A Two-Party Private Set Intersection Method and System for Hiding the Number of Receiver Elements
Through elliptic curve encryption and partial homomorphic encryption methods, two rounds of communication and data preprocessing are realized, solving the problems of low computing performance and data leakage in the prior art, and improving the efficiency and security of privacy set interception.
Patent Information
- Application Number
- CN202510315286.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-03-18
AI Technical Summary
The existing private set intersection protocols have low computing performance and large traffic when comparing set elements, and cannot effectively hide the number of elements on the receiver, which may reveal the total amount of user data.
The elliptic curve encryption method and the partially homomorphic encryption method of multiplication homomorphic are used to reduce the encrypted communication volume through two rounds of communication. The sender and the receiver themselves preprocess the data to reduce the amount of computing by the receiver, and the hash table is filled with a random mask to keep the total amount of data consistent.
It improves computing efficiency, reduces the computing and communication volume of the receiver, enhances the security and privacy protection of the protocol, and avoids the leakage of the total user data.
Smart Images

Figure CN119853913B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of private set intersection comparison protocols, and particularly to a two-party private set intersection method and system for hiding the number of elements of a recipient. Background Art
[0002] With the advent of the big data era, data privacy protection has become increasingly important. The private set intersection technology can calculate the intersection of the common data of multiple participants without revealing their respective data. This technology is crucial for complying with privacy regulations, protecting personal information, and ensuring data security, providing strong technical support for data privacy protection.
[0003] In the prior art, this technology can achieve sharing data without revealing private information. In the data preprocessing stage of federated learning, the private set intersection technology can also be used for data alignment without revealing private data, which is crucial for protecting user privacy and large-scale application of federated learning.
[0004] Existing private set intersection protocols often adopt methods related to public key encryption. Existing methods use fully homomorphic encryption schemes when comparing set elements. This design often leads to low computational performance and requires three rounds of interaction, resulting in a large communication volume. The fast PSI (Private Set Intersection) method using fully homomorphic encryption proposed by Chen et al. The security and privacy of this method completely depend on the FHE (Fully Homomorphic Encryption) scheme with circuit privacy, which limits its efficiency in practice. In addition, existing PSI methods cannot guarantee not to disclose the total amount of user data while ensuring the privacy and unlinkability of the sender and the recipient. Summary of the Invention
[0005] To solve the above problems in the prior art, the present invention provides a two-party private set intersection method and system for hiding the number of elements of a recipient. The invention adopts the elliptic curve encryption method and the partially homomorphic encryption method with multiplicative homomorphism, which only requires two rounds of communication, reducing the encryption communication volume. At the same time, through the preprocessing of data by the sender and the recipient themselves, the computational amount of the recipient is reduced, improving the computational efficiency. Finally, a random mask with a blinding effect is filled in the hash table, making the total amount of transmitted data consistent, ensuring that the total amount of user data is not disclosed, and enhancing the security and privacy protection of the protocol. To achieve the above object, the technical solution is as follows:
[0006] On the one hand, the present invention provides a two-party private set intersection method for hiding the number of elements of a recipient, the method comprising:
[0007] S1. Based on the security parameters jointly selected by the recipient and the sender, through a trusted third-party institution, obtain the generator of the elliptic curve group and the large prime order of the elliptic curve group;
[0008] S2. Based on the security parameters jointly selected by the recipient and the sender, through a trusted third-party institution, obtain the multiplicative group;
[0009] S3. Based on the multiplicative group and the large prime order of the elliptic curve group, through a trusted third-party institution, obtain the first hash function;
[0010] S4. Based on the number of elements of the sender, through a trusted third-party institution, obtain three hash functions with the same range;
[0011] S5. Based on the recipient's private set, the multiplicative group, the first hash function, the generator of the elliptic curve group, and the three hash functions with the same range, through calculation, obtain the recipient's set of process parameters;
[0012] S6. Based on the sender's private set, the multiplicative group, the first hash function, the generator of the elliptic curve group, the three hash functions with the same range, and the recipient's set of process parameters, through calculation, obtain the sender's set of process parameters;
[0013] S7. Send the sender's set of process parameters to the recipient, and through comparison and selection between the recipient's set of process parameters and the sender's set of process parameters, obtain the data set required by the recipient.
