A Privacy-Preserving Pedestrian Re-Identification Method and System

By adopting dual-server architecture and batch-process secure homomorphic computing in the pedestrian re-identification method, the problems of privacy protection, calculation costs and encryption and decryption error rate are solved, and the pedestrian re-identification effect with strong privacy and low cost is achieved.

CN115941273BActive Publication Date: 2025-06-24GUANGZHOU INSTITUTE OF TECHNOLOY XIDIAN UNIVERSITY +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211386100.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-07
Publication Date
2025-06-24
Estimated Expiration
2042-11-07

AI Technical Summary

Technical Problem

The existing pedestrian re-identification methods cannot effectively protect pedestrian privacy, and the communication overhead and calculation cost are high when calculating high-dimensional features using encryption, and the floating-point number feature vector encryption and decryption error rate is high.

Method used

Using a non-cohesive dual-server architecture, pedestrian re-identification for privacy protection is achieved through batch-process secure homomorphic computing and high-precision data secure computing and coding methods.

Benefits of technology

It solves the problem of pedestrian privacy protection, reduces the cost of high-dimensional feature calculation and communication, and improves the accuracy and efficiency of floating-point feature encryption and decryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941273B_ABST
    Figure CN115941273B_ABST
Patent Text Reader

Abstract

The present invention provides a privacy - protected person re - identification method and system. The method involves an organizer, participants, a cloud platform CP, and a computing service provider CSP, and includes the following steps: Step S1. Initialization: The organizer publishes a person re - identification task and generates public and private keys; after splitting the private key sk into two parts, they are respectively sent to the cloud platform CP and the computing service provider CSP; the organizer obtains the target person image feature vector library G, encrypts it using the public key and stores it in the cloud platform CP; Step S2. Feature extraction: The participants capture person images and extract their feature vectors, encrypt them using the public key, and send them to the cloud platform CP for storage; Step S3. Calculate the similarity between the captured person feature vectors and the target person feature vectors; Step S4. Calculate and decrypt the person image feature similarity and sort; Step S5. Compare the feature vectors and feedback the results. This method has the advantages of strong privacy and low cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital image processing, and particularly relates to a pedestrian re-identification method and system for privacy protection. Background Art

[0002] Pedestrian re-identification technology can find target pedestrians with the same identity under the vision of different cameras. With the establishment of smart cities and safe cities, video surveillance has been widely popularized, and pedestrian re-identification technology has been widely applied in fields such as intelligent video surveillance, security, and criminal investigation. It is a hot research topic in the current field of computer vision.

[0003] In modern society where intelligent video processing is increasingly developed, cameras have spread all over the streets and alleys. For a large amount of video image data, how to intelligently analyze video images has become a very important topic. Great progress has been made in research fields such as pedestrian detection and target tracking. As a technology connecting these two topics, pedestrian re-identification technology has also attracted extensive attention in computer vision. Cloud computing technology provides great flexibility and convenience at a low cost. Organizations with limited computing and storage resources can outsource large computing and storage workloads to the cloud. An organization can outsource the pedestrian re-identification task to multiple surveillance cameras and cloud platforms to save deployment costs. At the same time, in order to execute the pedestrian re-identification task, surveillance cameras located in different regions capture pedestrian images and send them to the cloud platform. The cloud platform receives the pedestrian image library sent by the organization and checks whether the person images submitted by each camera match the target person appearing in the image library. In recent years, pedestrian re-identification has attracted great attention to personal image privacy. In the prior art, the pedestrian re-identification method has the following problems: (1) All person images and their feature vectors are exposed to the cloud platform, but the cloud platform is untrusted and cannot guarantee privacy. (2) The communication overhead and calculation cost of using encrypted calculation for high-dimensional features are high. (3) Floating-point feature vectors cannot be correctly encrypted and decrypted.

