Data Processing Method, Medium, Device, and Product for Secure Computing

By performing data processing procedures based on the target protocol and polynomial evaluation in multi-party security calculations, the problem of how to ensure calculation accuracy in multi-party security calculations is solved, and the effect of reducing traffic, avoiding data leakage and ensuring the accuracy of feature sharding is achieved.

CN119089493BActive Publication Date: 2025-06-20BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411132997.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-16
Publication Date
2025-06-20
Estimated Expiration
2044-08-16

AI Technical Summary

Technical Problem

In the multi-party security calculation process, how to ensure the accuracy of the calculation, especially when data or intermediate results need to be held in a shared form, the prior art is difficult to effectively solve.

Method used

By performing a data processing process based on the target protocol between the first and the second party, both parties jointly obtain and verify the intersection information, use the target identification set to replace the intersection, and calculate the value of the polynomial on the intersection, thereby obtaining feature shards.

Benefits of technology

This method not only reduces traffic and avoids first-party data leakage, but also ensures the accuracy of feature sharding when the intersection is not a subset, so that the target data processing task is reliably executed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119089493B_ABST
    Figure CN119089493B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a data processing method, medium, device, and product for secure computing. The participants in secure computing include a first party and a second party. The first party holds a first set of identifiers, and the identifiers in the first set of identifiers correspond to h-dimensional features. The second party holds a second set of identifiers. The method applied to the first party includes: based on the first set of identifiers, performing a data processing process based on a target protocol with the second party, so that the second party obtains at least the first index number of the intersection of the first set of identifiers and the second set of identifiers in the first set of identifiers; for each of at least some of the h-dimensional features, obtaining a first polynomial corresponding to the dimensional feature; calculating the value of the first polynomial on at least some of the identifiers in the target set of identifiers with the second party to obtain a first shard of the value; and performing a target data processing task based at least on the first shard. Through this solution, data security can be protected and accuracy can be ensured in scenarios such as model training and SQL queries.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of secure multi-party computation, and in particular, to a data processing method, medium, device, and product for secure computation. Background Art

[0002] Secure multi-party computation, also known as multi-party secure computation (MPC), allows multiple parties to jointly compute the result of a function without revealing the input data of each party in the function. The computed result is disclosed to one or more of the parties. Typical applications of secure multi-party computation include, for example, joint statistical analysis of multi-party data with privacy protection, machine learning, etc. Here, the function is a statistical operation function, a machine learning algorithm, and so on.

[0003] During the multi-party secure computation process, in order not to disclose the data of each party and the intermediate computation results, the data or intermediate results can be held by each party in a shared form. Each party holds a data shard, and the shards held by all parties are combined to restore the corresponding data. In the development and application promotion of MPC technology, in addition to paying attention to the security of the MPC computation protocol itself, the accuracy of MPC itself also needs to be emphasized. Among them, how to ensure the accuracy of MPC is crucial for ensuring the reliability and effectiveness of the multi-party secure computation process and results. Summary of the Invention

[0004] This Summary of the Invention section is provided to introduce concepts in a brief form that will be described in detail in the subsequent Detailed Implementation section. This Summary of the Invention section is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to be used to limit the scope of the claimed technical solution.

[0005] In a first aspect, the present disclosure provides a data processing method for secure computation. The parties participating in the secure computation include a first party and a second party. The first party holds a first set of identifiers, and the identifiers in the first set of identifiers correspond to h-dimensional features. The second party holds a second set of identifiers, where h≥1. The method is applied to the first party and includes:

[0006] Performing a data processing process based on a target protocol with the second party based on the first set of identifiers, so that the second party obtains at least the first index numbers of the intersection of the first set of identifiers and the second set of identifiers in the first set of identifiers;

[0007] For each of at least some of the h - dimensional features, obtain a first polynomial corresponding to the dimensional feature, where the first polynomial is constructed based on the dimensional feature corresponding to the identifiers in the third identifier set, and the third identifier set is generated based on the index numbers of the identifiers in the first identifier set; calculate, with the second party, the values of the first polynomial on at least some of the identifiers in the target identifier set to obtain a first shard of the values, where the target identifier set is generated by the second party based on the first index number, and the third identifier set and the target identifier set are generated in the same way;

[0008] Perform a target data processing task based at least on the first shard.

[0009] In a second aspect, the present disclosure provides a data processing method for secure computing. The parties involved in the secure computing include a first party and a second party. The first party holds a first identifier set, and the identifiers in the first identifier set correspond to h - dimensional features. The second party holds a second identifier set, where h≥1. The method is applied to the second party and includes:

[0010] Based on the second identifier set, perform a data processing process based on a target protocol with the first party to obtain at least a first index number of the intersection of the first identifier set and the second identifier set in the first identifier set;

[0011] Generate a target identifier set based on the first index number;

[0012] For each of at least one first polynomial, calculate, with the first party, the values of the first polynomial on at least some of the identifiers in the target identifier set to obtain a sixth shard of the values, where the at least one first polynomial is constructed by the first party for each of at least some of the h - dimensional features based on the dimensional feature corresponding to the identifiers in the third identifier set, and the third identifier set is generated by the first party based on the index numbers of the identifiers in the first identifier set, and the third identifier set and the target identifier set are generated in the same way;

[0013] Perform a target data processing task based at least on the sixth shard.

[0014] In a third aspect, the present disclosure provides a computer - readable medium, on which a computer program is stored. When the program is executed by a processing device, it implements the steps of the data processing method for secure computing provided in the first aspect of the present disclosure or the steps of the data processing method for secure computing provided in the second aspect of the present disclosure.

[0015] In a fourth aspect, the present disclosure provides an electronic device, including:

[0016] A storage device, on which a computer program is stored;

[0017] A processing device is configured to execute the computer program in the storage device to implement the steps of the data processing method for secure computing provided in the first aspect of the present disclosure or the steps of the data processing method for secure computing provided in the second aspect of the present disclosure.

[0018] In a fifth aspect, the present disclosure provides a computer program product, including a computer program which, when executed by a processor, implements the steps of the data processing method for secure computing provided in the first aspect of the present disclosure or the steps of the data processing method for secure computing provided in the second aspect of the present disclosure.

[0019] In the above technical solution, first, a first party and a second party jointly execute a data processing process based on a target protocol, and the second party obtains at least a first index number of the intersection of a first identification set and a second identification set in the first identification set; then, the second party generates a target identification set based on the first index number. Meanwhile, for each of at least some dimensions of the h-dimensional features held by the first party, the first party obtains a first polynomial corresponding to this dimension of feature; next, the first party and the second party calculate the values of the first polynomial on at least some identifications in the target identification set to respectively obtain a shard of the values; finally, the first party and the second party respectively execute a target data processing task based on the shards held by themselves. In this way, the sharding problem of the features corresponding to the intersection of the identification sets held by both parties can be ingeniously converted into a polynomial evaluation problem. Among them, the first party synchronizes the first index number without substantial physical meaning to the second party, so that the second party generates the target identification set locally based on the first index number, rather than directly synchronizing the target identification set to the second party, which can not only reduce the communication volume, but also avoid data leakage of the first party. In addition, both parties use the target identification set to replace the intersection to calculate the values of the first polynomial on the intersection. In this way, even when the second identification set is not a subset of the first identification set, it can be ensured that the obtained feature shards are accurate results of the features corresponding to the intersection. Therefore, the accuracy of the feature shards can be ensured, enabling the target data processing task to be reliably executed. Moreover, both parties do not need to calculate the intersection, but use the target identification set to replace the intersection, which can avoid the problem of data leakage caused by any party calculating the intersection. Thus, through this solution, data security can be protected and accuracy can be ensured in scenarios such as model training and SQL queries.

[0020] Other features and advantages of the present disclosure will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In conjunction with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the original and elements are not necessarily drawn to scale. In the drawings:

[0022] Figure 1 is a flowchart of a data processing method for secure computing applied to a first party according to an exemplary embodiment.

[0023] Figure 2 is a schematic diagram of a first party and a second party executing an oblivious pseudorandom function protocol according to an exemplary embodiment.

[0024] Figure 3 is a schematic diagram of a first party and a second party executing an oblivious pseudorandom function protocol according to another exemplary embodiment.

[0025] Figure 4 is a flowchart of a data processing method for secure computing applied to a second party according to an exemplary embodiment.

[0026] Figure 5 is a block diagram of a data processing apparatus for secure computing applied to a first party according to an exemplary embodiment.

[0027] Figure 6 is a block diagram of a data processing apparatus for secure computing applied to a second party according to an exemplary embodiment.

[0028] Figure 7 is a schematic diagram of the structure of an electronic device according to an exemplary embodiment. Specific Embodiments

[0029] Before introducing the specific embodiments of the present disclosure, the nouns involved in the present disclosure and the specific application scenarios of multi-party secure computing are first introduced and explained.

[0030] Ring: refers to a set that defines two operations, addition and multiplication, and forms a commutative group (i.e., an Abelian group) for addition, forms a semigroup for multiplication of non-zero elements, and multiplication satisfies the distributive law for addition.

[0031] Secret Sharing, also known as secret splitting or secret sharing, is a technique where a secret (such as a key, private data, etc.) is split into multiple shares and distributed to different parties for safekeeping. Only when more than the threshold number of parties combine their shares can the secret be recovered; any information about the secret cannot be retrieved from shares obtained from fewer than the threshold number of parties. In multi-party secure computation, the threshold number is usually the same as the number of participating parties, and the shares into which the secret is split can also be referred to as shards. Among them, private data is the data that parties do not want other parties to know in multi-party secure computation.

[0032] Private Set Intersection (PSI) is a type of proprietary protocol in the field of secure multi-party computation. It allows two participating parties to input their private sets and jointly compute the intersection of the sets, while ensuring that no additional element information is leaked except for the result of the set intersection.

[0033] Homomorphic encryption is a technique that allows computations to be performed on encrypted data (i.e., ciphertext) and then decrypted to obtain the result. The computational result of homomorphic encryption is the same as the result obtained by directly computing on the original data (i.e., plaintext), but the entire computational process is carried out on the encrypted data.

[0034] Offline: The process of pre-processing data before performing the actual computational task. Generally speaking, the time requirement for the offline process is not strict.

[0035] Online: The process of performing the actual computational task. Usually, it is desired that the online computation can be completed as soon as possible.

[0036] Traffic volume: Since the data of the participating parties in secure computation is on different machines, network communication is required to complete the interaction. During the computational process, ciphertext data is transmitted over the network, and the amount of data transmitted is the traffic volume.

[0037] In practical applications, for the purpose of privacy protection, multi-party secure computation algorithms are usually black-box algorithms, and the data transmission behavior between the computing nodes carrying the multi-party secure computation algorithms is not transparent. As discussed in the background technology, typical applications of multi-party secure computation include machine learning. Among them, multi-party secure computation technology can be used to protect private data during the inference and training stages of machine learning, mainly involving the protection of model parameters and the data of each participating party during the training process.

[0038] Currently, common privacy-preserving machine learning solution strategies based on secure multi-party computation include: privacy-preserving machine learning protocols based on techniques such as garbled circuits and oblivious transfer, and executing secure multi-party computation protocols to complete non-linear operation calculations such as activation functions. The secret sharing technology allows multiple parties to participate in the training or prediction of machine learning network models, and this process does not disclose data or model information.

[0039] In addition to the above application fields, multi-party secure computation can also be applied to privacy-preserving network security detection, joint statistical analysis of multi-party data with privacy protection, spam cleaning and filtering of encrypted emails, advertisement conversion and other fields.

