A multi-party joint statistical method based on random mask calculation
By employing a multi-party joint statistical method based on random mask calculation, the problem of not being able to obtain the total user balance and protect customer balance information in existing technologies has been solved. This enables secure acquisition and hierarchical analysis of the total user balance, thereby improving business efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-24
- Publication Date
- 2026-03-27
AI Technical Summary
Existing statistical techniques cannot obtain total user balances without disclosing specific customer information, nor can they protect the privacy of subsidiary customers' balance information.
A multi-party joint statistical method based on random mask calculation is adopted. Through key negotiation, random mask balance PSI intersection summation and denoising operation, the same user balance information of the headquarters and subsidiaries is gradually obtained. Users who have not yet reached the intersection are encrypted to ensure information security.
This allows headquarters to obtain total user data without disclosing customer details, enabling them to perform tiered and tagged analysis of customers, thereby improving business revenue, while protecting the privacy of subsidiary companies' customer ID information.
Smart Images

Figure CN116167083B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of computer information technology, in particular to a multi-party joint statistical method based on random mask calculation. BACKGROUND
[0002] Private Set Intersection (PSI) belongs to a specific application problem in the field of privacy calculation, which has important theoretical significance and strong practical application value. With the increasing demand for privacy protection of user data, PSI can meet the convenience of businesses that rely on personal information while protecting the privacy of personal information to the greatest extent.
[0003] PSI allows multiple parties holding their own private data sets to calculate the intersection of their data, while not revealing any information outside the intersection. For ease of writing, this paper assumes that PSI intersection occurs between two parties. As shown in the following figure, assuming that one party holds data set A and the other party holds data set B, the result of PSI is A intersection B. The information obtained by A from B is only the intersection of AB; similarly, the information obtained by B from A is only the intersection of AB.
[0004] Consider the following scenario: the headquarters needs to count the customers who have conducted business in all subsidiaries, integrate all balance information under each subsidiary and the headquarters business, and conduct user classification and tagging statistical analysis on the total amount, but each subsidiary is an independent business, and the authorization agreement signed by the customer and the subsidiary does not allow the sharing of user balance information to the headquarters. The same customers of the headquarters and each subsidiary can perceive the user id, but the customers that the headquarters does not have cannot perceive the user id, and the users existing in the subsidiaries are mutually identifiable and cumulative.
[0005] Existing statistical techniques are basically plaintext statistics, which cannot achieve absolute protection of customer detailed information, or cannot count the balance information of users outside the intersection of the headquarters. Therefore, how to obtain the total amount of users without revealing the specific information of customers in each subsidiary is a problem that needs to be solved urgently. SUMMARY
[0006] Therefore, the application provides a multi-party joint statistical scheme based on random mask calculation, which first performs intersection of PSI to obtain the same users of the headquarters and the sub-companies, performs random mask balance noise on the balance of the users in the intersection in two parties, and then records the total balance in the headquarters. Secondly, the users in the sub-companies which do not intersect are independently loaded with random mask, and are returned to the headquarters for recording, and the id is encrypted. Then, the encryption keys of all the sub-companies need to be negotiated, and the id which does not intersect is uniformly encrypted when returned to the headquarters, so that the headquarters can distinguish the total balance. Finally, after all the mask noise total balances are summarized, the headquarters needs to send a de-noising request to all the sub-companies in steps to obtain the final real total amount.
[0007] In a first aspect, the application provides a multi-party joint statistical method based on random mask calculation, characterized in that the method comprises the following steps:
[0008] S1, key negotiation, the headquarters initiates a random mask key negotiation request to the sub-companies, and all the sub-companies return a key negotiation ACK to the headquarters after completing the key negotiation;
[0009] S2, random mask balance PSI intersection summary, the headquarters initiates a polling to all the sub-companies to obtain all the customer ids and the balance total amount after random mask noise;
[0010] S3, the headquarters obtains the final accurate balance information after the sub-companies de-noise the balance total amount.
