intersection between the two parties is realized by the security calculation, protecting user privacy, and is suitable for subsequent security calculations between the two parties such as modeling operations.
Smart Images

Figure CN114445208B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data processing, and in particular, to a data processing system and method. Background Art
[0002] Secure multi-party computation is a computing protocol in which multiple parties each provide an input and jointly compute an output. The feature of this protocol is that each party only knows its own input and the computed output, and has no knowledge of the inputs of any other party. For example, in the "millionaire problem": two parties each input their own wealth amounts, and finally calculate who has more wealth, without knowing any information about the other party's wealth value.
[0003] In the data cooperation between two organizations, Party A and Party B, using secure two-party computation, neither party can know the data content of the other party except for the computation result. However, in the prior art, it is often necessary to align data, that is, to calculate the common customers (user intersection) of both parties, and then perform data modeling on the intersection. However, the result of calculating the intersection actually reveals the privacy of individual users (for example, Party A discovers that Zhang San is also a user of Party B, but Zhang San may not consent to this information being known to Party A). Therefore, this method has a risk of security leakage.
[0004] Therefore, there is a need for an intersection calculation method that does not disclose intersection items. Summary of the Invention
[0005] One technical problem to be solved by the present disclosure is to provide an intersection calculation method that does not disclose intersection items. By cleverly utilizing the characteristics of modular exponentiation encryption, it is possible to determine the equality of data without disclosing the original data, enabling both parties in secure computation to not know the intersection content but be able to perform subsequent calculations on the intersection. According to the first aspect of the present disclosure, there is provided a data processing system, including Party A and Party B that respectively use data x and data y to participate in secure two-party computation. Among them, Party A performs modular exponentiation on a part of data x and a part of the obtained data y ; Party B performs modular exponentiation on another part of data x and another part of the obtained data y ; Party A performs secondary modular exponentiation on the modular exponentiation result obtained from Party B; Party B performs secondary modular exponentiation on the modular exponentiation result obtained from Party A; and multiply the x component and the y component in the secondary modular exponentiation results of Party A and Party B respectively, and determine whether x and y are equal according to the multiplication result. Among them, Party A and Party B respectively x and y each xPerform secret sharing splitting and perform modular exponentiation twice using the same private key respectively.
[0006] According to a second aspect of the present disclosure, there is provided a data processing method, including: taking modular exponentiation of a part of data and the acquired data; obtaining the result of a partner taking modular exponentiation of another part of the data and another part of the acquired data; performing secondary modular exponentiation on the modular exponentiation result obtained from the partner; obtaining the result of the partner performing secondary modular exponentiation on one's own modular exponentiation result; multiplying the x component and the y component in the secondary modular exponentiation results of both parties respectively, and determining whether x and y are equal according to the multiplication result. x and y and x and y are equal.
[0007] According to a third aspect of the present disclosure, there is provided a data processing method, including: Party A performs secret sharing splitting on entry X, where entry X includes a specific item and one or more first other items, and the value of the specific item x ; Party B performs secret sharing splitting on entry Y, where entry Y includes the specific item and one or more second other items, and the value of the specific item y ; both parties send secret sharing components to each other to obtain a secret sharing table to be processed that concatenates entry X and entry Y, and both parties run a two-party oblivious perturbation to shuffle the entry order in the secret sharing table to be processed to obtain a shuffled secret sharing table; Party A takes modular exponentiation of a part of data and the acquired data; Party B takes modular exponentiation of another part of the data and another part of the acquired data; Party A performs secondary modular exponentiation on the modular exponentiation result obtained from Party B; Party B performs secondary modular exponentiation on the modular exponentiation result obtained from Party A; multiplying the x component and the y component in the secondary modular exponentiation results of Party A and Party B respectively; combining the entries with equal multiplication results and deleting the entries without equal specific items to obtain an intersection secret sharing table composed of the combined entries. x and y and x component and the y component respectively; combining the entries with equal multiplication results and deleting the entries without equal specific items to obtain an intersection secret sharing table composed of the combined entries.
[0008] According to a fourth aspect of the present disclosure, there is provided a computing device, including: a processor; and a memory storing executable code thereon, which when executed by the processor causes the processor to execute the methods described in the second and third aspects above.
[0009] According to a fifth aspect of the present disclosure, there is provided a non-transitory machine-readable storage medium having executable code stored thereon, which when executed by a processor of an electronic device, causes the processor to execute the methods described in the second and third aspects above.
[0010] Thus, the present invention ingeniously utilizes the characteristics of modular exponentiation encryption and can determine the equality of data without revealing the original data. Further, the present invention determines the intersection items through secret sharing and modular exponentiation techniques, and the intersection calculation result can be represented in the form of secret sharing. Thus, it can be used for subsequent secure two-party computations, such as subsequent modeling operations, without either party knowing the content of the intersection. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] By describing the exemplary embodiments of the present disclosure in more detail in conjunction with the accompanying drawings, the above and other objects, features, and advantages of the present disclosure will become more apparent, wherein in the exemplary embodiments of the present disclosure, the same reference numerals generally represent the same components.
[0012] Figure 1 An example of secret sharing is shown.
[0013] Figure 2 A schematic diagram of the composition of a data processing system 200 according to an embodiment of the present invention is shown.
[0014] Figure 3 A flowchart of an operation for determining data equality according to the present invention is shown.
[0015] Figure 4 An example of determining data equality according to the present invention is shown.
[0016] Figure 5 An example of oblivious perturbation according to the present invention is shown.
[0017] Figure 6 A schematic flowchart of a data processing method according to an embodiment of the present invention is shown.
[0018] Figure 7 A flow example of a unilateral execution data processing method according to the present invention is shown.
[0019] Figure 8 A schematic diagram of the structure of a computing device that can be used to implement the above data processing method according to an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0020] The preferred embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the preferred embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.
[0021] Today, in the era of data explosion, people's demand for privacy protection is increasing day by day. Secure computing enables people to complete computing tasks while protecting data privacy. Secure computing, also known as Secure Multi-party Computation (SMC) for short, refers to achieving multi-party computing while protecting data security. As the name implies, multi-party computing means that multiple participants bring together their respective data, perform certain calculations on this large dataset, and obtain the final calculation result.
[0022] The simplest way to achieve multi-party computing is to find a trusted third party, aggregate multi-party data on the third-party server, and perform calculations. However, since the data is placed on the server in plaintext, the server operator can know the exact data of each participant, and it also increases the risk of the server itself being attacked by security threats.
[0023] To solve the above problems, secure multi-party computing can be used to still obtain the result of joint computing without each party having to tell the exact data to other parties (that is, the real data never leaves itself). For example, in large model training and large-scale statistics, since the computing tasks require data from multiple participants, but each participant often does not want (or is not allowed) to exchange or disclose the data, secure multi-party computing can be used to achieve the above training or statistics at this time.
[0024] In secure two-party computing, Party A and Party B cannot know the data content of the other party except for the calculation result. However, in the prior art, it is often necessary to align the data, that is, calculate the common customers (user intersection) of the two parties, and then perform data modeling on the intersection. However, the result of calculating the intersection actually reveals the privacy of individual users (for example, Party A discovers that Zhang San is also a user of Party B, but Zhang San may not agree that this information is known to Party A), so this method has security risks.
[0025] Therefore, the present invention proposes an intersection calculation method that does not disclose the intersection items. The intersection items are determined through secret sharing and modular exponentiation techniques, and the intersection calculation result is represented in the form of secret sharing. The two parties of secure computing do not know the content of the intersection, but can perform subsequent calculations on the intersection, such as subsequent modeling.
[0026] Specifically, Party A and Party B can split their respective data through secret sharing and use homomorphic encryption technology to determine whether the data is equal without revealing the data values. The data items used for determination can be user IDs, thereby realizing the merging of user information and subsequent calculations.
[0027] Here, the basic idea of Secret Sharing (SS) is to break each number x into multiple numbers x 1 ,x 2 ,…, x n and distribute these numbers to multiple participants S 1 , S 2 ,…, S n there. Then each participant only gets a part of the original data, and one or a few participants cannot restore the original data. Only when everyone puts their respective data together can the real data be restored. During the calculation, each participant directly uses the local data for calculation and exchanges some data at appropriate times (the exchanged data itself also looks random and does not contain information about the original data). After the calculation, the result is still dispersed among the participants in the form of secret sharing and certain data are combined when the result is finally needed. Thus, secret sharing ensures that each participant sees only some random numbers during the calculation process, but still calculates the desired result in the end.