[0040] Among them, two-party secure computation is usually used for the joint statistical analysis of two-party data for privacy protection, that is, querying across two-party databases while protecting the private data of both parties.

[0041] For example, consider the following Structured Query Language (SQL) statement:

[0042] select avg(a.key)from a join b on a.id=b.id;

[0043] This SQL statement is used to align table a and table b according to the id column, and based on the aligned table, calculate the average of a.key to obtain the query result. Among them, table a is stored in the first party P0, table a includes an id column and at least one feature column, table b is stored in the second party P1, table b includes an id column, the parties P0 and P1 perform an SQL query through two-party secure computation technology without exposing their own private data to each other, and only expose the query result to the querying party after the query ends. The query result is stored in the parties P0 and P1 in a sharded form.

[0044] Specifically, in the related technology, the parties P0 and P1 align table a and table b according to the id column in the following way (which can be called PSI to share), so as to store the features corresponding to the intersection held by the party P0 in a sharded form in the parties P0 and P1. Among them, the intersection is the intersection of the first id set held by the party P1 (constituted by all elements in the id column of table b) and the second id set held by the party P0 (constituted by all elements in the id column of table a): For each feature column held by itself, the party P0 constructs a polynomial based on this feature column; then, the parties P0 and P1 securely calculate the value of this polynomial on the first id set, and both parties obtain a shard of this value respectively, as the feature shard corresponding to the above intersection, that is, store the features corresponding to the above intersection held by the party P0 in a sharded form in the parties P0 and P1, so as to facilitate the parties to perform an SQL query based on the feature shards held by each of them.

[0045] Among them, in the case where the first ID set is a subset of the second ID set, the above intersection is the first ID set. At this time, the feature shards obtained by the above related technology are the exact results of the feature shards corresponding to the intersection of the first ID set and the second ID set; in the case where the first ID set is not a subset of the second ID set, the feature shards obtained by the above related technology are a superset of the feature shards corresponding to the above intersection. Therefore, the above related technology cannot guarantee the accuracy of feature shards in all cases.

[0046] In view of this, the present disclosure provides a data processing method, medium, device and product for secure computing to ensure the accuracy of feature shards.

[0047] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0048] It should be understood that the various steps recited in the method embodiments of the present disclosure can be executed in a different order and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.

[0049] As used herein, the term "including" and its variants are open-ended, i.e., "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0050] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0051] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0052] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are for illustrative purposes only and are not used to limit the scope of these messages or information.

[0053] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0054] For example, when responding to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's information. Thus, the user can autonomously choose whether to provide information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the technical solutions of the present disclosure according to the prompt message.

[0055] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving an active request from the user can be, for example, in the form of a pop-up window, and the prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry a selection control for the user to choose "agree" or "disagree" to provide information to the electronic device.

[0056] It can be understood that the above process of notifying and obtaining the user's authorization is only illustrative and does not limit the implementation manners of the present disclosure, and other manners that meet relevant laws and regulations can also be applied to the implementation manners of the present disclosure.

[0057] At the same time, it can be understood that the data involved in the technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related regulations.

[0058] Before describing the specific implementation manners of the present disclosure, the core idea of the data processing method for secure computing in the present disclosure is first introduced.

[0059] In the present disclosure, the parties participating in secure computing include a first party and a second party. Among them, the first party holds a first set of identifiers, and each identifier in the first set of identifiers corresponds to h-dimensional features, that is, each identifier in the first set of identifiers corresponds to h-dimensional features respectively. The second party holds a second set of identifiers, h≥1, that is, each identifier in the first set of identifiers corresponds to at least one-dimensional feature. Both the first set of identifiers and the second set of identifiers contain at least one identifier, and the first set of identifiers is different from the second set of identifiers. Exemplarily, the first party is the above-mentioned P0, and the second party is the above-mentioned P1.

[0060] Among them, in one implementation, the identifiers in the second identifier set may correspond to one-dimensional features, and each identifier in the second identifier set corresponds to a one-dimensional feature respectively, that is, both the first party and the second party hold features. At this time, the h-dimensional feature does not include this one-dimensional feature.

[0061] Exemplarily, for the above SQL statement, in addition to the id column, table b also includes a feature column, and this feature column and at least one feature column in table a belong to features of different dimensions.

[0062] In another implementation, the identifiers in the second identifier set may not correspond to any features either, that is, only the first party holds features.

[0063] The core idea of the data processing method for secure computing is: converting the problem of fragmenting the features corresponding to the intersection of the first identifier set and the second identifier set into a polynomial evaluation problem. Specifically, the first party can encode each of at least some of the h-dimensional features into a polynomial respectively, such that the value of the polynomial at the corresponding identifier in the third identifier set is the value of the dimension feature corresponding to this identifier; then, calculate the values of the polynomials encoded by the first party at the identifiers in the target identifier set, where these values are distributed in the form of fragments between the first party and the second party, and the value fragment is the feature fragment corresponding to the corresponding identifier in the target identifier set. Among them, the third identifier set is generated based on the index numbers of the identifiers in the first identifier set, the target identifier set is generated by the second party based on the first index numbers of the intersection in the first identifier set, and the generation methods of the third identifier set and the target identifier set are the same. The first index numbers of the intersection in the first identifier set are synchronized from the first party to the second party, and the first index numbers are used to represent the index positions of the elements belonging to the first identifier set in the above intersection. Here, the "index number" can be understood as the position identifier of the elements in the intersection in the corresponding set, for example, the row number, which has no actual physical meaning.

[0064] The degree of each polynomial encoded by the first party is the number of identifiers in the third identifier set (that is, also the number of identifiers in the first identifier set). The communication volume during polynomial evaluation is proportional to the degree of the polynomial. In this way, when the number of identifiers in the third identifier set is large, it indicates that the degree of the polynomial is high. If directly evaluating it, the communication overhead is huge. Therefore, it can be considered to split the polynomial evaluation process into two sub-processes of reducing the degree (that is, reducing the degree of the polynomial) and evaluating in sequence.

[0065] In the sub-process of reducing the degree, the degree of the polynomial is reduced from the O(N) level to the O(q) level. In the sub-process of evaluating, the O(q)-degree polynomial is evaluated at the q identifiers in the target identifier set respectively. N is the number of identifiers in the first identifier set, and q is the number of identifiers in the target identifier set. Among them, the degree of the polynomial can be reduced based on the following theorem:

[0066] Theorem: Let be a field, x w be the w-th identifier in the target identifier set, be a set of polynomials with coefficients in x, where x is the independent variable. If then there is and f(x) are both polynomials in, that is, if one polynomial is equal to another polynomial mod g(x), then the values of these two polynomials at the same identifier are equal.

[0067] Specifically, first, the first party converts the polynomial f(x) into the following form:

[0068]

[0069] where f k (x) is the k-th polynomial, and its degree is less than or equal to q - 1.

[0070] Then, the second party prepares the data h k (x) = x kq mod g(x), k = 0, 1, 2,..., L, then there is:

[0071]

[0072] That is, the degree of the polynomial is less than or equal to 2q - 2, which is the polynomial obtained after reducing the degree of the polynomial f(x).

[0073] For example, N = 7, q = 3, f(x) = a0 + a1x + a2x 2 + a3x 3 + a4x 4 + a5x 5 + a6x 6 + a7x 7 , then At this time, f(x) can be converted into the following form:

[0074] f(x) = (a0 + a1x + a2x 2 ) + (a3 + a4x + a5x 2 )x 3 + (a6 + a7x + a8x 2 )x 6

[0075] where \(f_0(x)=a_0 + a_1x + a_2x\) 2 , \(f_1(x)=a_3 + a_4x + a_5x\) 2 , \(f_2(x)=a_6 + a_7x + a_8x\) 2 , and \(a_8 = 0\). At this time, the second party prepares \(h_1(x)=x\) 3 \(\bmod g(x)\), \(h_2(x)=x\) 6 \(\bmod g(x)\).

[0076] Figure 1 is a flowchart of a data processing method for secure computing applied to a first party shown according to an exemplary embodiment. As Figure 1 shown, the method may include S101 to S104.

[0077] In S101, based on the first identifier set, perform a data processing process based on the target protocol with the second party, so that the second party obtains at least the first index number of the intersection of the first identifier set and the second identifier set in the first identifier set.

[0078] In the present disclosure, the first party and the second party jointly perform a data processing process based on the target protocol, that is, jointly execute the target protocol, and the second party obtains at least the first index number of the intersection of the first identifier set and the second identifier set in the first identifier set. The target protocol can be used to synchronize the first index number of the intersection in the first identifier set to the second party. When the identifiers in the second identifier set correspond to one-dimensional features, the target protocol can also be used to store the second party features (i.e., the above one-dimensional features) corresponding to the intersection in a fragmented form in the first party and the second party.

[0079] Among them, when the identifiers in the second identifier set correspond to one-dimensional features, by executing the target protocol, the second party can obtain the above first index number, the second index number of the intersection in the second identifier set, and the fourth fragment of the one-dimensional feature corresponding to the intersection. The first party can obtain the fifth fragment of the one-dimensional feature corresponding to the intersection. That is, when the identifiers in the second identifier set correspond to one-dimensional features, by executing the target protocol, both parties can respectively obtain a fragment of the second party features corresponding to the intersection. In addition, the second party can also obtain the first index number and the second index number. The second index number of the intersection in the second identifier set is used to represent the index position of the elements belonging to the second identifier set in the above intersection.

[0080] When the identifiers in the second identifier set do not correspond to any features, by executing the target protocol, the second party can obtain the above first index number, and the first party does not obtain any features. That is, when the identifiers in the second identifier set do not correspond to any features, by executing the target protocol, the second party can obtain the first index number, and the information obtained by the first party is empty.

[0081] In S102, for each of at least some of the h-dimensional features, obtain a first polynomial corresponding to this dimensional feature.

[0082] In the present disclosure, the first polynomial is constructed based on the dimensional feature corresponding to the identifier in the third identifier set (that is, each identifier in the third identifier set). The value of the first polynomial at any identifier in the third identifier set is the value of the dimensional feature corresponding to this identifier. That is, taking the identifier in the third identifier set as the independent variable and the dimensional feature as the dependent variable to construct the first polynomial, and the degree of the first polynomial is less than or equal to the number of identifiers in the third identifier set.

[0083] The third identifier set is generated based on the index numbers of the identifiers in the first identifier set. Among them, new identifiers can be respectively assigned to each piece of data held by the first party (specifically, each identifier in the first identifier set) to obtain the third identifier set. In a possible implementation manner, the unit root with the index number of the identifier in the first identifier set as the order can be used as the new identifier.

[0084] Exemplarily, the index numbers of the identifiers in the first identifier set are successively 0, 1, 2, …, N−1, and the third identifier set includes ξ 0 , ξ 1 , ξ 2 , …, ξ N-1 , where ξ i is the i-th primitive unit root, i = 0, 1, 2, …, N−1.

[0085] In addition, the two parties can slice some of the h-dimensional features. At this time, the first party can obtain the first polynomial corresponding to each of the dimensional features in the partial dimensional features; the two parties can also slice the h-dimensional features. At this time, the first party can obtain the first polynomial corresponding to each of the h-dimensional features. At this time, a total of h first polynomials are obtained. The present disclosure does not make a specific limitation on the number of features to be sliced by the first party.

[0086] In S103, calculate with the second party the values of the first polynomial at at least some of the identifiers in the target identifier set to obtain a first slice of the values.

