A privacy-protected matching method and system

By using inadvertent transmission and inadvertent pseudo-random functions in pattern matching, the problem of difficult data privacy in the prior art is solved, and pattern matching with efficient privacy protection is achieved.

CN115733671BActive Publication Date: 2025-05-16ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211370603.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-03
Publication Date
2025-05-16
Estimated Expiration
2042-11-03

AI Technical Summary

Technical Problem

The prior art is difficult to effectively protect the data privacy of both parties involved in the matching of information when performing pattern matching, and the matching efficiency is low and the communication overhead is large.

Method used

A privacy-protected matching method is proposed. By sending the length value of the character substring and the random binary matrix, an inadvertent transmission and preset inadvertent pseudo-random functions are performed to ensure that no information is leaked during the matching process and to improve matching efficiency.

Benefits of technology

While protecting data privacy, significantly improve pattern matching efficiency, reduce communication overhead, and achieve efficient privacy protection matching results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115733671B_ABST
    Figure CN115733671B_ABST
Patent Text Reader

Abstract

The present invention discloses a privacy-protected matching method, which includes the following steps: sending the length value m of the character substring to the second end, so that the second end cuts the long character string held by the second end into g character strings of length m; receiving the number g returned by the second end, and obtaining the value k to generate two random binary matrices of g rows and k columns, namely, matrix T and matrix U; in the case of receiving an instruction for the receiving end to participate in the oblivious transmission, performing k oblivious transmissions of length g with the corresponding columns of matrix T and matrix U as input; in the case of receiving an oblivious pseudo-random function execution instruction, performing g preset oblivious pseudo-random functions with the character substring as input to obtain a first output result; obtaining the second input result sent by the second end, and comparing the first output result with the second output result to confirm the matching result. Accordingly, the present invention discloses a privacy-protected matching system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a privacy computing technology, and in particular to a privacy-preserving matching method and system. Background Art

[0002] Pattern matching is a basic algorithm in strings. Given a substring, it is required to find all substrings that are identical to the substring in a string. Pattern matching is widely used in scenarios such as sensitive word detection, paper duplication checking, gene sequencing, and pattern mining.

[0003] With the introduction and improvement of laws and regulations such as the Cybersecurity Law and the Personal Information Protection Law, data compliance and privacy security are increasingly valued. How to perform pattern matching without exposing the original plaintext data has many application scenarios. For example: sensitive word detection. On some content production platforms, content creators need to pass the platform's sensitive word detection and related content review before publishing articles. If sensitive word detection can be completed without exposing the plaintext of the article, it will effectively protect the intellectual property rights of content creators and increase the attractiveness and credibility of the platform.

[0004] In the prior art, a simple hashing method can be used, that is, the two parties A and B can use the same hash function H to calculate the hash value of the data, and then send the hashed data to each other, and then determine whether it matches. This method is simple and fast, but not safe, and may leak additional information. If the data that the two parties need to intersect has a relatively small data space, then a malicious party can collide with the hash value transmitted by the other party through hash collision, thereby stealing additional information.

[0005] In view of this, it is hoped to obtain a new privacy-preserving matching method, which can complete pattern matching while protecting the data privacy of both parties involved in information matching. Summary of the invention

[0006] One of the purposes of the present invention is to provide a privacy-preserving matching method, which does not leak information of the interacting parties when performing pattern matching, thereby completing pattern matching while protecting private information from being leaked, and significantly improving matching efficiency and reducing communication overhead.

[0007] Based on the above invention purpose, the present invention proposes a privacy-preserving matching method, which is applied to a first end holding a character substring corresponding to a matching target, and comprises the steps of:

[0008] Sending the length value m of the character substring to the second end, so that the second end divides the long character string held by the second end into g character strings of length m;

[0009] Receive the quantity g returned by the second end, and obtain the value k to generate two random binary matrices with g rows and k columns, namely, matrix T and matrix U;

[0010] When receiving the instruction to participate in oblivious transmission as the receiving end, perform k oblivious transmissions of length g with the corresponding columns of the matrix T and the matrix U as input;

[0011] When receiving the oblivious pseudo-random function execution instruction, executing a preset oblivious pseudo-random function g times with the character substring as input to obtain a first output result;

[0012] Obtain a second input result sent by the second end, and compare the first output result with the second output result to confirm a matching result.

[0013] In the present invention, a pattern matching scheme under privacy protection is proposed, which can simultaneously protect the data privacy of long character strings and character substrings from being leaked, and complete pattern matching at the same time; protocol construction is based on the oblivious transfer extension protocol, which can effectively reduce communication costs and greatly improve computing efficiency.

[0014] Further, in some implementations, initializing two random binary matrices of g rows and k columns includes:

[0015] Initialize a random binary matrix T with g rows and k columns;

[0016] Obtain a preset random encoding function C, and use the character substring p as input to obtain an encoding result C(p);

[0017] The XOR result of the i-th column of the matrix T and C(p) is taken as the i-th column of the matrix U to construct the matrix U.

[0018] Further, in some embodiments, executing a preset random pseudo-random function g times with the character substring as input to obtain a first output result includes:

[0019] A hash function H is obtained, and a hash value is outputted with the current number j and the j-th row tj of the matrix T as input, to obtain a first output result.

[0020] Furthermore, in some embodiments, performing k oblivious transfers of length g with corresponding columns of the matrix T and the matrix U as inputs includes:

[0021] When receiving the instruction to participate in oblivious transmission as the sender, the i-th column ti of the matrix T and the i-th column ui of the matrix U are used as inputs to perform k oblivious transmissions.