[0014] Optionally, in S4, based on the number of elements of the sender, through a trusted third-party institution, obtaining three hash functions with the same range includes:
[0015] S41. Based on the number of elements of the sender, obtain the number of buckets of the hash function;
[0016] S42. Based on the number of buckets of the hash function, through mapping by formula (1), obtain three hash functions with the same range, and the three hash functions with the same range include: the first cuckoo hash function, the second cuckoo hash function, and the third cuckoo hash function.
[0017] (1)
[0018] In the formula: is the first cuckoo hash function, is the second cuckoo hash function, is the third cuckoo hash function, is the number of buckets of the hash function.
[0019] Optionally, in S5, according to the private set of the recipient, the multiplicative group, the first hash function, the generator of the elliptic curve group, and three hash functions with the same value range, through calculation, the process parameter set of the recipient is obtained, including:
[0020] S51. According to the multiplicative group and the generator of the elliptic curve group, respectively through formula (2) and formula (3), the first operation unit of the recipient and the second operation unit of the recipient are obtained.
[0021] (2)
[0022] (3)
[0023] In the formula: is the first operation unit of the recipient. is the second operation unit of the recipient. is the generator of the elliptic curve group. is the multiplicative group, and x and y are both elements randomly selected from the multiplicative group. ;
[0024] S52. According to the private set of the recipient and the first hash function, the private set of the recipient after hash mapping is obtained.
[0025] S53. According to the private set of the recipient after hash mapping, the first operation unit of the recipient, the second operation unit of the recipient, and the generator of the elliptic curve group, through the multi-factor exponential congruence operation formula (4), a multi-factor exponent is obtained.
[0026] (4)
[0027] In the formula: is a random element in the private set of the recipient after hash mapping. is the corresponding multi-factor exponent.
[0028] S54. According to the private set of the recipient after hash mapping and the three hash functions with the same value range, the hash table of the recipient is obtained.
[0029] S55. Integrate the first operation unit of the recipient, the second operation unit of the recipient, the multi-factor exponent, and the hash table of the recipient to obtain the process parameter set of the recipient.
[0030] Optionally, in S54, according to the private set of the recipient after hash mapping and the three hash functions with the same value range, obtaining the hash table of the recipient includes:
[0031] S541. Obtain the number of rows of the hash table and three storage locations of the recipient according to three hash functions with the same value range;
[0032] S542. Obtain the number of columns of the hash table according to the number of elements of the recipient;
[0033] S543. Store the privately-owned set of the recipient after hash mapping into three positions of the recipient respectively according to the number of rows of the hash table, the number of columns of the hash table and the three storage locations of the recipient, and obtain a hash table with a privately-owned set;
[0034] S544. Fill the empty bucket positions of the hash table with the privately-owned set with random masks to obtain the hash table of the recipient.
[0035] Optionally, the number of rows of the hash table includes: the number of rows of the hash table is the number of elements of the sender.
[0036] Optionally, the random mask includes 0 or 1.
[0037] Optionally, in S6, according to the privately-owned set of the sender, the multiplicative group, the first hash function, the generator of the elliptic curve group, three hash functions with the same value range and the process parameter set of the recipient, through calculation, obtain the process parameter set of the sender, including:
[0038] S61. Obtain the encrypted multiplicative group through public key encryption operation according to the multiplicative group;
[0039] S62. Obtain the privately-owned set of the sender after hash mapping according to the privately-owned set of the sender and the first hash function;
[0040] S63. Obtain the cuckoo hash table of the sender by adopting the cuckoo data structure according to the privately-owned set of the sender after hash mapping and three hash functions with the same value range;
[0041] S64. Respectively obtain the first intermediate operation unit of the recipient and the second intermediate operation unit of the recipient according to the cuckoo hash table of the sender, the multiplicative group and the process parameter set of the recipient through formula (5) and formula (6),
[0042] (5)
[0043] (6)
[0044] In the formula: is the first intermediate operation unit of the recipient, is the second intermediate operation unit of the recipient, is the first operation unit of the recipient, and They are all random elements in the multiplicative group, and t is the sequence number of the element in the sender's cuckoo hash table;
[0045] S65. According to the sender's cuckoo hash table, the receiver's set of process parameters, the multiplicative group, and the receiver's second intermediate operation unit, the receiver's third intermediate operation unit is obtained through formula (7).
[0046] (7)
[0047] In the formula: is the receiver's third intermediate operation unit, is the public key encryption operation function of the sender, is the receiver's second operation unit, is the element in the sender's cuckoo hash table;
[0048] S66. Integrate the encrypted multiplicative group, the sender's cuckoo hash table, the receiver's first intermediate operation unit, and the receiver's third intermediate operation unit to obtain the sender's set of process parameters.