[0028] Figure 1 Fig. shows an example of secret sharing. Suppose Party A has a secret number x and he wants to distribute it to S 1 , S 2 ,…, S n there. Then Party A first generates n -1 random numbers r 1 ,r 2 ,…, r n and then calculates the n number . Finally, Party A makes x 1 = r 1 ,x 2 = r 2 ,…, x n = r n and sends them to S 1 , S 2 ,…, S n . The above simple method has the following properties:
[0029] 1. Each digit x 1 ,x 2 ,…, x n is randomly distributed, and a single one or several of them do not disclose any information;
[0030] 2. When all x 1 ,x 2 ,…, x n are combined, it can be restored x , because ;
[0031] 3. This scheme has the property of additive homomorphism, that is, each participant can directly calculate the sum of the secret data without exchanging any data.
[0032] Suppose there is another party B, who also has a secret number y , and distributes the data to S 1 , S 2 ,…, S n together with Party A. To perform addition, S 1 can calculate z 1 = x 1 + y 1, S 2 can calculate z 2 = x 2 + y 2,…, S n can calculate z n = x n + y n . Each participant only operates on the local random numbers without exchanging data. According to the properties of secret sharing, it can be seen that: . That is to say, the secret sharing of z = x + y can be obtained, and the result of this summation can be kept hidden and continue to be used for other things. As described above in combination with Figure 1 describes a simple example of secret analysis, which satisfies additive homomorphism and ensures that only n participants can jointly unlock the data when all are combined.
[0033] Homomorphic encryption is a form of encryption that allows people to perform specific forms of algebraic operations on ciphertexts to obtain results that are still encrypted, and the results obtained by decrypting them are the same as the results of performing the same operations on the plaintext. In other words, this technology enables people to perform operations such as retrieval and comparison on encrypted data and obtain correct results without decrypting the data throughout the processing. Thus, it can truly and fundamentally solve the confidentiality problem when delegating data and its operations to a third party and is suitable for use in secure multi-party computing.
[0034] Homomorphic encryption can directly encrypt the original text and then perform various operations on the ciphertext to finally obtain the ciphertext of the result, which can be formally expressed as:
[0035] Therefore, with the help of homomorphic encryption, operating directly on the ciphertext and operating on the plaintext and then encrypting can achieve the same effect. A typical application scenario is: the data holder wants to perform calculations on a large amount of data in their possession, but they lack the computing resources and want to rely on the computing power of the cloud server to complete the calculation. If done in the conventional way, by transmitting the data to the cloud server and then running a pre-written program for calculation, sensitive data will be exposed on the cloud server. Homomorphic encryption can exactly solve such problems. Before transmitting the data, the data holder encrypts the data first. After receiving the data, the cloud server calculates as usual. Since the calculation is performed on the ciphertext, there will be no leakage of information in the cloud. After obtaining the result, the ciphertext of the result is returned to the data holder, and the data holder can decrypt it to obtain the final result.
[0036] Many well-known public-key encryption schemes actually have homomorphic properties, but they only support partial homomorphisms, that is, they only support addition or multiplication operations on ciphertexts and cannot perform both addition and multiplication. For example, the famous RSA encryption scheme supports homomorphic multiplication. In recent years, some encryption schemes can support (at least under certain conditions or operations) fully homomorphic encryption.
[0037] Here, when the encryption function is E and the plaintexts are x and y, additive homomorphism means that if there exists an efficient algorithm ⊕ such that E(x + y) = E(x) ⊕ E(y) or x + y = D(E(x) ⊕ E(y)) holds, and no x and y is leaked. Multiplicative homomorphism means that if there exists an efficient algorithm such that E(x × y) = E(x) E(y) or xy = D(E(x) E(y)) holds, and no x and y is leaked.
[0038] In the present invention, by ingeniously utilizing the characteristics of secret sharing and homomorphic encryption (especially modular exponentiation technology), it is possible to determine the equality of data without revealing the original data. Using the equality of the above data, the matching intersection of two parties can be obtained. The intersection data obtained by matching can be represented in the form of secret sharing and used for subsequent secure two-party computations, such as subsequent modeling operations, without either party knowing the content of the intersection.
[0039] Figure 2 FIG. 4 shows a schematic diagram of the composition of a data processing system 200 according to an embodiment of the present invention. As Figure 2 shown, the system 200 includes two parties participating in secure two-party computation: Party A 210 and Party B 220. Among them, Party A uses the entry X containing data x to participate in secure computation, and Party B uses the entry Y containing data y to participate in secure computation. The data x and y can be, for example, the ids of entries X and Y. The entry X used by Party A can include multiple entries each containing different ids. The entry Y used by Party B can also include multiple entries each containing different ids. By utilizing secret sharing and modular exponentiation technology, it is possible to determine that the ids of a certain entry X and a certain entry Y are the same without revealing the actual values of the ids themselves. Thus, data alignment can be performed based on the same id (i.e., the entries where the same id items are located are merged), and the resulting intersection data can be used for subsequent secure two-party computations, such as modeling operations.
[0040] Figure 3 FIG. 5 shows a flowchart of an operation for determining data equality according to the present invention. The operations of Party A and Party B based on the present invention will be described below in conjunction with Figure 3 . Here, the data x and the data y used for determining data alignment can be identification information that needs to be kept confidential from the other party. Specifically, the identification information can be the entry IDs included in the respective entries of Party A and Party B, such as identification data that can distinguish user identities, for example, the user's mobile phone number, etc. The above identification information needs to be kept confidential from the other party at all times. For example, ensure that although Zhang San's data can be used as intersection data, neither party knows that Zhang San's data is specifically used in the intersection data.
[0041] In step S310, Party A performs modular exponentiation on a part of the data x and a part of the obtained data y . Here, a part of the data y can be pre-sent by Party B to Party A. Similarly, Party A can send another part of the data x to Party B. In step S320, Party B performs modular exponentiation on another part of the data x and the obtained datay Another part calculates modular exponentiation. In step S330, Party A performs secondary modular exponentiation on the modular exponentiation result obtained from Party B. In step S340, Party B performs secondary modular exponentiation on the modular exponentiation result obtained from Party A. Subsequently, in step S350, the x components and y components are multiplied respectively, and based on the multiplication result, it is determined whether x and y are equal.
[0042] Here, steps S310 and S320 can be executed simultaneously or in reverse order. Similarly, steps S330 and S340 can also be executed simultaneously or in reverse order. Step S350 can be executed by either Party A or Party B, or a third party.
[0043] Before performing modular exponentiation calculation, both Party A and Party B need to split their respective data. Here, Party A performs secret sharing split on the data x to obtain a part of the x and another part of the x , for example, x 1 and x 2 as described below. Party B performs secret sharing split on the data y to obtain a part of the y and another part of the y , for example, y 1 and y 2 as described below.
[0044] Furthermore, Party A performs two modular exponentiation calculations using the same private key, such as the private key R1 as described below, and Party B performs two modular exponentiation calculations using the same private key, such as the private key R2 as described below. Thus, the exponents in the final multiplied components are equal to each other, for example, both are R1R2, so that it can be deduced whether x and y are equal based on whether the R1R2 powers of x and y are equal. At the same time, according to the discrete logarithm problem, the values of x and y themselves are hidden.
[0045] To further illustrate the principle of the present invention, Figure 4 shows an example of data alignment according to the present invention, and shows a specific data operation example of the Figure 3 shown steps.
[0046] To ensure the security of their respective data, Party A and Party B can split their respective data to conform to the required form of secret sharing. For this purpose, Party A 410 can split the data x into secret shares x 1 and x 2. Party B 420 can then split the data y into secret shares y 1 and y 2. Common splitting methods include additive secret sharing and multiplicative secret sharing. When using additive secret sharing, for example, it can be made such that x = x 1 +x 2, y = y 1 +y 2. However, in order to utilize modular exponentiation techniques later and hide the data x and y itself based on the discrete logarithm problem, multiplicative secret sharing needs to be adopted here. When using multiplicative secret sharing, it is made such that x = x 1 *x 2, y = y 1 * y 2.
