Scalable multi-party privacy protection set intersection method, system and related equipment

By simulating the multi-party intersection process, utilizing the collaborative operation of the initiator and participants to select and modify the matrix, and combining random matrices and pseudo-random function keys, the problem of information leakage in multi-party intersection is solved, and a safe and efficient multi-party intersection operation is achieved.

CN115865306BActive Publication Date: 2025-09-16INSIGHT TECHNOLOGY (XIONGAN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211496530.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2025-09-16
Estimated Expiration
2042-11-25

AI Technical Summary

Technical Problem

In multi-party intersection applications, the intermediate results will expose some data information outside the intersection, which cannot meet security requirements. Existing technologies make it difficult to complete multi-party intersection operations while ensuring security.

Method used

Through collaborative operations between the initiator and the participants, the initial matrix is ​​selected and modified using the local data set. Combined with the random matrix and pseudo-random function key, the two-party intersection process is simulated, and finally the intersection is calculated in the last step to achieve multi-party privacy intersection.

Benefits of technology

The security of multi-party intersection operations is improved, ensuring that information outside the intersection is not leaked, while completing the intersection task and supporting any multi-party privacy intersection function.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865306B_ABST
    Figure CN115865306B_ABST
Patent Text Reader

Abstract

The present application discloses a scalable multi-party privacy-preserving set intersection method, system, and related equipment. The method includes: selecting and modifying a first initial matrix by an initiator to obtain a reference first initial matrix; selecting and modifying a second initial matrix by the first n-1 participants to obtain a reference second initial matrix for the first n-1 participants; obtaining a random matrix by the initiator, and determining an initial OT operation result using the random matrix and the reference first initial matrix; determining the OT operation result of the n-1th participant based on the initial OT operation result and the reference second initial matrix of the first n-1 participants by the first n-1 participants; determining initial intersection judgment information by the n-th participant based on the OT operation result of the n-1th participant and the local data set of the n-th participant; and determining target intersection judgment information by the initiator based on the initial intersection judgment information. The present application embodiment can improve security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of privacy computing technology and computer technology, and specifically to a scalable multi-party privacy protection set intersection method, system, and related equipment. Background Art

[0002] With the development of artificial intelligence, the value of data is increasingly valued. Data analysis has also become a research focus. In practical applications, when performing multiple two-way intersections, the intermediate results can reveal data outside of the intersection, making it impossible to meet the security requirements of multi-party intersection. However, due to its superior performance, it is still used in some scenarios. Therefore, how to improve the security of multi-party intersection operations is an urgent issue. Summary of the Invention

[0003] The embodiments of the present application provide a scalable multi-party privacy-preserving set intersection method, system, and related devices, which can improve the security of multi-party intersection operations.

[0004] In a first aspect, embodiments of the present application provide a scalable multi-party privacy-preserving set intersection method, applied to a multi-party computing system; the multi-party computing system includes an initiator and n participants, where n is an integer greater than 1; each party in the multi-party computing system corresponds to a local data set, the method comprising:

[0005] The initiator selects a first initial matrix and modifies the first initial matrix using its local data set to obtain a reference first initial matrix;

[0006] By each of the first n-1 participants among the n participants selecting a second initial matrix and modifying the corresponding second initial matrix using their respective local data sets, a reference second initial matrix for each of the first n-1 participants is obtained;

[0007] Obtaining a random matrix through the initiator, and determining an initial OT operation result through the random matrix and the reference first initial matrix;

[0008] Determining, by the first n-1 participants, an OT operation result of the n-1th participant based on the initial OT operation result and a reference second initial matrix of each participant in the first n-1 participants;

[0009] The nth participant determines initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant;

[0010] The initiator determines target intersection judgment information according to the local data set of the initiator and the initial intersection judgment information.

[0011] In a second aspect, an embodiment of the present application provides a multi-party computing system, the multi-party computing system including an initiator and n participants, where n is an integer greater than 1; each party in the multi-party computing system corresponds to a local data set, wherein:

[0012] The initiator is configured to select a first initial matrix and modify the first initial matrix using its local data set to obtain a reference first initial matrix;

[0013] Each of the first n-1 of the n parties is configured to select a second initial matrix and modify the corresponding second initial matrix using its own local data set to obtain a reference second initial matrix for each of the first n-1 parties;

[0014] The initiator is further configured to obtain a random matrix and determine an initial OT operation result using the random matrix and the reference first initial matrix;

[0015] The first n-1 participants are configured to determine an OT operation result of the n-1th participant based on the initial OT operation result and a reference second initial matrix of each participant in the first n-1 participants;

[0016] The nth participant is configured to determine initial intersection determination information based on the OT operation result of the n-1th participant and the local data set of the nth participant;

[0017] The initiator is further configured to determine target intersection judgment information according to the local data set of the initiator and the initial intersection judgment information.

[0018] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor, a memory, a communication interface, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, and the program comprises instructions for executing the steps in the first aspect of the embodiment of the present application.

[0019] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the above-mentioned computer-readable storage medium stores a computer program for electronic data exchange, wherein the above-mentioned computer program enables a computer to execute some or all of the steps described in the first aspect of the embodiment of the present application.