[0049] Optionally, in S63, according to the sender's private set after hash mapping and three hash functions with the same value range, a cuckoo hash table of the sender is obtained by using the cuckoo data structure, including:
[0050] S631. According to the three hash functions with the same value range, obtain the buckets of the sender's cuckoo hash table and three storage locations of the sender;
[0051] S632. According to the buckets of the sender's cuckoo hash table and the three storage locations of the sender, randomly store the sender's private set after hash mapping into one of the three storage locations of the sender to obtain a cuckoo hash table with a private set;
[0052] S633. Fill the empty bucket positions of the cuckoo hash table with the private set with random masks to obtain the sender's cuckoo hash table.
[0053] Optionally, in S7, the data set required by the receiver is obtained by comparing and selecting through the receiver's set of process parameters and the sender's set of process parameters, including:
[0054] S71. According to the receiver's set of process parameters, obtain the multi-factor exponent and the receiver's hash table;
[0055] S72. According to the process parameter set of the sender, the multi-factor index, and the hash table of the receiver, compare and select the elements in the process parameter set of the corresponding sender through formula (8). If the equation holds, the elements in the process parameter set of the participating operation receiver are equal to the elements in the process parameter set of the sender, that is, the intersection elements are obtained, and the data set required by the receiver is obtained.
[0056] (8)
[0057] In the formula, is an encrypted multiplicative group, is the multi-factor index corresponding to the element in the t-th row and m-th column of the receiver's hash table, is the public key encryption operation function of the receiver.
[0058] On the other hand, the present invention provides a two-party private set intersection system for hiding the number of elements of the receiver. The system is applied to a two-party private set intersection method for hiding the number of elements of the receiver. The system includes:
[0059] The first acquisition module is used to obtain the generator of the elliptic curve group and the large prime order of the elliptic curve group through a trusted third-party institution according to the security parameters jointly selected by the receiver and the sender;
[0060] The second acquisition module is used to obtain the multiplicative group through a trusted third-party institution according to the security parameters jointly selected by the receiver and the sender;
[0061] The third acquisition module is used to obtain the first hash function through a trusted third-party institution according to the multiplicative group and the large prime order of the elliptic curve group;
[0062] The fourth acquisition module is used to obtain three hash functions with the same value range through a trusted third-party institution according to the number of elements of the sender;
[0063] The first calculation module is used to obtain the process parameter set of the receiver through calculation according to the private collection of the receiver, the multiplicative group, the first hash function, the generator of the elliptic curve group, and the three hash functions with the same value range;
[0064] The second calculation module is used to obtain the process parameter set of the sender through calculation according to the private collection of the sender, the multiplicative group, the first hash function, the generator of the elliptic curve group, the three hash functions with the same value range, and the process parameter set of the receiver;
[0065] The data correspondence module is used to send the process parameter set of the sender to the receiver, and through comparison and selection between the process parameter set of the receiver and the process parameter set of the sender, obtain the data set required by the receiver.
[0066] Compared with the prior art, the technical solution of the present invention has at least the following beneficial effects:
[0067] On the one hand, the above solution adopts the elliptic curve encryption method and the partially homomorphic encryption method of multiplicative homomorphism, which only requires two rounds of communication, reducing the communication volume of encryption. On the second hand, through the preprocessing of data by the sender and the receiver themselves, the computing amount of the receiver is reduced, and the computing efficiency is improved. On the third hand, a random mask with a blinding effect is filled in the hash table, so that the total amount of transmitted data is consistent, ensuring that the total amount of user data is not leaked, and enhancing the security and privacy protection of the protocol. Description of the Drawings
[0068] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0069] Figure 1 It is a flowchart of an embodiment of the two-party private set intersection method for hiding the number of receiver elements of the present invention;
[0070] Figure 2 It is a flowchart of obtaining three hash functions with the same value range in an embodiment of the two-party private set intersection method for hiding the number of receiver elements of the present invention;
[0071] Figure 3 It is a flowchart of obtaining the process parameter set of the receiver in an embodiment of the two-party private set intersection method for hiding the number of receiver elements of the present invention;
[0072] Figure 4 It is a flowchart of obtaining the hash table of the receiver in an embodiment of the two-party private set intersection method for hiding the number of receiver elements of the present invention;
[0073] Figure 5 It is a flowchart of obtaining the process parameter set of the sender in an embodiment of the two-party private set intersection method for hiding the number of receiver elements of the present invention;
[0074] Figure 6 It is a flowchart of obtaining the cuckoo hash table of the sender in an embodiment of the two-party private set intersection method for hiding the number of receiver elements of the present invention;
[0075] Figure 7 It is a flowchart of obtaining the data set required by the receiver in an embodiment of the two-party private set intersection method for hiding the number of receiver elements of the present invention;
[0076] Figure 8 It is a system block diagram of an embodiment of a two - party private set intersection system that hides the number of recipient elements of the present invention. Detailed implementation manners
[0077] Next, in conjunction with the accompanying drawings, the technical solutions in the present invention will be described.
