Data Processing Method, Apparatus, Device, and Medium

Through the combination of addition secret sharing, multiplication secret resharing and inadvertent transmission protocols, the target data set is generated, which solves the problem of data leakage in private set interception, and realizes secure data sharing and accurate intersection acquisition.

CN115618380BActive Publication Date: 2025-07-18CCB FINTECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211219743.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-30
Publication Date
2025-07-18
Estimated Expiration
2042-09-30

AI Technical Summary

Technical Problem

In the existing privacy collection interception scheme, the data privacy of the data demander is easily leaked, and the data provider may obtain the intersection results, resulting in poor data sharing synergy.

Method used

Addition secret sharing and multiplication secret resharing technology are used to process the screening threshold and feature data, combined with the inadvertent transmission protocol, the target data set is generated through the privacy transfer algorithm to protect the security of the screening conditions and data samples.

Benefits of technology

It realizes accurate acquisition of intersection data that meets the filtering conditions without leaking filter conditions and data sample information, improving the security and privacy protection of data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115618380B_ABST
    Figure CN115618380B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data processing method, apparatus, device, and medium, which can be applied to the fields of big data technology and encryption technology. The data processing method applied to the data demand side includes: processing preset screening threshold information through the additive secret sharing method to generate a first threshold secret shard and a second threshold secret shard; generating a first feature data set according to the first threshold secret shard and the first feature secret shard; obtaining a third feature data set through the multiplicative secret resharing method according to the first feature data set and the second feature data set processed by the data provider using a preset parameter group; and obtaining a first screening mask data set from the data provider according to the third feature data set by executing the oblivious transfer protocol; receiving a second encrypted data set and a third encrypted data set from the data provider; and obtaining a target data set by using the private intersection algorithm according to the first screening mask data set, the second encrypted data set, and the third encrypted data set.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the fields of big data technology and encryption technology, and particularly relates to a data processing method, apparatus, device, medium, and program product. Background Art

[0002] For the privacy set intersection scheme based on greater than or less than, for the data requester, it is necessary to ensure that the data requester can correctly obtain the sample intersection set that meets the corresponding sample feature equal to the screening value, and the data requester cannot reverse any samples and feature data information outside the intersection result. For the data provider, it is necessary to ensure that the data provider cannot obtain the screening threshold condition and cannot independently obtain the intersection result, so as to achieve the data sharing and collaboration effect that no effective information can be obtained from the perspective of the data provider.

[0003] The traditional privacy intersection scheme is that the data requester provides the screening condition or screening value to the data provider. This method is prone to leaking the data privacy of the data requester and there is a risk of core parameter leakage. Summary of the Invention

[0004] In view of the above problems, the present disclosure provides a data processing method, apparatus, device, medium, and program product.

[0005] According to a first aspect of the present disclosure, there is provided a data processing method, applied to a data demand side, including: processing preset screening threshold information through an additive secret sharing method to generate a first threshold secret shard and a second threshold secret shard; generating a first feature data set according to the first threshold secret shard and a first feature secret shard; obtaining a third feature data set through a multiplicative secret resharing method according to the first feature data set and a second feature data set processed by the data provider using a preset parameter group; and obtaining a first screening mask data set from the data provider according to the third feature data set by executing an oblivious transfer protocol; receiving a second encrypted data set and a third encrypted data set from the data provider, where the second encrypted data set is obtained by processing the first encrypted data set using the shared key, and the first encrypted data set is obtained by processing a first data set to be matched using the shared key and a first private key by the data demand side; the third encrypted data set is obtained by processing a second data set to be matched using the shared key, a second private key, and a second screening mask data set; and obtaining a target data set using a privacy intersection algorithm according to the first screening mask data set, the second encrypted data set, and the third encrypted data set.

[0006] According to an embodiment of the present disclosure, the above-mentioned first feature secret shard is obtained by the above-mentioned data provider processing the second data set to be matched through the additive secret sharing method; the above-mentioned second feature data set is determined by the above-mentioned data provider according to the second feature secret shard and the above-mentioned second threshold secret shard; the above-mentioned second screening mask data set is determined according to the fourth feature data set according to the oblivious transfer protocol, wherein the above-mentioned fourth feature data set is determined by the multiplicative secret resharing method according to the first feature data set processed by the above-mentioned data provider using a preset parameter group, and the product of the corresponding elements in the above-mentioned third feature data set and the above-mentioned fourth feature data set and the sum of the above-mentioned first feature data set and the above-mentioned second feature data set satisfy a preset condition.

[0007] According to an embodiment of the present disclosure, the processing of the first data set to be matched using the shared key and the first private key includes: inputting the above-mentioned shared key and the above-mentioned first data set to be matched into a preset random point generation function to obtain a first private data set; for each private data in the above-mentioned first private data set, performing a double-point operation on the above-mentioned private data using the first private key to obtain a first encrypted data set.

[0008] According to an embodiment of the present disclosure, the above-mentioned first feature data set includes n first feature data, and the above-mentioned second feature data set includes n second feature data; the above-mentioned obtaining the third feature data set by the multiplicative secret resharing method according to the above-mentioned first feature data set and the second feature data set processed by the above-mentioned data provider using a preset parameter group includes: for the k-th first feature data, generating a k-th first feature parameter using the k-th first parameter, the k-th second parameter in the preset parameter group, and the above-mentioned k-th first feature data, and sending the above-mentioned k-th first feature parameter to the above-mentioned data provider; receiving a k-th second feature parameter, wherein the above-mentioned k-th second feature parameter is determined by the above-mentioned data provider according to the above-mentioned k-th first feature parameter, the above-mentioned k-th second feature data, the k-th third parameter, and the k-th fourth parameter, and the product of the above-mentioned k-th first parameter and the above-mentioned k-th third parameter is equal to the sum of the above-mentioned k-th second parameter and the above-mentioned k-th fourth parameter; generating a k-th third feature data according to the above-mentioned k-th first parameter and the above-mentioned k-th second feature parameter, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0009] According to an embodiment of the present disclosure, the above third feature dataset includes n third feature data; the obtaining of the first screening mask dataset from the data provider according to the above third feature dataset by executing the oblivious transfer protocol includes: for the k-th third feature data, inputting the k-th third feature data into a sign function to output a k-th target value; obtaining the k-th group of random arrays from the data provider by executing the oblivious transfer protocol; determining the k-th first screening mask data from the k-th group of random arrays according to the k-th target value, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0010] According to an embodiment of the present disclosure, the obtaining of the target dataset by using the private intersection algorithm according to the above first screening mask dataset, the above second encrypted dataset, and the above third encrypted dataset includes: performing a double point operation on the above third encrypted dataset by using the first private key and the above first screening mask dataset to obtain a third encrypted dataset embedded with the first screening mask; generating a target dataset according to the above second encrypted dataset and the above third encrypted dataset embedded with the first screening mask by using the private combination intersection protocol.

[0011] According to an embodiment of the present disclosure, the generating of the target dataset according to the above second encrypted dataset and the above third encrypted dataset embedded with the first screening mask by using the private combination intersection protocol includes: obtaining a target intersection according to the above second encrypted dataset and the above third encrypted dataset embedded with the first screening mask by using the private combination intersection protocol; determining the target dataset from the above first dataset to be matched according to the corresponding relationship between each element in the above target intersection and the above second encrypted dataset.