[0047] Due to the nature of computer calculations and to avoid revealing the x and y values from their split values when the x and y values are small, multiplicative secret sharing in the form of x = x 1 *x 2 mod q , y = y 1 *y 2 mod q is usually also adopted. Thus, by performing a modulo operation on a larger value (for example, q can be equal to a known fixed value, a large fixed value such as 2 to the 64th power), the x 1, x 2, y 1, y 2 can each have a larger range of values, thereby enhancing the randomness of the values. For this purpose, although the part of "mod Figure 3 " is not shown in q for display convenience, it should be understood that for ensuring randomness and the natural properties of computer data processing, the split in Figure 3 can be understood as x = x 1 *x 2 mod q , y = y 1 *y 2 mod qin the form where q can be equal to a known fixed value, such as 2 to the power of 64.
[0048] Party A and Party B can each send a part of the segmented data in their respective data to the other party for processing. Specifically, Party B can send the generated y 1 to Party A. Party A can send the generated x 2 to Party B. At this time, Party A holds x 1 and y 1, and Party B holds x 2 and y 2. Therefore, after the first data exchange, both parties hold data that meets the requirements of secret sharing.
[0049] Party A uses the private key R1 to perform modular exponentiation on x 1 and y 1 to obtain x 1 R1 and y 1 R1 and sends the obtained x 1 R1 and y 1 R1 to Party B. Party B uses the private key R2 to perform modular exponentiation on x 2 and y 2 to obtain x 2 R2 and y 2 R2 and sends the obtained x 2 R2 and y 2 R2 to Party A. Here, the private keys R1 and R2 can be random numbers generated by Party A and Party B respectively in any way, or at least numbers that the other party cannot know.
[0050] At this time, after the second data exchange, Party A holds x 1 and y 1, as well as x 2 R2 and y 2 R2 . Party B holds x 2 and y 2, as well as x 1 R1 and y 1 R1 . Since the private keys R2 and R1 belong to the other party respectively, and based on the discrete logarithm problem, both parties hold data that meets the requirements of secret sharing.
[0051] Party A can use the private key R1 for the x 2 R2 and y 2 obtained from Party BR2 Obtain the modular exponentiation to get x 2 R2R1 and y 2 R2R1 Party B can use the private key R2 for the obtained from Party A x 1 R1 and y 1 R1 Obtain the modular exponentiation to get x 1 R1R2 and y 1 R1R2 .
[0052] Subsequently, at least one party obtains the components obtained by the other party x 2 R2R1 and y 2 R2R1 or x 1 R1R2 and y 1 R1R2 , and multiply them to get:
[0053] x 2 R2R1 * x 1 R1R2 = ( x 1 * x 2) R1R2 = x R1R2 , and
[0054] y 2 R2R1 * y 1 R1R2 = ( y 1 * y 2) R1R2 = y R1R2 .
[0055] According to x R1R2 and y R1R2 's comparison result, determine x and y whether they are equal
[0056] For example, the components that both parties can obtain through interaction x 2 R2R1 and y 2 R2R1 and x 1 R1R2 and y 1 R1R2 , or the party that executes the subsequent secure two-party computation (e.g., Party A) can obtain Party B's computation result x 1R1R2 and y 1 R1R2 Thus, by aggregating the modular exponentiation components of both parties, data can be x and y transformed into x R1R2 and y R1R2 while always conforming to the secret sharing form, and it is possible to determine whether x R1R2 and y R1R2 are equal based on the comparison result of x and y . Thus, subsequent operations, such as data alignment operations, can be performed based on the determination that x and y are equal.
[0057] Here, modular exponentiation is a power operation on a modulus and has advantages in computer science, especially in public key cryptography. Modular exponentiation refers to the process of finding the remainder c when the e - th power b e of an integer b is divided by a positive integer m, which can be represented by the mathematical symbol c = b e mod m. From the definition of c, it follows that 0 ≤ c < m. For example, given b = 5, e = 3, and m = 13, 53 = 125 divided by 13 gives a remainder c = 8. Even when the integers are very large, the above - mentioned modular exponentiation is actually easy to perform. However, calculating the discrete logarithm of the modulus (i.e., finding the exponent e when b, c, and m are known) is more difficult. This behavior similar to a one - way function makes modular exponentiation applicable to encryption algorithms.
[0058] In the present invention, through multiplicative modular exponentiation sharing and modular exponentiation techniques as a specific implementation in multiplicative homomorphic encryption, it is possible to achieve a high level of private key (R1 and R2) security with a small amount of computation, thus ensuring the security of shared data. In addition, when calculating the modular exponentiation in the present invention, although only the exponent calculation is shown in the text, the process of finding the remainder is also included in each calculation. For example, it was described above that Party A uses the private key R1 to perform modular exponentiation on x 1 and y 1 to obtain " x 1 R1 and y 1 R1 ", but in actual operation, the modular exponentiation results in x 1 R1 mod m and y 1 R1 mod m. Here, the value of m can be a fixed large number, such as 2 to the 128th power.
[0059] In actual use, the data provided by Party A for cooperation usually x includes multiple pieces of data x , and the data provided by Party B for cooperation y includes multiple pieces of data y . At this time, the system can calculate the quadratic modulus power of each component of each piece of data x and each piece of data y , and determine whether a certain piece of data x is equal to a certain piece of data y according to whether the product of the quadratic modulus powers of the respective components of each piece of data is equal.
[0060] Specifically, Party A can divide each of the multiple pieces of data for cooperation x into their respective x 1* x 2, and Party B can divide each of the multiple pieces of data for cooperation y into their respective y 1* y 2. The system can calculate the x and each piece of data y of x R1R2 and y R1R2 , and determine whether a certain piece of data x R1R2 and y R1R2 is equal to a certain piece of data x according to whether their values are equal. y
[0061] For example, the data provided by Party A for cooperation x can include four pieces of data, a1, a2, a3, and a4, and the data provided by Party B for cooperation y can include four pieces of data, b1, b2, b3, and b4. At this time, both Party A and Party B can perform the operations shown in Figure 3 on their respective data, a1, a2, a3, a4, and b1, b2, b3, b4, to obtain a1 R1R2 , a2 R1R2 , a3 R1R2 , and a4 R1R2 , as well as b1 R1R2 , b2 R1R2 , b3 R1R2 , and b4 R1R2 . Subsequently, it can be determined whether the modulus power values of a and b are the same. For example, if a2 R1R2 = b3 R1R2 and a3 R1R2 = b4 R1R2 , it can be determined that a2 = b3 and a3 = b4, and subsequent operations can be performed. For example, when data x and y represent the id values of their respective entries, a2 = b3 can indicate that the entries to which a2 belongs and the entries to which b3 belongs are entries pointing to the same object, and a3 = b4 can indicate that the entries to which a3 belongs and the entries to which b4 belongs are entries pointing to the same object. Therefore, the above entries can be merged, for example, for subsequent secure two-party computations such as modeling operations.
[0062] Specifically, data x is the value of a specific item in entry X, and data y is the value of the same item in entry Y. And when it is determined that x and y are equal, the other items in entry X and entry Y are merged to obtain a concatenated intersection entry. For example, based on the merging of entries with the same id value. The other items in the concatenated intersection entry also need to be held by Party A and Party B in a secret sharing manner.
[0063] At this time, Party A needs to perform secret sharing splitting on each item in entry X, which includes secret sharing splitting data x into x = x 1* x 2, and also includes the splitting of other items, such as additive secret splitting or multiplicative secret splitting. At the same time, Party B also needs to perform secret sharing splitting on each item in entry Y, which includes secret sharing splitting data y into y = y 1* y 2, and also includes the splitting of other items, such as additive secret splitting or multiplicative secret splitting.
[0064] The two parties exchange the secret sharing components obtained by splitting, so that Party A and Party B each hold a secret sharing table to be processed with the secret sharing components of entry X and entry Y concatenated. Here, it includes the exchange of the secret sharing components of data x and y , and also includes the exchange for other items.