[0004] Therefore, aiming at the problems existing in the prior art, it is particularly important to provide a privacy protection pedestrian re-identification technology with strong privacy and low cost. Summary of the Invention

[0005] The technical problem to be solved by the present invention is based on the problems that the existing pedestrian re-identification method cannot protect pedestrian privacy, the communication overhead of using encrypted calculation for high-dimensional features, high calculation cost, and floating-point feature vectors cannot be correctly encrypted and decrypted.

[0006] Based on this, the present invention provides a privacy protection pedestrian re-identification method, which adopts a non-collusive dual-server architecture (i.e., cloud platform CP and computing service provider CSP), and neither party can obtain the plaintext image features to solve the problem of privacy protection.

[0007] Meanwhile, to address the issues of high computational costs and communication overheads for high-dimensional features, this method provides a secure homomorphic computing method that supports batch processing to solve this problem; to improve the high error rate of floating-point feature encryption and decryption, this method provides a high-precision data security computing encoding method to solve this problem.

[0008] To achieve the above objectives, the present invention adopts the following technical solutions:

[0009] A privacy-preserving person re-identification method, including an organizer, participants, a cloud platform CP, and a computing service provider CSP. The method includes the following steps:

[0010] Step S1. Initialization: The organizer publishes a person re-identification task and generates a public-private key pair (pk, sk), where pk represents the public key and sk represents the private key;

[0011] After splitting the private key sk into two parts (λ1, λ2), the first public-private key pair (pk, λ1) and the second public-private key pair (pk, λ2) are obtained; (pk, λ1) and (pk, λ2) are respectively sent to the cloud platform CP and the computing service provider CSP;

[0012] The organizer obtains the target person image feature vector library G, encrypts it using the public key and stores it in the cloud platform CP;

[0013] Step S2. Feature extraction: The participant uses a camera device to capture a person image, extracts the feature vector of the person image, encrypts it using the public key and then sends it to the cloud platform CP for storage;

[0014] Step S3. Calculate the similarity between the captured person feature vector and the target person feature vector: The cloud platform CP and the computing service provider CSP calculate the similarity of the person image features through a pre-written batch secure multiplication protocol BatchSMUL where and i ∈ [1, |G|], p = (p 1 , ···, p n ), n is the dimension of the feature vector, and G is the target person image feature vector library;

[0015] Step S4. Calculate and decrypt the similarity of the person image features and sort: The computing service provider CSP calculates where represents N(g i, the last term of k); the computing service provider CSP and the cloud platform CP cooperate to calculate the similarity of the person image features after floating-point encoding {Q(p·g1), ···, Q(p·g |G| )} through the pre-written batch partial decryption protocol BatchPDec, and sort them in descending order to obtain the index I of the top k values;

[0016] Step S5. Compare feature vectors and feedback results: The computing service provider CSP compares Q(p·g i ),

[0017] , where i ∈ I; the comparison method is as follows:

[0018] If then p ∈ N(g i , k), otherwise, the computing service provider CSP accumulates the number of p ∈ N(g i , k) and records it as count; if count ≥ εk, the CSP gets 1, otherwise it gets 0, and feedbacks this result to the organizer.

[0019] The above, in step S1, the person re-identification task is where represents the encrypted feature vector of the captured person image, ε is a control parameter and ε ∈ (0, 1]; k and ω are control parameters used to control and the similarity metric between, k is a random integer in the interval (0, |G|), ω is a random number in the interval ; N(p, k) is the KNN algorithm, representing the k vectors most similar to the vector p.

[0020] The above, in step S1, the key platform adopted is the Paillier cryptosystem; the cloud platform CP and the computing service provider CSP are a non-collusive dual-server architecture, the public key pk = (g, N), where N = pq, g = N + 1 and p, q are both strong prime numbers; the private key sk = (λ, μ), where λ = lcm(p - 1, q - 1), μ = λ -1 mod N, the partial private key λ1 is a random integer in (0, λμ), λ2 = λμ - λ1.

[0021] The above, in step S2, the encryption algorithm is Enc(p, pk) = (1 + pN)·r N mod N 2 , where r is a random positive integer less than N.

