Conditional Anonymized Tracking Query Method, System and Device Based on Privacy Computing

Through the comparison algorithm of privacy collection interception and secret sharing, a secure anonymous query within the condition range is realized, and the problem of data privacy and security of query objects in the existing technology is solved, and efficient and secure condition anonymous query is realized.

CN114637746BActive Publication Date: 2025-06-10TONGDUN NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210224195.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-07
Publication Date
2025-06-10
Estimated Expiration
2042-03-07

AI Technical Summary

Technical Problem

The prior art cannot ensure the data privacy and security of the query object during the anonymous query process, especially when querying within the conditional range.

Method used

A conditional anonymous query method based on privacy calculation is proposed. By obtaining the conditional query statement, privacy collection interception is performed, and the comparison algorithm of secret sharing is used to restore the comparison results of each index and condition range of the data service provider, and the index within the condition range is filtered according to the results, for the anonymous query.

Benefits of technology

It realizes safe and efficient anonymous query within the scope of conditions, ensures the data privacy and security of the query objects, and avoids data leakage and unauthorized queries.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114637746B_ABST
    Figure CN114637746B_ABST
Patent Text Reader

Abstract

A conditional anonymity query method, system, and device based on privacy computing provided by the present invention are applied to the field of data processing technology. Before the anonymity query, the method determines the first index corresponding to the intersection field value without conditions through private set intersection, and determines the comparison result between each index of the data service party and the conditional range through a secret sharing comparison algorithm. Then, based on the comparison result, the second index within the conditional range is selected from the first index. Therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the query party can implement a conditional anonymity query with the data service party based on the second index. Moreover, the query party can only obtain the comparison result of the conditional range within the intersection field value, and the coordinator can only obtain the comparison result between each index of the data service party and the conditional range. The data service party cannot obtain the complete conditional range and the specific query object, ensuring the privacy and security of the conditional anonymity query process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention is applied to the field of data processing technology, and particularly relates to a conditional trace hiding query method, system and device based on privacy computing. Background Art

[0002] Trace hiding query is a privacy information retrieval technology. Specifically, during the interaction between the querying party and the data service party, the querying party hides the keyword or customer ID information of the queried object, and the data service party provides the matching query results without knowing the specific corresponding queried object, usually implemented based on cryptographic technologies such as encryption algorithms and oblivious transfer. This is to achieve data calculation without leaving the door, thereby eliminating the possibility of data caching, data leakage, and data trafficking.

[0003] Currently, the oblivious transfer protocol and private set intersection can be used to implement trace hiding query. The querying party provides the queried object, and uses the private set intersection method to determine the location of the queried object in the data service party without revealing other data of the data service party, and then uses oblivious transfer to obtain the query results corresponding to the queried object from the data service party without the data service party knowing the specific query location. However, the above trace hiding query process can only obtain the query results corresponding to all queried objects, realizing an unconditional query of the queried objects, and cannot guarantee the data privacy security when the queried objects are queried for trace hiding within the conditional range. Summary of the Invention

[0004] In view of this, embodiments of the present invention propose a conditional trace hiding query method, system and device based on privacy computing, which are used to solve the problem that conditional trace hiding query cannot be realized in the current query services in the field of privacy computing.

[0005] The first aspect of the present invention provides a conditional trace hiding query method based on privacy computing. The method is applied to the querying party and may include:

[0006] Obtain a conditional query statement, where the conditional query statement includes a first query field value and a conditional range;

[0007] Perform a private set intersection based on the first query field value and the field values stored by the data service party to obtain a first index corresponding to the intersection field value, and send the first index to the coordinator. The first index is used to indicate the storage location of the intersection field value in the data service party;

[0008] Perform a secret sharing comparison algorithm with the data service party and the coordinator based on the conditional range, so that the coordinator restores the comparison results of each index of the data service party and the conditional range;

[0009] Receive the second index sent by the coordinator, where the second index is obtained by the coordinator screening the first index within the conditional range according to the comparison result;

[0010] Perform a stealth query with the data service party according to the second index.

[0011] Optionally, the conditional range includes a conditional field, a conditional threshold, and a comparison operator. The comparison algorithm for secret sharing with the data service party and the coordinator based on the conditional range is used to recover, at the coordinator, the comparison result of each index of the data service party with the conditional range, including:

[0012] Send the conditional field to the data service party, and send the comparison operator to the data service party and the coordinator;

[0013] Use the comparison algorithm for secret sharing with the data service party and the coordinator based on the conditional field, the conditional threshold, and the comparison operator to recover, at the coordinator, the comparison result of each index of the data service party with the conditional range.

[0014] Optionally, the performing a stealth query with the data service party according to the second index includes:

[0015] Obtain the second query field value within the conditional range according to the second index in the intersection field value, and perform a stealth query with the data service party according to the second query field value.

[0016] Optionally, the performing a private set intersection of the first query field value and the field values stored by the data service party to obtain the first index corresponding to the intersection field value includes:

[0017] Perform a private set intersection of the first query field value and the field values stored by the data service party to obtain the intersection field value;

[0018] Receive the first index sent by the data service party according to the intersection field value.

[0019] Optionally, the data service party stores at least one field value data table, and each field value data table stores at least one field value. The performing a private set intersection of the first query field value and the field values stored by the data service party to obtain the first index corresponding to the intersection field value includes:

[0020] Specify a field value data table for the data service party, and perform a private set intersection of the first query field value and the field value data table of the data service party to obtain the first index corresponding to the intersection field value.

[0021] Optionally, performing private set intersection on the basis of the first query field value and the field values stored by the data service party to obtain a first index corresponding to the intersection field value, includes:

[0022] Performing private set intersection on the basis of the first query field value and the field values stored by the data service party by using the oblivious transfer extension protocol to obtain a first index corresponding to the intersection field value.

[0023] According to a second aspect of the present invention, a conditional stealth query method based on privacy computing is provided. This method can be applied to a coordinator, and the method may include:

[0024] Receiving a first index sent by a query party, where the first index is used to indicate the storage location of the intersection field value in the data service party, the intersection field value is obtained by performing private set intersection on the basis of the first query field value between the query party and the field values stored by the data service party, and the first query field value is used to indicate the query object of the query party;

[0025] Performing a comparison algorithm of secret sharing with the query party and the data service party based on the conditional range, and restoring the comparison result between each index of the data service party and the conditional range, where the conditional range is used to indicate the query range of the query party;

[0026] Filtering the first index according to the comparison result to obtain a second index within the conditional range;

[0027] Sending the second index to the query party so that the query party performs a stealth query with the data service party according to the second index.

[0028] According to a third aspect of the present invention, a conditional stealth query system based on privacy computing includes a query party, a data service party, and a coordinator. The query party is used to obtain a conditional query statement, and the conditional query statement includes a first query field value and a conditional range;

[0029] The query party is further used to perform private set intersection on the basis of the first query field value and the field values stored by the data service party to obtain a first index corresponding to the intersection field value, and send the first index to the coordinator, where the first index is used to indicate the storage location of the intersection field value in the data service party;

[0030] The coordinator is used to perform a comparison algorithm of secret sharing with the query party and the data service party based on the conditional range, and restore the comparison result between each index of the data service party and the conditional range;

[0031] The coordinator is further used to filter the first index according to the comparison result to obtain a second index within the conditional range;

[0032] The coordinating party is further configured to send the second index to the querying party;

[0033] The querying party is further configured to perform a stealth query with the data service party according to the second index.