[0078] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two.
[0079] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail in conjunction with the accompanying drawings and specific embodiments.
[0080] As Figure 1 shown in the flowchart of the embodiment of the two - party private set intersection method that hides the number of recipient elements of the present invention, the present invention provides a two - party private set intersection method that hides the number of recipient elements. This method is implemented by a two - party private set intersection system that hides the number of recipient elements. The method includes:
[0081] S1. According to the security parameters jointly selected by the recipient and the sender, through a trusted third - party institution, obtain the generator of the elliptic curve group and the large prime order of the elliptic curve group;
[0082] S2. According to the security parameters jointly selected by the recipient and the sender, through a trusted third - party institution, obtain the multiplicative group;
[0083] S3. According to the multiplicative group and the large prime order of the elliptic curve group, through a trusted third - party institution, obtain the first hash function;
[0084] Specifically, through formula (9), obtain the first hash function,
[0085] (9)
[0086] In the formula: is the first hash function, is the multiplicative group, is the large prime order of the elliptic curve group;
[0087] The elements in the multiplicative group are {1, 2,..., p - 1}.
[0088] S4. Based on the number of elements of the sender, obtain three hash functions with the same value range through a trusted third - party institution;
[0089] Specifically, as Figure 2 shown in the flowchart of obtaining three hash functions with the same value range in the embodiment of the two - party private set intersection method for hiding the number of receiver elements of the present invention, in S4, based on the number of elements of the sender, obtain three hash functions with the same value range through a trusted third - party institution, including:
[0090] S41. Based on the number of elements of the sender, obtain the number of buckets of the hash function;
[0091] Further, the relationship between the number of elements of the sender and the number of buckets of the hash function is shown in formula (10),
[0092] (10)
[0093] In the formula: is the number of buckets of the hash function, is the number of elements of the sender.
[0094] S42. Based on the number of buckets of the hash function, through the mapping of formula (1), obtain three hash functions with the same value range. These three hash functions with the same value range include: the first cuckoo hash function, the second cuckoo hash function, and the third cuckoo hash function,
[0095] (1)
[0096] In the formula: is the first cuckoo hash function, is the second cuckoo hash function, is the third cuckoo hash function, is the number of buckets of the hash function.
[0097] S5. Based on the private set of the receiver, the multiplicative group, the first hash function, the generator of the elliptic curve group, and the three hash functions with the same value range, through calculation, obtain the process parameter set of the receiver;
[0098] Specifically, as Figure 3 shown in the flowchart of obtaining the process parameter set of the receiver in the embodiment of the two - party private set intersection method for hiding the number of receiver elements of the present invention, in S5, based on the private set of the receiver, the multiplicative group, the first hash function, the generator of the elliptic curve group, and the three hash functions with the same value range, through calculation, obtain the process parameter set of the receiver, including:
[0099] S51. According to the generators of the multiplicative group and the elliptic curve group, the first operation unit of the receiver and the second operation unit of the receiver are obtained through formula (2) and formula (3) respectively.
[0100] (2)
[0101] (3)
[0102] Where: is the first operation unit of the receiver, is the second operation unit of the receiver, is the generator of the elliptic curve group, is the multiplicative group, and both x and y are elements randomly selected from the multiplicative group ;
[0103] S52. According to the private collection of the receiver and the first hash function, the private set of the receiver after hash mapping is obtained.
[0104] Furthermore, the private collection of the receiver , is the number of elements of the receiver,
[0105] For each , it is calculated through formula (11) to obtain the private set of the receiver after hash mapping,
[0106] (11)
[0107] Where: is an element in the private set of the receiver after hash mapping.
