A method and device for verifying the result of private set intersection

The method encrypts query objects and uses privacy-preserving protocols to verify PSI results, addressing the complexity and privacy concerns of traditional verification methods by ensuring accurate and secure comparisons across institutions.

CN119442318BActive Publication Date: 2025-07-15WEBANK (CHINA)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411537576.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-31
Publication Date
2025-07-15
Estimated Expiration
2044-10-31

AI Technical Summary

Technical Problem

It is difficult for the existing technology to effectively verify the results of privacy submissions. Traditional methods require direct access to plain text data, which poses a risk of privacy leakage and cannot cover all situations.

Method used

By encrypting the objects to be queried and the full objects, using the privacy submission protocol to generate privacy identifiers, combining query flow records and object change records, offline verification is carried out to ensure data security and accuracy.

Benefits of technology

It realizes the accurate verification of the privacy submission results without leaking data information, improves the reliability and security of verification, and avoids privacy leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119442318B_ABST
    Figure CN119442318B_ABST
Patent Text Reader

Abstract

The present application provides a method and apparatus for verifying a private intersection result, including: after the (i-1)-th offline moment, a first institution receives a private intersection request, where the private intersection request includes an object to be queried; the first institution encrypts the object to be queried into a first privacy identifier and sends it to a second institution, and obtains a first private intersection result fed back by the second institution; the first institution writes the first private intersection result and the object to be queried into a query flow record; at the i-th offline moment, the first institution obtains the records to be verified within the i-th interval period from the query flow record; the first institution obtains each second privacy identifier of the second institution; each second privacy identifier is obtained after the second institution encrypts its own stored full amount of objects respectively; the first institution verifies each private intersection result within the i-th interval period fed back by the second institution according to the records to be verified and each second privacy identifier. This solution can effectively verify the private intersection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method and device for verifying the result of private set intersection. Background Art

[0002] Private Set Intersection (PSI) is an important means to protect the privacy of participants during the data exchange process, which enables the participating parties to jointly calculate the intersection of data without disclosing their respective data. This technology has a wide range of applications in multiple fields, including but not limited to financial services, healthcare, social networks, market research, etc.

[0003] The core advantage of private set intersection lies in protecting data privacy. The participating parties cannot obtain the original data information of the other party, which makes the verification of the private set intersection result a complex and difficult problem. Traditional data verification methods usually require direct access to plaintext data, which is obviously no longer applicable in this scenario. Summary of the Invention

[0004] This application provides a method and device for verifying the result of private set intersection, which can effectively verify the result of private set intersection.

[0005] In a first aspect, an embodiment of this application provides a method for verifying the result of private set intersection. This method can be executed by a verification device for the result of private set intersection. The verification device for the result of private set intersection can be a terminal device or a module for a terminal device, or a server or a module for a server. This application does not limit the execution entity of this method. The method includes: after receiving a private set intersection request at the (i - 1)-th offline moment, the first institution, where the private set intersection request includes an object to be queried; where i is a positive integer; the first institution encrypts the object to be queried into a first privacy identifier and sends it to the second institution, and obtains a first private set intersection result fed back by the second institution; the first private set intersection result is used to indicate whether the second institution has the object to be queried; the first institution writes the first private set intersection result and the object to be queried into a query flow record; the first institution obtains the to-be-verified records within the i-th interval period from the query flow record at the i-th offline moment; the i-th interval period is the period corresponding to the (i - 1)-th offline moment to the i-th offline moment; the first institution obtains each second privacy identifier of the second institution; each second privacy identifier is obtained by the second institution encrypting its own stored full amount of objects respectively; the first institution verifies each private set intersection result within the i-th interval period fed back by the second institution according to the to-be-verified records and each second privacy identifier.

[0006] In the above solution, first obtain the real-time private intersection result of the first institution in the i-th interval, and then compare the real-time private intersection result of the i-th interval with each second private identifier of the second institution, which can accurately and effectively verify each private intersection result within the i-th interval fed back by the second institution.

[0007] In a possible implementation method, the query water record further includes the processing time corresponding to the private intersection request; the first institution verifies each private intersection result within the i-th interval fed back by the second institution according to the record to be verified and each second private identifier, including: determining the second private intersection result of the record to be verified and each second private identifier of the second institution; if the first private intersection result in any record in the record to be verified matches the second private intersection result, it is determined that the first private intersection result fed back by the second institution passes the verification; if the first private intersection result in any record in the record to be verified does not match the second private intersection result, the object change record recorded by the second institution and the processing time in the unmatched record are used to further verify the unmatched first private intersection result; the object change record records the change time and change status of any object.

[0008] In the above solution, since the i-th interval has a certain time length, it is possible that during this time period, the data of each object of the second institution changes, resulting in an error in verifying the first private intersection result. Therefore, when it is determined that the first private intersection result does not match the second private intersection result, through the object change record recorded by the second institution and the processing time in the unmatched record, it is possible to accurately and effectively further verify the unmatched first private intersection result.

[0009] In a possible implementation method, according to the privacy intersection result, each record in the to-be-verified record is divided into a first to-be-verified set and a second to-be-verified set; each record in the first to-be-verified set represents that the second institution does not have a corresponding to-be-query object; each record in the second to-be-verified set represents that the second institution has a corresponding to-be-query object; determining the second privacy intersection result between the to-be-verified record and each second privacy identifier of the second institution includes: determining the third privacy intersection result between the first to-be-verified set and each second privacy identifier of the second institution; determining the fourth privacy intersection result between the second to-be-verified set and each second privacy identifier of the second institution; judging whether the first privacy intersection result in any record matches the second privacy intersection result in the following way, including: if the set of the third privacy intersection results is empty, it is determined that the first privacy intersection result corresponding to the first privacy identifier in any record matches the second privacy intersection result, otherwise it does not match; if the first privacy intersection result in any record in the to-be-verified record is in the fourth privacy intersection result, it is determined that the first privacy intersection result corresponding to the first privacy identifier in any record matches the second privacy intersection result, otherwise it does not match.