[0022] Above, in step S3, write a secure multiplication algorithm BatchSMUL that supports batch processing, including the following steps:

[0023] Step S3-1: The cloud platform CP has δ ciphertext pairs and performs additive blinding processing on each ciphertext pair using random numbers and the Paillier homomorphic calculation method and then combines the blinded ciphertexts X i , Y i into ciphertext c i to obtain a ciphertext group {c1, ···, c δ}, perform a product operation on the ciphertext group to aggregate it into ciphertext C, and use the partial private key λ1 to partially decrypt the ciphertext to obtain C1, obtaining the ciphertext pair <C, C1>; then send the ciphertext pair <C, C1> to the computing service provider CSP, and the calculation process is as follows:

[0024]

[0025] C1 = PDec(λ1, C), where r i,1 , r i,2 are random numbers, and r i,1、 r i,2 ∈ {0, 1} σ , σ is a security parameter; L is a constant and satisfies L ≥ 2 σ+2 ; x i , y i ∈ [0, 2 l ), i is a positive integer and i ∈ [1, δ], l is a security parameter;

[0026] Step S3-2: The computing service provider CSP uses the partial λ2 to partially decrypt the ciphertext C to obtain C2, and uses the threshold decryption algorithm to decrypt the ciphertext pair <C1, C2> to obtain the plaintext corresponding to each ciphertext pair in step S3-1 (x i + r i,1 )·(y i + r i,2 ), and sends the encrypted in batches to the cloud platform CP; its calculation process includes: calculating PDec(λ2, C) to partially decrypt C to obtain ciphertext C2, calculating TDec(C1, C2) to obtain the plaintext Μ = L 2δ-1 ·(x δ + r δ,1 ) + L 2δ-2 ·(y δ + r δ,2 ) + ··· + L·(x1 + r 1,1 ) + y1 + r 1,2 、calculating the plaintext where \(i\in[1,\delta]\);

[0027] The threshold decryption algorithm used in the calculation process is \(TDec(M1,M2) = L(M1\cdot M2\bmod N 2 )

[0028] Subsequently, the computing service provider CSP will calculate \(x i +r i,1 and \(y i +r i,2 encrypt them and send them to the cloud platform CP;

[0029] Step 3-3: For each ciphertext received by the cloud platform CP obtain it through Paillier homomorphic calculation The calculation process is as follows:

[0030] Specifically, additive blinding processing means adding a random number blinding factor to the ciphertext. In step S3-1, a random number \(r1\) is added to \(x\), and a random number \(r2\) is added to \(y\).

[0031] As mentioned above, in step S3, a secure multiplication protocol is written including the following steps:

[0032] Step S3-1': The cloud platform CP uses a random number and the Paillier homomorphic calculation method to perform additive blinding processing on the ciphertext and merge the blinded ciphertexts \(X\) and \(Y\) into ciphertext \(C\), and use the partial private key \(\lambda1\) to perform partial decryption on the ciphertext to obtain \(C1\), and then send the ciphertext pair \(\lt C,C1\gt\) to the computing service provider CSP, that is: calculate and where \(r1,r2\) are random numbers \(r1,r2\leftarrow\{0,1\} σ \), \(\sigma\) is a security parameter; subsequently, the cloud platform CP calculates \(C\leftarrow X L \cdot Y\), \(C1\leftarrow PDec(\lambda1,C)\), where \(L\) is a constant and satisfies \(L\geq2 σ+2 \); the cloud platform CP sends \(\lt C,C1\gt\) to the computing service provider CSP;

[0033] Step S3-2': The computing service provider CSP uses the partial key \(\lambda2\) to perform partial decryption on the ciphertext \(C\) to obtain \(C2\), uses the threshold decryption algorithm to decrypt the ciphertext pair \(\lt C1,C2\gt\) to obtain the plaintext \((x + r1)\cdot(y + r2)\), and after encryption, the obtained Send to the cloud platform CP, and the calculation process includes: obtaining C2 ← PDec(λ2, C) through partial decryption, obtaining L·(x + r1) + y + r2 ← TDec(C1, C2) using the threshold decryption algorithm, and calculating y + r2 = (L·(x + r1) + y + r2) mod L, and encrypting (x + r1)·(y + r2) with the public key and sending it to the CP cloud platform;