[0108] S53. According to the private set of the receiver after hash mapping, the first operation unit of the receiver, the second operation unit of the receiver, and the generator of the elliptic curve group, a multi-factor exponent congruence operation formula (4) is used to obtain a multi-factor exponent.
[0109] (4)
[0110] Where: is a random element in the private set of the receiver after hash mapping, is the corresponding multi-factor exponent;
[0111] S54. According to the private set of the receiver after hash mapping and three hash functions with the same value range, the hash table of the receiver is obtained.
[0112] S55. Integrate the first arithmetic unit of the recipient, the second arithmetic unit of the recipient, the multi-factor exponent, and the hash table of the recipient to obtain the process parameter set of the recipient.
[0113] Further, as Figure 4 shown in the flowchart of obtaining the hash table of the recipient in the two-party private set intersection method for hiding the number of recipient elements of the present invention, in S54, according to the private set of the recipient after hash mapping and the three hash functions with the same value range, the hash table of the recipient is obtained, including:
[0114] S541. According to the three hash functions with the same value range, obtain the number of rows of the hash table and three storage positions of the recipient;
[0115] The number of rows of the hash table is the number of elements of the sender.
[0116] S542. According to the number of elements of the recipient, obtain the number of columns of the hash table;
[0117] The number of columns of the hash table is a fixed value. When the number of recipient elements does not exceed , the number of columns of the hash table takes 28;
[0118] S543. According to the number of rows of the hash table, the number of columns of the hash table, and the three storage positions of the recipient, store the private set of the recipient after hash mapping into the three positions of the recipient respectively to obtain a hash table with a private set;
[0119] S544. Fill the empty bucket positions of the hash table with a private set with random masks to obtain the hash table of the recipient.
[0120] The random mask includes 0 or 1.
[0121] S6. According to the private set of the sender, the multiplicative group, the first hash function, the generator of the elliptic curve group, the three hash functions with the same value range, and the process parameter set of the recipient, through calculation, obtain the process parameter set of the sender;
[0122] Specifically, as Figure 5 shown in the flowchart of obtaining the process parameter set of the sender in the two-party private set intersection method for hiding the number of recipient elements of the present invention, in S6, according to the private set of the sender, the multiplicative group, the first hash function, the generator of the elliptic curve group, the three hash functions with the same value range, and the process parameter set of the recipient, through calculation, obtain the process parameter set of the sender, including:
[0123] S61. According to the multiplicative group, through public key encryption operation, obtain the encrypted multiplicative group;
[0124] S62. Obtain the private set of the sender after hash mapping according to the private collection of the sender and the first hash function;
[0125] S63. According to the private set of the sender after hash mapping and three hash functions with the same value range, use the cuckoo data structure to obtain the cuckoo hash table of the sender;
[0126] S64. According to the cuckoo hash table of the sender, the multiplicative group and the process parameter set of the receiver, respectively, through formula (5) and formula (6), obtain the first intermediate operation unit of the receiver and the second intermediate operation unit of the receiver,
[0127] (5)
[0128] (6)
[0129] Wherein: is the first intermediate operation unit of the receiver, is the second intermediate operation unit of the receiver, is the first operation unit of the receiver, and are both random elements in the multiplicative group, and t is the serial number of the element in the cuckoo hash table of the sender;
[0130] S65. According to the cuckoo hash table of the sender, the process parameter set of the receiver, the multiplicative group and the second intermediate operation unit of the receiver, through formula (7), obtain the third intermediate operation unit of the receiver,
[0131] (7)
[0132] Wherein: is the third intermediate operation unit of the receiver, is the public key encryption operation function of the sender, is the second operation unit of the receiver, is the element in the cuckoo hash table of the sender;
[0133] If is a random mask, then is set to 1.
[0134] S66. Integrate the encrypted multiplicative group, the cuckoo hash table of the sender, the first intermediate operation unit of the receiver and the third intermediate operation unit of the receiver to obtain the process parameter set of the sender.
[0135] Further, as Figure 6Flowchart of obtaining the sender's cuckoo hash table in the embodiment of the two-party private set intersection method for hiding the number of recipient elements of the present invention. In S63, according to the privately-owned set of the sender after hash mapping and three hash functions with the same value range, a cuckoo data structure is used to obtain the sender's cuckoo hash table, including:
[0136] S631. According to the three hash functions with the same value range, obtain the buckets of the sender's cuckoo hash table and three storage locations of the sender;
[0137] S632. According to the buckets of the sender's cuckoo hash table and the three storage locations of the sender, randomly store the privately-owned set of the sender after hash mapping into one of the three storage locations of the sender to obtain a cuckoo hash table with a privately-owned set;
[0138] S633. Fill the empty bucket positions of the cuckoo hash table with the privately-owned set with random masks to obtain the sender's cuckoo hash table.