[0010] In the above solution, each record in the to-be-verified record is divided into a first to-be-verified set and a second to-be-verified set, and the privacy intersection results of the first to-be-verified set and the second to-be-verified set can be verified respectively according to different situations of the first to-be-verified set and the second to-be-verified set, so as to accurately and effectively verify each privacy intersection result in the i-th time interval fed back by the second institution.

[0011] In a possible implementation method, if the unmatched record belongs to the first to-be-verified set, through the object change record recorded by the second institution, it is determined that before the processing time in the unmatched record, the change status of the second privacy identifier corresponding to the first privacy identifier in the unmatched record in the second institution is an invalid state; after the processing time in the unmatched record, the change status of the second privacy identifier corresponding to the first privacy identifier in the unmatched record in the second institution is updated to a valid state, then it is determined that the first privacy intersection result in the unmatched record matches the third privacy intersection result.

[0012] The above solution can be accurate and effective, and further verify the unmatched first privacy intersection result.

[0013] In a possible implementation method, if the unmatched record belongs to the second set of records to be verified, determine, through the object change records recorded by the second institution, that before the processing time in the unmatched record, the change status of the second privacy identifier corresponding to the first privacy identifier in the unmatched record in the second institution is the valid status; after the processing time in the unmatched record, the change status of the second privacy identifier corresponding to the first privacy identifier in the unmatched record in the second institution is updated to the invalid status, then determine that the first privacy intersection result in the unmatched record matches the fourth privacy intersection result.

[0014] The above solution can be accurate and effective, and further verify the unmatched first privacy intersection result.

[0015] In a possible implementation method, the encryption algorithm is determined according to the private set intersection protocol.

[0016] In the above solution, the private set intersection protocol is used to encrypt the objects to be queried and the records to be verified of the first institution, which enables the second institution to perform private set intersection operations based on the encrypted objects to be queried and the records to be verified, without knowing the plaintext information of the objects to be queried and the records to be verified of the first institution, thus ensuring the security of the data of the first institution; the private set intersection protocol is used to encrypt all the objects stored by the second institution itself, so that the first institution can perform private set intersection operations based on the encrypted all objects, without knowing the plaintext information of the second institution, thus ensuring the security of the data of the second institution.

[0017] In a second aspect, an embodiment of the present application provides a verification device for a private set intersection result, including: a transceiver unit and a processing unit. The transceiver unit is configured to receive a private set intersection request after the (i - 1)-th offline time, where the private set intersection request includes an object to be queried; where i is a positive integer; encrypt the object to be queried into a first privacy identifier and send it to a second institution, and obtain a first private set intersection result fed back by the second institution; the first private set intersection result is used to indicate whether the object to be queried exists in the second institution; the processing unit is configured to write the first private set intersection result and the object to be queried into a query flow record; obtain records to be verified within the i-th interval period from the query flow record at the i-th offline time; the i-th interval period is the period corresponding to the (i - 1)-th offline time to the i-th offline time; the transceiver unit is configured to obtain each second privacy identifier of the second institution; each second privacy identifier is obtained after the second institution encrypts all the objects stored by itself respectively; the processing unit is configured to verify each private set intersection result within the i-th interval period fed back by the second institution according to the records to be verified and each second privacy identifier.

[0018] In a possible implementation method, the query water record further includes the processing time corresponding to the private set intersection request; the processing unit is configured to determine a second private set intersection result between the record to be verified and each second private identifier of the second institution; if the first private set intersection result in any record in the record to be verified matches the second private set intersection result, it is determined that the first private set intersection result fed back by the second institution passes the verification; if the first private set intersection result in any record in the record to be verified does not match the second private set intersection result, the first private set intersection result that does not match is further verified through the object change record recorded by the second institution and the processing time in the record that does not match; the object change record records the change time and change status of any object.

[0019] In a possible implementation method, the processing unit is configured to divide each record in the record to be verified into a first set of records to be verified and a second set of records to be verified according to the private set intersection result; each record in the first set of records to be verified represents that the second institution does not have a corresponding object to be queried; each record in the second set of records to be verified represents that the second institution has a corresponding object to be queried; determine a third private set intersection result between the first set of records to be verified and each second private identifier of the second institution; determine a fourth private set intersection result between the second set of records to be verified and each second private identifier of the second institution; if the set of third private set intersection results is empty, it is determined that the first private set intersection result corresponding to the first private identifier in any record matches the second private set intersection result, otherwise it does not match; if the first private set intersection result in any record in the record to be verified is in the fourth private set intersection result, it is determined that the first private set intersection result corresponding to the first private identifier in any record matches the second private set intersection result, otherwise it does not match.

[0020] In a possible implementation method, if the record that does not match belongs to the first set of records to be verified, the processing unit is configured to determine, through the object change record recorded by the second institution, that the change status of the second private identifier corresponding to the first private identifier in the record that does not match is an invalid status before the processing time in the record that does not match; after the processing time in the record that does not match, the change status of the second private identifier corresponding to the first private identifier in the record that does not match is updated to an effective status in the second institution, and it is determined that the first private set intersection result in the record that does not match matches the third private set intersection result.

[0021] In a possible implementation method, the processing unit is configured to, if the unmatched record belongs to the second set to be verified, determine, through the object change record recorded by the second institution, that before the processing time in the unmatched record, the change status of the second privacy identifier corresponding to the first privacy identifier in the unmatched record in the second institution is the valid status; and after the processing time in the unmatched record, the change status of the second privacy identifier corresponding to the first privacy identifier in the unmatched record in the second institution is updated to the invalid status, then determine that the first privacy intersection result in the unmatched record matches the fourth privacy intersection result.