[0034] Step S3-3': The cloud platform CP obtains through Paillier homomorphic calculation The calculation process is: calculate and

[0035] The above-mentioned, in step S4, write a partial decryption algorithm BatchPDec that supports batch processing, including the following steps:

[0036] Step S4-1: The cloud platform CP aggregates the ciphertext into ciphertext D through product operation, and uses the partial private key λ1 to partially decrypt the ciphertext to obtain D1, and then sends the ciphertext pair <D, D1> to the computing service provider CSP. The calculation process is: by calculating the ciphertext where L′ ≥ 2 2l+2 ; then calculate PDec(λ1, D) to obtain the ciphertext D1, and send <D, D1> to the computing service provider CSP;

[0037] Step S4-2: The computing service provider CSP calculates PDec(λ2, D) to obtain the ciphertext D2 ← PDec(λ2, D), and then calculates TDec(D1, D2) to obtain the plaintext d ← TDec(D1, D2), so as to calculate through Q(p·g1) ← d mod L′, to obtain {Q(p·g1), ···, Q(p·g n )}, where

[0038] The above-mentioned, in step S5 where l is a constant, x ↑ , x ↓ is an integer, and Q(x) converts the floating-point number x into an integer.

[0039] The above-mentioned, the imaging device can be a surveillance video.

[0040] The present invention also provides a privacy-preserving pedestrian re-identification system applying the foregoing privacy-preserving pedestrian re-identification method. The system includes a cloud platform, a computing service provider module, a participant module, and an organizer module; wherein,

[0041] The organizer module is configured to initiate a person re-identification task, generate public and private key information, and split the private key into two parts to generate first public and private key information and second public and private key information; the organizer module sends the first public and private key information and the obtained target person image feature vector library to the cloud platform, and sends the second public and private key information to the computing service provider module;

[0042] The cloud platform sends a recruitment instruction to the participant module to form a connection; the participant module is configured to use a camera device to capture a person image, extract features from the image, and send the encrypted image using the public key to the cloud platform;

[0043] The cloud platform is configured to jointly calculate the batch secure multiplication protocol BatchSMUL with the computing service provider module, and cooperate with the computing service provider module to calculate the batch partial decryption protocol BatchPDec;

[0044] The computing service provider module is configured to calculate the similarity of the encrypted feature vector library of the target person image, compare the feature vectors, and feedback the result to the organizer module.

[0045] The present invention also provides a storage device, in which multiple instructions are stored, and the instructions are suitable for being loaded and executed by a processor to perform the step operations of the person re-identification method as described above.

[0046] The present invention further provides an intelligent terminal, including a processor for executing each instruction and a storage device for storing multiple instructions, and the instructions are suitable for being loaded and executed by the processor to perform the step operations of the person re-identification method as described above.

[0047] Compared with the prior art, the present invention has the following beneficial effects:

[0048] The privacy - protected pedestrian re - identification method and system provided by the present invention can solve the problem of pedestrian privacy protection. By designing a privacy - protected pedestrian Re - ID framework with a two - server architecture, it will not disclose anyone's privacy to the cloud platform, but allows the cloud platform to perform state - of - the - art pedestrian re - identification operations on encrypted data and output the final pedestrian re - identification result as plaintext. Moreover, it can also solve the communication and computational cost problems caused by high - dimensional feature vectors. By designing a batch - processing secure multiplication protocol (BatchSMUL) and a batch - processing partial decryption protocol (BatchPDec), it realizes the batch processing of encrypted feature vectors to perform state - of - the - art pedestrian re - identification operations. Compared with the existing secure multiplication protocol (SM), BatchSMUL reduces at least half of the computational and communication costs. In addition, it can also solve the problem of the encryption - decryption error rate of floating - point features. By providing a new encoding mechanism (ECMO) to effectively process the encryption of floating - point numbers, ECMO reduces the decoding error rate to 0, reduces the computational error rate to 22%, and significantly reduces the encryption cost. It has the advantages of strong privacy and low cost. Brief Description of the Drawings