[0034] According to a fourth aspect of the present invention, a conditional stealth query device based on privacy computing is provided. The device is applied to a querying party and may include:

[0035] A query statement acquisition module, configured to acquire a conditional query statement, where the conditional query statement includes a first query field value and a conditional range;

[0036] A first index sending module, configured to perform a private set intersection on the first query field value and the field values stored by the data service party to obtain a first index corresponding to the intersection field value, and send the first index to the coordinating party, where the first index is used to indicate the storage location of the intersection field value in the data service party;

[0037] A first comparison algorithm module, configured to perform a comparison algorithm for secret sharing with the data service party and the coordinating party based on the conditional range, so that the coordinating party restores the comparison result between each index of the data service party and the conditional range;

[0038] A second index receiving module, configured to receive the second index sent by the coordinating party, where the second index is obtained by the coordinating party filtering the first index within the conditional range according to the comparison result;

[0039] A stealth query module, configured to perform a stealth query with the data service party according to the second index.

[0040] Optionally, the conditional range includes a conditional field, a conditional threshold, and a comparison operator. The first comparison algorithm module includes:

[0041] A conditional sending sub-module, configured to send the conditional field to the data service party, and send the comparison operator to the data service party and the coordinating party;

[0042] A conditional comparison sub-module, configured to perform a comparison algorithm for secret sharing with the data service party and the coordinating party based on the conditional field, the conditional threshold, and the comparison operator, so that the coordinating party restores the comparison result between each index of the data service party and the conditional range.

[0043] Optionally, the stealth query module is specifically configured to obtain a second query field value within the conditional range according to the second index from the intersection field values, and perform a stealth query with the data service party according to the second query field value.

[0044] Optionally, the first index sending module includes:

[0045] An intersection field value obtaining sub-module, configured to perform a private set intersection on the basis of the first query field value and the field values stored by the data service party to obtain intersection field values;

[0046] A first index obtaining sub-module, configured to receive the first index sent by the data service party according to the intersection field values.

[0047] Optionally, the data service party stores at least one field value data table, and at least one field value is stored in each field value data table. The first index sending module is specifically configured to specify a field value data table for the data service party, and perform a private set intersection on the basis of the first query field value and the field value data table of the data service party to obtain a first index corresponding to the intersection field value.

[0048] Optionally, the first index sending module is specifically configured to perform a private set intersection on the basis of the first query field value and the field values stored by the data service party by using an oblivious transfer extension protocol to obtain a first index corresponding to the intersection field value.

[0049] According to a fifth aspect of the present invention, a conditional anonymity tracking query device based on privacy computing is provided. The device is applied to a coordinator, and the device may include:

[0050] A first index receiving module, configured to receive a first index sent by a query party. The first index is used to indicate the storage location of intersection field values in the data service party. The intersection field values are obtained by performing a private set intersection on the basis of the first query field value by the query party and the field values stored by the data service party. The first query field value is used to indicate the query object of the query party;

[0051] A second comparison algorithm module, configured to perform a comparison algorithm for secret sharing with the query party and the data service party based on the conditional range, and recover the comparison result between each index of the data service party and the conditional range. The conditional range is used to indicate the query range of the query party;

[0052] A second index screening module, configured to screen the first index according to the comparison result to obtain a second index within the conditional range;

[0053] A second index sending module, configured to send the second index to the query party, so that the query party performs an anonymity tracking query with the data service party according to the second index.

[0054] According to a sixth aspect of the present invention, there is provided an electronic device, including a processor, a memory, and a program or instruction stored on the memory and executable on the processor. When the program or instruction is executed by the processor, the method for conditional traceable query based on privacy computing described in the first aspect or the second aspect above is implemented.

[0055] According to a seventh aspect of the present invention, there is provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for conditional traceable query based on privacy computing described in the first aspect or the second aspect is implemented.

[0056] In view of the related art, the present invention has the following advantages:

[0057] In an embodiment of the present invention, a conditional traceable query based on privacy computing is provided. In this method, the querying party performs a private set intersection based on the first query field value and the field values stored by the data service party to determine the first index corresponding to the intersection field value, and sends the first index to the coordinating party. The first query field value is used to indicate the target query object, and the first index is used to indicate the storage location of the intersection field value in the data service party; the querying party also performs a comparison algorithm of secret sharing with the data service party and the coordinating party based on a conditional range to obtain the comparison result of each index of the data service party and the conditional range; the querying party then receives a second index, and the second index is obtained by the coordinating party screening the first indexes within the conditional range according to the comparison result.

[0058] In the embodiment of the present invention, before the traceable query, the first index corresponding to the intersection field value without conditions is determined through a private set intersection, and the comparison result of each index of the data service party and the conditional range is determined through a comparison algorithm of secret sharing. The second index is selected from the first indexes according to the conditional range based on the comparison result. Therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the querying party can implement a conditional traceable query with the data service party based on the second index. Moreover, in the embodiment of the present invention, the querying party can only know the comparison result of the intersection field value within the conditional range, and cannot know the comparison results of other field values; the coordinating party can only know the comparison result of each index in the data service party and the conditional range, and cannot know the field value corresponding to each index, so that the coordinating party cannot actually obtain the comparison result of each field value and the conditional range, thus realizing a safe and efficient conditional traceable query.

[0059] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other objects, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention are hereinafter specifically described. Brief Description of the Drawings

[0060] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become apparent to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0061] Figure 1 is one of the step flowcharts of the conditional anonymity tracking query method based on privacy computing provided by an embodiment of the present invention;

[0062] Figure 2 is the second step flowchart of the conditional anonymity tracking query method based on privacy computing provided by an embodiment of the present invention;

[0063] Figure 3 is the third step flowchart of the conditional anonymity tracking query method based on privacy computing provided by an embodiment of the present invention;

[0064] Figure 4 is the structural block diagram of a conditional anonymity tracking query system based on privacy computing provided by an embodiment of the present invention;

[0065] Figure 5 is the specific example step flowchart of a conditional anonymity tracking query method based on privacy computing provided by an embodiment of the present invention;

[0066] Figure 6 is the first structural block diagram of a conditional anonymity tracking query device based on privacy computing provided by an embodiment of the present invention;

[0067] Figure 7 is the second structural block diagram of a conditional anonymity tracking query device based on privacy computing provided by an embodiment of the present invention;

[0068] Figure 8 is the structural block diagram of an electronic device provided by an embodiment of the present invention. Detailed Embodiments

[0069] The exemplary embodiments of the present invention will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided so that the present invention can be more thoroughly understood and the scope of the present invention can be completely conveyed to those skilled in the art.