[0022] In a possible implementation method, the encryption algorithm is determined according to the private set intersection protocol.

[0023] In a third aspect, an embodiment of the present application further provides a computing device, including:

[0024] a memory for storing program instructions;

[0025] a processor for calling the program instructions stored in the memory and executing any method of the first aspect as obtained according to the program instructions.

[0026] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, in which computer-readable instructions are stored, and when a computer reads and executes the computer-readable instructions, any method of the first aspect is implemented.

[0027] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program executable by a computer device. When the program runs on the computer device, the computer device is caused to execute any method of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 is a schematic flowchart of a method for verifying a private set intersection result provided by an embodiment of the present application;

[0029] Figure 2 is a system architecture diagram of a method for verifying a private set intersection result provided by an embodiment of the present application;

[0030] Figure 3 is a schematic flowchart of a real-time private set intersection method provided by an embodiment of the present application;

[0031] Figure 4 is a schematic flowchart of a real-time private set intersection method provided by an embodiment of the present application;

[0032] Figure 5 is a schematic flowchart of a real-time private set intersection method provided by an embodiment of the present application;

[0033] Figure 6 It is a schematic flow diagram of a method for verifying the result of private set intersection provided by an embodiment of the present application;

[0034] Figure 7 It is a schematic flow diagram of a method for verifying the result of private set intersection provided by an embodiment of the present application;

[0035] Figure 8 It is a schematic flow diagram of a method for verifying the result of private set intersection provided by an embodiment of the present application;

[0036] Figure 9 It is a schematic structural diagram of a device for verifying the result of private set intersection provided by an embodiment of the present application;

[0037] Figure 10 It is a schematic structural diagram of a device for verifying the result of private set intersection provided by an embodiment of the present application. Detailed implementation manners

[0038] The current solutions for verifying the correctness of the private set intersection result mainly include:

[0039] (1) More functional tests and a more complete test set.

[0040] Through in-depth testing, potential problems in the system can be discovered and solved, improving the reliability and stability of the software and ensuring normal functions.

[0041] However, relying solely on testing cannot solve all problems in the program. Private set intersection belongs to a relatively new technical field with relatively high complexity, and it is difficult to exhaust all situations.

[0042] (2) Plaintext sampling inspection.

[0043] By directly comparing with plaintext, it can be quickly confirmed whether the private set intersection result meets the expected result.

[0044] The following problems exist in plaintext sampling inspection:

[0045] Firstly, sampling inspection is a sampling behavior and cannot cover all data aspects. From the perspective of integrity, if the sampling inspection result is normal, it cannot be stated that the results of the entire data set are normal and meet the expectations. Additionally, plaintext sampling inspection will expose the original data information, which may cause privacy leakage problems and is not applicable to some sensitive scenarios.

[0046] (3) Trusted third-party audit

[0047] Having a trusted third party review the privacy intersection result is also a solution, but there is still the problem of exposing the original information and causing privacy leakage. For some institutions, there are also issues such as compliance in third-party reviews.

[0048] Figure 1 FIG. 4 is a schematic flowchart of a method for verifying a privacy intersection result provided by an embodiment of the present application. This method can be executed by a verification device for the privacy intersection result. The verification device for the privacy intersection result can be a terminal device or a module for a terminal device, or a server or a module for a server. The present application does not limit the execution entity of this method.

[0049] The method includes the following steps:

[0050] Step 101, the first institution receives a privacy intersection request after the (i - 1)-th offline moment.

[0051] Wherein, the privacy intersection request includes an object to be queried; i is a positive integer.

[0052] In a possible implementation method, the first institution receives the privacy intersection request in real time during the period corresponding to the (i - 1)-th offline moment to the i-th offline moment, and writes the privacy intersection result into a query flow record.

[0053] Step 102, the first institution encrypts the object to be queried into a first privacy identifier and sends it to the second institution, and obtains the first privacy intersection result fed back by the second institution.

[0054] Wherein, the first privacy intersection result is used to indicate whether the second institution has the object to be queried.

[0055] In a possible implementation method, the algorithm for encrypting the object to be queried is determined according to a privacy intersection protocol, where the privacy intersection protocol includes one or more of the following: Oblivious Pseudo-Random Function (OPRF) protocol, Yao's garbled circuit, private set intersection of fully homomorphic encryption (FHE), or private set intersection based on public key encryption.

[0056] The first institution encrypts the object to be queried into a first privacy identifier and sends it to the second institution. The second institution cannot obtain the object to be queried based on the first privacy identifier. That is, the second institution cannot obtain the plaintext information of the first institution by decrypting the corresponding privacy identifier.

[0057] Step 103, the first institution writes the first privacy intersection result and the object to be queried into the query flow record.

[0058] In a possible implementation method, the query flow record is stored in the first institution.

[0059] In a possible implementation method, the first institution writes the first private intersection result and the object to be queried into the query flow record; when it is necessary to verify the private intersection result subsequently, the object to be queried is encrypted again.

[0060] Step 104, at the i-th offline moment, the first institution obtains the records to be verified within the i-th interval period from the query flow record.

[0061] Wherein, the i-th interval period is the period corresponding to the (i - 1)-th offline moment to the i-th offline moment.

[0062] In a possible implementation method, the record to be verified is the private intersection result within the period corresponding to the (i - 1)-th offline moment to the i-th offline moment.

[0063] Step 105, the first institution obtains each second privacy identifier of the second institution.

[0064] Wherein, each of the second privacy identifiers is obtained after the second institution encrypts its stored full amount of objects respectively.