[0049] Figure 1 It is a framework diagram of the pedestrian re - identification method provided by the present invention;

[0050] Figure 2 It is a flowchart of the pedestrian re - identification method provided by the present invention. Detailed Embodiments

[0051] The following further describes the detailed embodiments of the present invention in conjunction with the drawings.

[0052] As Figures 1 to 2 shown, this embodiment provides a privacy - protected pedestrian re - identification method. Without disclosing the privacy of pedestrian image features, a privacy - protected pedestrian re - identification method is realized through a secure outsourcing calculation method with a two - server architecture under the Paillier cryptosystem. To implement the privacy - protected pedestrian re - identification method, in combination with Figure 1 and Figure 2 drawings, this method involves entities such as an organizer, a participant P, a cloud platform CP, and a computing service provider CSP (where both CP and CSP are cloud platforms). For the convenience of understanding the implementation of the technical solution, in this embodiment, specific data is used for demonstration.

[0053] Step S1. Initialization: The organizer publishes a pedestrian re - identification task and generate a public-private key pair (pk, sk), where pk represents the public key and sk represents the private key; in this embodiment, the public key pk = (7286768429118725476237467623960619521231846434269299288577342403999805723154496931685607382350168588887699841444452925086074157846932007245791500178750424,

[0054] 7286768429118725476237467623960619521231846434269299288577342403999805723154496931685607382350168588887699841444452925086074157846932007245791500178750423), the private key

[0055] sk = (7286768429118725476237467623960619521231846434269299288577342403999805723154326197433744982665129638829807622197647670828176175056794810235770086774467320, 6027926380386517535130925824690647176502728472221055613179503218396009760793469736870970042838150325924968076576674730889985538050397326631816427776497069);

[0057] Split the private key sk into two parts (λ1, λ2), that is

[0058] (λ1, λ2) = (78669549368610526682434058697385696879540752379108782351991766205179703281593,

[0059] 43924103641652389222482712394197286322038235558682765255702720533963461833555729902236511108430629957060671360708527398673283783109887418736801372254942928133390124083410717573783764089931900747520839022725043539948471862582927892284104567651511660672442060244707990451505247999531721844896522709998313003487), obtain (pk, λ1), (pk, λ2); send (pk, λ1) and (pk, λ2) to the cloud platform CP and the computing service provider CSP respectively;

[0060] Subsequently, the organizer obtains the target person image feature vector library G and encrypts it using the public key and stores it in the cloud platform CP; for the convenience of narration, the encrypted feature vector library of the target person image stored in the cloud platform CP contains where g1 = [0.51449576, 0.68599434, 0.51449576], g2 = [0.23570226, 0.23570226, 0.94280904], g3 = [0.66666667, 0.66666667, 0.33333333], g4 = [0.63960215, 0.42640143, 0.63960215];

[0061] Step S2. Feature extraction: The participant uses the surveillance video to capture the person image and extracts the feature vector of the person image, encrypts it using the public key and then sends it to the cloud platform CP for storage; for the convenience of narration, p = [0.87287156, 0.21821789, 0.43643578], encrypts p using the public key

[0062]

[0063] Step S3. Calculate the similarity between the captured person feature vector and the target person feature vector: The cloud platform CP and the computing service provider CSP calculate the person image feature similarity through the pre-written batch secure multiplication protocol BatchSMUL where and i ∈ [1, |G|], p = (p 1, ···, p n ), n is the dimension of the feature vector, and G is the feature vector library of the target person's image;

[0064] In this embodiment,

[0065]

