Privacy intersection method based on block chain and related device
By storing the real Merkel root of the second data set on the blockchain and transmitting the hash set off the chain, the problem of data tampering in traditional privacy interception technology is solved, data integrity verification and privacy protection are achieved, and the accuracy and security of the calculation results are improved.
Patent Information
- Application Number
- CN202510058749.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-14
AI Technical Summary
Traditional privacy interception technology is easily tampered by third parties during data transmission, resulting in incorrect calculation results and it is impossible to ensure that the intersection data is correctly obtained.
Using a blockchain-based privacy request method, by storing the real Merkel root of the second data set on the Ethereum blockchain and transmitting the second hash set off the chain, the client can verify data integrity through the blockchain to ensure the accuracy of the calculation results.
Through the immutability and transparency of blockchain, data integrity and privacy protection are ensured, the security and reliability of privacy interception technology are improved, and the correct interception data is obtained.
Smart Images

Figure CN119995823A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of privacy-enforcing technology, and in particular to a privacy-enforcing method and related devices based on blockchain. Background Art
[0002] In today's big data and information society, data sharing and interaction have become crucial. In many scenarios (such as medical, financial, e-commerce, etc.), different data holders need to calculate intersection data under the premise of ensuring privacy to obtain common business needs. The implementation of this process requires the use of Private Set Intersection (PSI) technology. Private Set Intersection technology is a cryptographic technology that allows two parties to find intersection data without exposing their complete data. That is, the data sets held by both parties can only know the public data without leaking the non-intersection part, which is used to realize intersection calculation while protecting data privacy.
[0003] The process of traditional privacy intersection technology is as follows: the client initiates a privacy intersection request, calculates the first hash set of the first data set provided by the client, and after receiving the privacy intersection request, the server calculates the second hash set of the second data set provided by the server, and sends the second hash set to the client, and the client then calculates the intersection of the first hash set and the second hash set to complete the privacy intersection process. However, traditional privacy intersection technology faces the following challenges in practical applications: the second hash set is likely to be tampered with by a third party during transmission, resulting in the final calculated intersection of the first hash set and the second hash set being incorrect, and the intersection data cannot be guaranteed to be correctly obtained. Summary of the invention
[0004] The purpose of this application is to provide a privacy intersection method and related devices based on blockchain, which can verify the data integrity of the second data set to ensure that the intersection data is correctly obtained.
[0005] To achieve the above objectives, this application provides the following solutions:
[0006] In a first aspect, the present application provides a privacy-enforcing system based on blockchain, the privacy-enforcing system based on blockchain comprising: a client and a server, both of which are nodes of the Ethereum blockchain;
[0007] The client is used to initiate a privacy intersection task, perform hash calculation on the first data set to obtain a first hash set, record a mapping relationship between the hash value in the first hash set and the data in the first data set to obtain a mapping set, and send the first Ethereum address of the client to the server;
[0008] The server is connected to the client for communication; upon receiving the privacy intersection task, the server performs hash calculation on the second data set to obtain a second hash set, calculates the real Merkle root of the second hash set, uploads the first Ethereum address, the real Merkle root and the task number to the Ethereum blockchain, and sends the second hash set, the second Ethereum address of the server and the task number to the client; the task number is a unique identifier for the privacy intersection task;
[0009] The client is used to query the Ethereum blockchain based on the second Ethereum address and the task number, obtain the real Merkle root, calculate the calculated Merkle root of the second hash set, and if the calculated Merkle root is the same as the real Merkle root, calculate the intersection of the first hash set and the second hash set, convert the hash value in the intersection into data based on the mapping set, and obtain the privacy intersection result.
[0010] Optionally, the client includes a first data processing module, a first data transmission module, a first blockchain interaction module and a hash verification intersection module;
[0011] The first data processing module is used to perform hash calculation on the first data set using the XXH64 hash function to obtain a first hash set, record the mapping relationship between the hash value in the first hash set and the data in the first data set to obtain a mapping set, and send the first hash set and the mapping set to the hash verification intersection module;
[0012] The first data transmission module is used to send the first Ethereum address of the client to the server;
[0013] The first blockchain interaction module is used to call the smart contract to query in the Ethereum blockchain based on the second Ethereum address and the task number, obtain the real Merkle root, and send the real Merkle root to the hash verification intersection module;
[0014] The hash verification intersection module is used to calculate the calculated Merkle root of the second hash set. If the calculated Merkle root is the same as the real Merkle root, the intersection of the first hash set and the second hash set is calculated, and the hash value in the intersection is converted into data based on the mapping set to obtain a privacy intersection result.