[0087] In the present disclosure, the target identification set is generated by a second party based on a first index number. After the second party obtains, through the target protocol, the first index number of the intersection of the first identification set and the second identification set in the first identification set, the target identification set can be generated according to the first index number in the same manner as the first party generates the third identification set. Subsequently, the first party and the second party jointly calculate the values of the first polynomial on at least some of the identifications in the target identification set. The first party can obtain a first shard of the value, and the second party can obtain a sixth shard of the value, that is, the value includes two shards, namely the first shard and the sixth shard. The values of the first polynomial on at least some of the identifications in the target identification set are the characteristic shards corresponding to at least some of the identifications in the target identification set.

[0088] In addition, the first party and the second party can jointly calculate the values of the first polynomial on each identification in the target identification set, or can jointly calculate the values of the first polynomial on some of the identifications in the target identification set. The present disclosure does not make specific limitations on this.

[0089] In S104, the target data processing task is performed at least based on the first shard.

[0090] In the present disclosure, when the identifications in the second identification set correspond to one-dimensional features, the first party can perform the target data processing task based on the first shard and the fifth shard, and the second party can perform the target data processing task based on the sixth shard and the fourth shard; when the identifications in the second identification set do not correspond to any features, the first party can perform the target data processing task only based on the first shard, and the second party can perform the target data processing task only based on the sixth shard.

[0091] Among them, the above target data processing task can be an SQL query task or a machine learning model training task.

[0092] In one implementation, when the target data processing task is an SQL query task, the first party and the second party can jointly perform an SQL query based on the characteristic shards they each hold to respectively obtain query result shards. Subsequently, both parties respectively feedback the query result shards they each obtain to the querying party; after receiving the query result shards sent by both parties, the querying party merges them to obtain the final query result.

[0093] Specifically, when the identifiers in the second identifier set correspond to one-dimensional features, the first party can jointly perform an SQL query with the second party based on the first shard and the fifth shard to obtain the first query result shard, and then feedback the first query result shard to the query party; correspondingly, the second party can jointly perform an SQL query with the first party based on the fourth shard and the sixth shard to obtain the second query result shard, and then feedback the second query result shard to the query party; finally, the query party merges the first query result shard and the second query result shard to obtain the final query result.

[0094] When the identifiers in the second identifier set do not correspond to any features, the first party can jointly perform an SQL query with the second party based on the first shard to obtain the first query result shard, and then feedback the first query result shard to the query party; correspondingly, the second party can jointly perform an SQL query with the first party based on the sixth shard to obtain the second query result shard, and then feedback the second query result shard to the query party; finally, the query party merges the first query result shard and the second query result shard to obtain the final query result.

[0095] In another implementation, when the target data processing task is a machine learning model training task, the second party can use the features of the first party for model training. Among them, the first party and the second party can perform model training in the MPC manner based on the feature shards they each hold to obtain model parameter shards respectively. Then, the first party sends the model parameter shards it holds to the second party, and the second party merges the model parameter shards obtained from the first party with the model parameter shards it holds to obtain the model parameters of the corresponding model, completing the model training of the second party. In this way, when the second party lacks training data or the training data is insufficient, the features of the first party can be used for model training, which can improve the accuracy of model training while ensuring the data privacy of the first party.

[0096] Specifically, when the identifiers in the second identifier set correspond to one-dimensional features, the first party can jointly perform model training with the second party based on the first shard and the fifth shard to obtain the first model parameter shard, and then feedback the first model parameter shard to the second party; correspondingly, the second party can jointly perform model training with the first party based on the fourth shard and the sixth shard to obtain the second model parameter shard, and then merge the second model parameter shard with the first model parameter shard received from the first party to obtain the complete model parameters.

[0097] When the identifiers in the second identifier set do not correspond to any features, the first party can, based on the first shard, jointly perform model training with the second party to obtain the first shard of model parameters, and then feedback the first shard of model parameters to the second party; correspondingly, the second party can, based on the sixth shard, jointly perform model training with the first party to obtain the second shard of model parameters, and then merge the second shard of model parameters with the first shard of model parameters received from the first party to obtain the complete model parameters.

[0098] In the above technical solution, first, the first party and the second party jointly execute the data processing process based on the target protocol, and the second party obtains at least the first index number of the intersection of the first identifier set and the second identifier set in the first identifier set; then, the second party generates the target identifier set based on the first index number, and at the same time, the first party obtains, for each of at least some of the h-dimensional features it holds, the first polynomial corresponding to the feature dimension; next, the first party and the second party calculate the values of the first polynomial on at least some of the identifiers in the target identifier set to respectively obtain a shard of the values; finally, the first party and the second party respectively perform the target data processing task based on the shards they hold. In this way, the sharding problem of the features corresponding to the intersection of the identifier sets held by both parties can be cleverly converted into a polynomial evaluation problem. Among them, the first party synchronizes the first index number that has no substantial physical meaning to the second party, so that the second party generates the target identifier set locally based on the first index number, rather than directly synchronizing the target identifier set to the second party, which can not only reduce the communication volume, but also avoid the leakage of the first party's data. In addition, both parties use the target identifier set to replace the intersection to calculate the values of the first polynomial on the intersection. In this way, even when the second identifier set is not a subset of the first identifier set, it can be ensured that the obtained feature shards are the exact results of the feature shards corresponding to the intersection. Therefore, the accuracy of the feature shards can be ensured, and the target data processing task can be reliably executed. In addition, both parties do not need to calculate the intersection, but use the target identifier set to replace the intersection, which can avoid the problem of data leakage caused by any party calculating the intersection. Therefore, through this solution, data security can be protected and accuracy can be ensured in scenarios such as model training and SQL queries.

[0099] The following will specifically describe the specific implementation manner of performing the data processing process based on the target protocol with the second party based on the first identifier set in S101 above, so that the second party obtains at least the first index number of the intersection of the first identifier set and the second identifier set in the first identifier set.

[0100] Specifically, when the identifiers in the second identifier set correspond to one-dimensional features, the first party can perform the data processing process based on the target protocol through the following steps (a1) to (a4):

[0101] Step (a1): Execute an oblivious pseudo-random function protocol with a second party to obtain a first blinding factor and a second shard of the one-dimensional feature corresponding to the second identification set.

[0102] In the present disclosure, a first party and a second party may jointly execute an oblivious pseudo-random function (OPRF) protocol. Among them, as Figure 2 shown, the second party P1 may execute the OPRF protocol based on the second identification set and the above-mentioned one-dimensional feature. The input of the first party P0 is empty. After executing the OPRF protocol, the first party P0 may obtain a first blinding factor and a second shard of the one-dimensional feature corresponding to the second identification set, and the second party P1 may obtain a third shard of the one-dimensional feature corresponding to the second identification set and a first blind text based on the second identification set.

[0103] Exemplarily, the above-mentioned second shard is r j , j = 0, 1, 2,..., n - 1, r j is the second shard of the one-dimensional feature corresponding to the j-th identification in the second identification set, and n is the number of identifications in the second identification set.

[0104] Step (a2): Use the first blinding factor to blind the hash values of the identifications in the first identification set to obtain a second blind text.

[0105] In the present disclosure, after obtaining the first blinding factor through the OPRF protocol, the first party may use the first blinding factor to blind the hash value of each identification in the first identification set to obtain a second blind text.

[0106] Exemplarily, the first party may use the first blinding factor to blind the hash values of the identifications in the first identification set through the following equation to obtain a second blind text:

[0107] M2 = k0 * H(y p )

[0108] where M2 is the second blind text; k0 is the first blinding factor; H(y p ) is the hash value of the p-th identification y p in the first identification set, p = 0, 1, 2,..., N - 1.

[0109] Step (a3): Send the second blind text to the second party for the second party to perform an intersection operation on the first blind text and the second blind text to obtain a first index number, a second index number of the intersection in the second identification set, and a fourth shard of the one-dimensional feature corresponding to the intersection, and send the second index number to the first party.

[0110] Step (a4): According to the received second index number, screen out a fifth shard of the one-dimensional feature corresponding to the intersection from the second shard.

[0111] In the present disclosure, after the first party blinds the hash value of the identifier in the first identifier set to obtain a second blind text, the second blind text can be sent to the second party; after the second party receives the second blind text, the first blind text obtained through the OPRF protocol and the second blind text are subjected to an intersection operation to obtain a first index number and a second index number of the intersection in the second identifier set; then, the second party filters out a fourth slice of the one-dimensional feature corresponding to the intersection from the third slice obtained through the OPRF protocol according to the second index number, and sends the second index number to the first party; after the first party receives the second index number, it filters out a fifth slice of the one-dimensional feature corresponding to the intersection from the second slice obtained through the OPRF protocol.

[0112] Exemplarily, n = 9, the above-mentioned second slice includes r0, r1,..., r8, and the second index numbers are 1, 5, 7, then the fifth slice includes r1, r5, r7.

[0113] Among them, the second party can filter out the fourth slice of the one-dimensional feature corresponding to the intersection from the third slice according to the second index number in a manner similar to filtering out the fifth slice of the one-dimensional feature corresponding to the intersection from the second slice, which is not elaborated in the present disclosure.

[0114] When the identifier in the second identifier set does not correspond to any feature, the first party can perform the data processing process based on the target protocol through the following steps (b1) to (b4):

[0115] Step (b1): Execute an oblivious pseudorandom function protocol with the second party to obtain a first blinding factor.

[0116] In the present disclosure, the first party and the second party can jointly execute the OPRF protocol. Among them, as Figure 3 shown, the second party P1 executes an oblivious pseudorandom function protocol based on the second identifier set, the input of the first party is empty, and after executing the OPRF protocol, the first party P0 can obtain a first blinding factor, and the second party P1 can obtain a first blind text based on the second identifier set.

[0117] Step (b2): Use the first blinding factor to blind the hash value of the identifier in the first identifier set to obtain a second blind text.

[0118] Step (b3): Send the second blind text to the second party so that the second party performs an intersection operation on the first blind text and the second blind text to obtain a first index number.

[0119] In the present disclosure, after the first party blinds the hash value of the first set of identifiers to obtain a second blind text, the second blind text can be sent to the second party; after receiving the second blind text, the second party performs an intersection operation on the first blind text obtained through the OPRF protocol and the second blind text to obtain a first index number.

[0120] The following is a detailed description of the specific implementation manner of performing the oblivious pseudorandom function protocol with the second party in step (a1) above to obtain the first blinding factor and the second shard of the one-dimensional feature corresponding to the second set of identifiers. Specifically, it can be implemented through the following steps (a11) to (a13):

[0121] Step (a11): In response to receiving the ciphertext feature and the third blind text sent by the second party, shuffle the order of the ciphertext feature and the order of the third blind text, and generate n random variables and a first blinding factor.

[0122] In the present disclosure, the ciphertext feature is obtained by the second party performing homomorphic encryption on the one-dimensional feature, and the third blind text is obtained by the second party blinding the hash value of the identifiers in the second set of identifiers.

[0123] Step (a12): Use the n random variables to mask the shuffled ciphertext feature to obtain masked data, use the first blinding factor to blind the shuffled third blind text to obtain a fourth blind text, and send the masked data and the fourth blind text to the second party, so that the second party performs homomorphic decryption on the masked data to obtain a third shard, and performs de-blinding on the fourth blind text to obtain a first blind text.

[0124] Step (a13): Determine the n random variables as the second shard.