[0012] According to a second aspect of the present disclosure, there is provided a data processing method applied to a data provider, including: processing a second dataset to be matched by additive secret sharing to obtain a first feature secret shard and a second feature secret shard; generating a second feature dataset according to the above second threshold secret shard and the second feature secret shard, where the above second threshold secret shard is obtained by the data requester through additive secret sharing according to preset threshold information; obtaining a fourth feature dataset by multiplicative secret resharing according to the first feature dataset processed by the data requester by using a preset parameter group; determining a second screening mask set according to the above fourth feature dataset by executing the oblivious transfer protocol; processing the above first encrypted dataset by using a second private key to obtain a second encrypted dataset; processing the second dataset to be matched by using a shared key, the above second private key, and the second screening mask set to obtain a third encrypted dataset, and sending the above second encrypted dataset and the above third encrypted dataset to the data requester.

[0013] According to an embodiment of the present disclosure, the first feature data set includes n first feature data, the second feature data set includes n second feature data, and obtaining a fourth feature data set according to the first feature data set and the second feature data set by means of multiplicative secret sharing includes: receiving a k-th first feature parameter from the data demand side; generating a k-th fourth feature data according to the k-th first feature parameter and the k-th third parameter in a preset parameter group, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0014] According to an embodiment of the present disclosure, the fourth feature data set includes n fourth feature data, and determining a second screening mask set according to the fourth feature data set by performing an oblivious transfer protocol includes: for the k-th fourth feature data, inputting the k-th fourth feature data into a sign function to output a k-th target value; by performing an oblivious transfer protocol, according to the k-th target value, determining a k-th second screening mask data from the k-th group of random arrays according to a preset rule, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0015] According to an embodiment of the present disclosure, generating a second feature data set according to the second threshold secret shard and the second feature secret shard includes: generating a third threshold secret shard according to the second threshold secret shard and system support coding parameters, where the system support coding parameters include a parameter value and a parameter format; generating the second feature data set according to the second feature secret shard and the third threshold secret shard.

[0016] A third aspect of the present disclosure provides a data processing device, which is applied to the data demand side and includes: a first generation module, configured to process preset screening threshold information through additive secret sharing to generate a first threshold secret shard and a second threshold secret shard; a second generation module, configured to generate a first feature data set according to the first threshold secret shard and the first feature secret shard; a first transmission module, configured to obtain a third feature data set through multiplicative secret resharing according to the first feature data set and a second feature data set processed by the data providing side using a preset parameter group; and obtain a first screening mask data set from the data providing side by executing an oblivious transfer protocol; a receiving module, configured to receive a second encrypted data set and a third encrypted data set from the data providing side, wherein the second encrypted data set is obtained by processing the first encrypted data set using the shared key, and the first encrypted data set is obtained by the data demand side using the shared key and a first private key to process a first data set to be matched; the third encrypted data set is obtained by processing the second data set to be matched using the shared key, a second private key, and a second screening mask data set; an intersection finding module, configured to obtain a target data set using a private intersection algorithm according to the first screening mask data set, the second encrypted data set, and the third encrypted data set.

[0017] A fourth aspect of the present disclosure provides a data processing device, which is applied to the data providing side and includes: a first processing module, configured to process a second data set to be matched through additive secret sharing to obtain a first feature secret shard and a second feature secret shard; and generate a second feature data set according to the second threshold secret shard and the second feature secret shard, wherein the second threshold secret shard is obtained by the data demand side through additive secret sharing according to preset threshold information; a second transmission module, configured to obtain a fourth feature data set through multiplicative secret resharing according to a first feature data set processed by the data demand side using a preset parameter group; and determine a second screening mask set according to the fourth feature data set by executing an oblivious transfer protocol; a second processing module, configured to process the first encrypted data set using a second private key to obtain a second encrypted data set; a sending module, configured to process the second data set to be matched using the shared key, the second private key, and the second screening mask set to obtain a third encrypted data set, and send the second encrypted data set and the third encrypted data set to the data demand side.

[0018] A fifth aspect of the present disclosure provides an electronic device, including: one or more processors; a memory, configured to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above data processing method.

[0019] The sixth aspect of the present disclosure also provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above data processing method.

[0020] The seventh aspect of the present disclosure also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above data processing method is implemented.

[0021] According to the embodiments of the present disclosure, by performing multiplicative secret reshare between the dataset to be matched and the preset threshold information, and determining the first screened mask dataset according to the positive and negative attributes of the multiplicative secret shards in combination with the oblivious transfer protocol, and performing private intersection on the dataset embedded with oblivious transfer information, it is possible to protect both the screening condition threshold from being leaked and the security of data samples outside the target dataset, achieving the technical effect of private set intersection based on the greater than or less than strategy, and at least partially overcoming the problem of data security risks existing in the traditional private data transmission process. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above content and other objects, features and advantages of the present disclosure will become clearer. In the drawings:

[0023] Figure 1 Schematically shows an application scenario diagram of the data processing method, device, equipment, medium and program product according to the embodiments of the present disclosure;

[0024] Figure 2 Schematically shows a flowchart of the data processing method at the data demand side according to the embodiments of the present disclosure;

[0025] Figure 3 Schematically shows a flowchart of processing the first dataset to be matched according to the embodiments of the present disclosure;

[0026] Figure 4 Schematically shows a flowchart of obtaining the third dataset according to the embodiments of the present disclosure;

[0027] Figure 5 Schematically shows a flowchart of obtaining the first screened mask dataset according to the embodiments of the present disclosure;

[0028] Figure 6 Schematically shows a flowchart of the data processing method at the data provider side according to the embodiments of the present disclosure;

[0029] Figure 7 Schematically shows a structural block diagram of the data processing device at the data demand side according to the embodiments of the present disclosure;

[0030] Figure 8A block diagram of a data processing device at a data providing end according to an embodiment of the present disclosure is schematically shown;

[0031] Figure 9 A block diagram of an electronic device suitable for implementing a data processing method according to an embodiment of the present disclosure is schematically shown. Detailed implementation manners

[0032] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure. However, it is obvious that one or more embodiments can be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.

[0033] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0034] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0035] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).

[0036] In the technical solution of the present disclosure, the processing of data involved (such as including but not limited to user personal information) in aspects such as collection, storage, use, processing, transmission, provision, disclosure, and application all comply with the provisions of relevant laws and regulations, necessary confidentiality measures are taken, and public order and good customs are not violated.

[0037] Embodiments of the present disclosure provide a data processing method, which is applied to the data demand side and includes: processing preset screening threshold information through additive secret sharing to generate a first threshold secret shard and a second threshold secret shard; generating a first feature data set according to the first threshold secret shard and a first feature secret shard; obtaining a third feature data set through multiplicative secret resharing according to the first feature data set and a second feature data set processed by a data provider using a preset parameter set; and obtaining a first screening mask data set from the data provider according to the third feature data set by executing an oblivious transfer protocol; receiving a second encrypted data set and a third encrypted data set from the data provider, where the second encrypted data set is obtained by processing a first encrypted data set using a shared key, and the first encrypted data set is obtained by processing a first data set to be matched by the data demand side using the shared key and a first private key; the third encrypted data set is obtained by processing a second data set to be matched using the shared key, a second private key, and a second screening mask data set; and obtaining a target data set according to the first screening mask data set, the second encrypted data set, and the third encrypted data set using a private set intersection algorithm.

[0038] Figure 1 FIG. schematically shows an application scenario diagram of data processing according to an embodiment of the present disclosure.

