Method and apparatus for private set intersection

By encrypting the big data volume and processing the data indiscriminately, combining local key replacement, data comparison between the small data volume and the big data volume is realized, solving the privacy submission problem under the imbalance of data volume, and improving the efficiency and security of privacy submission.

CN116204901BActive Publication Date: 2025-07-18ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211734385.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-31
Publication Date
2025-07-18
Estimated Expiration
2042-12-31

AI Technical Summary

Technical Problem

The prior art is difficult to efficiently complete privacy submissions when the data volume is unbalanced, especially the privacy submissions between large data volumes and small data volumes, resulting in waste of computing and communication resources.

Method used

The data is encrypted by one party in the large data volume and sent to the small data volume party, and the process is performed indiscriminately. The local key is used to interact with the key of the large data volume party, and the replacement of the encryption key is completed, and the data comparison between the small data volume party and the large data volume party is realized, and the intersection data is determined, and the intersection data is obtained by the large data volume party.

Benefits of technology

In the case of unbalanced data volume, the traffic volume is reduced, the effectiveness of privacy requests is improved, so that one party with a large data volume can obtain data intersections, while the other party with a small data volume cannot obtain effective information of the intersections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116204901B_ABST
    Figure CN116204901B_ABST
Patent Text Reader

Abstract

The embodiments of this specification provide a method and device for private set intersection, which are applicable to the private set intersection process between two data parties with unbalanced dataset quantities. According to one implementation, the party with the large dataset can pre-send the data ciphertext to the party with the small dataset. During the private set intersection process, the party with the small dataset sends the data ciphertext of the local dataset to the party with the large dataset, and the party with the large dataset calculates the secondary ciphertext and feeds it back after scrambling the order. The party with the small dataset decrypts the scrambled secondary ciphertext using the inverse of the local key, so as to obtain a data ciphertext equivalent to the one obtained by decrypting the data encrypted only with the key of the party with the large dataset after removing the local key. Furthermore, the party with the small dataset can compare the data encrypted with the key of the party with the large dataset for both sides to obtain the intersection data and feed it back to the party with the large dataset, and the party with the large dataset obtains the plaintext intersection. This method can provide a solution for obtaining intersection data for the larger dataset in private set intersection with less communication volume.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of computer technology, and in particular, to a method and apparatus for private set intersection. Background Art

[0002] Secure multi-party computation, also known as multi-party secure computation, means that multiple parties jointly calculate the result of a function without disclosing the input data of each party to this function, and the calculation result is disclosed to one or more of the parties. For example, a typical application of secure multi-party computation is private set intersection. Private set intersection (PSI), or known as password spraying, can be understood as determining the data intersection among multiple parties on the premise of privacy protection. Private set intersection can be used in business such as multi-party collaborative training of machine learning algorithms, multi-head lending, etc. The core idea of private set intersection is that at the end of the protocol interaction, one or more parties obtain the correct intersection and do not obtain any other data in the data sets of other parties outside the intersection. During the process of private set intersection, the amount of data and communication directly affect the computer resource occupancy and the efficiency of private set intersection.

[0003] Most of the research on conventional PSI is applicable to the situation where the number of participating party sets is close, and there is less research on non-balanced / asymmetric PSI. In some actual application scenarios, such as joint marketing of multiple platforms, joint product advertising promotion in the banking and insurance industries, etc., it may occur that the data magnitudes of the two parties in PSI differ greatly, such as private set intersection of data volumes in the millions vs. billions. How to complete private set intersection with less computation and communication volume in such a situation is a technical problem worthy of research. Summary of the Invention

[0004] One or more embodiments of this specification describe a method and apparatus for private set intersection to solve one or more problems mentioned in the background art.

[0005] According to a first aspect, there is provided a method for private set intersection, which is used for a first party holding n1 pieces of first data and a first key r, and a second party holding n2 pieces of second data and a second key β, where n1 < n2, and the second party obtains the intersection of the n1 pieces of first data and the n2 pieces of second data; the method is executed by the first party and includes: performing a predetermined encryption operation with the second party to obtain respective first reference ciphertexts obtained by encrypting each piece of first data under a predetermined encryption method via the second key β; comparing each first reference ciphertext with each respective second reference ciphertext corresponding to each piece of second data, so as to determine at least one data identifier of the second reference ciphertext corresponding to the intersection of the first data and the second data, where the second reference ciphertext is provided after the second party encrypts each of the n2 pieces of second data through a predetermined encryption method under the second key β; providing the second party with the at least one data identifier for the second party to determine the intersection of the first data and the second data based on each data identifier.

[0006] Wherein, the predetermined encryption operation includes: the first party encrypts each piece of first data via the first key r under a predetermined encryption method to obtain respective first ciphertexts corresponding to each piece of first data and provides them to the second party; the second party encrypts each of the first ciphertexts under the second key β in a predetermined encryption method, and after performing a scrambling operation on the obtained respective second ciphertexts, feeds them back to the first party; the first party processes each of the second ciphertexts through the inverse r of the first key under a predetermined encryption method to obtain respective first reference ciphertexts corresponding to each piece of first data. -1 Process each of the second ciphertexts to obtain respective first reference ciphertexts corresponding to each piece of first data.

