Encryption and decryption method, system and electronic device based on oblivious transfer extension
By optimizing the inadvertent transmission extension protocol, the receiver can select and obtain multiple messages in one interaction, solving the problem of inefficiency in the existing technology and achieving efficient and flexible multi-message transmission, which is suitable for recommendation systems, distributed database query and privacy computing.
Patent Information
- Application Number
- CN202510387894.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-03-31
AI Technical Summary
The existing inadvertent transmission protocol only supports a single message transmission in one communication, resulting in inefficiency and excessive computing overhead in large-scale data interaction scenarios, which cannot meet the flexibility and efficiency requirements of modern practical applications.
By optimizing the inadvertent transmission extension protocol, select bitmasks and anti-collision homomorphic encryption algorithms are introduced, allowing the receiver to select and obtain multiple messages in one interaction, while ensuring the sender's choice of unknown recipients, reducing the number of interaction rounds and communication costs.
It realizes efficient transmission of multiple messages in a single protocol interaction, significantly reducing communication and computing overhead, improving the efficiency and flexibility of the protocol, and is suitable for large-scale data interaction scenarios.
Smart Images

Figure CN119892525B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cryptography, and particularly relates to an encryption and decryption method, system, and electronic device based on oblivious transfer extension. Background Art
[0002] Oblivious transfer is an important primitive in cryptography, which can protect the privacy and security of interactive data between the receiver and the sender. Specifically, it allows the sender to transfer one of multiple messages to the receiver. While the receiver obtains the information, it has no idea which message it has received, and the sender can only know the requested information and cannot learn other information. Therefore, the oblivious transfer method has the characteristic of protecting the privacy of both communication parties and plays a crucial role in the process of data transmission and sharing, providing a solid theoretical foundation for constructing various cryptographic protocols.
[0003] (1) Oblivious Transfer Protocol
[0004] In 1981, the prior art proposed a probabilistic oblivious transfer algorithm based on RSA public-key encryption. That is, when the sender communicates with the receiver, the probability for the receiver to obtain information is 1 / 2, and the sender cannot know whether the receiver has received the information, laying a theoretical foundation for the development of oblivious transfer. Subsequently, the concept of oblivious transfer has evolved continuously. The prior art first proposed the classic 1-out-of-2 oblivious transfer protocol (abbreviated as ), which consists of two participating parties, and its ideal function is as Figure 1 shown. The protocol requires the sender (abbreviated as ) to provide a pair of strings, and the receiver (abbreviated as ) can only select one of them, and can only obtain this string and cannot learn any information about the other string; and also cannot determine which option is selected.
[0005] After that, the prior art further pointed out that the classic 1-out-of-2 oblivious transfer protocol is equivalent to the probabilistic oblivious transfer protocol. Based on this protocol, some researchers constructed a 1-out-of- Select the 1-out-of-2 oblivious transfer protocol, whose overhead is reduced to the linear level. However, if the existing public-key cryptography-based oblivious transfer protocol is directly deployed in a cloud distributed architecture, the computational and communication overhead of the distributed sharing scheme will increase exponentially with the increase in the number of servers, resulting in inability to be instantiated in application scenarios.
[0006] (2) Oblivious Transfer Extension Protocol
[0007] The research on oblivious transfer mainly focuses on reducing the number of OT protocol executions and computational overhead. Currently, two main methods have been proposed, the pre-computed OT (Random Oblivious Transfer, abbreviated as ROT) technique and the oblivious transfer extension (Oblivious Transfer Extension, abbreviated as OTE) technique. On the one hand, some researchers utilized the idea similar to Beaver triples, proposed a pre-computed OT protocol with theoretical significance, and designed the standard 1-out-of-2 oblivious transfer protocol for the first time. A large amount of computation was migrated to offline pre-computation, and only a small number of operations needed to be performed during the online execution of the protocol. Although the Beaver pre-computation idea did not reduce the amount of computation, it improved the online computational efficiency. Both parties only needed symmetric operations and an additional interaction online.
[0008] In addition, the oblivious transfer extension technique uses symmetric encryption to replace public-key encryption, significantly reducing the algorithm overhead. Some researchers also utilized the "row-to-column" idea and proposed the classic OTE protocol, called the IKNP03 protocol. Specifically, assume the size of the matrix to be transmitted is ( ), the traditional OT protocol needs to execute times of protocol, that is . However, IKNP03 executes times of column OT to replace times of row transmissions in , where represents the number of columns. Their protocol successfully reduces the number of runs of the base OT from to , significantly improving the protocol running efficiency and providing security against semi-honest receivers. The IKNP protocol mainly includes three stages: the base OT stage, the OTE stage, and the output stage.