[0022] Further, in some implementations, confirming the matching result by comparing the first output result and the second output result includes:

[0023] In a case where the second output result includes the same result as the first output result, it indicates that the long character string includes a character string that matches the character substring to be matched.

[0024] Further, in some implementations, confirming the matching result by comparing the first output result and the second output result includes:

[0025] When the second output result includes a third result and the third result is the same as the first output result, the position of the character string matching the character substring to be matched in the long character string is determined according to the position of the third result in the second output result.

[0026] Furthermore, in some implementations, after obtaining and sending the length m of the character substring, the method further includes:

[0027] Receive the value g returned by the second end, repeatedly arrange g rows with the character substring as rows, and generate a matrix P, wherein the matrix P is used to construct the matrix U and the matrix T.

[0028] The present invention also proposes another privacy-preserving matching method, which is applied to a second end holding a long string to be matched, and comprises the steps of:

[0029] Receive a length value m sent by the first end, and divide the long character string to be matched into g character strings of length m, where the length value m is the length value of the character substring corresponding to the matching target held by the first end;

[0030] Get k and initialize a random vector s of length k;

[0031] When receiving the instruction for the receiver to participate in the oblivious transmission, taking the elements in the random vector s as input, performing k oblivious transmissions, and constructing the matrix Q according to the k columns of output results obtained by the k oblivious transmissions;

[0032] When receiving an instruction for participating in an oblivious pseudo-random function as a sending end, the segmented character string is input as a variable, and a preset oblivious pseudo-random function is calculated using the rows of the matrix Q as a key to obtain a second output result, and the second output result is sent to the first end, and the second output result is used by the first end to output a matching result between the long character string and the character substring to be matched.

[0033] Further, in some implementations, calculating a preset inadvertent pseudo-random function to obtain and send a second output result includes:

[0034] Obtain hash function H and encoding function C;

[0035] Take the segmented string xj as input and obtain the encoding result C(xj);

[0036] A hash value is generated according to the execution number j, C(x), the random vector s, and the j-th row qj of the matrix Q to obtain a second output result.

[0037] Furthermore, in some implementations, after obtaining the length value m of the character substring corresponding to the matching target, the method includes:

[0038] Get the length value m of the character substring corresponding to the matching target;

[0039] The length n of the long character string z to be matched is calculated, n-m+1 is calculated and recorded as g, and the value g is sent to the first end.

[0040] Further, in some implementations, obtaining the length value m of the character substring corresponding to the matching target, and dividing the long character string to be matched into g character strings of length m includes:

[0041] Receive the length value m sent by the first end;

[0042] According to the length n of the long string z to be matched, calculate n-m+1, recorded as g;

[0043] Starting from the first position of the string z, move one position in sequence as the starting point to generate a string of length g, and arrange the strings in sequence to obtain an input matrix X, where each row of the matrix X is a string of length m after segmentation. The matrix X is used as an input matrix of an inadvertent pseudo-random function.

[0044] Another object of the present invention is to provide a privacy-preserving matching system, which will not leak the information of the interacting parties when performing pattern matching, thereby completing pattern matching while protecting private information from being leaked, and significantly improving matching efficiency and reducing communication overhead.

[0045] Based on the above purpose, the present invention also provides a privacy-preserving matching system, which includes a server and a user end communicating with the server, the server holds a long string z to be matched, and the user end holds a character substring p corresponding to the matching target, wherein:

[0046] The client obtains the length m of the character substring p and sends the value m to the server;

[0047] The server obtains the value m and splits the long string into g strings of length m;

[0048] The server initializes a random vector s of length k, and the client initializes two random binary matrices of g rows and k columns, namely matrix T and matrix U, where k is a preset security parameter less than m;

[0049] The server and the client perform k oblivious transmissions of length g. The client is the sender and the input is the corresponding columns of the matrix T and the matrix U. The server is the receiver and the input is the elements in the random vector s. The server constructs the matrix Q according to the output results of the above k oblivious transmissions.

[0050] The client uses the character substring p as input to execute a preset random pseudo-random function to obtain a first output result; the server uses the segmented character string as a variable input, uses the rows of the matrix Q as a key to calculate the preset random pseudo-random function to obtain a second output result, and sends the second result to the client;

[0051] The user end obtains the second result, and confirms a matching result by comparing the first output result with the second output result.

[0052] Furthermore, in some implementations, the server and the client have a uniformly preset random encoding function C.

[0053] The user terminal initializes a random binary matrix T with g rows and k columns;

[0054] The user terminal obtains a coding result C(p) by taking the character substring p as input according to the random coding function C;

[0055] The user end takes the XOR result of the i-th column of the matrix T and C(p) as the i-th column of the matrix U to construct the matrix U.

[0056] Furthermore, in some implementations, the server and the client have a unified preset hash function H.

[0057] The user terminal outputs a hash value with the current number j and the j-th row tj of the matrix T as input according to the hash function H, and obtains a first output result;

[0058] The server takes the segmented string xj as input in turn to obtain the encoding result C(xj); then generates a hash value based on the number of executions j, C(x), the random vector s, and the j-th row qj of the matrix Q to obtain the second output result.