[0015] Optionally, the server includes a second data processing module, a second data transmission module and a second blockchain interaction module;
[0016] The second data processing module is used to perform hash calculation on the second data set using the XXH64 hash function to obtain a second hash set, calculate the true Merkle root of the second hash set, send the second hash set to the second data transmission module, and send the true Merkle root to the second blockchain interaction module;
[0017] The second data transmission module is used to send the second hash set, the second Ethereum address of the server and the task number to the client;
[0018] The second blockchain interaction module is used to call the smart contract and upload the first Ethereum address, the real Merkle root and the task number to the Ethereum blockchain.
[0019] In a second aspect, the present application provides a privacy intersection method based on blockchain, which is applied to any of the privacy intersection systems based on blockchain described above, and the privacy intersection method based on blockchain includes:
[0020] Initiate a privacy intersection task, perform hash calculation on the first data set to obtain a first hash set, record the mapping relationship between the hash value in the first hash set and the data in the first data set to obtain a mapping set, and send the first Ethereum address of the client to the server;
[0021] Receive the second hash set, the second Ethereum address and the task number returned by the server; when receiving the privacy intersection task, the server performs hash calculation on the second data set to obtain the second hash set, calculates the real Merkle root of the second hash set, uploads the first Ethereum address, the real Merkle root and the task number to the Ethereum blockchain, and sends the second hash set, the second Ethereum address and the task number to the client; the task number is the unique identifier of the privacy intersection task;
[0022] Based on the second Ethereum address and the task number, a query is performed in the Ethereum blockchain to obtain the real Merkle root, and the calculated Merkle root of the second hash set is calculated. If the calculated Merkle root is the same as the real Merkle root, the intersection of the first hash set and the second hash set is calculated, and the hash value in the intersection is converted into data based on the mapping set to obtain the privacy intersection result.
[0023] Optionally, performing a hash calculation on the first data set to obtain a first hash set specifically includes: performing a hash calculation on the first data set using an XXH64 hash function to obtain a first hash set.
[0024] Optionally, the first data set and the second data set are both a column of data, or the first data set and the second data set are both a row of data.
[0025] Optionally, after obtaining the privacy intersection result, if the server denies the existence of the target data in the second data set, the blockchain-based privacy intersection method also includes: calculating the target hash value corresponding to the target data, and determining the Merkel proof path corresponding to the target data based on the target hash value and the second hash set, and uploading the target hash value, Merkel proof path, task number and second Ethereum address to the Ethereum blockchain; the Ethereum blockchain is used to calculate the target Merkel root based on the target hash value and the Merkel proof path. If the target Merkel root is the same as the real Merkel root, the target data belongs to the second data set.
[0026] In a third aspect, the present application provides a computer device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the above-mentioned blockchain-based privacy intersection methods.
[0027] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-mentioned blockchain-based privacy intersection methods.
[0028] In a fifth aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, implements any of the above-mentioned blockchain-based privacy intersection methods.
[0029] According to the specific embodiments provided in this application, this application has the following technical effects:
[0030] The present application provides a privacy intersection method based on blockchain and a related device, including: a client and a server, both of which are nodes of the Ethereum blockchain, the client initiating a privacy intersection task, performing hash calculation on a first data set to obtain a first hash set, recording a mapping relationship between a hash value in the first hash set and data in the first data set to obtain a mapping set, and sending the client's first Ethereum address to the server. When the server receives the privacy intersection task, it performs hash calculation on a second data set to obtain a second hash set, calculates a real Merkle root of the second hash set, uploads the first Ethereum address, the real Merkle root and the task number to the Ethereum blockchain, and sends the second hash set, the second Ethereum address of the server and the task number to the client. The client queries the Ethereum blockchain based on the second Ethereum address and the task number to obtain the real Merkle root, calculates the calculated Merkle root of the second hash set, and if the calculated Merkle root is the same as the real Merkle root, calculates the intersection of the first hash set and the second hash set, converts the hash value in the intersection into data based on the mapping set, and obtains a privacy intersection result. This application introduces blockchain technology, stores the true Merkle root of the second hash set on the Ethereum blockchain, and sends the second hash set to the client off-chain. The client can query the true Merkle root from the Ethereum blockchain, and verify the data integrity of the second hash set through the true Merkle root. When the second hash set is correct, the intersection of the first hash set and the second hash set is calculated to ensure that the intersection data is obtained correctly, thereby improving the security and reliability of the privacy intersection technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0032] Figure 1 A schematic diagram of a framework of a privacy-enabling system based on blockchain provided in Example 1 of the present application.
[0033] Figure 2 A flowchart of a privacy intersection method based on blockchain provided in Example 2 of the present application.
[0034] Figure 3 A schematic diagram of the structure of a computer device provided in Example 3 of the present application. DETAILED DESCRIPTION
[0035] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0036] Example 1
[0037] This embodiment provides a privacy-enforcing system based on blockchain, and the privacy-enforcing system based on blockchain includes: a client and a server, and both the client and the server are nodes of the Ethereum blockchain.
[0038] The client is used to initiate a privacy intersection task, perform hash calculation on the first data set to obtain a first hash set, record the mapping relationship between the hash value in the first hash set and the data in the first data set, obtain a mapping set, and send the client's first Ethereum address to the server.