[0039] As Figure 1 shown, the application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0040] Users may use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0041] The first terminal device 101, the second terminal device 102, and the third terminal device 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablets, laptop portable computers, and desktop computers, etc.

[0042] The server 105 may be a server that provides various services. For example, it may be a background management server (merely an example) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0043] It should be noted that the data processing method provided by the embodiments of the present disclosure can generally be executed by the server 105. Correspondingly, the data processing device provided by the embodiments of the present disclosure can generally be set in the server 105. The data processing method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or the server 105. Correspondingly, the data processing device provided by the embodiments of the present disclosure can also be set in a server or a server cluster different from the server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or the server 105.

[0044] The data processing method provided by the embodiments of the present disclosure can be executed by the server or by the client. The embodiments of the present disclosure do not make specific limitations on the execution subject.

[0045] It should be understood that Figure 1 the numbers of the terminal devices, the network, and the server in

[0046] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 1 Based on the scenario described below Figures 2 to 6 the data processing method of the embodiments of the present disclosure will be described in detail.

[0047] Figure 2 Schematically shows a flowchart of the data processing method at the data demand side according to the embodiments of the present disclosure.

[0048] As Figure 2 shown, the data processing at the data demand side of this embodiment includes operation S210 to operation S250.

[0049] In operation S210, the preset screening threshold information is processed by the additive secret sharing method to generate a first threshold secret shard and a second threshold secret shard.

[0050] According to the embodiments of the present disclosure, the preset threshold information can be determined according to the screening strategy. For example, if the screening strategy is that the age is greater than 30, then the preset screening threshold information can be determined to be 30.

[0051] According to an embodiment of the present disclosure, for the preset screening threshold information a, the first threshold secret shard a1 and the second threshold secret shard a2 can be randomly generated by the additive secret sharing method. Wherein, the sum of the first threshold secret shard a1 and the second threshold secret shard a2 is equal to the preset screening threshold information a. For example: if the preset screening threshold information is 30, the first threshold secret shard can be 12, then the second threshold secret shard can be 18; the first threshold secret shard can also be 10, then the second threshold secret shard can be 20.

[0052] In operation S220, a first feature data set is generated according to the first threshold secret shard and the first feature secret shard.

[0053] According to an embodiment of the present disclosure, the first feature secret shard is obtained by the data provider processing the second data set to be matched through the additive secret sharing method. For example: the second data set to be matched can be x1,..., x can be randomly generated respectively by the additive secret sharing method n additive secret shards [x1],..., [x n , where [x k = (y k , z k ), satisfying x k = y k + z k , k = 1,..., n. That is, the first feature secret shard can be represented as y1,..., y n , and the second feature secret shard can be represented as z1,..., z n .

[0054] According to an embodiment of the present disclosure, the first feature data set can be generated according to the difference between the first feature secret shard and the first threshold secret shard. For example: the k-th element y' k in the first feature data set can be expressed as y' k = y k - a1, where k = 1,..., n.

[0055] In operation S230, through the multiplicative secret resharing method, according to the first feature data set and the second feature data set processed by the data provider using the preset parameter group, a third feature data set is obtained; and by executing the oblivious transfer protocol, a first screening mask data set is obtained from the data provider according to the third feature data set.

[0056] According to an embodiment of the present disclosure, the multiplicative shard of x k - a can be determined by the multiplicative secret resharing method, that is, the k-th element u kand the k-th element v in the fourth feature dataset k satisfies u k ·v k = x k -a, k = 1, …, n.

[0057] According to an embodiment of the present disclosure, by executing the oblivious transfer protocol, taking the k-th element u k as an example, the first screening mask dataset can be obtained from the data provider. For example: the data provider randomly generates n groups of random arrays (α k , β k ), and the random numbers in each group of random arrays are not equal to each other. By executing the oblivious transfer protocol, a random number can be determined from the k-th group of random arrays as the k-th first screening mask data according to the k-th element u k .

[0058] In operation S240, receive the second encrypted dataset and the third encrypted dataset from the data provider, where the second encrypted dataset is obtained by processing the first encrypted dataset using the shared key, and the first encrypted dataset is obtained by processing the first dataset to be matched by the data requester using the shared key and the first private key; the third encrypted dataset is obtained by processing the second dataset to be matched using the shared key, the second private key, and the second screening mask dataset.

[0059] According to an embodiment of the present disclosure, before executing the data processing method of the embodiment of the present disclosure, the data provider and the data requester can determine the elliptic curve (G, q) and the random point generation function H p (·) through negotiation, and determine an elliptic curve generator g ∈ G. Both parties generate their own matching private keys sk A , sk B ∈ Zq, where sk A is the matching private key of the data requester P A , and sk B is the matching private key of the data provider P B . Both parties calculate their own matching public keys and disclose them. For example: the shared key K for this task can be calculated and determined based on the Diffie-Hellman key negotiation algorithm. It should be noted that the shared key K can be used as the service identifier for executing this data processing task to identify the task. The first private key and the second private key of both parties are used to encrypt the data information of both parties to prevent privacy leakage.

[0060] In the embodiment of the present disclosure, the second encrypted dataset and the third encrypted dataset are data processing operations performed by the data provider, which are described in detail in the data processing method of the data provider and will not be elaborated here.

[0061] In operation S250, according to the first screening mask data set, the second encrypted data set, and the third encrypted data set, a target data set is obtained by using a private intersection algorithm.

[0062] According to an embodiment of the present disclosure, by using the first screening mask data set and the third encrypted data set, a third encrypted data set embedded with screening conditions can be obtained, and then an intersection is performed with the second encrypted data set by using a private intersection algorithm to obtain a target data set.

[0063] According to an embodiment of the present disclosure, by performing multiplicative secret re-sharing between the data set to be matched and the preset threshold information, and determining the first screening mask data set according to the positive and negative attributes of the multiplicative secret shards in combination with the oblivious transfer protocol, and performing a private intersection on the data set embedded with the oblivious transfer information, it is possible to protect both the leakage of the screening condition threshold and the security of the data samples outside the target data set, achieving the technical effect of private set intersection based on a greater than or less than strategy, and at least partially overcoming the problem of data security risks existing in the traditional private data transmission process.

[0064] Figure 3 Schematically shows a flowchart of processing a first data set to be matched according to an embodiment of the present disclosure.

[0065] As Figure 3 shown, where the first feature data set includes n first feature data, and the second feature data set includes n second feature data; the processing of the first data set to be matched in this embodiment includes operations S310 to S320.

[0066] In operation S310, the shared key and the first data set to be matched are input into a preset random point generation function to obtain a first private data set.

[0067] In operation S320, for each private data in the first private data set, a double point operation is performed on the private data by using the first private key to obtain a first encrypted data set.

[0068] According to an embodiment of the present disclosure, the first data set to be matched can be expressed as A = {ID1, ID2,..., ID m}. Where ID can be used to represent identity identification, enterprise credit identification, number identification, etc., which are uniquely directed identification information.

[0069] According to an embodiment of the present disclosure, the first data set to be matched is input into a preset random point generation function H p (·) to obtain a first private data set, and a double point operation is performed on the first private data set by using the first private key sk A to obtain a first encrypted data set

[0070] Based on the elliptic curve and preset random point generation function determined by mutual agreement, the data privacy security of the data provider can be effectively protected.