[0007] In one embodiment, the predetermined encryption method is implemented based on a predetermined cluster that satisfies the following conditions: the fusion result of any two elements in the predetermined cluster under the predetermined encryption method is still an element in the predetermined cluster; the two encryption processes of a single element in the predetermined cluster in sequence according to the predetermined encryption method are commutative.

[0008] In a further embodiment, when the predetermined cluster is a finite field defined by a prime number P, the predetermined encryption method is exponential encryption; when the predetermined cluster is a point group on an elliptic curve, the predetermined encryption method is point multiplication encryption.

[0009] In one embodiment, the difference between n1 and n2 is greater than a predetermined threshold, where the difference between n1 and n2 is measured by a difference or a ratio.

[0010] In one embodiment, the data identifier is the position information of the intersection of the first data and the second data in each second reference ciphertext.

[0011] In one embodiment, the product of the first key r and its inverse is 1.

[0012] According to a second aspect, a method for private set intersection is provided, which is used for a first party holding n1 pieces of first data and a first key r and a second party holding n2 pieces of second data and a second key β, where n1 < n2, and the second party obtains the intersection of the n1 pieces of first data and the n2 pieces of second data; the method is executed by the second party and includes: performing a predetermined encryption operation with the first party, so that the first party obtains respective first reference ciphertexts obtained by encrypting each piece of first data through the second key β in a predetermined encryption method; determining the intersection of the first data and the second data according to at least one data identifier received from the first party, where the at least one data identifier is determined by the first party comparing each first reference ciphertext and each second reference ciphertext, and is used to indicate the second reference ciphertext corresponding to the intersection of the first data and the second data, and each second reference ciphertext is obtained by the second party encrypting each piece of second data through the second key β in a predetermined encryption method and providing it to the first party;

[0013] Wherein, the predetermined encryption operation includes: the first party encrypts each piece of first data through the first key r in a predetermined encryption method, obtains respective first ciphertexts corresponding to each piece of first data and provides them to the second party; the second party encrypts each first ciphertext through the second key β in a predetermined encryption method, and after performing a scrambling operation on the obtained second ciphertexts, feeds them back to the first party; the first party processes each second ciphertext through the inverse r of the first key -1 in a predetermined encryption method to obtain respective first reference ciphertexts corresponding to each piece of first data.

[0014] In one embodiment, the predetermined encryption method is implemented based on a predetermined group that satisfies the following conditions: the fusion result of any two elements in the predetermined group in the predetermined encryption method is still an element in the predetermined group; the two encryption processes of a single element in the predetermined group in sequence according to the predetermined encryption method are commutative.

[0015] In a further embodiment, when the predetermined group is a prime group, the predetermined encryption method is exponential encryption; when the predetermined group is a group of points on an elliptic curve, the predetermined encryption method is point multiplication encryption.

[0016] In one embodiment, the difference between n1 and n2 is greater than a predetermined threshold, where the difference between n1 and n2 is measured by a difference or a ratio.

[0017] In one embodiment, the data identifier is each position information of the intersection of the first data and the second data in the second reference ciphertext; the determining the intersection of the first data and the second data according to at least one data identifier received from the first party includes: determining each second data corresponding to each position information as the intersection of the first data and the second data.

[0018] According to a third aspect, there is provided a device for private set intersection, which is used for a first party holding n1 pieces of first data and a first key r, and a second party holding n2 pieces of second data and a second key β, where n1 < n2, and the second party obtains the intersection of the n1 pieces of first data and the n2 pieces of second data; the device is provided in the first party and includes:

[0019] A secure computing unit configured to perform a predetermined encryption operation with the second party to obtain respective first reference ciphertexts obtained by encrypting each piece of first data under a predetermined encryption method via the second key β;

[0020] A comparison unit configured to compare each first reference ciphertext with respective second reference ciphertexts corresponding to each piece of second data, so as to determine at least one data identifier of the second reference ciphertext corresponding to the intersection of the first data and the second data, where the second reference ciphertexts are provided by the second party after encrypting each of the n2 pieces of second data through a predetermined encryption method under the second key β;

[0021] A providing unit configured to provide the second party with the at least one data identifier for the second party to determine the intersection of the first data and the second data based on each data identifier;

[0022] Wherein, the predetermined encryption operation includes:

[0023] The first party encrypts each piece of first data under a predetermined encryption method via the first key r to obtain respective first ciphertexts corresponding to each piece of first data and provides them to the second party;

[0024] The second party encrypts each of the first ciphertexts under a predetermined encryption method via the second key β, and after performing a scrambling operation on the obtained respective second ciphertexts, feeds them back to the first party;

[0025] The first party processes each of the second ciphertexts under a predetermined encryption method through the inverse r of the first key -1 to obtain respective first reference ciphertexts corresponding to each piece of first data.