[0039] The server is connected to the client for communication. When receiving a privacy intersection task, the server performs hash calculation on the second data set to obtain a second hash set, calculates the true Merkle root of the second hash set, uploads the first Ethereum address, the true Merkle root and the task number to the Ethereum blockchain, and sends the second hash set, the second Ethereum address of the server and the task number to the client; the task number is a unique identifier for the privacy intersection task.
[0040] The client is used to query the Ethereum blockchain based on the second Ethereum address and the task number, obtain the real Merkle root, calculate the calculated Merkle root of the second hash set, and if the calculated Merkle root is the same as the real Merkle root, calculate the intersection of the first hash set and the second hash set, convert the hash value in the intersection into data based on the mapping set, and obtain the privacy intersection result.
[0041] The privacy intersection system of this embodiment is a privacy intersection system that uses blockchain technology to achieve identity authentication and data integrity verification, and is intended to protect a privacy intersection system based on the Ethereum blockchain. Specifically, the Ethereum blockchain is introduced in the privacy intersection process. In the process of performing a privacy intersection, the main roles are the client composed of mobile terminals and the server composed of server devices. Both the client and the server are nodes of the Ethereum blockchain, which can upload and query specified data to the Ethereum blockchain. The transparency and immutability of the Ethereum blockchain are used to ensure the security of privacy data and the credibility of the calculation process. The specific method includes the participants uploading the hashed data to the Ethereum blockchain, and then performing the privacy intersection calculation off-chain. During the privacy intersection calculation process, the authenticity and validity of the calculation are verified through the data stored on the Ethereum blockchain. This method solves the data tampering problem in the existing privacy intersection technology and improves the security of privacy protection.
[0042] like Figure 1 As shown, the privacy request process of this embodiment is described as follows:
[0043] (1) The client initiates a task.
[0044] The client initiates a privacy intersection task. After the privacy intersection task is initiated, the client performs a hash calculation on the specified first data set on the local device through the XXH64 hash function to generate the corresponding first hash set H client Specifically, hash calculation is performed on each data in the first data set to obtain the hash value corresponding to each data. All hash values constitute the first hash set H client , and generate the first hash set H client In the process, the data in the first data set and the first hash set H are recorded in real time. client The corresponding relationship between the hash values in the first hash set H client The mapping relationship between the hash value in the first data set and the data in the first data set is used to generate a mapping set MAP for mapping the hash value to the original data. client , used for subsequent intersection operations.
[0045] It should be noted that a hash function is a mathematical algorithm that converts data input of any length into an output of a fixed length (called a hash value or digest). It is irreversible and is commonly used for data integrity verification and fast search. The hash function used in this embodiment is XXHash, specifically the XXH64 hash function. XXHash is an extremely fast non-encrypted hash algorithm designed for high-speed processing of large amounts of data. It is typically used to check data integrity and file comparison. It has the characteristics of fast speed, low latency, and low collision rate, and is suitable for high-performance application scenarios.
[0046] At the same time, the client will send its first Ethereum address Add to the server. client , send the first Ethereum address Add client The purpose is to facilitate the subsequent use of the Ethereum blockchain (also known as the Ethereum blockchain network) to accurately find the content required for this privacy intersection task by combining the information provided by the client and the server, that is, to find the real Merkle root E generated based on the second hash set on the server. server .
[0047] It should be noted that the Ethereum blockchain is a decentralized blockchain platform that supports smart contracts. Users can develop and run applications on it without the need for a third party. The Ethereum address is the user's unique identifier on the Ethereum blockchain. It is generated by the account's public key and usually starts with "0x" followed by 40 hexadecimal characters. It is used to receive and send Ether or interact with smart contracts. A smart contract is a self-executing program running on the blockchain that automatically executes transactions or operations according to pre-set rules without the need for third-party intervention, and the execution results are open and transparent.
[0048] (2) The server performs data preprocessing.
[0049] The server performs hash calculation on the specified second data set that needs to be privacy-intersected with the first data set through the XXH64 hash function on the local device to obtain the second hash set H server , perform hash calculation on each data in the second data set to obtain the hash value of each data, and all hash values constitute the second hash set H server At the same time, the server will construct a second hash set H during the hash calculation process. server The corresponding Merkle Tree is a data structure that compresses a large amount of data into a unique root hash value through layer-by-layer hash calculation. It divides the data into blocks and performs hash calculation on each block, and then recursively combines adjacent hash values and calculates a new hash value until a unique root hash value (i.e., the Merkle Root) is generated. This data structure can effectively verify the integrity and consistency of any data block without checking the entire data set. Therefore, the Merkle Tree is used to verify data integrity. Merkle trees constructed from different hash sets have unique Merkle roots, so the Merkle root can be used to verify whether the data content has been tampered with.
