A privacy set intersection method based on additive homomorphic encryption of national secret SM2

By adopting the additive homomorphic encryption algorithm based on Guomi SM2 and Shamir secret sharing solution in the multi-party privacy set intersection technology, the problems of low efficiency and non-compliance with the requirements of cyberspace security and autonomous controllable are solved in the existing technology, and efficient and secure multi-party privacy set intersection calculation is achieved.

CN116248247BActive Publication Date: 2025-05-06CHONGQING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211550211.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-05
Publication Date
2025-05-06
Estimated Expiration
2042-12-05

AI Technical Summary

Technical Problem

The existing multi-party privacy collection intersection technology mainly relies on foreign homomorphic encryption technology, which cannot meet the requirements of security, autonomous and controllable cyberspace, and is also inefficient in processing big data.

Method used

The addition homomorphic encryption algorithm based on the National Secret SM2 is adopted, and the encryption algorithm parameters and key pairs are generated through the trusted center, and large-scale data calculations are used for cloud servers, and data privacy protection is achieved through the Shamir secret sharing solution.

Benefits of technology

While ensuring data security, it improves the efficiency of multi-party privacy set intersection computing, is suitable for big data scenarios, and meets the requirements of security, autonomous and controllable cyberspace.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116248247B_ABST
    Figure CN116248247B_ABST
Patent Text Reader

Abstract

The present invention claims protection for a privacy set intersection method based on the national cryptographic SM2 additive homomorphism encryption, which is characterized by the following: four entities, namely, a trusted center, a cloud server CS, a designated participant, and other participants, where: the trusted center is responsible for generating the parameters required to implement the set intersection; the cloud server CS is responsible for processing a large amount of data; the designated participant is used to input its original data set and calculate the parameter s required for decryption k , and obtain the intersection of all input sets; other participants are used to input their original data sets and calculate the parameter s k . The present invention protects the privacy attributes of the input set elements and their sizes of multiple participants in the set intersection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of secure multi-party computing, and in particular to a privacy set intersection method based on additive homomorphic encryption of national secret SM2, which can be used to protect the privacy of input set elements and their sizes of multiple participants in the set intersection. Background Art

[0002] Privacy data protection originated from secure multi-party computing. The millionaire problem proposed by Professor Yao Qizhi is a classic problem of secure multi-party computing. The current solution to this problem is not ideal and has a great impact in practical applications. With the advent of the Internet big data era, a large amount of data is generated all the time in various applications used by people. It is precisely because of the generation of these data that better services can be provided to people. While enjoying these services, the problem of personal privacy data leakage will also arise. Nowadays, people's awareness of protecting their more sensitive data is gradually increasing. Therefore, in order to achieve data availability but invisible and avoid the phenomenon of data islands, how to complete related calculations under the premise of protecting user data privacy has become a hot issue of concern in the academic community.

[0003] Nowadays, the privacy-preserving set intersection technology is relatively mature in the environment of two participants. There are fewer studies on the multi-party privacy set intersection, but its research is of great significance. For example, in a company, it is necessary to confirm the credit report of employees, and each person's credit report is composed of multiple indicators, which are controlled by different institutions. The institutions have a list of people who have completed the indicator. If the company needs to judge the credit of an employee, it needs to determine whether the employee belongs to the intersection of the lists of those institutions. In this scenario, the multi-party privacy set intersection technology is needed.

[0004] The problem of the intersection of multiple privacy sets can be solved by using homomorphic encryption technology. However, existing solutions are designed based on foreign homomorphic encryption technology, which does not meet the requirements of autonomous and controllable cyberspace security and has low efficiency.

[0005] CN111641603A, a privacy set intersection data interaction method based on homomorphic encryption, and corresponding computer media, in addition, the present invention also provides a privacy set intersection data interaction system based on homomorphic encryption. The privacy set intersection data interaction method based on homomorphic encryption provided by the present invention performs multi-layer encryption on the data of the client and the server respectively, during the data interaction process, neither the client nor the server can obtain the plaintext data of the other party, thereby ensuring the privacy of the data, and the multi-layer encryption greatly reduces the risk of data leakage.

