Multi-party dataset intersection method, apparatus, device, and storage medium
Patent Information
- Application Number
- CN202211586155.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2042-12-09
AI Technical Summary
[0005]本申请实施例提供了一种多方数据集求交集方法、装置、设备和存储介质,以至少解决相关技术中多方数据集求交集过程的安全性较低的问题
[0028]Compared to related technologies, the multi-party dataset intersection method, apparatus, device, and storage medium provided in this application embodiment solves the problem of low security in the multi-party dataset intersection process in related technologies. This is achieved by having multiple participating members encrypt their respective datasets using their private keys, resulting in multiple first encrypted data. Then, each participating member is designated as a target member, and other participating members encrypt the target member's first encrypted data using their private keys, resulting in multiple second encrypted data. The target member then performs an inverse operation on the multiple second encrypted data using their private key, resulting in multiple third encrypted data. These third encrypted data are then aggregated to obtain fourth encrypted data. Finally, the intersection of all the fourth encrypted data from all participating members is calculated to obtain fifth encrypted data. The dataset intersection result is then obtained based on the fifth encrypted data.
Smart Images

Figure CN116305234B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing, and in particular to a method, apparatus, device, and storage medium for finding the intersection of multiple datasets. Background Technology
[0002] Private Set Intersection (PSI), an important branch of secure multi-party computation, is used by multiple participants to collaboratively find the intersection of their respective private sets without revealing any information beyond the intersection. As a specific application problem of secure multi-party computation, PSI not only has significant theoretical implications but also a wide range of applications, such as privacy-preserving location sharing, measuring the effective conversion rate of online advertising, and paternity testing, disease prediction, and pedigree testing based on human genome sequences.
[0003] In related technologies, two-party privacy set intersection schemes are relatively mature, such as the PSI scheme based on DH key exchange and the PSI scheme based on unintentional transmission protocol. However, these schemes are limited to two-party use. If multi-party PSI is required, existing technologies usually use pairwise intersection or a central auxiliary method. Pairwise intersection will leak the intersection content between the two parties, violating the principle of PSI not leaking information other than the intersection. Central auxiliary methods require the deployment of a central node, but real-world scenarios are often decentralized, because the deployment location of the central node needs to be considered, as well as the security risks of the central node.
[0004] Currently, no effective solution has been proposed to address the low security of the process of finding the intersection of multi-party datasets in related technologies. Summary of the Invention
[0005] This application provides a method, apparatus, device, and storage medium for finding the intersection of multiple datasets, in order to at least address the problem of low security in the process of finding the intersection of multiple datasets in related technologies.
[0006] In a first aspect, embodiments of this application provide a method for finding the intersection of multiple datasets, including:
[0007] Step S1: Multiple participating members in the group use their respective private keys to encrypt their respective datasets, resulting in multiple first encrypted data sets;
[0008] Step S2: Taking each participating member as the target member, the first encrypted data of the target member is sent to the other participating members. The other participating members use their private keys to encrypt the first encrypted data of the target member to obtain multiple second encrypted data. The other participating members send the multiple second encrypted data to the target member. The target member uses its own private key to perform the inverse operation on the multiple second encrypted data to obtain multiple third encrypted data. The target member aggregates the multiple third encrypted data with its own first encrypted data to obtain fourth encrypted data.
[0009] Step S3: Find the intersection of multiple fourth encrypted data to obtain fifth encrypted data signed by the group private key, and send the fifth encrypted data to the participating members. The participating members obtain the intersection of the datasets based on the fifth encrypted data.
[0010] In some embodiments, the individual private keys of the group members and the group private key include:
[0011] Based on the group private key, key fragments are distributed to the group members as their respective private keys. The signature of the group private key can be obtained by aggregating the signatures of the key fragments with a number not less than a threshold threshold, where the threshold threshold does not exceed the total number of the group members.
[0012] In some embodiments, the number of participating members is not less than the threshold value.
[0013] In some embodiments, the target member aggregating the plurality of third encrypted data includes:
[0014] The multiple third encrypted data are aggregated with their own first encrypted data to form the fourth encrypted data signed by the group's private key.
[0015] In some embodiments, the method further includes encrypting the datasets held by each participating member using their respective private keys before:
[0016] Perform a one-way hash calculation on the datasets held by each of the multiple participating members to ensure that the lengths of the datasets held by each of the multiple participating members are equal.