[0071] Figure 4 The flowchart of obtaining the third data set according to the embodiment of the present disclosure is schematically shown.

[0072] like Figure 4 As shown, the first feature data set includes n first feature data, and the second feature data set includes n second feature data; obtaining the third data set in this embodiment includes operations S410 to S430.

[0073] In operation S410, for the kth first feature data, a kth first feature parameter is generated using the kth first parameter, the kth second parameter and the kth first feature data in the preset parameter group, and the kth first feature parameter is sent to a data provider.

[0074] In operation S420, a kth second characteristic parameter is received, wherein the kth second characteristic parameter is determined by a data provider based on the kth first characteristic parameter, the kth second characteristic data, the kth third parameter, and the kth fourth parameter, and the product of the kth first parameter and the kth third parameter is equal to the sum of the kth second parameter and the kth fourth parameter.

[0075] In operation S430, a kth third feature data is generated according to the kth first parameter and the kth second feature parameter, wherein n and k are both positive integers, and 1≤k≤n.

[0076] According to an embodiment of the present disclosure, the preset parameter group may be a preset parameter group sent from a third-party platform to both parties according to an agreement between the two parties. The preset parameter group may include n groups of parameters, each of which may include a first parameter, a second parameter, a third parameter, and a fourth parameter. Taking the kth group of parameters as an example, the first parameter may be e k , the second parameter can be g′ k , the third parameter can be f k , the fourth parameter can be g″ k Among them, the data demander knows the first parameter and the second parameter. The data provider knows the third parameter and the fourth parameter. And the above parameters meet the following conditions: g′ k +g″ k =e k .f k .

[0077] According to an embodiment of the present disclosure, for the k-th first feature data, the k-th first feature parameter is generated by using the k-th first parameter, the k-th second parameter, and the k-th first feature data in a preset parameter group. The first feature parameter can be calculated according to Equation (1):

[0078] p k =(y′ k -g′ k ) / e k (1)

[0079] Wherein, p k represents the k-th first feature parameter; y′ k represents the k-th first feature data; g′ k represents the k-th second parameter; e k represents the k-th first parameter.

[0080] According to an embodiment of the present disclosure, the data demand side can send the first feature parameter to the data providing side. The data providing side can perform subsequent calculations according to the first feature parameter.

[0081] According to an embodiment of the present disclosure, the first feature data set includes n first feature data, the second feature data set includes n second feature data, and the fourth feature data set is obtained according to the first feature data set and the second feature data set through the multiplicative secret sharing method, including:

[0082] Receiving the k-th first feature parameter from the data demand side;

[0083] Generating the k-th fourth feature data according to the k-th first feature parameter and the k-th third parameter in the preset parameter group, where n and k are both positive integers, and 1≤k≤n.

[0084] For example: as shown in Equations (2) and (3):

[0085] v k =f k +p k (2)

[0086] q k =(z′ k -g″ k ) / v k (3)

[0087] Wherein, f k represents the k-th third parameter; g″ k represents the k-th fourth parameter; z′ k represents the k-th second feature data; v k represents the k-th fourth feature data in the fourth feature data set; q kRepresents the k-th second characteristic parameter.

[0088] According to an embodiment of the present disclosure, the data demand side receives the second characteristic parameter from the data providing side and performs calculations according to Equation (4):

[0089] u k = e k + q k (4)

[0090] Wherein, u k represents the k-th third characteristic data.

[0091] According to an embodiment of the present disclosure, the screening condition is multiplicatively fragmented by means of multiplicative secret reshare, and the multiplicative fragmentation of the screening condition is converted into a condition that can be used to determine the first screening mask data, thereby protecting the privacy of the screening condition threshold of the data demand side.

[0092] Figure 5 Schematically shows a flowchart for obtaining the first screening mask data set according to an embodiment of the present disclosure.

[0093] As Figure 5 shown, the third characteristic data set includes n third characteristic data; obtaining the first screening mask data set in this embodiment includes operations S510 to S530.

[0094] In operation S510, for the k-th third characteristic data, the k-th third characteristic data is input into the sign function, and the k-th target value is output.

[0095] In operation S520, the k-th group of random arrays is obtained from the data providing side by executing the oblivious transfer protocol.

[0096] In operation S530, according to the k-th target value, the k-th first screening mask data is determined from the k-th group of random arrays according to a preset rule, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0097] According to an embodiment of the present disclosure, taking the k-th third characteristic data u k as an example, u k is input into the sign function sig(), and the k-th target value u' k is output. For the sign function sig(), when the independent variable x > 0, then sig(x) = 1, and if x < 0, then sig(x) = -1.

[0098] According to an embodiment of the present disclosure, in the k-th group of random arrays (α k , β k ), when u' k = 1, α k is determined as the k-th first mask data. When u'k When it is equal to -1, determine β k as the k-th first mask data.

[0099] According to an embodiment of the present disclosure, by introducing a sign function and using the positive and negative attributes of the third feature data, the first mask data is determined from a random array, thereby effectively avoiding the leakage of the screening conditions on the data demand side.

[0100] According to an embodiment of the present disclosure, according to the first screening mask data set, the second encrypted data set, and the third encrypted data set, a target data set is obtained by using a private intersection algorithm, including:

[0101] Perform a double point operation on the third encrypted data set by using the first private key and the first screening mask data set to obtain a third encrypted data set embedded with the first screening mask;

[0102] According to the second encrypted data set and the third encrypted data set embedded with the first screening mask, use a private combination intersection protocol to generate a target data set.

[0103] According to an embodiment of the present disclosure, the third encrypted data set T1 can be expressed as:

[0104] Each element in the set is in the form of

[0105] According to an embodiment of the present disclosure, use the first private key sk A and the first screening mask data set (θ1,..., θ n ) to perform a double point operation on to obtain a third encrypted data set T2 embedded with the first screening mask:

[0106]

[0107] According to an embodiment of the present disclosure, the second encrypted data set can be expressed as: where

[0108] According to an embodiment of the present disclosure, according to the second encrypted data set and the third encrypted data set embedded with the first screening mask, use a private combination intersection protocol to generate a target data set, including:

[0109] According to the second encrypted data set and the third encrypted data set embedded with the first screening mask, use a private combination intersection protocol to obtain a target intersection;

[0110] According to the correspondence between each element in the target intersection and the second encrypted data set, determine the target data set from the first data set to be matched.

[0111] According to an embodiment of the present disclosure, for example, a private intersection algorithm can be used to obtain the intersection I = S2 ∩ T2 = {I1, …, I l} between the second encrypted dataset S2 and the third encrypted dataset T2 embedded with the first screening mask. The original set intersection can be restored by using the correspondence between each element in the intersection I and the second encrypted dataset S2 , thereby obtaining the target dataset.

[0112] According to an embodiment of the present disclosure, since the first screening mask capable of representing the screening strategy has been embedded in the third encrypted dataset, compared with the traditional private set intersection algorithm, it can support the data intersection requirements with the feature screening strategy, and can perform data screening more accurately and effectively while ensuring the forward security of the screening conditions and sample data.

[0113] Figure 6 The flowchart of the data processing method of the data provider according to the embodiment of the present disclosure is schematically shown.

[0114] As Figure 6 shown, the data processing of the data provider in this embodiment includes operation S610 to operation S640.

