A Privacy Set Operation Method and System Based on Fully Homomorphic Encryption
By constructing an optimized privacy set operation protocol based on fully homomorphic encryption, the problem of inefficiency in the existing technology in non-balanced scenarios is solved, and a safe and efficient privacy set operation is achieved.
Patent Information
- Application Number
- CN202211026207.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-25
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-08-25
AI Technical Summary
The existing private set operation protocol is inefficient in unbalanced scenarios, especially the communication complexity is linearly related to large set sizes, making it difficult to apply in practice.
Using a method based on all-homomorphic encryption, the PSU, PSI-card and PSI-sum-card protocols are constructed through hierarchical homomorphic encryption technology, and combined with technologies such as permutation matrix privacy equality testing and inadvertent transmission, the protocol is optimized to communicate complexity independent of the length of the set element.
It realizes safe and efficient private set operation in unbalanced scenarios, and the traffic volume is linearly correlated with small sets and logarithmic correlation with large sets, reducing the computational complexity and improving application efficiency.
Smart Images

Figure CN115529118B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cryptography technology, and in particular, to a privacy set operation method and system based on fully homomorphic encryption. Background Technique
[0002] The statements in this part only mention the background technology related to the present invention and do not necessarily constitute the prior art.
[0003] Privacy set operation can complete specific set operation operations while ensuring the privacy of the input sets of all parties, and can provide a data circulation mode of "data can be used but not seen". It is a key cryptography technology that takes into account both data circulation and privacy protection at present, and has become a powerful cryptography tool for solving the current "data island" problem.
[0004] Private Set Union (PSU) means that each participating party has a set of private data, and they jointly calculate the union of the sets without disclosing other information. Private set union is widely used in practice. For example, two Internet companies can conduct network risk assessment and management by analyzing the combined IP blacklist and combined vulnerability data; or an institution needs to investigate the current housing purchase and rental demand of residents. It can perform a private set union operation on the data of real estate agents while ensuring the privacy of the real estate agent data.
[0005] Private Set Intersection Cardinality (PSI-card) means that each participating party has a set of private data, and they jointly calculate the number of elements in the intersection without disclosing any other information. Private set intersection cardinality is widely used in practice. For example, in a social network, two users can calculate the number of common friends without disclosing their own friend information to calculate the overlap of social relationships; two companies can calculate the number of common users without disclosing their own user information to calculate the overlap of target user relationships, etc.
[0006] Private Set Intersection Sum with Cardinality (PSI-sum-card) means that each party has a set of private data, and they jointly calculate the sum of the intersection elements without revealing any other information. There is a variant of Private Set Intersection Sum with Cardinality called Labeled Private Set Intersection Sum with Cardinality (Labeled PSI-sum-card). Labeled PSI-sum-card means that each party has a set of private data with labels, and they jointly calculate the sum of the data corresponding to the intersection elements without revealing any other information. Private Set Intersection Sum can calculate the statistical properties of the intersection data while ensuring the privacy of the intersection. For example, it can calculate the average blood pressure of patients taking a certain drug, or the home ownership rate of residents living in a specific area, etc.
[0007] Currently, there is relatively rich research on PSU, but it mainly focuses on the balanced scenario, that is, the case where the set sizes input by both parties are equal. However, most practical applications are more in line with the unbalanced scenario, that is, the set size of the sender may be much smaller than that of the receiver. For example, the sender (client) may be a mobile device with limited battery, weak computing power, and small storage space, while the receiver (server) is a large high-end computing device, and the bandwidth between the two parties may be limited. Existing PSU protocols are not efficient when applied to the unbalanced scenario. In particular, their communication complexity is at least linearly related to the large set size. Therefore, constructing a secure and efficient PSU protocol applicable to the unbalanced scenario is an important development direction in this field.
[0008] Currently, there is little research on PSI-card and PSI-sum-card, and it mainly focuses on the balanced scenario, that is, the case where the set sizes input by both parties are equal. However, most practical applications are mainly in the unbalanced scenario, that is, the set of the receiver may be much smaller than that of the sender. For example, in the Server-Client scenario, the receiver (client) has a small set and is a mobile device with weak computing and storage capabilities; the sender (server) has a large set and is a high-end computing device with large storage capacity, and the bandwidth between the two parties may be very limited. Existing PSI-card and PSI-sum-card protocols are not efficient when applied to the unbalanced scenario. In particular, their communication complexity is at least linearly related to the large set, making it difficult to be applied in practice. Therefore, constructing secure and efficient PSI-card and PSI-sum-card protocols applicable to the unbalanced scenario is an important development direction in this field. Summary of the Invention
[0009] To solve the deficiencies of the prior art, the present invention provides a method and system for privacy set operations based on fully homomorphic encryption, with communication complexity independent of the length of elements in the set and applicable to unbalanced scenarios.
[0010] In a first aspect, the present invention provides a method for privacy set operations based on fully homomorphic encryption;
[0011] A method for privacy set operations based on fully homomorphic encryption, in response to a privacy set operation instruction, the server and the client perform interactive calculations through a protocol to obtain a set operation result;
[0012] Among them, the protocol is constructed based on the hierarchical homomorphic encryption technology.
[0013] Further, if the privacy set operation instruction is an instruction to find the union of privacy sets, the server and the client perform interactive calculations through the PSU protocol to obtain the union of the sets;
[0014] The PSU protocol adopts a basic PSU protocol constructed based on the hierarchical homomorphic encryption technology, or a PSU optimized protocol obtained by optimizing the basic PSU protocol with cuckoo hashing, naive hashing, batch, windowing, blocking, the Paterson-Stockmeyer algorithm, and modulo conversion technology, and combining permutation matrix private equality testing and oblivious transfer.
[0015] Further, the permutation matrix private equality testing is constructed based on permutation sharing and multi-point oblivious pseudorandom functions.
[0016] Further, the permutation matrix private equality testing is constructed based on the decisional Diffie-Hellman assumption.
[0017] Further, if the privacy set operation instruction is an instruction to find the cardinality of the intersection of privacy sets, the server and the client perform interactive calculations through the PSI-card protocol to obtain the number of elements in the intersection;
[0018] The PSI-card protocol adopts a basic PSI-card protocol constructed based on the hierarchical homomorphic encryption technology, or a PSI-card optimized protocol obtained by optimizing the basic PSI-card protocol with cuckoo hashing, naive hashing, batch, windowing, blocking, the Paterson-Stockmeyer algorithm, and modulo conversion technology.
[0019] Further, in response to an instruction to find the sum and cardinality of the intersection of privacy sets, the server and the client perform interactive calculations through the PSI-sum-card protocol to obtain the cardinality of the intersection, and the sum of the elements in the intersection, or the sum of the data corresponding to the elements in the intersection.
[0020] Furthermore, if the server and the client each have a set of privacy data without tags, the PSI-sum-card protocol adopts a basic PSI-sum-card protocol constructed based on the hierarchical homomorphic encryption technology, or a PSI-sum-card optimized protocol obtained by optimizing the basic PSI-sum-card protocol using cuckoo hashing, naive hashing, batch, windowing, chunking, Paterson-Stockmeyer algorithm, and modular conversion technology.
[0021] Furthermore, if the server and the client each have a set of privacy data with tags, the PSI-sum-card protocol adopts a basic Labeled PSI-sum-card protocol, or a Labeled PSI-sum-card optimized protocol obtained by optimizing the basic Labeled PSI-sum-card protocol using cuckoo hashing, naive hashing, batch, windowing, chunking, Paterson-Stockmeyer algorithm, and modular conversion technology.
[0022] Furthermore, the basic PSI-sum-card protocol, based on the basic PSI-card protocol, uses a non-intersection element elimination technology to convert all non-intersection elements into 0.
[0023] In a second aspect, the present invention provides a privacy set operation system based on fully homomorphic encryption;
[0024] A privacy set operation system based on fully homomorphic encryption includes a server and a client;
[0025] The server and the client respond to a privacy set operation instruction and perform interactive calculations through a protocol to obtain a set operation result.
[0026] Compared with the prior art, the beneficial effects of the present invention are:
[0027] For the privacy set operation method based on fully homomorphic encryption of the present invention, its communication volume is linearly related to the small set and logarithmically related to the large set.
[0028] For the privacy set operation method based on fully homomorphic encryption of the present invention, in terms of the communication volume being independent of the element length (except for OT): The PSU protocol, PSI-card, and PSI-sum-card protocols and their variants constructed by the present invention, except for the OT protocol stage, the communication complexity of other processes is independent of the length of the elements in the set; specifically, both parties can use the same collision-resistant hash function to hash the elements in their respective sets into small fixed sizes, and then use the hash values to replace the set elements for subsequent protocol calculations.
[0029] A privacy set operation method based on fully homomorphic encryption according to the present invention, in terms of offline or online execution: in the PSU protocol constructed by the present invention, the preprocessing process of the receiver can be completely completed offline without the participation of the sender, further improving the application efficiency; specifically, the receiver can set an upper bound on the set size of the sender in advance, and then select parameters locally and perform preprocessing calculations. Subsequently, after knowing the actual set size of the sender in the online phase, the receiver can send the specific parameters to the sender, and the sender can fill in the same elements known to both parties, such as ⊥, to complete the subsequent protocol.
