A Trustworthy Privacy Data Comparison Method, Its Storage Device, and Smart Terminal

Through Paillier homomorphic encryption algorithm and partial private key decryption, the problem of malicious modification and inefficiency in the privacy comparison is solved, and the comparison and efficient calculation of privacy data trusted by both parties is realized.

CN116132012BActive Publication Date: 2025-07-22GUANGZHOU INSTITUTE OF TECHNOLOY XIDIAN UNIVERSITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211386111.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-07
Publication Date
2025-07-22
Estimated Expiration
2042-11-07

AI Technical Summary

Technical Problem

In the existing privacy comparison methods, one party may maliciously modify the results, and it is difficult to ensure the correctness and security of the results under the malicious model, and the calculation efficiency is low.

Method used

Paillier homomorphic encryption algorithm is used to pre-calculate the intermediate value and use part of the private key for decryption, ensuring that both parties obtain comparison results without leaking private data, and verify the correctness of the results through random numbers and partial decryption algorithms.

Benefits of technology

It realizes that both parties can trust the data size comparison results without leaking private data, and improves the computing efficiency and ensures the trustworthiness and security of the results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132012B_ABST
    Figure CN116132012B_ABST
Patent Text Reader

Abstract

The present invention discloses a trustworthy privacy data comparison method, its storage device, and an intelligent terminal, belonging to the technical field of information security and privacy protection. In the present invention, Paillier encryption algorithm is used to encrypt the privacy data of both parties, and then the problem of privacy data comparison is transformed into the problem of both parties decrypting to obtain the final comparison result through a series of homomorphic encryption operations. By enabling both parties of the protocol to verify the correctness of the final result, the problem that in the existing privacy calculation, one party first obtains the final result but dishonestly sends the final result to the other party is solved, ensuring that neither party can obtain privacy information other than the comparison result; in addition, by calculating some intermediate values before the start of the protocol, such as the relevant selection and encryption operations of random numbers r1, r2, and s, and the fact that the two participating parties can perform parallel operations during partial decryption #imgabs0#, the computing efficiency of homomorphic secure operations can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security and privacy protection, and particularly relates to a trustworthy privacy data comparison method, its storage device, and intelligent terminal. Background Art

[0002] The Paillier encryption algorithm was invented by Pascal Paillier in 1999. It is a homomorphic encryption algorithm based on the difficulty problem of composite residue classes, and this encryption algorithm satisfies homomorphic addition. Among them, the homomorphic addition operation can map the multiplication operation on the ciphertext to the addition operation on the plaintext without exposing the plaintext information.

[0003] Privacy comparison enables the private data held by both parties to obtain the size relationship between the data without leakage. Privacy comparison originated from the millionaire problem proposed by Yao Qizhi in 1982: There are two millionaires who want to compare who is richer, but they don't want to disclose how much money they have to each other. How to obtain the comparison result without a trusted third party. Privacy comparison has two application scenarios, namely the semi-honest model and the malicious model.

[0004] In the semi-honest model, semi-honest participants will participate in the protocol honestly, but will infer private information based on the information they obtain in the protocol. In this model, whether it is the method based on garbled circuits or the method based on homomorphic encryption can well solve the privacy comparison problem, but these methods cannot resist the attacks of malicious participants.

[0005] In the malicious model, malicious participants can actively modify the sent information to attack the protocol to obtain private information. This situation is more common in real life and more in line with the actual situation. In this model, Lindell proposed a privacy comparison method against malicious adversaries based on garbled circuits. This method enables the sender Alice to construct and send multiple circuits to the receiver Bob. Bob will randomly select half of the circuits and ask Alice to check their correctness. If the check is correct, then use the remaining circuits to calculate and output the privacy comparison result. Due to the need to construct a large number of circuits, the efficiency of this method and most methods based on the malicious model is relatively low.

[0006] The problems existing in the existing privacy comparison methods are as follows:

[0007] (1) Most of the existing privacy comparison methods are that one party first obtains the result, assumed to be Alice, and then Alice shares the result with Bob. At this time, Alice may maliciously modify the result, and the existing methods have problems in how to ensure that Bob can verify the correctness of the result.

[0008] (2) How to improve the privacy comparison efficiency while ensuring security.