[0066] Step S4. Calculate and decrypt the similarity of the person image features and sort: The service provider CSP calculates where represents the last term of N(g i , k); The service provider CSP and the cloud platform CP cooperate to calculate the similarity of the person image features encoded as floating-point numbers {Q(p·g1), ···, Q(p·g |G| )} through the pre-written batch partial decryption protocol BatchPDec, and sort them in descending order to obtain the indices I of the top k values;

[0067] In this embodiment, in the kNN algorithm, k is taken as 2, and the CSP calculates where

[0068]

[0069] Then, the service provider CSP and the cloud platform CP cooperate to calculate

[0070] {Q(p·g1), Q(p·g2), Q(p·g3), Q(p·g4)}, where Q(p·g1) = 7415891168998236.0, Q(p·g2) = 6022644398105174.0, Q(p·g3) = 7862128084371927.0, Q(p·g4) = 8381056683061694.0, and sort them in descending order to obtain the indices I = [4, 3];

[0071] Step S5. Compare the feature vectors and feedback the results: The service provider CSP compares Q(p·g i ), where i ∈ I; The comparison method is as follows:

[0072] If then p ∈ N(g i , k), otherwise, The service provider CSP accumulates p ∈ N(g i, the number of (k) is denoted as count = 1; in this embodiment, ε is taken as 0.8. Since count < εk, CSP obtains 0 and feeds the result back to the organizer.

[0073] The present invention also provides a privacy - protected person re - identification system applying the above - mentioned method. The system includes a cloud platform, a computing service provider module, a participant module, and an organizer module; wherein,

[0074] The organizer module is configured to initiate a person re - identification task, generate public - private key information, and split the private key into two parts to generate first public - private key information and second public - private key information; the organizer module sends the first public - private key information and the obtained target person image feature vector library to the cloud platform, and sends the second public - private key information to the computing service provider module;

[0075] The cloud platform sends a recruitment instruction to the participant module to form a connection; the participant module is configured to use a camera device to capture a person image, extract features from the image, and send it to the cloud platform after encrypting it with the public key;

[0076] The cloud platform is configured to jointly calculate the batch - processing secure multiplication protocol BatchSMUL with the computing service provider module, and cooperate with the computing service provider module to calculate the batch - processing partial decryption protocol BatchPDec;

[0077] The computing service provider module is configured to calculate the similarity of the encrypted feature vector library of the target person image, compare the feature vectors, and feed the result back to the organizer module.

[0078] According to the disclosure and teaching of the above - mentioned specification, those skilled in the art of the present invention can also make changes and modifications to the above - mentioned embodiments. Therefore, the present invention is not limited to the specific embodiments disclosed and described above. Some modifications and changes to the invention should also fall within the protection scope of the claims of the present invention. In addition, although some specific terms are used in this specification, these terms are only for convenience of description and do not constitute any limitation to the present invention.