[0020] In a fifth aspect, embodiments of the present application provide a computer program product, wherein the computer program product includes a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a computer to perform some or all of the steps described in the first aspect of the embodiments of the present application. The computer program product may be a software installation package.

[0021] The implementation of the embodiments of this application has the following beneficial effects:

[0022] It can be seen that the scalable multi-party privacy protection set intersection method, system and related equipment described in the embodiments of the present application are applied to a multi-party computing system; the multi-party computing system includes an initiator and n participants, n is an integer greater than 1; each party in the multi-party computing system corresponds to a local data set, the initiator selects a first initial matrix and uses its local data set to modify the first initial matrix to obtain a reference first initial matrix, each of the first n-1 participants among the n participants selects a second initial matrix and uses their respective local data sets to modify the corresponding second initial matrix to obtain a reference second initial matrix for each of the first n-1 participants, the initiator obtains a random matrix, and the initial OT operation is determined by the random matrix and the reference first initial matrix. As a result, the first n-1 participants determine the OT operation result of the n-1th participant based on the initial OT operation result and the reference second initial matrix of each participant in the first n-1 participants, the nth participant determines the initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant, and the initiator determines the target intersection judgment information based on the initiator's local data set and the initial intersection judgment information. The n-party intersection process can be modularized, and the two adjacent parties simulate the two-party intersection process, and only the PSI intersection is calculated in the last step. This ensures that information outside the intersection is not leaked and the intersection task can be completed. In addition, by expanding the three-party intersection, the privacy intersection function of any multiple parties is realized, thereby improving the security of the multi-party intersection operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0024] Figure 1 This is a schematic diagram of the structure of a multi-party computing system for implementing a scalable multi-party privacy-preserving set intersection method provided in an embodiment of the present application;

[0025] Figure 2 This is a flowchart of a scalable multi-party privacy-preserving set intersection method provided in an embodiment of the present application;

[0026] Figure 3 This is a flowchart of another scalable multi-party privacy-preserving set intersection method provided in an embodiment of the present application;

[0027] Figure 4 This is a flowchart of another scalable multi-party privacy-preserving set intersection method provided in an embodiment of the present application;

[0028] Figure 5 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0029] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0030] The terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish between different objects, not to describe a particular order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.

[0031] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0032] The computing node (any party in the multi-party computing system) described in the embodiment of the present application can be an electronic device, and the electronic device can include a smart phone (such as an Android phone, an iOS phone, a Windows Phone phone, etc.), a tablet computer, a PDA, a driving recorder, a server, a laptop computer, a mobile Internet device (MID, Mobile Internet Devices) or a wearable device (such as a smart watch, a Bluetooth headset), etc. The above is only an example, not an exhaustive list, including but not limited to the above electronic devices, which can also be a cloud server, or the electronic device can also be a computer cluster. In the embodiment of the present application, the initiator and the participant can both be the above electronic devices.

[0033] The following is a detailed introduction to the embodiments of the present application.

[0034] See also Figure 1 , Figure 1 This is a schematic diagram of the architecture of a multi-party computing system for implementing a scalable multi-party privacy-preserving set intersection method, provided in an embodiment of the present application. As shown in the figure, the method is applied to a multi-party computing system; the multi-party computing system includes an initiator and n participants, where n is an integer greater than 1; each party in the multi-party computing system corresponds to a local data set. Based on the multi-party computing system, the following functions can be implemented:

[0035] The initiator selects a first initial matrix and modifies the first initial matrix using its local data set to obtain a reference first initial matrix;

[0036] By each of the first n-1 participants among the n participants selecting a second initial matrix and modifying the corresponding second initial matrix using their respective local data sets, a reference second initial matrix for each of the first n-1 participants is obtained;

[0037] Obtaining a random matrix through the initiator, and determining an initial OT operation result through the random matrix and the reference first initial matrix;

[0038] Determining, by the first n-1 participants, an OT operation result of the n-1th participant based on the initial OT operation result and a reference second initial matrix of each participant in the first n-1 participants;

[0039] The nth participant determines initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant;

[0040] The initiator determines target intersection judgment information according to the local data set of the initiator and the initial intersection judgment information.

[0041] Optionally, the step of selecting a first initial matrix by the initiator and modifying the first initial matrix using its local data set to obtain a reference first initial matrix includes:

[0042] Obtaining the first initial matrix and pseudo-random function key through the initiator;

[0043] determining the column information of the initiator according to the pseudo-random function key and the local data set of the initiator;

[0044] The first initial matrix is ​​modified according to the column information to obtain the reference first initial matrix.

[0045] Optionally, the following functions can also be implemented based on the multi-party computing system:

[0046] The pseudo-random function key is sent to any one of the n participants through the initiator.

[0047] Optionally, the determining, by the initiator, of the target intersection judgment information according to the initiator's local data set and the initial intersection judgment information includes:

[0048] The target intersection judgment information is determined according to the column information of the initiator and the initial intersection judgment information.

[0049] Optionally, the step of selecting a second initial matrix by each of the first n-1 participants among the n participants and modifying the corresponding second initial matrix using the respective local data sets includes:

[0050] A corresponding second initial matrix is ​​selected by the i-th participant; the i-th participant is any participant among the first n-1 participants;

[0051] Determining column information of the i-th participant according to the pseudo-random function key and the local data set of the i-th participant;

[0052] The second initial matrix of the i-th participant is modified according to the column information of the i-th participant to obtain a reference second initial matrix of the i-th participant.