[0009] Therefore, there is an urgent need to provide a trustworthy privacy data comparison method, its storage device, and intelligent terminal to solve the above problems. Summary of the Invention

[0010] The main purpose of the present invention is to overcome the shortcomings and deficiencies of existing privacy comparison technologies, and provide a privacy comparison method based on Paillier homomorphic encryption, so that both parties can obtain the result of comparing the sizes of privacy data without learning any information of the other party during the process of participating in the protocol, and both parties in this solution can verify whether the other party follows the protocol, improving the security of the solution. This method also improves the privacy comparison efficiency by pre-computing the intermediate values required by the protocol.

[0011] The technical solution of the present invention is implemented as follows:

[0012] A trustworthy privacy data comparison method, including participant Alice and participant Bob, and the implementation steps of the method are as follows:

[0013] S1. System initialization: Participant Alice initializes the Paillier cryptosystem A, generates a key pair {pka, ska}, where pka is the public key and ska is the private key, and splits the private key ska into partial private keys ska1 and ska2; Participant Bob initializes the Paillier cryptosystem B, generates a key pair {pkb, skb}, where pkb is the public key and skb is the private key; among them, participant Alice holds the privacy data a, and participant Bob holds the privacy data b;

[0014] S2. Participant Bob calls the public key pkb and the Enc encryption model to encrypt the privacy data b, and sends the public key pkb and the encrypted data to participant Alice; the encryption process is expressed as:

[0015]

[0016] S3. Participant Alice calls the public key pkb and the Enc encryption model to encrypt the privacy data a, and at the same time generates a random number s, where s randomly takes 0 or 1; then calls the Enc encryption model to encrypt s using the public key pka, and the encryption processes are respectively:

[0017]

[0018] Participant Alice then generates random numbers r1 and r2, and uses the properties of Paillier homomorphic encryption, combines the Enc1 encryption model, the Enc2 encryption model and the public key pkb to calculate r1 and r2, and obtains and The calculation process is expressed as:

[0019]

[0020] If s = 0, participant Alice will send the public key pka, the partial private key ska2, and to participant Bob;

[0021] If s = 1, then participant Alice will send the public key pka, the partial private key ska2, and to participant Bob;

[0022] S4. Participant Bob decrypts the ciphertext through the Dec decryption model of Paillier cryptosystem B and the private key skb to obtain m i , where the value of i is 0 or 1; the decryption process is expressed as:

[0023]

[0024] Participant Bob sets u1 according to m i ;

[0025] If then u1 = 0;

[0026] If then u1 = 1;

[0027] where Nb is part of the public key pkb;

[0028] Participant Bob encrypts u1 with the public key pka to obtain the ciphertext and sends to participant Alice; then, combining with the properties of Paillier homomorphic encryption, calculates and to obtain the ciphertext of the private comparison result The calculation process is expressed as:

[0029]

[0030] S5. After participant Alice receives , combines the public key pka and the ciphertext to calculate the ciphertext of the private comparison result according to the properties of homomorphic encryption Then, uses the Dec decryption model of Paillier cryptosystem A and the private key ska to decrypt to obtain the private comparison result u, and the calculation process is expressed as:

[0031]

[0032] If u = 0, it means a ≥ b; if u = 1, it means a < b;

[0033] The participant Alice uses the partial private key ska1 and the PDec partial decryption model to perform partial decryption to obtain the partial decryption result and sends the partial decryption result to the participant Bob; the decryption process is expressed as:

[0034]

[0035] S6. The participant Bob uses the partial private key ska2 and the PDec partial decryption model to perform partial decryption to obtain the partial decryption result The decryption process is expressed as:

[0036]

[0037] Then, through the partial decryption result and combining with the TDec full decryption model to perform full decryption to obtain the privacy comparison result u, that is:

[0038] In step S4, the participant Bob only has the ciphertext of the privacy comparison result and the intermediate value ciphertext but does not have the directly decryptable private key ska. Therefore, at this time, Bob cannot directly obtain the comparison result; the participant Alice is also not fully trusting of the ciphertext of the privacy comparison result obtained by Bob and cannot directly verify the ciphertext result. Therefore, in this protocol, the data sent by Bob to Alice is the intermediate value ciphertext And in step S5, Alice can calculate through s to obtain the ciphertext of the privacy comparison result and decrypt it to obtain the result u. The calculation process is equivalent to a verification. If has not been modified, the final result u obtained must be 0 or 1; at this time, Bob is also not fully trusting of the comparison result obtained by Alice. Therefore, Alice can only use the partial private key ska1 to perform partial decryption on and then send the obtained and the partial private key ska2 to Bob; in step S6, Bob uses the partial private key ska2 to perform partial decryption on to obtain and then combines it with Perform complete decryption to obtain the final comparison result u. Therefore, the above calculation process can ensure that the results calculated by Alice and Bob respectively are trustworthy, that is, each can obtain the correct comparison result or identify the incorrect comparison result.