[0030] A privacy set operation method based on fully homomorphic encryption according to the present invention, in terms of offline or online execution: in the PSI-card and PSI-sum-card protocols constructed by the present invention, the preprocessing process of the sender can be completely completed offline without the participation of the receiver, further improving the application efficiency; specifically, the sender can set an upper bound on the set size of the receiver in advance, and then select parameters locally and perform preprocessing calculations. Subsequently, after knowing the actual set size of the receiver in the online phase, the sender can send the specific parameters to the receiver, and the receiver can fill in ⊥ or symbols in other non-set elements, and then complete the subsequent protocol. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The specification drawings forming a part of this application are used to provide a further understanding of this application. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation of this application.
[0032] Figure 1 Schematic diagram of the basic PSU protocol (omitting OT) described in Example 2 and related optimizations;
[0033] Figure 2 Frame diagram of the PSU protocol structure described in Example 2;
[0034] Figure 3 Schematic diagram of the basic PSI-card protocol described in Example 3;
[0035] Figure 4 Schematic diagram of the basic PSI-sum-card protocol described in Example 3;
[0036] Figure 5 Schematic diagram of the basic Labeled PSI-sum-card with small set protocol described in Example 3;
[0037] Figure 6 Schematic diagram of the basic Labeled PSI-sum-card with large set protocol described in Example 3;
[0038] Figure 7 Schematic diagram of the PSI-card optimization protocol described in the third embodiment;
[0039] Figure 8 Schematic diagram of the PSI-sum-card optimization protocol described in the third embodiment;
[0040] Figure 9 Schematic diagram of the Labeled PSI-sum-card with small set optimization protocol described in the third embodiment;
[0041] Figure 10 Schematic diagram of the Labeled PSI-sum-card with large set optimization protocol described in the third embodiment. Detailed implementation manners
[0042] It should be noted that the following detailed description is exemplary and is intended to provide further illustration of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs.
[0043] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary implementation manners according to the present application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0044] Term explanation:
[0045] PSU protocol:
[0046] Parameters: The sender has the set X, and the receiver has the set Y;
[0047] Functions: 1. The sender inputs the set X = {x 1 …x n}, and the receiver inputs the set Y = {y 1 , …, x n};
[0048] 2. Output X ∪ T to the receiver.
[0049] Permuted matrix private equality test (pm-PEQT):
[0050] Parameters: The sender has the matrix R′ α×mand matrix permutation π = (π c , π r ), the receiver has matrix R α×m ;
[0051] Function: 1. The sender inputs matrix R' α×m and matrix permutation π = (π c , π r ), the receiver inputs matrix R α×m ;
[0052] 2. Outputs a binary matrix B α×m to the receiver. For the matrices R' c and R r permuted by π = (π α×m and R α×m ), if r π(ij) = r' π(ij) , then b ij = 1, otherwise b ij = 0.
[0053] Oblivious transfer (OT) protocol:
[0054] Parameters: The sender has The receiver has b ∈ {0, 1};
[0055] Function: 1. The sender inputs The receiver inputs b ∈ {0, 1};
[0056] 2. Outputs x b to the receiver.
[0057] Multi-point oblivious pseudorandom function (mp-OPRF):
[0058] Parameters: Pseudorandom function: F; The receiver has
[0059] Function: 1. The receiver inputs
[0060] 2. Randomly selects a key k of the pseudorandom function for the sender; Sends the pseudorandom function values {F k (x 1 ), …, F k (x n )} to the receiver.
[0061] Permute+Share protocol:
[0062] Parameters: The sender has a vector X = {x 0 , …, x n}, and the receiver has a permutation π.
[0063] Functions: 1. The sender inputs the vector X = {x 0 , …, x n}, and the receiver inputs the permutation π;
[0064] 2. Select a set of permutation shares {s π(0) , …, s π(n)} for the sender; send a set of permutation shares {s′ π(0) , …, s′ π(n)} to the receiver, where
[0065] Example 1
[0066] This example provides a privacy set operation method based on fully homomorphic encryption. In response to a privacy set operation instruction, the server and the client perform interactive calculations through a protocol to obtain the set operation result.
[0067] The privacy set operation instruction is an instruction for finding the union of privacy sets, an instruction for finding the cardinality of the intersection of privacy sets, or an instruction for finding the sum and cardinality of the intersection of privacy sets.
[0068] The protocol is the PSU protocol, the PSI-card protocol, or the PSI-sum-card protocol. The PSU protocol, the PSI-card protocol, and the PSI-sum-card protocol are all constructed based on hierarchical homomorphic encryption technology.
[0069] If the privacy set operation instruction is an instruction for finding the union of privacy sets, the server and the client perform interactive calculations through the PSU protocol to obtain the union of the sets;
[0070] The PSU protocol adopts the basic PSU protocol, or the PSU optimized protocol obtained by optimizing the basic PSU protocol through cuckoo hashing, naive hashing, batching, windowing, chunking, the Paterson-Stockmeyer algorithm, and modulo conversion techniques, and combining the permutation matrix private equality test and oblivious transfer. Among them, batching, windowing, chunking, and modulo conversion are conventional optimization techniques in LFHE. The batching technique is from the paper "Fast private set intersection from homomorphic encryption" published in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017 in 2017. The windowing technique is from the paper "Labeled PSI from fully homomorphic encryption with malicious security" published in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS 2018 in 2018. The modulo conversion technique is from the paper "Labeled PSI from homomorphic encryption with reduced computation and communication" published in CCS’21: 2021 ACM SIGSAC Conference on Computer and Communications Security in 2021.
[0071] If the private set operation instruction is an instruction to find the cardinality of the intersection of private sets, the server and the client perform interactive calculations through the PSI-card protocol to obtain the number of intersection elements;
[0072] The PSI-card protocol adopts the basic PSI-card protocol, or the PSI-card optimized protocol obtained by optimizing the basic PSI-card protocol with cuckoo hashing, naive hashing, batching, windowing, chunking, the Paterson-Stockmeyer algorithm, and modulo conversion techniques.
[0073] In response to the instructions to find the sum and cardinality of the intersection of private sets, the server and the client perform interactive calculations through the PSI-sum-card protocol to obtain the cardinality of the intersection, the sum of the intersection elements, or the sum of the data corresponding to the intersection elements.
[0074] If the server and the client each have a set of privacy data without tags, the PSI-sum-card protocol adopts the basic PSI-sum-card protocol, or the PSI-sum-card optimized protocol obtained by optimizing the basic PSI-sum-card protocol with cuckoo hashing, naive hashing, batch, windowing, chunking, Paterson-Stockmeyer algorithm, and modular conversion technology.
[0075] If the server and the client each have a set of privacy data with tags, the PSI-sum-card protocol adopts the basic Labeled PSI-sum-card protocol, or the Labeled PSI-sum-card optimized protocol obtained by optimizing the basic Labeled PSI-sum-card protocol with cuckoo hashing, naive hashing, batch, windowing, chunking, Paterson-Stockmeyer algorithm, and modular conversion technology.
[0076] Example Two
[0077] This example provides a privacy set operation method based on fully homomorphic encryption. In response to the instruction of finding the union of privacy sets, the server and the client perform interactive calculations through the PSU protocol to obtain the union of the sets.
[0078] In the PSU protocol, the sender is the client with the small set X = {x 1 , …, x m}, denoted by S; the receiver is the server with the large set Y = {y 1 , …, y n}, denoted by R; let the symbol [n] denote {1, …, n}, and let the symbol [m] denote {1, 2,..., m}.
[0079] PSU protocol construction idea: First, a basic PSU protocol is given based on LFHE. This protocol has optimal communication complexity, that is, it is linearly related to small sets. However, the homomorphic computation circuit depth of this protocol is relatively deep and the computational complexity is relatively high. Subsequently, the basic PSU protocol is optimized using cuckoo hashing and optimization techniques of LFHE to design a semi-PSU protocol (OT is omitted). Then, by combining the permutation matrix privacy equality test (pm-PEQT) and oblivious transfer (OT), a general construction of the complete PSU protocol (i.e., the PSU optimization protocol) is given. Finally, in terms of instantiation, two constructions of pm-PEQT are given respectively: the first is based on permutation sharing (Permute+Share) and multi-point oblivious pseudorandom function (mp-OPRF); the second is based on the decisional Diffie-Hellman (DDH) assumption; through pm-PEQT combined with existing efficient constructions of LFHE and OT, a secure and efficient PSU protocol applicable to unbalanced scenarios is instantiated.