[0053] Optionally, when n is 2, determining the OT operation result of the n-1th participant by the first n-1 participants based on the initial OT operation result and a reference second initial matrix of each participant among the first n-1 participants includes:

[0054] Determining, by the first participant, an OT operation result of the first participant based on the initial OT operation result and a reference second initial matrix of the first participant;

[0055] In the aspect of determining the initial intersection judgment information by the nth participant based on the OT operation result of the n-1th participant and the local data set of the nth participant, the method includes:

[0056] The initial intersection judgment information is determined by the second participant according to the OT operation result of the first participant and the local data set of the second participant.

[0057] Optionally, in determining the initial OT operation result by using the random matrix and the reference first initial matrix, the method includes:

[0058] The initiator performs an XOR operation on the random matrix and the reference first initial matrix to obtain the initial OT operation result.

[0059] See also Figure 2 , Figure 2 This is a flow chart of a scalable multi-party privacy protection set intersection method provided by the embodiment of the present application, which is applied to Figure 1 The multi-party computing system shown in FIG. 1 includes an initiator and n participants, where n is an integer greater than 1. Each party in the multi-party computing system corresponds to a local data set. As shown in the figure, the scalable multi-party privacy-preserving set intersection method includes:

[0060] 201. The initiator selects a first initial matrix and modifies the first initial matrix using its local data set to obtain a reference first initial matrix.

[0061] In the embodiment of the present application, the multi-party computing system may include an initiator and n participants, where n is an integer greater than 1, that is, at least 3 parties participate in the operation. Each party in the multi-party computing system corresponds to a local data set.

[0062] In an embodiment of the present application, the initiator may have a local data set, which may include N data groups, each data group may include P data, each data may correspond to a tag information, and each data may be understood as an information field, which is used to express the content of the tag information. The tag information may include at least one of the following: ID number, identity card number (ID-CARD), telephone number (Phone Number), bank card number (Bank Card), social security account number, social account number, student number, work number, etc., which are not limited here.

[0063] In a specific implementation, for example, a local data set is provided as shown in Table 1 below:

[0064] Table 1

[0065] ID-CARD Phone Number Bank Card 1234 66666 AAAA 1789 88888 BBBB 1258 99999 CCCC

[0066] ID-CARD, Phone Number, and Bank Card all represent tag information. The local data set can include three data groups: {1234, 66666, AAAA} represents a data group, 1234 represents a single piece of data, and ID-CARD is the tag information for 1234. In practical applications, only any column of data in Table 1 can be used for calculations.

[0067] In the implementation of this application, the initiator can select the first initial matrix D∈{1} m×w , then the first initial matrix can also be expressed as D={D1||...||D w}, where m represents the number of rows and w represents the number of columns. The sizes of m and w can be determined based on the amount of data in the local data sets of the initiator and each of the n participants. The first initial matrix can be an all-one matrix, that is, each element of the first initial matrix is ​​1. Furthermore, the corresponding column information can be determined using the local data set, and the first initial matrix can be modified based on the column information to obtain a reference first initial matrix. In practical applications, the modification of the first initial matrix can be performed by changing the elements of some positions in the first initial matrix from 1 to 0.

[0068] Furthermore, it is assumed that the initiator corresponds to the local data set Y and the pseudo-random function key K∈{0,1} λ ,λ represents the security parameter. For example,λ can take the value of 40, then the column information of the local data set y∈Y,v=F can be calculated K (H1(y)), modify the initial matrix D i [v[i]]=0,i∈[w], v represents the calculation result of the pseudo-random function, which is a long vector, H represents the hash function, y represents the input data, and i represents the i-th position of the v vector.

[0069] Optionally, the following steps may also be included:

[0070] The pseudo-random function key is sent to any one of the n participants through the initiator.

[0071] In a specific implementation, the initiator sends the pseudo-random function key to any of the n participants, and then each participant who receives the pseudo-random function key sends the pseudo-random function key to the next participant. Alternatively, the initiator can also send the pseudo-random function key to each of the n participants. For example, K∈{0,1} λSent to any participant except the initiator.

[0072] Optionally, the above step 201, wherein the initiator selects a first initial matrix and modifies the first initial matrix using its local data set to obtain a reference first initial matrix, may include the following steps:

[0073] 11. Obtain the first initial matrix and pseudo-random function key through the initiator;

[0074] 12. Determine the column information of the initiator according to the pseudo-random function key and the local data set of the initiator;

[0075] 13. Modify the first initial matrix according to the column information to obtain the reference first initial matrix.

[0076] In embodiments of the present application, the pseudo-random function key can be a key calculated by multiple parties using the same pseudo-random function (e.g., AES). This key ensures that the same input produces the same output, and that the output appears random to anyone without the key. For example, when using the AES algorithm, the pseudo-random function key can be understood as the AES key, which can be a private key.

[0077] In an embodiment of the present application, the initiator can obtain the first initial matrix and the pseudo-random function key K, and then determine the column information of the initiator based on the pseudo-random function key and the local data set of the initiator, wherein the local data set can be regarded as a matrix, that is, the matrix can be encrypted by the pseudo-random function key, thereby obtaining the column information of the initiator, and then modifying the first initial matrix based on the column information to obtain a reference first initial matrix.