[0125] In the present disclosure, when the first party and the second party jointly execute the OPRF protocol, the second party first generates a second blinding factor (randomly generated), and blinds the hash values of the identifiers in the second identifier set using the second blinding factor to obtain a third braille; meanwhile, the second party can homomorphically encrypt the above-mentioned single-dimensional feature held by itself using the locally generated target homomorphic encryption private key to obtain a ciphertext feature; then, the second party sends the ciphertext feature and the third braille to the first party; after receiving the ciphertext feature and the third braille, the first party shuffles the order of the ciphertext feature and the order of the third braille, and generates n random variables and a first blinding factor (randomly generated); then, the first party uses the n random variables to mask the shuffled ciphertext feature to obtain masked data, and uses the first blinding factor to blind the shuffled third braille to obtain a fourth braille; next, the first party sends the masked data and the fourth braille to the second party; after receiving the masked data and the fourth braille, the second party homomorphically decrypts the masked data using the above-mentioned target homomorphic encryption private key to obtain the above-mentioned third shard, and uses the second blinding factor to de-blind the fourth braille to obtain a first braille; meanwhile, the first party determines the locally generated n random variables as the second shard.

[0126] Exemplarily, the first party can use the n random variables to mask the shuffled ciphertext feature through the following equation to obtain masked data:

[0127]

[0128] where, YG j is the j-th masked data; k1 is the above-mentioned target homomorphic encryption private key; p j is the single-dimensional feature corresponding to the j-th identifier in the second identifier set; is the j-th ciphertext feature in the shuffled ciphertext feature; d j is the j-th random variable, j = 0, 1, 2,..., n - 1.

[0129] It should be noted that the second party can use the second blinding factor to blind the hash values of the identifiers in the second identifier set in a manner similar to the above-mentioned blinding of the hash values of the identifiers in the first identifier set using the first blinding factor, which will not be elaborated in the present disclosure.

[0130] In the above embodiment, after the first party receives the ciphertext feature and the third braille, it first shuffles the order of the ciphertext feature and the order of the third braille. Then, the first party uses n locally generated random variables to mask the ciphertext feature obtained after shuffling the order, obtaining masked data, and uses the locally generated first blinding factor to blind the third braille obtained after shuffling the order, obtaining the fourth braille, and sends the masked data and the fourth braille to the second party. In this way, it is possible to prevent the second party from learning the correspondence between the masked data and the ciphertext feature, and the correspondence between the third braille and the fourth braille, and thus infer the second shard, thereby preventing the second shard held by the first party from being leaked to the second party.

[0131] Next, a detailed description will be given of the specific implementation manner of performing the oblivious pseudorandom function protocol with the second party in the above step (b1) to obtain the first blinding factor. Specifically, it can be implemented through the following steps (b11) and (b12):

[0132] Step (b11): In response to receiving the third braille sent by the second party, shuffle the order of the third braille and generate the first blinding factor.

[0133] In the present disclosure, the third braille is obtained by the second party blinding the hash value of the identifier in the second identifier set.

[0134] Step (b12): Use the first blinding factor to blind the third braille obtained after shuffling the order, obtaining the fourth braille, and send the fourth braille to the second party for the second party to perform de-blinding processing on the fourth braille to obtain the first braille.

[0135] In the present disclosure, when the first party and the second party jointly execute the OPRF protocol, the second party first generates a second blinding factor (randomly generated), and uses the second blinding factor to blind the hash value of the identifier in the second identifier set to obtain the third braille; then, the second party sends the third braille to the first party; after the first party receives the third braille, it shuffles the order of the third braille and generates a first blinding factor (randomly generated); then, the first party uses the first blinding factor to blind the third braille obtained after shuffling the order to obtain the fourth braille; next, the first party sends the fourth braille to the second party; after the second party receives the fourth braille, it uses the second blinding factor to perform de-blinding processing on the fourth braille to obtain the first braille.

[0136] In the above embodiment, after the first party receives the third braille, it first shuffles the order of the third braille. Then, the first party uses the locally generated first blinding factor to blind the third braille obtained after shuffling the order, obtaining the fourth braille, and sends the fourth braille to the second party. In this way, it is possible to prevent the second party from learning the correspondence between the third braille and the fourth braille and inferring the first blinding factor.

[0137] The following is a detailed description of the specific implementation manner of obtaining the first polynomial corresponding to this dimension feature in S102 above.

[0138] In one implementation manner, the first party can construct the first polynomial through interpolation, so that the first polynomial f(x) ∈ F[x] satisfies f(ξ i ) = z i , where z i is the value of this dimension feature corresponding to the i-th identifier in the third identifier set, that is, the value of the first polynomial at the corresponding identifier in the third identifier set is the value of this dimension feature corresponding to the identifier, i = 0, 1, 2,..., N - 1.

[0139] Among them, the first party can construct the first polynomial through various interpolation methods. In one implementation manner, the first party can construct the first polynomial through Lagrange interpolation method. Among them, the complexity of constructing the first polynomial in this way is O(N 3 ).

[0140] In another implementation manner, the first party can use the fast Fourier transform method to perform polynomial interpolation on the dimension features corresponding to the identifiers in the third identifier set to obtain the first polynomial corresponding to this dimension feature. Among them, the complexity of constructing the first polynomial in this way is O(NlogN). Therefore, preferably, the fast Fourier transform method can be used to construct the first polynomial to reduce the complexity of polynomial construction, thereby improving the execution efficiency of the target data processing task.

[0141] In the present disclosure, the first polynomial can be constructed online. In order to improve the execution efficiency of the target data processing task, the first polynomial can also be constructed offline (that is, the first polynomial is constructed in advance).

[0142] The following is a detailed description of the specific implementation manner of calculating the values of the first polynomial at at least some identifiers in the target identifier set with the second party in S103 above to obtain the first shard of the values. Specifically, it can be implemented through the following steps (c1) and (c2).

[0143] Step (c1): In response to receiving the ciphertext polynomial sent by the second party, perform degree reduction processing on the first polynomial according to the ciphertext polynomial to obtain the second polynomial.

[0144] In the present disclosure, the ciphertext polynomial is generated by the second party based on the target identifier set. Specifically, the second party can construct a fourth polynomial based on the target identifier set and perform homomorphic encryption on the fourth polynomial to obtain the ciphertext polynomial.

[0145] Exemplarily, based on the target identifier set, the fourth polynomial can be constructed through the following equation:

[0146] h k (x) = x kq mod g(x) k = 0, 1, 2, …, L

[0147] Among them, there are L + 1 fourth polynomials, and h k (x) is the k-th fourth polynomial, and the second party obtains N by interacting with the first party.

[0148] After constructing L + 1 fourth polynomials, the second party can use the locally generated first homomorphic encryption private key to perform homomorphic encryption on the L + 1 fourth polynomials respectively to obtain L + 1 ciphertext polynomials, and send them to the first party. Among them, the k-th ciphertext polynomial is obtained by the second party performing homomorphic encryption on h k (x) (i.e., x kq mod g(x)).

[0149] After receiving the ciphertext polynomials sent by the second party, the first party can perform a degree reduction process on the first polynomial according to the ciphertext polynomials to obtain the second polynomial.

[0150] Step (c2): Calculate the values of the second polynomial on at least some of the identifiers in the target identifier set with the second party to obtain the first shard.

[0151] In the present disclosure, after the first party and the second party jointly calculate the values of the second polynomial on at least some of the identifiers in the target identifier set, the first party can obtain the first shard of the values, and the second party can obtain the sixth shard of the values. Among them, the values of the second polynomial on at least some of the identifiers in the target identifier set are the feature shards corresponding to at least some of the identifiers in the target identifier set.

[0152] Next, the specific implementation manner of performing a degree reduction process on the first polynomial according to the ciphertext polynomials in step (c1) above to obtain the second polynomial will be described in detail. Specifically, it can be implemented through the following steps (c11) to step (c13):

[0153] Step (c11): Convert the first polynomial into form.

[0154] Step (c12): Multiply f k (x) by the k-th ciphertext polynomial to obtain the fifth polynomial, where k = 0, 1, 2, …, L.

[0155] Among them, f k (x) is the plaintext, and the ciphertext polynomial is the ciphertext. At this time, the plaintext-ciphertext multiplication protocol can be used to multiply the two to obtain the fifth polynomial.

[0156] Step (c13): Determine the sum of each fifth polynomial and f0(x) as the second polynomial.

[0157] The sum of each fifth polynomial and f0(x) is which is equal to That is, the second polynomial is obtained

[0158] The following details the specific implementation for the first party and the second party to calculate the values of the second polynomial on at least some of the identities in the target identity set in step (c2) above to obtain the first shard. Specifically, it can be implemented through the following steps (c21) to step (c23):

[0159] Step (c21): Generate a random polynomial with the same degree as the second polynomial.

[0160] Step (c22): Use the random polynomial to mask the second polynomial to obtain a masked polynomial, and send the masked polynomial to the second party for the second party to decrypt the masked polynomial to obtain the third polynomial.

[0161] Specifically, the difference between the second polynomial and the random polynomial can be determined as the masked polynomial and sent to the second party; after receiving the masked polynomial, the second party can decrypt it using the first homomorphic encryption private key to obtain the third polynomial.

[0162] Step (c23): Based on the random polynomial, execute a sharded polynomial evaluation protocol with the second party to obtain the first shard of the values of the second polynomial on at least some of the identities in the target identity set, where the second party executes the sharded polynomial evaluation protocol based on the third polynomial.

[0163] In the present disclosure, the first party can, based on the random polynomial, and the second party can, based on the third polynomial, jointly execute a Shared Polynomial Evaluation Protocol to respectively obtain the shards of the values of the second polynomial on at least some of the identities in the target identity set.

[0164] Specifically, the first party can homomorphically encrypt the coefficient vector of the random polynomial using the locally generated second homomorphic encryption private key to obtain an encrypted vector and send it to the second party; after receiving the encrypted vector, the second party can generate a difference vector based on the encrypted vector and the third polynomial and send it to the first party; the first party decrypts the received difference vector using the second homomorphic encryption private key to obtain the first shard of the values of the second polynomial on at least some of the identities in the target identity set.

[0165] Among them, the second party can generate a difference vector based on the encrypted vector and the third polynomial in the following manner:

[0166] First, generate a sixth polynomial with the sum of the coefficient vector of the third polynomial and the encrypted vector as the coefficient vector; then, substitute each identifier in at least part of the identifiers in the target identifier set into the sixth polynomial respectively to obtain a result vector. Among them, after each identifier in at least part of the identifiers in the target identifier set is substituted into the sixth polynomial, the value of the sixth polynomial on this identifier can be obtained, and these values constitute the result vector; next, generate a random vector with the same length as the result vector, and determine the difference between the result vector and the random vector as the difference vector. Among them, the second party uses this random vector as the sixth shard of the value of the second polynomial on at least part of the identifiers in the intersection target identifier set.

[0167] Figure 4 It is a flowchart of a data processing method for secure computing applied to the second party shown according to an exemplary embodiment. As Figure 4 shown, the method may include S201 to S204.

[0168] In S201, based on the second identifier set, perform a data processing process based on the target protocol with the first party, and at least obtain the first index number of the intersection of the first identifier set and the second identifier set in the first identifier set.

[0169] In the present disclosure, the participants in secure computing include the first party and the second party. The first party holds the first identifier set, and the identifiers in the first identifier set correspond to h-dimensional features. The second party holds the second identifier set, where h≥1.

[0170] In S202, generate a target identifier set based on the first index number.

[0171] In S203, for each polynomial in at least one first polynomial, calculate the value of the first polynomial on at least part of the identifiers in the target identifier set with the first party to obtain the sixth shard of the value.