[0070] Figure 1 is one of the step flowcharts of the conditional anonymity tracking query method based on privacy computing provided by an embodiment of the present invention. As Figure 1 shown, this method can be applied to the querying party, and this method can include:

[0071] Step 101: Obtain a conditional query statement, where the conditional query statement includes a first query field value and a conditional range.

[0072] In an embodiment of the present invention, the querying party (client) refers to the entity using the data query service, and the data service party (server) refers to the entity providing the data query service. The querying party can define the first query field value to be queried in the data query service and the specific query conditional range through the conditional query statement. The first query field value can be used to indicate the keyword provided by the querying party to the data service party. For example, the first query field value can be an ID (Identity document) value, a mobile phone number, an occupation name, an age value, an asset value, etc. The data service party can provide different fields and different field values corresponding to the fields. For example, the fields provided by the data service party can be ID, mobile phone number, occupation name, age, asset, etc. On this basis, the field "ID" can correspond to different ID values, the field "mobile phone number" can correspond to different mobile phone numbers, the field "occupation" can correspond to different occupation names...; the conditional range refers to the range for querying the field value. For example, when querying the user's age, the conditional range can limit the range of gender, occupation or age, etc. When querying the user's income, the conditional range can limit the range of mobile phone number, age or income, etc. For example, the meaning of the conditional query statement can be "query the ages of users with mobile phone numbers from a to z and over 30 years old", or "query the incomes of users with mobile phone numbers from a to z and over 30 years old", where "mobile phone numbers from a to z" is the first query field value, and "over 30 years old" is the conditional range.

[0073] In an embodiment of the present invention, the data service party can authorize the querying party to use the query services of different fields. Thus, when the querying party provides the first query field value of the authorized field, the data service party can query according to the first query field value and provide the query result corresponding to the first query field value. For example, if the data service party authorizes the querying party to use the query service of the field "mobile phone number", the querying party can provide a specific mobile phone number to the data service party as the first query field value to use the query service of the field "mobile phone number".

[0074] Step 102: Perform a private set intersection on the first query field value and the field values stored by the data service party to obtain a first index corresponding to the intersection field value, and send the first index to the coordinator. The first index is used to indicate the storage location of the intersection field value in the data service party.

[0075] In the embodiments of the present invention, Private Set Intersection (PSI) refers to a calculation process of obtaining the intersection of the data held by the participating parties without disclosing other information of the participating parties except the intersection. The participating parties in this embodiment include a querying party, a data service party, and a coordinating party. By performing a private set intersection on the first query field value of the querying party and the field values stored by the data service party, the intersection field values can be obtained. The intersection field values may include all of the first query field values or may include some of the first query field values. Optionally, the storage location of the field values can be represented by an index. Based on the determined intersection field values, the querying party can receive a first index provided by the data service party according to the intersection field values. The first index indicates the storage location of the intersection field values in the data service party, so that the first index and the intersection field values can be in one-to-one correspondence. The querying party can send the obtained first index to the coordinating party.

[0076] Step 103: Perform a comparison algorithm for secret sharing with the data service party and the coordinating party based on the conditional range, so that the coordinating party can recover the comparison result between each index of the data service party and the conditional range.

[0077] In the embodiments of the present invention, secret sharing is a type of secure multi-party computation. It can disassemble a secret and distribute it to different participating parties. Different participating parties can perform local computations, or randomly exchange data, and disperse the computation results to be saved in different participating parties. When needed, the computation results dispersed and saved by different participating parties are merged and recovered. In the embodiments of the present invention, the querying party can share the conditional range as a secret with the three parties of the data service party and the coordinating party, and then compare the field values stored by the data service party with the conditional range through a comparison algorithm, and represent the comparison result by the index of the field value and the relationship between the field value and the conditional range.

[0078] For example, if the field value x is within the conditional range, it can be recorded as 1, and the index corresponding to the field value x in the data service party is x'. Then the comparison result is represented in the form of [x', 1]; if the field value y is not within the conditional range, it can be recorded as 0, and the index corresponding to the field value y in the data service party is y'. Then the comparison result is represented in the form of [y', 0].

[0079] In the embodiments of the present invention, the comparison result can be recovered by the coordinating party, so that the data service party cannot know the specific conditional range. The coordinating party can only know whether the field value corresponding to the index is within the conditional range or outside the conditional range, and cannot know the specific conditional range and the field values stored by the data service party.

[0080] Step 104: Receive a second index sent by the coordinating party. The second index is obtained by the coordinating party filtering the first indexes within the conditional range according to the comparison result.

[0081] In an embodiment of the present invention, the querying party may receive a second index sent by the coordinating party. The coordinating party may filter the first index according to the first index corresponding to the intersection field value provided by the querying party and the comparison result of each index with the conditional range obtained based on the secret sharing-based comparison algorithm, filter out the first indexes outside the conditional range, and determine the first indexes within the conditional range as the second index. The querying party may obtain the second index from the coordinating party. At this time, the second index may indicate the storage location of the intersection field value within the conditional range in the data service party.

[0082] Step 105: Perform a traceable query with the data service party according to the second index.

[0083] In an embodiment of the present invention, the second index may indicate the storage location of the intersection field value within the conditional range in the data service party. Based on the obtained second index, the querying party may perform a traceable query with the data service party to obtain the query result of the field value corresponding to the second index. At this time, the querying party cannot know the query results of other field values other than the field value corresponding to the second index, and the data service party also cannot know which field values are queried.

[0084] In the present invention, a conditional traceable query method based on privacy computing is provided. In this method, the querying party performs a private set intersection on the first query field value and the field values stored in the data service party to determine the first index corresponding to the intersection field value, and sends the first index to the coordinating party. The first query field value is used to indicate the target query object, and the first index is used to indicate the storage location of the intersection field value in the data service party. The querying party also performs a secret sharing-based comparison algorithm with the data service party and the coordinating party based on the conditional range to obtain the comparison result of each index of the data service party with the conditional range. The querying party then receives the second index, and the second index is obtained by the coordinating party filtering the first indexes within the conditional range according to the comparison result. Since in the embodiment of the present invention, before the traceable query, the first index corresponding to the intersection field value without conditions is determined through a private set intersection, and the comparison result of each index of the data service party with the conditional range is determined through a secret sharing-based comparison algorithm, and the second index is selected from the first indexes according to the conditional range based on the comparison result, therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the querying party can implement a conditional traceable query with the data service party based on the second index. Moreover, in the embodiment of the present invention, the querying party can only know the comparison result of the conditional range within the intersection field value and cannot know the comparison results of other field values; the coordinating party can only know the comparison result of each index in the data service party with the conditional range and cannot know the field value corresponding to each index, so that the coordinating party cannot actually obtain the comparison result of each field value with the conditional range, thus realizing a safe and efficient conditional traceable query.

[0085] Figure 2 This is the second step flowchart of the conditional anonymous tracking query method based on privacy computing provided by an embodiment of the present invention. As Figure 2 shown, this method can be applied to the querying party, and the method may include:

[0086] Step 201: Obtain a conditional query statement, where the conditional query statement includes a first query field value and a conditional range.

[0087] In the embodiment of the present invention, step 201 can be correspondingly referred to the relevant description of the foregoing step 101. To avoid repetition, it will not be elaborated here.