[0059] Further, in some embodiments, performing k oblivious transmissions of length g comprises the steps of:

[0060] The user end acts as the transmitter, taking the i-th column ti of the matrix T and the i-th column ui of the matrix U as input;

[0061] The server acts as the receiving end, takes as input the element si in the random vector s, and performs k oblivious transfers of length g;

[0062] The server combines the above k output results into a matrix Q in the form of columns.

[0063] Further, in some implementations, when the second output result includes the same result as the first output result, the client indicates to the server that the long character string z includes a character string matching the character substring p.

[0064] Furthermore, in some embodiments, the user terminal is also used to include a third result in the second output result, and when the third result is the same as the first output result, determine the position of the character string that matches the character substring to be matched in the long character string based on the position of the third result in the second output result.

[0065] Furthermore, in some embodiments, the server is also used to receive the length m of the character substring p sent by the user terminal; calculate n-m+1 according to the length n of the long character string z to be matched, recorded as g, and send the value g to the user terminal.

[0066] Furthermore, in some embodiments, the server is also used to obtain the length value m of the character substring corresponding to the matching target; calculate n-m+1 according to the length n of the long character string z to be matched, recorded as g; starting from the first position of the character string z, move one position in turn as the starting point to generate a character string of length g, and arrange the character strings in sequence to obtain an input matrix X, wherein each row of the matrix X is a character string of length m after segmentation, and the matrix X is used as an input matrix of an inadvertent pseudo-random function.

[0067] Furthermore, in some implementations, the client is further configured to receive a g value sent by the server, expand p to g rows, and generate a matrix P, wherein the matrix P is used to construct the matrix U and the matrix T.

[0068] The pattern matching system under privacy protection provided by the present invention can simultaneously protect the data privacy of long character strings and character substrings from being leaked, and simultaneously complete pattern matching; protocol construction based on the oblivious transfer extension protocol can effectively reduce communication costs and greatly improve computing efficiency.

[0069] The present invention also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the steps applied to the S end in the pattern matching method under privacy protection described in the present invention.

[0070] The present invention further provides another computer-readable storage medium having a computer program stored thereon. When the computer program is executed in a computer, the computer is caused to execute the steps applied to the R end in the pattern matching method under privacy protection described in the present invention.

[0071] The method and system described in the present invention have the following beneficial effects:

[0072] Firstly, a privacy-preserving pattern matching scheme is proposed, which can protect the data privacy of long strings and character substrings corresponding to matching targets from being leaked, and complete pattern matching at the same time.

[0073] Secondly, protocol construction based on the oblivious transfer extension protocol can effectively reduce communication costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] Figure 1 The flowchart of the privacy protection matching method of the present invention in one implementation is exemplarily shown.

[0075] Figure 2 The flowchart of the privacy protection matching method of the present invention in another implementation manner is exemplarily shown.

[0076] Figure 3 A system schematic diagram of a privacy-preserving matching system according to the present invention in one implementation is exemplarily shown.

[0077] Figure 4 The flowchart exemplarily shows the steps executed by the privacy protection matching system described in the present invention in one implementation mode. DETAILED DESCRIPTION

[0078] The privacy protection matching method and system of the present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments of the specification, but the detailed description does not constitute a limitation to the present invention.

[0079] Oblivious Transfer (OT) is a cryptographic protocol that enables the sender to pass one of many messages to the receiver, but the receiver is unaware of the message received.

[0080] A commonly used oblivious transmission scheme is 1-2 oblivious transmission. In 1-2 oblivious transmission, the sender holds two data and the receiver can choose to obtain one of them, but the sender does not know which data the receiver has chosen. For example, the sender S inputs data m0 and m1. The plaintext m1 and m2 are encrypted first and then calculated, which is equivalent to calculating first and then encrypting. The receiver R inputs a bit b, b∈{0,1}. After running the oblivious transmission, R will obtain m b, which is the data corresponding to b. However, S does not know the b input by R, and R does not know the m held by S. 1-b . 1-2 oblivious transmission can be extended to 1-n oblivious transmission, that is, the receiver can choose to obtain one data from n data and keep it confidential from the sender.

[0081] For pattern matching, when both parties S and R have only one string of equal length, it can be transformed into checking whether the information held by both parties is the same without revealing the information they hold. Assume that S holds data x and R holds data y. The byte lengths of x and y are equal, and the length is m. S generates two random binary strings for each bit of data x, with a length of l. With R as the receiver and S as the sender, the 1-2 oblivious transfer protocol is executed. Then R generates two random binary strings for each bit of y. i , select one of the two random binary strings held by S, and XOR the m binary strings received to obtain a binary string K y The sender A can also select a binary string according to each bit of x, and XOR these m binary strings to obtain the binary string K x . Finally, A will K x Send it to B, B compares K x With K y It can be determined whether A and B are the same.

[0082] Furthermore, if the binary string held by A is regarded as a random seed k, held by A. From the perspective of R, the previous process of comparing whether the strings x and y held by S and R are the same is that R inputs data y and obtains a random binary string. This binary string is determined by the random seed k held by S and the input y, and S cannot know R's input y. This process can be regarded as an oblivious pseudorandom function (OPRF). An oblivious pseudorandom function is a cryptographic protocol in which the sender can choose a random seed, the receiver can choose an input and obtain the output of a pseudorandom function, and the sender does not know it. The receiver R executes an oblivious pseudorandom function, and the sender S can execute an ordinary pseudorandom function. Pattern matching can be achieved through comparison.