[0139] S7. Send the set of process parameters of the sender to the recipient, and through comparison and selection between the set of process parameters of the recipient and the set of process parameters of the sender, obtain the data set required by the recipient.
[0140] Specifically, as Figure 7 Flowchart of obtaining the data set required by the recipient in the embodiment of the two-party private set intersection method for hiding the number of recipient elements of the present invention. In S7, through comparison and selection between the set of process parameters of the recipient and the set of process parameters of the sender, obtain the data set required by the recipient, including:
[0141] S71. According to the set of process parameters of the recipient, obtain the multi-factor exponent and the recipient's hash table;
[0142] S72. According to the set of process parameters of the sender, the multi-factor exponent, and the recipient's hash table, compare and select the elements in the corresponding set of process parameters of the sender through formula (8). If the equation holds, the elements in the set of process parameters of the recipient participating in the operation are equal to the elements in the set of process parameters of the sender, that is, the intersection elements are obtained, and the data set required by the recipient is obtained.
[0143] (8)
[0144] In the formula, is an encrypted multiplicative group, is the multi-factor exponent corresponding to the element in the t-th row and m-th column of the recipient's hash table, is the public key encryption operation function of the recipient.
[0145] Furthermore, formula (8) satisfies multiplicative homomorphic operation.
[0146] As Figure 8 shown in the system block diagram of the two-party private set intersection system for hiding the number of recipient elements of the present invention, the present invention provides a two-party private set intersection system for hiding the number of recipient elements. This system is applied to a two-party private set intersection method for hiding the number of recipient elements. The system includes: a first acquisition module, a second acquisition module, a third acquisition module, a fourth acquisition module, a first calculation module, a second calculation module, and a data correspondence module. Specifically,
[0147] The first acquisition module is used to obtain the generator of the elliptic curve group and the large prime order of the elliptic curve group through a trusted third-party institution according to the security parameters jointly selected by the recipient and the sender.
[0148] The second acquisition module is used to obtain the multiplicative group through a trusted third-party institution according to the security parameters jointly selected by the recipient and the sender.
[0149] The third acquisition module is used to obtain the first hash function through a trusted third-party institution according to the multiplicative group and the large prime order of the elliptic curve group.
[0150] The fourth acquisition module is used to obtain three hash functions with the same value range through a trusted third-party institution according to the number of elements of the sender.
[0151] The first calculation module is used to obtain the process parameter set of the recipient through calculation according to the private set of the recipient, the multiplicative group, the first hash function, the generator of the elliptic curve group, and the three hash functions with the same value range.
[0152] The second calculation module is used to obtain the process parameter set of the sender through calculation according to the private set of the sender, the multiplicative group, the first hash function, the generator of the elliptic curve group, the three hash functions with the same value range, and the process parameter set of the recipient.
[0153] The data correspondence module is used to send the process parameter set of the sender to the recipient, and through comparison and selection between the process parameter set of the recipient and the process parameter set of the sender, obtain the data set required by the recipient.
[0154] The present invention provides a two-party private set intersection method and system for hiding the number of recipient elements. The invention adopts an elliptic curve encryption method and a partially homomorphic encryption method with multiplicative homomorphism, which only requires two rounds of communication, reducing the encrypted communication volume. At the same time, through the preprocessing of data by the sender and the recipient themselves, the computational amount of the recipient is reduced, and the computational efficiency is improved. Finally, a random mask with a blinding effect is filled in the hash table, making the total amount of transmitted data consistent, ensuring that the total amount of user data is not leaked, and enhancing the security and privacy protection of the protocol.
[0155] It can be understood that the present invention is described by the above embodiments and should not be construed as a limitation on the implementation manner and scope of the present invention. Those skilled in the art know that various changes or equivalent replacements can be made to these features and embodiments without departing from the spirit and scope of the present invention. In addition, under the teaching of the present invention, these features and embodiments can be modified to adapt to specific situations and materials without departing from the spirit and scope of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed herein, and all embodiments falling within the scope of the claims of this application belong to the scope protected by the present invention.