[0050] The second hash set H constructed after the hash calculation is completed server The corresponding Merkle tree's true Merkle root R server It will wait to be uploaded to the Ethereum blockchain together with other data fields for subsequent clients to verify data integrity.
[0051] (3) The server sends verification information to the Ethereum blockchain.
[0052] The server will add the first Ethereum address received from the client client 、True Merkle root R server And according to the addresses of both ends (that is, the first Ethereum address of the client Add client And the second Ethereum address of the server Add server ) and other information to generate a unique task number M and upload it to the Ethereum blockchain. The task number M can be set according to the needs, as long as one privacy-seeking task corresponds to one task number M. For example, the first Ethereum address Add client 、Add the second Ethereum address of the server server and upload time as the task number M. The real Merkle root R server After being uploaded to the Ethereum blockchain, it cannot be tampered with. It can record the privacy-seeking tasks that have occurred in the past, which can be used as a reference for subsequent privacy-seeking tasks, and the real Merkle root R server After being recorded in the Ethereum blockchain, it cannot be tampered with and can be used to verify the second hash set H transmitted at any time in the future. server The integrity of the content.
[0053] (4) The server sends the required content to the client.
[0054] The server will send the second hash set H server 、Add the second Ethereum address of the server server And the task number M is transmitted to the client. These data can help the client obtain the real Merkle root R server , to perform verification work and execute subsequent intersection operations.
[0055] Since data transmission on the Ethereum blockchain is costly and slow, it is not suitable for transmitting large amounts of data. server The amount of data is often very large, and the on-chain transmission method will incur huge costs in terms of money and time. Therefore, when transmitting this part of the content, the server will establish a network channel with the client off-chain through protocols such as HTTP (HyperText Transfer Protocol) to carry out fast and large-scale data transmission.
[0056] (5) The client queries the real Merkle root and verifies it.
[0057] After obtaining the second Ethereum address of the server in this privacy intersection task, Add serverand task number M, the client can use these parameters to call the smart contract on the Ethereum blockchain, quickly verify the identity, and obtain the real Merkle root R corresponding to this privacy intersection task server .
[0058] The client has obtained the second hash set H through off-chain methods. server , so it can be possible to use the second hash set H in the local device server Construct a Merkle tree and get a computational Merkle root R' server , if there is R′ server =R server , then the second hash set H obtained through off-chain transmission server The data integrity is reliable and subsequent intersection operations can be performed.
[0059] (6) The client seeks intersection and obtains intersection data.
[0060] The client finds the first hash set H client With the second hash set H server The consistent hash entries (i.e., hash values) in the two ends correspond to the hash values of the same data (also called elements) in the data sets (i.e., the first data set and the second data set) specified by both ends, through the mapping set MAP client The consistent hash entries can be mapped back to the corresponding original data. The client will record this data as the privacy intersection result, which will be output as a file to the local path specified by the client. During this process, the server cannot obtain the intersection content, and the client cannot obtain other data in the server except the same data, thus protecting data privacy security to the greatest extent.
[0061] In this embodiment, the client is the initiator of the privacy intersection task, and implements identity authentication on the Ethereum blockchain through a smart contract, obtains the real Merkle root uploaded by the server, and implements data integrity verification and intersection operations on the local device. The server is the provider of privacy intersection data, and sends the real Merkle root for verifying data integrity to the Ethereum blockchain through a smart contract. The two parties can convert each other in different privacy intersection tasks, and the final privacy intersection result will be output to the client's local device.
[0062] The following, combined Figure 1 Introduce each module in the client and server:
[0063] (1) Client
[0064] (1) The first data processing module.
[0065] Input a column of data in the specified data set as the first data set. The first data processing module will generate a corresponding hash value for each data in the first data set through the XXH64 hash function in turn to obtain the first hash set, and store the mapping from the hash value to the original data to obtain a mapping set, so as to quickly restore the intersecting original data content after intersection.
[0066] (2) The first blockchain interaction module.
[0067] The first blockchain interaction module uses the received second Ethereum address of the server and the task number as parameters to call the smart contract to obtain the real Merkle root uploaded by the server to the Ethereum blockchain to verify the data integrity. When the server denies that the second data set provided contains a certain target data, the first blockchain interaction module can also actively specify the target hash value and the corresponding Merkle proof path of a certain target data through the client to verify whether the Merkle proof path is legal, so as to determine whether the certain target data exists in the second data set provided by the server. The steps are as follows:
[0068] 1) After completing the privacy intersection, the client first calculates the target hash value H(D) of the target data denied by the server. Then, the client uses the complete second hash set provided by the server to generate the Merkle proof path layer by layer according to the construction rules of the Merkle tree. The generation process is as follows: First, locate the position of the target hash value H(D) of the target data in the second hash set and use it as the starting point of the leaf node; then, determine the hash value of its brother node at each layer and record them in turn, thereby forming a Merkle proof path P=[H sibling1 , H sibling2 , …, H siblingN ], H sibling1 Its sibling node at the first level, H sibling2 Its sibling node at the second level, H siblingN is its sibling node at the Nth layer. The first layer is the layer where the target hash value of the target data is located. The second layer is the layer below the first layer in the direction from the first layer to the root node. The Nth layer is the layer above the root node. For example, for the target hash value H(D) of the target data, at the first layer, the hash value H of its sibling node (the node that belongs to the same parent node and is located at the same layer) is sibling1 Add to the path, at level 2, the hash value H of the sibling node of its parent node sibling2 is added to the path, and so on, until the root node.