[0065] In a possible implementation method, the algorithm for the second institution to encrypt its stored full amount of objects respectively is determined according to the private intersection protocol, that is, the first institution cannot obtain the plaintext information of the second institution by decrypting each second privacy identifier.

[0066] Step 106, the first institution verifies each private intersection result within the i-th interval period fed back by the second institution according to the record to be verified and each of the second privacy identifiers.

[0067] In a possible implementation method, if each private intersection result within the i-th interval period is abnormal, the first institution performs abnormal handling according to the abnormality.

[0068] In the above solution, first obtain the real-time private intersection result of the first institution in the i-th interval period, and then compare the real-time private intersection result in the i-th interval period with each second privacy identifier of the second institution, which can accurately and effectively verify each private intersection result within the i-th interval period fed back by the second institution.

[0069] Optionally, the first institution and the second institution are two independent institutions. It is possible to verify the real-time private intersection result of the first institution or the real-time private intersection result of the second institution; this application does not make a limitation on this. Verifying the real-time private intersection result of the second institution is similar to verifying the real-time private intersection result of the first institution, and will not be elaborated here. The subsequent embodiments will be described by taking the verification of the real-time private intersection result of the first institution as an example.

[0070] In a possible implementation method, the privacy intersection results in the query transaction records can be verified multiple times. This application does not limit the verification of the privacy intersection results in the query transaction records for the i-th interval period, and the privacy intersection results at any time in the query transaction records can be verified multiple times according to actual needs.

[0071] In one embodiment, the query transaction records further include the processing time corresponding to the privacy intersection request;

[0072] The first institution verifies each privacy intersection result within the i-th interval period fed back by the second institution according to the record to be verified and each second privacy identifier, including:

[0073] Determine the second privacy intersection results of the record to be verified and each second privacy identifier of the second institution; if the first privacy intersection result in any record in the record to be verified matches the second privacy intersection result, it is determined that the first privacy intersection result fed back by the second institution passes the verification; if the first privacy intersection result in any record in the record to be verified does not match the second privacy intersection result, the first privacy intersection result that does not match is further verified through the object change record recorded by the second institution and the processing time in the record that does not match; the object change record records the change time and change status of any object. In this solution, since the i-th interval period has a certain time length, it is possible that the data of each object of the second institution changes during this period, resulting in an error in verifying the first privacy intersection result. Therefore, when it is determined that the first privacy intersection result does not match the second privacy intersection result, through the object change record recorded by the second institution and the processing time in the record that does not match, it is possible to accurately and effectively further verify the first privacy intersection result that does not match.

[0074] In a possible implementation method, according to the privacy intersection results, each record in the record to be verified is divided into a first set of records to be verified and a second set of records to be verified; each record in the first set of records to be verified represents that the second institution does not have a corresponding object to be queried; each record in the second set of records to be verified represents that the second institution has a corresponding object to be queried.

[0075] In a possible implementation method, for the record that does not match, the first institution encrypts the record that does not match and sends it to the second institution, and the second institution performs further verification; or, after the second institution receives the encrypted record that does not match sent by the first institution, it sends the change stream of the second privacy identifier corresponding to the encrypted record that does not match to the first institution, and the first institution performs further verification.

[0076] In a possible implementation method, a third privacy intersection result of the first set to be verified and each second privacy identifier of the second institution is determined; if the third privacy intersection result set is empty, it is determined that the first privacy intersection result corresponding to the first privacy identifier in any record matches the second privacy intersection result, otherwise it is determined that they do not match.

[0077] In a possible implementation method, if the unmatched record belongs to the first set to be verified, it is determined through the object change record recorded by the second organization that before the processing time in the unmatched record, the second privacy identifier corresponding to the first privacy identifier in the unmatched record is in an invalid change status in the second organization; after the processing time in the unmatched record, the second privacy identifier corresponding to the first privacy identifier in the unmatched record is updated to a valid change status in the second organization, then it is determined that the first privacy intersection result in the unmatched record matches the third privacy intersection result.

[0078] For example, the first set to be verified is (1, 2, 3), and the second privacy identification set obtained after the second institution encrypts all objects stored in itself is (1, 4, 5). Logically, each record in the first set to be verified indicates that the second institution does not have a corresponding object to be queried. Therefore, the first set to be verified should not have an intersection with the second privacy identification set. However, at this time, it is found that the first set to be verified and the second privacy identification set have an intersection (1), so the intersection (1) is an unmatched record, recorded as the first unmatched record.

[0079] At this time, query the processing time of the second privacy identifier corresponding to the first unmatched record in the second institution in the object change record recorded by the second institution; if before the processing time, the change status of the second privacy identifier corresponding to the first unmatched record in the second institution is invalid, and after the processing time, the change status of the second privacy identifier corresponding to the first unmatched record in the second institution is valid, it means that the second privacy identifier corresponding to the first unmatched record in the second institution is added to the second institution after the processing time, and at this time, it is considered that the first privacy intersection result of the first unmatched record matches the second privacy identifiers.

[0080] In a possible implementation method, the invalid state means that the object to be queried does not exist in the second institution. The valid state means that the object to be queried exists in the second institution.

[0081] In a possible implementation method, the processing time refers to the time when the second institution receives the privacy exchange request, or the time when the second institution sends the privacy exchange request result to the first institution.

[0082] In a possible implementation method, the fourth privacy intersection result of the second set to be verified and each second privacy identifier of the second institution is determined; if the first privacy intersection result in any record of the records to be verified is in the fourth privacy intersection result, then the first privacy intersection result corresponding to the first privacy identifier in any record is determined to match the second privacy intersection result, otherwise it is not matched. Specifically, if the non-intersection of the first privacy intersection result and the fourth privacy intersection result in any record of the records to be verified is empty, then the first privacy intersection result corresponding to the first privacy identifier in any record is determined to match the second privacy intersection result; if the non-intersection of the first privacy intersection result and the fourth privacy intersection result in any record of the records to be verified is not empty, then the first privacy intersection result corresponding to the first privacy identifier in any record is determined to not match the second privacy intersection result.