[0006] When encrypting data, this technology performs multiple layers of encryption on the data and uses RSA to encrypt the ciphertext, which is more secure. However, this reduces the efficiency and is not suitable for scenarios with large amounts of data. The present invention uses an additive homomorphic encryption algorithm based on the national secret SM2. While ensuring security, it entrusts the calculation of a large amount of related data to the cloud server, effectively improving efficiency. Summary of the invention

[0007] The present invention aims to solve the above problems of the prior art. A privacy set intersection method based on additive homomorphic encryption of the national secret SM2 is proposed. The technical solution of the present invention is as follows:

[0008] A privacy set intersection method based on additive homomorphic encryption of the national secret SM2, comprising the following steps:

[0009] (1) The trusted center generates encryption algorithm parameters, generates a key pair (pk, sk), generates secret shares related to the private key sk and distributes them to each participant, and sends the parameters and public key pk to each participant; (2) All participants P1,...,P N Hold confidential collections separately All participants will share their own secret sets S1,...,S N Using 0-1 encoding, construct array M i , where N represents the number of participants, Q represents the total ordered set, and the total number of elements in the total ordered set is l, q i represents an element in the total ordered set; (3) all participants P i Use the public key pk to encrypt the self-encoded array M i , get the encrypted array E(M i ), and the encrypted array E(M i ) sent to the cloud server CS;

[0010] (4) The cloud server CS receives all participants P i (i=1,2,...,N) sent by E(M i ) and then use the additive homomorphic encryption properties of SM2 to encrypt E(M i ) to obtain the summed array E(W), and send E(W) to all participants P i (i=1,2,...,N);

[0011] (5) All participants P i After obtaining the array E(W), for all elements in the array E(W), calculate s according to the Shamir secret sharing scheme. k , participant P i(i=1,2,...,N-1) After calculating s k Afterwards, k Sent to the designated participant P N , where s k It is the partial value of calculating sk;

[0012] (6) Designated participant P N Calculate [sk]u' k That is, other participants P i (i=1,2,...,N-1) sent s k Then calculate [m]G and recover m from [m]G, where m represents the plaintext message and [m]G represents the elliptic curve point containing the plaintext message m. Then get the intersection S0 of the set based on m and send the intersection S0 to other participants P. i (i=1,2,...,N-1), where in order to prevent the private key sk from being disclosed to any participant, sk should not be calculated directly, but should be hidden in [sk]u' k Privacy set intersection is an important part of information security and an important branch of secure multi-party computation. It has a wide range of applications in real life, such as measuring advertising conversion rates, fingerprint matching, botnets, and searching for potential friendships through social networks.

[0013] Furthermore, in step (1), the trusted center selects parameters of the encryption algorithm, generates a key pair (pk, sk), generates secret shares related to sk, and distributes the secret shares, specifically:

[0014] (2a) The trusted center selects the parameters of the encryption algorithm, including: selecting the finite field F p The scale p; choose the elliptic curve E(F p ) Two elements a, b∈F of the equation p ; Select E(F p ) on the base point G=(X G ,Y G ), where G≠O,X G and Y G Yes F p Two elements in; the order n of the generated base point G;

[0015] (2b) The trusted center generates a key pair (pk, sk), including: generating a random private key sk∈[2,...,n-1]; calculating an encryption public key pk=[sk]G;

[0016] (2c) The trusted center randomly selects a t-1 order polynomial f(x) and calculates the secret share y of each participant i , and send it to the i-th participant P i, which is expressed as follows:

[0017]

[0018] y i =f(i),

[0019] where a j ∈[2,...,n-1], j represents the subscript of a term in the polynomial, a j represents the coefficient of the j-th polynomial, a j x j represents the j-th polynomial, a0 represents the first constant term of the polynomial, and f(i) represents the participant U i Substituting i into f(x) yields the result, y i Denote the i-th secret share, and let a0 = sk, i∈[1,N]. Further, in step (2), all participants set their own secret sets S1,...,S N Using 0-1 encoding, construct array M i , which is expressed as follows:

[0020] M i ={m i1 ,m i2 ,...,m il},

[0021]

[0022] Where i = 1, 2, ..., N, N represents the number of participants, j = 1, 2, ..., l, l represents the number of elements in the total ordered set Q. ij Represents the participant P i A collection of secrets for yourself i The value obtained by encoding the j-th element in 0-1.