[0009] In the base-OT stage, the sender and the receiver exchange identities. The receiver ( ) acts as the sender and inputs strings of length bits to form matrices and , and the sender ( As the receiver, input a column vector of length , where the column vector has the relationship with matrices and , as shown in Figure 2 .
[0010] Randomly select a row vector , which has matrices and . The two perform times of the base OT protocol. Select one column of matrices and , according to the value of the -th bit. Combine the received groups of strings to form a matrix . The interaction process is as shown in Figure 3 .
[0011] In the OTE phase, when , use matrix to calculate ; when , . At this time, has a group of messages , has the matrix corresponding to row vector , as shown in Figure 4 . It can be found that can use each row of matrix to perform hash and XOR operations on the data to achieve symmetric encryption of the data.
[0012] In the output phase, use the matrix to decrypt the data, and only the selected data can be obtained, and no information about other data can be learned. The decryption idea is as shown in Figure 5 .
[0013] Then, some researchers found that IKNP03 consumes 42% of the computational overhead on matrix transpose and cannot resist malicious receiver attacks. They constructed a strongly secure OTE protocol based on pseudorandom functions (PRF for short) in the standard model, called the ALSZ13 protocol, and reduced the computational complexity of matrix transpose from to , where is the CPU register size. At the same time, they resist malicious receivers by adding a consistency phase to ensure resistance to malicious models. Some researchers have respectively used a small amount of , commitment technology, and Pseudorandom Generator (PRG) technology to resist malicious receivers. Some researchers have found that IKNP03 uses repeated coding technology to generate selected strings , restricting the sender to only be able to achieve once per OTE instance .
[0014] To address this limitation, some researchers introduced Error-correcting Code (ECC) to replace repeated coding and generate strings . Based on this, they designed protocol, that is, expanding a single OTE instance from to . To further optimize and apply OTE, some researchers used Pseudorandom Function (PRF) instead of error-correcting code and designed protocol, that is, only executing one instance to achieve string equality detection once. However, algorithm cannot achieve the defined Hamming-related robustness. To efficiently construct the OTE protocol in the random oracle, some researchers constructed a DDH-based secure oblivious transfer protocol and instantiated OTE through the Crystals.Kyber key protocol, which can complete the interaction with only one round of communication. Some researchers improved the literature in terms of communication load, abandoned the time-consuming matrix transmission, and used order polynomial transmission to implement OTE, reducing the communication complexity from to . Some researchers optimized the literature in terms of balancing communication load and running efficiency. By changing the output of the error-correcting code from a string to a matrix, the communication complexity was reduced from to . Some researchers pointed out that simply reusing the protocol to achieve batch processing of OTE is an insecure method. They achieved secure batch processing of OTE by using region separation technology between OTE instances. Some researchers first proposed to instantiate the entire OTE protocol as , reducing the communication overhead by half compared to the traditional OTE protocol. Some researchers pointed out that the security parameter of the OT instance in IKNP03 is , the cost of generating OTE is still very high. They optimized the communication cost of IKNP03 in the Minicrypt model and proposed the SoftSpoken OT protocol, reducing the size of the security parameter to . Some researchers constructed an OTE protocol in the reverse firewall. Some researchers designed a multi-party matrix calculation scheme based on OTE, effectively reducing the number of communication rounds. However, the existing oblivious transfer extension protocols cannot be applied to distributed scenarios, and do not consider problems such as the easy leakage of access patterns and the single transmission mode during the transmission of shared data.
[0015] To sum up, domestic and foreign research scholars have carried out a large amount of research on the security, performance optimization, and application expansion of oblivious data transfer. However, most of the existing oblivious transfer protocols and oblivious transfer extension protocols based on public-key cryptography only consider one-to-one application scenarios and are applicable to two-party application scenarios, but not to protocols for cloud distributed storage architectures. At the same time, the current distributed oblivious transfer protocols mainly use secret sharing technology to realize data interaction, which is difficult to adapt to distributed scenarios. In addition, the oblivious transfer protocol only protects the private information of the two communicating parties, and there are risks such as leakage of access patterns and transmission traces when multiple parties interact. Therefore, the oblivious transfer protocol for data needs to be further studied in terms of security, performance optimization, and scenario adaptation.