[0172] Among them, at least one first polynomial is constructed by the first party for each dimension feature in at least part of the dimension features in the h-dimensional features, based on the dimension feature corresponding to the identifier in the third identifier set. The third identifier set is generated by the first party based on the index number of the identifier in the first identifier set, and the generation method of the third identifier set is the same as that of the target identifier set;

[0173] In S204, perform the target data processing task based at least on the sixth shard.

[0174] In the above technical solution, first, the first party and the second party jointly execute a data processing process based on a target protocol, and the second party obtains at least the first index number of the intersection of the first identification set and the second identification set in the first identification set; then, based on the first index number, the second party generates a target identification set. At the same time, for each of at least some of the h-dimensional features held by the first party, the first party obtains a first polynomial corresponding to the feature dimension; next, the first party and the second party calculate the values of the first polynomial on at least some of the identifications in the target identification set to respectively obtain a shard of the value; finally, the first party and the second party respectively execute a target data processing task based on the shards held by themselves. In this way, the sharding problem of the features corresponding to the intersection of the identification sets held by both parties can be cleverly converted into a polynomial evaluation problem. Among them, the first party synchronizes the first index number without substantial physical meaning to the second party, so that the second party generates a target identification set locally based on the first index number, rather than directly synchronizing the target identification set to the second party, which can not only reduce the communication volume but also avoid the leakage of the first party's data. In addition, both parties use the target identification set to replace the intersection to calculate the value of the first polynomial on the intersection. In this way, even when the second identification set is not a subset of the first identification set, it can be ensured that the obtained feature shard is an accurate result of the feature shard corresponding to the intersection. Therefore, the accuracy of the feature shard can be guaranteed, enabling the target data processing task to be reliably executed. In addition, instead of calculating the intersection, both parties use the target identification set to replace the intersection, which can avoid the problem of data leakage caused by any party calculating the intersection. Therefore, through this solution, data security can be protected and accuracy can be guaranteed in scenarios such as model training and SQL queries.

[0175] Optionally, the identifications in the second identification set correspond to single-dimensional features; based on the second identification set, when executing the data processing process based on the target protocol with the first party and obtaining at least the first index number of the intersection of the first identification set and the second identification set in the first identification set, it includes: executing an oblivious pseudorandom function protocol with the first party based on the second identification set and the single-dimensional features to obtain a third shard of the single-dimensional features corresponding to the second identification set and a first braille based on the second identification set; in response to receiving the second braille sent by the first party, performing an intersection operation on the first braille and the second braille to obtain the first index number and the second index number of the intersection in the second identification set, where the second braille is obtained by the first party blinding the hash values of the identifications in the first identification set; according to the second index number, screening out a fourth shard of the single-dimensional features corresponding to the intersection from the third shard and sending the second index number to the first party, so that the first party can obtain a fifth shard of the single-dimensional features corresponding to the intersection according to the second index number.

[0176] Optionally, based on the second identifier set and the one-dimensional feature, perform an oblivious pseudorandom function protocol with the first party to obtain a third shard of the one-dimensional feature corresponding to the second identifier set and a first braille based on the second identifier set, including: generating a second blinding factor, and using the second blinding factor to blind the hash value of the identifier in the second identifier set to obtain a third braille; performing homomorphic encryption on the one-dimensional feature to obtain a ciphertext feature; sending the ciphertext feature and the third braille to the first party, so that the first party performs a masking process on the ciphertext feature to obtain masked data, and performs a blinding process on the third braille to obtain a fourth braille, and sends the masked data and the fourth braille to the second party; performing homomorphic decryption on the received masked data to obtain a third shard, and using the second blinding factor to perform a deblinding process on the received fourth braille to obtain a first braille.

[0177] Optionally, perform a target data processing task based at least on the sixth shard, including: performing a target data processing task based on the sixth shard and the fourth shard.

[0178] Optionally, the identifier in the second identifier set does not correspond to any feature; based on the second identifier set, perform a data processing process based on a target protocol with the first party to at least obtain a first index number of the intersection of the first identifier set and the second identifier set in the first identifier set, including: based on the second identifier set, perform an oblivious pseudorandom function protocol with the first party to obtain a first braille based on the second identifier set; in response to receiving the second braille sent by the first party, perform an intersection operation on the first braille and the second braille to obtain a first index number, where the second braille is obtained by the first party blinding the hash value of the identifier in the first identifier set.

[0179] Optionally, based on the second identifier set, perform an oblivious pseudorandom function protocol with the first party to obtain a first braille based on the second identifier set, including: generating a second blinding factor, and using the second blinding factor to blind the hash value of the identifier in the second identifier set to obtain a third braille; sending the third braille to the first party, so that the first party performs a blinding process on the third braille to obtain a fourth braille, and sends the fourth braille to the second party; using the second blinding factor to perform a deblinding process on the received fourth braille to obtain a first braille.

[0180] Optionally, calculate the value of the first polynomial on at least some of the identifiers in the target identifier set with the first party to obtain a sixth shard of the value, including: based on the target identifier set, construct a fourth polynomial, and perform homomorphic encryption on the fourth polynomial to obtain a ciphertext polynomial; send the ciphertext polynomial to the first party, so that the first party, for each of at least some of the h-dimensional features in the h-dimensional feature, according to the ciphertext polynomial, perform a degree reduction process on the first polynomial corresponding to the dimension feature to obtain a second polynomial; calculate the value of the second polynomial on at least some of the identifiers in the target identifier set with the first party to obtain a sixth shard.

[0181] Optionally, calculating, by the first party, values of a second polynomial on at least some of the identities in the target identity set to obtain a sixth shard, including: decrypting the masked polynomial in response to receiving the masked polynomial sent by the first party to obtain a third polynomial, where the masked polynomial is obtained by the first party masking a randomly generated polynomial of its own; based on the third polynomial, performing a sharded polynomial evaluation protocol with the first party to obtain a sixth shard of the values of the second polynomial on at least some of the identities in the target identity set, where the first party performs the sharded polynomial evaluation protocol based on the randomly generated polynomial. The specific implementation manners of the steps in the data processing method for secure computation applied to the second party according to the embodiments of the present disclosure have been described in detail in the data processing method for secure computation applied to the first party according to the embodiments of the present disclosure, and will not be elaborated here.

[0182] Figure 5 is a block diagram of a data processing device for secure computation applied to a first party shown according to an exemplary embodiment. Among them, the parties participating in the secure computation include a first party and a second party. The first party holds a first identity set, and the identities in the first identity set correspond to h-dimensional features. The second party holds a second identity set, where h≥1. As Figure 5 shown, the device 300 includes: a first index number synchronization module 301, configured to perform a data processing process based on a target protocol with the second party based on the first identity set, so that the second party obtains at least a first index number of the intersection of the first identity set and the second identity set in the first identity set; an acquisition module 302, configured to, for each of at least some of the h-dimensional features, acquire a first polynomial corresponding to the feature, where the first polynomial is constructed based on the feature corresponding to the identity in a third identity set, and the third identity set is generated based on the index numbers of the identities in the first identity set; a first evaluation module 303, configured to calculate, with the second party, values of the first polynomial on at least some of the identities in the target identity set to obtain a first shard of the values, where the target identity set is generated by the second party based on the first index number, and the third identity set and the target identity set are generated in the same manner; a first execution module 304, configured to perform a target data processing task based at least on the first shard.

[0183] In the above technical solution, first, the first party and the second party jointly execute a data processing process based on a target protocol, and the second party obtains at least the first index number of the intersection of the first identification set and the second identification set in the first identification set; then, the second party generates a target identification set based on the first index number. At the same time, for each of at least some of the h-dimensional features held by the first party, the first party obtains a first polynomial corresponding to the dimension feature; next, the first party and the second party calculate the values of the first polynomial on at least some of the identifications in the target identification set to respectively obtain a shard of the value; finally, the first party and the second party respectively execute a target data processing task based on the shards held by themselves. In this way, the sharding problem of the features corresponding to the intersection of the identification sets held by both parties can be cleverly converted into a polynomial evaluation problem. Among them, the first party synchronizes the first index number without substantial physical meaning to the second party, so that the second party generates a target identification set locally based on the first index number, rather than directly synchronizing the target identification set to the second party, which can not only reduce the communication volume, but also avoid the leakage of the first party's data. In addition, both parties use the target identification set to replace the intersection to calculate the value of the first polynomial on the intersection. In this way, even when the second identification set is not a subset of the first identification set, it can be ensured that the obtained feature shard is an accurate result of the feature shard corresponding to the intersection. Therefore, the accuracy of the feature shard can be ensured, and the target data processing task can be reliably executed. In addition, instead of calculating the intersection, both parties use the target identification set to replace the intersection, which can avoid the problem of data leakage caused by any party calculating the intersection. Therefore, through this solution, data security can be protected and accuracy can be ensured in scenarios such as model training and SQL queries.

[0184] Optionally, the identifiers in the second identifier set correspond to one-dimensional features; the first index number synchronization module 301 includes: a first execution sub-module, configured to execute an oblivious pseudo-random function protocol with the second party to obtain a first blinding factor and a second shard of the one-dimensional features corresponding to the second identifier set, wherein the second party executes the oblivious pseudo-random function protocol based on the second identifier set and the one-dimensional features to obtain a third shard of the one-dimensional features corresponding to the second identifier set and a first blind text based on the second identifier set; a first blinding sub-module, configured to perform a blinding process on the hash values of the identifiers in the first identifier set by using the first blinding factor to obtain a second blind text; a first sending sub-module, configured to send the second blind text to the second party, so that the second party performs an intersection operation on the first blind text and the second blind text to obtain the first index number, a second index number of the intersection in the second identifier set, and a fourth shard of the one-dimensional features corresponding to the intersection, and send the second index number to the first party; a first screening sub-module, configured to screen out a fifth shard of the one-dimensional features corresponding to the intersection from the second shards according to the received second index number.

[0185] Optionally, the first execution sub-module includes: a first scrambling sub-module, configured to, in response to receiving a ciphertext feature and a third blind text sent by the second party, scramble the order of the ciphertext feature and the order of the third blind text, and generate n random variables and the first blinding factor, wherein the ciphertext feature is obtained by the second party performing homomorphic encryption on the one-dimensional features, n is the number of identifiers in the second identifier set, and the third blind text is obtained by the second party performing a blinding process on the hash values of the identifiers in the second identifier set; a first processing sub-module, configured to perform a masking process on the scrambled ciphertext feature by using the n random variables to obtain masked data, perform a blinding process on the scrambled third blind text by using the first blinding factor to obtain a fourth blind text, and send the masked data and the fourth blind text to the second party, so that the second party performs homomorphic decryption on the masked data to obtain the third shard, and performs a de-blinding process on the fourth blind text to obtain the first blind text; a determination sub-module, configured to determine the n random variables as the second shards.

[0186] Optionally, the first execution module 304 is configured to perform a target data processing task based on the first shard and the fifth shard.

[0187] Optionally, the identifiers in the second identifier set do not correspond to any features; the first index number synchronization module 301 includes: a second execution sub-module, configured to execute an oblivious pseudo-random function protocol with the second party to obtain a first blinding factor, where the second party executes the oblivious pseudo-random function protocol based on the second identifier set to obtain a first blind text based on the second identifier set; a first blinding sub-module, configured to perform a blinding process on the hash values of the identifiers in the first identifier set by using the first blinding factor to obtain a second blind text; a second sending sub-module, configured to send the second blind text to the second party, so that the second party performs an intersection operation on the first blind text and the second blind text to obtain the first index number.