[0083] In a possible implementation method, if the unmatched record belongs to the second set to be verified, it is determined through the object change record recorded by the second organization that before the processing time in the unmatched record, the second privacy identifier corresponding to the first privacy identifier in the unmatched record is in a valid change status in the second organization; after the processing time in the unmatched record, the second privacy identifier corresponding to the first privacy identifier in the unmatched record is updated to an invalid change status in the second organization, then it is determined that the first privacy intersection result in the unmatched record matches the fourth privacy intersection result.

[0084] Exemplarily, the second set to be verified is (1,2,3,4), and the second privacy identifier set obtained after the second institution encrypts all objects stored in itself is (1,2,3,5,6,7); in theory, each record in the first set to be verified represents that the second institution has a corresponding object to be queried; so the intersection of the first set to be verified and the second privacy identifier set should be the same as the second set to be verified. However, at this time, it is found that the intersection of the first set to be verified and the second privacy identifier set is (1,2,3), then the intersection (1,2,3) does not exist in the set (4) in the second set to be verified (1,2,3,4), then the combination (4) is an unmatched record, recorded as the second unmatched record.

[0085] At this time, query the processing time of the second privacy identifier corresponding to the second unmatched record in the object change record recorded by the second institution; if before the processing time, the change status of the second privacy identifier corresponding to the second unmatched record in the second institution is the valid status; after the processing time, the change status of the second privacy identifier corresponding to the second unmatched record in the second institution is the invalid status, it indicates that the second privacy identifier corresponding to the second unmatched record in the second institution has been deleted or is unavailable after the processing time. At this time, it is considered that the first privacy intersection result of the second unmatched record matches the second privacy identifiers.

[0086] Based on the same technical concept, Figure 2 Exemplarily, a system for privacy intersection results provided by an embodiment of the present application is shown. The system includes a first institution and a second institution. Among them, the first institution corresponds to Figure 2 institution A, and the second institution corresponds to Figure 2 institution B. Each institution includes a business system, a real-time privacy intersection system, and an offline verification system. Among them, the business system is used to store the plaintext data of the corresponding institution and send a privacy intersection request to the real-time privacy intersection system; the real-time privacy intersection system is used to provide real-time privacy intersection functions to meet the real-time, availability, and security requirements of the system; the offline verification system is used to verify historical privacy intersection results to enhance the reliability and accuracy of the system.

[0087] The real-time privacy intersection system and the offline verification system are introduced separately below.

[0088] In a possible implementation method, the real-time privacy intersection system is separately deployed in each institution, and data synchronization interfaces such as addition, update, and deletion are provided for the real-time privacy intersection system, and the business system corresponding to each institution is called to keep the data of the two consistent.

[0089] In a possible implementation method, the business system stores a business data table, and the business data table records the plaintext business data of each institution.

[0090] In a possible implementation method, the real-time privacy intersection system stores a data identifier table, and the data identifier table corresponds to the business data table of the business system. However, the data identifier table records the identifier information corresponding to each piece of data in the business data table. For example, the ID card of each user in the business data table is used as the first identifier, and the first identifier is calculated through a hash algorithm and then stored in the data identifier table as the second identifier.

[0091] In a possible implementation method, the data identification table includes a data identification, a data status, and an update time; wherein, the data identification may be the hash value of the identification information corresponding to each piece of data in the business data table; the data status includes a valid status and an invalid status; newly added and updated data are in the valid status, and deleted data is in the invalid status. The business system calls the interface provided by the private set intersection service, and in order to ensure the privacy of business data, the business system synchronizes the hashed data to the private set intersection system.

[0092] In a possible implementation method, the real-time private set intersection system stores a change log table, and the change log table is used to record the change records of each object.

[0093] In a possible implementation method, the change log table includes a data identification, a change time, and a change type; wherein the change type includes one or more of the following: addition, update, and deletion.

[0094] Exemplarily, the business system calls the private set intersection service to insert a record with a hash value of 0x9812… at the time of "20230901181523", and the generated log record is: addition, 20230901181523, 0x9812…; the business system calls the private set intersection service to delete the record with the hash value of 0x9812… at the time of "20230902210543", and the generated log record is: deletion, 20230902210543, 0x9812….

[0095] In one embodiment, the specific process of real-time private set intersection of the first institution is as Figure 3 and Figure 4 shown. This process includes the following steps, where Figure 3 the hash data table mentioned above is the data identification table, institution A is the first institution, and institution B is the second institution.

[0096] Suppose the first institution needs to confirm whether the user "Xiaowang" is the intersection data of the two institutions. At this time, the first institution is the active querying party, and the second institution is the passive querying party. The process is as follows.

[0097] Step 401, the business system of the first institution sends a private set intersection request to the real-time private set intersection system of the first institution.

[0098] Wherein, the private set intersection request includes the object to be queried.

[0099] Exemplarily, the business system of the first institution sends the hash value of the user "Xiaowang" to the real-time private set intersection service of the first institution to initiate a private set intersection request.

[0100] Step 402: The real-time private set intersection service of the first institution receives a private set intersection request. According to the private set intersection protocol, it generates a first privacy identifier for the object to be queried and sends the first privacy identifier to the real-time private set intersection service of the second institution.

[0101] Step 403: The real-time private set intersection service of the second institution receives the first privacy identifier sent by the first institution.