[0016] In recent years, protocols such as IKNP03, ALSZ13, and ALSZ15 have all adopted a 1-out-of-2 oblivious transfer algorithm in the oblivious transfer extension stage. In the above protocols, it is required that the sender can only send 2 pieces of information to the receiver each time, and the receiver can only select one piece of information from the 2 pieces of information each time during the interaction. In other words, during the interaction process, the receiver cannot request 2 or more pieces of information from the sender at the same time, which severely limits the flexibility of retrieving information during the interaction process. In addition, some researchers introduced error-correcting codes (ECC for short) to replace the repetition coding and generate strings . Based on this, they designed protocol, that is, expanding one OTE instance from to . In order to further optimize and apply OTE, some researchers used a pseudorandom function (PRF for short) to replace the error-correcting code and designed protocol, that is, only executing one instance to achieve a string equality detection.
[0017] Although the 1-out-of-2 oblivious transfer protocol is theoretically effective, it faces great limitations in practical applications. Especially when the receiver hopes to obtain from the sender When a message is received, the following operation must be repeated times The [selected 1] oblivious transfer protocol. Each execution of the existing protocol involves complex cryptographic operations such as key generation, encryption, transmission, and decryption. Therefore, repeated execution multiple times will lead to a linear increase in computational and communication costs. This characteristic makes the traditional The [selected 1] oblivious transfer protocol inefficient in practical scenarios that require large-scale data interaction. For example, in distributed database queries, private information retrieval, or secure computing of machine learning models, the recipient often needs to obtain a large amount of data. If a complete set of oblivious transfer protocols needs to be re-executed for each query, the overall overhead of the system will increase rapidly as the number of queries increases, and this method is difficult to meet the actual requirements of high efficiency and low latency. In addition, the existing technical solutions also face the problem of insufficient data flexibility. In Under the [selected 1] setting, each protocol can only obtain a specific piece of information at a time, and it is impossible to flexibly obtain multiple pieces of data simultaneously. This constraint is particularly inconvenient in some application scenarios. For example, in the scenario where the recipient needs to obtain multiple related pieces of information from a large dataset at one time, the existing method needs to transmit them one by one, which is difficult to meet the efficient interaction requirements in the actual scenario.
[0018] In summary, although The [selected 1] oblivious transfer meets the requirements of privacy protection in design, its limitations in efficiency and flexibility make it difficult to adapt to modern practical application scenarios that require large-scale data interaction. Summary of the Invention
[0019] A key technical bottleneck in current oblivious transfer schemes is the inability to efficiently obtain multiple messages in a single communication between two parties. This problem severely restricts the flexibility and scalability of the protocol. Traditional oblivious transfer protocols only support the ability to obtain one message in a single transfer. If the receiver wishes to obtain \(n\) messages, the oblivious transfer protocol must be executed \(n\) times. Although this method is theoretically feasible, its communication and computational overheads increase linearly with \(n\), resulting in a significant decrease in efficiency in practical applications, especially in scenarios where large-scale data interaction is required. To solve this problem, the present invention proposes an encryption and decryption method and system based on extended selective oblivious transfer, which can achieve the goal of the receiver obtaining multiple messages in a single oblivious transfer. Compared with the prior art, the present invention significantly reduces the communication cost and computational overhead by optimizing the transfer process and reducing the number of interaction rounds, greatly improving the efficiency of the protocol. In the present invention, the receiver can flexibly select \(n\) messages of interest through a single protocol interaction, while ensuring that the sender remains completely unaware of the receiver's selection. The present invention not only improves the efficiency of the protocol, but also expands the application scenarios of oblivious transfer, providing greater flexibility and operability for the deployment of practical systems.
[0020] The present invention adopts the following technical solutions:
[0021] An encryption and decryption method based on extended oblivious transfer, comprising the following steps:
[0022] Step 1: The sender and the receiver perform oblivious transfer;
[0023] Step 2: The receiver sends the oblivious transfer selection bitmask to the sender;
[0024] Step 3: The sender encrypts the original data and then sends it to the receiver;
[0025] Step 4: The receiver decrypts the ciphertext sent by the sender.