[0115] In operation S610, the second dataset to be matched is processed by additive secret sharing to obtain the first feature secret shard and the second feature secret shard; and a second feature dataset is generated according to the second threshold secret shard and the second feature secret shard, where the second threshold secret shard is obtained by the data requester through additive secret sharing according to the preset threshold information.

[0116] According to an embodiment of the present disclosure, the second dataset to be matched respectively randomly generates additive secret shards [x1], …, [x n of x1, …, x n , where [x k = (y k , z k ), satisfying x k = y k + z k , k = 1, …, n. That is, the first feature secret shard can be represented as y1, …, y n , and the second feature secret shard can be represented as z1, …, z n .

[0117] According to an embodiment of the present disclosure, the second feature dataset can be generated according to the difference between the second feature secret shard and the second threshold secret shard. For example: the k-th element z′ k in the first feature dataset can be represented as z′ k = zk -a2, where k = 1, …, n.

[0118] In operation S620, a fourth feature dataset is obtained from the first feature dataset processed by the data requester using a preset parameter set through multiplicative secret resharing; and a second screening mask set is determined based on the fourth feature dataset by executing an oblivious transfer protocol.

[0119] According to an embodiment of the present disclosure, a fourth feature dataset v is obtained from the first feature dataset processed by the data requester using a preset parameter set through multiplicative secret resharing k . The specific implementation of this operation has been described above and will not be elaborated here.

[0120] In operation S630, the first encrypted dataset is processed using the second private key to obtain a second encrypted dataset.

[0121] According to an embodiment of the present disclosure, the first encrypted dataset can be expressed as: Using the second private key sk B to process the first encrypted dataset, the obtained second encrypted dataset is:

[0122] In operation S640, the second dataset to be matched is processed using the shared key, the second private key, and the second screening mask set to obtain a third encrypted dataset, and the second encrypted dataset and the third encrypted dataset are sent to the data requester.

[0123] According to an embodiment of the present disclosure, using the shared key K, the second private key sk B and the second screening mask set (γ1, …, γ n ) to process the second dataset to be matched, a third encrypted dataset is obtained. For example: the second dataset to be matched S2 can be: The third encrypted dataset T1 can be

[0124] According to an embodiment of the present disclosure, by performing multiplicative secret resharing between the dataset to be matched and the preset threshold information, and determining the first screening mask dataset based on the positive and negative attributes of the multiplicative secret shards in combination with the oblivious transfer protocol, and performing private intersection on the dataset embedded with the oblivious transfer information, it is possible to protect both the screening condition threshold from being leaked and the security of data samples outside the target dataset, achieving the technical effect of private set intersection based on the greater than or less than strategy, and at least partially overcoming the problem of data security risks existing in the traditional private data transmission process.

[0125] According to an embodiment of the present disclosure, the fourth feature dataset includes n fourth feature data. Determining the second screening mask set according to the fourth feature dataset by executing the oblivious transfer protocol includes:

[0126] For the k-th fourth feature data, input the k-th fourth feature data into the sign function to output the k-th target value;

[0127] By executing the oblivious transfer protocol, according to the k-th target value, determine the k-th second screening mask data from the k-th group of random arrays, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0128] According to an embodiment of the present disclosure, for example: taking the k-th fourth feature data v k as an example, input v k into the sign function sig(), and output the k-th target value v′ k . For the sign function sig(), when the independent variable x > 0, then sig(x) = 1; if x < 0, then sig(x) = -1.

[0129] According to an embodiment of the present disclosure, in the k-th group of random arrays (α k , β k ), when v′ k = 1, determine α k as the k-th first mask data. When v′ k = -1, determine β k as the k-th first mask data.

[0130] According to an embodiment of the present disclosure, by introducing the sign function and utilizing the positive and negative attributes of the third feature data, the first mask data is determined from the random array, thereby effectively avoiding the leakage of the screening conditions at the data demand side.

[0131] Since the dataset in this solution is generally a floating-point number, the second threshold secret sharding can be fine-tuned through the system encoding parameters, thereby improving the screening accuracy.

[0132] According to an embodiment of the present disclosure, generating the second feature dataset according to the second threshold secret sharding and the second feature secret sharding includes:

[0133] Generate the third threshold secret sharding according to the second threshold secret sharding and the system support encoding parameters, where the system support encoding parameters include parameter values and parameter formats;

[0134] Generate the second feature dataset according to the second feature secret sharding and the third threshold secret sharding.

[0135] According to an embodiment of the present disclosure, taking the greater-than strategy (x > 3) as an example, after Party B receives a2 sent by Party A, it can calculate the new a'2 = a2 + ∈, where ∈ is a decimal supported by the system for encoding. For example, ∈ = 0.0000x, and use a'2 instead of a2 for subsequent calculations. Then the screening strategy becomes (x > 3 + ∈). According to the sparsity of the samples and the value range of the features in the actual scenario, it can be ensured that the fine-tuned strategy does not result in x k = a + ∈, so u' will not be generated k = 0, which leads to the risk of information leakage of Party B

[0136] To further elaborate on the technical effects of this solution in detail, the following will elaborate in detail from three aspects: the correctness, security, and accuracy of the solution

[0137] According to an embodiment of the present disclosure, since the screening condition is x k > a, and since both parties obtain u k , v k as the multiplicative shards of x k - a, satisfying x k - a = u k .v k , so both parties can transform the condition of x k , v k > a into (u' k = 1, v' k = 1) or (u' k = -1, v' k = -1) by using the sign function sig representing the positive and negative of u k . It can be seen that in the case where the condition x k > a is satisfied, γ k = θ k ; while in the case where the condition x k > a is not satisfied, γ k ≠ θ k . In particular, when u' k = 0, since Party A already knows x k = a at this time and will exclude this sample in the final intersection extraction according to the scheme, the influence when u' k = 0 is not considered for the time being. Through the subsequent scheme fine-tuning, we use other methods to avoid the occurrence of u' k = 0

[0138]

[0139] It can be seen that when x k > a, β k = θ k , at this time It can be seen that when When Thus, through the intersection of S2 and T2, it can be concluded whether there is an intersection between Party A and Party B and whether it meets the condition of being greater than the screening condition.

[0140] When x k <a, γ k ≠θ k At this time Therefore, even if it cannot be output as an intersection in the intersection-finding process.

[0141] When x k =a, it is a sample that satisfies u′ k =0. Whether the corresponding element is an intersection or not, it will be excluded from the intersection result.

[0142] Therefore, the correctness of the solution is established.

[0143] According to the embodiments of the present disclosure, for the data provider, all the data it processes are random values, and no effective information such as intersections, screening strategy judgment results, and the number of intersection elements can be obtained. For the data requester, by running the solution, an intersection result that meets the condition of being greater than the screening judgment can be obtained. It cannot obtain any other sample information and feature information of the data provider, nor can it determine whether the samples not in the final intersection are due to not being in the intersection or not meeting the screening conditions.

[0144] According to the embodiments of the present disclosure, in the above specific embodiments, the greater-than strategy is used as an example for explanation. For the screening strategy of the less-than strategy, only the first feature set at the data request end needs to be modified to y′ k =a1 - y k , and the second feature data set at the data provider end is modified to z′ k =a2 - z k .

[0145] According to the embodiments of the present disclosure, for the screening strategies of greater than or equal to or less than or equal to, based on the technical solution of the greater-than strategy, the second threshold secret sharding can be finely adjusted using the system-supported encoding, which will not be elaborated here.