[0102] Step 404: The real-time private set intersection service of the second institution determines whether the object to be queried exists in the second institution according to its own stored data identifier table, and generates a response result for the private set intersection result according to the private set intersection protocol.

[0103] Step 405: The real-time private set intersection service of the second institution sends the response result to the real-time private set intersection service of the first institution.

[0104] Step 406: The real-time private set intersection service of the first institution parses the response result and sends the parsed response result to the business system of the first institution.

[0105] In a possible implementation, the real-time private set intersection service of the first institution writes the parsed response result into the query log, as Figure 5 shown. The query log is used for the real-time private set intersection service to record the log of the return result of querying the intersection by invoking the real-time private set intersection service of the second institution. Among them, the intersection query log table is the query log.

[0106] In a possible implementation, the query log includes the first private set intersection result, the first privacy identifier, and the processing time corresponding to the private set intersection request.

[0107] Exemplarily, at the moment of "20210730102231", the first institution queries the data with the hash value of 0x54d5… from the second institution, and the return result is the intersection data. Then the newly added query log: 0x54d5…, 20210730102231, yes;

[0108] At the moment of "20220628111724", the first institution queries the data with the hash value of 0x6ada… from the second institution, and the return result is non-intersection data. Then the newly added query log: 0x6ada…, 20220628111724, no.

[0109] Step 407: The business system of the first institution determines whether the object to be queried exists in the second institution according to the parsed response result.

[0110] In a possible implementation method, the offline verification system is designed to perform periodic multiple verifications on the results of the real-time private intersection system, and a more secure private intersection algorithm or a combination of multiple private intersection algorithm results can be used for cross-checking to enhance the reliability of the system and the correctness of the results.

[0111] Exemplarily, the incremental data in the query flow records of the first institution in the first period is reconciled with the full amount of data in the data identification table of the second institution, which can check whether the real-time intersection query return of the intersection query flow records of the first institution meets the expectations. Similarly, the incremental data in the query flow records of the second institution in the first period is reconciled with the full amount of data in the data identification table of the first institution, which can check whether the real-time intersection query return of the intersection query flow records of the second institution meets the expectations.

[0112] In a possible implementation method, the reconciliation time and frequency are set. For example, offline verification is performed when the real-time private intersection system is relatively idle; or a fixed frequency is set to perform an offline verification on all real-time private intersection results within the current hour every hour. This application does not limit the reconciliation time and frequency.

[0113] In one embodiment, the specific process of the offline verification of the first institution is as Figure 6 shown, where Figure 6 the data hash table therein is the above-mentioned data identification table, and the hash change flow table is the above-mentioned query flow record; institution A is the first institution and institution B is the second institution.

[0114] In a possible implementation method, according to the private intersection result, each record in the record to be verified is divided into a first set of records to be verified and a second set of records to be verified; each record in the first set of records to be verified represents that the second institution does not have a corresponding object to be queried; each record in the second set of records to be verified represents that the second institution has a corresponding object to be queried.

[0115] In a possible implementation method, the process of offline verification of the first set of records to be verified is as Figure 7 shown, including the following steps:

[0116] Step 701, the offline verification system of the first institution obtains the records to be verified in the first period from the first set of records to be verified.

[0117] Step 702, the offline verification system of the second institution obtains all the stored objects from the data identification table.

[0118] Step 703, the first institution and the second institution start a batch private intersection task according to the private intersection protocol.

[0119] Step 704, after the first institution obtains the third private intersection result, if the third private intersection result is empty, it verifies that the real-time private intersection result is correct.

[0120] In a possible implementation method, after the first institution obtains the third private intersection result, if the result of the offline verification system intersection is empty, it indicates that the query stream recorded by the real-time private intersection service of the first institution meets the expectations. The data in the non-intersection set is also non-intersection data in the result of the batch intersection, and this round of reconciliation ends.

[0121] In a possible implementation method, if the third private intersection result is not empty, assuming that one of the query records is identified as h and the processing time is t, there are two possible results that meet the expectations:

[0122] It is possible that after the processing time t, the data status corresponding to the data identification table h of the second institution has changed:

[0123] Case 1, before the processing time t, the second institution did not have the h data, and after the time t, the h data was newly added;

[0124] Case 2, before the processing time t, the h data of the second institution was in a deleted state, and after the time t, the status of t changed to a valid state.

[0125] For this scenario, the second institution performs the verification by querying its own change log table to check whether there is a log that changes the status of the h data to a valid state within the interval where the processing time > t.

[0126] In a possible implementation method, the process of offline verification of the second set to be verified is as Figure 8 shown, including the following steps:

[0127] Step 801, the offline verification system of the first institution obtains the records to be verified within the first period from the second set to be verified.

[0128] Step 802, the offline verification system of the second institution obtains all the stored objects from the data identification table.

[0129] Step 803, the first institution and the second institution start a batch private intersection task according to the private intersection protocol.

[0130] Step 804, after the first institution obtains the fourth private intersection result, if the fourth private intersection result is the same as the second set to be verified, it verifies that the real-time private intersection result is correct.

[0131] In a possible implementation method, the intersection of the fourth private intersection result and the second set to be verified is calculated. If the non-intersection part of the fourth private intersection result and the second set to be verified is empty, it indicates that the real-time private intersection service of the first institution in the first cycle meets the expectations. The data in the intersection set of the real-time private intersection is also the intersection data in the result of the batch intersection, and this round of reconciliation ends.

[0132] In a possible implementation method, if the non-intersection part of the fourth private intersection result and the second set to be verified is not empty, assume that one of the record identifiers is h and the processing time is t. Before the processing time t, the h data of the second institution is in a valid state, and after the time t, the state of t changes to an invalid state; for this scenario, the second institution performs verification by querying its own change log table to check whether there is a log that changes the state of the h data to an invalid state in the interval where the processing time > t.