[0039] However, if the participant Alice sends the private key ska to the participant Bob, then the participant Bob can directly obtain the ciphertext result.

[0040] Preferably, the public key pka = (ga, Na), where pa and qa are large prime numbers, Na = pa * qa, ga = Na + 1;

[0041] The private key ska = (λa, μa), where λa is the least common multiple of pa - 1 and qa - 1, that is, λa = pa * qa - pa - qa + 1, μa = (λa) -1 (mod Na);

[0042] The partial private keys ska1 and ska2 satisfy ska1 + ska2 = 0 (mod λa), ska1 + ska2 = 1 (mod Na), and ska1 is an arbitrary integer. ska2 is obtained by the Chinese Remainder Theorem, that is: ska2 = λa * μa + ηa * λa * Na - ska1, where ηa is a non - negative integer; the Chinese Remainder Theorem is a method in ancient China for solving a system of linear congruences.

[0043] The public key pkb = (gb, Nb), where pb and qb are large prime numbers, Nb = pb * qb, gb = Nb + 1;

[0044] The private key skb = (λb, μb), where λb is the least common multiple of pb - 1 and qb - 1, that is, λb = pb * qb - pb - qb + 1, μb = (λb) -1 (mod Nb).

[0045] Preferably, in steps S2 and S3, the Enc encryption model is:

[0046] Enc(pk, x) = (g) x *r N mod(N) 2 ,

[0047] where g and Nb are both part of the public key pk, r is a random positive integer less than N, and x is the data to be encrypted.

[0048] Preferably, in step S3, the Enc1 encryption model is:

[0049]

[0050] The Enc2 encryption model is as follows:

[0051]

[0052]

[0053] Among them, and

[0054] Preferably, in steps S4 and S5, the Dec decryption model is as follows:

[0055]

[0056] Among them, both λ and u are part of the private key sk, and N is part of the public key pk. is the ciphertext after the data y is encrypted by the public key pk. The private key sk and the public key pk belong to the same key group, and

[0057]

[0058] The Enc3 encryption model is as follows:

[0059] Among them, Na is part of the public key pka.

[0060] Preferably, in steps S5 and S6, the PDec partial decryption model is as follows:

[0061]

[0062] Among them, ska' is the partial private key of ska, and u is the result of private comparison. is the ciphertext after u is encrypted by the public key pka. Na is part of the public key pka, and the private key ska and the public key pka belong to the same key group.

[0063] Preferably, in step S6, the TDec complete decryption model is as follows:

[0064]

[0065] Among them, Na is part of the public key pka, and

[0066] Preferably, in step S2, b ∈ [-2 l , 2 l , where l represents the size of the data field, Nb is part of the public key pkb, and l is less than Nb;

[0067] When b ≥ 0, b is encrypted as

[0068] When b < 0, b is encrypted as

[0069] The present invention also provides a storage device, in which multiple instructions are stored, and the instructions are executed by a processor to implement the above-mentioned trusted private data comparison method.

[0070] The present invention also provides an intelligent terminal, which includes a storage device for storing multiple instructions and a processor for executing the multiple instructions. The processor can load and execute the instructions in the storage device to implement the above-mentioned trusted private data comparison method.