Claims
1. A method for finding the intersection of two private sets with the number of elements of the receiving party hidden, characterized in that: The method comprises: S1. Based on the security parameters jointly selected by the receiver and the sender, the generator of the elliptic curve group and the large prime order of the elliptic curve group are obtained through a trusted third-party organization; S2. Obtaining a multiplication group through a trusted third party institution according to the security parameters jointly selected by the receiver and the sender; S3. Obtaining a first hash function through a trusted third party according to the multiplication group and the large prime order of the elliptic curve group; S4. Obtain three hash functions with the same value range through a trusted third party organization according to the number of elements of the sender; S5. Obtain a process parameter set of the recipient through calculation according to the private collection of the recipient, the multiplication group, the first hash function, the generator of the elliptic curve group, and the three hash functions with the same range; S6. Obtain the process parameter set of the sender through calculation according to the private collection of the sender, the multiplication group, the first Hash function, the generator of the elliptic curve group, the three Hash functions with the same value range, and the process parameter set of the receiver; S7. Send the process parameter set of the sender to the receiver, and obtain the data set required by the receiver by comparing and selecting the process parameter set of the receiver with the process parameter set of the sender.
2. The method for finding the intersection of two private sets with the number of hidden receiver elements according to claim 1, characterized in that: In S4, three hash functions with the same value range are obtained through a trusted third-party organization according to the number of elements of the sender, including: S41, obtaining the number of buckets of the hash function according to the number of elements of the sender; S42. According to the number of buckets of the hash function, three hash functions with the same value range are obtained by mapping through formula (1), wherein the three hash functions with the same value range include: a first cuckoo hash function, a second cuckoo hash function and a third cuckoo hash function. (1) Where: is the first cuckoo hash function, is the second cuckoo hash function, is the third cuckoo hash function, is the number of buckets of the hash function.
3. The method for finding the intersection of two private sets with the number of hidden receiver elements according to claim 1, characterized in that: In S5, the process parameter set of the receiver is obtained by calculation according to the private set of the receiver, the multiplication group, the first hash function, the generator of the elliptic curve group and the three hash functions with the same value range, including: S51, according to the generators of the multiplication group and the elliptic curve group, respectively obtain the first operation unit of the receiving party and the second operation unit of the receiving party through formula (2) and formula (3), (2) (3) Where: is the first computing unit of the receiver, is the second computing unit of the receiver, is the generator of the elliptic curve group, is a multiplication group, x and y are both multiplication groups A randomly selected element from S52, obtaining a private set of the recipient after hash mapping according to the private set of the recipient and the first hash function; S53, according to the private set of the recipient after the hash mapping, the first operation unit of the recipient, the second operation unit of the recipient and the generator of the elliptic curve group, a multi-factor index is obtained through the multi-factor exponential congruence operation formula (4), (4) Where: is a random element in the recipient's private collection after hash mapping, is the corresponding multi-factor index; S54, obtaining a hash table of the recipient according to the recipient's private set after hash mapping and the three hash functions with the same value range; S55 , integrating the first computing unit of the receiving party, the second computing unit of the receiving party, the multi-factor index and the hash table of the receiving party to obtain a process parameter set of the receiving party.
4. The method for finding the intersection of two private sets with the number of hidden receiver elements according to claim 3, characterized in that: In S54, the hash table of the recipient is obtained according to the private set of the recipient after the hash mapping and the three hash functions with the same value range, including: S541. Obtain the number of rows in the hash table and three storage locations of the receiver according to the three hash functions with the same value range; S542, obtaining the number of columns of the hash table according to the number of elements of the receiving party; S543, according to the number of rows of the hash table, the number of columns of the hash table and the three storage locations of the receiver, the private set of the receiver after the hash mapping is stored in the three locations of the receiver respectively, to obtain a hash table with the private set; S544: Fill the empty bucket positions of the hash table with the private set with a random mask to obtain the hash table of the recipient.
5. The method for finding the intersection of two private sets with the number of hidden receiver elements according to claim 4, characterized in that: The number of rows of the hash table includes: the number of rows of the hash table is the number of elements of the sender.
6. The method for finding the intersection of two private sets with the number of hidden receiver elements according to claim 4, characterized in that: The random mask includes 0 or 1.