[0026] According to a fourth aspect, there is provided a device for private set intersection, which is used for a first party holding n1 pieces of first data and a first key r, and a second party holding n2 pieces of second data and a second key β, where n1 < n2, and the second party obtains the intersection of the n1 pieces of first data and the n2 pieces of second data; the device is provided in the second party and includes:

[0027] A secure computing unit configured to perform a predetermined encryption operation with the first party, so that the first party obtains respective first reference ciphertexts obtained by encrypting each piece of first data under a predetermined encryption method via the second key β;

[0028] An intersection determination unit, configured to determine the intersection of first data and second data according to at least one data identifier received from a first party, where the at least one data identifier is determined by the first party comparing each first reference ciphertext and each second reference ciphertext, and is used to indicate the second reference ciphertext corresponding to the intersection of the first data and the second data, and each second reference ciphertext is obtained by a second party encrypting each piece of second data in a predetermined encryption method via a second key β and provided to the first party;

[0029] Wherein, the predetermined encryption operation includes:

[0030] The first party encrypts each piece of first data in a predetermined encryption method via a first key r to obtain each first ciphertext corresponding to each piece of first data and provides it to the second party;

[0031] The second party encrypts each first ciphertext in a predetermined encryption method via a second key β, and after performing a scrambling operation on the obtained second ciphertexts, feeds them back to the first party;

[0032] The first party processes each second ciphertext in a predetermined encryption method through the inverse r of the first key -1 to obtain each first reference ciphertext corresponding to each piece of first data.

[0033] According to a fifth aspect, there is provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed in a computer, the computer is made to execute the method of the first aspect or the second aspect.

[0034] According to a sixth aspect, there is provided a computing device, including a memory and a processor. The memory stores executable code, and when the processor executes the executable code, the method of the first aspect or the second aspect is implemented.

[0035] Through the method and device provided by the embodiments of this specification, in the process of private intersection of two data parties with a large difference in data volume, the party with a large amount of data encrypts the data and sends it to the party with a small amount of data. The party with a small amount of data encrypts the local data and interacts with the party with a large amount of data according to the oblivious transfer random function, so as to complete the replacement of the encryption key, and the data encrypted by the local key is replaced with the data encrypted by the party with a large amount of data. Furthermore, the party with a small amount of data compares the encrypted data of both parties using the same encryption key and encryption method, and provides the data identifier corresponding to the intersection data to the party with a large amount of data, so that the party with a large amount of data can obtain the intersection data according to the data identifier.

[0036] Among them, during the key permutation process, the secondary ciphertext (the data ciphertext encrypted by the keys of both parties) fed back by the party with a large amount of data can be shuffled, which can avoid the possibility that the party with a small amount of data cracks the key of the party with a large amount of data in sequence. The online process of private set intersection in this way can perform private set intersection with a relatively small amount of data, effectively obtaining the data intersection on the side of the party with a large amount of data, and improving the effectiveness of private set intersection. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0038] Figure 1 is a schematic diagram of a specific implementation scenario of private set intersection;

[0039] Figure 2 shows a timing diagram of the private set intersection process under the technical concept of this specification;

[0040] Figure 3 is a schematic flowchart of the private set intersection executed by the party with a small amount of data according to an embodiment;

[0041] Figure 4 is a schematic flowchart of the private set intersection executed by the party with a large amount of data according to an embodiment;

[0042] Figure 5 shows a schematic block diagram of the private set intersection device provided on the side of the party with a small amount of data according to an embodiment;

[0043] Figure 6 shows a schematic block diagram of the private set intersection device provided on the side of the party with a large amount of data according to an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] The following will describe the solutions provided in this specification in conjunction with the drawings.

[0045] First, clarify several professional terms that may be used in this specification:

[0046] Private Set Intersection (PSI): Private Set Intersection, which is a research field of secure multi-party computing, enabling participating parties to obtain the intersection without leaking the non-intersection part to other participating parties;

[0047] Exponential encryption: Data is mapped to elements in a predetermined cluster, and encryption is performed with the mapped elements as the base and the key as the exponent. Here, the predetermined cluster is, for example, a set of points on an elliptic curve, a set of prime numbers, etc. When the predetermined cluster is implemented as a set of points on an elliptic curve, exponential encryption is achieved through point multiplication operations (performing multiple elliptic curve point additions by a scalar); in the case where the predetermined cluster is implemented as a finite field in the interval [0, P - 1] defined by a prime number P, exponential encryption is achieved through modular exponentiation. For two numbers a and b, one as the base and the other as the exponent, taking the modulus with respect to the prime number P, that is, modular exponentiation a b %P, which is equivalent to the result of (a % P) b %P.

[0048] Inverse element: The inverse element of an element can also be called the inverse of this element, and its product with this element is 1 (the identity element on an elliptic curve).

[0049] Reference Figure 1 As shown, a specific implementation scenario of private set intersection is given. In this implementation scenario, the two data parties holding business data are respectively denoted as the first party and the second party. Among them, the second party can obtain the intersection of the business data of both parties, and the first party cannot obtain any data or key information of the first party.

[0050] As Figure 1 shown, assume that the business data held by the first party is denoted as a, and the number of items is denoted as n1. Then the data held by the first party can be expressed as (a1, a2, a3... a n1 ), the business data held by the second party is denoted as b, the number of items is denoted as n2, and the data b can be expressed as (b1, b2, b3... b n2 ). The first party can also hold a private key r, and the second party can also hold a private key β. In a conventional private set intersection process, the first party and the second party respectively encrypt each local piece of data. For example, they are respectively denoted as H(a j ), H(b i ). H can represent a hash or other encryption method. In conventional techniques, for the convenience of calculation, each piece of business data is usually also mapped to an elliptic curve.