[0078] 202. Each of the first n-1 participants among the n participants selects a second initial matrix and uses their respective local data sets to modify the corresponding second initial matrix to obtain a reference second initial matrix for each of the first n-1 participants.

[0079] In an embodiment of the present application, the second initial matrix can be selected by each of the first n-1 participants among the n participants, that is, except for the n parties, each party can select the initial matrix and modify it, and then use the modified result as the input of OT.

[0080] Specifically, the corresponding column information can be determined using their respective local data sets and pseudo-random key functions, and then the corresponding second initial matrix can be modified based on the column information to obtain a reference second initial matrix for each of the first n-1 participants. The principle is similar to that of step 201, that is, the specific principle can refer to step 201 and will not be repeated here.

[0081] Optionally, the above step 202, wherein each of the first n-1 participants among the n participants selects a second initial matrix and modifies the corresponding second initial matrix using their respective local data sets, may include the following steps:

[0082] 21. Selecting a corresponding second initial matrix through the i-th participant; the i-th participant is any participant among the first n-1 participants;

[0083] 22. Determine the column information of the i-th participant based on the pseudo-random function key and the local data set of the i-th participant;

[0084] 23. Modify the second initial matrix of the i-th participant according to the column information of the i-th participant to obtain a reference second initial matrix of the i-th participant.

[0085] In the embodiment of the present application, taking the i-th participant as an example, the i-th participant is any participant among the first n-1 participants. Specifically, the i-th participant can select a corresponding second initial matrix, and then determine the column information of the i-th participant based on the pseudo-random function key and the i-th participant's local data set, wherein the local data set can be regarded as a matrix, that is, the matrix can be encrypted using the pseudo-random function key, thereby obtaining the column information of the i-th participant, and then modifying the second initial matrix based on the column information to obtain a reference second initial matrix.

[0086] 203. Obtain a random matrix through the initiator, and determine an initial OT operation result using the random matrix and the reference first initial matrix.

[0087] In a specific implementation, a random matrix can be understood as a random selection of elements at each position. A random matrix can be generated in a variety of ways. For example, the blake2 algorithm can be used to simulate and obtain a random matrix.

[0088] In an embodiment of the present application, a random matrix can be obtained by the initiator, and an XOR operation can be performed on the random matrix and the reference first initial matrix to obtain an intermediate matrix. The random matrix and the intermediate matrix can be used to determine the initial OT operation result, or the two can be XORed to obtain the initial OT operation result.

[0089] Optionally, the above step 203, determining the initial OT operation result by using the random matrix and the reference first initial matrix, can be implemented as follows:

[0090] The initiator performs an XOR operation on the random matrix and the reference first initial matrix to obtain the initial OT operation result.

[0091] In a specific implementation, the initiator may perform an XOR operation on the random matrix and the reference first initial matrix to obtain an initial OT operation result.

[0092] Specifically, assuming D is the first initial matrix, B is the intermediate matrix, and A is the random matrix, then B=A⊕D,{A i ,B i} i∈[w] , ⊕ represents the exclusive OR operation.

[0093] 204. Determine the OT operation result of the n-1th participant according to the initial OT operation result and the reference second initial matrix of each participant in the first n-1 participants through the first n-1 participants.

[0094] In an embodiment of the present application, the initiator and each participant can run a special two-party oblivious pseudo-random function (OPRF)-private set intersection (PSI) function, referred to as the OPRF-PSI function, and each party can run OT, that is, the oblivious transfer (OT) protocol.

[0095] In the embodiment of the present application, the intersection function is realized by using a multi-point OPRF function, which has strong security and excellent performance, and helps to improve user experience.

[0096] In the embodiment of the present application, in a specific implementation, the OT operation result can be used as part of the input, thereby realizing the transmission of information and ensuring the correctness of the intersection result.

[0097] 205. The nth participant determines initial intersection judgment information according to the OT operation result of the n-1th participant and the local data set of the nth participant.

[0098] In an embodiment of the present application, except for the initiator, the OT input of each party must depend on the OT result of the previous party, and the final intersection judgment information is sent by the nth participant to the initiator based on the initial intersection judgment information calculated by it based on the OT operation result of the previous party and its local data set, and the initiator relies on the initial intersection judgment information to complete the intersection calculation.

[0099] Optionally, when n is 2, step 204, in which the first n-1 participants determine the OT operation result of the n-1th participant based on the initial OT operation result and the reference second initial matrix of each participant in the first n-1 participants, can be implemented as follows:

[0100] Determining, by the first participant, an OT operation result of the first participant based on the initial OT operation result and a reference second initial matrix of the first participant;

[0101] Then, the above step 205, in which the nth participant determines the initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant, can be implemented as follows:

[0102] The initial intersection judgment information is determined by the second participant according to the OT operation result of the first participant and the local data set of the second participant.

[0103] In an embodiment of the present application, when n is 2, the n participants may include the first participant and the second participant. Specifically, the first participant can determine the OT operation result of the first participant based on the initial OT operation result and the first participant's reference second initial matrix, and then the second participant can determine the initial intersection judgment information based on the OT operation result of the first participant and the local data set of the second participant.