[0083] However, when performing pattern matching through OT and OPRF, the speed of the algorithm depends on the number of set elements to be intersected and the size of each element. As a result, when the size of the set becomes large or the elements in the set become long, the speed of the algorithm will become slower and slower.

[0084] The present invention is also a privacy-preserving matching method scheme proposed based on the basic theories of OT and OPRF. It can not only perform one-to-one information comparison, but also more efficiently query whether a long text contains target matching information while protecting the data privacy of both parties.

[0085] In one embodiment of the present invention, a privacy-preserving matching method is proposed. Figure 1 The flowchart of the privacy protection matching method of the present invention in one implementation is exemplarily shown.

[0086] like Figure 1 As shown, for the R end holding the character substring corresponding to the matching target, the privacy protection matching method includes the steps of:

[0087] 100: Send the length value m of the character substring to the second end, so that the second end divides the long character string held by the second end into g character strings of length m.

[0088] 110: receiving the quantity g returned by the second end, and obtaining a value k, and generating two random binary matrices with g rows and k columns, namely, matrix T and matrix U;

[0089] 120: upon receiving the instruction to participate in oblivious transmission as a receiving end, performing k oblivious transmissions of length g with corresponding columns of the matrix T and the matrix U as input;

[0090] 130: When receiving the oblivious pseudo-random function execution instruction, execute a preset oblivious pseudo-random function g times with the character substring as input to obtain a first output result;

[0091] 140: Obtain a second input result sent by the second end, and compare the first output result with the second output result to confirm a matching result, wherein the second input result comes from the S end holding the long string to be matched.

[0092] Since the privacy-preserving matching method provided by the present invention involves more cryptographic privacy calculations and the two-end interactions are relatively close, in order to facilitate a clearer and more complete explanation of the solution, the methods executed by the two parties of the pattern matching interaction, namely the R end and the S end described in the present invention, are described in combination.

[0093] Figure 2 The flowchart of the privacy protection matching method of the present invention in another implementation manner is exemplarily shown.

[0094] like Figure 2 As shown, for the S end holding the long string to be matched, the privacy-preserving matching method includes the steps of:

[0095] 200: Receive the length value m sent by the first end, and divide the long character string to be matched into g characters of length m. The length value m is the length value of the character substring corresponding to the matching target held by the first end.

[0096] 210: Get k, initialize a random vector s with a length of k;

[0097] 220: When receiving the instruction for the receiving end to participate in the oblivious transmission, perform k oblivious transmissions with the elements in the random vector s as input, and construct a matrix Q according to the k columns of output results obtained by the k oblivious transmissions;

[0098] 230: When receiving the instruction to participate in the oblivious pseudo-random function as the sending end, the segmented character string is input as a variable, and the rows of the matrix Q are used as a key to calculate the preset oblivious pseudo-random function to obtain a second output result, and the second output result is sent to the first end. The second output result is used by the first end to output the matching result between the long character string and the character substring to be matched.

[0099] In some specific embodiments, in combination with the processing steps of the R end and the S end, the privacy protection matching method provided by the present invention is as follows:

[0100] The R end holds a character substring p, obtains its length m, and sends the value m to the S end. The S end holds a long text z, whose length is n, n ≥ m. The primary goal of the privacy protection matching method provided by the present invention is to enable the R end to determine whether z contains the p string without leaking the specific information of p and z.

[0101] First, R sends the length m of its character substring p to S, and S will split the long string z it holds to obtain g split substrings of length m. These split substrings are arranged in sequence in z, and all possible arrangements of strings of length m are compared one by one with the character substring p corresponding to the matching target to confirm whether there is a string matching p in z.

[0102] In some embodiments, the S end obtains the number g of the segmented substrings by calculating n-m+1, and sends the value g to the R end, because the value g is the basis for the subsequent number of comparisons.

[0103] Take the string absde held by the S end as an example. If the length of p is m=3, the S end segments the string with a length of 3 to obtain adc, bcd, and cde. In some embodiments, in order to facilitate the subsequent calculation of the oblivious transfer and the oblivious transfer function, the segmented string is represented in the form of a string sequence or a matrix. After calculating the value g, starting from the first position of the string z, move one position in sequence as the starting point to generate a string of length g, and arrange the strings in sequence to obtain the input matrix X. Among them, each row of the matrix X is a string of length m after segmentation.

[0104] In a more specific embodiment, we still take the string abcde held by S as an example, n=5, when the length of p is m=2, g=n-m+1=4. Then, starting from the first position of the string z, we move one position in turn as the starting point to generate a string of length 4, and we can get z1=abcd, z2=bcde. i Arrange the columns to get the matrix It can be seen that each row of the matrix X is a string of length m. Optionally, for the convenience of explanation and calculation, the matrix X is represented and calculated in the form of rows, that is, expressed as

[0105] In some embodiments, in order to unify the input format and facilitate subsequent comparison, p is also constructed as an input matrix with g rows.

[0106] Since the efficiency of pattern matching based on OT is low, when constructing an oblivious pseudo-random function, n oblivious transmissions are required. And the number of transmissions is proportional to the size of the set. In addition, since oblivious transmission uses public-private key encryption technology, the speed of oblivious transmission is very slow. Therefore, in order to reduce the number of oblivious transmissions used, the Oblivious Transfer Extension (OTE) method will be introduced.