[0069] 2) After obtaining the complete Merkle proof path, the client combines the target hash value H(D) of the target data with the Merkle proof path P to construct a Merkle Proof, which is submitted to the Ethereum blockchain for verification.
[0070] 3) The client takes the target hash value H(D) of the target data and the calculated Merkle proof path P as parameters, and uploads these parameters, the task number and the second Ethereum address of the server to the Ethereum blockchain by calling the smart contract on the Ethereum blockchain.
[0071] 4) After the smart contract receives the target hash value H(D), Merkle proof path P, task number and second Ethereum address of the target data uploaded by the client, it starts from the target hash value H(D) of the target data and recursively calculates the hash value H of the parent node based on the Merkle proof path P layer by layer according to the construction rules of the Merkle tree. parent =H(H current ||H sibling ) or H parent =H(H sibling ||H current ), H current is the hash value of the current node (i.e. the node corresponding to the target hash value of the target data and its parent node), H sibling is the hash value of the brother node until the root hash value (i.e. the target Merkle root) H is finally calculated. calculated .
[0072] 5) The smart contract obtains the real Merkle root R corresponding to the task number and the second Ethereum address from the Ethereum blockchain server , the calculated target Merkle root H calculated The real Merkle root R stored on the Ethereum blockchain server A comparison is performed. If the two are the same, it means that the target data exists in the second data set; if the two are different, it means that the target data does not exist in the second data set.
[0073] 6) Finally, the smart contract returns the verification status information to the client based on the verification results, and records the verification process and results in the Ethereum blockchain, ensuring that the entire process is open, transparent and cannot be tampered with, providing the client with a reliable verification basis.
[0074] (3) The first data transmission module.
[0075] The first data transmission module is responsible for transmitting the first Ethereum address of the client to the server off-chain. The first Ethereum address will be used by the client to subsequently implement identity authentication and obtain the real Merkle root on the Ethereum blockchain.
[0076] (4) Hash verification intersection module.
[0077] The hash verification intersection module calculates the calculated Merkle root of the second hash set. If the calculated Merkle root is the same as the real Merkle root, the intersection of the first hash set and the second hash set is calculated, and the hash value in the intersection is converted into data based on the mapping set to obtain a privacy intersection result.
[0078] (2) Server side.
[0079] (1) The second data processing module.
[0080] Input a column of data in the specified data set as the second data set. The second data processing module will generate the corresponding hash value for each data in the second data set through the XXH64 hash function in turn to obtain the second hash set. A Merkle tree is constructed for the hash values in the generated second hash set to generate a real Merkle root. The second hash set will be transmitted to the client through the second data transmission module, and the real Merkle root will be uploaded to the Ethereum blockchain through the second blockchain interaction module.
[0081] The formula for calculating the Merkle root can be expressed as:
[0082] Merkle Root=H(…H(H(D1)||H(D2))||H(H(D3)||H(D4))…||H(H(DN-1)||H(DN))…);
[0083] The above formula can be broken down into the following steps:
[0084] 1) Leaf node hashing: Hash calculation is performed on each data block to generate the hash value of the leaf node, for example, H(D1), H(D2), ..., where H represents the hash function, such as XXH64.
[0085] 2) Recursively calculate the parent node: Combine the hash values of two adjacent leaf nodes and perform hash calculation to generate the hash value of the parent node. For example, the first leaf node and the second leaf node are combined to generate the first parent node H(H(D1)||H(D2)), where || represents the concatenation operation.
[0086] 3) Continue recursively until the root node: Repeatedly combine the hash values of adjacent nodes and perform hash calculations until only one hash value of the root node remains. This value is the true Merkle root.
[0087] (2) The second blockchain interaction module.
[0088] The second blockchain interaction module is responsible for sending the real Merkle root generated by the second data processing module, the first Ethereum address sent by the client, and the unique task number generated according to the addresses of both parties and other parameters to the Ethereum blockchain by calling the smart contract, waiting for the client to interact with the Ethereum blockchain to obtain the real Merkle root, or verify whether a certain target data exists in the second data set.
[0089] (3) The second data transmission module.
[0090] The second data transmission module establishes a data transmission channel through the HTTP protocol, and quickly transmits the second Ethereum address, task number and second hash set of the server to the client off-chain.