[0188] Optionally, the second execution sub-module includes: a second scrambling sub-module, configured to, in response to receiving a third blind text sent by the second party, scramble the order of the third blind text and generate the first blinding factor, where the third blind text is obtained by the second party performing a blinding process on the hash values of the identifiers in the second identifier set; a second processing sub-module, configured to perform a blinding process on the scrambled third blind text by using the first blinding factor to obtain a fourth blind text, and send the fourth blind text to the second party, so that the second party performs a de-blinding process on the fourth blind text to obtain the first blind text.

[0189] Optionally, the obtaining module 302 is configured to perform polynomial interpolation on the feature corresponding to the identifier in the third identifier set by using a fast Fourier transform method to obtain a first polynomial corresponding to the feature.

[0190] Optionally, the first evaluation module 303 includes: a degree reduction sub-module, configured to, in response to receiving a ciphertext polynomial sent by the second party, perform a degree reduction process on the first polynomial according to the ciphertext polynomial to obtain a second polynomial, where the ciphertext polynomial is generated by the second party based on the target identifier set; a first calculation sub-module, configured to calculate, with the second party, the values of the second polynomial on at least some of the identifiers in the target identifier set to obtain the first shard.

[0191] Optionally, the first calculation sub-module includes: a generation sub-module for generating a random polynomial having the same degree as the second polynomial; a third processing sub-module for masking the second polynomial with the random polynomial to obtain a masked polynomial, and sending the masked polynomial to the second party for the second party to decrypt the masked polynomial to obtain a third polynomial; a first evaluation sub-module for performing a sharded polynomial evaluation protocol with the second party based on the random polynomial to obtain a first shard of the values of the second polynomial on at least some of the identities in the target identity set, wherein the second party performs the sharded polynomial evaluation protocol based on the third polynomial.

[0192] Figure 6 is a block diagram of a data processing device for secure computing applied to a second party shown according to an exemplary embodiment. Among them, the parties participating in the secure computing include a first party and a second party. The first party holds a first identity set, and the identities in the first identity set correspond to h-dimensional features. The second party holds a second identity set, where h≥1. As Figure 6 shown, the device 400 includes: a second index number synchronization module 401 for performing a data processing process based on the target protocol with the first party based on the second identity set to at least obtain a first index number of the intersection of the first identity set and the second identity set in the first identity set; a generation module 402 for generating a target identity set based on the first index number; a second evaluation module 403 for calculating, for each of at least one first polynomial, the value of the first polynomial on at least some of the identities in the target identity set with the first party to obtain a sixth shard of the value, wherein the at least one first polynomial is constructed by the first party for each of at least some of the h-dimensional features based on the feature corresponding to the identity in the third identity set, the third identity set is generated by the first party based on the index numbers of the identities in the first identity set, and the generation method of the third identity set is the same as that of the target identity set; a second execution module 404 for performing a target data processing task based at least on the sixth shard.

[0193] In the above technical solution, first, the first party and the second party jointly execute a data processing process based on a target protocol. The second party obtains at least the first index number of the intersection of the first identification set and the second identification set in the first identification set. Then, based on the first index number, the second party generates a target identification set. At the same time, for each of at least some of the h-dimensional features held by the first party, the first party obtains a first polynomial corresponding to the feature dimension. Next, the first party and the second party calculate the values of the first polynomial on at least some of the identifications in the target identification set to respectively obtain a shard of the values. Finally, the first party and the second party respectively execute a target data processing task based on the shards held by themselves. In this way, the sharding problem of the features corresponding to the intersection of the identification sets held by both parties can be cleverly converted into a polynomial evaluation problem. Among them, the first party synchronizes the first index number without substantial physical meaning to the second party, so that the second party generates a target identification set locally based on the first index number, rather than directly synchronizing the target identification set to the second party, which can not only reduce the communication volume, but also avoid the leakage of the first party's data. In addition, both parties use the target identification set to replace the intersection to calculate the value of the first polynomial on the intersection. In this way, even when the second identification set is not a subset of the first identification set, it can be ensured that the obtained feature shard is an accurate result of the feature shard corresponding to the intersection. Therefore, the accuracy of the feature shard can be ensured, and the target data processing task can be reliably executed. In addition, instead of calculating the intersection, both parties use the target identification set to replace the intersection, which can avoid the problem of data leakage caused by any party calculating the intersection. Therefore, through this solution, data security can be protected and accuracy can be ensured in scenarios such as model training and SQL query.

[0194] Optionally, the identifications in the second identification set correspond to single-dimensional features. The second index number synchronization module 401 includes: a third execution sub-module, configured to execute an oblivious pseudorandom function protocol with the first party based on the second identification set and the single-dimensional features to obtain a third shard of the single-dimensional features corresponding to the second identification set and a first blind text based on the second identification set; an intersection calculation sub-module, configured to perform an intersection operation on the first blind text and the second blind text in response to receiving the second blind text sent by the first party to obtain the first index number and a second index number of the intersection in the second identification set, where the second blind text is obtained by the first party blinding the hash value of the identifications in the first identification set; a second screening sub-module, configured to screen out a fourth shard of the single-dimensional features corresponding to the intersection from the third shards according to the second index number and send the second index number to the first party, so that the first party obtains a fifth shard of the single-dimensional features corresponding to the intersection according to the second index number.

[0195] Optionally, the third execution sub-module includes: a second blinding sub-module, configured to generate a second blinding factor and use the second blinding factor to perform a blinding process on the hash values of the identifiers in the second identifier set to obtain a third braille; a homomorphic encryption sub-module, configured to perform homomorphic encryption on the one-dimensional feature to obtain a ciphertext feature; a third sending sub-module, configured to send the ciphertext feature and the third braille to the first party, so that the first party performs a masking process on the ciphertext feature to obtain masked data, and performs a blinding process on the third braille to obtain a fourth braille, and sends the masked data and the fourth braille to the second party; a homomorphic decryption sub-module, configured to perform homomorphic decryption on the received masked data to obtain the third shard, and use the second blinding factor to perform a de-blinding process on the received fourth braille to obtain the first braille.

[0196] Optionally, the second execution module 404 is configured to perform a target data processing task based on the sixth shard and the fourth shard.

[0197] Optionally, the identifiers in the second identifier set do not correspond to any features; the second index number synchronization module 401 includes: a fourth execution sub-module, configured to execute an oblivious pseudorandom function protocol with the first party based on the second identifier set to obtain a first braille based on the second identifier set; a fourth sending sub-module, configured to perform an intersection operation on the first braille and the second braille in response to receiving the second braille sent by the first party to obtain the first index number, where the second braille is obtained by the first party performing a blinding process on the hash values of the identifiers in the first identifier set.

[0198] Optionally, the fourth execution sub-module includes: a second blinding sub-module, which generates a second blinding factor and uses the second blinding factor to perform a blinding process on the hash values of the identifiers in the second identifier set to obtain a third braille; a fifth sending sub-module, configured to send the third braille to the first party, so that the first party performs a blinding process on the third braille to obtain a fourth braille, and sends the fourth braille to the second party; a de-blinding sub-module, configured to perform a de-blinding process on the received fourth braille using the second blinding factor to obtain the first braille.

[0199] Optionally, the second evaluation module 403 includes: a construction sub-module, configured to construct a fourth polynomial based on the target identifier set, and perform homomorphic encryption on the fourth polynomial to obtain a ciphertext polynomial; a sixth sending sub-module, configured to send the ciphertext polynomial to the first party, so that the first party performs a degree reduction process on a first polynomial corresponding to each dimension feature in at least some of the h-dimensional features according to the ciphertext polynomial, to obtain a second polynomial; a second calculation sub-module, configured to calculate, with the first party, values of the second polynomial on at least some of the identifiers in the target identifier set, to obtain the sixth shard.

[0200] Optionally, the second calculation sub-module includes: a polynomial decryption sub-module, configured to decrypt the masking polynomial in response to receiving the masking polynomial sent by the first party, to obtain a third polynomial, where the masking polynomial is obtained by the first party performing a masking process on a randomly generated polynomial of its own; a second evaluation sub-module, configured to, based on the third polynomial, execute a sharded polynomial evaluation protocol with the first party to obtain a sixth shard of values of the second polynomial on at least some of the identifiers in the target identifier set, where the first party executes the sharded polynomial evaluation protocol based on the randomly generated polynomial.

[0201] The present disclosure also provides a computer-readable medium, on which a computer program is stored, and when the program is executed by a processing device, the steps of the data processing method for secure computing provided by the present disclosure and applied to the first party or the steps of the data processing method for secure computing provided by the present disclosure and applied to the second party are implemented.

[0202] The present disclosure also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the data processing method for secure computing provided by the present disclosure and applied to the first party or the steps of the data processing method for secure computing provided by the present disclosure and applied to the second party are implemented.

[0203] Next, refer to Figure 7 , which shows a schematic structural diagram of an electronic device (such as a terminal device or a server) 600 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The electronic device shown is only an example, and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0204] As Figure 7As shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage device 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.

[0205] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 7 the electronic device 600 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0206] Specifically, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above functions defined in the method of the embodiment of the present disclosure are executed.

[0207] It should be noted that the computer-readable medium described above in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0208] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0209] The above computer-readable medium can be included in the above electronic device; it can also exist separately without being assembled into the electronic device.

[0210] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: based on a first set of identifiers, perform a data processing process based on a target protocol with a second party, so that the second party obtains at least a first index number of the intersection of the first set of identifiers and a second set of identifiers in the first set of identifiers, where the parties participating in the secure calculation include a first party and a second party, the first party holds the first set of identifiers, the identifiers in the first set of identifiers correspond to h-dimensional features, the second party holds the second set of identifiers, and h≥1; for each of at least some of the h-dimensional features, obtain a first polynomial corresponding to the feature, where the first polynomial is constructed based on the feature corresponding to the identifiers in a third set of identifiers, and the third set of identifiers is generated based on the index numbers of the identifiers in the first set of identifiers; calculate with the second party the values of the first polynomial on at least some of the identifiers in a target set of identifiers to obtain a first shard of the values, where the target set of identifiers is generated by the second party based on the first index number, and the third set of identifiers and the target set of identifiers are generated in the same way; perform a target data processing task based at least on the first shard.

[0211] Alternatively, the above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: based on a second set of identifiers, perform a data processing process based on a target protocol with the first party, and at least obtain a first index number of the intersection of the first set of identifiers and the second set of identifiers in the first set of identifiers, where the parties participating in the secure calculation include a first party and a second party, the first party holds the first set of identifiers, the identifiers in the first set of identifiers correspond to h-dimensional features, the second party holds the second set of identifiers, and h≥1; generate a target set of identifiers based on the first index number; for each of at least one first polynomial, calculate with the first party the values of the first polynomial on at least some of the identifiers in the target set of identifiers to obtain a sixth shard of the values, where the at least one first polynomial is constructed by the first party for each of at least some of the h-dimensional features based on the feature corresponding to the identifiers in a third set of identifiers, the third set of identifiers is generated by the first party based on the index numbers of the identifiers in the first set of identifiers, and the third set of identifiers and the target set of identifiers are generated in the same way; perform a target data processing task based at least on the sixth shard.

[0212] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0213] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0214] The modules described in the embodiments of the present disclosure may be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the module itself in some cases. For example, the first execution module may also be described as "the module that performs the target data processing task at least based on the first shard".

[0215] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, by way of non-limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), system on a chip (SOC), complex programmable logic devices (CPLD), and so on.