[0026] Preferably, in Step 1, the sender randomly selects a string , consisting of 0s and 1s, with a length of ; denotes the \(i\)-th bit of the string ; this string represents that in the basic oblivious transfer, the sender acts as the receiver, while the string is the selection bit for each 2-out-of-1 oblivious transfer, indicating the subscript of the message it wants to select; the receiver's input has two parts: the first part is selection numbers , where ranges from ; Indicates the selection bit of the receiver in the -th oblivious transfer, indicating which data he wants to select; the second part is a collision-resistant homomorphic encryption algorithm , and has an encryption public key and a decryption private key ; the public input is a decimal-to-binary function F, where represents the -th bit of the binary form of the decimal number ; finally, a collision-resistant hash function is also required.
[0027] Preferably, in step 1, the receiver generates two -sized matrices , : randomly generate and determine the value of by calculating ; where, , respectively represent the , -th row values of ; in the basic oblivious transfer, the receiver acts as the sender's identity, and what needs to be sent are and these two messages. After sending out these two messages, the sender selects one message to receive according to the string generated in step 1, thus realizing the basic function of 2-out-of-1 oblivious transfer; the detailed process is as follows:
[0028] The sender and the receiver perform times of 2-out-of-1 oblivious transfer, where represents the number of columns of the matrices , :
[0029] Step 1.1: The receiver sends two messages , , where, , respectively represent the , -th columns of the matrices ;
[0030] Step 1.2: The sender selects one of them to receive according to his own selection bit ; if , then it receives ; if , then it receives ;
[0031] After completing the above steps, the sender will obtain strings. By merging these strings column by column, a matrix can be obtained; Let represent the th row of the Q matrix, which satisfies .
[0032] Preferably, Step 2 is specifically as follows: After Step 1 is completed, the first part: The basic oblivious transfer has been completed. Through the information exchange in the previous steps, the recipient has a matrix , and the sender has matrix . The relationship between matrix and matrix is ; Subsequently, for , where m represents the number of rows of matrix , the recipient performs the following operations: If , then the recipient calculates and sends it to the sender; If , then the recipient generates a random string and uses it as the value of and sends it to the sender; represents the choice bitmask of the oblivious transfer recipient.
[0033] Preferably, Step 3 is specifically as follows: After Step 2 is completed, all the preliminary preparations have been completed. Next, only the sender needs to encrypt the original data and then send it to the recipient for decryption. For , where m represents the number of rows of matrix , the input of the sender is a set of information , where the length of each message is bits, represents the th data sent in the rd oblivious transfer; The sender encrypts the data according to the following formula and sends it to the recipient:
[0034] ;
[0035] Preferably, Step 4 is specifically as follows: For the ciphertext sent by the sender, some of the messages can be directly decrypted by the receiver because the receiver has the necessary key for the decryption operation; for the other part of the messages, they are indistinguishable from random numbers to the receiver, so the receiver cannot decrypt them to obtain the original data; specifically, which messages can be decrypted and which cannot are indicated in the input of the receiver. The receiver first constructs a binary string, where 0 represents the information that does not need to be obtained and 1 represents the information that needs to be obtained, and then converts this string into a decimal number and assigns this number to ; In the specific protocol, for , the receiver decrypts the ciphertexts it wants from according to the following formula:
[0036] .
[0037] The process of the present invention is all completed. Next, its effectiveness is demonstrated, that is, the receiver can finally decrypt the data it wants, as proved by the following formula:
[0038] ;
[0039] As can be seen from the above formula, the receiver can finally use as the key to decrypt ciphertexts, and the positions of these ciphertexts have been marked in .
[0040] The present invention also discloses an encryption and decryption system based on oblivious transfer extension for performing the above method, which includes the following modules:
[0041] Oblivious transfer module: used to perform oblivious transfer between the sender and the receiver;
[0042] Selected bit mask sending module: used to perform the receiver sending the selected bit mask of the oblivious transfer to the sender;
[0043] Encryption module: used to perform the sender encrypting the original data and then sending it to the receiver;
[0044] Decryption module: used to perform the receiver decrypting the ciphertext sent by the sender.
[0045] The present invention also discloses an electronic device, which includes:
[0046] Processor;
[0047] A memory for storing a program, which, when called and executed by a processor, causes the processor to execute the above method or system.