[0071] Compared with the prior art, the present invention has the following beneficial effects:

[0072] (1) The present invention realizes private comparison through the properties of Paillier homomorphic encryption, enabling both parties participating in the data comparison to obtain the comparison result of the data size without exposing their respective private data. Moreover, a random number s is added during the calculation process, and partial private keys and partial decryption algorithms are used to provide a result correctness verification method for the data holder, allowing the data holder to identify whether the result is correct and ensuring the trustworthiness of the result. That is, as long as the final result u decrypted by both parties is not 0 or 1, it indicates that the other party has modified the relevant data, that is, there is a malicious tampering behavior;

[0073] (2) The present invention can calculate the intermediate values required for the protocol before the start of the protocol, such as the relevant selection and encryption operations of random numbers r1, r2, and s, and the partial decryption of both participating parties can be performed in parallel, which can effectively improve the calculation efficiency of homomorphic encryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] Figure 1 is a flowchart of a trusted private data comparison method of the present invention; DETAILED DESCRIPTION OF THE EMBODIMENTS

[0075] In order to make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0076] As Figure 1 shown, the present invention provides a trusted private data comparison method, including participant Alice and participant Bob. The implementation steps of the method are as follows:

[0077] S1. System initialization: Participant Alice initializes the Paillier cryptosystem A, generates a key pair {pka, ska}, where pka is the public key and ska is the private key, and splits the private key ska into partial private keys ska1 and ska2; Participant Bob initializes the Paillier cryptosystem B, generates a key pair {pkb, skb}, where pkb is the public key and skb is the private key; among them, Participant Alice holds the private data a, and Participant Bob holds the private data b;

[0078] In this embodiment, the public key pka = (ga, Na), where pa and qa are large prime numbers, Na = pa * qa, and ga = Na + 1;

[0079] The private key ska = (λa, μa), where λa is the least common multiple of pa - 1 and qa - 1, that is, λa = pa * qa - pa - qa + 1, and μa = (λa) -1 (mod Na);

[0080] The partial private keys ska1 and ska2 satisfy ska1 + ska2 = 0 (mod λa), ska1 + ska2 = 1 (mod Na), and ska1 is an arbitrary integer. ska2 is obtained by the Chinese Remainder Theorem, that is: ska2 = λa * μa + ηa * λa * Na - ska1, where ηa is a non - negative integer; The Chinese Remainder Theorem is a method in ancient China for solving a system of linear congruences.

[0081] The public key pkb = (gb, Nb), where pb and qb are large prime numbers, Nb = pb * qb, and gb = Nb + 1;

[0082] The private key skb = (λb, μb), where λb is the least common multiple of pb - 1 and qb - 1, that is, λb = pb * qb - pb - qb + 1, and μb = (λb) -1 (mod Nb).

[0083] S2. Participant Bob calls the public key pkb and the Enc encryption model to encrypt the private data b, and sends the public key pkb and the encrypted data to Participant Alice; The encryption process is expressed as:

[0084]

[0085] Specifically, in step S2, b ∈ [-2 l , 2 l , where l represents the size of the data domain, Nb is part of the public key pkb, and l is less than Nb;

[0086] When b ≥ 0, b is encrypted as

[0087] When b < 0, b is encrypted as

[0088] S3. Participant Alice calls the public key pkb and the Enc encryption model to encrypt the private data a, and at the same time generates a random number s, where s randomly takes 0 or 1; then calls the Enc encryption model and uses the public key pka to encrypt s. The encryption processes are respectively:

[0089]

[0090] Participant Alice then generates random numbers r1 and r2, and uses the properties of Paillier homomorphic encryption, combines the Enc1 encryption model, the Enc2 encryption model and the public key pkb to calculate r1, r2, and obtains and The calculation process is expressed as:

[0091]

[0092] If s = 0, participant Alice will the public key pka, the partial private key ska2 and send to participant Bob;

[0093] If s = 1, then participant Alice will the public key pka, the partial private key ska2 and send to participant Bob;

[0094] Specifically, in steps S2 and S3, the Enc encryption model is:

[0095] Enc(pk,x) = (g) x *r N mod(N) 2 ,

[0096] where g and Nb are both parts of the public key pk, r is a random positive integer less than N, and x is the data to be encrypted.