Claims

1. A pedestrian re-identification method for privacy protection, including an organizer, participants, a cloud platform CP, and a computing service provider CSP, characterized in that, The method includes the following steps: Step S1. Initialization: The organizer publishes a person re-identification task and uses a key platform to generate public and private keys (pk, sk), where pk represents the public key and sk represents the private key; the person re-identification task is where represents the encrypted feature vector of the captured person image, ε is a control parameter and ε ∈ (0, 1]; k and ω are control parameters used to control and the similarity measure between, k is a random integer in the interval (0, |G|), ω is a random number in the interval ; N(p, k) is the KNN algorithm, representing the k vectors most similar to the vector p; the key platform is the Paillier cryptosystem; After splitting the private key sk into two parts (λ1, λ2), the first public-private key (pk, λ1) and the second public-private key (pk, λ2) are obtained; (pk, λ1) and (pk, λ2) are respectively sent to the cloud platform CP and the computing service provider CSP; the cloud platform CP and the computing service provider CSP are a non-collusive dual-server architecture, the public key pk = (g, N), where N = pq, g = N + 1 and both p and q are strong prime numbers; the private key sk = (λ, μ), where λ = lcm(p - 1, q - 1), μ = λ -1 modN, and the partial private key λ1 is a random integer in (0, λμ), λ2 = λμ - λ1; The organizer obtains the target person image feature vector library G and encrypts it using the public key and stores it in the cloud platform CP; Step S2. Feature extraction: The participant uses a camera device to capture a person image and extracts the feature vector p of the person image, and encrypts it with the public key and then sends it to the cloud platform CP for storage; where Enc(p, pk) = (1 + pN) · r mod N N mod N 2 , r is a random positive integer less than N; Step S3. Calculate the similarity between the captured human feature vector and the target human feature vector: The cloud platform CP and the computing service provider CSP calculate the similarity of the human image features through the pre-written batch secure multiplication protocol BatchSMUL. where and i ∈ [1, |G|], p = (p 1 , ···, p n ), n is the dimension of the feature vector, and G is the feature vector library of the target human image. The specific steps of the batch secure multiplication protocol BatchSMUL are as follows: Step S3-1: The cloud platform CP has δ ciphertext pairs and performs additive blinding processing on each ciphertext pair using a random number and the Paillier homomorphic calculation method and then combines the blinded ciphertexts X i , Y i into ciphertext c i , obtaining a ciphertext group {c1, ···, c δ}, performing a product operation on the ciphertext group to aggregate it into ciphertext C, and using a partial private key λ1 to partially decrypt the ciphertext to obtain C1, obtaining a ciphertext pair <C, C1>; then sending the ciphertext pair <C, C1> to the computing service provider CSP, and the calculation process is as follows: C1 = PDec(λ1, C), where r i,1 、r i,2 is a random number, and r i,1 、r i,2 ∈ {0, 1} σ , σ is a security parameter; L is a constant and satisfies L ≥ 2 σ+2 ; δ ≤ [|N| / 2|L|]; x i , y i ∈ [0, 2 l ), i is a positive integer and i ∈ [1, δ], l is a security parameter; Step S3-2: The service provider CSP partially decrypts the ciphertext C using the partial key λ2 to obtain C2, and decrypts the ciphertext pair <C1, C2> using the threshold decryption algorithm to obtain the plaintext corresponding to each ciphertext pair in Step S3-1 (x i +r i,1 )·(y i +r i,2 ). Then, the encrypted result is batch-sent to the cloud platform CP. The calculation process includes: calculating PDec(λ2, C) to partially decrypt C to obtain the ciphertext C2, calculating TDec(C1, C2) to obtain the plaintext Μ = L 2δ-1 ·(x δ +r δ,1 ) + L 2δ-2 ·(y δ +r δ,2 ) + ··· + L·(x1 + r 1,1 ) + y1 + r 1,2 , and calculating the plaintext where i ∈ [1, δ]; The threshold decryption algorithm used in the calculation process is TDec(M1, M2) = L(M1·M2 mod N 2 ) Subsequently, the computing service provider CSP will calculate x i +r i,1 and y i +r i,2 encrypt them and send to the cloud platform CP; Step 3-3: For each ciphertext received by cloud platform CP obtained through Paillier homomorphic calculation The calculation process is as follows: Among them, the secure multiplication protocol adopted includes the following steps: Step S3-1’: The cloud platform CP performs additive blinding processing on the ciphertexts and using a random number and the Paillier homomorphic calculation method, combines the blinded ciphertexts X and Y into ciphertext C, and performs partial decryption on the ciphertext using the partial private key λ1 to obtain C1, and then sends the ciphertext pair <C, C1> to the computing service provider CSP, that is: compute and where r1, r2 are random numbers r1, r2 ← {0, 1} σ , σ is a security parameter; subsequently, the cloud platform CP computes C ← X L ·Y, C1 ← PDec(λ1, C), where L is a constant and satisfies L ≥ 2 σ+2 ; the cloud platform CP sends <C, C1> to the computing service provider CSP; Step S3-2’: The cloud service provider CSP partially decrypts the ciphertext C using the partial key λ2 to obtain C2, and decrypts the ciphertext pair <C1, C2> using the threshold decryption algorithm to obtain the plaintext (x + r1)·(y + r2). After encryption, the is sent to the cloud platform CP. The calculation process includes: obtaining C2 ← PDec(λ2, C) through partial decryption, obtaining L·(x + r1) + y + r2 ← TDec(C1, C2) using the threshold decryption algorithm, and calculating y + r2 = (L·(x + r1) + y + r2) mod L, and encrypting (x + r1)·(y + r2) with the public key and send it to the CP cloud platform; Step S3-3': The cloud platform CP obtains it through Paillier homomorphic calculation The calculation process is: Calculate Step S4. Calculate and decrypt the similarity of the human image features and sort: The computing service provider CSP calculates where represents the last term of N(g i , k); The computing service provider CSP and the cloud platform CP cooperate to calculate the similarity of the human image features after floating-point encoding {Q(p·g1), ···, Q(p·g |G| )} through the pre-written batch partial decryption protocol BatchPDec, and sort them in descending order to obtain the indexes I of the first k values; The specific steps of the batch partial decryption protocol BatchPDec are as follows: Step S4-1: The cloud platform CP aggregates the ciphertext into ciphertext D through product operation, and uses the partial private key λ1 to partially decrypt the ciphertext to obtain D1, and then sends the ciphertext pair <D, D1> to the computing service provider CSP. The computing process is as follows: by calculating the ciphertext where Then calculate PDec(λ1, D) to obtain the ciphertext D1, and send <D, D1> to the computing service provider CSP; Step S4-2: The service provider CSP calculates PDec(λ2,D) to obtain the ciphertext D2←PDec(λ2,D), and then calculates TDec(D1,D2) to obtain the plaintext d←TDec(D1,D2), so as to obtain Q(p·g1)←d modL′, obtaining {Q(p·g1),···,Q(p·g n )}, where Step S5. Compare the feature vectors and feedback the result: Calculate the comparison between the feature vectors of the service provider CSP for Q(p·g i ), where i ∈ I; The comparison method is as follows: If then p ∈ N(g i , k), otherwise the computing service provider CSP accumulates the number of p ∈ N(g i , k) and records it as count; if count ≥ εk, then CSP gets 1, otherwise gets 0, and feedbacks this result to the organizer.