[0017] In some embodiments, finding the intersection of the plurality of the fourth encrypted data includes:
[0018] A fast matching process is performed on multiple sets of fourth encrypted data to determine whether there are overlapping elements among them. If there are overlapping elements among the fourth encrypted data, the overlapping elements are output as the intersection result.
[0019] In some embodiments, the method further includes the following when the dataset changes:
[0020] When the dataset is added or the data changes, steps S1 to S2 are performed once on the added or changed dataset to obtain updated third encrypted data, and then aggregated with other unchanged historical third encrypted data to obtain updated fourth encrypted data.
[0021] When the dataset is deleted, the first encrypted data and multiple third encrypted data corresponding to the dataset are deleted directly.
[0022] Secondly, this application provides a device for finding the intersection of multiple datasets, comprising:
[0023] The first encryption module is used by multiple participating members in the group to encrypt their respective datasets using their private keys, resulting in multiple first encrypted data.
[0024] The second encryption module is used to send the first encrypted data of each participating member to other participating members other than the target member, with each participating member as the target member. The other participating members use their private keys to encrypt the first encrypted data of the target member to obtain multiple second encrypted data. The other participating members send the multiple second encrypted data to the target member. The target member uses its own private key to perform the inverse operation on the multiple second encrypted data to obtain multiple third encrypted data. The target member aggregates the multiple third encrypted data to obtain fourth encrypted data.
[0025] Intersection module: used to find the intersection of multiple fourth encrypted data to obtain fifth encrypted data, and send the fifth encrypted data to the participating members, who then obtain the intersection of the datasets based on the fifth encrypted data.
[0026] Thirdly, this application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, when the processor executes the computer program, it implements the step of finding the intersection of multiple datasets as claimed in any one of claims 1 to 61 to 7.
[0027] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, characterized in that, when executed by a processor, the program implements the step of finding the intersection of multiple datasets as described in any one of claims 1 to 61 to 7.
[0028] Compared to related technologies, the multi-party dataset intersection method, apparatus, device, and storage medium provided in this application embodiment solves the problem of low security in the multi-party dataset intersection process in related technologies. This is achieved by having multiple participating members encrypt their respective datasets using their private keys, resulting in multiple first encrypted data. Then, each participating member is designated as a target member, and other participating members encrypt the target member's first encrypted data using their private keys, resulting in multiple second encrypted data. The target member then performs an inverse operation on the multiple second encrypted data using their private key, resulting in multiple third encrypted data. These third encrypted data are then aggregated to obtain fourth encrypted data. Finally, the intersection of all the fourth encrypted data from all participating members is calculated to obtain fifth encrypted data. The dataset intersection result is then obtained based on the fifth encrypted data.
[0029] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description
[0030] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0031] Figure 1 This is a hardware structure block diagram of the terminal for the multi-dataset intersection method in this embodiment;
[0032] Figure 2 This is a flowchart of the method for finding the intersection of multiple datasets in this embodiment;
[0033] Figure 3 This is a schematic diagram of the multi-party encryption of the dataset for the multi-party dataset intersection method in this embodiment;
[0034] Figure 4 This is a schematic diagram of the private key encryption of the dataset group in the multi-party dataset intersection method of this embodiment;
[0035] Figure 5 This is a structural block diagram of the apparatus for the method of finding the intersection of multiple datasets in this embodiment. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of this application clearer, the application is described and illustrated below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. All other embodiments obtained by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application.
[0037] Obviously, the accompanying drawings described below are merely some examples or embodiments of this application. Those skilled in the art can apply this application to other similar scenarios based on these drawings without any inventive effort. Furthermore, it is understood that although the efforts made in this development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this application, any changes to design, manufacturing, or production based on the technical content disclosed in this application are merely conventional technical means and should not be construed as insufficient disclosure of the content of this application.
[0038] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.
[0039] Unless otherwise defined, the technical or scientific terms used in this application shall have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms “a,” “an,” “an,” “the,” and similar words used in this application do not indicate quantity limitation and may indicate singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units not listed, or may include other steps or units inherent to these processes, methods, products, or apparatuses. The term “multiple” used in this application refers to two or more.
[0040] The method embodiments provided in this example can be executed on a terminal, computer, or similar computing device. For example, it can run on a terminal. Figure 1 This is a hardware structure block diagram of the terminal for the multi-dataset intersection method in this embodiment. For example... Figure 1 As shown, a terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 and a memory 104 for storing data are also included. The processor 102 may be, but is not limited to, a microprocessor (MCU) or a programmable logic device (FPGA). The terminal may also include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that… Figure 1The structure shown is for illustrative purposes only and does not limit the structure of the terminal described above. For example, the terminal may also include components that are larger than... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown are illustrated.