[0023] Furthermore, in step (3), all participants P i Use the public key pk to encrypt the self-encoded array M i , get the encrypted array E(M i ), which is expressed as follows:

[0024] E(M i )={E(m i1 ),E(m i2 ),...,E(m il )}={(u i1 ,v i1 ),(u i2 ,v i2 ),...,(u il ,v il )},

[0025] (u ij ,v ij )=([k ij ]G,[m ij ]G+[k ij ]pk),

[0026] Where i = 1, 2, ..., N, N represents the number of participants, j = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u ij Represents the participant P i For m ij The first part of the encrypted ciphertext, v ij Represents the second part of the ciphertext, k ij represents a random number, G represents the base point on the elliptic curve, and pk represents the encrypted public key.

[0027] Furthermore, in step (4), the cloud server receives E(M i ), we use the additive homomorphic encryption property of SM2 to encrypt E(M i ) and the summed array E(W) is obtained, which is expressed as follows:

[0028] E(W)={E(W1),E(W2),...,E(W l )},

[0029]

[0030] Where i = 1, 2, ..., N, N represents the number of participants, k = 1, 2, ..., l, j = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, k ij represents a random number, G represents the base point on the elliptic curve, and pk represents the encrypted public key. u' k represents the result of summing the first part of the k-th array encrypted by all participants, v' k Represents the result of the second part of the summation.

[0031] Furthermore, in step (5), all participants calculate s for all elements in the array E(W) according to the Shamir secret sharing scheme. k , which is expressed as follows:

[0032] s k =[y i Δ i (0)modq]u' k ,

[0033]

[0034] Among them, yi Represents participant P i The secret share, k = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u' k represents the kth element E(W) in the array E(W) k ), where N represents the number of participants.

[0035] Shamir secret sharing scheme: The trusted center gives n participants {U1,U2,...,U n}Distribute secret shares so that only any t or more honest participants can reconstruct the secret information s, and any participant less than t cannot obtain any information about the secret s.

[0036] Furthermore, the specific implementation of step (6) is as follows:

[0037] (7a) Designated participant P N Calculate [sk]u' k , that is, other participants P i (i=1,2,...,N-1) sent s k The sum of:

[0038]

[0039] Among them, y i Represents participant P i The secret share, k = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u' k represents the kth element E(W) in the array E(W) k ), where N represents the number of participants;

[0040] (7b) Designated Participant P N Calculate [m k ]G, thus we get m k :

[0041] [m k ]G=v' k -[sk]u' k ,

[0042] Among them, v' k represents the kth element E(W) in the array E(W) k )’s second ciphertext;

[0043] (7c) Designated Party P N Calculate m k After that, initialize an empty set S0 and judge m k Is it equal to 0?

[0044] If so, then the element q k Add to set S0;

[0045] Otherwise, no operation is performed on set S0;

[0046] Output the final set S0, which is the intersection of all participants’ input sets;

[0047] The advantages and beneficial effects of the present invention are as follows:

[0048] First, the invention uses an additive homomorphic encryption algorithm based on the national secret SM2 for data encryption and decryption. As for using homomorphic encryption technology to solve the problem of intersection of multiple privacy sets, current solutions are designed based on foreign homomorphic encryption technology, which does not meet the requirements of autonomous and controllable cyberspace security.

[0049] Second, in the process of processing set data, the present invention uses 0-1 coding to encode the sets of all participants into sets with the same size as the total ordered set, so that all other participants except the participant itself cannot obtain the size of its set, thereby realizing the hiding of the set size input by other participants;

[0050] Third, the present invention entrusts a large amount of computing content to the cloud server, which greatly improves the computing efficiency, and the content delivered to the cloud server is encrypted to protect the data from leakage. During calculation, due to the nature of homomorphic encryption, the cloud server can directly perform calculations on the ciphertext. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 It is a flowchart of a privacy set intersection method based on additive homomorphic encryption of the national encryption SM2 in a preferred embodiment provided by the present invention. DETAILED DESCRIPTION

[0052] The following will describe the technical solutions in the embodiments of the present invention in detail in conjunction with the accompanying drawings in the embodiments of the present invention. The described embodiments are only part of the embodiments of the present invention.