[0048] The technical solution submitted by the present invention significantly improves the efficiency of oblivious transfer and breaks through the limitations of traditional protocols in terms of single - transfer capacity. By reducing the number of interaction rounds and optimizing the communication process, the present invention realizes efficient multi - message transfer capabilities and has broad application prospects, especially showing important value in the fields of recommendation systems and privacy computing.
[0049] The present invention optimizes the traditional oblivious transfer protocol and proposes a scheme that can efficiently transfer multiple messages in a single protocol interaction, fundamentally solving the limitations of existing technical solutions in terms of efficiency and flexibility. Traditional oblivious transfer protocols usually only allow the receiver to select and obtain one message in a single interaction. If the receiver needs to obtain k messages, the protocol must be executed k times repeatedly. Although this method is theoretically feasible, its communication and computational overheads increase linearly with the increase of k. Especially in practical applications that require large - scale data interaction, it is prone to problems such as low efficiency, response delay, and waste of system resources. This limitation makes traditional oblivious transfer difficult to adapt to modern high - efficiency privacy - protection scenarios.
[0050] To solve this problem, the present invention introduces a new mechanism by optimizing the protocol design and transfer process, enabling the receiver to flexibly select and obtain multiple interested messages in a single protocol interaction, while the sender remains completely unaware of the receiver's specific selection during this process, and the receiver cannot obtain the unselected messages. This improvement significantly reduces the number of interaction rounds and communication costs, greatly enhancing the overall efficiency of the protocol. Compared with traditional solutions, the present invention not only achieves the goal of obtaining multiple messages in a single protocol, but also expands the application scenarios of oblivious transfer, making it more practical in practical applications with high privacy - protection requirements and large amounts of interactive data.
[0051] The present invention shows important value in recommendation systems. Recommendation systems usually need to push multiple pieces of content that a user may be interested in to the user, and the user then selects several interested items from them. However, traditional solutions require multiple executions of the protocol for each user selection, which is not only inefficient but also increases the communication burden on the platform. The present invention allows the user to select multiple interested contents from the recommendation list in a single interaction, while the platform cannot know which items the user has specifically selected during this process. This mechanism not only protects the user's privacy but also greatly reduces the communication and computational resources required for protocol execution.
[0052] In addition, the present invention can also be widely applied to multiple fields such as distributed database query, private information retrieval, privacy-preserving machine learning, etc. In a distributed database, a user can efficiently query multiple data items of interest from the database at one time, and the database itself cannot know the specific query content of the user. In privacy-preserving machine learning, a user can obtain multiple prediction results or parameters from the model at one time without multiple interactions. This ability not only improves the performance of the protocol but also meets the urgent need for efficient privacy interaction in data-intensive scenarios.
[0053] In summary, by significantly improving the efficiency and flexibility of oblivious transfer, the present invention breaks through the limitations of traditional protocols and provides an efficient, secure, and practical solution for privacy protection and large-scale data interaction scenarios. This innovation demonstrates broad application potential in fields such as recommendation systems, distributed databases, and privacy computing, laying a solid foundation for the future development of privacy protection technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 is the interaction flowchart of the selective oblivious transfer protocol;
[0055] Figure 2 is the relationship diagram of column vectors and matrices;
[0056] Figure 3 is the interaction process diagram of the basic OT protocol;
[0057] Figure 4 is the interaction process diagram of the OTE stage;
[0058] Figure 5 is the interaction process diagram of the output stage;
[0059] Figure 6 is the block diagram of an encryption and decryption system based on oblivious transfer extension in a preferred embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0060] The following will describe in detail the preferred embodiments of the present invention with reference to the accompanying drawings.
[0061] As Figure 1 shown, an encryption and decryption method based on oblivious transfer extension in this embodiment involves two participating parties: the data sender and the data receiver.
[0062] The overall solution of this embodiment can be divided into two stages: The first stage is the basic oblivious transfer (base-OT). In this part, the sender and the receiver will swap identities. The receiver sends data, and the sender receives data, and several rounds of 2-out-of-1 oblivious transfer are performed. The second stage is the extended part of oblivious transfer. In this part, the sender sends the data it has prepared, and the receiver selects a part of the data to receive according to its selected bit positions. The number of received data can be adjusted flexibly, and the receiver does not know the data it has not received, and the sender also does not know the situation of the receiver's received data. The following details the specific steps of this embodiment:
[0063] The specific steps of Step 1 are as follows:
[0064] The sender randomly selects a string , consisting of 0s and 1s, with a length of . Denote the -th bit of the string . The string means that in the basic oblivious transfer, the sender acts as the receiver, while (the string is the selection bit for each 2-out-of-1 oblivious transfer, representing the subscript of the message it wants to select).