[0011] The step S1 specifically comprises,
[0012] The headquarters initiates a random mask key negotiation request to the sub-companies, the sub-companies receiving the negotiation request request negotiation in turn according to a preset sub-company order, and the last sub-company participating in the negotiation feeds back a key negotiation ACK to the headquarters.
[0013] The preset sub-company order is generated by the headquarters according to a preset rule, and the preset sub-company order is sent to the first sub-company participating in the key negotiation when the random mask key negotiation request is initiated.
[0014] The headquarters initiates a polling to all the sub-companies to obtain all the customer ids and the balance total amount after random mask noise, which specifically comprises the following sub-steps,
[0015] S201, the headquarters initiates a PSI intersection with any sub-company, and the headquarters receives the clear id and the balance information after random mask noise corresponding to the clear id returned by the sub-company for the id in the intersection;
[0016] S202, the subsidiary uses the key generated in step S1 to perform an encryption operation on the user id that has not been settled, and returns the balance information corresponding to the user id that has not been settled after random masking and noise addition to the headquarters;
[0017] S203, the headquarters receives the returned information and merges and summarizes the balance information based on the user id;
[0018] S204, the headquarters repeats steps S201-S203 until all customer ids and the total balance after random masking and noise addition are obtained, the customer ids including plaintext ids and ciphertext ids.
[0019] In a second aspect, the present application provides a computing device, comprising: a processor, a memory, a communication interface and a communication bus, the processor, the memory and the communication interface complete communication with each other through the communication bus;
[0020] The memory is used to store at least one executable program, and the executable program makes the processor execute the corresponding operation of the multi-party joint statistical method based on random masking calculation.
[0021] The above description is only a summary of the technical solutions of the present application, in order to more clearly understand the technical means of the present application, and can be implemented according to the content of the specification, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings needed to be used in the description of the present application or the prior art. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.
[0023] Figure 1 Secret key negotiation flowchart;
[0024] Figure 2 PSI intersection noise addition and summary flowchart. DETAILED DESCRIPTION
[0025] In order to make the purpose, technical scheme and advantages of the embodiments of the present application more clear, the technical scheme in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0026] The terminology used in the description of the implementation of the present application is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application. As used in the description of the implementation of the present application and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. “Plural” generally includes at least two.
[0027] It should be understood that the term “and / or” as used herein merely describes associated objects in an associated manner, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of A existing alone, A and B existing together, and B existing alone. In addition, the character “ / ” herein generally represents an “or” relationship between the front and rear associated objects.
[0028] Depending on the context, the word “if’ as used herein can be interpreted to mean “when” or “while” or “in response to determining” or “in response to detecting.” Similarly, the phrase “if it is determined” or “if (a stated condition or event) is detected” can be interpreted to mean “when it is determined” or “in response to determining” or “when (a stated condition or event) is detected” or “in response to detecting (a stated condition or event)”, depending on the context.
[0029] It should also be noted that the terms “comprises”, “comprising”, or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a product or a process that includes a list of elements does not only include those elements but can also include other elements not expressly listed or inherent to such product or process. Without more limitations, an element defined by the phrase “comprising a” does not exclude the presence of additional identical elements in the product or process that includes the element.
[0030] In addition, the sequence of steps in each of the following method embodiments is only an example and is not strictly limited.
[0031] The present application provides a multi-party joint statistical method based on random mask calculation, characterized in that the method comprises the following steps:
[0032] S1, key negotiation, the headquarters initiates a random mask key negotiation request to the subsidiary, and all the subsidiaries return the key negotiation ACK to the headquarters after completing the key negotiation.
[0033] In a specific implementation, as shown in the accompanying Figure 1 The headquarters initiates a random mask key negotiation request to the subsidiary, the subsidiary that receives the negotiation request requests negotiation in turn according to the preset subsidiary order, and the last subsidiary that participates in the negotiation feeds back the key negotiation ACK to the headquarters. Note that at this time, only the negotiation completion is synchronized to the headquarters, and the key is not shared with the headquarters.