[0080] Construct a basic PSU protocol based on the leveled homomorphic encryption (LFHE) technology. In this embodiment, the basic PSU protocol is constructed based on LFHE as follows:
[0081] (1) S generates the public key pk and private key sk of FHE, and secretly stores the private key; encrypts each element using pk: c i = FHE.Enc(pk, x i ), i ∈ [m], and sends the public key and ciphertext to R;
[0082] (2) R selects random values r = [r 1 , …, r m , calculates the polynomial according to its own set Y where x is the independent variable of the function f, and then, according to the properties of fully homomorphic encryption, performs homomorphic computation on the ciphertext c i to obtain a new ciphertext c i ′ = FHE.Enc(pk, r i + f(x i ), i ∈ [m], and sends the new ciphertext c i ′ to S;
[0083] (3) S can decrypt the new ciphertext c i ′ to obtain r i ′ = r i + f(x i ), and returns r i ′ to R;
[0084] (4) R verifies r i ′ = r iWhether it holds. If it holds, let b i = 0; otherwise b i = 1;
[0085] (5) R and S run the oblivious transfer protocol. R inputs b i ∈ {0, 1}, and S inputs (⊥, x i ); when b i = 1, R obtains x i , otherwise R obtains ⊥, where ⊥ represents a meaningless symbol. That is, it is meaningless for R to obtain ⊥. According to the function of oblivious transfer, R can obtain the union; according to the algorithm, b i = 1 corresponds to the non-intersection elements. At this time, R can obtain the non-intersection element x i , and b i = 0 corresponds to the intersection elements. R cannot obtain the corresponding elements. At this time, R obtains the meaningless ⊥.
[0086] Because in step 2, R selects a random value to randomize the plaintext, and the decryption result r i ' does not leak information. In step 3, S returns the decryption result to R. R can judge whether f(x i ) = 0 holds according to whether r i and r i ' are equal. If it holds, it means that the corresponding x i belongs to the intersection, but R does not know which root of f(x) = 0 the x i corresponds to, that is, it cannot distinguish which element in Y the x i corresponds to. In addition, if r i and r i ' are not equal, f(x i ) ≠ 0 leaks the information of x i , but this leakage does not affect the security of the PSU protocol because according to the function of the PSU protocol, finally R also needs to obtain x i .
[0087] Subsequently, technologies such as Cuckoo hash, simple hash, batching, windowing, partitioning, Paterson-Stockmeyer algorithm, modulus switching, etc. are used to optimize the basic PSU to reduce the depth of the homomorphic operation circuit and improve the computing efficiency. The specific basic PSU protocol (omitting OT) and related optimization technologies are as shown in Figure 1 , where H represents the simple hash function and CH represents the Cuckoo hash.
[0088] In this embodiment, a basic PSU protocol is constructed based on the leveled fully homomorphic encryption (LFHE) scheme, and then the basic protocol is optimized. Finally, the permutation matrix privacy equality test (pm-PEQT) technology is used to determine whether the elements after permutation are in the intersection, and the oblivious transfer technology is used to enable the receiver to obtain the elements in the non-intersection. The specific framework is as Figure 2 shown. The general construction of the PSU protocol is as follows:
[0089] (1) [Protocol establishment phase] S and R negotiate the parameters of the fully homomorphic encryption scheme, cuckoo hash, naive hash, pm-PEQT protocol, and OT protocol;
[0090] (2) [Hashing phase] S uses cuckoo hash to hash all elements of set X to X c [i], where i ∈ [m c ; R uses naive hash to hash all elements of set Y to where X c [i] is a hash table, that is, S uses the cuckoo function to hash X to the hash table X c [i], which contains m c positions, and each position has only one value; is that 3 naive hash functions hash Y to the hash table, which can be regarded as a matrix, with a total of B rows and m c columns, and each column corresponds to the same hash value;
[0091] (3) [R pre-computes Y]
[0092] (301) R divides into α sub-matrices Y 1 , …, Y α , and each sub-matrix has B′ = B / α rows and m c columns. The i-th sub-matrix is represented as: Y i = [y i,1 , …, y i,B′ T , where i ∈ [α], and y i,k , k ∈ [B′] represents the k-th row of Y i ; where α is set autonomously according to the protocol and belongs to the block technology, which is an optimized value for balancing communication volume and computational volume, that is, the matrix is divided into α blocks; (302) For the j-th row y′ i,j = [y i,j,1 , …, y i,j,B′ T , where i ∈ [α], j ∈ [m c (to distinguish it from y i,k , y i,k represents the k-th row of the i-th sub-matrix, and y′i,j (representing the j-th column of the i-th sub-matrix), where y i,j,k represents y' i,j and the k-th element in it; R calculates the polynomial based on all elements of y' i,j and can obtain a polynomial of degree B', where y is the independent variable of the function f and a i,j represents the coefficient of the polynomial f i,j,k (y). R selects a random matrix i,j and sets the j-th column of the i-th sub-matrix of the coefficient matrix A as: A = [a i,j , …, a i,j,0 , …, a i,j,B′ T , i ∈ [α], j ∈ [m c , where a i,j,0 = r i,j + a' i,j,0 ;
[0093] (303) R uses the batch optimization technology of fully homomorphic encryption, i.e., the Single Instruction Multiple Data (SIMD) technology, to batch process the coefficient matrix A. Each row of A is regarded as a vector of length m c and each element belongs to the group R encodes each vector into β = m c / n plaintext polynomials. Each row of the i-th sub-matrix A i is encoded into β polynomials, denoted as A' i,j , i ∈ [α], j ∈ [β];
[0094] (4) [S encrypts X]
[0095] (401) S regards as a vector of length m c and each element belongs to the group Then it uses the SIMD technology to batch encode it into β = m c / n plaintext polynomials, denoted as X' 1 , …, X' β ;
[0096] (402) For each batch-processed plaintext polynomial X', S calculates the corresponding power number, where the i.2 j -th power number is
[0097] (403) S encrypts each power number using the public key generated by itself based on the fully homomorphic encryption scheme to obtain β groups of ciphertexts Cj , where \(j\in[\beta]\); \(S\) sends all the ciphertexts to \(R\);
[0098] (5) [R Homomorphic Computation Phase]
[0099] (501) For each group of received ciphertexts, \(R\) homomorphically computes the ciphertexts of all powers to obtain \(C\) j = [c j,0 , …, c j,B′ , where \(j\in[\beta]\), and \(c j.k , \(0\leq k\leq B'\) represents the ciphertext obtained by homomorphic computation , where, represents the \(k\) - th power of the \(j\) - th group of plaintext \(X'\);
[0100] (502) \(R\) homomorphically computes the dot product: homomorphically computes \(C'\) i,j = \(C j A' i,j , where \(i\in[\alpha]\), \(j\in[\beta]\), and performs modulo conversion on each ciphertext, then sends the modulo - converted ciphertexts to \(S\);
[0101] (6) [S Decryption Phase] \(S\) decrypts all the received ciphertexts and decodes the results into a matrix
[0102] (7) [pm - PEQT Phase] \(R\) and \(S\) run the pm - PEQT protocol: \(R\) inputs the matrix \(S\) inputs the matrix and the permutation \(\pi=(\pi c , \pi r )\); \(R\) obtains the zero - one matrix \(B a×m , where \(b ij = 1\) indicates \(r π(ij) = r' π(ij) , otherwise \(r π(ij) \neq r' π(ij) , where \(i\in[\alpha]\), \(j\in[m c \); \(b ij \) represents the element in the \(i\) - th row and \(j\) - th column of the matrix \(B α×m \), \(r π(ij) , r' π(ij) \) respectively represent the elements in the matrices (the elements after permutation using the permutation \(\pi\)); where, \(r π(ij) = r' π(ij) \), indicates and The corresponding positions are the same. When there are identical values in a certain column, it indicates that the elements corresponding to this column belong to the intersection elements; if there are no identical values in a certain column, it means that the elements corresponding to this column do not belong to the intersection, that is, R needs to obtain this element through the oblivious transfer protocol (OT); (8) [Output stage] R checks the zero-one matrix B α×m , for all elements in the j-th column, if all b ij = 0, i ∈ [α], then let b j = 1, otherwise let b j = 0 (that is, for the integration of the matrix B α×m , if all elements in a certain column of this matrix are 0, it means that the elements at the corresponding positions of this column are all different, so let the b j of this column be 1, indicating that the elements corresponding to this column belong to the non-intersection elements, and then R uses OT to select the elements corresponding to this column); then R and S run the OT protocol: for each column j ∈ [m c , R inputs b j , S inputs (⊥, X C [π c (j)]); if b j = 1, R obtains X c [π c (j)], otherwise obtains ⊥; finally, R outputs the union Y ∪ {X c [π c (j)]} for all j ∈ [m c , where π c (j) represents the π c permutation of column j, and π c is a random permutation on [m c , which can permute j to any value in [m c .
[0103] This embodiment uses the filling method of cuckoo hashing: The sender uses cuckoo hashing to hash |X| elements in the set X to m c positions, and both parties agree to fill ⊥ in the hash table. In this way, the filled ⊥ can be regarded as intersection elements and will not affect the subsequent union operation. According to the general construction of the above PSU protocol, a semi-honest secure PSU protocol can be constructed based on any IND-CPA secure and circuit-private LFHE, semi-honest secure pm-PEQT, and OT protocol.
[0104] Instantiation of the PSU protocol: According to the general construction framework of the PSU protocol, the underlying components instantiated in this embodiment include LFHE, pm-PEQT, and OT, and a specific PSU protocol can be constructed. Currently, there are many LFHE schemes and OT protocols that meet the conditions, but the construction of pm-PEQT is lacking.