[0133] In a possible implementation method, the result calculated by the real-time private intersection service of the first institution is abnormal, and an alarm is sent to the business system of the first institution, and the business system of the first institution troubleshoots the abnormality.

[0134] Based on the same technical concept, Figure 9 Exemplarily, a verification device 900 for the private intersection result provided by the embodiment of the present application is shown. As Figure 9 shown, it includes a transceiver unit 901 and a processing unit 902. The transceiver unit 901 is configured to receive a private intersection request after the (i - 1)-th offline moment, where the private intersection request includes an object to be queried; where i is a positive integer; encrypt the object to be queried into a first private identifier and send it to the second institution, and obtain the first private intersection result fed back by the second institution; the first private intersection result is used to indicate whether the object to be queried exists in the second institution; the processing unit 902 is configured to write the first private intersection result and the object to be queried into a query flow record; obtain the records to be verified in the i-th interval period from the query flow record at the i-th offline moment; the i-th interval period is the period corresponding to the (i - 1)-th offline moment to the i-th offline moment; the transceiver unit 901 is configured to obtain each second private identifier of the second institution; each second private identifier is obtained by encrypting all the objects stored by the second institution respectively; the processing unit 902 is configured to verify each private intersection result in the i-th interval period fed back by the second institution according to the records to be verified and each second private identifier.

[0135] In a possible implementation method, the query water record further includes the processing time corresponding to the private intersection request; the processing unit 902 is configured to determine a second private intersection result between the record to be verified and each second private identifier of the second institution; if the first private intersection result in any record in the record to be verified matches the second private intersection result, it is determined that the first private intersection result fed back by the second institution is verified to be passed; if the first private intersection result in any record in the record to be verified does not match the second private intersection result, the first private intersection result that does not match is further verified through the object change record recorded by the second institution and the processing time in the record that does not match; the object change record records the change time and change status of any object.

[0136] In a possible implementation method, the processing unit 902 is configured to divide each record in the record to be verified into a first set of records to be verified and a second set of records to be verified according to the private intersection result; each record in the first set of records to be verified represents that the second institution does not have a corresponding object to be queried; each record in the second set of records to be verified represents that the second institution has a corresponding object to be queried; determine a third private intersection result between the first set of records to be verified and each second private identifier of the second institution; determine a fourth private intersection result between the second set of records to be verified and each second private identifier of the second institution; if the third private intersection result set is empty, it is determined that the first private intersection result corresponding to the first private identifier in any record matches the second private intersection result, otherwise it does not match; if the first private intersection result in any record in the record to be verified is in the fourth private intersection result, it is determined that the first private intersection result corresponding to the first private identifier in any record matches the second private intersection result, otherwise it does not match.

[0137] In a possible implementation method, if the record that does not match belongs to the first set of records to be verified, the processing unit 902 is configured to determine, through the object change record recorded by the second institution, that the change status of the second private identifier corresponding to the first private identifier in the record that does not match is an invalid status before the processing time in the record that does not match; after the processing time in the record that does not match, the change status of the second private identifier corresponding to the first private identifier in the record that does not match is updated to an effective status in the second institution, and it is determined that the first private intersection result in the record that does not match matches the third private intersection result.

[0138] In a possible implementation method, the processing unit 902 is configured to, if the unmatched record belongs to the second set to be verified, determine, through the object change record recorded by the second institution, that before the processing time in the unmatched record, the change status of the second privacy identifier corresponding to the first privacy identifier in the unmatched record in the second institution is a valid status; and after the processing time in the unmatched record, the change status of the second privacy identifier corresponding to the first privacy identifier in the unmatched record in the second institution is updated to an invalid status, then determine that the first privacy intersection result in the unmatched record matches the fourth privacy intersection result.

[0139] In a possible implementation method, the encryption algorithm is determined according to the private set intersection protocol.

[0140] Based on the same technical concept, an embodiment of the present application provides a verification device 1000 for private set intersection results. The verification device 1000 for private set intersection results may be, for example, a computing device. As Figure 10 shown, a verification device 1000 for private set intersection results includes at least one processor 1001 and a memory 1002 connected to the at least one processor. In the embodiment of the present application, the specific connection medium between the processor 1001 and the memory 1002 is not limited. Figure 10 Taking the example that the processor 1001 and the memory 1002 are connected through a bus. The bus can be divided into an address bus, a data bus, a control bus, etc.

[0141] In the embodiment of the present application, the memory 1002 stores instructions executable by at least one processor 1001. By executing the instructions stored in the memory 1002, the at least one processor 1001 can execute the above verification method for private set intersection results.

[0142] Among them, the processor 1001 is the control center of a verification device 1000 for private set intersection results. It can connect various parts of the computer device through various interfaces and lines, and by running or executing the instructions stored in the memory 1002 and calling the data stored in the memory 1002, resource settings can be performed. Optionally, the processor 1001 may include one or more determination units. The processor 1001 may integrate an application processor and a modulation and demodulation processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modulation and demodulation processor mainly processes wireless communication. It can be understood that the above modulation and demodulation processor may not be integrated into the processor 1001. In some embodiments, the processor 1001 and the memory 1002 may be implemented on the same chip, and in some embodiments, they may also be implemented on separate chips respectively.

[0143] The processor 1001 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0144] The memory 1002, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 1002 may include at least one type of storage medium, for example, it may include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disk, and so on. The memory 1002 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1002 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0145] The embodiments of the present application further provide a computer-readable storage medium, which stores a computer-executable program, and the computer-executable program is used to cause a computer to execute a method for verifying a private intersection result listed in any of the above manners.