[0216] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0217] According to one or more embodiments of the present disclosure, Example 1 provides a data processing method for secure computing. The parties involved in the secure computing include a first party and a second party. The first party holds a first set of identifiers, and the identifiers in the first set of identifiers correspond to h-dimensional features. The second party holds a second set of identifiers, where h≥1. The method is applied to the first party and includes: based on the first set of identifiers, performing a data processing process based on a target protocol with the second party, so that the second party obtains at least a first index number of the intersection of the first set of identifiers and the second set of identifiers in the first set of identifiers; for each of at least some of the h-dimensional features, obtaining a first polynomial corresponding to the feature, where the first polynomial is constructed based on the feature corresponding to the identifiers in a third set of identifiers, and the third set of identifiers is generated based on the index numbers of the identifiers in the first set of identifiers; calculating with the second party the values of the first polynomial on at least some of the identifiers in a target set of identifiers to obtain a first shard of the values, where the target set of identifiers is generated by the second party based on the first index number, and the third set of identifiers and the target set of identifiers are generated in the same manner; performing a target data processing task based at least on the first shard.

[0218] According to one or more embodiments of the present disclosure, Example 2 provides the method of Example 1. The identifiers in the second identifier set correspond to one-dimensional features. The data processing process based on the target protocol is performed with the second party based on the first identifier set, so that the second party obtains at least the first index number of the intersection of the first identifier set and the second identifier set in the first identifier set, including: performing an oblivious pseudorandom function protocol with the second party to obtain a first blinding factor and a second shard of the one-dimensional features corresponding to the second identifier set, where the second party performs the oblivious pseudorandom function protocol based on the second identifier set and the one-dimensional features to obtain a third shard of the one-dimensional features corresponding to the second identifier set and a first blind text based on the second identifier set; blinding the hash values of the identifiers in the first identifier set with the first blinding factor to obtain a second blind text; sending the second blind text to the second party, so that the second party performs an intersection operation on the first blind text and the second blind text to obtain the first index number, the second index number of the intersection in the second identifier set, and a fourth shard of the one-dimensional features corresponding to the intersection, and sending the second index number to the first party; screening out a fifth shard of the one-dimensional features corresponding to the intersection from the second shard according to the received second index number.

[0219] According to one or more embodiments of the present disclosure, Example 3 provides the method of Example 2. The performing an oblivious pseudorandom function protocol with the second party to obtain a first blinding factor and a second shard of the one-dimensional features corresponding to the second identifier set includes: in response to receiving a ciphertext feature and a third blind text sent by the second party, shuffling the order of the ciphertext feature and the order of the third blind text, and generating n random variables and the first blinding factor, where the ciphertext feature is obtained by the second party performing homomorphic encryption on the one-dimensional features, n is the number of identifiers in the second identifier set, and the third blind text is obtained by the second party blinding the hash values of the identifiers in the second identifier set; masking the shuffled ciphertext feature with the n random variables to obtain masked data, blinding the shuffled third blind text with the first blinding factor to obtain a fourth blind text, and sending the masked data and the fourth blind text to the second party, so that the second party performs homomorphic decryption on the masked data to obtain the third shard, and performs de-blinding processing on the fourth blind text to obtain the first blind text; determining the n random variables as the second shard.

[0220] According to one or more embodiments of the present disclosure, Example 4 provides the method of Example 2. The performing a target data processing task based on at least the first shard includes: performing a target data processing task based on the first shard and the fifth shard.

[0221] According to one or more embodiments of the present disclosure, Example 5 provides the method of Example 1, where the identifiers in the second identifier set do not correspond to any features; based on the first identifier set, performing a data processing process with the second party based on a target protocol, so that the second party obtains at least a first index number of the intersection of the first identifier set and the second identifier set in the first identifier set, including: performing an oblivious pseudorandom function protocol with the second party to obtain a first blinding factor, where the second party performs the oblivious pseudorandom function protocol based on the second identifier set to obtain a first blind text based on the second identifier set; using the first blinding factor to perform a blinding process on the hash value of the identifier in the first identifier set to obtain a second blind text; sending the second blind text to the second party, so that the second party performs an intersection operation on the first blind text and the second blind text to obtain the first index number.

[0222] According to one or more embodiments of the present disclosure, Example 6 provides the method of Example 5, where performing an oblivious pseudorandom function protocol with the second party to obtain a first blinding factor includes: in response to receiving a third blind text sent by the second party, shuffling the order of the third blind text and generating the first blinding factor, where the third blind text is obtained by the second party performing a blinding process on the hash value of the identifier in the second identifier set; using the first blinding factor to perform a blinding process on the shuffled third blind text to obtain a fourth blind text, and sending the fourth blind text to the second party, so that the second party performs a deblinding process on the fourth blind text to obtain the first blind text.

[0223] According to one or more embodiments of the present disclosure, Example 7 provides the method of Example 1, where obtaining a first polynomial corresponding to this dimension of feature includes: using a fast Fourier transform method to perform polynomial interpolation on the feature corresponding to the identifier in the third identifier set to obtain a first polynomial corresponding to this dimension of feature.

[0224] According to one or more embodiments of the present disclosure, Example 8 provides the method of Example 1, where calculating, with the second party, the value of the first polynomial on at least some of the identifiers in the target identifier set to obtain a first shard of the value includes: in response to receiving a ciphertext polynomial sent by the second party, performing a degree reduction process on the first polynomial according to the ciphertext polynomial to obtain a second polynomial, where the ciphertext polynomial is generated by the second party based on the target identifier set; calculating, with the second party, the value of the second polynomial on at least some of the identifiers in the target identifier set to obtain the first shard.

[0225] According to one or more embodiments of the present disclosure, Example 9 provides the method of Example 8. Calculating, with the second party, values of the second polynomial on at least some of the identities in the target identity set to obtain the first shard includes: generating a random polynomial having the same degree as the second polynomial; using the random polynomial to mask the second polynomial to obtain a masked polynomial, and sending the masked polynomial to the second party for the second party to decrypt the masked polynomial to obtain a third polynomial; based on the random polynomial, performing a sharded polynomial evaluation protocol with the second party to obtain a first shard of the values of the second polynomial on at least some of the identities in the target identity set, wherein the second party performs the sharded polynomial evaluation protocol based on the third polynomial.

[0226] According to one or more embodiments of the present disclosure, Example 10 provides a data processing method for secure computing. The parties participating in the secure computing include a first party and a second party. The first party holds a first identity set, and the identities in the first identity set correspond to h-dimensional features. The second party holds a second identity set, h≥1. The method is applied to the second party and includes: based on the second identity set, performing a data processing process based on a target protocol with the first party to at least obtain a first index number of the intersection of the first identity set and the second identity set in the first identity set; based on the first index number, generating a target identity set; for each of at least one first polynomial, calculating, with the first party, values of the first polynomial on at least some of the identities in the target identity set to obtain a sixth shard of the values, wherein the at least one first polynomial is constructed by the first party for each of at least some of the h-dimensional features in the h-dimensional features based on the feature corresponding to the identity in a third identity set, and the third identity set is generated by the first party based on the index numbers of the identities in the first identity set, and the third identity set is generated in the same manner as the target identity set; performing a target data processing task based at least on the sixth shard.

[0227] According to one or more embodiments of the present disclosure, Example 11 provides the method of Example 10, where the identifiers in the second identifier set correspond to one-dimensional features; the data processing process based on the target protocol with the first party based on the second identifier set obtains at least the first index number of the intersection of the first identifier set and the second identifier set in the first identifier set, including: performing an oblivious pseudorandom function protocol with the first party based on the second identifier set and the one-dimensional features to obtain a third shard of the one-dimensional features corresponding to the second identifier set and a first braille based on the second identifier set; in response to receiving a second braille sent by the first party, performing an intersection operation on the first braille and the second braille to obtain the first index number and a second index number of the intersection in the second identifier set, where the second braille is obtained by the first party performing a blinding process on the hash value of the identifier in the first identifier set; according to the second index number, screening out a fourth shard of the one-dimensional features corresponding to the intersection from the third shard, and sending the second index number to the first party for the first party to obtain a fifth shard of the one-dimensional features corresponding to the intersection according to the second index number.

[0228] According to one or more embodiments of the present disclosure, Example 12 provides the method of Example 11, where the performing an oblivious pseudorandom function protocol with the first party based on the second identifier set and the one-dimensional features to obtain a third shard of the one-dimensional features corresponding to the second identifier set and a first braille based on the second identifier set includes: generating a second blinding factor and using the second blinding factor to perform a blinding process on the hash value of the identifier in the second identifier set to obtain a third braille; performing homomorphic encryption on the one-dimensional features to obtain a ciphertext feature; sending the ciphertext feature and the third braille to the first party for the first party to perform a masking process on the ciphertext feature to obtain masked data and perform a blinding process on the third braille to obtain a fourth braille, and sending the masked data and the fourth braille to the second party; performing homomorphic decryption on the received masked data to obtain the third shard, and using the second blinding factor to perform a deblinding process on the received fourth braille to obtain the first braille.

[0229] According to one or more embodiments of the present disclosure, Example 13 provides the method of Example 11, where the performing a target data processing task based at least on the sixth shard includes: performing a target data processing task based on the sixth shard and the fourth shard.

[0230] According to one or more embodiments of the present disclosure, Example 14 provides the method of Example 10, where the identifiers in the second identifier set do not correspond to any features; based on the second identifier set, performing a data processing process based on a target protocol with the first party, and at least obtaining a first index number of the intersection of the first identifier set and the second identifier set in the first identifier set, including: based on the second identifier set, performing an oblivious pseudorandom function protocol with the first party to obtain a first braille based on the second identifier set; in response to receiving a second braille sent by the first party, performing an intersection operation on the first braille and the second braille to obtain the first index number, where the second braille is obtained by the first party performing a blinding process on the hash value of the identifiers in the first identifier set.

[0231] According to one or more embodiments of the present disclosure, Example 15 provides the method of Example 14, where the based on the second identifier set, performing an oblivious pseudorandom function protocol with the first party to obtain a first braille based on the second identifier set, including: generating a second blinding factor, and using the second blinding factor to perform a blinding process on the hash value of the identifiers in the second identifier set to obtain a third braille; sending the third braille to the first party for the first party to perform a blinding process on the third braille to obtain a fourth braille, and sending the fourth braille to the second party; using the second blinding factor to perform a de - blinding process on the received fourth braille to obtain the first braille.

[0232] According to one or more embodiments of the present disclosure, Example 16 provides the method of Example 10, where calculating, with the first party, the value of the first polynomial on at least some of the identifiers in the target identifier set to obtain a sixth shard of the value, including: based on the target identifier set, constructing a fourth polynomial, and performing a homomorphic encryption on the fourth polynomial to obtain a ciphertext polynomial; sending the ciphertext polynomial to the first party for the first party to, for each of at least some of the h - dimensional features in the h - dimensional features, perform a degree - reduction process on the first polynomial corresponding to the feature dimension according to the ciphertext polynomial to obtain a second polynomial; calculating, with the first party, the value of the second polynomial on at least some of the identifiers in the target identifier set to obtain the sixth shard.

[0233] According to one or more embodiments of the present disclosure, Example 17 provides the method of Example 16. Calculating the values of the second polynomial on at least some of the identities in the target identity set with the first party to obtain the sixth shard includes: in response to receiving the masked polynomial sent by the first party, decrypting the masked polynomial to obtain a third polynomial, where the masked polynomial is obtained by the first party masking a randomly generated polynomial of its own; based on the third polynomial, performing a sharded polynomial evaluation protocol with the first party to obtain the sixth shard of the values of the second polynomial on at least some of the identities in the target identity set, where the first party performs the sharded polynomial evaluation protocol based on the randomly generated polynomial.