[0105] This embodiment gives two constructions of pm-PEQT: the first is based on Permute+Share and multi-point oblivious pseudorandom function (mp-OPRF); the second is based on the DDH assumption. The specific constructions are as follows:
[0106] Construct pm-PEQT based on Permute+Share and mp-OPRF: S has matrix R′ α×m and matrix permutation π = (π c , π r ), R has matrix R α×m .
[0107] (1) S and R run the Permute+Share protocol: S inputs column permutation π c , R inputs each column of matrix R α×m . According to the function of the Permute+Share protocol, R obtains S obtains where i ∈ [α], j ∈ [m]; where, s π(ij) and both represent input values. denotes the exclusive OR operation. For bit strings r1 = 10101, r2 = 11001; if r1 = r2, then is an all-0 string.
[0108] (2) S and R continue to run the Permute+Share protocol: S inputs row permutation π r , R inputs each row of matrix . According to the function of the Permute+Share protocol, R obtains S obtains where i ∈ [α], j ∈ [m];
[0109] (3) R obtains the permutation matrix share S calculates the permutation matrix share where where, r (ij) represents the element in the i-th row and j-th column of matrix R α×m , r π(ij) represents the element in the i-th row and j-th column of the permutation matrix after permuting matrix R α×m using π; R inputs S π and runs the mp-OPRF protocol with S, and R obtains the pseudorandom function value F k (s π(ij)), S obtains the key k of the pseudo-random function, where F represents the pseudo-random function and k represents the key of the pseudo-random function; (4) S uses the permutation π = (π c , π r ) to permute the matrix R′ α×m and perform an XOR calculation with the corresponding elements of S′ π , where r′ represents the element of the matrix obtained by permuting the matrix R′ π(ij) using the permutation π = (π c , π r ), and s′ α×m represents the element of the matrix obtained by permuting S′ π(ij) using the permutation π = (π c , π r ), and then calculates the pseudo-random function values of each element using the key k π and sends all the pseudo-random function values to R; (5) R verifies
[0110] whether it holds. If it holds, let b = 1, otherwise b ij = 0, and outputs the binary matrix B ij , where the element in the i-th row and j-th column of the binary matrix B α×m is represented as b a×m . ij .
[0111] Construct pm-PEQT based on the DDH assumption: S has the matrix R′ α×m and the matrix permutation π = (π c , π r ), and R has the matrix R α×m . Let be a cyclic group of order q, and the DDH problem on the group is difficult. Let the hash function H output random elements on the group and simulate a random oracle.
[0112] (1) R selects a random value calculates and sends v ij = H(r ij ) a , i ∈ [α], j ∈ [m] to S, where represents randomly selecting a random value a in the group , is a standard mathematical symbol representing the set {0, 1, 2,..., q - 1}; H is the hash function, and H(r ij ) a represents the element r α×m in the matrix R ij Perform a hash operation and raise to the power of a; r ij Denote the element in the i-th row and j-th column of matrix R α×m ;
[0113] (2) S selects a random value Calculate v′ ij = H(r′ ij ) b and v″ ij = (v ij ) b , i ∈ [α], j ∈ [m], and respectively use the permutation π = (π c , π r ) to permute v′ ij and v″ ij , obtaining v′ π(ij) = π(v′ ij ), v″ π(ij) = π(v″ ij ); Send v′ π(ij) and v″ π(ij) to R; where r′ ij denotes the element in the i-th row and j-th column of matrix R′ α×m ;
[0114] (3) R verifies whether v″ π(ij) = (v′ π(ij) ) a holds. If it holds, let b ij = 1, otherwise b ij = 0, i ∈ [α], j ∈ [m], and output the binary matrix B α×m .
[0115] Combined with the existing LFHE scheme, OT protocol, and the construction of pm-PEQT, a secure and efficient PSU protocol applicable to unbalanced scenarios can be obtained.
[0116] Offline / Online Execution: In the PSU protocol constructed in the present invention, the preprocessing process of the receiver can be completely completed offline without the participation of the sender, further improving the application efficiency. Specifically, the receiver can set an upper bound on the set size of the sender in advance, and then select parameters locally and perform preprocessing calculations. Subsequently, in the online phase, after knowing the actual set size of the sender, the receiver can send the specific parameters to the sender, and the sender can fill in the same elements known to both parties, such as ⊥, to complete the subsequent protocol.
[0117] Traffic is independent of element length (except for OT): The PSU protocol constructed in the present invention has a communication complexity independent of the length of elements in the set during processes other than the OT protocol phase. Specifically, both parties can use the same collision-resistant hash function to hash the elements in their respective sets to a small fixed size, and then use the hash values to replace the set elements for subsequent PSU calculations. The sender needs to save the mapping relationship between its set elements and hash values, and in the final OT phase, input the original set elements instead of the corresponding hash values so that the receiver can obtain the original non-intersecting elements.
[0118] Implementation and comparison of the PSU protocol: In this embodiment, the BFV fully homomorphic encryption scheme implemented in the FHE open-source library - SEAL library is used as an instantiation of the underlying LFHE, and the OT protocol implemented in the LibOTe open-source library is used as an instantiation of the underlying OT protocol; this private institution separately implemented pm-PEQT based on Permute+Share and mp-OPRF and pm-PEQT based on the DDH assumption; two PSU protocols were respectively implemented according to the general construction framework of the PSU protocol:
[0119] PSU PS : The PSU protocol is constructed based on LFHE, pm-PEQT, and OT, where pm-PEQT is designed based on Permute+Share and mp-OPRF;
[0120] PSU DDH : The PSU protocol is constructed based on LFHE, pm-PEQT, and OT, where pm-PEQT is constructed based on the DDH assumption;
[0121] Implementation environment: In this embodiment, all test experiments are executed in a test environment with an Intel Core processor, 3.00GHz, and 8GB RAM, and the Linux tc command is used to simulate network latency and bandwidth. One local area network environment: 10Gbps throughput, 0.2ms round-trip time (RTT). Two wide area network environments are 100Mbps and 10Mbps bandwidth respectively, and each has an RTT of 80ms. We set the computational security parameter to 128 bits and the statistical security parameter to 40 bits.
[0122] This embodiment first tests the communication efficiency and computational efficiency of PSU DDH and PSU PS with small set sizes of 2 10 , 2 11M , and large set sizes of 2 18 , 2 20 , 2 22, in a 10 Gbps bandwidth environment, the number of threads is 1 and 4 respectively. The specific test data is shown in Table 1. According to the experimental data, the PSU of this embodiment is very efficient in the unbalanced scenario. For data with a large set of millions and a small set of a relatively small size (such as thousands), the communication volume of the PSU DDH is only 4.57 MB, and the online calculation time does not require 10 seconds.
[0123] Table 1. Test results of communication volume (MB) and running time (s)
[0124]
[0125]
[0126] Subsequently, this embodiment is compared with the PSU DDH , PSU PS , and the current fastest PSU protocols (PSU1, PSU*1, and PSU*2. PSU1 and PSU*1 are from the paper Shuffle-based private set union: Faster and more secure published in Usenix Security 2022 in 2022, and PSU*2 is from the paper Scalable private set union from symmetric-key techniques published in ASIACRYPT 2019 in 2019. Among them, the PSU * represents a non-standard secure PSU protocol. The test environment is as follows: the small set sizes are 2 10 , 2 11 , the large set sizes are 2 18 , 2 19 , the bandwidth environments are 10 Gbps (0.2 ms RTT), 100 Mbps, and 10 Mbps (80 ms RTT), and the number of threads is 1 and 4 respectively. The specific comparison data is shown in Table 2. According to the comparison data, in the case of a set size of (2 10 , 2 19 ) and a single thread of 10 Gbps, the communication efficiency of PSU DDH is 300 times higher than that of PSU, and the computing efficiency is increased by 30 times.
[0127] Table 2. Comparison of communication volume (MB) and running time (s)
[0128]
[0129] Example 3
[0130] This embodiment provides a privacy set operation method based on fully homomorphic encryption. In response to an instruction to find the cardinality of the intersection of privacy sets, the server and the client perform interactive calculations through the PSI-card protocol to obtain the number of intersection elements; in response to an instruction to find the sum and cardinality of the intersection of privacy sets, the server and the client perform interactive calculations through the PSI-sum-card protocol to obtain the cardinality of the intersection and the sum of the intersection elements, or obtain the sum of the data corresponding to the intersection elements.
[0131] This embodiment gives a secure and efficient PSI-card protocol based on the leveled fully homomorphic encryption (LFHE) scheme. Subsequently, a non-intersection element elimination technique is proposed to turn non-intersection elements into encryptions of 0 while keeping the encryption of intersection elements unchanged, and then combined with the LFHE technique, a secure and efficient PSI-sum-card protocol is designed. The communication complexity of the PSI-card and PSI-sum-card protocols in this embodiment is linearly related to small sets and logarithmically related to large sets. Therefore, the PSI-card and PSI-sum-card protocols proposed by the present invention are highly applicable to unbalanced application scenarios, namely the server-client scenario, where the receiver (client) has a small set; the sender (server) has a large set, and the bandwidth between the two parties is very limited.