2. The pedestrian re-identification method according to claim 1, wherein In the step S5, Q(x) is that the floating-point encoding mechanism converts the floating-point number x into an integer, where l is a constant, x ↑ , x ↓ is an integer.

3. A pedestrian re-identification system for privacy protection, characterized in that, Applying the pedestrian re-identification method according to any one of claims 1 to 2, the system includes a cloud platform, a computing service provider module, a participant module, and an organizer module; wherein, The organizer module is configured to initiate a pedestrian re-identification task, generate public and private key information, and split the private key into two parts to generate first public and private key information and second public and private key information; the organizer module sends the first public and private key information and the obtained target person image feature vector library to the cloud platform, and sends the second public and private key information to the computing service provider module; The cloud platform sends a recruitment instruction to the participant module to form a connection; the participant module is configured to capture a person image using a camera device, extract features from the image, and send the encrypted image to the cloud platform using the public key; The cloud platform is configured to jointly calculate the batch secure multiplication protocol BatchSMUL with the computing service provider module, and cooperate with the computing service provider module to calculate the batch partial decryption protocol BatchPDec; The computing service provider module is configured to calculate the similarity of the encrypted feature vector library of the target person image, compare the feature vectors, and feedback the result to the organizer module.

4. A storage device in which multiple instructions are stored, characterized in that, The instruction is applicable to the step operation of loading and executing the pedestrian re-identification method according to any one of claims 1 to 2 by a processor.

Citation Information

Patent Citations

  • Privacy protection system and method for target search through Internet of Things camera

    CN112865958A

  • Data privacy protection method based on secure multi-party clustering method

    CN115150060A