[0091] At this time, in this embodiment, the client includes a first data processing module, a first data transmission module, a first blockchain interaction module and a hash verification intersection module.
[0092] The first data processing module is used to perform hash calculation on the first data set using the XXH64 hash function to obtain a first hash set, record the mapping relationship between the hash value in the first hash set and the data in the first data set, obtain a mapping set, and send the first hash set and the mapping set to the hash verification intersection module.
[0093] The first data transmission module is used to send the first Ethereum address of the client to the server.
[0094] The first blockchain interaction module is used to call the smart contract to query in the Ethereum blockchain based on the second Ethereum address and the task number, obtain the real Merkle root, and send the real Merkle root to the hash verification intersection module.
[0095] The hash verification intersection module is used to calculate the calculated Merkle root of the second hash set. If the calculated Merkle root is the same as the real Merkle root, the intersection of the first hash set and the second hash set is calculated, and the hash value in the intersection is converted into data based on the mapping set to obtain a privacy intersection result.
[0096] The server includes a second data processing module, a second data transmission module and a second blockchain interaction module.
[0097] The second data processing module is used to perform hash calculation on the second data set using the XXH64 hash function to obtain a second hash set, calculate the true Merkle root of the second hash set, send the second hash set to the second data transmission module, and send the true Merkle root to the second blockchain interaction module.
[0098] The second data transmission module is used to send the second hash set, the second Ethereum address of the server and the task number to the client.
[0099] The second blockchain interaction module is used to call the smart contract and upload the first Ethereum address, the real Merkle root and the task number to the Ethereum blockchain.
[0100] Compared with the existing privacy intersection technology, this embodiment combines blockchain technology and off-chain data transmission solutions to significantly improve the security of privacy protection, the effectiveness of data integrity verification, and the efficiency of data transmission. The specific technical effects are as follows:
[0101] (1) Efficient data integrity verification.
[0102] This embodiment uses the immutability of the blockchain to record the true Merkle root of the second hash set of the server on the Ethereum blockchain. The true Merkle root is calculated layer by layer through the hash values in the second hash set and is closely related to each hash value in the second hash set. Therefore, it is only necessary to record the true Merkle root on the Ethereum blockchain to ensure the integrity and immutability of all hash values in the second hash set. The client can query the true Merkle root through the Ethereum blockchain and perform data integrity verification without storing the complete second hash set on the chain, thereby improving the convenience and credibility of evidence storage.
[0103] (2) Optimization of data privacy protection and interaction efficiency.
[0104] Traditional blockchain solutions have high costs and slow speeds in transmitting large-scale data. This embodiment stores minimized data (real Merkle root) on the chain and uses an off-chain communication protocol (such as HTTP) to transmit the second hash set, avoiding the high cost of large-scale data transmission on the chain. The client can directly verify the data integrity locally through off-chain data. This design significantly reduces the cost of data transmission and achieves secure and efficient data interaction through the combination of on-chain and off-chain.
[0105] (3) Flexible identity authentication and task tracking.
[0106] This embodiment designs a smart contract for identity authentication and data tracking. Each privacy intersection task generates a unique task number and identity information record on the blockchain. Flexible identity authentication is achieved through smart contract calls, allowing the client to quickly verify and trace historical privacy intersection tasks through the task number, thereby increasing the security and transparency of the system.
[0107] (4) Security of privacy-enhancing results.
[0108] The system only allows the client to obtain elements in the intersection, and other non-intersection parts cannot be leaked. By performing hash intersection operations on the data sets off-chain and using the mapping relationship (the client's hash value is mapped to the original data), the client can quickly restore the intersection data while ensuring the security of the server's data. The server cannot obtain the intersection content, thus ensuring the privacy of both parties' data.
[0109] In summary, this embodiment overcomes the problems of difficult data integrity verification, high data transmission cost, incomplete privacy protection, etc. in traditional privacy intersection technology by innovatively combining blockchain and privacy intersection technology, and provides an efficient, reliable and highly secure privacy intersection solution.
[0110] Traditional privacy intersection technology still has the problem of high computing and communication overhead. This is because traditional privacy intersection technology mainly relies on high-density cryptographic means, such as homomorphic encryption, secure multi-party computing (MPC), etc. These methods often generate high computing and communication burdens while protecting privacy, especially in big data processing environments, which limits the actual application effect of privacy intersection technology. To address this problem, this embodiment introduces the XXH64 hash function, which can improve computing efficiency and solve the problem of high computing overhead. The generated calculation results contain less data, solving the problem of high communication overhead.