[0065] The receiver's input has two parts. The first part is selection numbers , where ranges from (the value of n is the same as the n in OTn choose k, indicating that in each OT instance, the sender transfers n messages to the receiver). Denote the selection bit of the receiver in the -th oblivious transfer, marking which data it wants to select; the second part is a collision-resistant homomorphic encryption algorithm , and has the encryption public key and the decryption private key .
[0066] The common input includes a decimal-to-binary function F and a collision-resistant hash function , where denotes the -th bit of the binary form of the decimal number .
[0067] The receiver generates two -sized matrices , as follows: Randomly generate and calculate through To determine value. Among them, means the value of the j-th bit of the string r, and the F function is to convert the value from decimal to binary, 、 respectively represent 、 the row value. In the basic oblivious transfer, the receiver acts as the sender's identity, and what needs to be sent are and these two messages. After sending out these two messages, the sender selects one message to receive according to the string generated in step one, thus realizing the basic function of 1-out-of-2 oblivious transfer. The following details its process:
[0068] The sender and the receiver perform times of 1-out-of-2 oblivious transfer, where represents the number of columns of the matrices 、 :
[0069] Step 1.1: The receiver sends two messages 、 , where 、 respectively represent the 、 th column of the matrices;
[0070] Step 1.2: The sender selects one to receive according to its own selection bit . If , it receives ; if , it receives .
[0071] After completing the above steps, the sender will obtain strings. Merging these strings by column, a matrix can be obtained. Let represent the th row of the Q matrix, then it satisfies .
[0072] Step two is as follows:
[0073] After step one is completed, the first stage, i.e., the basic oblivious transfer, has been completed. Through the information exchange in the previous steps, it can be obtained that: the receiver has a matrix , and the sender has the matrix , the matrix and the matrix have the relationship of . Subsequently, for , where m represents the number of rows of the matrix , the receiver performs the following operations: If ( means the value of the j-th bit of the string r, and the F function is to convert from decimal to binary, and the subscript k refers to the k-th bit of the binary string), then the receiver uses the encryption key to calculate and sends it to the sender; if , then the receiver generates a random string and uses it as 's value and sends it to the sender. represents the oblivious transfer receiver's selection bitmask.
[0074] Step three is specifically as follows:
[0075] After step two is completed, all the preliminary preparations have been completed. Next, only the sender needs to encrypt the original data and then send it to the receiver for decryption. For , where m represents the number of rows of the matrix , the sender's input is a set of information , where each message has a length of bits, represents the -th data sent in the -th oblivious transfer. The sender encrypts the data according to the following formula and sends it to the receiver:
[0076] ;
[0077] where, represents the plaintext message transmitted by the sender in each OT instance (oblivious transfer instance), j represents this is the j-th OT instance, and k represents this is the k-th message transmitted in this OT instance. represents the ciphertext received by the receiver, and the meanings of j and k are the same as above.
[0078] Step four is specifically as follows:
[0079] For the ciphertext sent by the sender, a part of the messages can be directly decrypted by the receiver because the receiver has the necessary key for the decryption operation; while for another part of the messages, they are indistinguishable from random numbers to the receiver, so the receiver cannot decrypt to obtain the original data. And specifically which messages can be decrypted and which cannot are indicated in the receiver's input as follows: The receiver first constructs a binary string, where 0 represents the information that does not need to be obtained, 1 represents the information that needs to be obtained, and converts this string into a decimal number, and assigns this number to That's it. In the specific implementation, for , the receiver decrypts the desired messages from ciphertexts according to the following formula:
[0080] ;
[0081] wherein, the meaning of means that after the receiver receives the ciphertext , decrypts it to obtain the decrypted message, and the meanings of j and k are the same as above.
[0082] After all the above steps are completed, next, the effectiveness of the present invention is demonstrated, that is, the receiver can finally decrypt the data it wants, as proved by the following formula:
[0083] ;
[0084] wherein, appears in step 1.2 and is a previously generated matrix.
[0085] It can be seen from the above formula that the receiver can finally use as the key to decrypt ciphertexts, and the positions of these ciphertexts are all marked in .