[0051] r and β can respectively have inverse elements. For example, r -1 , β -1 . Those skilled in the art can understand that the calculation method of the inverse element is, for example, through Euler's theorem, which will not be elaborated here. According to the properties of the inverse element, r -1 r is 1, β -1 β is 1. Based on this property of the inverse element, the first party can send the data a encrypted by r (for example, a r ) to the second party. The second party obtains the data a encrypted by r and further encrypts it using β to obtain a secondary ciphertext of a (for example, a βr)Feed it back to the first party, and the first party uses r -1 Process this second ciphertext, and the ciphertext data a encrypted by the second party's key β for the data a can be permuted out β , and the first party does not know β, and the second party does not know a and r. This process can also be called an oblivious pseudorandom function process

[0052] In this way, when the second party sends the ciphertext data b encrypted by the local key β for the data b β to the first party, the first party can use the permuted ciphertext data a β to match with the ciphertext data b β to obtain the intersection data of a and b

[0053] In the above Figure 1 shown process, the communication volume of the second party sending the ciphertext data b β to the first party is the communication volume of n2 data (which can be offline or online), and the key permutation process requires two communications, and the communication volume is 2×n1 data (online). Therefore, in the case where the data volumes of the two participating parties differ greatly, taking the party with the smaller data volume as the first party has a smaller communication volume

[0054] However, in practice, it may be necessary for the party with the larger data volume to obtain the intersection data. Therefore, based on the Figure 1 conventional technology, this specification proposes a new technical concept. In the case where the data volumes of the two participating parties differ greatly, the data intersection is obtained on the side of the party with the larger data volume, and the party with the smaller data volume cannot learn the effective information of the intersection data

[0055] Figure 2 shows the interaction timing diagram between the first party (the party with the smaller data volume) and the second party (the party with the larger data volume) under the technical concept of this specification. Assume that the first party holds n1 pieces of first data, and the second party holds n2 pieces of second data. Among them, the first data and the second data can be service data required for subsequent service processing, and the agreed consistent data form, such as the user's mobile phone number, identity identification code, etc

[0056] The technical concept of this specification is proposed for the case where the difference between n1 and n2 is large. Assume that n1 < n2, and it is especially applicable to the case where the difference between n1 and n2 is greater than a predetermined threshold, such as denoted as n1 << n2. Among them, the difference between n1 and n2 can be measured by the modulus of parameters such as the difference value, ratio, and order of magnitude difference. Taking the order of magnitude difference as an example, the predetermined threshold can be 1. In the case where the orders of magnitude of n1 and n2 are the million order of magnitude and the billion order of magnitude respectively, the order of magnitude difference is 2, which is greater than the predetermined threshold

[0057] In addition, assume that the first party holds a private key r (hereinafter referred to as the first key), and the second party holds a private key β (hereinafter referred to as the second key), asFigure 2 As shown in the figure, the interaction process of one-time private intersection can include the following steps:

[0058] Step 200, the second party encrypts each of the n2 pieces of second data through a predetermined encryption method under the second key β and provides it to the first party.

[0059] Here, the predetermined encryption method can be an encryption method agreed upon with the first party. This encryption method is an encryption method that can achieve key permutation and has commutativity, such as satisfying the commutative law. Specifically, for a certain piece of data, the encryption results of encrypting it first with the first key and then with the second key and encrypting it first with the second key and then with the first key are the same. This predetermined encryption method can be implemented based on a predetermined large number cluster (such as a finite field, an elliptic curve, etc.). The elements in the large number cluster here usually have the following characteristics: after the corresponding encryption operation, the obtained encryption result is still an element in the large number cluster.

[0060] According to one implementation, this predetermined encryption method can be implemented through elliptic curve encryption. In the elliptic curve encryption method, the second party uses the second key β to encrypt each piece of second data. Taking a single piece of second data D 2i (i is an integer between 1 and n2) as an example, the second party can map it to a point H(D 2i ) on the elliptic curve through a calculation method such as a hash operation, and then use the key β to encrypt H(D 2i ) based on the point multiplication operation. The encryption result is recorded as β·H(D 2i ).

[0061] According to another implementation, this predetermined encryption method can be implemented through finite field encryption. In the finite field encryption method, the second party maps each piece of second data into the finite field and performs exponential encryption with the second key β as the exponent. Taking a single piece of second data D 2i as an example, the second party can map it to an element in the finite field through a calculation method such as taking the modulus of the prime number P that defines the finite field, such as (D 2i ) % P, or H(D 2i ) % P. Here, % represents taking the modulus, and H represents the hash operation. Then, perform modular exponentiation calculation with the second key β for encryption. The encryption result is: (D 2i )β % P, or H(D 2i )β % P.

[0062] In other implementations, the second party can also encrypt each piece of second data using other predetermined encryption methods, and the obtained encryption results are recorded as respective second reference ciphertexts. The second party can provide the corresponding n2 second reference ciphertexts to the first party. Optionally, to further avoid privacy leakage, the second party can also shuffle the order of the respective second reference ciphertexts and then provide them to the first party.