7. The method for finding the intersection of two private sets with the number of hidden receiver elements according to claim 3, characterized in that: In S6, the process parameter set of the sender is obtained by calculation according to the private set of the sender, the multiplication group, the first Hash function, the generator of the elliptic curve group, the three Hash functions with the same value range and the process parameter set of the receiver, including: S61, performing a public key encryption operation according to the multiplication group to obtain an encrypted multiplication group; S62, obtaining a private set of the sender after hash mapping according to the private set of the sender and the first hash function; S63, according to the private set of the sender after hash mapping and the three hash functions with the same value range, using a cuckoo data structure to obtain a cuckoo hash table of the sender; S64, according to the cuckoo hash table of the sender, the multiplication group and the process parameter set of the receiver, respectively obtain the first intermediate operation unit of the receiver and the second intermediate operation unit of the receiver through formula (5) and formula (6), (5) (6) Where: is the first intermediate computing unit of the receiver, is the second intermediate computing unit of the receiver, is the first computing unit of the receiver, and are all random elements in the multiplication group, and t is the sequence number of the element in the sender's cuckoo hash table; S65, according to the cuckoo hash table of the sender, the process parameter set of the receiver, the multiplication group and the second intermediate operation unit of the receiver, the third intermediate operation unit of the receiver is obtained by formula (7), (7) Where: is the third intermediate computing unit of the receiver, is the sender’s public key encryption function, is the second computing unit of the receiver, is the element in the sender's cuckoo hash table; S66. Integrate the encrypted multiplication group, the cuckoo hash table of the sender, the first intermediate operation unit of the receiver, and the third intermediate operation unit of the receiver to obtain a process parameter set of the sender.
8. The method for finding the intersection of two private sets with the number of hidden receiver elements according to claim 7, characterized in that: In S63, according to the private set of the sender after hash mapping and the three hash functions with the same value range, a cuckoo data structure is used to obtain the cuckoo hash table of the sender, including: S631. Obtain the buckets of the cuckoo hash table of the sender and three storage locations of the sender according to the three hash functions with the same value range; S632: According to the bucket of the cuckoo hash table of the sender and the three storage locations of the sender, randomly store the private set of the sender after hash mapping into one of the three storage locations of the sender to obtain a cuckoo hash table with the private set; S633: Fill the empty bucket positions of the cuckoo hash table with the private set with a random mask to obtain the cuckoo hash table of the sender.
9. The method for finding the intersection of two private sets with the number of elements of the hidden receiver according to claim 7, characterized in that: The step S7 compares and selects the process parameter set of the receiver with the process parameter set of the sender to obtain a data set required by the receiver, including: S71, obtaining a multi-factor index and a hash table of the receiver according to the process parameter set of the receiver; S72. According to the process parameter set of the sender, the multi-factor index and the hash table of the receiver, the corresponding element in the process parameter set of the sender is selected by comparison through formula (8). If the equation holds, the element in the process parameter set of the receiver participating in the operation is equal to the element in the process parameter set of the sender, that is, the intersection element is obtained, and the data set required by the receiver is obtained. (8) In the formula, is the encrypted multiplication group, is the multi-factor index of the element in row t and column m in the recipient’s hash table, It is the receiver's public key encryption operation function.
10. A two-party private set intersection system for hiding the number of receiver elements, used to implement the two-party private set intersection method for hiding the number of receiver elements as claimed in any one of claims 1 to 9, characterized in that: The system comprises: A first acquisition module is used to obtain, through a trusted third party organization, a generator of an elliptic curve group and a large prime order of the elliptic curve group according to security parameters jointly selected by a receiver and a sender; A second acquisition module is used to obtain a multiplication group through a trusted third party institution according to the security parameters jointly selected by the receiver and the sender; A third acquisition module obtains a first hash function through a trusted third party institution according to the multiplication group and the large prime order of the elliptic curve group; A fourth acquisition module is used to obtain three hash functions with the same value range through a trusted third party organization according to the number of elements of the sender; A first calculation module is used to obtain a process parameter set of the receiver through calculation according to the private collection of the receiver, the multiplication group, the first hash function, the generator of the elliptic curve group and the three hash functions with the same value range; A second calculation module is used to obtain the sender's process parameter set by calculation according to the sender's private collection, the multiplication group, the first Hash function, the generator of the elliptic curve group, the three Hash functions with the same value range and the receiver's process parameter set; The data corresponding module is used to send the process parameter set of the sender to the receiver, and obtain the data set required by the receiver by comparing and selecting the process parameter set of the receiver with the process parameter set of the sender.
Citation Information
Patent Citations
Multi-strategy security ciphertext data sharing method based on privacy protection
CN116318663A
Image chaotic encryption method based on elliptic curve and S box
CN117318915A