[0065] Furthermore, since the order of each entry in the concatenated secret sharing table to be processed is known, for example, eight pieces of data including a1, a2, a3, a4, b1, b2, b3, b4 sorted by source order, even if the values of data x and y are hidden through modular exponentiation techniques, the sorting positions of each entry will still expose the entries where the matching intersections are located.
[0066] To this end, both parties need to run a two-party oblivious shuffle to scramble the entry order in the to-be-processed secret sharing table. After obtaining the secret sharing table with the scrambled order, the modular exponentiation operations of R1 and R2 for the data x and y are then performed. Oblivious shuffle is an algorithm whose pattern of module movement and calculation operations does not leak any information about the actual permutation to the server. In other words, by running a two-party oblivious shuffle, neither Party A nor Party B will know the order of the entries after the perturbation.
[0067] Any oblivious shuffle algorithm can be used to achieve the perturbation. In the present invention, in particular, a method of reordering data (for example, random sorting) by Party A and Party B respectively when the other party holds the private key can be used for oblivious shuffle.
[0068] Figure 5 An example of oblivious shuffle according to the present invention is shown. The operations of Party A and Party B based on the present invention will be described below in conjunction with Figure 5 .
[0069] To ensure the security of their respective data, Party A and Party B can split their respective data to conform to the required form of secret sharing. To this end, Party A 510 can split the data x into secret shares x 1 and x 2. Party B 520 can then split the data y into secret shares y 1 and y 2. Common splitting methods include additive secret sharing and multiplicative secret sharing. For subsequent modular exponentiation operations, multiplicative secret sharing needs to be adopted. When adopting multiplicative secret sharing, make x = x 1 *x 2, y = y 1 *y 2. For other items in entries X and Y, additive secret sharing can also be adopted. For example, make x = x 1 +x 2, y = y 1 +y 2.
[0070] It should also be understood that the illustrated x = x 1 *x 2, y = y 1 *y 2 can actually refer to x = x 1 *x 2 mod q , y = y 1 *y 2 mod qMultiplicative secret sharing in the form. Thus, by performing a modulo operation on a relatively large value (e.g., q can be equal to a known fixed value, a relatively large fixed value, such as 2 to the power of 64), it is possible to increase x 1, x 2, y 1, y 2's respective value ranges, thereby enhancing the randomness of the values. At this time, q can be equal to a known fixed value, such as 2 to the power of 64.
[0071] Party A and Party B can each send a part of the divided data in their respective data to the other party for processing. Specifically, Party B can send the generated y 1 to Party A. Party A can send the generated x 2 to Party B. At this time, Party A holds x 1 and y 1, and Party B holds x 2 and y 2. Therefore, both parties hold data that meets the requirements of secret sharing.
[0072] After Party A obtains y 1, it can perform homomorphic encryption on x 1 and y 1 to obtain Enc( x 1) and Enc( y 1). Here, Party A's homomorphic encryption of x 1 and y 1 needs to be in the same form as the division of x 1 and x 2 and y 1 and y 2. When using multiplicative secret sharing for division, corresponding multiplicative homomorphic encryption needs to be performed. In the example of Figure 4 , any known or future-discovered multiplicative homomorphic encryption function can be used to perform homomorphic encryption on x 1 and y 1.
[0073] It is possible to perform homomorphic encryption on x 1 and y 1 using the first private key to obtain Enc( x 1) and Enc( y 1). Generally, the same secret sharing division method needs to be used for x and y . At this time, Party A also performs the same type of homomorphic encryption on x 1 and y 1. For example, it is possible to perform operations on x and yUsing multiplicative secret sharing division, Party A can perform multiplicative homomorphic encryption on x 1 and y 1. Since Party A needs to decrypt the data containing x and y randomly sorted by Party B later, for x 1 and y 1, the same multiplicative homomorphic encryption method needs to be used, and the same key is used to encrypt x 1 and y 1. As can be seen from the above, the "first private key" is used here to represent the same key held by Party A for performing homomorphic encryption on x 1 and y 1.
[0074] After obtaining Enc( x 1) and Enc( y 1), Party A can send them to Party B. At this time, Party B holds Enc( x 1) and Enc( y 1) as well as x 2 and y 2. Since Party B does not know the first private key held by Party A, Party B does not know the data x and the data y itself.
[0075] After obtaining Enc( x 1) and Enc( y 1), Party B can perform homomorphic operations on Enc( x 1) and x 2 as well as Enc( y 1) and y 2 respectively. Similarly, the homomorphic operations performed at this time need to be in the same form as the division of x 1 and x 2 as well as y 1 and y 2. When using multiplicative secret sharing for division, corresponding multiplicative homomorphic operations need to be performed. In the example of Figure 4 , Enc( x 1) and x 2 as well as Enc( y 1) and y 2 can be multiplied respectively. According to the definition of multiplicative homomorphism, Enc( x ) = Enc( x 1) *x 2 and Enc( y ) = Enc( y 1) *y 2 can be used to obtain Enc( x) and Enc( y ).
[0076] Subsequently, Party B can randomly sort Enc( x ) and Enc( y ), and send Enc( x ) and Enc( y ) that meet the requirements of secret sharing to Party A, that is, send Enc( x ) and Enc( y ) that are each operated with a random number unknown to Party A. Specifically, Party B can send the first operation result of the division operation of the shuffled Enc( x ) and Enc( y ) with the random numbers R and S to Party A.
[0077] In a specific implementation, Party B can first shuffle the order of Enc( x ) and Enc( y ), and then perform the division operation with the random numbers, or can first perform the division operation and then shuffle the order of the shuffled Enc( x ) and Enc( y ). In either case, Party B can obtain the first operation result of the division operation of the shuffled Enc( x ) and Enc( y ) with the random numbers R and S. At this time, Party B knows the order of the shuffled Enc( x ) and Enc( y ), and knows the correspondence between the random numbers R and S and Enc( x ) and Enc( y ). In the example of Figure 4 , for example, after random sorting, Enc( x ) is still in the front and Enc( y ) is in the back. At this time, Enc( x ) / R and Enc( y ) / S can be used as the first operation result and sent to Party A.
[0078] After obtaining the first operation result, Party A can use the first private key that encrypted Enc( x 1) and Enc( y 1) before to decrypt the first operation result, and obtain the second operation result of the division operation of R and S with the shuffled x and y respectively. For example, Party A obtains Enc( x ) / R and Enc( y ) / S. According to the properties of homomorphic encryption, when using the one for Enc( x 1) and Enc(y After decrypting the encrypted first private key, one can obtain x / R and y / S. At this time, Party A holds x / R and y / S, but does not know the order of x / R and y / S, that is, does not know which of the relevant data of x and y is in the front and which is in the back. And Party B knows which of the relevant data of x and y is in the front and which is in the back, that is, Party B knows that what Party A decrypts to obtain is x / R and y / S, and at the same time Party B holds R and S.
[0079] Up to this point, Party A holds x / R and y / S, Party B holds R and S, and both parties still hold the x and y in the form of secret sharing. The difference is that at this time, Party A no longer knows the order of x and y (but Party B knows).
[0080] In addition, it should be understood that although the form of random numbers R and S is used for representation here, as can be seen from the definition of secret sharing combined above, the operation of Party B sending Enc( x ) / R and Enc( y ) / S back to Party A and holding R and S can be regarded as performing another additive secret splitting on x and y . For example, it can be set that x / R = x 3, y / S = y 3, R = x 4, S = y 4. At this time, x = x 3 *x 4, y =y 3 *y 4. Further, x = x 3 *x 4 mod q , y = y 3 *y 4 mod q .
[0081] Subsequently, only by swapping the roles of Party A and Party B and running the above steps again can a new set of x and yThe form of secret sharing, where neither Party A nor Party B knows x and y the order.
[0082] Specifically, Party B can homomorphically encrypt R and S using the second private key to obtain Enc’(R) and Enc’(S), and send them to Party A. Here, “’” represents the encryption not used by Party A with the first key.
[0083] Party A obtains Enc’(R) and Enc’(S), and performs the multiplication operation on Enc’(R) and Enc’(S) and the second operation result to obtain the shuffled Enc’( x ) and Enc’( y ). In Figure 4 the example of x ), Enc’( y ) can be multiplied by x / R and y / S, which are used as the second operation result, respectively, to obtain Enc’( x ) = Enc’(R) * x / R, Enc’( y ) = Enc’(S) * y / S.