[0088] Step 202: Perform a private set intersection on the basis of the first query field value and the field values stored by the data service party to obtain a first index corresponding to the intersection field value, and send the first index to the coordinator. The first index is used to indicate the storage location of the intersection field value in the data service party.

[0089] In the embodiment of the present invention, step 202 can be correspondingly referred to the relevant description of the foregoing step 102. To avoid repetition, it will not be elaborated here.

[0090] Optionally, step 201 includes:

[0091] Step S11: Perform a private set intersection on the basis of the first query field value and the field values stored by the data service party to obtain an intersection field value.

[0092] Step S12: Receive the first index sent by the data service party according to the intersection field value.

[0093] In the embodiment of the present invention, the querying party can first perform a private set intersection on the basis of the first query field value and the field values stored by the data service party to determine the intersection field value existing between the first query field value and the field values already stored by the data service party. In the case of determining the intersection field value, the querying party can further receive the first index corresponding to the intersection field value sent by the data service party, so as to know the storage location of the intersection field value in the data service party. Optionally, the data service party can send the first index in plaintext or encrypted.

[0094] In the embodiment of the present invention, when the querying party performs a private set intersection with the data service party based on the first query field value, it can also obtain an index of the intersection field value in the querying party to indicate the storage location of the intersection field value in the querying party, so that the querying party can obtain the intersection field value from the corresponding storage location.

[0095] Optionally, the data service party stores at least one field value data table, and at least one field value is stored in each field value data table. Step 202 specifically includes:

[0096] Step S21: Specify the field value data table to the data service provider, and perform a private set intersection on the basis of the first query field value and the field value data table of the data service provider to obtain the first index corresponding to the intersection field value.

[0097] In the embodiments of the present invention, the data service provider may store information such as fields and field values in the form of a data table. On this basis, the index may be the storage order of the field value in the data table. The querying party may specify the data table during the query process, thereby realizing a more accurate and efficient query process. Among them, the data service provider may store at least one data table and authorize the query service of the data table to the querying party, so as to provide the query service of the data service provider to the querying party when the querying party specifies the data table. On the basis that the querying party specifies the data table, the querying party may perform a private set intersection on the first query field value and the field values stored in the data table of the data service provider.

[0098] Optionally, step 202 specifically includes:

[0099] Step S31: Perform a private set intersection on the basis of the first query field value and the field values stored by the data service provider by using the oblivious transfer extension protocol to obtain the first index corresponding to the intersection field value.

[0100] In the embodiments of the present invention, the oblivious transfer extension protocol (OTE) is an improvement of the oblivious transfer protocol, which can reduce the number of oblivious transfers used, thereby improving the speed of private set intersection. The querying party may perform a private set intersection on the basis of the first query field value and the field values stored by the data service provider by using OTE, so as to effectively improve the efficiency of the querying party to obtain the first index corresponding to the intersection field value.

[0101] Optionally, the conditional range includes a conditional field, a conditional threshold, and a comparison operator.

[0102] In the embodiments of the present invention, the conditional range may be defined by a conditional field, a conditional threshold, and a comparison operator. Among them, the conditional field is used to limit the type of condition. For example, the conditional field may be age, phone number, etc. The conditional threshold is used to limit the value limit of the condition. For example, the conditional threshold may be 30 years old for age, 123456 for phone number, etc. The comparison operator is used to limit the value range of the condition. For example, the comparison operator may be "=", ">", "≤", etc.

[0103] In an embodiment of the present invention, the querying party can obtain an SQL (Structured Query Language) statement as a conditional query statement. The SQL statement can provide fields, field values, conditional ranges, etc., so as to implement conditional tracking queries.

[0104] For example, the querying party obtains the following SQL statement:

[0105] select phone_number,age,salary from table1 where phone_number in(186,135)and sex='M'

[0106] Among them, "phone_number" is a field, "table1" is a data table, "(186,135)" is the first query field value, sex='M' is the conditional range, and "age" and "salary" are query results;

[0107] In the above conditional range, "sex" is the conditional field "gender", 'M' is the conditional threshold "male", "=" is the comparison operator, "age" is the query result "age", and "salary" is the query result "income";

[0108] This SQL statement means to query the ages of male users whose "phone_number" is "(186,135)" in the "table1" data table.

[0109] Step 203: Send the conditional field to the data service party, and send the comparison operator to the data service party and the coordination party.

[0110] In an embodiment of the present invention, the querying party can determine the conditional field, conditional threshold, and comparison operator in the conditional range, then send the conditional field to the data service party, send the comparison operator to the data service party and the coordination party, and retain the conditional threshold, so as to hide the conditional threshold from the data service party and prevent the data service party from knowing the specific conditional range of the querying party.

[0111] Step 204: Perform a secret sharing comparison algorithm with the data service party and the coordination party based on the conditional field, the conditional threshold, and the comparison operator, so as to recover the comparison result between each index of the data service party and the conditional range at the coordination party.

[0112] In the embodiments of the present invention, based on the sharing of the conditional fields, conditional thresholds, and comparison operators by the querying party, the data service party, and the coordinating party, a comparison algorithm for secret sharing can be performed. For specific details, reference can be made to the relevant description in step 102 above. To avoid repetition, it will not be elaborated here. Additionally, each index can be an index corresponding to all field values stored by the data service party, or an index corresponding to all field values stored in the data table specified by the querying party. The embodiments of the present invention do not make specific limitations in this regard.

[0113] Step 205: Receive the second index sent by the coordinating party, where the second index is obtained by the coordinating party filtering the first index within the conditional range according to the comparison result.

[0114] In the embodiments of the present invention, step 205 can be correspondingly referred to the relevant description in step 104 above. To avoid repetition, it will not be elaborated here.

[0115] Step 206: Obtain the second query field values within the conditional range according to the second index from the intersection field values, and perform a traceable query with the data service party based on the second query field values.

[0116] In the embodiments of the present invention, the querying party can also filter based on the second index in the intersection field values. Since the second index indicates the storage locations of the intersection field values within the conditional range in the data service party, and the querying party has learned the storage locations of each intersection field value in the data service party according to the first index, therefore, the querying party can filter the intersection field values according to the second index, determine the intersection field values within the conditional range as the second query field values, and perform a traceable query with the data service party based on the second query field values.

[0117] In the implementation of the present invention, a conditional anonymity tracing query method based on privacy computing is provided. In this method, the querying party performs a private set intersection on the first query field value and the field values stored by the data service party to determine the first index corresponding to the intersection field value, and sends the first index to the coordinating party. The first query field value is used to indicate the target query object, and the first index is used to indicate the storage location of the intersection field value in the data service party. The querying party also performs a secret sharing-based comparison algorithm with the data service party and the coordinating party based on a conditional range to obtain the comparison result of each index of the data service party and the conditional range. The querying party then receives a second index, and the second index is obtained by the coordinating party filtering the first index within the conditional range according to the comparison result. Since in the embodiment of the present invention, before the anonymity tracing query, the first index corresponding to the intersection field value without conditions is determined through a private set intersection, and the comparison result of each index of the data service party and the conditional range is determined through a secret sharing-based comparison algorithm, and the second index is selected from the first index according to the conditional range based on the comparison result. Therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the querying party can implement a conditional anonymity tracing query with the data service party based on the second index. Moreover, in the embodiment of the present invention, the querying party can only know the comparison result of the conditional range within the intersection field value, and cannot know the comparison result of other field values; the coordinating party can only know the comparison result of each index in the data service party and the conditional range, and cannot know the field value corresponding to each index, so that the coordinating party cannot actually obtain the comparison result of each field value and the conditional range, thus realizing a safe and efficient conditional anonymity tracing query.