[0104] In the embodiment of the present application, the three-party intersection process can be modularized, and two adjacent parties can simulate the two-party intersection process, and the PSI intersection is only calculated in the last step. This ensures that information outside the intersection is not leaked and the intersection task can be completed. In addition, by expanding the three-party intersection, the privacy intersection function of any multiple parties is realized.

[0105] 206. The initiator determines target intersection judgment information according to the local data set of the initiator and the initial intersection judgment information.

[0106] In an embodiment of the present application, the nth participant can send the initial intersection judgment information to the initiator, the initiator receives the initial intersection judgment information, and then determines the target intersection judgment information based on the initiator's local data set and the initial intersection judgment information.

[0107] In practical applications, private intersection primarily refers to obtaining the intersection of local data from multiple parties without leaking any data outside the intersection. Currently, the main use cases for private intersection include two-party intersection, three-party intersection, and multi-party intersection. Multi-party intersection can usually be achieved through the extension of three-party intersection. The embodiments of this application primarily consider three-party intersection and multi-party intersection.

[0108] In the specific implementation, in the embodiment of the present application, a matrix structure of multi-point OPRF is used to realize three-party privacy intersection, and based on this, the expansion from three parties to multiple parties is realized.

[0109] Optionally, the above step 206, in which the initiator determines the target intersection judgment information according to the initiator's local data set and the initial intersection judgment information, can be implemented as follows:

[0110] The target intersection judgment information is determined according to the column information of the initiator and the initial intersection judgment information.

[0111] In the specific implementation, the initiator can determine the target intersection judgment information based on the initiator's column information and the initial intersection judgment information, that is, the values ​​of certain positions can be taken from the random matrix A through the column information vector (v). These positions are specified by the column information vector (v), and then these values ​​are used as the input of the hash function H2. The calculation result is the judgment set, and the judgment set is intersected with the initial intersection judgment information. The intersection result is the intersection result of the local original set.

[0112] For example, Figure 3 As shown, in the embodiment of the present application, the parties participating in the operation in the multi-party computing system may include party id 0, party id 1, and party id 2, and the input data sets are Y, X, and Z respectively. The specific steps are as follows:

[0113] 1. ID 0: Select the initial matrix, obtain the pseudo-random key function and calculate the column information of the local data set, and modify the initial matrix. Specifically: select the initial matrix D∈{1} m×w ,D={D1||...||D w}, pseudo-random function key K∈{0,1} λ , calculate the column information of the local data set y∈Y,v=F K (H1(y)), modify the initial matrix D i [v[i]]=0,i∈[w];set K∈{0,1} λ Send to party id 1, party id 1 will K∈{0,1} λ Send to party id 2; party id 1 selects S1←{0,1} w ;

[0114] 2. Party id 0 acts as the OT sender and runs OT, specifically: select A←{0,1} m×w ,make Party 1 is the OT receiver. In the specific implementation, in the OT protocol, the OT sender has two inputs A and B, and the OT receiver's input is S. The function of the OT protocol is that the OT receiver obtains certain data of the OT sender based on each bit of S. For example, when S is 0, A is obtained, and when S is 1, B is obtained.

[0115] 3. Party id1, as the OT receiver, obtains C, i.e., runs the OT protocol and obtains Cm×w Among them, C m×w It is the result obtained by the OT receiver in step 2;

[0116] 4. id1 side: Select the initial matrix and calculate the column information of the local data set, and modify the initial matrix to obtain E. Specifically: select the initial matrix E∈{1} m×w ,E={E1||...||E w}, calculate the column information of the local data set x∈X,v1=F K (H1(x)), let E i [v1[i]]=0,i∈[w];

[0117] 5. Party id1 acts as the OT sender and runs OT. Specifically: C∈{0,1} m×w , that is, through C and E, we can get F. Specifically, we can let F=C⊕E,{C i ,F i} i∈[w] ; F is used as the input of the OT sender in step 6. Specifically, the input of the OT sender is C and F;

[0118] 6. ID2 acts as the OT receiver, runs OT, and obtains G m×w ; G m×w The results obtained for the OT recipient;

[0119] 7. id2 side: Calculate local column information and calculate psi judgment set, specifically: calculate the column information z∈Z,v2=F of the local data set K (H1(z)), calculate psi judgment set information ψ=H2(G1[v2[1]]||...||G w [v2[w]]),ψ={ψ} z∈Z ;

[0120] 8. id0 side: Calculate local column information and calculate psi judgment set, specifically: calculate the column information y∈Y,v=F of the local data set K (H1(y)), calculate psi judgment set information if Output y, at this time, y∈X∩Y∩Z.

[0121] In specific implementation, the following steps can be implemented:

[0122] 1. ID 0 selects the initial matrix D∈{1} m×w and the pseudo-random function key K, then calculates the column information v based on the local set, and modifies the initial matrix D based on the column information. id 1 selects the OT key S1;

[0123] 2. Party id 0 acts as OT Sender and runs OT protocol with party id 1. The input is matrix {A, B}, where matrix A is a random matrix and matrix

[0124] 3. Party 1, acting as the OT Receiver, runs the OT protocol with party 0 to obtain the matrix C.