[0084] Subsequently, Party A generates the third operation result of dividing the doubly shuffled Enc’( x ) and Enc’( y ) by the random numbers M and N. Similar to the previous random sorting by Party B, in specific implementation, Party A can first shuffle the order of Enc’( x ) and Enc’( y ), and then perform the division operation with the random numbers, or first perform the division operation and then shuffle the order of the Enc’( x ) and Enc’( y ) after the operation. For this purpose, Party A randomly shuffles the order of Enc’( x ) and Enc’( y ), and generates two random numbers M and N; Party A divides M and N by the shuffled Enc’( x ) and Enc’( y ) respectively, and sends the generated third operation result back to Party B, or Party A generates random numbers M and N, and divides M and N by Enc’( x ) and Enc’( y ) respectively; Party A randomly shuffles the order of Enc’( x ) and Enc’( y ) after the second operation.
[0085] In either case, Party A can obtain the third operation result of the division of the secondarily scrambled Enc’( x ) and Enc’( y ) by the random numbers M and N. At this time, Party A knows how Enc’( x ) and Enc’( y ) are secondarily sorted on its own side, and knows the correspondence between the random numbers M and N and Enc’( x ) and Enc’( y ). In the example of Figure 3 , for example, after random sorting, Enc’( y ) is in the front and Enc’( x ) is in the back. At this time, Enc’( y ) / M and Enc’( x ) / N can be sent to Party B as the third operation result.
[0086] Party B decrypts the third operation result using the second private key to obtain the fourth operation result of the division of M and N by the secondarily scrambled x and y respectively. For example, Party B obtains Enc’( y ) / M and Enc’( x ) / N as shown in the figure. According to the properties of homomorphic encryption, after decrypting using the second private key encrypted for Enc’(R) and Enc’(S), y / M and x / N can be obtained. At this time, Party A holds M and N. Although it knows how M and y / M and x / N are shuffled in the secondary random sorting, it does not know the order of x / R and y / S in the initial random sorting by Party B; Party B holds y / M and x / N, but does not know the order of y / M and x / N.
[0087] At this point, Party A holds M and N, and Party B holds y / M and x / N. Both parties still hold the secret sharing form of x and y , and at this time, neither Party A nor Party B knows the order of x and y (so they have performed random sorting while keeping the private keys of each other).
[0088] In addition, it should also be understood that although the random numbers M and N are used for representation here, as can be seen from the definition of secret sharing combined above, Party A sends Enc’( y ) / M and Enc’( x ) / N back to Party B and holds M and N. This operation can be regarded as performing another additive secret splitting on x and y . For example, it can be set that y / M = x 5, x / N = y 5, M = x 6, N = y 6. At this time, x= x 5 *x 6, y = y 5 *y . Further, x = x 5 *x 6 mod q , y = y 5 *y 6 mod q . Since the modular exponentiation process shown in Figure 4 is performed on the shuffled secret sharing table after the oblivious perturbation, Party A can directly use the held M and N as Figure 4 shown x 1 and y 1 (shuffled), and Party B can directly use y / M and x / N as Figure 4 shown x 2 and y 2 (shuffled).
[0089] Thus, Figure 5 's example cleverly utilizes the characteristics of secret sharing and homomorphic encryption. When Party A and Party B process data separately, the private key of the data is held by the other party, so that the confidentiality of the data will not be affected when both parties process the data separately. Further, by randomly shuffling the data once by each of Party A and Party B, the final order is the superposition of the random sorting results of both parties, thus ensuring that neither party knows the order of the data.
[0090] The above oblivious perturbation scheme does not limit the specific secret sharing scheme and homomorphic scheme. For example, Figure 5 the multiplicative homomorphism shown can also be replaced with an additive homomorphism. For example, other items in the entry except x and y can perform additive secret sharing and additive homomorphic encryption. At this time, only the secret sharing scheme needs to be correspondingly replaced with a multiplicative secret sharing, that is, x= x1 + x 2, y = y 1 + y 2, and further, x = x 1 + x 2 mod q , y = y 1 + y 2 mod q . Subsequently, it can respectively have x- R, y- S, y- M, x- N and other forms.
[0091] In actual use, if it only includes one piece of data from Party A x and one piece of data from Party B y , then even after two - party perturbation, its sorting result has only two cases: x in the front y in the back, or y in the front x in the back. Obviously, the random sorting method of the present invention can more prominently show its function of perturbing and hiding the sorting when both Party A and Party B include multiple pieces of data. For this reason, assume that the data provided by Party A for cooperation x includes multiple pieces of data x , and the data provided by Party B for cooperation y includes multiple pieces of data y .
[0092] At this time, Party A can divide the multiple pieces of data for cooperation x into their respective x 1 and x 2, and Party B can divide the multiple pieces of data for cooperation y into their respective y 1 and y 2. When performing the initial perturbation, further, generate the first operation result of dividing the shuffled Enc( x ) and Enc( y ) by the random numbers R and S, including: for each piece of data included in Enc( x ) and Enc( y ), randomly generate random numbers for division operation respectively. Generate the third operation result of dividing the second - shuffled Enc’( x ) and Enc’( y ) by the random numbers M and N, including: for Enc’( x ) and Enc’( y) For each piece of data contained therein, a random number is generated randomly for division operation. This ensures that the random numbers for each piece of data are generated separately. In other words, Party B can randomly shuffle multiple Enc( x ) and Enc( y ) so that the data from both parties are mixed and randomly sorted. When performing the second perturbation, Party A can make the two-party data that has been mixed and randomly sorted be randomly mixed and sorted again, thus hiding the sorted data from both parties.
[0093] For example, the data used by Party A for cooperation x can include four pieces of data, a1, a2, a3, and a4, and the data used by Party B for cooperation y can include four pieces of data, b1, b2, b3, and b4. At this time, both Party A and Party B can first perform secret sharing and splitting on their respective data a1, a2, a3, a4 and b1, b2, b3, b4. Through the homomorphic encryption of part of the data by Party A and the random sorting and random number operation of the encrypted data by Party B, the first operation result is obtained. For example, after the first perturbation by Party B, the order of the data changes from being sorted in the order of origin a1, a2, a3, a4, b1, b2, b3, b4 to b2, a4, b4, a2, a1, b1, b3, a3, and each of the 8 changed data is divided by a random number (corresponding to R and S) whose size and order are known to Party B. Subsequently, through the second random perturbation by Party A, the order of the data can change from b2, a4, b4, a2, a1, b1, b3, a3 to b1, b2, a3, a2, a1, b3, a4, b4, and each of the 8 changed data is divided by a random number (corresponding to M and N) whose size and order are known to Party A.
[0094] For the final sorting, for example, for b1, b2, a3, a2, a1, b3, a4, b4 obtained after the second random sorting, since Party B only knows its first random sorting and Party A only knows the second random sorting based on the first random sorting, neither Party A nor Party B knows the order of the final sorting, thus perfectly hiding the order of the cooperation data. In normal cooperation, the amount of data input by both Party A and Party B is usually not a single digit, but for example, thousands, tens of thousands, or even higher-order numbers of data entries. Therefore, the random sorting result at this time is used for a more powerful non-retraceability, thus avoiding the leakage of the data order relationship.
[0095] Thus, the system can use M and N held by Party A and the fourth operation result held by Party B respectively to perform the modular exponentiation operation as Figure 3 shown to find the intersection entries, and the obtained intersection secret sharing table can be used for subsequent secure two-party calculations, such as model training on the cloud held by Party A, etc.
[0096] The present invention can also be implemented as a data processing method performed by Party A or Party B with the cooperation of the other party. Figure 6 FIG. shows a schematic flowchart of a data processing method according to an embodiment of the present invention. This method can be executed by Party A. However, since the execution steps of both parties are symmetric, it can also be regarded as being executed by Party B. In the case of Party A's execution, Party A is the self-party and Party B is the cooperation party.