[0111] Traditional privacy intersection technology also has the problem of difficult to monitor data tampering. This is because traditional privacy intersection technology is difficult to effectively prevent data tampering, especially in the scenario of multi-party collaborative computing. It is difficult to ensure that the data of the participating parties are authentic and complete. Once a participating party tamperes with the data, the intersection calculation result will be affected, and it is difficult to trace the source of the problem. To address this problem, in this embodiment, when the server denies that the second data set provided contains a certain target data, the client can actively specify the target hash value of a certain target data and the corresponding Merkel proof path to verify whether the Merkel proof path is legal, so as to determine whether the certain target data exists in the second data set provided by the server, thereby avoiding tampering of the second data set.
[0112] At present, there is no mature technology that can effectively combine blockchain with privacy intersection technology to achieve data integrity verification and privacy protection. Traditional privacy intersection technologies mostly rely on cryptographic methods, such as homomorphic encryption and multi-party secure computing. Although they guarantee data privacy to a certain extent, they cannot provide effective data tampering protection and reliable identity authentication methods. In addition, traditional privacy intersection technologies have high computing and communication costs when processing large-scale data. The privacy intersection solution combined with blockchain can provide an efficient and low-cost solution through on-chain evidence storage and off-chain data processing. Therefore, the privacy intersection system combined with blockchain technology is innovative and unique in the current technical context.
[0113] This embodiment proposes a privacy protection system combined with blockchain technology to achieve dual protection of data security and integrity. The immutability and openness and transparency of blockchain make it possible to effectively monitor the authenticity of data submission when sharing data. At the same time, the combination of blockchain and off-chain data transmission solutions not only achieves efficient computing and data transmission, but also reduces the high cost of on-chain storage and communication. The introduction of smart contracts not only enhances the flexibility of task tracking and identity authentication, but also improves the security and operability of the overall system.
[0114] Example 2
[0115] This embodiment provides a privacy-enforcing method based on blockchain, such as Figure 2 As shown, the privacy intersection method based on blockchain includes:
[0116] S1: Initiate a privacy intersection task, perform hash calculation on the first data set to obtain a first hash set, record the mapping relationship between the hash value in the first hash set and the data in the first data set, obtain a mapping set, and send the client's first Ethereum address to the server.
[0117] S2: Receive the second hash set, the second Ethereum address and the task number returned by the server; when receiving the privacy intersection task, the server performs hash calculation on the second data set to obtain the second hash set, calculates the true Merkle root of the second hash set, uploads the first Ethereum address, the true Merkle root and the task number to the Ethereum blockchain, and sends the second hash set, the second Ethereum address and the task number to the client; the task number is the unique identifier of the privacy intersection task.
[0118] S3: Based on the second Ethereum address and the task number, query the Ethereum blockchain to obtain the real Merkle root, calculate the calculated Merkle root of the second hash set, and if the calculated Merkle root is the same as the real Merkle root, calculate the intersection of the first hash set and the second hash set, and convert the hash value in the intersection into data based on the mapping set to obtain the privacy intersection result.
[0119] Among them, performing hash calculation on the first data set to obtain the first hash set specifically includes: performing hash calculation on the first data set using the XXH64 hash function to obtain the first hash set.
[0120] The first data set and the second data set are both a column of data, or the first data set and the second data set are both a row of data.
[0121] After obtaining the privacy intersection result, if the server denies the existence of the target data in the second data set, the blockchain-based privacy intersection method of this embodiment also includes: calculating the target hash value corresponding to the target data, and determining the Merkle proof path corresponding to the target data based on the target hash value and the second hash set, uploading the target hash value, the Merkle proof path, the task number and the second Ethereum address to the Ethereum blockchain, and the Ethereum blockchain is used to calculate the target Merkle root based on the target hash value and the Merkle proof path. If the target Merkle root is the same as the real Merkle root, the target data belongs to the second data set.
[0122] Example 3
[0123] In an exemplary embodiment, a computer device is provided. The computer device may be a server or a terminal. The internal structure diagram thereof may be as follows: Figure 3 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the privacy intersection method based on blockchain in Example 2 is implemented.
[0124] Those skilled in the art will understand that Figure 3 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0125] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the privacy intersection method based on blockchain in Example 2 is implemented.
[0126] Example 4
[0127] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, which, when executed by a processor, implements the blockchain-based privacy intersection method in Example 2.
[0128] Example 5
[0129] In an exemplary embodiment, a computer program product is provided, including a computer program, which, when executed by a processor, implements the blockchain-based privacy intersection method in Example 2.
[0130] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0131] The technical features of the above embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0132] This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for those skilled in the art, according to the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.