[0097] Specifically, in step S3, the Enc1 encryption model is:

[0098]

[0099] The Enc2 encryption model is:

[0100]

[0101] where, And

[0102] S4. Participant Bob decrypts the ciphertext through the Dec decryption model and private key skb of Paillier cryptosystem B to obtain m i , where the value of i is 0 or 1; the decryption process is expressed as:

[0103]

[0104] Participant Bob sets u1 according to m i ;

[0105] If then u1 = 0;

[0106] If then u1 = 1;

[0107] where Nb is part of the public key pkb;

[0108] Participant Bob encrypts u1 with the public key pka to obtain the ciphertext and sends to participant Alice; then, combined with the properties of Paillier homomorphic encryption, use the Enc3 encryption model to calculate and to obtain the ciphertext of the private comparison result The calculation process is expressed as:

[0109]

[0110] S5. After participant Alice receives , combined with the public key pka and the ciphertext calculate the ciphertext of the private comparison result according to the properties of homomorphic encryption Then use the Dec decryption model and private key ska of Paillier cryptosystem A to decrypt to obtain the private comparison result u, and the calculation process is expressed as:

[0111]

[0112] If u = 0, it means a ≥ b; if u = 1, it means a < b;

[0113] Participant Alice uses the partial private key ska1 and the PDec partial decryption model to perform partial decryption to obtain the partial decryption result and sends the partial decryption result to participant Bob; the decryption process is expressed as:

[0114]

[0115] Specifically, in steps S4 and S5, the Dec decryption model is as follows:

[0116]

[0117] Among them, both λ and u are part of the private key sk, and N is part of the public key pk. is the ciphertext after the data y is encrypted by the public key pk. The private key sk and the public key pk belong to the same group of key sets, and

[0118]

[0119] The Enc3 encryption model is as follows:

[0120] Among them, Na is part of the public key pka.

[0121] S6. Participant Bob performs partial decryption through the partial private key ska2 and the PDec partial decryption model to obtain the partial decryption result The decryption process is expressed as:

[0122]

[0123] Then, through the partial decryption result and combining with the TDec complete decryption model to perform complete decryption to obtain the privacy comparison result u, that is:

[0124] Specifically, in steps S5 and S6, the PDec partial decryption model is as follows:

[0125]

[0126] Among them, ska' is the partial private key of ska, and u is the privacy comparison result. is the ciphertext after u is encrypted by the public key pka. Na is part of the public key pka, and the private key ska and the public key pka belong to the same group of key sets.

[0127] Specifically, in step S6, the TDec complete decryption model is as follows:

[0128]

[0129] Among them, Na is part of the public key pka, and

[0130] At step S4, the participant Bob only has the ciphertext of the privacy comparison result and the ciphertext of the intermediate value and does not have the private key ska that can be directly decrypted. Therefore, Bob cannot directly obtain the comparison result at this time; the participant Alice is also not fully trusting of the ciphertext of the privacy comparison result obtained by Bob and cannot directly verify the ciphertext result. Therefore, in this protocol, the data sent by Bob to Alice is the ciphertext of the intermediate value And in step S5, Alice can calculate through s to obtain the ciphertext of the privacy comparison result and decrypt it to obtain the result u. The calculation process is equivalent to a verification. If has not been modified, the final result u obtained must be 0 or 1; at this time, Bob is also not fully trusting of the comparison result obtained by Alice. Therefore, Alice can only use the partial private key ska1 to perform partial decryption, and then send the obtained and the partial private key ska2 to Bob; in step S6, Bob uses the partial private key ska2 to perform partial decryption to obtain and then combine it with to perform complete decryption to obtain the final comparison result u. Therefore, the above calculation process can ensure that the results calculated by Alice and Bob respectively are trustworthy, that is, each can obtain the correct comparison result or identify the wrong comparison result.

[0131] However, if the participant Alice sends the private key ska to the participant Bob, then the participant Bob can directly obtain the ciphertext result.

[0132] In this embodiment, for the participants Alice and Bob to compare private data, the specific implementation steps are as follows:

[0133] S1. System Initialization: Participant Alice initializes the Paillier cryptosystem A, generates a key pair {pka, ska}, where pka = (ga = 19782, Na = 19781) is the public key and ska = (λa = 19500, μa = 14079) is the private key. Then, Alice splits the private key ska into partial private keys ska1 = 19500 and ska2 = 22908. Participant Bob initializes the Paillier cryptosystem B, generates a key pair pkb = (gb = 23214, Nb = 23213), where pkb = (gb = 23214, Nb = 23213) is the public key and skb = (λb = 22908, μb = 2816) is the private key. Here, participant Alice holds the private data a = 9, and participant Bob holds the private data b = 3. Without knowing each other's private data, both parties can obtain the size relationship between a and b.