[0097] In step S610, modular exponentiation is performed on a part of the data x and a part of the acquired data y In step S620, the result of the cooperation party performing modular exponentiation on another part of the data x and another part of the acquired data y is obtained. In step S630, the modular exponentiation result obtained from the cooperation party is subjected to secondary modular exponentiation. In step S640, the result of the cooperation party performing secondary modular exponentiation on the modular exponentiation result of the self-party is obtained. In step S650, the x component and the y component in the secondary modular exponentiation results of both parties are multiplied respectively, and based on the multiplication result, it is determined whether x and y are equal.
[0098] To further illustrate the operation of a single party, Figure 7 FIG. shows a flow example of a single-party execution data processing method according to the present invention, and shows a specific data operation example of the steps Figure 6 shown.
[0099] In step S710, the data x is secretly shared and split into x = x 1* x 2. In step S720, the secretly shared components obtained by splitting are exchanged with the cooperation party, so that the self-party holds x 1 and y 1, and the cooperation party holds x 2 and y 2. In step S730, modular exponentiation is performed on x 1 and y 1 using the private key R1 to obtain x 1 R1 and y 1 R1 , and the obtained x 1 R1 and y 1 R1 are sent to the cooperation party. In step S740, the result of the cooperation party performing modular exponentiation on x 2 and y 2 using the private key R2 to obtain x 2R2 and y 2 R2 。In step S750, use the private key R1 to perform modular exponentiation on the x 2 R2 and y 2 R2 obtained from the partner to get x 2 R2R1 and y 2 R2R1 。In step S760, obtain the result of the partner using the private key R2 to perform modular exponentiation on the x 1 R1 and y 1 R1 obtained from itself to get x 1 R1R2 and y 1 R1R2 。In step S770, multiply the components x 2 R2R1 and y 2 R2R1 as well as x 1 R1R2 and y 1 R1R2 respectively to get:
[0100] x 2 R2R1 * x 1 R1R2 = ( x 1* x 2) R1R2 = x R1R2 ,and
[0101] y 2 R2R1 * y 1 R1R2 = ( y 1* y 2) R1R2 = y R1R2 。
[0102] In step S780, based on the comparison result of x R1R2 and y R1R2 , determine whether x and y are equal.
[0103] Figure 7 The process shown can be regarded as Figure 6Refinement of the shown process, and the above steps S710 - S730 can be regarded as sub - steps 1 - 3 of step S610, steps S740 - S760 correspond to steps S620 - S640, and steps S770 - S780 can be regarded as sub - steps 1 - 2 of step S650.
[0104] Under normal circumstances, the data x includes multiple pieces of data x , and the data y includes multiple pieces of data y . Thus, the party itself and the partner obtain each piece of data x and each piece of data y 's x R1R2 and y R1R2 , and based on whether the values of x R1R2 and y R1R2 of each piece of data are equal, determine whether a certain piece of data x is equal to a certain piece of data y .
[0105] Under normal circumstances, the data for cooperation x and the data y belong to item X and item Y respectively. For this reason, the method further includes: when determining that x and y are equal, merge at least some of the other items in item X and item Y to which the data x and the data y belong, to obtain the merged item. For example, item X may include the ID item represented by the data x , and feature A. Item Y may include the ID item represented by the data y , and feature B and label L. When determining that x and y are equal, item X and Y can be merged. At this time, the merged item may include the ID item, feature A item, feature B item, and label L item, but each item in the merged item needs to be held by the party itself and the partner in a secret - sharing manner.
[0106] Furthermore, in the case of item sharing, split the secret sharing of the data x into x = x 1 * x 2 includes: performing secret - sharing splitting on each item in item X. Exchange the secret - sharing components obtained by splitting with the partner, so that the party itself holds x 1 and y 1, and the partner holds x 2 andy 2 includes: exchanging the split secret sharing components with the partner, and both the local party and the partner hold the to-be-processed secret sharing table spliced with entry X and entry Y's secret sharing components.
[0107] Further, the method may further include: running a two-party oblivious perturbation (e.g., Figure 5 the shown oblivious perturbation) with the partner to shuffle the entry order in the to-be-processed secret sharing table to obtain the shuffled secret sharing table. The merged entries form the intersection secret sharing table for both the local party and the partner to respectively utilize data x and data y to participate in secure two-party computation.
[0108] The present invention may also be implemented as a data processing method for constructing an intersection secret sharing table. The method includes: the first party secret sharing and splitting entry X, where entry X includes a specific item and one or more first other items, and the value of the specific item x (e.g., x can be split into x = x 1 * x 2); the second party secret sharing and splitting entry Y, where entry Y includes the specific item and one or more second other items, and the value of the specific item y (e.g., y can be split into y = y 1 * y 2); both parties send the secret sharing components to each other to obtain the to-be-processed secret sharing table spliced with entry X and entry Y; both parties run a two-party oblivious perturbation to shuffle the entry order in the to-be-processed secret sharing table to obtain the shuffled secret sharing table.
[0109] Subsequently, the first party calculates the modular exponentiation of a part of data x and the obtained data y ; the second party calculates the modular exponentiation of another part of data x and the obtained data y ; the first party performs a secondary modular exponentiation on the modular exponentiation result obtained from the second party; the second party performs a secondary modular exponentiation on the modular exponentiation result obtained from the first party; multiply the x component and the y component in the secondary modular exponentiation results of both the first party and the second party respectively; merge the entries with equal multiplication results and delete the entries without equal specific items to obtain the intersection secret sharing table composed of the merged entries.
[0110] If described using data representation, the above data alignment operation can be specifically implemented as: the first party uses the private key R1 forx 1 and y 1 takes the modular exponentiation to get x 1 R1 and y 1 R1 , and sends the obtained x 1 R1 and y 1 R1 to Party B; Party B uses the private key R2 for x 2 and y 2 takes the modular exponentiation to get x 2 R2 and y 2 R2 , and sends the obtained x 2 R2 and y 2 R2 to Party A; Party A uses the private key R1 for the x 2 R2 and y 2 R2 takes the modular exponentiation to get x 2 R2R1 and y 2 R2R1 ; Party B uses the private key R2 for the x 1 R1 and y 1 R1 takes the modular exponentiation to get x 1 R1R2 and y 1 R1R2 ; The two parties exchange the held components x 2 R2R1 and y 2 R2R1 as well as x 1 R1R2 and y 1 R1R2 , and multiply to get:
[0111] x 2 R2R1 * x 1 R1R2 = ( x 1 * x 2) R1R2 = x R1R2 , and
[0112] y 2 R2R1 * y 1 R1R2 = ( y 1 * y 2) R1R2 =y R1R2 ;
[0113] merge x R1R2 and y R1R2 If the entries are equal, the entries without equal specific items are deleted to obtain an intersection secret sharing table consisting of the merged entries. Thus, the intersection secret sharing table can be used for the own party and the partner to each use data x and data y Participatory secure two-party computation.
[0114] For the purpose of merging entries, the first other entry should be different from the second other entry. That is, entry X and entry Y include data other than x and y To this end, the generation of the secret sharing table to be processed includes the expansion of entries. In the secret sharing table to be processed: entry X includes the specific item, the first other item and the expanded second other item; entry Y includes the specific item, the expanded first other item and the second other item, and the expanded item value is zero or empty.
[0115] Typically, the entry X includes multiple entries X, each of which includes a specific item and one or more first other items, and the value of each specific item is x are different; and the entry Y includes multiple entries Y, each entry Y includes a specific item and one or more second other items, and the value of each specific item y All different.
[0116] Figure 8 A schematic diagram of the structure of a computing device that can be used to implement the above data processing method according to an embodiment of the present invention is shown.
[0117] See also Figure 8 , the computing device 800 includes a memory 810 and a processor 820 .
[0118] The processor 820 may be a multi-core processor or may include multiple processors. In some embodiments, the processor 820 may include a general-purpose main processor and one or more special coprocessors, such as a graphics processing unit (GPU), a digital signal processor (DSP), etc. In some embodiments, the processor 820 may be implemented using a customized circuit, such as an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA).