[0063] It should be noted that step 200 can be executed offline or online. Here, online execution is the process from the start to the end of the private set intersection. Offline execution can be an operation independent of online execution. The results of offline execution can be used during online execution, while offline execution does not require any operation results of online execution. Therefore, in Figure 2 step 200 is represented by a dashed box. In this way, for some data processing processes, they can be executed offline as a preprocessing process and pre-executed between the first party and the second party, and can be carried out during the calculation of one party or the communication gap between the two parties, thereby saving online computing and communication volume.

[0064] Step 210, the first party and the second party perform a predetermined encryption operation, so that the first party obtains respective first reference ciphertexts obtained by encrypting each piece of first data under the predetermined encryption method via the second key β.

[0065] The predetermined encryption operation in this step 210 can be an encryption process implemented through key permutation, for example, including the following sub-steps 211 to step 213.

[0066] Sub-step 211, the first party encrypts each piece of first data under the predetermined encryption method via the first key r, obtains respective first ciphertexts corresponding to each piece of first data, and provides them to the second party.

[0067] Here, the encryption process of the first party for the first data is similar to the encryption process of the second party for the second data in step 200, and will not be elaborated here. A single piece of first data is denoted as D 1j (j is an integer from 1 to n1), and the encryption result can be, for example, the point multiplication encryption result r·H(D 1j ) under elliptic curve encryption, or the exponential encryption result (D 1j )r%P, H(D 1j )r%P, etc. under finite field encryption.

[0068] Step 212, the second party encrypts each of the first ciphertexts under the second key β in the predetermined encryption method, and after shuffling the obtained second ciphertexts, feeds them back to the first party.

[0069] It can be understood that the second ciphertext is the double ciphertext of the first data, that is, the encryption result obtained by double encrypting the first data with the first key r and the second key β. Here, each first ciphertext is encrypted with the second key β in a predetermined encryption method, and the encryption process is similar to that of encrypting each second data with the second key β in the predetermined encryption method, which will not be elaborated here. A single first data D 1j The corresponding single second ciphertext is, for example, the point multiplication encryption result β·r·H(D 1j ) under elliptic curve encryption, or the exponential encryption result (D 1j )rβ%P, H(D 1j )rβ%P, etc.

[0070] The second party can feedback each second ciphertext to the first party. However, if the second party feedbacks the second ciphertexts in the original order, the first party can correspond each second ciphertext with the first data. To avoid the first party obtaining effective information of the intersection data based on the relative positions of the second ciphertexts, the second party can feedback each second ciphertext to the first party after scrambling. In this way, the first party cannot correspond the second ciphertexts with the first data.

[0071] Step 213, the first party processes each second ciphertext with the inverse r -1 of the first key in a predetermined encryption method to obtain each first reference ciphertext corresponding to each first data.

[0072] Among them, the first party can use the inverse r -1 of the first key as a new key to further encrypt each second ciphertext in a predetermined encryption method. A single first data D 1j The corresponding single second ciphertext is, for example, the point multiplication encryption result r -1 ·β·r·H(D 1j ) under elliptic curve encryption, or the exponential encryption result (D 1j )rβr(-1)%P, H(D 1j )rβr(-1)%P, etc. Since the predetermined encryption method satisfies the commutative law of multiplication, if r -1 ·r = 1 is substituted, the encryption result is equivalent to the point multiplication encryption result β·H(D 1j ) under elliptic curve encryption, or the exponential encryption result (D 1j )β%P, H(D 1j )β%P, etc. This encryption result is equivalent to the encryption result of directly encrypting each first data by the second party with the second key β through the predetermined encryption method. That is to say, the encryption result of encrypting the first data with the first key r is replaced with the encryption result of encrypting with the second key β. In this specification, it can be called the first reference ciphertext.

[0073] Step 220: The first party compares each first reference ciphertext with each second reference ciphertext corresponding to each piece of second data, so as to determine at least one data identifier of the second reference ciphertext corresponding to the intersection of the first data and the second data.

[0074] Wherein, the data identifier here is used to identify the second reference ciphertext, and it may include at least one piece of information such as the line number and relative storage position of the second reference ciphertext. Through a single data identifier, a single second reference ciphertext indicated can be determined.

[0075] According to the foregoing, the first reference ciphertext is equivalent to the ciphertext data obtained by encrypting the first data with the second key β held by the second party in a predetermined encryption method. The second reference ciphertext is the ciphertext data obtained by encrypting the first data with the second key β in a predetermined encryption method. If a single piece of first data is the same as a single piece of second data, then their corresponding first reference ciphertext and second reference ciphertext are also the same. Therefore, the first party can compare each first reference ciphertext with a single second reference ciphertext. When a single first reference ciphertext is the same as a single second reference ciphertext, the corresponding first data and second data are the intersection of the two parties' data.

[0076] In this way, by comparing the first reference ciphertext and the second reference ciphertext, the first party can determine the data identifier corresponding to the intersection of the two parties' data for each second reference ciphertext. For example, it is the line number or relative storage position of the second reference ciphertext, etc. The first party can obtain at least one data identifier describing the intersection.

[0077] Step 230: The first party provides the second party with the above at least one data identifier.

[0078] Step 240: The second party determines the intersection of the first data and the second data based on each data identifier.

[0079] The second party can determine the corresponding pieces of second data according to each data identifier. In the case where the second reference ciphertext provided by the second party to the first party is in a scrambled order, the second party can first determine the position information of the second reference ciphertext corresponding to the intersection data according to each data identifier, and then determine each piece of second data corresponding to each data identifier fed back by the first party according to the corresponding relationship before and after scrambling, and determine it as the intersection data with the first data.