[0146] The embodiments of the present application provide a computer program product, including a computer program executable by a computer device. When the program runs on the computer device, it causes the computer device to execute a method for verifying a private intersection result listed in any of the above manners.

[0147] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.

[0148] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0149] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0150] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0151] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A method for verifying the result of private set intersection, characterized in that Including: The first institution receives a private set intersection request after the (i - 1)-th offline moment, and the private set intersection request includes an object to be queried; where i is a positive integer; The first institution encrypts the object to be queried into a first privacy identifier and sends it to the second institution, and obtains a first private set intersection result feedback by the second institution; the first private set intersection result is used to indicate whether the second institution has the object to be queried; The first institution writes the first private set intersection result and the object to be queried into a query transaction record; The first institution obtains a record to be verified within the i-th interval period from the query transaction record at the i-th offline moment; the i-th interval period is the period corresponding to the (i - 1)-th offline moment to the i-th offline moment; The first institution obtains each second privacy identifier of the second institution; each of the second privacy identifiers is obtained by the second institution encrypting its stored full amount of objects respectively; The first institution verifies each private set intersection result within the i-th interval period feedback by the second institution according to the record to be verified and each second privacy identifier.

2. The method according to claim 1, characterized in that, The query transaction record further includes a processing time corresponding to the private set intersection request; The first institution verifies each private set intersection result within the i-th interval period feedback by the second institution according to the record to be verified and each second privacy identifier, including: Determining a second private set intersection result between the record to be verified and each second privacy identifier of the second institution; If the first private set intersection result in any record in the record to be verified matches the second private set intersection result, it is determined that the first private set intersection result feedback by the second institution passes the verification; If the first private set intersection result in any record in the record to be verified does not match the second private set intersection result, further verification is performed on the non-matching first private set intersection result through an object change record recorded by the second institution and the processing time in the non-matching record; the object change record records the change time and change status of any object.

3. The method according to claim 2, wherein According to the private set intersection result, each record in the record to be verified is divided into a first set of records to be verified and a second set of records to be verified; each record in the first set of records to be verified represents that the second institution does not have the corresponding object to be queried; each record in the second set of records to be verified represents that the second institution has the corresponding object to be queried; Determining a second private set intersection result between the record to be verified and each second privacy identifier of the second institution includes: Determining a third private set intersection result between the first set of records to be verified and each second privacy identifier of the second institution; Determining a fourth private set intersection result between the second set of records to be verified and each second privacy identifier of the second institution; Judging whether the first private set intersection result in any record matches the second private set intersection result by the following method, including: If the third private intersection result set is empty, it is determined that the first private intersection result corresponding to the first private identifier in any record matches the second private intersection result; otherwise, it does not match. If the first private intersection result in any record in the record to be verified is in the fourth private intersection result, it is determined that the first private intersection result corresponding to the first private identifier in any record matches the second private intersection result; otherwise, it does not match.

4. The method according to claim 3, characterized in that, Further verify the unmatched first private intersection result through the object change record recorded by the second institution and the processing time in the unmatched record, including: If the unmatched record belongs to the first set to be verified, through the object change record recorded by the second institution, it is determined that before the processing time in the unmatched record, the change status of the second private identifier corresponding to the first private identifier in the unmatched record in the second institution is an invalid state; after the processing time in the unmatched record, the change status of the second private identifier corresponding to the first private identifier in the unmatched record in the second institution is updated to a valid state, then it is determined that the first private intersection result in the unmatched record matches the third private intersection result.

5. The method according to claim 3, wherein Further verify the unmatched first private intersection result through the object change record recorded by the second institution and the processing time in the unmatched record, including: If the unmatched record belongs to the second set to be verified, through the object change record recorded by the second institution, it is determined that before the processing time in the unmatched record, the change status of the second private identifier corresponding to the first private identifier in the unmatched record in the second institution is a valid state; after the processing time in the unmatched record, the change status of the second private identifier corresponding to the first private identifier in the unmatched record in the second institution is updated to an invalid state, then it is determined that the first private intersection result in the unmatched record matches the fourth private intersection result.

6. The method according to any one of claims 1 to 5, characterized in that, The encryption algorithm is determined according to the private intersection protocol.

7. A verification device for the private intersection result, characterized in that, It includes a transceiver unit and a processing unit: The transceiver unit is used to receive a private intersection request after the (i - 1)-th offline moment, where the private intersection request includes an object to be queried; here, i is a positive integer; encrypt the object to be queried into a first private identifier and send it to the second institution, and obtain the first private intersection result fed back by the second institution; the first private intersection result is used to indicate whether the object to be queried exists in the second institution. The processing unit is used to write the first private intersection result and the object to be queried into the query flow record; obtain the record to be verified within the i-th interval period from the query flow record at the i-th offline moment; the i-th interval period is the period corresponding to the (i - 1)-th offline moment to the i-th offline moment. The transceiver unit is further used to obtain each second private identifier of the second institution; each second private identifier is obtained after the second institution encrypts all the objects stored by itself respectively. The processing unit is further configured to verify, according to the record to be verified and the second privacy identifiers, the privacy intersection results in the i-th interval period fed back by the second institution.

8. A computing device, characterized in that, Comprising: a memory for storing program instructions; a processor for calling the program instructions stored in the memory and executing the method according to any one of claims 1 to 6 according to the obtained program instructions.

9. A computer-readable storage medium, characterized in that, Comprising computer-readable instructions, when the computer reads and executes the computer-readable instructions, the method according to any one of claims 1 to 6 is implemented.

10. A computer program product, characterized in that, Comprising a computer program executable by a computer device, when the program runs on the computer device, the computer device is caused to execute the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Streaming privacy intersection method and system based on block chain

    CN116521758A

  • Multi-party privacy intersection method and device and electronic equipment

    CN117574412A