[0107] The goal of OTE is to use a small amount of basic oblivious transmission, combined with symmetric encryption, to achieve a large amount of oblivious transmission. To represent m times of oblivious transmission, each time transmitting l bits, the definition of oblivious transmission extension is to use To achieve Where k is a relatively small security parameter, which is much smaller than m. The above process is first implemented using To achieve Reuse It can be easily implemented

[0108] For example, the input of S is g pairs (x j,0 ,xj,1 ), the R end has a selection string r, and there is a random function F between the S end and the R end, which is used to randomly map a bit string of length k to a bit string of length l. The S end initializes a random binary vector of length k, that is, s∈{0,1} k ,s i is the i-th bit of vector s.

[0109] Assume that R first initializes a random binary bit matrix T, T is g rows and k columns, and each element of the matrix is ​​0 or 1. With R as the sender and S as the receiver, execute For the i-th oblivious transmission of length g, the input to R is where t i Represents the i-th column of matrix T, with a length of g; the input of the S terminal is s i , when s i = 0, S gets t i ,s i =1, S gets All the columns received by S are combined into a matrix with g rows and k columns, which is called matrix Q. Then R is used as the receiver and S is used as the sender. S needs to perform g transmissions. For any 1≤j≤g, S sends a pair of data (y j,0 ,y j,1 )in, q j is the jth row of matrix Q. Then, for the receiver R, the output is t j represents the jth row of matrix T. It can be proved that

[0110] From the perspective of oblivious transmission, r can be regarded as the receiver's selection bit. is the sender's input data, and there are a total of g oblivious transmissions. In this case, the data transmitted by the oblivious transmission is random. If you want to transmit specific data, you can put As the key of the encryption function, used to encrypt (x j,0 ,x j,1 ), the recipient can use t j Decrypt the corresponding x j,r The encryption and decryption here is symmetric encryption, which is much more efficient than asymmetric encryption. The key with a transmission length of k is used as the key for symmetric encryption, and then the data with a length of g is encrypted for transmission, which increases the computational overhead caused by asymmetric encryption.

[0111] However, the above method has not reduced the amount of data transmitted. Therefore, in addition to OTE, the k-times oblivious transmission can be expanded from the original 1-2 oblivious transmission to n-choose-1 oblivious transmission, and further expanded to infinite-choose-1, so that only one oblivious transmission can be performed to realize the oblivious pseudo-random function, which has higher efficiency and privacy performance.

[0112] In some embodiments, after the R terminal initializes a random binary matrix T with g rows and k columns, each column t i It will also be XORed with the selected bit vector and sent to the sender via 2-choose-1 oblivious transmission. Each column obtained forms the matrix U, then Furthermore, in some embodiments, the S side and the R side have a common random coding function C: {0,1} * →{0,1} k , for encoding an arbitrary length bit input into a k-bit output, where r comes from the encoding function C, At this time, the sender's selection bit r is not limited to one or a fixed bit, but can be any length bit. That is, the string used for matching is no longer a single number, but can be of any length. Similarly, for the sender, matching can also be performed on text of any length.

[0113] In some embodiments, there is also a common hash function H between the S end and the R end. There are g selected strings p on the R end, a common random encoding function C, the encoding length of C is k, and a common hash function H: [g]×{0,1} k →{0,1} l .

[0114] The R side initializes a random binary matrix T with g rows and k columns, and passes Construct the matrix U. Initialize k randomly selected bits s = (s1,…,s k ).

[0115] R acts as the sender and S acts as the receiver to perform k OTs of length g. For the i-th oblivious transmission, the input of R is (t i ,u i ); the input of S is s i , when s i = 0, S gets t i ,s i =1, S gets u i The S end combines all the received columns into a matrix with g rows and k columns, which is the matrix Q. From the perspective of the rows,

[0116] Then R acts as the receiver and S as the sender, and performs g OPRFs. R outputs H(j,t j )

[0117] According to the above, the input at the R end is p, satisfying In addition, since the S end as a sender does not generate output, it is also necessary to calculate locally Where 1≤j≤g. After calculating the above results, the S end needs to send g calculation results to the R end. The R end determines the matching result by comparing the output results of the S end and the R end. In the case of , it is determined that the long string z includes the matching target p. The R side can also calculate the position of the j-th line string in z by traversing all j and finding no equal items, which means that the match is not completed and there is no equal substring in p in z.

[0118] The privacy-preserving matching method provided by the present invention provides an efficient and low-cost matching method while protecting the information privacy of both parties in pattern matching.

[0119] In another embodiment of the present invention, a privacy-preserving matching system is provided. Figure 3 The following is a schematic diagram of a privacy protection matching system according to the present invention in one embodiment. Figure 3 As shown, the privacy-preserving matching system includes a server and a client for data communication with the server, and the number of the client can be one or more. The server holds a long string z to be matched, and the client holds a character substring p corresponding to the matching target. Figure 4 The flowchart of the steps executed by the privacy protection matching system of the present invention in one embodiment is shown as an example. Figure 4 As shown, the privacy-preserving matching system is used to perform the following steps:

[0120] 400: The client obtains the length m of the character substring p and sends the value m to the server;

[0121] 410: The server obtains the value m and splits the long string into g strings of length m;

[0122] 420: The server initializes a random vector s of length k, and the client initializes two random binary matrices of g rows and k columns, namely, matrix T and matrix U, where k is a preset security parameter less than m.