[0125] 4. id 1 party selects the initial matrix E∈{1} m×w , then calculate the column information v1 based on the local set, and modify the initial matrix E according to the column information;

[0126] 5. Party 1 acts as OT Sender and runs OT protocol with party 2. The input is matrix {C, F}.

[0127] 6. Party 2, acting as the OT Receiver, runs the OT protocol with party 1 to obtain the matrix G.

[0128] 7. Party id 2 calculates the local column information v2, then calculates the psi judgment set ψ and sends it to party id 0;

[0129] 8. Calculate local column information for id 0, and then calculate the PSI judgment set according to Enter the intersection.

[0130] Step 5 uses the OT result from step 3 as part of the input, enabling information transfer and ensuring the correctness of the intersection result. Step 7 calculates the PSI judgment set and sends it to party ID 0, ensuring that only party ID 0 can obtain the intersection result, and other participants cannot infer the intersection information from the intermediate results. Step 8 modularizes the three-party intersection processing, providing the possibility of subsequent expansion.

[0131] In the embodiments of this application, the OT key is essential for completing the OT protocol. The OT protocol consists of two parties: the sender and the receiver. The sender: has the data and will send the data according to the key selected by the receiver; the receiver: selects the key and then receives the data from the sender.

[0132] In an embodiment of the present application, the values ​​of certain positions are taken from the random matrix A through the column information vector (v). These positions are specified by the column information vector (v) and these values ​​are used as inputs of the hash function H2. The calculation result is a judgment set. The judgment set is intersected with the set sent in step 7, and the intersection result is the intersection result of the local original set.

[0133] Further, such as Figure 4 As shown, Figure 4The application scenario is an n-party extended application scenario. Based on the solution in the embodiment of this application, it can be easily extended to an n-party protocol. By observing the protocol flow, it can be concluded that, except for party n, each party must select an initial matrix and modify it, and then use the modified result as the OT input. Except for party 0, the OT input of each party depends on the OT result of the previous party. The final intersection judgment information is sent from party 0 to party 0, and party 0 completes the intersection calculation.

[0134] In specific implementation, such as Figure 4 As shown, the parties involved in the multi-party computing system may include party id 0, party id 1, ..., party id n-1, and party id n, and the corresponding input data sets are X0, X1, ..., X n-1 and X n , you can implement the following steps:

[0135] S0, id 0, select the initial matrix D0, and modify the initial matrix according to the local column information, run OT, input A,

[0136] S1, id 1, as the OT receiver, obtains the OT result C1; selects the initial matrix D1 and modifies the initial matrix according to the local column information; runs OT with input C1.

[0137] Sn-1, id n-1 party runs OT and obtains OT result C n-1 , select the initial matrix D n-1 , and modify the initial matrix according to the local column information; run OT, the input is C n-1 ,

[0138] Sn, id n party runs OT and obtains OT result C n , calculate the local column information, calculate the psi judgment set ψ, Ψ = {ψ}, and then send Ψ to the id 0 party;

[0139] Sn+1, id 0 calculates local column information and calculates psi judgment set if Output y, at this time, y∈X0∩...∩X n-1 ∩X n .

[0140] For example, if n institutions (1 initiator and n-1 participants) want to use the user information they have for joint modeling, the first step is to count the common user information of the n institutions, because it is meaningful to use the characteristics of these users for modeling training. However, it is necessary to protect the user information outside the intersection of each institution. This is for the sake of their own data security and to protect their own interests. At this time, the first step of joint modeling is to use multi-party privacy intersection technology to find the intersection. Among them, the institutions can include at least one of the following: banks, suppliers, operators, dealers, etc., which are not limited here.

[0141] It can be seen that the scalable multi-party privacy protection set intersection method described in the embodiment of the present application is applied to a multi-party computing system; the multi-party computing system includes an initiator and n participants, n is an integer greater than 1; each party in the multi-party computing system corresponds to a local data set, the initiator selects a first initial matrix and uses its local data set to modify the first initial matrix to obtain a reference first initial matrix, each of the first n-1 participants among the n participants selects a second initial matrix and uses their respective local data sets to modify the corresponding second initial matrix to obtain a reference second initial matrix for each of the first n-1 participants, the initiator obtains a random matrix, and determines the initial OT operation result by using the random matrix and the reference first initial matrix, The first n-1 participants determine the OT operation result of the n-1th participant based on the initial OT operation result and the reference second initial matrix of each participant in the first n-1 participants, the nth participant determines the initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant, and the initiator determines the target intersection judgment information based on the initiator's local data set and the initial intersection judgment information. The n-party intersection process can be modularized, and the two adjacent parties simulate the two-party intersection process, and only calculate the PSI intersection in the last step. This ensures that information outside the intersection is not leaked and the intersection task can be completed. In addition, by expanding the three-party intersection, the privacy intersection function of any multiple parties is realized, thereby improving the security of the multi-party intersection operation.