[0041] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the multi-dataset intersection method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0042] The transmission device 106 is used to receive or send data via a network. This network includes a wireless network provided by the terminal's communication provider. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 can be a Radio Frequency (RF) module used for wireless communication with the Internet.
[0043] This embodiment provides a method for finding the intersection of multiple datasets. Figure 2 This is a flowchart of the method for finding the intersection of multiple datasets in this embodiment, as shown below. Figure 2 As shown, the process includes the following steps:
[0044] In step S1, multiple participating members in the group use their respective private keys to encrypt their respective datasets to obtain multiple first encrypted data.
[0045] Among them, private key s i (i = 1, 2, ..., n) are only visible to the group members who hold the corresponding private key, while the group private key s is not visible to any group members. Each group member holds a dataset X. i Using private key s i For the corresponding dataset X i After encryption, the first encrypted data is obtained.
[0046] In step S2, each participating member is designated as the target member. The target member's first encrypted data is sent to the other participating members. The other participating members use their private keys to encrypt the target member's first encrypted data to obtain multiple second encrypted data. The other participating members send the multiple second encrypted data to the target member. The target member uses its own private key to perform the inverse operation on the multiple second encrypted data to obtain multiple third encrypted data. The target member aggregates the multiple third encrypted data with its own first encrypted data to obtain the fourth encrypted data.
[0047] Among them, such as Figure 3 As shown, the target member P i The first encrypted data after it is encrypted Send to all other participants except itself, for example, one of the participating members P j Received target member P i The first encrypted data sent and using the private key s held j right Encryption is performed to obtain a second encrypted data. Right now Participating member P j Send the second encrypted data to the target member P i P i After receiving, use the private key s i For the second encrypted data Performing the inverse operation yields the following result: That is, the target member P i In non-participating member P j Knowing dataset X i In the case of the content, the participating member P was obtained. j Use private key j For dataset X i Third-party encrypted data All other participating members, except the target member, repeat the above steps until the target member obtains all the third encrypted data encrypted by each of the other participating members using their respective private keys. At this point, the target member has all the third encrypted data they have obtained, plus the first encrypted data they encrypted with their own private key. The target member possesses encrypted data that has been encrypted once by the private keys of all participating members. The number of these encrypted data is the number of participating members, t, in this intersection finding process. These encrypted data are then aggregated to obtain the fourth encrypted data of the original dataset, which is then encrypted using the group's private key signature, completing the process as follows: Figure 4 The encryption process is shown.
[0048] Step S3: Find the intersection of multiple fourth encrypted data sets to obtain the fifth encrypted data signed by the group private key, and send the fifth encrypted data to the participating members. The participating members obtain the intersection of the datasets based on the fifth encrypted data.
[0049] In step S2, the data set H is obtained after the group private key is used to sign and encrypt the data of each participating member. s (X i For each set of data (i = 1, 2, ..., n), finding the intersection of the original datasets is equivalent to finding the intersection of the encrypted datasets, i.e., X1 ∩ X2 ∩ ... X n Equivalent to H s (X1)∩H s (X2)∩…∩H s (X n After obtaining the intersection result of the encrypted data, i.e., the fifth encrypted data, the participating members select the portion of their own dataset that has the same fields as the fifth encrypted data as the final dataset intersection result.
[0050] Through the above steps S1 to S3, multiple participating members in the group use their respective private keys to encrypt their respective datasets, obtaining multiple first encrypted data. Taking each participating member as the target member, other participating members use their respective private keys to encrypt the target member's first encrypted data, obtaining multiple second encrypted data. The target member uses their private key to perform the inverse operation on the multiple second encrypted data, obtaining multiple third encrypted data. The multiple third encrypted data are then aggregated to obtain fourth encrypted data. The intersection of the fourth encrypted data of all participating members is calculated to obtain fifth encrypted data. The dataset intersection result is obtained based on the fifth encrypted data. This solves the problem of low security in the process of finding the intersection of multiple datasets in related technologies and achieves the beneficial effect of protecting the privacy of participating members when finding the intersection of multiple datasets.
[0051] In some embodiments, the private key of each group member and the group private key include: distributing key fragments to group members as their respective private keys based on the group private key, wherein the signature of the group private key can be obtained by aggregating the signatures of key fragments of a number not less than a threshold threshold, and the threshold threshold does not exceed the total number of group members.