[0234] According to one or more embodiments of the present disclosure, Example 18 provides a computer-readable medium having a computer program stored thereon, and when the computer program is executed by a processing device, the steps of the method according to any one of Examples 1-17 are implemented.

[0235] According to one or more embodiments of the present disclosure, Example 19 provides an electronic device, including: a storage device having a computer program stored thereon; a processing device for executing the computer program in the storage device to implement the steps of the method according to any one of Examples 1-17.

[0236] According to one or more embodiments of the present disclosure, Example 20 provides a computer program product including a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of Examples 1-17 are implemented.

[0237] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features having similar functions disclosed in the present disclosure.

[0238] Moreover, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limitations on the scope of the present disclosure. Certain features that are described in the context of separate embodiments may also be implemented combinatorially in a single embodiment. Conversely, the various features that are described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0239] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims. With regard to the apparatus in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method and will not be elaborated here.

Claims

1. A data processing method for secure computing, wherein the participants of the secure computing include a first party and a second party, the first party holds a first identification set, and the identifications in the first identification set correspond to h dimension feature, the second party holds a second set of identifiers, h ≥1, characterized in that The method is applied to the first party, comprising: Based on the first identification set, perform a data processing process based on the target protocol with the second party, so that the second party obtains at least a first index number of an intersection of the first identification set and the second identification set in the first identification set; Regarding the h For each dimensional feature of at least some of the dimensional features in the dimensional features, obtain a first polynomial corresponding to the dimensional feature, wherein the first polynomial is constructed based on the dimensional feature corresponding to an identifier in a third identifier set, and the third identifier set is generated based on the index number of the identifier in the first identifier set; calculate with the second party the value of the first polynomial on at least some of the identifiers in the target identifier set to obtain a first slice of the value, wherein the target identifier set is generated by the second party based on the first index number, and the third identifier set is generated in the same manner as the target identifier set; Execute a target data processing task based at least on the first shard; The calculating, with the second party, the value of the first polynomial on at least part of the identifiers in the target identifier set to obtain a first slice of the value includes: In response to receiving the ciphertext polynomial sent by the second party, performing a degree reduction process on the first polynomial according to the ciphertext polynomial to obtain a second polynomial, wherein the ciphertext polynomial is generated by the second party based on the target identifier set; generating a random polynomial of the same degree as the second polynomial; Using the random polynomial to mask the second polynomial to obtain a masked polynomial, and sending the masked polynomial to the second party so that the second party can decrypt the masked polynomial to obtain a third polynomial; Based on the random polynomial, a sharded polynomial evaluation protocol is executed with the second party to obtain a first shard of the value of the second polynomial on at least some of the identifiers in the target identifier set, wherein the second party executes the sharded polynomial evaluation protocol based on the third polynomial.

2. The method according to claim 1, characterized in that The identifiers in the second identifier set correspond to single-dimensional features; The performing, based on the first identification set, a data processing process based on the target protocol with the second party so that the second party obtains at least a first index number of an intersection of the first identification set and the second identification set in the first identification set, comprises: performing an oblivious pseudo-random function protocol with the second party to obtain a first blinding factor and a second slice of the one-dimensional feature corresponding to the second set of identifiers, wherein the second party performs the oblivious pseudo-random function protocol based on the second set of identifiers and the one-dimensional feature to obtain a third slice of the one-dimensional feature corresponding to the second set of identifiers and a first braille based on the second set of identifiers; Using the first blinding factor to blind the hash value identified in the first identification set to obtain a second Braille; Sending the second Braille to the second party, so that the second party performs an intersection operation on the first Braille and the second Braille to obtain the first index number, the second index number of the intersection in the second identifier set, and the fourth slice of the one-dimensional feature corresponding to the intersection, and sending the second index number to the first party; According to the received second index number, a fifth slice of the one-dimensional feature corresponding to the intersection is screened out from the second slices.

3. The method according to claim 2, characterized in that The performing of the oblivious pseudo-random function protocol with the second party to obtain the second sharding of the one-dimensional feature corresponding to the first blinding factor and the second identification set includes: In response to receiving the ciphertext features and the third Braille sent by the second party, disrupting the order of the ciphertext features and the order of the third Braille, and generating n random variables and the first blinding factor, wherein the ciphertext feature is obtained by the second party performing homomorphic encryption on the one-dimensional feature, n is the number of identifiers in the second identifier set, and the third Braille is obtained by the second party performing blinding processing on the hash values ​​of the identifiers in the second identifier set; Using the n The method comprises: masking the ciphertext features obtained after the scrambling using a random variable to obtain masked data, blinding the third Braille obtained after the scrambling using the first blinding factor to obtain a fourth Braille, and sending the masked data and the fourth Braille to the second party, so that the second party performs homomorphic decryption on the masked data to obtain the third fragment, and deblinding the fourth Braille to obtain the first Braille; The n A random variable is determined as the second slice.

4. The method according to claim 2, characterized in that: The performing the target data processing task at least based on the first shard includes: Based on the first shard and the fifth shard, a target data processing task is executed.

5. The method according to claim 1, characterized in that The identifiers in the second identifier set do not correspond to any features; The performing, based on the first identification set, a data processing process based on the target protocol with the second party so that the second party obtains at least a first index number of an intersection of the first identification set and the second identification set in the first identification set, comprises: performing an oblivious pseudo-random function protocol with the second party to obtain a first blinding factor, wherein the second party performs the oblivious pseudo-random function protocol based on the second identifier set to obtain a first braille based on the second identifier set; Using the first blinding factor to blind the hash value identified in the first identification set to obtain a second Braille; The second Braille is sent to the second party, so that the second party performs an intersection operation on the first Braille and the second Braille to obtain the first index number.

6. The method according to claim 5, characterized in that The performing an inadvertent pseudo-random function protocol with the second party to obtain a first blinding factor comprises: In response to receiving a third Braille sent by the second party, scrambling the order of the third Braille and generating the first blinding factor, wherein the third Braille is obtained by the second party blinding the hash value identified in the second identification set; The third Braille obtained after the shuffle is blinded using the first blinding factor to obtain a fourth Braille, and the fourth Braille is sent to the second party so that the second party de-blinds the fourth Braille to obtain the first Braille.

7. The method according to claim 1, characterized in that The obtaining of a first polynomial corresponding to the dimensional feature includes: A fast Fourier transform method is used to perform polynomial interpolation on the dimensional feature corresponding to the identifier in the third identifier set to obtain a first polynomial corresponding to the dimensional feature.

8. A data processing method for secure computing, wherein the participants of the secure computing include a first party and a second party, the first party holds a first identification set, and the identifications in the first identification set correspond to h dimension feature, the second party holds a second set of identifiers, h ≥1, characterized in that The method is applied to the second party, comprising: Based on the second identification set, perform a data processing process based on the target protocol with the first party to obtain at least a first index number of an intersection of the first identification set and the second identification set in the first identification set; Based on the first index number, generating a target identification set; For each of the at least one first polynomial, the first party calculates the value of the first polynomial on at least part of the identifiers in the target identifier set to obtain a sixth slice of the value, wherein the at least one first polynomial is calculated by the first party for the h Each dimensional feature of at least some of the dimensional features is constructed based on the dimensional feature corresponding to an identifier in a third identifier set, the third identifier set is generated by the first party based on an index number of the identifier in the first identifier set, and the third identifier set is generated in the same manner as the target identifier set; Execute a target data processing task based at least on the sixth shard; The step of calculating with the first party the value of the first polynomial on at least part of the identifiers in the target identifier set to obtain a sixth fragment of the value includes: Based on the target identification set, construct a fourth polynomial, and perform homomorphic encryption on the fourth polynomial to obtain a ciphertext polynomial; The ciphertext polynomial is sent to the first party so that the first party can h For each dimensional feature of at least some of the dimensional features in the dimensional features, according to the ciphertext polynomial, a first polynomial corresponding to the dimensional feature is reduced in degree to obtain a second polynomial; In response to receiving the masking polynomial sent by the first party, decrypting the masking polynomial to obtain a third polynomial, wherein the masking polynomial is obtained by masking a random polynomial generated by the first party itself; Based on the third polynomial, a sharded polynomial evaluation protocol is executed with the first party to obtain a sixth shard of the value of the second polynomial on at least some of the identifiers in the target identifier set, wherein the first party executes the sharded polynomial evaluation protocol based on the random polynomial.

9. The method according to claim 8, characterized in that The identifiers in the second identifier set correspond to single-dimensional features; The step of performing a data processing process based on a target protocol with the first party based on the second identification set to obtain at least a first index number of an intersection of the first identification set and the second identification set in the first identification set includes: Based on the second identification set and the one-dimensional feature, executing an oblivious pseudo-random function protocol with the first party to obtain a third segment of the one-dimensional feature corresponding to the second identification set and a first Braille based on the second identification set; In response to receiving a second Braille sent by the first party, performing an intersection operation on the first Braille and the second Braille to obtain the first index number and a second index number of the intersection in the second identification set, wherein the second Braille is obtained by the first party performing blinding processing on a hash value identified in the first identification set; According to the second index number, the fourth slice of the one-dimensional feature corresponding to the intersection is filtered out from the third slice, and the second index number is sent to the first party, so that the first party can obtain the fifth slice of the one-dimensional feature corresponding to the intersection according to the second index number.

10. The method according to claim 9, characterized in that The method of performing an oblivious pseudo-random function protocol with the first party based on the second identification set and the one-dimensional feature to obtain a third fragment of the one-dimensional feature corresponding to the second identification set and a first Braille based on the second identification set includes: Generate a second blinding factor, and use the second blinding factor to blind the hash value identified in the second identification set to obtain a third Braille; Performing homomorphic encryption on the one-dimensional feature to obtain a ciphertext feature; sending the ciphertext feature and the third Braille to the first party, so that the first party performs masking processing on the ciphertext feature to obtain masked data, and performs blinding processing on the third Braille to obtain a fourth Braille, and sends the masked data and the fourth Braille to the second party; The received masked data is homomorphically decrypted to obtain the third fragment, and the received fourth Braille is deblinded using the second blinding factor to obtain the first Braille.

11. The method according to claim 9, characterized in that The performing the target data processing task at least based on the sixth shard includes: Based on the sixth shard and the fourth shard, a target data processing task is executed.

12. The method according to claim 8, characterized in that The identifiers in the second identifier set do not correspond to any features; The step of performing a data processing process based on a target protocol with the first party based on the second identification set to obtain at least a first index number of an intersection of the first identification set and the second identification set in the first identification set includes: Based on the second identification set, executing an oblivious pseudo-random function protocol with the first party to obtain a first Braille based on the second identification set; In response to receiving a second Braille sent by the first party, performing an intersection operation on the first Braille and the second Braille to obtain the first index number, wherein the second Braille is obtained by the first party performing blinding processing on a hash value identified in the first identification set.

13. The method according to claim 12, characterized in that The step of performing an oblivious pseudo-random function protocol with the first party based on the second identification set to obtain a first Braille based on the second identification set includes: Generate a second blinding factor, and use the second blinding factor to blind the identifier hash value in the second identifier set to obtain a third Braille; Sending the third Braille to the first party, so that the first party can perform blinding processing on the third Braille to obtain a fourth Braille, and sending the fourth Braille to the second party; The received fourth Braille is de-blinded by using the second blinding factor to obtain the first Braille.

14. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 13 are implemented.

15. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 13.

16. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 13 are implemented.

Citation Information

Patent Citations

  • Three-party privacy set intersection acquisition method and system

    CN115277253A

  • Method and device for determining multi-party privacy data intersection

    CN115758441A