[0080] Through Figure 2 the above interaction process shown, the second party can obtain the intersection data among n1 pieces of first data and n2 pieces of second data, and the first party cannot learn the effective information of the intersection data.

[0081] Furthermore, the first party and the second party are independent business parties and each executes the corresponding process. In order to clarify the operations performed by the first party and the second party respectively,Figure 3 , Figure 4 shows the processes respectively executed by the first party and the second party during the private set intersection process.

[0082] As Figure 3 shown, the process executed by the first party may include:

[0083] Step 301: Perform a predetermined encryption operation with the second party to obtain respective first reference ciphertexts obtained by encrypting each piece of first data under a predetermined encryption method via the second key β;

[0084] Step 302: Compare each first reference ciphertext with each second reference ciphertext corresponding to each piece of second data, so as to determine at least one data identifier of the second reference ciphertext corresponding to the intersection of the first data and the second data, wherein the second reference ciphertext is provided by the second party after encrypting each of the n2 pieces of second data through a predetermined encryption method under the second key β;

[0085] Step 303: Provide the above at least one data identifier to the second party for the second party to determine the intersection of the first data and the second data based on each data identifier.

[0086] As Figure 4 shown, the process executed by the second party may include:

[0087] Step 401: Perform a predetermined encryption operation with the first party, so that the first party obtains respective first reference ciphertexts obtained by encrypting each piece of first data under a predetermined encryption method via the second key β;

[0088] Step 402: Determine the intersection of the first data and the second data according to the at least one data identifier received from the first party.

[0089] Wherein, the above at least one data identifier is determined by the first party comparing each first reference ciphertext and each second reference ciphertext, and is used to indicate the second reference ciphertext corresponding to the intersection of the first data and the second data. In addition, each second reference ciphertext is obtained by the second party encrypting each piece of second data under a predetermined encryption method via the second key β and provided to the first party.

[0090] It should be noted that Figure 3 , Figure 4 the processes executed by the first party and the second party shown respectively are consistent with the operations executed by the first party and the second party in Figure 2 , and the operations executed by the first party and the second party in Figure 2 are also applicable to the processes shown in Figure 3 , Figure 4 , and will not be elaborated here. Figure 2 , Figure 3 , Figure 4Some of the steps shown are only for one implementation example. In practice, without substantially affecting the result, some steps can be swapped in order. For example, Figure 3 in Figure 3 , the process in which the second party encrypts each piece of second data to obtain each second reference ciphertext can be a step pre-executed offline, or a step executed before, after, or simultaneously with step 301 in the online private set intersection process. This specification does not make any limitations on this.

[0091] Reviewing the above process, in the process of private set intersection between two parties with a large difference in data volume, in order to meet the business requirements that the party with a large data volume can obtain the data intersection and the party with a small data volume cannot know the effective information of the intersection, the party with a large data volume provides the ciphertext of the local data to the party with a small data volume in advance as the reference ciphertext of the local data. In the online private set intersection process, the two parties perform a predetermined encryption operation so that the party with a small data volume obtains the ciphertext of the local data encrypted by the key of the party with a large data volume as the reference ciphertext. In this way, the party with a small data volume can compare the reference ciphertexts of the two parties' data to determine the data identifiers of the intersection data. Thus, the party with a large data volume determines the data intersection based on the data identifiers, and the party with a small data volume cannot obtain the effective information of the intersection. This method can complete the private set intersection service in the case of data volume imbalance with less communication volume and improve the effectiveness of private set intersection.

[0092] According to an embodiment of another aspect, there is also provided a device for private set intersection that can be disposed in a single participating party. The device for private set intersection is used for the first party holding n1 pieces of first data and the first key r and the second party holding n2 pieces of second data and the second key β, where n1 < n2, and the second party obtains the intersection of the n1 pieces of first data and the n2 pieces of second data, and the first party cannot obtain the effective information of the intersection data. Since the technical concept of this specification is proposed based on the private set intersection process of two participating parties with unbalanced data volume, the devices disposed in the first party and the second party can be different.

[0093] Referring to Figure 5 as shown, the private set intersection device 500 disposed in the first party, which is the party with a small data volume, may include:

[0094] A secure computing unit 501, configured to perform a predetermined encryption operation with the second party to obtain each first reference ciphertext obtained by encrypting each piece of first data with the second key β in a predetermined encryption method;

[0095] A comparison unit 502, configured to compare each first reference ciphertext with each second reference ciphertext corresponding to each piece of second data, so as to determine at least one data identifier of the second reference ciphertext corresponding to the intersection of the first data and the second data, where the second reference ciphertext is provided after the second party encrypts each of the n2 pieces of second data through a predetermined encryption method under the second key β;

[0096] A providing unit 503 is configured to provide the at least one data identifier to a second party for the second party to determine the intersection of the first data and the second data based on each data identifier.