[0053] The technical solution of the present invention to solve the above technical problems is:

[0054] This example includes four entities: the trusted center, the cloud server CS, the designated participants, and other participants. Among them:

[0055] A trusted center, which is responsible for generating the parameters required to achieve set intersection;

[0056] Cloud Server CS, which is responsible for processing large amounts of data;

[0057] Specify the participant, who is used to input his original data set and calculate the parameter s required for decryption k , and get the intersection of all input sets;

[0058] Other participants use it to input their original data set and calculate the parameter s required for decryption. k .

[0059] Reference Figure 1 , the implementation steps of this example are as follows:

[0060] Step 1: System initialization.

[0061] 1.1) The trusted center selects the parameters of the encryption algorithm, including: selecting the finite field F p The scale p; choose the elliptic curve E(F p ) Two elements a, b∈F of the equation p ; Select E(F p ) on the base point G=(X G ,Y G ), where G≠O,X G and Y G Yes F p Two elements in; the order n of the generated base point G;

[0062] 1.2) The trusted center generates a key pair (pk, sk), including: generating a random private key sk∈[2,...,n-1]; calculating the encryption public key pk=[sk]G;

[0063] 1.3) The trusted center randomly selects a t-1 order polynomial f(x) and calculates the secret share y of each participant i , and send it to the i-th participant P i , which is expressed as follows:

[0064]

[0065] y i =f(i),

[0066] where a j ∈[2,...,n-1], and let a0=sk, i∈[1,N].

[0067] Step 2: All participants P1,...,P N Separate collections All participants will share their own secret sets S1,...,S N Using 0-1 encoding, construct array M i , where N represents the number of participants and Q represents the total order set.

[0068] Mi ={m i1 ,m i2 ,...,m il},

[0069]

[0070] Among them, i=1,2,...,N, N represents the number of participants, j=1,2,...,l, l represents the number of elements in the total ordered set Q.

[0071] Step 3: All participants use the public key to encrypt the array, and the encrypted array is sent to the cloud server for processing and then sent to all participants.

[0072] 3.1) All participants P i Use the public key pk to encrypt the self-encoded array M i , get the encrypted array E(M i ), which is expressed as follows:

[0073] E(M i )={E(m i1 ),E(m i2 ),...,E(m il )}={(u i1 ,v i1 ),(u i2 ,v i2 ),...,(u il ,v il )},

[0074] (u ij ,v ij )=([k ij ]G,[m ij ]G+[k ij ]pk),

[0075] Where i = 1, 2, ..., N, N represents the number of participants, j = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, k ij represents a random number, G represents a base point on the elliptic curve, and pk represents an encrypted public key;

[0076] 3.2) The encrypted array E(M i ), and send the encrypted array to the cloud server CS;

[0077] 3.3) The cloud server receives E(M i ), we use the additive homomorphic encryption property of SM2 to encrypt E(M i ) and the summed array E(W) is obtained, which is expressed as follows:

[0078] E(W)={E(W1),E(W2),...,E(W l )},

[0079]

[0080] Where i = 1, 2, ..., N, N represents the number of participants, k = 1, 2, ..., l, j = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, k ij represents a random number, G represents the base point on the elliptic curve, and pk represents the encrypted public key.

[0081] Step 4: All participants calculate the parameter s according to the Shamir joint random secret sharing scheme k , and sends it to the designated participant, who calculates the parameter [sk]u' k , then calculate [m]G to get the decrypted data m, and get the intersection of the sets based on m, and finally send the intersection of the sets to other participants.