[0123] 430: The server and the client perform k oblivious transfers of length g, the client is a sender and the input is the corresponding columns of the matrix T and the matrix U, the server is a receiver and the input is the elements in the random vector s, and the server constructs the matrix Q according to the output results of the k oblivious transfers;

[0124] 440: The client uses the character substring p as input to execute a preset oblivious pseudo-random function to obtain a first output result; the server uses the segmented character string as a variable input, uses the row of the matrix Q as a key to calculate the preset oblivious pseudo-random function to obtain a second output result, and sends the second result to the client;

[0125] 450: The user terminal obtains the second result, and confirms the matching result by comparing the first output result and the second output result.

[0126] In the privacy-preserving matching system provided by the present invention, the user terminal holds a character substring p corresponding to the matching target phrase, and the server holds a long text z, whose length is n, n ≥ m. The primary goal of the above privacy-preserving matching system is that the user terminal can determine whether p is included in the character string z without leaking the specific information of p and z.

[0127] First, the client determines the length m of the character substring p and sends the value m to the server. The server will split the long string z it holds to obtain g split substrings of length m. These split substrings are all possible string arrangements of length m in z. The split strings can be compared one by one with the character substring p corresponding to the matching target to confirm whether there is a string in z that matches p.

[0128] In some embodiments, the server obtains the number g of segmented substrings by calculating n-m+1, and sends the value g to the user end, because the value g is the basis for the number of subsequent comparisons.

[0129] Take the string absde held by the server as an example. If the length of p is m=3, the server segments the string with a length of 3 to obtain adc, bcd, and cde. In some embodiments, in order to facilitate the subsequent calculation of oblivious transfer and oblivious transfer functions, the segmented string is represented in the form of a string sequence or matrix. After calculating the value g, starting from the first position of the string z, move one position in sequence as the starting point to generate a string of length g, and arrange the strings in sequence to obtain the input matrix X. Among them, each row of the matrix X is a string of length m after segmentation.

[0130] In a more specific embodiment, the server still holds the string abcde, for example, n = 5, when the length of p is m = 2, g = n-m+1 = 4. Then, starting from the first position of the string z, move one position in turn as the starting point to generate a string of length 4, and you can get z1 = abcd, z2 = bcde. i Arrange the columns to get the matrix It can be seen that each row of the matrix X is a string of length m. Optionally, for the convenience of explanation and calculation, the matrix X is represented and calculated in the form of rows, that is, expressed as

[0131] In some embodiments, in order to unify the input format and facilitate the execution of OPRF, p is also constructed as an input matrix with g rows

[0132] Since the efficiency of pattern matching based on OT is low, when constructing an oblivious pseudo-random function, n oblivious transmissions are required. And the number of transmissions is proportional to the size of the set. In addition, since oblivious transmission uses public-private key encryption technology, the speed of oblivious transmission is very slow. Therefore, in order to reduce the number of oblivious transmissions used, the Oblivious Transfer Extension (OTE) method will be introduced.

[0133] The goal of OTE is to use a small amount of basic oblivious transmission, combined with symmetric encryption, to achieve a large amount of oblivious transmission. To represent m times of oblivious transmission, each time transmitting l bits, the definition of oblivious transmission extension is to use To achieve Where k is a relatively small security parameter, which is much smaller than m. The above process is first implemented using To achieve Reuse It can be easily implemented

[0134] For example, the server input is g pairs (x j,0 ,x j,1 ), the client has a selection string r, and there is a random function F between the server and the client, which is used to randomly map a bit string of length k to a bit string of length l. The server initializes a random binary vector of length k, that is, s∈{0,1} k ,s i is the i-th bit of vector s.

[0135] Assume that the client first initializes a random binary bit matrix T, T is g rows and k columns, and each element of the matrix is ​​0 or 1. The client is the sender and the server is the receiver. For the i-th oblivious transmission of length g, the input from the user is where t i represents the i-th column of matrix T, with a length of g; the input of the server is s i , when s i = 0, S gets t i ,s i =1, S gets All the columns received by the server are combined into a matrix with g rows and k columns, called matrix Q. Then the user end is regarded as the receiver and the server as the sender. The server needs to perform g transmissions. For any 1≤j≤g, the S end sends a pair of data (y j,0 ,y j,1 )in, q j is the jth row of matrix Q. Then, for the receiver user end, the output is t j represents the jth row of matrix T. It can be proved that

[0136] From the perspective of oblivious transmission, r can be regarded as the receiver's selection bit. is the sender's input data, and there are a total of g oblivious transmissions. In this case, the data transmitted by the oblivious transmission is random. If you want to transmit specific data, you can put As the key of the encryption function, used to encrypt (x j,0 ,x j,1 ), the recipient can use t j Decrypt the corresponding x j,r The encryption and decryption here is symmetric encryption, which is much more efficient than asymmetric encryption. The key with a transmission length of k is used as the key for symmetric encryption, and then the data with a length of g is encrypted for transmission, which increases the computational overhead caused by asymmetric encryption.

[0137] However, the above method has not reduced the amount of data transmitted. Therefore, in addition to OTE, the k-times oblivious transmission can be expanded from the original 1-2 oblivious transmission to n-choose-1 oblivious transmission, and further expanded to infinite-choose-1, so that only one oblivious transmission can be performed to realize the oblivious pseudo-random function, which has higher efficiency and privacy performance.