[0119] The memory 810 may include various types of storage units, such as system memory, read-only memory (ROM), and permanent storage devices. Among them, the ROM can store static data or instructions required by the processor 820 or other modules of the computer. The permanent storage device can be a readable and writable storage device. The permanent storage device can be a non-volatile storage device that does not lose the stored instructions and data even when the computer is powered off. In some embodiments, the permanent storage device employs a mass storage device (such as a magnetic or optical disk, flash memory) as the permanent storage device. In some other embodiments, the permanent storage device can be a removable storage device (such as a floppy disk, optical drive). The system memory can be a readable and writable storage device or a volatile readable and writable storage device, such as dynamic random access memory. The system memory can store some or all of the instructions and data required by the processor during operation. In addition, the memory 810 can include any combination of computer-readable storage media, including various types of semiconductor storage chips (DRAM, SRAM, SDRAM, flash memory, programmable read-only memory), and magnetic disks and / or optical disks can also be used. In some embodiments, the memory 810 can include a removable storage device that is readable and / or writable, such as a compact disc (CD), read-only digital versatile disc (such as DVD-ROM, dual-layer DVD-ROM), read-only Blu-ray disc, super density disc, flash memory card (such as SD card, min SD card, Micro-SD card, etc.), magnetic floppy disk, and so on. Computer-readable storage media do not include carrier waves and instantaneous electronic signals transmitted wirelessly or by wire.
[0120] Executable code is stored on the memory 810, and when the executable code is processed by the processor 820, it can cause the processor 820 to execute the data processing method described above.
[0121] [Application Example]
[0122] For ease of understanding, assume that Party A has 2 users {Id1, Id2}, and Party B has 2 users {Id2, Id3}, and Id2 is their common customer.
[0123] Party A and Party B have characteristics from different perspectives of the users. Specifically, Party A has the characteristic F_A, and Party B has the characteristic F_B and the label L_B.
[0124] Taking A as a shopping website and B as a bank as an example, F_A can be the shopping preferences of the user, F_B can be the transfer records of the user, and L_B can be a credit loss label indicating whether the user has defaulted on a loan.
[0125] The purpose of Party A and Party B is to find the common customer ID2, align the data {Id2, F_A2, F_B2, L_B2}, and then perform modeling on the aligned data to judge the loan default situation of users. For example, model training can be carried out using the aligned data {Id2, F_A2, F_B2, L_B2} to obtain a certain correspondence between F_A and loan default. Subsequently, Party A can, based on the results of model training, determine whether a user has the risk of loan default by simply analyzing the shopping preferences of a certain user.
[0126] In the prior art, the difficulty in the above modeling is that id2 is the privacy information of users, and users may not want others to know that they are the common customers of both parties. Therefore, it is necessary to use the data processing method of the present invention to obtain the intersection data table without disclosing the intersection for subsequent secure two-party computation.
[0127] The specific steps are as follows:
[0128] 1. First, Party A gives the items X for cooperation, which includes two items here, Id1 and Id2. Here, Id can be an identifier that can identify the user's identity, such as a mobile phone number. In other words, users who register for shopping websites and banks using the same mobile phone can be regarded as the same user. And the data used by Party A for cooperation is as follows:
[0129]
[0130] Correspondingly, Party B gives the items Y for cooperation, which includes two items here, Id2 and Id3. And the data used by Party B for cooperation is as follows:
[0131]
[0132] 2. Subsequently, the construction of the secret sharing table to be processed is carried out.
[0133] During the construction of the secret sharing table, both parties can secretly share and split each item. For example, Party A splits the data used for cooperation into:
[0134]
[0135] Party B splits the data used for cooperation into:
[0136]
[0137] Here, the data of the ID item needs to perform modular exponentiation operations subsequently, so it needs to be split by multiplicative secret sharing. For other data, such as F_A, F_B, and L_B, the secret sharing splitting method can be freely selected, such as the additive secret sharing splitting shown in this example, or multiplicative secret sharing splitting.
[0138] Subsequently, the two parties exchange data. That is, Party A sends the data with the suffix "_B" in its split data to Party B, and Party B sends the data with the suffix "_A" in its split data to Party A.
[0139] After obtaining the data sent by the other party, both Party A and Party B can splice the obtained secret sharing components and expand their original data items. For example, Party A can add columns F_B and L_B, and Party B can add column F_A. The expanded data items can be empty or zero. Thus, the secret sharing table obtained by Party A is:
[0140]
[0141] Correspondingly, the secret sharing table obtained by Party B is:
[0142]
[0143] In this step, in order to clearly and concisely show the secret sharing table, the numbers of additive secret sharing can be briefly recorded as [], for example, [A] is A1 and A2; the numbers of multiplicative secret sharing are recorded as <>, for example They are A3 and A4. Then, the two parties send the secret sharing components to each other and splice them to obtain the secret sharing table as shown below:
[0144]
[0145] 3. The two parties run a two-party oblivious shuffle algorithm to shuffle the row order. After shuffling, neither party knows which row the shuffled data corresponds to in the original data.
[0146] Any existing shuffle algorithm can be used here. For example, it is preferable to use Figure 4 the quadratic perturbation method shown. Thus, the secret sharing table with the scrambled order is obtained.
[0147]
[0148] 4. Subsequently, the modular exponentiation operation as shown in the present invention Figure 3 can be performed to determine whether the ids are the same. Here, the Id_A and Id_B generated by Party A can be regarded as Figure 3 1 and x 2 in x and the Id_A and Id_B generated by Party B can be regarded as Figure 3 1 and y 2 in y 2.
[0149] Specifically, for the secret sharing table with the scrambled order, Party A randomly generates a number R1 and calculates the R1-th modular exponentiation of Party A's id component <id>_A R1 , and send it to Party B.
[0150] Party B randomly generates the number R2 and calculates the R2-th modular exponentiation of Party B's id component <id>_B R2 , and send it to Party A.
[0151] Then replace all the id components of Party B with the R2-th modular power of the components sent by Party A above:
[0152] <id> _B = <id>_A R1 R2
[0153] Party A replaces its own ID component with the R1-th modular power of the component sent by Party B above:
[0154] <id> _A = <id>_B R2 R1 。
[0155] Both parties send their respective id components to each other; then use multiplication for restoration:
[0156] <id> _A R1 R2 * <id>_B R2 R1 = id R2 R1
[0157] Thus, for the entire perturbed-order secret sharing table, the two parties obtain the following:
[0158]
[0159] Locally add the rows with equal id columns. If a row in the id column has no other equal rows, delete that row. The following secret sharing table can be obtained. Subsequently, the two parties can use any secure multi-party computation algorithm to model on this secret sharing table.
[0160]
[0161] Due to the discrete logarithm problem, the two parties cannot infer the identity of id2 from Id2 R2 R1. In actual calculations, Party A and Party B can provide more data, such as 10,000 pieces of data, and can construct a to-be-processed secret sharing table including 20,000 pieces of data as described above. After being inadvertently perturbed by the two parties, a perturbed secret sharing table including 20,000 pieces of data is obtained. Subsequently, through modular exponentiation calculation, find, for example, 4,000 pieces of intersection data. Thus, an intersection modular exponentiation sharing table including 4,000 pieces of intersection merged entries is obtained, and subsequent calculations are performed, such as modeling calculations.
[0162] The data processing method and system according to the present invention have been described in detail above with reference to the accompanying drawings. The present invention cleverly utilizes the characteristics of secret sharing and homomorphic encryption. When Party A and Party B respectively perform random sorting processing on data, the private key of the data is held by the other party. Thus, when each party processes the data, it will not affect the confidentiality of the data, and it can ensure that the final processed data result is randomly sorted in an order unknown to both parties.
[0163] In addition, the method according to the present invention can also be implemented as a computer program or a computer program product, which includes computer program code instructions for executing the above steps defined in the above method of the present invention.
[0164] Alternatively, the present invention can also be implemented as a non-transitory machine-readable storage medium (or computer-readable storage medium, or machine-readable storage medium), on which executable code (or computer program, or computer instruction code) is stored. When the executable code (or computer program, or computer instruction code) is executed by a processor of an electronic device (or computing device, server, etc.), the processor executes each step of the above method according to the present invention.
[0165] Those skilled in the art will also understand that the various exemplary logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein can be implemented as electronic hardware, computer software, or a combination of both.