[0142] In accordance with the above embodiment, please refer to Figure 5 , Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. As shown in the figure, the electronic device includes a processor, a memory, a communication interface, and one or more programs, and is applied to a multi-party computing system; the multi-party computing system includes an initiator and n participants, where n is an integer greater than 1; each party in the multi-party computing system corresponds to a local data set, and the one or more programs are stored in the memory and configured to be executed by the processor. In the embodiment of the present application, the program includes instructions for performing the following steps:

[0143] The initiator selects a first initial matrix and modifies the first initial matrix using its local data set to obtain a reference first initial matrix;

[0144] By each of the first n-1 participants among the n participants selecting a second initial matrix and modifying the corresponding second initial matrix using their respective local data sets, a reference second initial matrix for each of the first n-1 participants is obtained;

[0145] Obtaining a random matrix through the initiator, and determining an initial OT operation result through the random matrix and the reference first initial matrix;

[0146] Determining, by the first n-1 participants, an OT operation result of the n-1th participant based on the initial OT operation result and a reference second initial matrix of each participant in the first n-1 participants;

[0147] The nth participant determines initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant;

[0148] The initiator determines target intersection judgment information according to the local data set of the initiator and the initial intersection judgment information.

[0149] Optionally, in the aspect of selecting a first initial matrix by the initiator and modifying the first initial matrix using its local data set to obtain a reference first initial matrix, the program includes instructions for executing the following steps:

[0150] Obtaining the first initial matrix and pseudo-random function key through the initiator;

[0151] determining the column information of the initiator according to the pseudo-random function key and the local data set of the initiator;

[0152] The first initial matrix is ​​modified according to the column information to obtain the reference first initial matrix.

[0153] Optionally, the program further includes instructions for executing the following steps:

[0154] The pseudo-random function key is sent to any one of the n participants through the initiator.

[0155] Optionally, in the aspect of determining, by the initiator, the target intersection judgment information based on the initiator's local data set and the initial intersection judgment information, the program includes instructions for executing the following steps:

[0156] The target intersection judgment information is determined according to the column information of the initiator and the initial intersection judgment information.

[0157] Optionally, in the aspect of selecting a second initial matrix by each of the first n-1 participants among the n participants and modifying the corresponding second initial matrix using their respective local data sets, the program includes instructions for performing the following steps:

[0158] A corresponding second initial matrix is ​​selected by the i-th participant; the i-th participant is any participant among the first n-1 participants;

[0159] Determining column information of the i-th participant according to the pseudo-random function key and the local data set of the i-th participant;

[0160] The second initial matrix of the i-th participant is modified according to the column information of the i-th participant to obtain a reference second initial matrix of the i-th participant.

[0161] Optionally, when n is 2, in determining the OT operation result of the n-1th participant by the first n-1 participants based on the initial OT operation result and a reference second initial matrix of each participant in the first n-1 participants, the program includes instructions for performing the following steps:

[0162] Determining, by the first participant, an OT operation result of the first participant based on the initial OT operation result and a reference second initial matrix of the first participant;

[0163] In terms of determining the initial intersection determination information by the nth participant based on the OT operation result of the n-1th participant and the local data set of the nth participant, the program includes instructions for executing the following steps:

[0164] The initial intersection judgment information is determined by the second participant according to the OT operation result of the first participant and the local data set of the second participant.

[0165] Optionally, in determining the initial OT operation result by using the random matrix and the reference first initial matrix, the program includes instructions for executing the following steps:

[0166] The initiator performs an XOR operation on the random matrix and the reference first initial matrix to obtain the initial OT operation result.

[0167] It can be seen that the electronic device described in the embodiment of the present application is applied to a multi-party computing system; the multi-party computing system includes an initiator and n participants, where n is an integer greater than 1; each party in the multi-party computing system corresponds to a local data set, and the initiator selects a first initial matrix and uses its local data set to modify the first initial matrix to obtain a reference first initial matrix, and each of the first n-1 participants among the n participants selects a second initial matrix and uses their respective local data sets to modify the corresponding second initial matrix to obtain a reference second initial matrix for each of the first n-1 participants, obtains a random matrix through the initiator, and determines the initial OT operation result through the random matrix and the reference first initial matrix, and obtains the reference second initial matrix for each of the first n-1 participants through the first n-1 participants. The participants determine the OT operation result of the n-1th participant based on the initial OT operation result and the reference second initial matrix of each participant in the first n-1 participants. The nth participant determines the initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant. The initiator determines the target intersection judgment information based on the initiator's local data set and the initial intersection judgment information. The n-party intersection process can be modularized, and the two adjacent parties simulate the two-party intersection process, and only calculate the PSI intersection in the last step. This ensures that information outside the intersection is not leaked and the intersection task can be completed. In addition, by expanding the three-party intersection, the privacy intersection function of any multiple parties is realized, thereby improving the security of the multi-party intersection operation.

[0168] An embodiment of the present application also provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute part or all of the steps of any method described in the above method embodiments, and the above computer includes an electronic device.

[0169] The present application also provides a computer program product comprising a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a computer to perform some or all of the steps of any of the methods described in the above method embodiments. The computer program product may be a software installation package, and the computer may comprise an electronic device.

[0170] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.

[0171] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0172] In the several embodiments provided in this application, it should be understood that the disclosed devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical or other forms.