[0052] First, a pre-defined private key s and threshold t are used to construct a polynomial f(x) of degree t-1: s + a1X + a2X 2 +…+a t-1 x t-1 Based on the number of group members n, select n random elements x1, x2, ..., xn. n Calculate f(x) respectively i ), (i = 1, 2, ..., n), and x i With the corresponding f(x)i The key is distributed as a key fragment to each of the n group members as their respective private keys. In this way, when there are more than or equal to t group members participating in the computation, more than or equal to t key fragments can be provided. Since the key fragments come from a polynomial f(x) of degree t-1, and each of the n group members' private keys is a point on f(x) with n different values, any t points among the n points can be used to recover the polynomial f(x).
[0053] In some embodiments, the number of participating members is not less than a threshold.
[0054] Since encrypted data signed by the group private key can only be obtained by aggregating encrypted data signed by key fragments with a number greater than or equal to the threshold threshold, the number of members participating in the calculation cannot be less than the threshold threshold.
[0055] In some embodiments, the target member aggregating multiple third encrypted data and its own first encrypted data includes: aggregating the multiple third encrypted data and its own first encrypted data into fourth encrypted data signed by the group's private key. Lagrange interpolation can be used for data aggregation. The specific aggregation formula is as follows: The fourth encrypted data obtained at this point is the original dataset X. i Encrypted data signed using the group's private key.
[0056] In some embodiments, before the multiple participating members encrypt their respective datasets using their private keys, the method further includes: performing a one-way hash calculation on the datasets held by the multiple participating members to make the lengths of the datasets held by the multiple participating members equal.
[0057] Wherein, the length X of the original dataset held by each participating member i They may not be the same; a hash algorithm can process any set of input data X. i The calculation yields a fixed-length output H(X). i This ensures that the data length of each participating member is equal, which facilitates data alignment and improves the efficiency of subsequent intersection calculation.
[0058] In some embodiments, finding the intersection of multiple fourth encrypted data includes: determining whether there are overlapping elements among the multiple fourth encrypted data; if there are overlapping elements among the fourth encrypted data, the precisely overlapping elements are output as the intersection result.
[0059] One approach is to use Bloom filters to find the intersection of data sets. Bloom filters can be used to quickly and efficiently determine whether an element belongs to a set, so they can be used to find the intersection of sets. When an element in one set overlaps with an element in another set, that overlapping element is output as the intersection result. Because the encryption of the data is performed in the preprocessing stage, the intersection of the datasets is directly calculated using ciphertext, which is equivalent to calculating the intersection using plaintext, thus improving the speed and efficiency of the computation.
[0060] In some embodiments, when the dataset changes, the method further includes: when the dataset is added or the data is changed, performing steps S1 to S2 once on the added or changed dataset to obtain updated fourth encrypted data; when the dataset is deleted, directly deleting the dataset and all encrypted data corresponding to the dataset.
[0061] When a dataset is added or changed, only one multi-party signature encryption is needed on the added or changed dataset to obtain the fourth encrypted data of the updated dataset. When a dataset is deleted, only all the encrypted data corresponding to the dataset needs to be deleted. That is, the addition, deletion and modification operations of the dataset do not affect the use of other unchanged datasets and all their corresponding encrypted data, which improves the flexibility of the intersection process.
[0062] This embodiment also provides a device for finding the intersection of multiple datasets. This device is used to implement the above embodiments and preferred embodiments, and will not be repeated as already described. As used below, the terms "module," "unit," "subunit," etc., can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0063] In some embodiments, Figure 5 This is a structural block diagram of a multi-data set intersection device according to an embodiment of this application, such as... Figure 5 As shown, the device for finding the intersection of multiple datasets includes:
[0064] The first encryption module 51 is used by multiple participating members in the group to encrypt their respective datasets using their private keys, thereby obtaining multiple first encrypted data.
[0065] The second encryption module 52 is used to send the first encrypted data of each participating member to the other participating members, with each participating member as the target member. The other participating members use their private keys to encrypt the first encrypted data of the target member to obtain multiple second encrypted data. The other participating members send the multiple second encrypted data to the target member. The target member uses its own private key to perform the inverse operation on the multiple second encrypted data to obtain multiple third encrypted data. The target member aggregates the multiple third encrypted data to obtain the fourth encrypted data.
[0066] Intersection module 53: used to find the intersection of multiple fourth encrypted data to obtain fifth encrypted data, and send the fifth encrypted data to the participating members, who then obtain the intersection of the datasets based on the fifth encrypted data.