[0132] For convenience, in this embodiment, S is used to represent the sender (server) with the large set X = {x 1 , …, x n}, the data set E = {e 1 , …, e n} corresponding to the elements of the large set, R is used to represent the receiver (client) with the small set Y = {y 1 , …, y m}, the data set D = {d 1 , …, d m} corresponding to the elements of the small set. Let [n] = {1, …, n}, [m] = {1, …, m}; R a×m represents a matrix of α rows and m columns, and π c represents a column permutation of the matrix; bold lowercase letters represent vectors, such as x.
[0133] PSI-sum-card protocol construction idea: First, based on LFHE, use the methods of multiplicative randomization and random permutation to construct the basic PSI-card protocol. Subsequently, a non-intersecting element elimination technique is proposed, and the two parties construct the basic PSI-sum-card protocol through an additional round of interaction. Specifically: After the two parties run the basic PSI-card protocol, the receiver R obtains the positions of the intersecting elements after permutation, but does not know the specific intersecting elements. Subsequently, the receiver R encrypts 1 at the positions corresponding to the intersecting elements and encrypts 0 at the positions corresponding to the non-intersecting elements. Then, the sender uses the ciphertext homomorphic multiplication of LFHE to obtain the ciphertext of the intersecting elements, the ciphertext corresponding to 0 at other positions, and uses the ciphertext homomorphic addition of LFHE to calculate the ciphertext of the sum of the intersecting elements and send it to the receiver. The receiver can use the private key to decrypt and obtain the sum of the intersecting elements.
[0134] The basic PSI-card and PSI-sum-card protocols constructed based on the above ideas have optimal communication complexity, that is, they are linearly related to small sets, but the homomorphic circuit depth of the protocols is relatively deep and the computational complexity is relatively high. Finally, in this embodiment, the PSI-sum-card protocol is optimized to obtain a secure and efficient PSI-sum-card protocol (including the PSI-card protocol).
[0135] Basic PSI-card protocol: Based on the LFHE technology, use the multiplicative randomization method to construct the basic PSI-card protocol as follows:
[0136] (1) The client R generates a public-private key pair (pk, sk) of LFHE and secretly stores the private key sk; then, uses the public key to encrypt each element y 1 , …, y m} of Y to obtain the ciphertext of each element: c i = FHE.Enc(pk, y i ), i ∈ [m]. Then, R sends the public key pk and all the ciphertexts c i , i ∈ [m] to the server S; i
[0137] (2) The server S encodes the large set X into a polynomial f and randomizes it using the multiplicative randomization method, and performs ciphertext calculations on the ciphertexts c i , i ∈ [m] based on the LFHE technology. Specifically as follows: First, calculate the polynomial f according to the set X = {x 1 , …, x n} such that Then select random values r = [r 1 , …, r m , randomize f using the multiplicative randomization method. Subsequently, perform operations on the ciphertexts c i, for \(i\in[m]\), perform encrypted computation \(r\) i f(c i ), to obtain the ciphertext \(c\) i ' = FHE.Enc(pk, r i f(y i )) for \(i\in[m]\). Subsequently, \(S\) selects a random permutation \(\pi\) on \([m]\) to permute the \(m\) ciphertexts \(c\) i ' to obtain \(c'\) π(i) , and sends the permuted ciphertext \(c'\) π(i) to the client \(R\);
[0138] (3) \(R\) receives all the permuted ciphertexts \(c'\) π(i) , and can use the decryption private key \(sk\) to decrypt the permuted ciphertext to obtain the decryption result \(r'\) i = r π(i) f(y π(i) ). Among them, if \(r'\) i = 0, it means that the element after position permutation belongs to the intersection; otherwise, the element after position permutation does not belong to the intersection. Therefore, \(R\) can calculate the number of 0s in the decryption result to obtain the number of elements in the intersection, which is the cardinality of the intersection \(|X\cap Y|\).
[0139] Because the use of LFHE encryption in step 1 ensures the security of the elements of the set \(Y\) of the client \(R\). In step 2, the server \(S\) selects random values to perform multiplicative randomization on the polynomial, and at the same time selects a random permutation to permute the ciphertext, ensuring the security of the elements in the set \(X\). In step 3, \(R\) can decrypt all the permuted ciphertexts. Since the positions that are not equal to 0 are randomized by the random numbers selected by \(S\) and do not leak information, the positions equal to 0 correspond to the intersection elements, but the random permutation selected by \(S\) ensures that \(R\) does not know the information of the intersection elements. The basic PSI - card protocol is as Figure 3 shown.
[0140] Basic PSI - sum - card protocol: Based on the basic PSI - card protocol, use the non - intersection element elimination technique to convert all non - intersection elements to 0. In this way, based on the homomorphic computing technology of LFHE, the ciphertext of the sum of all intersection elements can be calculated. Finally, the client \(R\) can use the decryption private key \(sk\) to decrypt the ciphertext to obtain the sum of the intersection elements. The first 3 steps of the specific protocol are the same as the basic PSI - card protocol, and the subsequent steps are described as follows:
[0141] (4) The client \(R\) uses the public key \(pk\) of LFHE to encrypt \(b\) i = 1 for the positions where \(r'\) i = 0, and encrypts \(b\) i = 0 for the positions where \(r'\) i ≠ 0 (that is, if \(r'\) i = 0, then let the symbol \(b\) i= 1, and then encrypt b i ; If r' i ≠ 0, then set the symbol b i = 0, and then encrypt b i ), that is R sends the ciphertext to the server S;
[0142] (5) After S receives the ciphertext , for c in step (1) i = FHE.Enc(pk, y i ), i ∈ [m], use the same random permutation π for permutation to obtain the permuted ciphertext c π(i) . Then, based on the property of the LFHE multiplicative homomorphism, S calculates the product of the ciphertexts at the corresponding positions in the ciphertext state Subsequently, for the calculated ciphertext , use the additive homomorphism to calculate the ciphertext of the sum of the intersection elements and send c sum to R;
[0143] (6) After R receives the ciphertext c sum , use the private key sk to decrypt the ciphertext, and the sum of the intersection elements can be obtained
[0144] Because in step 4, R knows which positions are the intersection elements through r' i = 0, so the ciphertext of 1 can be calculated using the fully homomorphic encryption LFHE, and the ciphertext of 0 can be calculated at other positions; The security of LFHE ensures that S cannot obtain other information; In step 5, S can perform the same permutation on the ciphertext corresponding to each element to ensure the correspondence of positions, and then use the multiplicative homomorphism to calculate the encryption where the corresponding position of the intersection element is the intersection element itself, and the encryption where the corresponding position of other non-intersection elements is 0, realizing the elimination of non-intersection elements. Finally, based on the property of the additive homomorphism of LFHE, S performs the summation operation in the ciphertext state to calculate the ciphertext of the sum of all intersection elements. In step 6, R can decrypt the ciphertext to obtain the sum sum of the intersection elements. The basic PSI-sum-card protocol is as Figure 4 shown.
[0145] The basic PSI-sum-card protocol calculates the sum of set elements. However, for set operations with labels, that is, the operation of summing the labels (data) of the intersection elements by both parties, it cannot be directly obtained using the PSI-sum-card protocol. Therefore, in this embodiment, a basic Labeled PSI-sum-card protocol is designed to achieve the operation of summing the labels (data) of the intersection elements. However, in large sets and small sets (comparing the number of set elements, a set with the number of elements greater than the set value is a large set, and a set with the number of elements less than the set value is a small set), each element (even if the elements are the same) may correspond to different label data. For example: the large set x = {x 1 , …, x n} corresponds to the label data set E = {e 1 , …, e n}, the small set Y = {y 1 , …, y m} corresponds to the label data set D = {d 1 , …, d m}, where there is an intersection element x i = y j , but the corresponding label data may be different e i ≠ d j .
[0146] The basic Labeled PSI-sum-card protocol includes a private set intersection and cardinality protocol for small set labels and a private set intersection and cardinality protocol for large set labels.
[0147] In this embodiment, first, consider the private set intersection and cardinality protocol for small set labels (Labeled PSI-sum-card with small set). The final calculation is the sum of the data of the small set labels corresponding to the intersection elements, that is, the sum of the label data corresponding to the intersection elements in D = {d 1 , …, d m}. The specific protocol is as follows:
[0148] The first 3 steps of the basic Labeled PSI-sum-card with small set protocol are the same as those of the basic PSI-card protocol. The subsequent process is as follows:
[0149] (4) The client R uses the public key pk of LFHE to encrypt b i = 1 at the position where r′ i = 0, and encrypts b i = 0 at the position where r′ i ≠ 0, that is, In addition, R uses the public key pk of LFHE to encrypt the tag data corresponding to each element: c″ i = FHE.Enc(pk, d i ), i ∈ [m], where the element y i corresponds to the tag data d i ; then R sends and c″ i to the server S;
[0150] (5) After the server S receives the ciphertext and c″ i , it permutes c″ i using the same random permutation π to obtain the permuted ciphertext c″ π(i) = π(c″ i ); then, it calculates the product of the ciphertexts at the corresponding positions in the ciphertext state Subsequently, for the ciphertext , it uses additive homomorphism to calculate the ciphertext of the sum of the tag data corresponding to the intersection elements: and sends the ciphertext c sum to R;
[0151] (6) After R receives the ciphertext c sum , it decrypts the ciphertext using the private key sk, and can obtain the sum of the tag data corresponding to all intersection elements
[0152] Compared with the basic PSI-sum-card protocol, in step (4) of the basic Labeled PSI-sum-card with small set protocol, the client needs to encrypt the tag data D = {d 1 , …, d m} corresponding to the small set elements in the corresponding order, generate the ciphertext of the tag data and send it to the server. The server can perform the non-intersection element (corresponding tag data) elimination technique and calculate the sum of the tag data corresponding to the intersection elements. The basic Labeled PSI-sum-card with small set protocol is as Figure 5 shown.