[0173] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0174] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0175] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the above-mentioned methods of each embodiment of the present application. The aforementioned memory includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0176] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program. The program can be stored in a computer-readable memory, and the memory can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0177] The above is a detailed introduction to the embodiments of the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of ​​the present application. At the same time, for those skilled in the art, according to the idea of ​​the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A scalable multi-party privacy-preserving set intersection method, characterized by: Applicable to a multi-party computing system; the multi-party computing system includes an initiator and n participants, where n is an integer greater than 1; Each party in the multi-party computing system corresponds to a local data set, and the method includes: The initiator selects a first initial matrix and modifies the first initial matrix using its local data set to obtain a reference first initial matrix; By each of the first n-1 participants among the n participants selecting a second initial matrix and modifying the corresponding second initial matrix using their respective local data sets, a reference second initial matrix for each of the first n-1 participants is obtained; Obtaining a random matrix through the initiator, and determining an initial OT operation result through the random matrix and the reference first initial matrix; Determining, by the first n-1 participants, an OT operation result of the n-1th participant based on the initial OT operation result and a reference second initial matrix of each participant in the first n-1 participants; The nth participant determines initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant; Determining, by the initiator, target intersection judgment information according to the initiator's local data set and the initial intersection judgment information; The initiator selecting a first initial matrix and modifying the first initial matrix using its local data set to obtain a reference first initial matrix includes: Obtaining the first initial matrix and pseudo-random function key through the initiator; determining the column information of the initiator according to the pseudo-random function key and the local data set of the initiator; Modify the first initial matrix according to the column information to obtain the reference first initial matrix; The method further comprises: Sending the pseudo-random function key to any one of the n participants through the initiator; The selecting of a second initial matrix by each of the first n-1 participants among the n participants and modifying the corresponding second initial matrix using their respective local data sets includes: A corresponding second initial matrix is ​​selected by the i-th participant; the i-th participant is any participant among the first n-1 participants; Determining column information of the i-th participant according to the pseudo-random function key and the local data set of the i-th participant; The second initial matrix of the i-th participant is modified according to the column information of the i-th participant to obtain a reference second initial matrix of the i-th participant.

2. The method according to claim 1, characterized in that The determining, by the initiator according to the local data set of the initiator and the initial intersection judgment information, of target intersection judgment information includes: The target intersection judgment information is determined according to the column information of the initiator and the initial intersection judgment information.

3. The method according to claim 1 or 2, characterized in that When n is 2, determining the OT operation result of the n-1th participant according to the initial OT operation result and a reference second initial matrix of each participant in the first n-1 participants by the first n-1 participants includes: Determining, by the first participant, an OT operation result of the first participant based on the initial OT operation result and a reference second initial matrix of the first participant; The determining, by the nth participant, of initial intersection judgment information based on the OT operation result of the n-1th participant and the local data set of the nth participant includes: The initial intersection judgment information is determined by the second participant according to the OT operation result of the first participant and the local data set of the second participant.

4. The method according to claim 1 or 2, characterized in that The determining of the initial OT operation result by using the random matrix and the reference first initial matrix includes: The initiator performs an XOR operation on the random matrix and the reference first initial matrix to obtain the initial OT operation result.

5. A multi-party computing system, characterized in that: The multi-party computing system includes an initiator and n participants, where n is an integer greater than 1; each party in the multi-party computing system corresponds to a local data set, wherein: The initiator is configured to select a first initial matrix and modify the first initial matrix using its local data set to obtain a reference first initial matrix; Each of the first n-1 of the n parties is configured to select a second initial matrix and modify the corresponding second initial matrix using its own local data set to obtain a reference second initial matrix for each of the first n-1 parties; The initiator is further configured to obtain a random matrix and determine an initial OT operation result using the random matrix and the reference first initial matrix; The first n-1 participants are configured to determine an OT operation result of the n-1th participant based on the initial OT operation result and a reference second initial matrix of each participant in the first n-1 participants; The nth participant is configured to determine initial intersection determination information based on the OT operation result of the n-1th participant and the local data set of the nth participant; The initiator is further configured to determine target intersection judgment information based on the local data set of the initiator and the initial intersection judgment information; The initiator selecting a first initial matrix and modifying the first initial matrix using its local data set to obtain a reference first initial matrix includes: Obtaining the first initial matrix and pseudo-random function key through the initiator; determining the column information of the initiator according to the pseudo-random function key and the local data set of the initiator; Modify the first initial matrix according to the column information to obtain the reference first initial matrix; The system is further specifically used for: Sending the pseudo-random function key to any one of the n participants through the initiator; The selecting of a second initial matrix by each of the first n-1 participants among the n participants and modifying the corresponding second initial matrix using their respective local data sets includes: A corresponding second initial matrix is ​​selected by the i-th participant; the i-th participant is any participant among the first n-1 participants; Determining column information of the i-th participant according to the pseudo-random function key and the local data set of the i-th participant; The second initial matrix of the i-th participant is modified according to the column information of the i-th participant to obtain a reference second initial matrix of the i-th participant.

6. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory is used to store one or more programs and is configured to be executed by the processor, wherein the programs include instructions for executing the steps of the method according to any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that A computer program for electronic data exchange is stored, wherein the computer program enables a computer to execute the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Multi-point multi-party data interaction method and system, electronic device and storage medium

    CN113312641A

  • Multi-party privacy set intersection method and device, equipment and storage medium

    CN115065459A