[0134] S2. Participant Bob calls the public key pkb and the Enc encryption model to encrypt the private data b, obtaining and sends the public key pkb and the encrypted data to participant Alice.

[0135] S3. Participant Alice calls the public key pkb and the Enc encryption model to encrypt the private data a, obtaining Meanwhile, Alice generates a random number s, where s randomly takes 0 or 1. In this embodiment, s = 0. Then, Alice calls the Enc encryption model and encrypts s using the public key pka, obtaining

[0136] Participant Alice then generates random numbers r1 = 8 and r2 = 11604. Since s = 0, the result is calculated by the Enc1 encryption model as and sends the public key pka, the partial private key ska2, and to participant Bob.

[0137] S4. Participant Bob decrypts the ciphertext using the Dec decryption model of the Paillier cryptosystem B and the private key skb, obtaining m1 = 11660. Since therefore u1 = 0.

[0138] Participant Bob encrypts u1 using the public key pka to obtain the ciphertext and sends to participant Alice. Then, combined with the properties of Paillier homomorphic encryption, the Enc3 encryption model is used to calculate and to obtain the ciphertext of the privacy comparison result

[0139] S5. Participant Alice receives and then, in combination with the public key pka and the ciphertext calculates the ciphertext of the privacy comparison result according to the properties of the homomorphic encryption and then decrypts it using the Dec decryption model of the Paillier cryptosystem A and the private key ska to obtain the privacy comparison result u = 0, indicating a ≥ b.

[0140] Participant Alice performs partial decryption using the partial private key ska1 and the PDec partial decryption model to obtain the partial decryption result and sends the partial decryption result to Participant Bob;

[0141] S6. Participant Bob performs partial decryption using the partial private key ska2 and the PDec partial decryption model to obtain the partial decryption result and then, through the partial decryption result and performs full decryption in combination with the TDec full decryption model to obtain the privacy comparison result u = 0, indicating a ≥ b.

[0142] In this embodiment, a storage device is further provided. Multiple instructions are stored in the storage device, and when the instructions are executed by a processor, the above-mentioned trusted privacy data comparison method is implemented.

[0143] In this embodiment, an intelligent terminal is further provided. The intelligent terminal includes a storage device storing multiple instructions and a processor for executing the multiple instructions. The processor can load and execute the instructions in the storage device to implement the above-mentioned trusted privacy data comparison method.

[0144] According to the disclosure and teachings of the above specification, those skilled in the art to which the present invention pertains can also make changes and modifications to the above-mentioned embodiments. Therefore, the present invention is not limited to the specific embodiments disclosed and described above, and some modifications and changes to the present invention should also fall within the protection scope of the claims of the present invention. In addition, although some specific terms are used in this specification, these terms are only for convenience of description and do not constitute any limitation to the present invention.

Claims

1. A trusted privacy data comparison method, including participant Alice and participant Bob, characterized in that, It includes the following steps: S1. System initialization: Participant Alice initializes the Paillier cryptosystem A, generates a key pair {pka, ska}, where pka is the public key and ska is the private key, and splits the private key ska into partial private keys ska1 and ska2; Participant Bob initializes the Paillier cryptosystem B, generates a key pair {pkb, skb}, where pkb is the public key and skb is the private key; where, Participant Alice holds the private data a, and Participant Bob holds the private data b; S2. Participant Bob calls the public key pkb and the Enc encryption model to encrypt the private data b, and sends the public key pkb and the encrypted data to Participant Alice; the encryption process is expressed as: S3. Participant Alice calls the public key pkb and the Enc encryption model to encrypt the private data a, and at the same time generates a random number s, where s randomly takes 0 or 1; then calls the Enc encryption model to encrypt s using the public key pka. The encryption processes are respectively: Participant Alice regenerates random numbers r1 and r2, and uses the properties of Paillier homomorphic encryption to calculate, in combination with the Enc1 encryption model, the Enc2 encryption model, and the public key pkb r1 and r2, obtaining and The calculation process is expressed as: If s = 0, participant Alice will send the public key pka, the partial private key ska2, and send them to participant Bob; If s = 1, then the participant Alice will send the public key pka, the partial private key ska2, and send them to the participant Bob; S4. Participant Bob decrypts the ciphertext through the Dec decryption model and private key skb of Paillier cryptosystem B to obtain m i , where the value of i is 0 or 1; the decryption process is expressed as: Participant Bob sets u1 according to m i Set u1; If then u1 = 0; If then u1 = 1; where, Nb is part of the public key pkb; The participant Bob encrypts u1 with the public key pka to obtain the ciphertext and sends to the participant Alice; then, combined with the properties of Paillier homomorphic encryption, the Enc3 encryption model is used to calculate and to obtain the ciphertext of the private comparison result The calculation process is expressed as: S5. Participant Alice receives After that, combining the public key pka and the ciphertext According to the properties of homomorphic encryption, the ciphertext of the private comparison result is calculated Then, use the Dec decryption model of Paillier cryptosystem A and the private key ska to decrypt To obtain the private comparison result u, the calculation process is expressed as: If u = 0, it means a ≥ b; if u = 1, it means a < b; Participant Alice uses a partial private key ska1 and the PDec partial decryption model to perform partial decryption to obtain a partial decryption result and sends the partial decryption result to Participant Bob; the decryption process is expressed as: S6. Participant Bob performs partial decryption using the partial private key ska2 and the PDec partial decryption model. Obtain the partial decryption result The decryption process is expressed as: Then, through the partial decryption result and combine with the TDec full decryption model to perform full decryption to obtain the privacy comparison result u, that is:

2. A trustworthy private data comparison method according to claim 1, wherein the public key pka = (ga, Na), where pa and qa are large prime numbers, Na = pa * qa, ga = Na + 1; The private key ska = (λa, μa), where λa is the least common multiple of pa - 1 and qa - 1, i.e., λa = pa * qa - pa - qa + 1, and μa = (λa) -1 (mod Na); the partial private keys ska1 and ska2 satisfy ska1 + ska2 = 0 (mod λa), ska1 + ska2 = 1 (mod Na), and ska1 is an arbitrary integer, and ska2 is obtained by the Chinese Remainder Theorem, that is: ska2 = λa * μa + ηa * λa * Na - ska1, where ηa is a non - negative integer; the public key pkb = (gb, Nb), where pb and qb are large prime numbers, Nb = pb * qb, gb = Nb + 1; The private key skb = (λb, μb), where λb is the least common multiple of pb-1 and qb-1, that is, λb = pb * qb - pb - qb + 1, and μb = (λb) -1 (mod Nb).

3. The trustworthy privacy data comparison method according to claim 1, wherein In steps S2 and S3, the Enc encryption model is: Enc(pk,x)=(g) x *r N mod(N) 2 , where, g and N are both part of the public key pk, r is a random positive integer less than N, and x is the data to be encrypted.

4. A trustworthy privacy data comparison method according to claim 1, characterized in that In step S3, the Enc1 encryption model is as follows: The Enc2 encryption model is: Among them, and 5. A trustworthy privacy data comparison method according to claim 1, characterized in that In steps S4 and S5, the Dec decryption model is: Among them, both λ and u are part of the private key sk, and N is part of the public key pk. is the ciphertext after the data y is encrypted by the public key pk. The private key sk and the public key pk belong to the same key group, and The Enc3 encryption model is as follows: where, Na is part of the public key pka.

6. A trustworthy privacy data comparison method according to claim 1, characterized in that, In steps S5 and S6, the PDec partial decryption model is: Among them, ska' is a partial private key of ska, and u is the result of private comparison. is the ciphertext after u is encrypted by the public key pka. Na is a part of the public key pka, and the private key ska and the public key pka belong to the same key group.

7. A trustworthy privacy data comparison method according to claim 1, characterized in that, In step S6, the TDec full decryption model is: wherein, Na belongs to a part of the public key pka, and 8. A trustworthy privacy data comparison method according to claim 1, characterized in that, In step S2, b ∈ [-2 l , 2 l , where l represents the size of the data field, Nb is part of the public key pkb, and l is less than Nb; When b ≥ 0, b is encrypted as When b < 0, b is encrypted as 9. A storage device that stores multiple instructions, characterized in that, The instruction is executed by the processor to implement a trustworthy private data comparison method according to any one of claims 1 - 8.

10. An intelligent terminal, the intelligent terminal comprising a storage device storing a plurality of instructions and a processor for executing the plurality of instructions, characterized in that, The processor can load and execute the instruction in the storage device to implement a trustworthy private data comparison method according to any one of claims 1 - 8.