[0067] It should be noted that the above modules can be functional modules or program modules, and can be implemented through software or hardware. For modules implemented through hardware, the above modules can reside in the same processor; or the above modules can be located in different processors in any combination.
[0068] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps of the method for finding the intersection of multiple datasets as provided in the above embodiments.
[0069] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the multi-dataset intersection method provided in the above embodiments.
[0070] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.
[0071] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0072] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A method for finding the intersection of multiple datasets, characterized in that, include: Step S1: Multiple participating members in the group use their respective private keys to encrypt their respective datasets, resulting in multiple first encrypted data sets; Step S2: Taking each participating member as the target member, the first encrypted data of the target member is sent to the other participating members. The other participating members use their private keys to encrypt the first encrypted data of the target member to obtain multiple second encrypted data. The other participating members send the multiple second encrypted data to the target member. The target member uses its own private key to perform the inverse operation on the multiple second encrypted data to obtain multiple third encrypted data. The target member aggregates the multiple third encrypted data with its own first encrypted data to obtain fourth encrypted data. Step S3: Find the intersection of multiple fourth encrypted data sets to obtain fifth encrypted data signed by the group private key, and send the fifth encrypted data to the participating members. The participating members obtain the intersection of the datasets based on the fifth encrypted data. The private key of each group member and the group private key include: distributing key fragments to the group members as their respective private keys based on the group private key, wherein the signature of the group private key is obtained by aggregating the signatures of the key fragments of a number not less than a threshold threshold, and the threshold threshold does not exceed the total number of the group members; The target member aggregates the multiple third encrypted data and its own first encrypted data, including: The multiple third encrypted data and its own first encrypted data are aggregated into the fourth encrypted data signed by the group's private key.
2. The method for finding the intersection of multiple datasets according to claim 1, characterized in that, The number of participating members is not less than the threshold value.
3. The method for finding the intersection of multiple datasets according to claim 1, characterized in that, The method further includes the following steps before multiple participating members encrypt their respective datasets using their private keys: Perform a one-way hash calculation on the datasets held by each of the multiple participating members to ensure that the lengths of the datasets held by each of the multiple participating members are equal.
4. The method for finding the intersection of multiple datasets according to claim 1, characterized in that, Finding the intersection of multiple sets of the fourth encrypted data includes: Determine whether there are overlapping elements among the multiple fourth encrypted data. If there are overlapping elements among the fourth encrypted data, output the overlapping elements as the intersection result.
5. The method for finding the intersection of multiple datasets according to claim 1, characterized in that, When the dataset changes, the method further includes: When the dataset is added or the data changes, steps S1 to S2 are performed once on the added or changed dataset to obtain updated fourth encrypted data, and the intersection with other unchanged historical fourth encrypted data is calculated to obtain updated intersection results. When the dataset is deleted, the dataset and all encrypted data corresponding to the dataset are deleted directly.
6. A device for finding the intersection of multiple datasets, characterized in that, include: The first encryption module is used by multiple participating members in the group to encrypt their respective datasets using their private keys, resulting in multiple first encrypted data. The second encryption module is used to send the first encrypted data of each participating member to other participating members other than the target member, with each participating member as the target member. The other participating members use their private keys to encrypt the first encrypted data of the target member to obtain multiple second encrypted data. The other participating members send the multiple second encrypted data to the target member. The target member uses its own private key to perform the inverse operation on the multiple second encrypted data to obtain multiple third encrypted data. The target member aggregates the multiple third encrypted data with its own first encrypted data to obtain fourth encrypted data. Intersection module: used to find the intersection of multiple fourth encrypted data to obtain fifth encrypted data, and send the fifth encrypted data to the participating members, who then obtain the intersection of the datasets based on the fifth encrypted data; The first encryption module is further configured to distribute key fragments as private keys to the group members based on the group private key, wherein the signature of the group private key is obtained by aggregating the signatures of the key fragments of a number not less than a threshold threshold, and the threshold threshold does not exceed the total number of the group members. The second encryption module is further configured to aggregate multiple third encrypted data and its own first encrypted data into fourth encrypted data signed by the group private key.
7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it performs the step of finding the intersection of multiple datasets as described in any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the step of finding the intersection of the multi-party datasets as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Data hiding query security sharing system and method based on multi-party security computing
CN112367170A
Shared data processing method based on security multi-party privacy protection in block chain
CN113449336A