[0086] As can be seen from the above, the oblivious transfer extension method proposed by the present invention only needs to be executed once to achieve the effect of the existing protocol executed selected times. As shown in
[0087] Figure 6 , this embodiment discloses an encryption and decryption system based on oblivious transfer extension for executing the above method, which includes the following modules:
[0088] Oblivious transfer module: used to execute the oblivious transfer between the sender and the receiver;
[0089] Selective bitmask sending module: used to execute the receiver to send the oblivious transfer selective bitmask to the sender;
[0090] Encryption module: used to execute the sender to encrypt the original data and then send it to the receiver;
[0091] Decryption module: used to execute the receiver to decrypt the ciphertext sent by the sender.
[0092] For other contents of this embodiment, reference may be made to the above method embodiment.
[0093] The present invention also discloses an electronic device, which includes:
[0094] Processor;
[0095] Memory, used to store a program, when the program is called and executed by the processor, the processor executes the above method or system.
[0096] The potential application scenario of the present invention in the recommendation system is particularly significant. For example, an institution wants to investigate the association between a certain lung disease and the patient's lung disease history. The institution needs to interact with the hospital to obtain the dataset of the patient's disease history. However, in order to protect the user's privacy, the hospital only wants to give the disease history related to the lung disease and does not want to expose other disease history data of the patient. Applied to this protocol, the hospital is the sender and the institution is the receiver, and the above functions and requirements can be completed.
[0097] In step one, the hospital party prepares the dataset to be transmitted and classifies it according to the disease type; the institution searches for the numbers where the lung-related disease history is located according to the classification and sets the selection bits. (The same patient may have multiple lung disease histories, that is, there are multiple numbers to be selected. Arrange the patient's disease history in order of numbers, set the disease history related to the lung disease to 1, and the disease history not related to the lung disease to 0. In this way, a string of binary numbers can be obtained, and then the binary numbers can be compressed to obtain a decimal selection bit). Then the hospital party and the institution party perform the remaining part of step one and step two, and the purpose of these two steps is to negotiate the encryption and decryption keys. In step three, the hospital party uses the negotiated key to encrypt all the disease histories of the patient and sends the ciphertext to the institution; in step four, the institution decrypts the ciphertext with the negotiated key, and it can only decrypt the disease history related to the lung disease and cannot decrypt the disease history of other diseases (the reason is that when setting the selection bits before, only the numbers of the disease history related to the lung disease are specified, and the encryption and decryption keys are related to the selection bits, so only the disease history of the lung disease can be decrypted here, and nothing is known about other information), at the same time, the hospital party also does not know which data the institution has obtained (because the hospital party only classifies and numbers the disease history and does not know which data the other party wants).
[0098] The proposed protocol of the present invention has been tested on a real machine and its performance has been compared with that of the previous protocol. The evaluation criterion for performance is set as the number of messages obtained by the receiver per millisecond. In the oblivious transfer extension protocol, the receiver is a relatively important party, and the speed at which it obtains data is also very important. In the KK protocol proposed in the prior art, the time required for the receiver to obtain 800,000 data is 363.5 milliseconds, which is approximately 2,200 messages per millisecond; in the KKRT protocol proposed in the prior art, the time required for the receiver to obtain 800,000 data is 404.5 milliseconds, which is approximately 1,978 messages per millisecond; while in the protocol of the present invention, the time required for the receiver to obtain 800,000 data is 89.3 milliseconds, which is approximately 8,958 messages per millisecond. It can be seen that the protocol of the present invention has a 4-5 times performance improvement compared with the previous protocols and can be well applied in actual life and production.
[0099] In addition, the present invention can also be extended to other large-scale data interaction scenarios that require privacy protection. For example, in a distributed database query, a user can select multiple interesting data items from the database at one time, and the database itself cannot know the specific selection of the user. In privacy-preserving machine learning, a user can efficiently obtain multiple model parameters or prediction results, and the model provider cannot track the user's query preferences. This efficient multi-message transmission ability enables the present invention not only to meet the current privacy computing requirements but also to provide new ideas for the oblivious transfer technology in future complex application scenarios.
[0100] The preferred embodiments and principles of the present invention have been described in detail above. For those of ordinary skill in the art, according to the idea provided by the present invention, there will be changes in the specific implementation manners, and these changes should also be regarded as the protection scope of the present invention.