[0153] The basic Labeled PSI-sum-card with small set protocol can only sum the tag data corresponding to the small set elements and cannot sum the tag data corresponding to the large set elements. Because the client does not have the tag data E = {e 1 , …, e n} corresponding to the large set elements, it cannot encrypt the tag data and send it to the server. Subsequently, the server cannot perform the non-intersection element elimination process and cannot calculate the sum of the tag data corresponding to the large set elements.
[0154] To solve the above problems, the present embodiment uses the following techniques. First, calculate the polynomial g such that for all x i ∈ X, g(x i ) = e i . Specifically, it can be calculated according to n points (x i , e i ), i ∈ [n] using the Lagrange interpolation formula: where Still using the multiplicative randomization method, calculate the polynomial h(x) = g(x) + rf(x), where Therefore, if y j ∈ X ∩ Y, then there exists x j ∈ X such that y j = x i , that is, h(y j ) = g(x i ) + rf(x i ) = g(x i ) + 0 = g(x i ) = e i . If is a random value. Then, during the fully homomorphic calculation process, the server can calculate the ciphertext of rf(y j ) and the ciphertext of h(y j ) respectively. The ciphertext of rf(y j ) can be permuted and transmitted to the client for decryption to determine which positions are the intersections, and encrypt 1 at the positions corresponding to the intersections and encrypt 0 at other positions. After sending it to the server, it can be used to eliminate the label data corresponding to non-intersection elements.
[0155] According to the above idea, the present embodiment constructs a privacy set intersection and sum-of-potentials protocol for large set labels (Labeled PSI-sum-card with large set). This protocol calculates the sum of the data of the large set labels corresponding to the intersection elements, that is, the sum of the label data corresponding to the intersection elements in E = {e 1 , …, e n}.
[0156] Specifically, the first three steps of the protocol are similar to the basic PSI-card protocol. Only in step (2), the server S calculates the polynomial h(x) = g(x) + rf(x) based on X = {x 1 , …, x n} and E = {e 1 , …, e n}, where h(x i ) = e i, and calculate the ciphertext \(c''\) according to the properties of LFHE i = FHE.Enc(pk, h(y i ), \(i\in[m]\) and save it; the last three steps are similar to the basic PSI - sum - card protocol, except that the above \(c''\) is used in step (5) i for homomorphic calculation. The detailed steps are as follows:
[0157] (1) The client \(R\) generates the public - private key pair \((pk, sk)\) of LFHE and secretly saves the private key \(sk\); then, uses the public key to encrypt each element \(y 1 ,\cdots,y m \) of \(Y = \{y i \}\), and obtains the ciphertext of each element: \(c i = FHE.Enc(pk, y i ), \(i\in[m]\). Then, \(R\) sends the public key \(pk\) and all the ciphertexts \(c i \), \(i\in[m]\) to the server \(S\);
[0158] (2) The server \(S\) encodes the large set \(X\) into a polynomial \(f\) and randomizes it using the multiplication randomization method, encodes \(X\) and \(E\) into a polynomial \(h\), and performs homomorphic calculations on the ciphertexts \(c i \), \(i\in[m]\) respectively based on the LFHE technology. Specifically, first calculate the polynomial \(f\) according to the set \(X=\{x 1 ,\cdots,x n \}\) such that Then select random values \(r = [r 1 ,\cdots,r m \), use the multiplication randomization method to perform a randomized calculation \(rf\) on \(f\), and calculate the polynomial \(h(x)=g(x)+rf(x)\) based on \(X = \{x 1 ,\cdots,x n \}\) and \(E=\{e 1 ,\cdots,e n \}\), where \(h(x i ) = e i \). Subsequently, in the ciphertext state, perform fully homomorphic calculations on the ciphertexts \(c i \), \(i\in[m]\) according to the polynomials \(f\) and \(h\) respectively, that is, perform homomorphic calculations \(r i f(c i )\) and \(h(c i ) = g(c i )+r i f(c i )\), and obtain the ciphertexts \(c' i = FHE.Enc(pk, r i f(y i ))\) and \(c'' i = FHE.Enc(pk, h(y i), i ∈ [m]; S saves c″ i , and selects a random permutation π on [m] for the m ciphertexts c i ′ to obtain c′ after permutation π(i) , and sends the permuted ciphertext c′ π(i) to the client R;
[0159] (3) R receives all the permuted ciphertexts c′ π(i) , and can use the decryption private key sk to decrypt the permuted ciphertext to obtain the decryption result r′ i = r π(i) f(y π(i) ), where if r′ i = 0, it means that the element after position permutation belongs to the intersection, otherwise, the element after position permutation does not belong to the intersection. Therefore, R can calculate the number of 0s in the decryption result to obtain the number of elements in the intersection, which is the cardinality of the intersection |X ∩ Y|;
[0160] (4) The client R uses the public key pk of LFHE to encrypt b i = 1 at the positions where r′ i = 0, and encrypts b i = 0 at the positions where r′ i ≠ 0, that is R sends the ciphertext to the server S;
[0161] (5) After S receives the ciphertext , it permutes the ciphertext c″ i = FHE.Enc(pk, h(y i )) in step 3) using the same random permutation π to obtain the permuted ciphertext c″ π(i) = π(c″ i ). Then, S calculates the product of the ciphertexts at the corresponding positions in the ciphertext state based on the multiplicative homomorphism property of LFHE Subsequently, for the calculated ciphertext uses the additive homomorphism to calculate the ciphertext of the sum of the intersection elements and sends csum to R;
[0162] (6) After R receives the ciphertext c sum , it decrypts the ciphertext using the private key sk to obtain the sum of the intersection elements
[0163] Because for any y j ∈ X ∩ Y, there exists x j ∈ x such that y j = x i , that is h(yj ) = g(x i ) + rf(x i ) = g(x i ) + 0 = g(x i ) = e i , so h(y j ), j ∈ [m] represents the label data e corresponding to all intersection elements i , where b i corresponds to h(y π(i) ). If y π(i) ∈X∩Y, then b i = 1, and for other b i = 0. Therefore, represents the sum of the label data corresponding to all intersection elements. The basic Labeled PSI - sum - card with large set protocol is as Figure 6 shown.