[0082] 4.1) All participants calculate s for all elements in the array E(W) according to Shamir's joint random secret sharing scheme k :

[0083] s k =[y i Δ i (0)modq]u' k ,

[0084]

[0085] Among them, y i Represents participant P i The secret share, k = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u' k represents the kth element E(W) in the array E(W) k ), where N represents the number of participants;

[0086] 4.2) Participant P i (i=1,2,...,N-1) After calculating s k Afterwards, k Sent to the designated participant P N ;

[0087] 4.3) Designated Participant P N Calculate [sk]u' k , that is, other participants P i (i=1,2,...,N-1) sent sk The sum of:

[0088]

[0089] Among them, y i Represents participant P i The secret share, k = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u' k represents the kth element E(W) in the array E(W) k ), where N represents the number of participants;

[0090] 4.4) Designated Participant P N Calculate [m k ]G, thus we get m k :

[0091] [m k ]G=v' k -[sk]u' k ,

[0092] Where k = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u' k represents the kth element E(W) in the array E(W) k )'s first ciphertext, v' k represents the kth element E(W) in the array E(W) k )’s second ciphertext;

[0093] 4.5) Designated Participant P N Calculate m k After that, initialize an empty set S0 and judge m k Is it equal to 0?

[0094] If so, then the element q k Add to set S0;

[0095] Otherwise, no operation is performed on set S0;

[0096] Output the final set S0, which is the intersection of all participants’ input sets;

[0097] Wherein, k=1,2,...,l, l represents the number of elements in the total ordered set Q.

[0098] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0099] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0100] The above embodiments should be understood to be only used to illustrate the present invention and not to limit the protection scope of the present invention. After reading the contents of the present invention, technicians can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.

Claims

1. A privacy set intersection method based on additive homomorphic encryption of the national secret SM2, characterized in that: The following steps are involved: (1) The trusted center generates encryption algorithm parameters, generates a key pair (pk, sk), generates secret shares related to the private key sk and distributes them to each participant, and sends the parameters and public key pk to each participant; (2) All participants P1,...,P N Hold confidential collections separately All participants will share their own secret sets S1,...,S N Using 0-1 encoding, construct array M i , where N represents the number of participants, Q represents the total ordered set, and the total number of elements in the total ordered set is l, q i represents an element in a total ordered set; (3) All participants P i Use the public key pk to encrypt the self-encoded array M i , get the encrypted array E(M i ), and the encrypted array E(M i ) is sent to the cloud server CS; (4) The cloud server CS receives all participants P i (i=1,2,...,N) sent by E(M i ) and then use the additive homomorphic encryption properties of SM2 to encrypt E(M i ) to obtain the summed array E(W), and send E(W) to all participants P i (i=1,2,...,N); (5) All participants P i After obtaining the array E(W), for all elements in the array E(W), calculate s according to the Shamir secret sharing scheme. k , participant P i (i=1,2,...,N-1) After calculating s k Afterwards, k Sent to the designated participant P N , where s k It is the partial value of calculating sk; (6) Designated participant P N Calculate [sk]u' k That is, other participants P i (i=1,2,...,N-1) sent s k Then calculate [m]G and recover m from [m]G, where m represents the plaintext message and [m]G represents the elliptic curve point containing the plaintext message m. Then get the intersection S0 of the set based on m and send the intersection S0 to other participants P. i (i=1,2,...,N-1), where in order to prevent the private key sk from being disclosed to any participant, sk should not be calculated directly, but should be hidden in [sk]u' k In; Privacy set intersection is an important part of information security.

2. According to claim 1, a privacy set intersection method based on additive homomorphic encryption of national secret SM2 is characterized in that: In step (1), the trusted center selects parameters of the encryption algorithm, generates a key pair (pk, sk), generates secret shares related to sk, and distributes the secret shares, specifically: (2a) The trusted center selects the parameters of the encryption algorithm, including: selecting the finite field F p The scale p; choose the elliptic curve E(F p ) Two elements a, b∈F of the equation p ; Select E(F p ) on the base point G=(X G ,Y G ), where G≠O,X G and Y G Yes F p Two elements in; the order n of the generated base point G; (2b) The trusted center generates a key pair (pk, sk), including: generating a random private key sk∈[2,...,n-1]; calculating an encryption public key pk=[sk]G; (2c) The trusted center randomly selects a t-1 order polynomial f(x) and calculates the secret share y of each participant i , and send it to the i-th participant P i , which is expressed as follows: y i =f(i), where a j ∈[2,...,n-1], j represents the subscript of a term in the polynomial, a j represents the coefficient of the j-th polynomial, a j x j represents the j-th polynomial, a0 represents the first constant term of the polynomial, and f(i) represents the participant U i Substituting i into f(x) yields the result, y i Denote the i-th secret share, and let a0=sk, i∈[1,N].