[0146] Based on the above data processing method, the present disclosure also provides a data processing device. The following will be combined with Figure 7 to describe this device in detail.

[0147] Figure 7 Schematically shows the structural block diagram of the data processing device at the data request end according to the embodiments of the present disclosure.

[0148] As Figure 7As shown, the data processing device 700 at the data demand side of this embodiment includes a first generation module 710, a second generation module 720, a first transmission module 730, a receiving module 740, and an intersection module 750.

[0149] The first generation module 710 is used to process the preset screening threshold information through the additive secret sharing method to generate a first threshold secret shard and a second threshold secret shard. In one embodiment, the first generation module 710 can be used to execute the operation S210 described above, which will not be elaborated here.

[0150] The second generation module 720 is used to generate a first feature data set according to the first threshold secret shard and the first feature secret shard. In one embodiment, the second generation module 720 can be used to execute the operation S220 described above, which will not be elaborated here.

[0151] The first transmission module 730 is used to obtain a third feature data set through the multiplicative secret resharing method according to the first feature data set and the second feature data set processed by the data provider using the preset parameter group; and obtain a first screening mask data set from the data provider according to the third feature data set by executing the oblivious transfer protocol. In one embodiment, the first transmission module 730 can be used to execute the operation S230 described above, which will not be elaborated here.

[0152] The receiving module 740 is used to receive a second encrypted data set and a third encrypted data set from the data provider. Among them, the second encrypted data set is obtained by processing the first encrypted data set using the shared key, and the first encrypted data set is obtained by the data demand side processing the first data set to be matched using the shared key and the first private key; the third encrypted data set is obtained by processing the second data set to be matched using the shared key, the second private key, and the second screening mask data set. In one embodiment, the receiving module 740 can be used to execute the operation S240 described above, which will not be elaborated here.

[0153] The intersection module 750 is used to obtain the target data set using the private intersection algorithm according to the first screening mask data set, the second encrypted data set, and the third encrypted data set. In one embodiment, the intersection module 750 can be used to execute the operation S250 described above, which will not be elaborated here.

[0154] According to an embodiment of the present disclosure, the above data processing device includes a processing unit, a first determination unit, and a second determination unit. Among them, the processing unit is configured to process the second dataset to be matched through additive secret sharing to obtain first feature secret shards; the first determination unit is configured to determine a second feature dataset by a data provider according to the second feature secret shards and the second threshold secret shards; the second determination unit is configured to determine a second screening mask dataset according to the oblivious transfer protocol based on a fourth feature dataset, where the fourth feature dataset is determined by multiplicative secret resharing according to the first feature dataset processed by the data provider using a preset parameter set, and the product of the corresponding elements in the third feature dataset and the fourth feature dataset and the sum of the first feature dataset and the second feature dataset satisfy a preset condition.

[0155] According to an embodiment of the present disclosure, the receiving module 740 includes a first obtaining unit and a second obtaining unit. Among them, the first obtaining unit is configured to input a shared key and a first dataset to be matched into a preset random point generation function to obtain a first private dataset; the second obtaining unit is configured to perform a point doubling operation on each private data in the first private dataset using a first private key to obtain a first encrypted dataset.

[0156] According to an embodiment of the present disclosure, the first transmission module 730 includes a first generating unit, a first receiving unit, and a second generating unit. Among them, the first generating unit is configured to generate a k-th first feature parameter for the k-th first feature data by using the k-th first parameter, the k-th second parameter, and the k-th first feature data in the preset parameter set, and send the k-th first feature parameter to the data provider; the first receiving unit is configured to receive a k-th second feature parameter, where the k-th second feature parameter is determined by the data provider according to the k-th first feature parameter, the k-th second feature data, the k-th third parameter, and the k-th fourth parameter, and the product of the k-th first parameter and the k-th third parameter is equal to the sum of the k-th second parameter and the k-th fourth parameter; the second generating unit is configured to generate a k-th third feature data according to the k-th first parameter and the k-th second feature parameter, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0157] According to an embodiment of the present disclosure, the first transmission module 730 includes a first output unit, a third obtaining unit, and a third determination unit. Among them, the first output unit is configured to input the k-th third feature data into a sign function for the k-th third feature data and output a k-th target value; the third obtaining unit is configured to obtain a k-th group of random arrays from the data provider by executing an oblivious transfer protocol; the third determination unit is configured to determine a k-th first screening mask data from the k-th group of random arrays according to the k-th target value according to a preset rule, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0158] According to an embodiment of the present disclosure, the intersection finding module 750 includes a fourth obtaining unit and a third generating unit. Among them, the fourth obtaining unit is configured to perform a point multiplication operation on the third encrypted data set by using the first private key and the first screening mask data set to obtain a third encrypted data set embedded with the first screening mask; the third generating unit is configured to generate a target data set according to the second encrypted data set and the third encrypted data set embedded with the first screening mask by using a private intersection protocol.

[0159] According to an embodiment of the present disclosure, the third generating unit includes an obtaining subunit and a generating subunit. Among them, the obtaining subunit is configured to obtain a target intersection according to the second encrypted data set and the third encrypted data set embedded with the first screening mask by using a private intersection protocol; the generating subunit is configured to determine a target data set from the first data set to be matched according to the corresponding relationship between each element in the target intersection and the second encrypted data set.

[0160] Based on the above data processing method, the present disclosure further provides a data processing device. The following will be combined with Figure 8 to describe this device in detail.

[0161] Figure 8 A structural block diagram of a data processing device at a data providing end according to an embodiment of the present disclosure is schematically shown.

[0162] As Figure 8 shown, the data processing device 800 at the data providing end of this embodiment includes a first processing module 810, a second transmission module 820, a second processing module 830, and a sending module 840.

[0163] The first processing module 810 is configured to process the second data set to be matched by an additive secret sharing method to obtain a first feature secret shard and a second feature secret shard; and generate a second feature data set according to the second threshold secret shard and the second feature secret shard, where the second threshold secret shard is obtained by the data demand end through an additive secret sharing method according to preset threshold information. In one embodiment, the first processing module 810 may be configured to perform the operation S610 described above, which will not be elaborated here.

[0164] The second transmission module 820 is configured to obtain a fourth feature data set according to the first feature data set processed by the data demand end by using a preset parameter group through a multiplicative secret resharing method; and determine a second screening mask set according to the fourth feature data set by executing an oblivious transfer protocol. In one embodiment, the second transmission module 820 may be configured to perform the operation S620 described above, which will not be elaborated here.

[0165] The second processing module 830 is configured to process the first encrypted data set by using the second private key to obtain a second encrypted data set. In one embodiment, the second processing module 830 may be configured to perform the operation S630 described above, which will not be elaborated herein.

[0166] The sending module 840 is configured to process the second data set to be matched by using the shared key, the second private key, and the second screening mask set to obtain a third encrypted data set, and send the second encrypted data set and the third encrypted data set to the data requester. In one embodiment, the sending module 840 may be configured to perform the operation S640 described above, which will not be elaborated herein.

[0167] According to an embodiment of the present disclosure, the second transmission module 820 includes a second receiving unit and a fourth generating unit. The second receiving unit is configured to receive the k-th first feature parameter from the data requester. The fourth generating unit is configured to generate the k-th fourth feature data according to the k-th first feature parameter and the k-th third parameter in the preset parameter group, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0168] According to an embodiment of the present disclosure, the second transmission module 820 includes a second output unit and a fourth determining unit. The second output unit is configured to input the k-th fourth feature data into a sign function for the k-th fourth feature data and output the k-th target value. The fourth determining unit is configured to determine the k-th second screening mask data from the k-th group of random arrays according to the k-th target value by executing an oblivious transfer protocol according to a preset rule, where n and k are both positive integers, and 1 ≤ k ≤ n.