[0138] In some embodiments, the user terminal first initializes a random binary matrix T with g rows and k columns, and each column t i It will also be XORed with the selected bit vector and sent to the sender via 2-choose-1 oblivious transmission. Each column obtained forms the matrix U, then Furthermore, in some embodiments, the server and the client have a common random encoding function C: {0,1} * →{0,1} k , used to encode an arbitrary length bit input into a k-bit output, where r comes from the encoding function C, At this time, the sender's selection bit r is not limited to one or a fixed bit, but can be any length bit. That is, the string used for matching is no longer a single number, but can be of any length. Similarly, for the sender, matching can also be performed on text of any length.

[0139] In some embodiments, there is also a common hash function H between the client and the server. There are g selected strings p on the client, a common random encoding function C, the encoding length of C is k, and a common hash function H: [g]×{0,1} k →{0,1} l .

[0140] The user initializes a random binary matrix T with g rows and k columns, and passes Construct the matrix U. The server initializes k randomly selected bits s=(s1,…,s k ).

[0141] The user end acts as a sender, and the server acts as a receiver to perform k OTs of length g. For the i-th oblivious transmission, the input of the user end is (t i ,u i ); the server input is s i , when s i = 0, the server gets t i ,s i =1, the server gets u i The server combines all received columns into a matrix with g rows and k columns, which is the matrix Q. From the perspective of rows,

[0142] Then the client acts as the receiver and the server acts as the sender, performing g OPRFs and outputting H(j,t j ).

[0143] According to the above, the user input is p, satisfying In addition, since the server as a sender does not generate any output, it is also necessary to calculate it locally. Where 1≤j≤g. After calculating the above results, the server needs to send g calculation results to the user end. The user end determines the matching result by comparing the output results of the server and the user end. In the case of , it is determined that the long string z includes the matching target p. The user end can also calculate the position of the j-th line string in z by traversing all j and finding no equal items, which means that the match is not completed and there is no equal substring in p in z.

[0144] It should be noted that the privacy protection matching method provided by the present invention is not limited to being used in a system including a server and a user end. For example, it can also be used in a system including only a server. When the server receives a pattern matching request, one or more modules in the server cooperate to implement the above-mentioned privacy protection matching method.

[0145] An embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the steps of the privacy protection matching method for the S end in the above embodiment of the present invention. Since the steps executed are the same as the steps of the privacy protection matching method described above, they will not be described again here.

[0146] One embodiment of the present invention further provides another computer-readable storage medium, on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the steps of the matching method for privacy protection of the R end in the above embodiment of the present invention. Since the steps executed are the same as the steps of the matching method for privacy protection described above, they will not be described again here.

[0147] It should be noted that the above examples are only specific embodiments of the present invention, and the present invention is obviously not limited to the above examples, and there are many similar variations. All variations directly derived or associated from the contents disclosed by the technicians in this field should fall within the protection scope of the present invention.

Claims

1. A privacy-preserving matching method, applied to a first end holding a character substring corresponding to a matching target, the method comprising: Sending the length value m of the character substring to the second end, so that the second end divides the long character string held by the second end into g character strings of length m; Receive the quantity g returned by the second end, obtain the value k, and generate two random binary matrices with g rows and k columns, namely, matrix T and matrix U; Upon receiving an instruction to participate in oblivious transmission with the second end, performing oblivious transmission of length g k times with corresponding columns of the matrix T and the matrix U as input; When receiving the oblivious pseudo-random function execution instruction, executing a preset oblivious pseudo-random function g times with the character substring as input to obtain a first output result; Obtain a second output result sent by the second end, and compare the first output result with the second output result to confirm a matching result.

2. According to the privacy-preserving matching method of claim 1, generating two random binary matrices with g rows and k columns comprises: Initialize a random binary matrix T with g rows and k columns; Obtain a preset random encoding function C, and use the character substring p as input to obtain an encoding result C(p); The XOR result of the i-th column of the matrix T and C(p) is taken as the i-th column of the matrix U to construct the matrix U.

3. According to the privacy protection matching method of claim 1, executing a preset random pseudo-random function g times with a character substring as input, obtaining a first output result comprises: Get the hash function H, and output the current number j and the jth row t of the matrix T j is the hash value of the input and obtains the first output result.

4. The privacy-preserving matching method according to claim 1, wherein the step of performing k oblivious transmissions of length g with corresponding columns of the matrix T and the matrix U as input comprises: When receiving the instruction to participate in the oblivious transmission by the sender, the i-th column t of the matrix T i and the i-th column u of the matrix U i As input, perform k oblivious transfers.

5. The privacy protection matching method according to claim 1, confirming the matching result by comparing the first output result and the second output result comprises: In a case where the second output result includes the same result as the first output result, it indicates that the long character string includes a character string that matches the character substring to be matched.

6. The privacy protection matching method according to claim 1, confirming the matching result by comparing the first output result and the second output result comprises: When the second output result includes a third result and the third result is the same as the first output result, the position of the character string matching the character substring to be matched in the long character string is determined according to the position of the third result in the second output result.

7. The privacy protection matching method according to claim 1, after sending the length m of the character substring to the second end, the method further comprises: Receive the value g returned by the second end, repeatedly arrange g rows with the character substring as rows, and generate a matrix P, wherein the matrix P is used to construct the matrix U and the matrix T.