[0118] In the embodiment of the present invention Figure 3 is the third step flow chart of the conditional anonymity tracing query method based on privacy computing provided by the embodiment of the present invention. As Figure 3 shown, this method can be applied to the coordinating party, and this method may include:

[0119] Step 301: Receive the first index sent by the querying party. The first index is used to indicate the storage location of the intersection field value in the data service party. The intersection field value is obtained by performing a private set intersection on the first query field value by the querying party and the field values stored by the data service party. The first query field value is used to indicate the query object of the querying party.

[0120] In the embodiment of the present invention, the coordinating party can receive the first index sent by the querying party. The first index can be correspondingly referred to the relevant descriptions of step 102 or step 202 above. To avoid repetition, it will not be elaborated here.

[0121] Step 302: Based on the conditional range, perform a comparison algorithm for secret sharing with the querying party and the data service party to recover the comparison result between each index of the data service party and the conditional range, where the conditional range is used to indicate the query range of the querying party.

[0122] In the embodiments of the present invention, the coordinator, the querying party, and the data service party can perform a comparison algorithm for secret sharing based on the conditional range. For details, reference can be made to the relevant descriptions in the foregoing step 103 or steps 203-204 to avoid repetition and will not be elaborated herein. Among them, the comparison result can indicate whether the field value corresponding to each index is within the conditional range. For example, if the field value stored at the storage location indicated by the index is within the conditional range, the comparison result corresponding to the index takes the value of 1; otherwise, it takes the value of 0. Then, the coordinator can only know the value of the comparison result corresponding to each index, but cannot know the specific field value and the specific conditional range.

[0123] Step 303: Screen the first index according to the comparison result to obtain a second index within the conditional range.

[0124] In the embodiments of the present invention, the coordinator can screen the first index according to the comparison result and determine the index within the conditional range in the first index as the second index. For details, reference can be made to the relevant descriptions in the foregoing step 103 to avoid repetition and will not be elaborated herein.

[0125] Step 304: Send the second index to the querying party so that the querying party can perform a traceable query with the data service party according to the second index.

[0126] In the embodiments of the present invention, after obtaining the second index within the conditional range from the first index according to the comparison result, the coordinator can send the second index to the querying party, enabling the querying party to perform a traceable query with the data service party according to the second index. The second index can indicate the intersection field value within the conditional range, thereby realizing a conditional traceable query. For details, reference can be made to the relevant descriptions in the foregoing step 105 or step 206 to avoid repetition and will not be elaborated herein.

[0127] In the implementation of the present invention, a conditional privacy-preserving query method based on privacy computing is provided. In this method, the coordinator can receive a first index sent by the querying party. The first index is obtained by the querying party through a private set intersection operation based on the first query field value and the field values of the data service provider to determine the index corresponding to the intersection field value. The first query field value is used to indicate the query object of the querying party, and the first index is used to indicate the storage location of the intersection field value in the data service provider. The coordinator also performs a comparison algorithm for secret sharing with the data service provider and the querying party based on a conditional range, and recovers the comparison result of each index of the data service provider and the conditional range. Then, the coordinator filters the first indexes within the conditional range according to the comparison results to obtain a second index, and sends it to the querying party, so that the querying party can perform a privacy-preserving query with the data service provider based on the second index. Since in the embodiment of the present invention, before the privacy-preserving query, the first index corresponding to the intersection field value without conditions is determined through a private set intersection operation, and the comparison result of each index of the data service provider and the conditional range is determined through a comparison algorithm for secret sharing, and the second index is selected from the first indexes according to the conditional range based on the comparison results. Therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the querying party can perform a conditional privacy-preserving query with the data service provider based on the second index. Moreover, in the embodiment of the present invention, the querying party can only know the comparison result of the conditional range within the intersection field value, and cannot know the comparison results of other field values; the coordinator can only know the comparison result of each index in the data service provider and the conditional range, and cannot know the field value corresponding to each index, so that the coordinator cannot actually obtain the comparison result of each field value and the conditional range; the data service provider cannot know the complete conditional range and the specific query object, ensuring the privacy and security of the conditional privacy-preserving query process.

[0128] Figure 4 It is a structural block diagram of a conditional privacy-preserving query system provided by an embodiment of the present invention, as Figure 4 shown. The system includes a querying party 401, a data service provider 402, and a coordinator 403, where:

[0129] The querying party 401 is used to obtain a conditional query statement, and the conditional query statement includes a first query field value and a conditional range;

[0130] The querying party 401 is also used to perform a private set intersection operation based on the first query field value and the field values stored in the data service provider 402 to obtain a first index corresponding to the intersection field value, and send the first index to the coordinator 403. The first index is used to indicate the storage location of the intersection field value in the data service provider 402;

[0131] The coordinator 403 is used to perform a comparison algorithm for secret sharing with the querying party 401 and the data service party 402 based on the conditional range, and recover the comparison result of each index of the data service party 402 with the conditional range;

[0132] The coordinator 403 is further used to screen the first index according to the comparison result to obtain a second index within the conditional range;

[0133] The coordinator 403 is further used to send the second index to the querying party 401;

[0134] The querying party 401 is further used to perform a stealth query with the data service party 402 according to the second index.

[0135] In the implementation of the present invention, a conditional stealth query system based on privacy computing is provided. The system includes a querying party, a data service party, and a coordinator. The querying party can perform a private set intersection based on the first query field value and the field value stored by the data service party to determine the first index corresponding to the intersection field value, and send the first index to the coordinator. The first query field value is used to indicate the query object of the querying party, and the first index is used to indicate the storage location of the intersection field value in the data service party. The querying party, the data service party, and the coordinator can also perform a comparison algorithm for secret sharing based on the conditional range, and the coordinator recovers the comparison result of each index of the data service party with the conditional range. The coordinator then screens the first index within the conditional range according to the comparison result to obtain a second index and sends it to the querying party. The querying party performs a stealth query with the data service party based on the second index. Since in the embodiment of the present invention, before the stealth query, the first index corresponding to the intersection field value without conditions is determined through a private set intersection, and the comparison result of each index of the data service party with the conditional range is determined through a comparison algorithm for secret sharing, and the second index is selected from the first index according to the conditional range based on the comparison result. Therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the querying party can implement a conditional stealth query with the data service party based on the second index. Moreover, in the implementation of the present invention, the querying party can only know the comparison result of the conditional range within the intersection field value, and cannot know the comparison result of other field values; the coordinator can only know the comparison result of each index in the data service party with the conditional range, and cannot know the field value corresponding to each index; the data service party cannot know the complete conditional range and the specific query object, ensuring the privacy and security of the conditional stealth query process.