Claims
1. A privacy-enabling system based on blockchain, characterized in that: The blockchain-based privacy-seeking system includes: a client and a server, both of which are nodes of the Ethereum blockchain; The client is used to initiate a privacy intersection task, perform hash calculation on the first data set to obtain a first hash set, record a mapping relationship between the hash value in the first hash set and the data in the first data set to obtain a mapping set, and send the first Ethereum address of the client to the server; The server is connected to the client for communication; upon receiving the privacy intersection task, the server performs hash calculation on the second data set to obtain a second hash set, calculates the real Merkle root of the second hash set, uploads the first Ethereum address, the real Merkle root and the task number to the Ethereum blockchain, and sends the second hash set, the second Ethereum address of the server and the task number to the client; the task number is a unique identifier for the privacy intersection task; The client is used to query the Ethereum blockchain based on the second Ethereum address and the task number, obtain the real Merkle root, calculate the calculated Merkle root of the second hash set, and if the calculated Merkle root is the same as the real Merkle root, calculate the intersection of the first hash set and the second hash set, convert the hash value in the intersection into data based on the mapping set, and obtain the privacy intersection result.
2. The privacy-enhancing system based on blockchain according to claim 1, characterized in that: The client includes a first data processing module, a first data transmission module, a first blockchain interaction module and a hash verification intersection module; The first data processing module is used to perform hash calculation on the first data set using the XXH64 hash function to obtain a first hash set, record the mapping relationship between the hash value in the first hash set and the data in the first data set to obtain a mapping set, and send the first hash set and the mapping set to the hash verification intersection module; The first data transmission module is used to send the first Ethereum address of the client to the server; The first blockchain interaction module is used to call the smart contract to query in the Ethereum blockchain based on the second Ethereum address and the task number, obtain the real Merkle root, and send the real Merkle root to the hash verification intersection module; The hash verification intersection module is used to calculate the calculated Merkle root of the second hash set. If the calculated Merkle root is the same as the real Merkle root, the intersection of the first hash set and the second hash set is calculated, and the hash value in the intersection is converted into data based on the mapping set to obtain a privacy intersection result.
3. The privacy-enhancing system based on blockchain according to claim 1, characterized in that: The server includes a second data processing module, a second data transmission module and a second blockchain interaction module; The second data processing module is used to perform hash calculation on the second data set using the XXH64 hash function to obtain a second hash set, calculate the true Merkle root of the second hash set, send the second hash set to the second data transmission module, and send the true Merkle root to the second blockchain interaction module; The second data transmission module is used to send the second hash set, the second Ethereum address of the server and the task number to the client; The second blockchain interaction module is used to call the smart contract and upload the first Ethereum address, the real Merkle root and the task number to the Ethereum blockchain.
4. A privacy intersection method based on blockchain, applied to the privacy intersection system based on blockchain as described in any one of claims 1-3, characterized in that: The privacy intersection method based on blockchain includes: Initiate a privacy intersection task, perform hash calculation on the first data set to obtain a first hash set, record the mapping relationship between the hash value in the first hash set and the data in the first data set to obtain a mapping set, and send the first Ethereum address of the client to the server; Receive the second hash set, the second Ethereum address and the task number returned by the server; when receiving the privacy intersection task, the server performs hash calculation on the second data set to obtain the second hash set, calculates the real Merkle root of the second hash set, uploads the first Ethereum address, the real Merkle root and the task number to the Ethereum blockchain, and sends the second hash set, the second Ethereum address and the task number to the client; the task number is the unique identifier of the privacy intersection task; Based on the second Ethereum address and the task number, a query is performed in the Ethereum blockchain to obtain the real Merkle root, and the calculated Merkle root of the second hash set is calculated. If the calculated Merkle root is the same as the real Merkle root, the intersection of the first hash set and the second hash set is calculated, and the hash value in the intersection is converted into data based on the mapping set to obtain the privacy intersection result.
5. The privacy intersection method based on blockchain according to claim 4 is characterized in that: Performing hash calculation on the first data set to obtain a first hash set specifically includes: performing hash calculation on the first data set using the XXH64 hash function to obtain the first hash set.
6. The privacy intersection method based on blockchain according to claim 5 is characterized in that: The first data set and the second data set are both a column of data, or the first data set and the second data set are both a row of data.
7. The privacy intersection method based on blockchain according to claim 4 is characterized in that: After obtaining the privacy intersection result, if the server denies the existence of the target data in the second data set, the blockchain-based privacy intersection method also includes: calculating the target hash value corresponding to the target data, and determining the Merkel proof path corresponding to the target data based on the target hash value and the second hash set, and uploading the target hash value, Merkel proof path, task number and second Ethereum address to the Ethereum blockchain; the Ethereum blockchain is used to calculate the target Merkel root based on the target hash value and the Merkel proof path. If the target Merkel root is the same as the real Merkel root, the target data belongs to the second data set.
8. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the privacy intersection method based on blockchain as described in any one of claims 4-7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the privacy intersection method based on blockchain described in any one of claims 4 to 7 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the privacy intersection method based on blockchain described in any one of claims 4 to 7 is implemented.
Citation Information
Patent Citations
Private data intersection method and system based on block chain and casual transmission expansion
CN115883106A
Trusted privacy set intersection method and device based on block chain, and server
CN118074921A
Asset certification method and device
CN118396751A
Method and apparatus for obtaining privacy set intersection, device and storage medium
EP3826222A2