8. A privacy-preserving matching method, applied to a second end holding a long string to be matched, the method comprising: Receive a length value m sent by the first end, and divide the long character string to be matched into g character strings of length m, where the length value m is the length value of the character substring corresponding to the matching target held by the first end; Get k and initialize a random vector s of length k; When receiving the instruction to participate in the oblivious transmission with the second end, taking the elements in the random vector s as input, performing k oblivious transmissions, and constructing a matrix Q according to the k columns of output results obtained by the k oblivious transmissions; When receiving an instruction for participating in an oblivious pseudo-random function as a sending end, the segmented character string is input as a variable, and a preset oblivious pseudo-random function is calculated using the rows of the matrix Q as a key to obtain a second output result, and the second output result is sent to the first end, and the second output result is used by the first end to output a matching result between the long character string and the character substring to be matched.

9. The privacy-preserving matching method according to claim 8, wherein the step of calculating a preset inadvertent pseudo-random function to obtain and send the second output result comprises: Obtain hash function H and encoding function C; Sequentially use the split string x j As input, get the encoding result C(x j ); According to the number of executions j and C(x), the random vector s and the j-th row q of the matrix Q j Generate a hash value and obtain a second output result.

10. The privacy protection matching method according to claim 8, after receiving the length value m sent by the first end, the method comprises: Get the length value m of the character substring corresponding to the matching target; The length n of the long character string z to be matched is calculated, n-m+1 is calculated and recorded as g, and the value g is sent to the first end.

11. The privacy protection matching method according to claim 8, receiving the length value m sent by the first end, and dividing the long string to be matched into g strings of length m comprises: Receive the length value m sent by the first end; According to the length n of the long string z to be matched, calculate n-m+1, recorded as g; Starting from the first position of the string z, move one position in sequence as the starting point to generate a string of length g, and arrange the strings in sequence to obtain an input matrix X, where each row of the matrix X is a string of length m after segmentation. The matrix X is used as an input matrix of an inadvertent pseudo-random function.

12. A privacy-preserving matching system, comprising a server and a client communicating with the server, wherein the server holds a long string z to be matched, and the client holds a character substring p corresponding to a matching target. The client obtains the length m of the character substring p and sends the value m to the server; The server obtains the value m and splits the long string into g strings of length m; The server initializes a random vector s of length k, and the client initializes two random binary matrices of g rows and k columns, namely matrix T and matrix U, where k is a preset safety parameter smaller than m; The server and the client perform k oblivious transmissions of length g. The client is the sender and the input is the corresponding columns of the matrix T and the matrix U. The server is the receiver and the input is the elements in the random vector s. The server constructs the matrix Q according to the output results of the above k oblivious transmissions. The user terminal executes a preset random pseudo-random function with the character substring p as input to obtain a first output result; The server uses the segmented character string as a variable input, uses the row of the matrix Q as a key to calculate the preset inadvertent pseudo-random function, obtains a second output result, and sends the second output result to the user terminal; The user end obtains the second output result, and confirms a matching result by comparing the first output result with the second output result.

13. The privacy-preserving matching system of claim 12, wherein the server and the user end have a uniformly preset random encoding function C, The user terminal initializes a random binary matrix T with g rows and k columns; The user terminal obtains a coding result C(p) by taking the character substring p as input according to the random coding function C; The user end takes the XOR result of the i-th column of the matrix T and C(p) as the i-th column of the matrix U to construct the matrix U.

14. The privacy-preserving matching system of claim 13, wherein the server and the user end have a uniformly preset hash function H. The user terminal outputs the hash function H with the current number j and the jth row t of the matrix T. j is the hash value of the input, and obtains the first output result; The server takes the split string x in turn. j As input, get the encoding result C(x j ); then according to the number of executions j and C(x), random vector s and the jth row q of matrix Q j Generate a hash value and obtain a second output result.

15. The privacy-preserving matching system of claim 12, wherein performing k times of oblivious transmission of length g comprises the steps of: The user end is the transmitter, with the i-th column t of the matrix T i and the i-th column u of the matrix U i is the input; The server acts as the receiving end, takes the element si in the random vector s as input, and performs k oblivious transfers of length g; The server combines the above k output results into a matrix Q in the form of columns.

16. The privacy-preserving matching system of claim 12, wherein when the second output result includes a result identical to the first output result, the client indicates to the server that the long character string z includes a character string matching the character substring p.

17. The privacy-preserving matching system of claim 12, wherein the user terminal is further configured to include a third result in the second output result, and when the third result is the same as the first output result, determine the position of the character string that matches the character substring to be matched in the long character string according to the position of the third result in the second output result.

18. In the privacy-preserving matching system as described in claim 12, the server is further used to receive the length m of the character substring p sent by the user terminal; calculate n-m+1 according to the length n of the long character string z to be matched, recorded as g, and send the value g to the user terminal.

19. The privacy-preserving matching system according to claim 12, wherein the server is further configured to: Get the length value m of the character substring corresponding to the matching target; According to the length n of the long string z to be matched, calculate n-m+1, recorded as g; Starting from the first position of string z, move one position in sequence as the starting point to generate a string of length g, and arrange the strings in sequence to obtain the input matrix X, where Each row of the matrix X is a segmented character string of length m, and the matrix X is used as an input matrix of the oblivious pseudo-random function.

20. The privacy-preserving matching system of claim 12, wherein the user terminal is further used to receive the g value sent by the server, expand p to g rows, and generate a matrix P, wherein the matrix P is used to construct the matrix U and the matrix T.

Citation Information

Patent Citations

  • Data processing method and system

    CN113259106A

  • Union calculation method and device for privacy sets of two parties

    CN113806795A