[0136] Figure 5 It is a specific example step flowchart of a conditional stealth query method based on privacy computing provided by an embodiment of the present invention. As Figure 5 shown, this process refers to Figures 1 to 3 shown in the conditional stealth query method based on privacy computing, and based onFigure 4 Implementation of the conditional anonymity tracking query system based on privacy computing, the process includes:

[0137] Step 501, the query party 401 obtains the SQL statement as follows:

[0138] select id,age from table1 where id in(12996837,34562701)and sex='M'

[0139] Step 502, the query party 401 sends the field "ID" to the data service party 402 and specifies "table1".

[0140] Step 503, the data service party 402 executes "select id from table1" to obtain the ID field values ["82917214", "12996837", "34562701", ···] in the specified data table.

[0141] Step 504, based on the first query field value "(12996837,34562701)" of the query party 401 and the ID field values ["82917214", "12996837", "34562701", ···] of the data service party 402, perform a private set intersection. The query party 401 obtains the intersection ID field values at the index "aligned_client_indexes:[0,1]" of the query party 401 and the first index "aligned_server_indexes:[1,2]".

[0142] Step 505, the query party 401 determines the intersection field values ["12996837", "34562701"] according to the intersection ID field values at the index "aligned_client_indexes:[0,1]" of the query party 401, and sends the first index "aligned_server_indexes:[1,2]" to the coordinator 403.

[0143] Step 506, the query party 401 parses the SQL statement to obtain the where comparison condition statement "sex='M'", sends the condition field "sex" to the data service party 402, sends the comparison operator "=" to the data service party 402 and the coordinator 403, and retains the condition threshold "'M'".

[0144] Step 507, the data service party 402 executes the SQL statement "select sex from table1" to obtain the sex field values in the specified data table.

[0145] Step 508: The querying party 401, the data service party 402, and the coordinating party 403 compare the sex field values corresponding to the indexes based on the secret sharing-based comparison algorithm according to the conditional threshold and the comparison operator, and the coordinating party 403 restores the complete comparison result. The comparison result is the corresponding relationship between the index and the value. If the sex field value corresponding to the index conforms to "sex = 'M'", the value corresponding to the index is 1; if the sex field value corresponding to the index does not conform to "sex = 'M'", the value corresponding to the index is 0. According to the storage order of the field values in the data table, the comparison result can be [1, 0, 1, ···].

[0146] Step 509: The coordinating party 403 determines the indexes with the value of 1 in the comparison result [1, 0, 1, ···] in the first index "aligned_server_indexes: [1, 2]" as the second index "aligned_server_indexes_meet_condition: [2]", and sends the second index "aligned_server_indexes_meet_condition: [2]" to the querying party 401.

[0147] Step 510: The querying party 401 obtains the second query field values ["34562701"] within the conditional range from the intersection field values according to the second index "aligned_server_indexes_meet_condition: [2]".

[0148] Step 511: The querying party 401 conducts a traceable query with the data service party 402 based on the second query field values and obtains the query result ["34562701_25"].

[0149] In the implementation of the present invention, a conditional privacy-preserving query method based on privacy computing is provided. This method is implemented based on a privacy-preserving query system, which includes a querying party, a data service party, and a coordinating party. The querying party can perform a private set intersection on the basis of the first query field value and the field values stored by the data service party to determine the first index corresponding to the intersection field value, and send the first index to the coordinating party. The first query field value is used to indicate the query object of the querying party, and the first index is used to indicate the storage location of the intersection field value in the data service party. The querying party, the data service party, and the coordinating party can also perform a comparison algorithm of secret sharing based on the conditional range, and the coordinating party restores the comparison result of each index of the data service party and the conditional range. The coordinating party then filters the first indexes within the conditional range according to the comparison result to obtain the second index and sends it to the querying party. The querying party performs a privacy-preserving query with the data service party based on the second index. Since in the embodiment of the present invention, before the privacy-preserving query, the first index corresponding to the intersection field value without conditions is determined through private set intersection, and the comparison result of each index of the data service party and the conditional range is determined through the comparison algorithm of secret sharing, and the second index is selected from the first indexes according to the conditional range based on the comparison result. Therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the querying party can implement a conditional privacy-preserving query with the data service party based on the second index. Moreover, in the embodiment of the present invention, the querying party can only know the comparison result of the conditional range within the intersection field value, and cannot know the comparison results of other field values; the coordinating party can only know the comparison result of each index in the data service party and the conditional range, and cannot know the field value corresponding to each index; the data service party cannot know the complete conditional range and the specific query object, ensuring the privacy and security of the conditional privacy-preserving query process.

[0150] Figure 6 FIG. 4 is one of the structural block diagrams of a conditional privacy-preserving query device 60 provided by an embodiment of the present invention. This device is applied to the querying party. The device 60 may include:

[0151] A query statement acquisition module 601, configured to acquire a conditional query statement, where the conditional query statement includes a first query field value and a conditional range;

[0152] A first index sending module 602, configured to perform a private set intersection on the basis of the first query field value and the field values stored by the data service party to obtain a first index corresponding to the intersection field value, and send the first index to the coordinating party. The first index is used to indicate the storage location of the intersection field value in the data service party;

[0153] A first comparison algorithm module 603, configured to perform a comparison algorithm of secret sharing with the data service party and the coordinating party based on the conditional range, so that the coordinating party restores the comparison result of each index of the data service party and the conditional range;

[0154] A second index receiving module 604, configured to receive the second index sent by the coordinator, where the second index is obtained by the coordinator filtering the first index within the condition range according to the comparison result;

[0155] A stealth query module 605, configured to perform a stealth query with the data service party according to the second index.

[0156] Optionally, the condition range includes a condition field, a condition threshold, and a comparison operator. The first comparison algorithm module 603 includes:

[0157] A condition sending sub-module, configured to send the condition field to the data service party, and send the comparison operator to the data service party and the coordinator;

[0158] A condition comparison sub-module, configured to perform a comparison algorithm of secret sharing with the data service party and the coordinator based on the condition field, the condition threshold, and the comparison operator, so as to recover, at the coordinator, the comparison result of each index of the data service party and the condition range.

[0159] Optionally, the stealth query module 605 is specifically configured to obtain a second query field value within the condition range according to the second index from the intersection field values, and perform a stealth query with the data service party according to the second query field value.

[0160] Optionally, the first index sending module 602 includes:

[0161] An intersection field value obtaining sub-module, configured to perform a private set intersection on the basis of the first query field value and the field values stored by the data service party to obtain intersection field values;

[0162] A first index obtaining sub-module, configured to receive the first index sent by the data service party according to the intersection field values.

[0163] Optionally, the data service party stores at least one field value data table, and at least one field value is stored in each field value data table. The first index sending module 602 is specifically configured to specify a field value data table for the data service party, and perform a private set intersection on the basis of the first query field value and the field value data table of the data service party to obtain the first index corresponding to the intersection field values.