[0097] Reference Figure 6 As shown, the private intersection device 600 of the second party located at the party holding a large amount of data may include:

[0098] A secure computing unit 601, configured to perform a predetermined encryption operation with a first party, so that the first party obtains respective first reference ciphertexts obtained by encrypting each piece of first data with a second key β in a predetermined encryption manner;

[0099] An intersection determination unit 602, configured to determine the intersection of the first data and the second data according to at least one data identifier received from the first party. Here, the at least one data identifier is determined by the first party comparing each first reference ciphertext and each second reference ciphertext, and is used to indicate the second reference ciphertext corresponding to the intersection of the first data and the second data. Each second reference ciphertext is obtained by the second party encrypting each piece of second data with a second key β in a predetermined encryption manner and providing it to the first party.

[0100] Wherein, the secure computing unit 501 located at the first party and the secure computing unit 601 located at the second party may complete the predetermined encryption operation through the following interaction:

[0101] The first party encrypts each piece of first data with a first key r in a predetermined encryption manner, obtains respective first ciphertexts corresponding to each piece of first data, and provides them to the second party;

[0102] The second party encrypts each of the first ciphertexts with a second key β in a predetermined encryption manner, and after performing a scrambling operation on the obtained second ciphertexts, feeds them back to the first party;

[0103] The first party processes each of the second ciphertexts with the inverse r of the first key -1 in a predetermined encryption manner to obtain respective first reference ciphertexts corresponding to each piece of first data.

[0104] It should be noted that Figure 5 、 Figure 6 The devices shown respectively correspond to Figure 3 、 Figure 4 the method embodiments shown, and respectively correspond to the first party and the second party in the embodiments shown in Figure 2 . Therefore, Figure 2 、 Figure 3 、 Figure 4 the corresponding descriptions in the method embodiments of Figure 5 、 Figure 6The described device will not be elaborated here.

[0105] According to an embodiment of another aspect, there is also provided a computer-readable storage medium having stored thereon a computer program, which, when executed in a computer, causes the computer to execute the method described in conjunction with Figure 3 or Figure 4 and so on.

[0106] According to an embodiment of yet another aspect, there is also provided a computing device including a memory and a processor, where the memory stores executable code, and when the processor executes the executable code, the method described in conjunction with Figure 3 or Figure 4 and so on is implemented.

[0107] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the embodiments of this specification can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0108] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the technical concept of this specification. It should be understood that the above are only specific embodiments of the technical concept of this specification and are not used to limit the protection scope of the technical concept of this specification. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the embodiments of this specification should be included within the protection scope of the technical concept of this specification.

Claims

1. A method for private set intersection, which is used for a first party holding n1 pieces of first data and a first key r, and a second party holding n2 pieces of second data and a second key β, where n1 < n2, to obtain the intersection of the n1 pieces of first data and the n2 pieces of second data by the second party; The method is executed by a first party and includes: Performing a predetermined encryption operation with a second party to obtain respective first reference ciphertexts obtained by encrypting each piece of first data under a predetermined encryption method via a second key β; Comparing each first reference ciphertext with respective second reference ciphertexts corresponding to each piece of second data, so as to determine at least one data identifier of the second reference ciphertext corresponding to the intersection of the first data and the second data, wherein the second reference ciphertexts are provided by the second party after encrypting each of n2 pieces of second data through a predetermined encryption method under the second key β; Providing the at least one data identifier to the second party for the second party to determine the intersection of the first data and the second data based on each data identifier; Wherein, the predetermined encryption operation includes: The first party encrypts each piece of first data via a first key r under a predetermined encryption method to obtain respective first ciphertexts corresponding to each piece of first data and provides them to the second party; The second party encrypts each of the first ciphertexts via the second key β under a predetermined encryption method, and performs a scrambling operation on the obtained second ciphertexts and then feeds them back to the first party; The first party processes each second ciphertext through the inverse r of the first key under a predetermined encryption method to obtain each first reference ciphertext corresponding to each piece of first data. -1 Process each second ciphertext to obtain each first reference ciphertext corresponding to each piece of first data respectively.

2. The method according to claim 1, wherein, The predetermined encryption method is implemented based on a predetermined cluster that satisfies the following condition: the fusion result of any two elements in the predetermined cluster under the predetermined encryption method is still an element in the predetermined cluster; For a single element in the predetermined cluster, the two encryption processes in sequence according to the predetermined encryption method are commutative.

3. The method according to claim 2, wherein: In the case where the predetermined cluster is a finite field defined by a prime number P, the predetermined encryption method is exponential encryption; In the case where the predetermined cluster is a point group on an elliptic curve, the predetermined encryption method is point multiplication encryption.

4. The method according to claim 1, wherein the difference between n1 and n2 is greater than a predetermined threshold, where The difference between n1 and n2 is measured by a difference or a ratio.

5. The method according to claim 1, wherein, The data identifier is the position information of the intersection of the first data and the second data in each second reference ciphertext.