3. According to claim 2, a privacy set intersection method based on additive homomorphic encryption of national secret SM2 is characterized in that: In step (2), all participants send their own confidentiality sets S1,...,S N Using 0-1 encoding, construct array M i , which is expressed as follows: M i ={m i1 ,m i2 ,...,m il }, Where i = 1, 2, ..., N, N represents the number of participants, j = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, m ij Represents the participant P i A collection of secrets for yourself i The value obtained by encoding the j-th element in 0-1.

4. According to claim 3, a privacy set intersection method based on additive homomorphic encryption of national secret SM2 is characterized in that: In step (3), all participants P i Use the public key pk to encrypt the self-encoded array M i , get the encrypted array E(M i ), which is expressed as follows: E(M i )={E(m i1 ),E(m i2 ),...,E(m il )}={(u i1 ,v i1 ),(u i2 ,v i2 ),...,(u il ,v il )}, (u ij ,v ij )=([k ij ]G,[m ij ]G+[k ij ]pk), Where i = 1, 2, ..., N, N represents the number of participants, j = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u ij Represents the participant P i For m ij The first part of the encrypted ciphertext, v ij Represents the second part of the ciphertext, k ij represents a random number, G represents the base point on the elliptic curve, and pk represents the encrypted public key.

5. According to claim 4, a privacy set intersection method based on additive homomorphic encryption of national secret SM2 is characterized in that: In step (4), the cloud server receives E(M i ), we use the additive homomorphic encryption property of SM2 to encrypt E(M i ) and the summed array E(W) is obtained, which is expressed as follows: E(W)={E(W1),E(W2),...,E(W l )}, Where i = 1, 2, ..., N, N represents the number of participants, k = 1, 2, ..., l, j = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, k ij represents a random number, G represents the base point on the elliptic curve, pk represents the encrypted public key, u' k represents the result of summing the first part of the k-th array encrypted by all participants, v' k Represents the result of the second part of the summation.

6. According to claim 5, a privacy set intersection method based on additive homomorphic encryption of national secret SM2 is characterized in that: In step (5), all participants calculate s for all elements in the array E(W) according to the Shamir secret sharing scheme. k , which is expressed as follows: s k =[y i Δ i (0)mod q]u' k , Among them, y i Represents participant P i The secret share, k = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u' k represents the kth element E(W) in the array E(W) k ), where N represents the number of participants; Shamir secret sharing scheme: The trusted center gives n participants {U1,U2,...,U n }Distribute secret shares so that only any t or more honest participants can reconstruct the secret information s, and any participant less than t cannot obtain any information about the secret s.

7. According to claim 6, a privacy set intersection method based on additive homomorphic encryption of national secret SM2 is characterized in that: The specific implementation of step (6) is as follows: (7a) Designated participant P N Calculate [sk]u' k , that is, other participants P i (i=1,2,...,N-1) sent s k The sum of: Among them, y i Represents participant P i The secret share, k = 1, 2, ..., l, l represents the number of elements in the total ordered set Q, u' k represents the kth element E(W) in the array E(W) k ), where N represents the number of participants; (7b) Designated Participant P N Calculate [m k ]G, thus we get m k : [m k ]G=v' k -[sk]u' k , Among them, v' k represents the kth element E(W) in the array E(W) k )’s second ciphertext; (7c) Designated Party P N Calculate m k After that, initialize an empty set S0 and judge m k Is it equal to 0? If so, then the element q k Add to set S0; Otherwise, no operation is performed on set S0; Output the final set S0, which is the intersection of all participants’ input sets.

Citation Information

Patent Citations

  • Set intersection method for realizing multi-party privacy

    CN113518092A

  • Privacy protection set intersection acquisition method and device based on domestic cryptographic algorithm

    CN114640444A