[0164] Optionally, the first index sending module 602 is specifically configured to perform a private set intersection on the basis of the first query field value and the field values stored by the data service party by using an oblivious transfer extension protocol to obtain the first index corresponding to the intersection field values.

[0165] In the implementation of the present invention, a conditional privacy-preserving query device is provided. This device is applied to the querying party and can perform a private set intersection on the basis of the first query field value and the field values stored by the data service party to determine the first index corresponding to the intersection field value, and send the first index to the coordinating party. The first query field value is used to indicate the query object of the querying party, and the first index is used to indicate the storage location of the intersection field value in the data service party. The querying party also performs a secret-sharing comparison algorithm with the data service party and the coordinating party based on the conditional range, so that the coordinating party can obtain the comparison result of each index of the data service party and the conditional range. The querying party then receives the second index sent by the coordinating party, and the second index is obtained by the coordinating party filtering the first index within the conditional range according to the comparison result. Since in the embodiment of the present invention, before the privacy-preserving query, the first index corresponding to the intersection field value without conditions is determined through a private set intersection, and the comparison result of each index of the data service party and the conditional range is determined through a secret-sharing comparison algorithm, and the second index is selected from the first index according to the conditional range based on the comparison result, therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the querying party can achieve a conditional privacy-preserving query with the data service party based on the second index. Moreover, in the implementation of the present invention, the querying party can only know the comparison result of the conditional range within the intersection field value and cannot know the comparison results of other field values; the coordinating party can only know the comparison result of each index in the data service party and the conditional range and cannot know the field value corresponding to each index, thus realizing a safe and efficient conditional privacy-preserving query.

[0166] Figure 7 This is the second structural block diagram of a conditional privacy-preserving query device 70 provided by an embodiment of the present invention. This device is applied to the coordinating party and may include:

[0167] A first index receiving module 701, configured to receive the first index sent by the querying party. The first index is used to indicate the storage location of the intersection field value in the data service party. The intersection field value is obtained by performing a private set intersection on the basis of the first query field value between the querying party and the field values stored by the data service party. The first query field value is used to indicate the query object of the querying party;

[0168] A second comparison algorithm module 702, configured to perform a secret-sharing comparison algorithm with the querying party and the data service party based on the conditional range to restore the comparison result of each index of the data service party and the conditional range. The conditional range is used to indicate the query range of the querying party;

[0169] A second index filtering module 703, configured to filter the first index according to the comparison result to obtain the second index within the conditional range;

[0170] The second index sending module 704 is configured to send the second index to the querying party, so that the querying party performs a traceable query with the data service party according to the second index.

[0171] In an embodiment of the present invention, a conditional traceable query device based on privacy computing is provided. The device is applied to a coordinator, and can receive a first index sent by a querying party. The first index is obtained by the querying party based on a privacy set intersection of the first query field value and the field values stored by the data service party to determine the index corresponding to the intersection field value. The first query field value is used to indicate the query object of the querying party, and the first index is used to indicate the storage location of the intersection field value in the data service party. The coordinator also performs a comparison algorithm for secret sharing with the data service party and the querying party based on the conditional range, and restores the comparison result of each index of the data service party and the conditional range. The coordinator then filters the first index within the conditional range according to the comparison result to obtain a second index, and sends it to the querying party, so that the querying party performs a traceable query with the data service party based on the second index. Since in the embodiment of the present invention, before the traceable query, the first index corresponding to the intersection field value without conditions is determined through a privacy set intersection, and the comparison result of each index of the data service party and the conditional range is determined through a comparison algorithm for secret sharing, and the second index is selected from the first index according to the conditional range based on the comparison result, therefore, the second index can indicate the storage location of the intersection field value within the conditional range, so that the querying party can implement a conditional traceable query with the data service party based on the second index. Moreover, in the embodiment of the present invention, the querying party can only know the comparison result of the conditional range within the intersection field value, and cannot know the comparison result of other field values; the coordinator can only know the comparison result of each index in the data service party and the conditional range, and cannot know the field value corresponding to each index; the data service party cannot know the complete conditional range and the specific query object, ensuring the privacy and security of the conditional traceable query process.

[0172] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the above Figures 1 to 2 , or Figure 3 conditional traceable query method based on privacy computing shown.

[0173] Figure 8 is a structural block diagram of an electronic device 800 provided by an embodiment of the present invention, as shown in Figure 8 shown, a memory 802 and a program or instruction stored on the memory 802 and executable on a processor 801. When the program or instruction is executed by the processor 801, it implements the above Figures 1 to 2 , or Figure 3 conditional traceable query method based on privacy computing shown.

[0174] Those skilled in the art can understand that the present invention includes devices for performing one or more of the operations described in the present invention. These devices can be specifically designed and manufactured for the required purposes, or can also include known devices in general-purpose computers. These devices have computer programs stored therein, and these computer programs are selectively activated or reconstructed. Such computer programs can be stored in the storage medium of the device (such as a computer) or stored in any type of medium suitable for storing electronic instructions and coupled to the bus respectively. The computer storage medium includes, but is not limited to, any type of disk (including floppy disks, hard disks, optical disks, CD-ROMs, and magneto-optical disks), ROM (Read-Only Memory), RAM (Random Access Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory, magnetic cards, or optical cards. That is, the storage medium includes any medium that can store or transmit information in a readable form by a device (such as a computer).

[0175] Those skilled in the art can understand that each block in these structural diagrams and / or block diagrams and / or flowcharts, as well as combinations of blocks in these structural diagrams and / or block diagrams and / or flowcharts, can be implemented using computer program instructions. Those skilled in the art can understand that these computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing methods to implement, so as to execute the solutions specified in the blocks or multiple blocks of the structural diagrams and / or block diagrams and / or flowcharts disclosed by the present invention through the processor of the computer or other programmable data processing methods.

[0176] As described above, it is only the specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, and all of them should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claimed rights.

Claims

1. A conditional anonymous tracing query method based on privacy computing, characterized in that , the method is applied to the querying party, and the method includes: Obtain a conditional query statement, where the conditional query statement includes a first query field value and a conditional range; Perform a private set intersection on the first query field value and the field values stored by the data service party to obtain the intersection field values and their corresponding first indexes, and send the first indexes to the coordination party, where the first indexes are used to indicate the storage locations of the intersection field values in the data service party; Perform a secret-sharing comparison algorithm with the data service party and the coordination party based on the conditional range, so that the coordination party can restore the comparison results between each index of the data service party and the conditional range; Receive the second indexes sent by the coordination party, where the second indexes are obtained by the coordination party filtering the first indexes within the conditional range according to the comparison results; Perform an anonymous tracing query with the data service party according to the second indexes; The conditional range includes a conditional field, a conditional threshold, and a comparison operator. The secret-sharing comparison algorithm performed with the data service party and the coordination party based on the conditional range to restore the comparison results between each index of the data service party and the conditional range at the coordination party includes: Send the conditional field to the data service party, and send the comparison operator to the data service party and the coordination party; Perform a secret-sharing comparison algorithm with the data service party and the coordination party based on the conditional field, the conditional threshold, and the comparison operator, so that the coordination party can restore the comparison results between each index of the data service party and the conditional range.