[0164] PSI - card optimization protocol: The homomorphic computing circuit of the basic PSI - card protocol has a relatively deep depth and a high computational complexity. In this embodiment, technologies such as Cuckoo hash, simple hash, batching, windowing, partitioning, Paterson - Stockmeyer algorithm, and modulus switching are used to optimize the basic PSI - card, reduce the depth of the homomorphic operation circuit, and improve the computational efficiency. The specific optimization protocol is as follows:
[0165] (1) The server S and the client R first negotiate the parameters of the LFHE scheme, Cuckoo hash, and simple hash;
[0166] (2) The server S pre - processes the large set X. First, it hashes all elements of the set X to This table contains m c columns, and each column can contain B elements;
[0167] (3) S divides into α blocks row - by - row. The j - th column of each block can be represented as X i,j , i ∈ [α], j ∈ [m c , and each column of each block contains B′ = B / α elements. The j - th column of the i - th block can be represented as [x i,j,1 , …, x i,j,B′ T . S calculates the polynomial for the elements of each column of each block S selects a random matrix , and according to the polynomial coefficients calculated for each of the above blocks, set the coefficient matrix A correspondingly: Let the \(j\)-th column of the \(i\)-th block of the coefficient matrix A be \(A_{ij}\) i,j = [r i,j a i,j,0 , …, r i,j a i,j,B′ , where \(i\in[\alpha]\) and \(j\in[m T ; c
[0168] (4) S uses the single instruction multiple data (SIMD) optimization technique of the LFHE scheme to batch process the coefficient matrix A. Each row of A can be regarded as a vector containing \(m\) c elements, which can be encoded into \(\beta = m c / n\) plaintext polynomials. Each row of the \(i\)-th block is represented as \(A'_{ij}\), where \(i\in[\alpha]\) and \(j\in[\beta]\); i,j
[0169] (5) The client R processes the small set Y and hashes all elements of the set Y to the table \(Y c [i]\), where \(i\in[m c \), which can be regarded as a vector of length \(m c \). It is batch encoded into \(\beta = m c / n\) plaintext polynomials, denoted as \(Y'_{i1}\), …, \(Y'_{i\beta}\). Then, R calculates the powers corresponding to the plaintext polynomial \(Y'\). Among them, the \(i\cdot2 1 \)-th power is β for \(1\leq i\leq2 j - 1\). l Finally, R encrypts each power using the LFHE public key to obtain \(\beta\) groups of ciphertexts \(C_j\), where \(j\in[\beta]\), and sends them to S; j
[0170] (6) After the server S receives all the ciphertexts, it can perform fully homomorphic calculations on the ciphertext polynomial values in the ciphertext state. First, S homomorphically calculates the ciphertexts of all powers from 0 to \(B'\) to obtain \(C_j = [c_{j0}, …, c_{jB'}]\), where \(j\in[\beta]\), and \(c_{jk}\), \(0\leq k\leq B'\) is represented as the ciphertext of the homomorphic calculation j of j,0 . Then, S homomorphically calculates the ciphertext of the dot product \(C'_{ij}=C_jA'_{ij}\), where \(i\in[\alpha]\) and \(j\in[\beta]\), and performs modulo conversion on each ciphertext. Finally, S selects \([m j,B′ and j.k 0\leq k\leq B'\) is represented as the ciphertext of the homomorphic calculation of i,j C j A' i,j , \(i\in[\alpha]\), \(j\in[\beta]\), and c For the random permutation π on [m], perform column transformation on the ciphertext matrix and send the permuted ciphertext matrix to R; where, Denotes the k-th power of the j-th group of plaintext Y′;
[0171] (7) R uses the decryption private key sk to decrypt all received ciphertexts to obtain the plaintext matrix. For the i-th row of the plaintext matrix, if there is a 0 at a certain position, then let b i = 1, otherwise let b i = 0; Then, R calculates the cardinality of the intersection
[0172] This embodiment uses the filling method of cuckoo hashing: The receiver uses cuckoo hashing to hash |Y| elements in the set Y to m positions, and fills the empty positions in the hash table with ⊥ or other symbols not in the set elements. In this way, when calculating the sum of the data corresponding to the cardinality of the intersection and the intersection elements (⊥ can correspond to random data), ⊥ will not be counted in it. Because the symbols filling non-set elements do not appear in the intersection, that is, the decryption result corresponding to the first decryption by R is a non-zero value and will not be counted in the number of intersection elements. At the same time, R encrypts all positions where the decryption result is non-zero to 0. When summing up later, the product of the plaintext corresponding to this position is also 0 and will not affect the sum of the data corresponding to the intersection elements. The optimized PSI-card protocol is as Figure 7 shown, where H represents the naive hash function, CH represents the cuckoo hash, and π represents the permutation on [m], and its action on the ciphertext matrix is the column permutation of the matrix.
[0173] According to the efficient optimization of the PSI-card protocol, this embodiment optimizes the PSI-sum-card protocol, the Labeled PSI-sum-card with small set protocol, and the Labeled PSI-sum-card with large set protocol to reduce the depth of the homomorphic operation circuit and improve the computing efficiency.
[0174] The Labeled PSI-sum-card optimization protocol includes the Labeled PSI-sum-card with small set optimization protocol and the Labeled PSI-sum-card with large set optimization protocol.
[0175] The first three steps of the PSI-sum-card optimization protocol completely use the PSI-card optimization protocol, and the subsequent steps are the same as the basic PSI-sum-card protocol. Specifically as Figure 8 shown.
[0176] The first three steps of the optimized protocol for private set intersection and potential with small set labels (Labeled PSI-sum-card with small set optimized protocol) are completely the same as those of the PSI-card optimized protocol, and the subsequent steps are the same as those of the basic Labeled PSI-sum-card with small set protocol. Specifically, as shown in Figure 9 shown below.
[0177] Compared with the basic Labeled PSI-sum-card with small set protocol, the optimized protocol for private set intersection and potential with large set labels (Labeled PSI-sum-card with large set optimized protocol) needs to homomorphically compute the ciphertext of the polynomial h(y i f(y i ) in the same way as the ciphertext of the polynomial r i ) = g(y i ) + r i f(y i ). However, there are significant differences in the calculation of PSI-card, as well as the subsequent element elimination and the calculation of the corresponding data sum for intersection. The specific optimized protocol is as follows:
[0178] (1) The server S and the client R first negotiate the parameters of the LFHE scheme, cuckoo hashing, and naive hashing;
[0179] (2) The server S preprocesses the large set X and the corresponding label set E. First, it uses naive hashing to hash all elements of the set X into This table contains m c columns, and each column can contain B elements. The label set E is filled correspondingly into
[0180] (3) S selects a random matrix Then, S divides into α blocks row by row. The j-th column of each block can be represented as X i,j , E i,j , i ∈ [α], j ∈ [m c . Each column of each block contains B' = B / α elements. The j-th column of the i-th block can be represented as [x i,j,1 , …, x i,j,B′ T and [e i,j,1 , …, e i,j,B′ T . S calculates the polynomial i,j for each column element of each block of X a i,j,k represents the polynomial fi,j Coefficient of (x); for X i,j , E i,j For each column element of each block, calculate the polynomial g i,j (x) such that g i,j (x i,j,k ) = e i,j,k , 0 ≤ k ≤ B′; then calculate h ij (x) = g i,j (x) + r ij f ij (x) = b i,j,0 + b i,j,1 x + … + b i,j,B′ - 1 x B′-1 + b i,j,B′ x B′ . S sets the coefficient matrix A f and A h according to the polynomial coefficients calculated for each block above: Let the (i, j)-th element of the coefficient matrix A f be A f i,j = [r i,j a i,j,0 , …, r i,j a i,j,B′ T , i ∈ [α], j ∈ [m c ; Let the (i, j)-th element of the coefficient matrix A h be A h i,j = [b i,j,0 , …, b i,j,B′ T , i ∈ [α], j ∈ [m c ;
[0181] (4) S uses the single-instruction multiple-data optimization technology of the LFHE scheme to batch process the coefficient matrices A f and A h . Each row of A f and A h is a vector of m c and can be encoded as β = m c / n plaintext polynomials. Each row of the i-th block is represented as and i ∈ [α], j ∈ [β];
[0182] (5) The client R processes the small set Y and hashes all elements of the set Y to the table Y c [i], i ∈ [m c , which can be regarded as a vector of length m c and is batch-encoded as β = mc / n plaintext polynomials, denoted as Y′ 1 , …, Y′ β . Then, R calculates the exponents corresponding to the plaintext polynomial Y′, where the i·2 j -th exponent is 1 ≤ i ≤ 2 l -1, l represents the windowing technique parameter, a parameter for balancing the computational amount and communication amount, which can be adjusted and set by oneself. Finally, R encrypts each exponent using the LFHE public key to obtain β ciphertexts C j , j ∈ [β], and sends them to S;
[0183] (6) After the server S receives all the ciphertexts, it can homomorphically calculate the polynomial values of the ciphertexts in the ciphertext state. First, S homomorphically calculates the ciphertexts of all exponents from 0 to B′ to obtain C j = [c j,0 , …, c j,B′ , j ∈ [β], where c j.k , 0 ≤ k ≤ B′ represents the ciphertext of the homomorphic calculation . Then S homomorphically calculates the ciphertext of the dot product i ∈ [α], j ∈ [β], and performs modulus conversion on each ciphertext. Finally, S selects a random permutation π on [m c , and performs column transformation on the ciphertext matrices and , and sends the permuted ciphertext matrix to R, and saves the ciphertext matrix for itself. Among them, represents homomorphically calculating the ciphertext using the coefficients corresponding to the polynomial f in the ciphertext state, represents the ciphertext of f(y j ); represents performing homomorphic calculation in the ciphertext state using the polynomial h;
[0184] (7) R uses the decryption private key sk to decrypt the permuted ciphertext matrix to obtain the plaintext matrix. For all positions i ∈ [α], j ∈ [m c of the plaintext matrix, for the positions where the decryption result is 0, let b ij = 1, otherwise let b ij = 0; then, R calculates the cardinality of the intersection
[0185] (8) R uses the public key pk of LFHE to encrypt b ij , that is, i ∈ [α], j ∈ [m c . R sends to the server S;
[0186] (9) After \(S\) receives the ciphertext , combined with the permuted ciphertext matrix in step (4) , based on the properties of LFHE fully homomorphic operations, calculate the product of ciphertexts at corresponding positions in the ciphertext state Among them, in step (1), \(\alpha\times m_c\) polynomials \(h_{ij}(x)\) are calculated, \(i\in\alpha\), \(j\in[m_c]\), and \(h_{i,\pi j}\) represents column permutation of \(h(x)\) using \(\pi\); a total of \(\alpha\times m\) ij ciphertexts are obtained. Subsequently, for all the calculated ciphertexts c , use additive homomorphic calculation to calculate the sum of corresponding data of the intersection and send \(c\) to \(R\); sum
[0187] (10) After \(R\) receives the ciphertext \(c\) sum , use the private key \(sk\) to decrypt the ciphertext, and the sum of the intersection elements can be obtained
[0188] The optimized protocol of Labeled PSI - sum - card with large set adopts the same cuckoo hash padding method as the optimized protocol of PSI - card. The calculations of polynomials \(f\) and \(h\) are similar to the basic Labeled PSI - sum - card with large set, but the fully homomorphic calculation of ciphertexts is similar to the optimized protocol of PSI - card. \(S\) calculates two ciphertext matrices and , uses the same column permutation, and sends them to \(R\). \(R\) can decrypt to determine which columns correspond to the positions of intersection elements , and locally saves them after permutation, corresponding to the ciphertexts of the labeled data of the large set. After \(S\) receives the ciphertext from \(R\) (this ciphertext encrypts 1 at the positions corresponding to the intersection elements and 0 at other positions), calculate the ciphertext multiplication. For the positions of non - intersection elements, it becomes the ciphertext for 0, and for the positions of intersection elements, it corresponds to the ciphertexts of the labeled data of the large set. Then perform ciphertext addition on all the ciphertexts to calculate the sum of the labeled data corresponding to the intersection elements of the large set. Specifically, as Figure 10 shown.