[0169] According to an embodiment of the present disclosure, the first processing module 810 includes a fifth generating unit and a sixth generating unit. The fifth generating unit is configured to generate a third threshold secret share according to the second threshold secret share and the system-supported coding parameter, where the system-supported coding parameter includes a parameter value and a parameter format. The sixth generating unit is configured to generate a second feature data set according to the second feature secret share and the third threshold secret share.

[0170] According to an embodiment of the present disclosure, any plurality of modules among the first generation module 710, the second generation module 720, the first transmission module 730, the receiving module 740, the intersection module 750, the first processing module 810, the second transmission module 820, the second processing module 830, and the sending module 840 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the first generation module 710, the second generation module 720, the first transmission module 730, the receiving module 740, the intersection module 750, the first processing module 810, the second transmission module 820, the second processing module 830, and the sending module 840 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or may be implemented by any other reasonable means such as hardware or firmware through integration or packaging of circuits, or may be implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the first generation module 710, the second generation module 720, the first transmission module 730, the receiving module 740, the intersection module 750, the first processing module 810, the second transmission module 820, the second processing module 830, and the sending module 840 may be at least partially implemented as a computer program module, and when the computer program module runs, it may execute corresponding functions.

[0171] Figure 9 FIG. schematically shows a block diagram of an electronic device suitable for implementing a data processing method according to an embodiment of the present disclosure.

[0172] As Figure 9 shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage section 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 901 may also include on-board memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0173] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0174] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, and the input / output (I / O) interface 905 is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read from it can be installed into the storage portion 908 as needed.

[0175] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.

[0176] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the ROM 902 and / or RAM 903 described above and / or one or more memories other than the ROM 902 and RAM 903.

[0177] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the item recommendation method provided by the embodiment of the present disclosure.

[0178] When the computer program is executed by the processor 901, it executes the above functions defined in the system / apparatus of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0179] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and is downloaded and installed through the communication part 909, and / or installed from the removable medium 911. The program code included in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0180] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 909, and / or installed from the removable medium 911. When the computer program is executed by the processor 901, it executes the above functions defined in the system of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0181] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0182] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented using a dedicated hardware-based system for performing the specified functions or operations, or can be implemented using a combination of dedicated hardware and computer instructions.

[0183] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or / and combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0184] The embodiments of the present disclosure have been described above. However, these embodiments are merely for illustrative purposes and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.

Claims

1. A data processing method, applied to the data demand side, includes: Processing preset screening threshold information through additive secret sharing to generate a first threshold secret shard and a second threshold secret shard; Generating a first feature data set according to the first threshold secret shard and a first feature secret shard; Through multiplicative secret resharing, obtaining a third feature data set according to the first feature data set and a second feature data set processed by a data provider using a preset parameter group; And by executing an oblivious transfer protocol, obtaining a first screening mask data set from the data provider according to the third feature data set; Receiving a second encrypted data set and a third encrypted data set from the data provider, where the second encrypted data set is obtained by processing a first encrypted data set using a shared key, and the first encrypted data set is obtained by the data demand side processing a first data set to be matched using the shared key and a first private key; the third encrypted data set is obtained by processing a second data set to be matched using the shared key, a second private key, and a second screening mask data set; Obtaining a target data set using a private set intersection algorithm according to the first screening mask data set, the second encrypted data set, and the third encrypted data set; Wherein, the first feature secret shard is obtained by the data provider processing the second data set to be matched through additive secret sharing; The second feature data set is determined by the data provider according to a second feature secret shard and the second threshold secret shard; The second screening mask data set is determined according to a fourth feature data set according to the oblivious transfer protocol, where the fourth feature data set is determined through multiplicative secret resharing according to a first feature data set processed by the data provider using a preset parameter group, and the product of corresponding elements in the third feature data set and the fourth feature data set and the sum of the first feature data set and the second feature data set satisfy a preset condition; Wherein, the processing of the first data set to be matched using the shared key and the first private key includes: Inputting the shared key and the first data set to be matched into a preset random point generation function to obtain a first private data set; For each private data in the first private data set, performing a point doubling operation on the private data using the first private key to obtain a first encrypted data set; The third feature data set includes n third feature data; the obtaining of the first screening mask data set from the data provider according to the third feature data set by executing the oblivious transfer protocol includes: For the k-th third feature data, inputting the k-th third feature data into a sign function to output a k-th target value; Obtaining the k-th group of random arrays from the data provider by executing the oblivious transfer protocol; Determining the k-th first screening mask data from the k-th group of random arrays according to the k-th target value, where n and k are both positive integers, and 1 ≤ k ≤ n.

2. The method according to claim 1, wherein, The first feature data set includes n pieces of first feature data, and the second feature data set includes n pieces of second feature data; obtaining a third feature data set by means of multiplicative secret reshare according to the first feature data set and the second feature data set processed by the data provider using a preset parameter set, includes: For the k-th piece of first feature data, generate a k-th first feature parameter by using the k-th first parameter, the k-th second parameter in the preset parameter set, and the k-th piece of first feature data, and send the k-th first feature parameter to the data provider; Receive the k-th second feature parameter, where the k-th second feature parameter is determined by the data provider according to the k-th first feature parameter, the k-th second feature data, the k-th third parameter, and the k-th fourth parameter, and the product of the k-th first parameter and the k-th third parameter is equal to the sum of the k-th second parameter and the k-th fourth parameter; Generate a k-th third feature data according to the k-th first parameter and the k-th second feature parameter, where n and k are both positive integers, and 1 ≤ k ≤ n.

3. The method according to claim 1, wherein, The obtaining the target data set by using the private intersection algorithm according to the first screening mask data set, the second encrypted data set, and the third encrypted data set, includes: Perform a double point operation on the third encrypted data set by using a first private key and the first screening mask data set to obtain a third encrypted data set embedded with the first screening mask; Generate a target data set by using a private combination intersection protocol according to the second encrypted data set and the third encrypted data set embedded with the first screening mask.

4. The method according to claim 3, wherein The generating a target data set by using a private combination intersection protocol according to the second encrypted data set and the third encrypted data set embedded with the first screening mask, includes: Obtain a target intersection by using a private combination intersection protocol according to the second encrypted data set and the third encrypted data set embedded with the first screening mask; Determine a target data set from the first data set to be matched according to the correspondence between each element in the target intersection and the second encrypted data set.