6. The method according to claim 1, wherein, The product of the first key r and its inverse is 1.

7. A method for private set intersection, which is used for a first party holding n1 pieces of first data and a first key r, and a second party holding n2 pieces of second data and a second key β, where n1 < n2, to obtain the intersection of the n1 pieces of first data and the n2 pieces of second data by the second party; The method is executed by a second party and includes: Performing a predetermined encryption operation with a first party, so that the first party obtains respective first reference ciphertexts obtained by encrypting each piece of first data under a predetermined encryption method via a second key β; Determining the intersection of the first data and the second data according to at least one data identifier received from the first party, where the at least one data identifier is determined by the first party comparing each first reference ciphertext with each second reference ciphertext and is used to indicate the second reference ciphertext corresponding to the intersection of the first data and the second data, and each second reference ciphertext is obtained by the second party encrypting each piece of second data via a second key β under a predetermined encryption method and provided to the first party; Wherein, the predetermined encryption operation includes: The first party encrypts each piece of first data via a first key r under a predetermined encryption method to obtain respective first ciphertexts corresponding to each piece of first data and provides them to the second party; The second party encrypts each of the first ciphertexts via the second key β under a predetermined encryption method, and performs a scrambling operation on the obtained second ciphertexts and then feeds them back to the first party; The first party processes each second ciphertext through the inverse r of the first key in a predetermined encryption method to obtain each first reference ciphertext corresponding to each piece of first data. -1 Process each second ciphertext to obtain each first reference ciphertext corresponding to each piece of first data respectively.

8. The method according to claim 7, wherein, The predetermined encryption method is implemented based on a predetermined cluster that satisfies the following conditions: the fusion result of any two elements in the predetermined cluster under the predetermined encryption method is still an element in the predetermined cluster; For a single element in the predetermined cluster, the two encryption processes in sequence according to the predetermined encryption method are commutative.

9. The method according to claim 8, wherein: When the predetermined cluster is a prime number group, the predetermined encryption method is exponential encryption; When the predetermined cluster is a point group on an elliptic curve, the predetermined encryption method is point multiplication encryption.

10. The method according to claim 7, wherein the difference between n1 and n2 is greater than a predetermined threshold, where The difference between n1 and n2 is measured by a difference or a ratio.

11. The method according to claim 7, wherein The data identifier is the position information of each position in the intersection of the first data and the second data in the second reference ciphertext; Determining the intersection of the first data and the second data according to at least one data identifier received from the first party includes: Determining each second data corresponding to each position information as the intersection of the first data and the second data.

12. A device for private set intersection, which is used for a first party holding n1 pieces of first data and a first key r and a second party holding n2 pieces of second data and a second key β, where n1 < n2, and the second party obtains the intersection of the n1 pieces of first data and the n2 pieces of second data; The device is disposed in the first party and includes: A secure computing unit configured to perform a predetermined encryption operation with the second party to obtain each first reference ciphertext obtained by encrypting each piece of first data under the predetermined encryption method via the second key β; A comparison unit configured to compare each first reference ciphertext with each second reference ciphertext corresponding to each piece of second data, so as to determine at least one data identifier of the second reference ciphertext corresponding to the intersection of the first data and the second data, wherein the second reference ciphertext is provided by the second party after encrypting each of the n2 pieces of second data through the predetermined encryption method under the second key β; A providing unit configured to provide the second party with the at least one data identifier for the second party to determine the intersection of the first data and the second data based on each data identifier; Wherein, the predetermined encryption operation includes: The first party encrypts each piece of first data under the predetermined encryption method via the first key r to obtain each first ciphertext corresponding to each piece of first data and provides it to the second party; The second party encrypts each of the first ciphertexts under the second key β in the predetermined encryption method, and after scrambling the obtained second ciphertexts, feeds them back to the first party; The first party processes each second ciphertext through the inverse r of the first key under a predetermined encryption method to obtain each first reference ciphertext corresponding to each piece of first data. -1 Process each second ciphertext to obtain each first reference ciphertext corresponding to each piece of first data respectively.

13. A device for private intersection, which is used for a first party holding n1 pieces of first data and a first key r and a second party holding n2 pieces of second data and a second key β, where n1 < n2, and the second party obtains the intersection of the n1 pieces of first data and the n2 pieces of second data; The device is disposed in the second party and includes: A secure computing unit configured to perform a predetermined encryption operation with the first party, so that the first party obtains each first reference ciphertext obtained by encrypting each piece of first data under the predetermined encryption method via the second key β; An intersection determination unit configured to determine the intersection of the first data and the second data according to at least one data identifier received from the first party, the at least one data identifier is determined by the first party comparing each first reference ciphertext and each second reference ciphertext, and is used to indicate the second reference ciphertext corresponding to the intersection of the first data and the second data, and each second reference ciphertext is obtained by the second party encrypting each piece of second data under the predetermined encryption method via the second key β and provided to the first party; Wherein, the predetermined encryption operation includes: The first party encrypts each piece of first data under the predetermined encryption method via the first key r to obtain each first ciphertext corresponding to each piece of first data and provides it to the second party; The second party encrypts each of the first ciphertexts under a predetermined encryption method via the second key β, and after performing a scrambling operation on the obtained second ciphertexts, feeds them back to the first party; The first party processes each second ciphertext through the inverse r of the first key under a predetermined encryption method to obtain each first reference ciphertext corresponding to each piece of first data. -1 Process each second ciphertext to obtain each first reference ciphertext corresponding to each piece of first data respectively.

14. A computer-readable storage medium, having stored thereon a computer program, which when executed on a computer, causes the computer to execute the method according to any one of claims 1-11.

15. A computing device, comprising a memory and a processor, characterized in that, Executable code is stored in the memory, and when the processor executes the executable code, the method according to any one of claims 1-11 is implemented.