Claims
1. The encryption and decryption method based on oblivious transfer extension is characterized by: The steps include: Step 1: The sender and receiver perform an oblivious transfer; Step 2: The receiver sends the obliviously transmitted selection bit mask to the sender; Step 3: The sender encrypts the original data and then sends it to the receiver; Step 4: The receiver decrypts the ciphertext sent by the sender; In step 1, the sender randomly selects a string s consisting of 0s and 1s with a length of k; s i Represents the i-th bit of string s; The input of the receiver includes: the first part is m selected numbers r = (r1, r2, ..., r m ), where 0≤r≤2 n -1; r i represents the receiver's selection bit in the i-th oblivious transmission, and n represents that in each OT instance, the sender transmits n messages to the receiver; the second part is a collision-resistant homomorphic encryption algorithm E(·), which has an encryption public key pk and a decryption private key sk; The common input is a decimal-to-binary function F and a collision-resistant hash function H(·); where F i (a) represents the i-th digit of the binary form of the decimal number a; In step 1, the receiver generates matrices T0 and T1 of size m×k as follows: Randomly generate t j,0 And by calculating To determine t j,1 The value of j,0 ,t j,1 Represents the j-th row value of T0 and T1 respectively; r j Represents the value of the jth bit of string r; the F function converts r j The value of is converted from decimal to binary; The receiver acts as the sender and sends two messages, T0 and T1. After sending the messages, the sender selects one message to receive based on the string s generated in step 1, so as to achieve 2-choose-1 oblivious transmission; In step 1, the sender and the receiver perform t times of 2-choose-1 oblivious transmission according to the following steps, where t represents the number of columns of matrices T0 and T1: Step 1.1: The receiver sends two messages in, Represent the i-th column of matrices T0 and T1 respectively; Step 1.2: The sender selects bit s i To select one of the messages in step 1.1 to receive, if s i = 0, then receive If s i =1, then receive After completing the above steps, the sender obtains t strings, and merges these t strings by column to obtain a matrix Q; let q j represents the jth row of the Q matrix, then Step 2 is as follows: For j∈[m], where m represents the number of rows in the matrix Q, the receiver performs the following operations: If F k (r j )=1, the receiver uses the encryption key pk to calculate V k =E(F(r j -2 k )) and V k Sent to the sender; if F k (r j )=0, the receiver generates a random string as V k The value of V is sent to the sender; k Indicates the optional bit mask of the oblivious transmission recipient, used for subsequent encryption x j,k ; F k (r j ) indicates that the F function converts r j The value of is converted from decimal to binary; Step 3 is as follows: For j∈[m], the sender’s input is a set of information (x j,1 ,x j,2 ,……,x j,n ), where each message x is l bits long, x j,i represents the i-th data sent in the j-th oblivious transmission; the sender encrypts n data according to the following formula and sends it to the receiver: Among them, x j,k represents the plaintext message transmitted by the sender in each OT instance, j represents the jth OT instance, and k represents the kth message transmitted in this OT instance; y j,k Indicates the ciphertext received by the receiver; Step 4 is as follows: for the ciphertext sent by the sender, the receiver decrypts part of the message using the key; for the other part of the message: the receiver first constructs a binary string, where 0 represents information that does not need to be obtained and 1 represents information that needs to be obtained, and converts the binary string into a decimal number, and assigns the number to r j ; For j∈[m], the receiver decrypts the desired k messages from n ciphertexts according to the following formula: z j,k Indicates that the receiver receives the ciphertext y j,k After that, decryption is performed to obtain the decrypted message.
2. An encryption and decryption system based on oblivious transfer extension, used to execute the method as claimed in claim 1, characterized in that: Includes the following modules: Oblivious transfer module: used to perform oblivious transfer between sender and receiver; Selection bit mask sending module: used to execute the receiver to send the inadvertent transmission selection bit mask to the sender; Encryption module: used for the sender to encrypt the original data and then send it to the receiver; Decryption module: used to execute the receiver to decrypt the ciphertext sent by the sender.
3. An electronic device, characterized in that: include: processor; The memory is used to store a program, and when the program is called and executed by the processor, the processor executes the method as claimed in claim 1.
Citation Information
Patent Citations
Casual data security sharing method in distributed system
CN116566605A
Method and system for confidential string-matching and deep packet inspection
US20210336770A1