[0189] Find the average value of the corresponding data of the intersection: \(R\) knows the sum of the corresponding data of the intersection and the cardinality (number of elements) of the intersection, and can calculate the average value: sum / |X ∩ Y|;
[0190] Offline / Online Execution: In the construction of the PSI-card and PSI-sum-card protocols in the present invention, the preprocessing process of the sender can be completely completed offline without the participation of the receiver, further improving the application efficiency. Specifically, the sender can set the upper bound of the set size of the receiver in advance, and then select parameters locally and perform preprocessing calculations. Subsequently, in the online phase, after knowing the actual set size of the receiver, the sender can send the specific parameters to the receiver. The receiver can fill in ⊥ or symbols in other non-set elements, and then complete the subsequent protocol.
[0191] Protocol Communication Volume Independent of Element Length: The communication complexity of the PSI-card and PSI-sum-card protocols and their variants constructed in the present invention is independent of the length of the elements in the set. Specifically, both parties can use the same collision-resistant hash function to hash the elements in their respective sets to a small fixed size, and then use the hash values for subsequent protocol calculations.
[0192] Embodiment 4
[0193] This embodiment provides a privacy set operation system based on fully homomorphic encryption;
[0194] A privacy set operation system based on fully homomorphic encryption, including a server and a client;
[0195] The server and the client interact and calculate through a protocol in response to a privacy set operation instruction to obtain a set operation result.
[0196] The detailed processes of each component have been introduced in Embodiment 1.
[0197] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A privacy set operation method based on fully homomorphic encryption, characterized in that, in response to a privacy set operation instruction, the server and the client perform interactive calculations through a protocol to obtain a set operation result; wherein, the protocol is constructed based on the leveled homomorphic encryption LFHE technology; if the privacy set operation instruction is an instruction for privacy set union PSU, the sender S and the receiver R perform interactive calculations through the PSU protocol to obtain the union of the sets; the PSU protocol adopts a basic PSU protocol constructed based on the leveled homomorphic encryption technology, and after optimizing the basic PSU protocol, combines a permutation matrix privacy equality test and oblivious transfer to obtain an optimized PSU protocol; the sender is a client having a small set X = {x1,..., xm}, denoted as S; the receiver is a server having a large set Y = {y1,..., yn}, denoted as R; The basic PSU protocol is as follows: (1) S generates the public key of LFHE pk and the private key sk , and secretly stores the private key; uses pk to encrypt each element: , and sends the public key and the ciphertext to R; (2) R selects a random value , calculates the polynomial Y according to its own set , where x is the independent variable of the function f , and then, according to the property of fully homomorphic encryption, performs a homomorphic calculation on the ciphertext to obtain a new ciphertext , and sends the new ciphertext to S; (3) S decrypts the new ciphertext to obtain , and returns to R; (4) R verifies whether holds. If it holds, let , otherwise ; (5) R and S run the oblivious transfer protocol. R inputs , and S inputs ; when , R obtains , otherwise R obtains , where ⊥ represents a meaningless symbol, that is, it is meaningless for R to obtain ⊥; according to the function of oblivious transfer, R obtains the union; according to the algorithm, it can be known that b i = 1 corresponds to non-intersection elements. At this time, R obtains the non-intersection elements x i , b i = 0 corresponds to intersection elements, and R cannot obtain the corresponding elements. At this time, R obtains the meaningless ⊥; if the privacy set operation instruction is an instruction for the cardinality of the privacy set intersection PSI-card, the sender S and the receiver R perform interactive calculations through the PSI-card protocol to obtain the number of intersection elements; the PSI-card protocol adopts a basic PSI-card protocol constructed based on the leveled homomorphic encryption technology, and an optimized PSI-card protocol after optimizing the basic PSI-card protocol; the sender is a server having a large set X = {x1,..., xn}, denoted as S; the receiver is a client having a small set Y = {y1,..., ym}, denoted as R; The basic PSI-card protocol is as follows: (1) R generates a public-private key pair of LFHE , secretly stores the private key ; then, encrypts each element of using the public key to obtain the ciphertext of each element: , and R sends the public key and all the ciphertexts to S; (2) S encodes the large set into a polynomial f , and randomizes it using the multiplicative randomization method. Based on the LFHE technology, performs homomorphic calculations on the ciphertext as follows: First, calculates the polynomial according to the set f such that , then selects a random value , randomizes using the multiplicative randomization method. Subsequently, performs homomorphic calculations on the ciphertext to obtain the ciphertext . Subsequently, S selects a random permutation on [m] to permute the ciphertexts to obtain , and sends the permuted ciphertext to R; (3) R receives all the permuted ciphertexts , decrypts the permuted ciphertext using the decryption private key to obtain the decryption result . If , it means that the permuted element belongs to the intersection; otherwise, the permuted element does not belong to the intersection. R calculates the number of 0s in the decryption result to obtain the number of elements in the intersection, which is the cardinality of the intersection .
2. A privacy set operation system based on fully homomorphic encryption, characterized in that, it includes a server and a client; the server and the client in response to a privacy set operation instruction perform interactive calculations through a protocol to obtain a set operation result; wherein, the protocol is constructed based on the leveled homomorphic encryption LFHE technology; if the privacy set operation instruction is an instruction for privacy set union PSU, the sender S and the receiver R perform interactive calculations through the PSU protocol to obtain the union of the sets; the PSU protocol adopts a basic PSU protocol constructed based on the leveled homomorphic encryption technology, and after optimizing the basic PSU protocol, combines a permutation matrix privacy equality test and oblivious transfer to obtain an optimized PSU protocol; the sender is a client having a small set X = {x1,..., xm}, denoted as S; the receiver is a server having a large set Y = {y1,..., yn}, denoted as R; The basic PSU protocol is as follows: (1) S generates the public key of FHE pk and the private key sk , and secretly stores the private key; encrypts each element using pk : , and sends the public key and the ciphertext to R; (2) R selects a random value , calculates the polynomial Y according to its own set , where x is the independent variable of the function f , and then, according to the properties of fully homomorphic encryption, performs a homomorphic calculation on the ciphertext to obtain a new ciphertext , and sends the new ciphertext to S; (3) S decrypts the new ciphertext to obtain , and returns to R; (4) R verifies whether holds. If it holds, let , otherwise ; (5) R and S run the oblivious transfer protocol. R inputs , and S inputs ; when , R obtains , otherwise R obtains , where ⊥ represents a meaningless symbol, that is, it is meaningless for R to obtain ⊥; according to the function of oblivious transfer, R obtains the union; according to the algorithm, it can be known that b i =1 corresponds to non-intersection elements. At this time, R obtains the non-intersection elements x i , b i =0 corresponds to intersection elements, and R cannot obtain the corresponding elements. At this time, R obtains the meaningless ⊥; if the privacy set operation instruction is an instruction for the cardinality of the privacy set intersection PSI-card, the sender S and the receiver R perform interactive calculations through the PSI-card protocol to obtain the number of intersection elements; the PSI-card protocol adopts a basic PSI-card protocol constructed based on the leveled homomorphic encryption technology, and an optimized PSI-card protocol after optimizing the basic PSI-card protocol; The sender represents a server that owns a large set X = {x1,..., xn}, denoted as S; the data set E = {e1,..., en} corresponding to the elements of the large set. The receiver represents a client that owns a small set Y = {y1,..., ym}, denoted as R; The basic PSI-card protocol is as follows: (1) R generates a public-private key pair for LFHE , secretly stores the private key ; then, encrypts each element of using the public key to obtain the ciphertext of each element: , and R sends the public key and all the ciphertexts to S; (2) S encodes the large set into a polynomial f , randomizes it using the multiplicative randomization method, and performs encrypted calculations on the ciphertext based on the LFHE technology, specifically as follows: First, calculate the polynomial according to the set f such that , then select a random value , randomize using the multiplicative randomization method. Subsequently, perform encrypted calculations on the ciphertext to obtain the ciphertext . Subsequently, S selects a random permutation on [m] to permute the ciphertexts to obtain , and sends the permuted ciphertext to R; (3) R receives all the permuted ciphertexts , decrypts the permuted ciphertext using the decryption private key to obtain the decryption result . If , it means that the permuted element belongs to the intersection; otherwise, the permuted element does not belong to the intersection. R calculates the number of 0s in the decryption result to obtain the number of elements in the intersection, which is the cardinality of the intersection .
Citation Information
Patent Citations
Efficient privacy set intersection calculation method and system based on assistance of cloud server
CN112910631A