[0034] The preset subsidiary sequence is generated by the headquarters according to preset rules, and is sent to the first subsidiary participating in the key negotiation when the mask key negotiation request is initiated.
[0035] The IDs need to be aligned when the backhaul headquarters does not exchange user information, that is, the same customer ID of different subsidiaries can still generate the same encrypted string after encryption, which facilitates the headquarters to use when summarizing the total amount of users. The key generated by the key negotiation must be shared among the subsidiaries and cannot disclose the headquarters.
[0036] S2, random mask balance PSI intersection summary, the headquarters initiates polling to all subsidiaries to obtain all customer IDs and random mask noise after balance total.
[0037] In specific implementation, as shown in the accompanying Figure 2 The step S2 further includes the following sub-steps:
[0038] S201, the headquarters initiates PSI intersection with any subsidiary, for the intersection ID, the headquarters receives the plaintext ID and the balance information corresponding to the plaintext ID returned by the subsidiary after random mask noise;
[0039] The headquarters obtains the intersection customer ID after PSI intersection with the subsidiary, the headquarters sends the balance information corresponding to the customer ID to the subsidiary after noise, the subsidiary obtains new balance information after noise calculation of the balance of the intersection ID in the local and the noise value returned by the headquarters, and returns the new balance information and the corresponding customer ID to the headquarters.
[0040] S202, the subsidiary performs encryption operation on the user ID not in the intersection using the key generated in step S1, and returns the balance information corresponding to the user ID not in the intersection to the headquarters after random mask noise;
[0041] Preferably, the same customer ID owned by different subsidiaries is consistent and alignable after encryption, which facilitates the headquarters to summarize and process the balance information.
[0042] S203, the headquarters merges and summarizes the balance information based on the user ID after receiving the returned information;
[0043] The merging and summarizing includes, for the plaintext ID, directly adding the balance of the intersection ID of the local and other subsidiaries after random mask noise; for the ciphertext ID, adding the balance corresponding to the same encrypted ID of different subsidiaries after random mask noise; since the IDs of different subsidiaries are consistent and alignable after encryption, the balance can also be added after noise.
[0044] S204, the headquarters repeats steps S201-S203 until all customer ids, including plaintext ids and ciphertext ids, and the total balance amount after random noise addition are obtained.
[0045] At this point, after the headquarters polls all the subsidiaries, all customer ids (plaintext and ciphertext) and the total balance amount after noise addition are obtained.
[0046] S3, the headquarters obtains the final accurate balance information of the subsidiaries after the total balance amount is denoised.
[0047] In a specific implementation, the headquarters polls all the subsidiaries in turn, and sends all the customer ids and the total balance amount information aggregated by the headquarters to the subsidiaries, and the subsidiaries perform denoising on the balance information corresponding to the customer ids belonging to the subsidiaries among all the customer ids and then return the information to the headquarters.
[0048] The headquarters loads the information returned by the subsidiaries to obtain accurate balance information. Finally, the headquarters performs local loading of information to obtain the final accurate balance information of all users.
[0049] By using the scheme of the present application, the customer balance detail information is protected, and the detail balance information of the customers in each subsidiary cannot be perceived by all parties except the subsidiary itself. Meanwhile, the customer id information of the subsidiary is also protected, and the id of the customers except the headquarters is encrypted by key negotiation, and the user id of the subsidiary can be perceived, but the headquarters cannot be cracked.
[0050] The headquarters can obtain the total amount information of all users of the group (the total amount information data does not violate rules), and perform user tagging analysis based on the balance information of the users, divides different levels of customers based on the balance information of the users to carry out different businesses, and improves the business income of the headquarters.
[0051] The present application also provides a computer device. The computer device is in the form of a general-purpose computing device. The components of the computer device can include but are not limited to one or more processors or processing units, system memory, and a bus connecting different system components.
[0052] The computer device typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device, including volatile and non-volatile media, removable and non-removable media.
[0053] The system memory can include a computer system readable medium in the form of volatile memory, and the memory can include at least one program product having a set (for example, at least one) program modules configured to perform the functions of the embodiments of the present application.