2. The method according to claim 1, characterized in that , the performing an anonymous tracing query with the data service party according to the second indexes includes: Obtain the second query field values within the conditional range from the intersection field values according to the second indexes, and perform an anonymous tracing query with the data service party according to the second query field values.

3. The method according to claim 1, characterized in that , the performing a private set intersection on the first query field value and the field values stored by the data service party to obtain the first indexes corresponding to the intersection field values includes: Perform a private set intersection on the first query field value and the field values stored by the data service party to obtain the intersection field values; Receive the first indexes sent by the data service party according to the intersection field values.

4. The method according to claim 1, characterized in that , the data service party stores at least one field value data table, and at least one field value is stored in each field value data table. The performing a private set intersection on the first query field value and the field values stored by the data service party to obtain the first indexes corresponding to the intersection field values includes: Specify a field value data table for the data service party, and perform a private set intersection on the first query field value and the field value data table of the data service party to obtain the first indexes corresponding to the intersection field values.

5. The method according to claim 1, characterized in that , performing private set intersection based on the first query field value and the field values stored by the data service provider to obtain a first index corresponding to the intersection field value, includes: Performing private set intersection based on the first query field value and the field values stored by the data service provider using the Oblivious Transfer Extension protocol to obtain a first index corresponding to the intersection field value.

6. A conditional privacy-preserving query method based on privacy computing Characterized in that , the method is applied to a coordinator, and the method includes: Receiving a first index sent by a querying party, where the first index is used to indicate the storage location of the intersection field value in the data service provider, and the intersection field value is obtained by performing private set intersection on the field values stored by the querying party and the data service provider based on a first query field value, and the first query field value is used to indicate the query object of the querying party; Performing a secret-sharing comparison algorithm with the querying party and the data service provider based on a conditional range to recover the comparison result of each index of the data service provider and the conditional range, where the conditional range is used to indicate the query range of the querying party; Filtering the first index according to the comparison result to obtain a second index within the conditional range; Sending the second index to the querying party so that the querying party can perform a privacy-preserving query with the data service provider according to the second index; The conditional range includes a conditional field, a conditional threshold, and a comparison operator. The secret-sharing comparison algorithm with the data service provider and the coordinator based on the conditional range to recover the comparison result of each index of the data service provider and the conditional range at the coordinator includes: Sending the conditional field to the data service provider, and sending the comparison operator to the data service provider and the coordinator; Performing a secret-sharing comparison algorithm with the data service provider and the coordinator based on the conditional field, the conditional threshold, and the comparison operator to recover the comparison result of each index of the data service provider and the conditional range at the coordinator.

7. A conditional privacy-preserving query system based on privacy computing Characterized in that , the system includes a querying party, a data service provider, and a coordinator. The querying party is used to obtain a conditional query statement, and the conditional query statement includes a first query field value and a conditional range; The querying party is further used to perform private set intersection based on the first query field value and the field values stored by the data service provider to obtain a first index corresponding to the intersection field value, and send the first index to the coordinator, where the first index is used to indicate the storage location of the intersection field value in the data service provider; The coordinator is used to perform a secret-sharing comparison algorithm with the querying party and the data service provider based on the conditional range to recover the comparison result of each index of the data service provider and the conditional range; The coordinator is further used to filter the first index according to the comparison result to obtain a second index within the conditional range; The coordinator is further used to send the second index to the querying party; The querying party is further configured to perform a trace - hiding query with the data - providing party according to the second index; The condition range includes a condition field, a condition threshold, and a comparison operator. The comparison algorithm for secret sharing with the data - providing party and the coordinating party based on the condition range is used to recover, at the coordinating party, the comparison result between each index of the data - providing party and the condition range, including: Sending the condition field to the data - providing party, and sending the comparison operator to the data - providing party and the coordinating party; Performing a comparison algorithm for secret sharing with the data - providing party and the coordinating party based on the condition field, the condition threshold, and the comparison operator to recover, at the coordinating party, the comparison result between each index of the data - providing party and the condition range.

8. A conditional trace - hiding query device based on privacy computing, Characterized in that , the device is applied to a querying party, and the device includes: A query statement acquisition module, configured to acquire a conditional query statement, where the conditional query statement includes a first query field value and a condition range; A first index sending module, configured to perform a private set intersection on the first query field value and the field values stored by the data - providing party to obtain a first index corresponding to the intersection field value, and send the first index to the coordinating party, where the first index is used to indicate the storage location of the intersection field value in the data - providing party; A first comparison algorithm module, configured to perform a comparison algorithm for secret sharing with the data - providing party and the coordinating party based on the condition range to recover, at the coordinating party, the comparison result between each index of the data - providing party and the condition range; A second index receiving module, configured to receive a second index sent by the coordinating party, where the second index is obtained by the coordinating party filtering the first index within the condition range according to the comparison result; A trace - hiding query module, configured to perform a trace - hiding query with the data - providing party according to the second index; The condition range includes a condition field, a condition threshold, and a comparison operator. The comparison algorithm for secret sharing with the data - providing party and the coordinating party based on the condition range is used to recover, at the coordinating party, the comparison result between each index of the data - providing party and the condition range, including: Sending the condition field to the data - providing party, and sending the comparison operator to the data - providing party and the coordinating party; Performing a comparison algorithm for secret sharing with the data - providing party and the coordinating party based on the condition field, the condition threshold, and the comparison operator to recover, at the coordinating party, the comparison result between each index of the data - providing party and the condition range.

9. A conditional trace - hiding query device based on privacy computing, Characterized in that , the device is applied to a coordinating party, and the device includes: The first index receiving module is configured to receive a first index sent by a querying party, where the first index is used to indicate the storage location of the intersection field value at the data service party. The intersection field value is obtained by performing a private set intersection on the field values stored by the querying party and the data service party based on a first query field value, and the first query field value is used to indicate the query object of the querying party. The second comparison algorithm module is configured to perform a comparison algorithm for secret sharing with the querying party and the data service party based on a conditional range, and recover the comparison result between each index of the data service party and the conditional range. The conditional range is used to indicate the query range of the querying party. The second index screening module is configured to screen the first index according to the comparison result to obtain a second index within the conditional range. The second index sending module is configured to send the second index to the querying party, so that the querying party can perform a traceable query with the data service party according to the second index. The conditional range includes a conditional field, a conditional threshold, and a comparison operator. The comparison algorithm for secret sharing with the data service party and the coordinating party based on the conditional range to recover the comparison result between each index of the data service party and the conditional range at the coordinating party includes: Sending the conditional field to the data service party, and sending the comparison operator to the data service party and the coordinating party. Performing a comparison algorithm for secret sharing with the data service party and the coordinating party based on the conditional field, the conditional threshold, and the comparison operator to recover the comparison result between each index of the data service party and the conditional range at the coordinating party.

Citation Information

Patent Citations

  • Hidden trace query method and device based on oblivious transmission protocol and secret sharing

    CN114143000A

  • Universal data index for rapid data exploration

    US20210149866A1