[0166] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems and methods according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a segment of code, or a part thereof that contains one or more executable instructions for implementing the specified logical function. It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the figures. For example, two consecutive blocks may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.
[0167] The embodiments of the present invention have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, the practical application, or improvements made to the technology in the market, or to enable other ordinary skilled in the art to understand the embodiments disclosed herein.< / id> < / id> < / id> < / id> < / id> < / id> < / id> < / id>
Claims
1. A data processing system comprising: x and data y Party A and Party B participate in secure two-party computing, where: Party A performs secret sharing splitting on the data x to obtain a part of the data x and another part of the data x ; Party B performs secret sharing splitting on the data y to obtain a part of the data y and another part of the data y ; Party A uses the private key R1 to perform modular exponentiation on a part of the said data x and a part of the obtained said data y to obtain the first modular exponentiation result; Party B uses the private key R2 to perform modular exponentiation on the other part of the obtained data x and the other part of the data y to obtain a second modular exponentiation result; Party A uses the private key R1 to perform a second modular exponentiation on the second modular exponentiation result obtained from Party B. Party B uses the private key R2 to perform a second modular exponentiation on the first modular exponentiation result obtained from Party A. And Multiply the x component sum and the y component in the results of the second modular exponentiation of Party A and Party B respectively, and determine whether x and y are equal according to the comparison result of the multiplication result. 2. The system according to claim 1, wherein Data x and data y include: identification information kept confidential from each other.
3. The system according to claim 1, wherein Data x including multiple pieces of data x and the data y including multiple pieces of data y , The system obtains each piece of data x and each piece of data y to calculate the quadratic modular power of their respective components, and determines whether a certain piece of data x is equal to a certain piece of data y by checking whether the products of the quadratic modular powers of the respective components of each piece of data are equal.
4. The system according to claim 3, wherein Data x is the value of a specific item in entry X, and the data y is the value of the same item in entry Y, and When determining that x and y are equal, other items in entry X and entry Y are merged to obtain the merged intersection entry.
5. The system according to claim 4, wherein, the other items in the merged intersection entries are held by Party A and Party B in a secret sharing manner.
6. The system according to claim 5, wherein Party A performs secret sharing splitting on each item in entry X; Party B performs secret sharing splitting on each item in entry Y; The two parties exchange the secret sharing components obtained by splitting, so that Party A and Party B each hold a to-be-processed secret sharing table spliced with the secret sharing components of entry X and entry Y.
7. The system according to claim 6, wherein, Both parties run a two-party oblivious permutation to shuffle the entries in the secret sharing table to be processed, and for the shuffled secret sharing table, perform two modular exponentiation operations on the data x and y respectively.
8. The system according to claim 7, wherein One-party perturbation in the two-party oblivious perturbation includes: Party A performs a homomorphic encryption operation on the Party A component held by itself to obtain a Party A encrypted component and sends it back to Party B; Party B performs a homomorphic operation on the Party A encrypted component and the Party B component held by itself, generates a first operation result by performing a first operation on the randomly shuffled homomorphic operation result and a random number, and sends the first operation result back to Party A, wherein the random number generated by Party B serves as a new Party B component; Party A decrypts the first operation result to obtain the result of performing the first operation on the original data and the random number as a new Party A component.
9. The system according to claim 7, wherein, Party A's performing secret sharing splitting on each item in entry X includes: Party A performs multiplicative secret sharing on the data in Item X x and; Party A performs multiplicative or additive secret sharing on other items in Item X except for the data x other than this Party B performs secret sharing splitting on each item in entry Y; Party B performs multiplicative secret sharing on the data in item Y y and; Party B performs multiplicative or additive secret sharing on other items in Entry X except for the data y thereafter.
10. The system according to claim 4, wherein, The merged entries form an intersection secret sharing table for data x and data y involved in the secure two-party computation.
11. A data processing method, including: Perform secret sharing splitting on the data x to obtain a part of the x and another part of the x ; Obtain data y Another part of, where the partner performs secret sharing splitting on the data y To obtain the said y One part of and the said y Another part of; Use the private key R1 for the data x and a part of the obtained data y to calculate the modular exponentiation to obtain the first modular exponentiation result; Obtain the data obtained by the partner using the private key R2 x and another part of the data y to calculate the result of modular exponentiation to obtain the second modular exponentiation result; using the private key R1 to perform a second modular exponentiation on the second modular exponentiation result obtained from a cooperating party; obtaining the result of the cooperating party using the private key R2 to perform a second modular exponentiation on the first modular exponentiation result of itself; Make the x component sum y in the results of the two - time modular exponentiation of both parties be multiplied respectively, and determine x and y whether they are equal according to the comparison result of the multiplication results.
12. The method according to claim 11, wherein Data x including multiple pieces of data x , the data y including multiple pieces of data y , Both the party itself and the cooperative party obtain each piece of data x and each piece of data y for the second modulus power of their respective components, and determine whether a certain piece of data x is equal to a certain piece of data y by checking whether the product of the second modulus powers of the respective components of each piece of data is equal 13. The method according to claim 12, further includes: When determining x and y are equal, merge data x and data y at least some of the other items belonging to entry X and entry Y to obtain the merged entry wherein each item in the merged entries is held by itself and the cooperating party in a secret sharing manner.
14. The method according to claim 12, further includes: performing secret sharing splitting on each item in entry X, exchanging the secret sharing components obtained by splitting with the cooperating party, and itself and the cooperating party hold a to-be-processed secret sharing table spliced with the secret sharing components of entry X and entry Y.
15. The method according to claim 14, includes: running a two-party oblivious perturbation with the cooperating party to shuffle the entry order in the to-be-processed secret sharing table to obtain a shuffled secret sharing table.
16. The method according to claim 13, wherein, The merged entries form an intersection secret sharing table for the party itself and the cooperative party to utilize the data respectively x and the data y involved in secure two-party computation.
17. A data processing method, including: Party A performs secret sharing and splitting on item X, where item X includes a specific item and one or more first other items, and the value of the specific item x ; Party B will perform secret sharing splitting on Entry Y, where Entry Y includes the specific item and one or more second other items, and the value of the specific item y ; The two parties send secret sharing components to each other to obtain a to-be-processed secret sharing table spliced with entry X and entry Y, the two parties run a two-party oblivious perturbation to shuffle the entry order in the to-be-processed secret sharing table to obtain a shuffled secret sharing table; Party A uses the private key R1 to perform modular exponentiation on a part of the data x and a part of the obtained data y to obtain the first modular exponentiation result; Party B uses the private key R2 to perform modular exponentiation on another part of the obtained data x and another part of the data y to obtain the second modular exponentiation result; Party A uses the private key R1 to perform a second modular exponentiation on the second modular exponentiation result obtained from Party B; Party B uses the private key R2 to perform a second modular exponentiation on the first modular exponentiation result obtained from Party A; Multiply the x component sum y and the components in the results of the second modular exponentiation of Party A and Party B respectively; merging the entries with equal multiplication results and deleting the entries without equal specific items to obtain an intersection secret sharing table composed of the merged entries.
18. The method according to claim 17, wherein, The first other item is different from the second other item, and in the secret sharing table to be processed: Entry X includes the specific item, the first other item, and the augmented second other item; Entry Y includes the specific item, the augmented first other item, and the second other item, and the value of the augmented item is zero or empty.
19. The method according to claim 18, wherein, The entry X includes a plurality of entry Xs, each entry X includes a specific item and one or more first other items, and the value x of each specific item is different; and The entry Y includes a plurality of entry Ys, each entry Y includes a specific item and one or more second other items, and the value y of each specific item is different.
20. The method according to claim 17, further comprising: Use the intersection secret sharing table for each of the party itself and the cooperating party to utilize data x and data y involved in secure two-party computation.
21. A computing device, comprising: A processor; And A memory having executable code stored thereon, which when executed by the processor, causes the processor to execute the method according to any one of claims 11-20.
22. A non-transitory machine-readable storage medium having executable code stored thereon, which when executed by a processor of an electronic device, causes the processor to execute the method according to any one of claims 11-20.
Citation Information
Patent Citations
Security protocol method, computer device and storage medium
CN109067538A
Privacy set intersection data interaction method based on homomorphic encryption and system thereof
CN111641603A