[0054] The processing unit performs various function applications and data processing by running programs stored in the system memory, such as implementing the method provided by other embodiments of the present application.
[0055] The present application also provides a storage medium containing computer executable instructions, and a computer program is stored thereon, which is executed by a processor to implement the method provided by other embodiments of the present application.
[0056] Note that the above only describes the preferred embodiments of the present application and the technical principles applied. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and various obvious changes, re-adjustments and substitutions can be made by those skilled in the art without departing from the scope of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the appended claims.
Claims
1. A multi-party joint statistical method based on random mask computation, characterized in that, The method includes the following steps: S1, Key Negotiation: The headquarters initiates a random mask key negotiation request to the subsidiaries. After all subsidiaries complete the key negotiation, they return a key negotiation ACK to the headquarters. S2, random mask balance PSI intersection summary, headquarters initiates a polling process to all subsidiaries to obtain all customer IDs and the total balance after random masking and adding noise; including: S201, the headquarters initiates a PSI request with any subsidiary. For the ID in the request, the headquarters receives the plaintext ID and the balance information with random masking and noise added to the plaintext ID returned by the subsidiary. This includes: the headquarters obtains the customer ID in the request after requesting a PSI from the subsidiary; the headquarters adds noise to the balance information corresponding to the customer ID in the request and sends it to the subsidiary along with the customer ID; the subsidiary adds noise to its own balance of the ID in the request and calculates a new balance information by combining it with the noise-added value returned by the headquarters; and the subsidiary returns the new balance information and its corresponding customer ID to the headquarters. S202, the subsidiary performs encryption on the user IDs that have not been submitted using the key generated in step S1, and randomly masks and adds noise to the balance information corresponding to the user IDs that have not been submitted before sending it back to headquarters; wherein, the same customer IDs owned by different subsidiaries are consistent and can be aligned after encryption; S203. After receiving the feedback information, the headquarters will merge and summarize the balance information based on the user ID, including: for plaintext IDs, summarizing the balance information by adding noise to the random mask of the ID directly with the headquarters and other subsidiaries; for encrypted IDs, summarizing the balance information by adding noise to the random mask of the same encrypted ID corresponding to different subsidiaries. S204, the headquarters repeats steps S201-S203 until all customer IDs and the total balance after random masking and noise addition are obtained, wherein the customer IDs include plaintext IDs and ciphertext IDs; S3, the headquarters obtains the final accurate balance information of the total balance after noise reduction from the subsidiary, including: the headquarters sequentially polls all subsidiaries and sends all customer IDs and total balance information collected by the headquarters to the subsidiaries; the subsidiaries perform noise reduction on the balance information corresponding to their own customer IDs among all customer IDs and then send it back to the headquarters; the headquarters loads the information sent back by the subsidiaries to obtain the accurate balance information.
2. The method according to claim 1, characterized in that, Step S1 specifically includes, The headquarters initiates a random mask key negotiation request to the subsidiaries. Subsidiaries that receive the negotiation request request request in the order of the preset subsidiaries, and the last subsidiary to participate in the negotiation sends an ACK to the headquarters.
3. The method according to claim 2, characterized in that, The preset subsidiary order is generated by the headquarters according to preset rules, and when the mask key negotiation request is initiated, the preset subsidiary order is sent to the first subsidiary participating in the key negotiation.
4. A computing device, comprising: The processor, memory, communication interface, and communication bus are provided, wherein the processor, memory, and communication interface communicate with each other via the communication bus. The memory is used to store at least one executable program, which causes the processor to perform the operation corresponding to the multi-party joint statistical method based on random mask calculation as described in any one of claims 1-3.
5. A computer storage medium storing at least one executable program, the executable program causing a processor to perform operations corresponding to the multi-party joint statistical method based on random mask computation as described in any one of claims 1-3.
Citation Information
Patent Citations
Multi-party safe intersection solving method and device, storage medium and equipment
CN113901425A
Privacy set intersection method and system applied to financial scene
CN115277169A