5. A data processing method, applied to a data provider, includes: Process a second data set to be matched by means of additive secret sharing to obtain a first feature secret shard and a second feature secret shard; And generate a second feature data set according to a second threshold secret shard and the second feature secret shard, where the second threshold secret shard is obtained by the data requester by means of additive secret sharing according to preset threshold information; Obtain a fourth feature data set by means of multiplicative secret reshare according to the first feature data set processed by the data requester using a preset parameter set; and determine a second screening mask data set according to the fourth feature data set by executing an oblivious transfer protocol; Process a first encrypted data set by using a second private key to obtain a second encrypted data set; Process the second dataset to be matched by using the shared key, the second private key, and the second set of screening masks to obtain a third encrypted dataset, and send the second encrypted dataset and the third encrypted dataset to the data requester; The first feature secret shard is obtained by the data provider processing the second dataset to be matched through additive secret sharing; The second feature dataset is determined by the data provider according to the second feature secret shard and the second threshold secret shard; The second set of screening masks is determined according to the fourth feature dataset by the oblivious transfer protocol, where the fourth feature dataset is determined by multiplicative secret resharing according to the first feature dataset processed by the data provider using a preset parameter set. The product of the corresponding elements in the third feature dataset and the fourth feature dataset and the sum of the first feature dataset and the second feature dataset satisfy a preset condition; the third feature dataset is obtained by the data requester through multiplicative secret resharing according to the first feature dataset and the second feature dataset processed by the data provider using a preset parameter set; Among them, the processing of the first dataset to be matched by using the shared key and the first private key includes: Input the shared key and the first dataset to be matched into a preset random point generation function to obtain a first private dataset; For each private data in the first private dataset, perform a point doubling operation on the private data by using the first private key to obtain a first encrypted dataset; The fourth feature dataset includes n fourth feature data. The determination of the second set of screening masks according to the fourth feature dataset by executing the oblivious transfer protocol includes: For the k-th fourth feature data, input the k-th fourth feature data into a sign function to output the k-th target value; By executing the oblivious transfer protocol, according to the k-th target value, determine the k-th second screening mask data from the k-th group of random arrays according to a preset rule, where n and k are both positive integers, and 1 ≤ k ≤ n.

6. The method according to claim 5, wherein, The first feature dataset includes n first feature data, and the second feature dataset includes n second feature data. The obtaining of the fourth feature dataset by multiplicative secret resharing according to the first feature dataset processed by the data requester using a preset parameter set includes: Receive the k-th first feature parameter from the data requester; Generate the k-th fourth feature data according to the k-th first feature parameter and the k-th third parameter in the preset parameter set, where n and k are both positive integers, and 1 ≤ k ≤ n.

7. The method according to claim 5, wherein The generation of the second feature dataset according to the second threshold secret shard and the second feature secret shard includes: Generate a third threshold secret shard according to the second threshold secret shard and the system support coding parameters, where the system support coding parameters include a parameter value and a parameter format; Generate the second feature dataset according to the second feature secret shard and the third threshold secret shard.

8. A data processing device, applied to the data demand side, includes: A first generation module, configured to process preset screening threshold information through additive secret sharing to generate a first threshold secret shard and a second threshold secret shard; A second generation module, configured to generate a first feature data set according to the first threshold secret shard and a first feature secret shard; A first transmission module, configured to obtain a third feature data set through multiplicative secret resharing according to the first feature data set and a second feature data set processed by a data provider using a preset parameter set; And obtain a first screening mask data set from the data provider according to the third feature data set by executing an oblivious transfer protocol; A receiving module, configured to receive a second encrypted data set and a third encrypted data set from the data provider, wherein the second encrypted data set is obtained by processing a first encrypted data set using a shared key, and the first encrypted data set is obtained by the data demand side using the shared key and a first private key to process a first data set to be matched; the third encrypted data set is obtained by processing a second data set to be matched using the shared key, a second private key, and a second screening mask data set; An intersection module, configured to obtain a target data set using a private intersection algorithm according to the first screening mask data set, the second encrypted data set, and the third encrypted data set; Wherein, the first feature secret shard is obtained by the data provider processing the second data set to be matched through additive secret sharing; The second feature data set is determined by the data provider according to a second feature secret shard and the second threshold secret shard; The second screening mask data set is determined according to a fourth feature data set according to the oblivious transfer protocol, wherein the fourth feature data set is determined through multiplicative secret resharing according to a first feature data set processed by the data provider using a preset parameter set, and the product of corresponding elements in the third feature data set and the fourth feature data set and the sum of the first feature data set and the second feature data set satisfy a preset condition; Wherein, the processing of the first data set to be matched using the shared key and the first private key includes: Inputting the shared key and the first data set to be matched into a preset random point generation function to obtain a first private data set; For each private data in the first private data set, performing a double point operation on the private data using the first private key to obtain a first encrypted data set; The third feature data set includes n third feature data; the obtaining of the first screening mask data set from the data provider according to the third feature data set by executing the oblivious transfer protocol includes: For the k-th third feature data, inputting the k-th third feature data into a sign function to output a k-th target value; Obtaining the k-th group of random arrays from the data provider by executing the oblivious transfer protocol; According to the k-th target value, determine the k-th first screening mask data from the k-th group of random arrays according to a preset rule, where n and k are both positive integers, and 1 ≤ k ≤ n.

9. A data processing device, applied to a data providing end, includes: A first processing module, configured to process a second dataset to be matched through an additive secret sharing method to obtain a first feature secret shard and a second feature secret shard; And generate a second feature dataset according to a second threshold secret shard and the second feature secret shard, where the second threshold secret shard is obtained by the data demanding end through an additive secret sharing method according to preset threshold information; A second transmission module, configured to obtain a fourth feature dataset through a multiplicative secret resharing method according to the first feature dataset processed by the data demanding end using a preset parameter group; and determine a second screening mask set according to the fourth feature dataset by executing an oblivious transfer protocol; A second processing module, configured to process a first encrypted dataset using a second private key to obtain a second encrypted dataset; A sending module, configured to process the second dataset to be matched using a shared key, the second private key, and a second screening mask dataset to obtain a third encrypted dataset, and send the second encrypted dataset and the third encrypted dataset to the data demanding end; Wherein, the first feature secret shard is obtained by the data providing end processing the second dataset to be matched through an additive secret sharing method; The second feature dataset is determined by the data providing end according to the second feature secret shard and the second threshold secret shard; The second screening mask dataset is determined according to the fourth feature dataset by executing an oblivious transfer protocol, where the fourth feature dataset is determined through a multiplicative secret resharing method according to the first feature dataset processed by the data providing end using a preset parameter group, and the product of the corresponding elements in the third feature dataset and the fourth feature dataset and the sum of the first feature dataset and the second feature dataset satisfy a preset condition; the third feature dataset is obtained by the data demanding end through a multiplicative secret resharing method according to the first feature dataset and the second feature dataset processed by the data providing end using a preset parameter group; Wherein, the processing of the first dataset to be matched using the shared key and the first private key includes: Inputting the shared key and the first dataset to be matched into a preset random point generation function to obtain a first private dataset; For each private data in the first private dataset, performing a double point operation on the private data using the first private key to obtain a first encrypted dataset; The fourth feature dataset includes n fourth feature data, and the determining of the second screening mask set according to the fourth feature dataset by executing an oblivious transfer protocol includes: For the k-th fourth feature data, inputting the k-th fourth feature data into a sign function to output a k-th target value; By executing the oblivious transfer protocol, according to the k-th target value, the k-th second screening mask data is determined from the k-th group of random arrays according to a preset rule, where n and k are both positive integers, and 1 ≤ k ≤ n.

10. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, Wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 4 or 5 to 7.

11. A computer-readable storage medium, having stored thereon executable instructions that, when executed by a processor, cause the processor to execute the method according to any one of claims 1 to 4 or 5 to 7.

12. A computer program product, comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 4 or 5 to 7.

Citation Information

Patent Citations

  • Method and system for improving secure multi-party computing efficiency

    CN111143894A

  • Data communication method, device and system

    CN113079008A