Efficient post-quantum privacy set intersection method and related device
By using the basic OT algorithm based on grids in the privacy interception algorithm for OT interaction, the existing algorithm is solved in the problem of insufficient security in the face of quantum attacks, and stronger security guarantees and higher quantum attack resistance are achieved.
Patent Information
- Application Number
- CN202510055823.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-14
AI Technical Summary
The existing privacy interception algorithm has insufficient security when facing quantum attacks and cannot effectively resist quantum computer attacks.
The basic OT algorithm based on grid is used for OT interaction, and the privacy interception judgment set is determined through multiple two-choice OT operations between the sender and the receiver, thereby achieving the target privacy interception result.
Through the basic OT algorithm based on grid, the security requirements of post-quantum are met, stronger security guarantees are provided, and the performance of privacy and interrogation resistance to quantum attacks is improved.
Smart Images

Figure CN119995852A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of privacy computing technology and computer technology, and specifically to an efficient post-quantum privacy set intersection method and related devices. Background Art
[0002] At present, privacy-seeking intersection algorithms are playing an increasingly important role in government affairs, finance, medical care and other fields, providing rich application channels for data assets.
[0003] With the continuous development of quantum computers, the security of current cryptographic algorithms based on classical mathematical problems (factorization, discrete logarithm) has been greatly challenged. The security of some efficient privacy intersection algorithms is based on such mathematical problems, which makes some existing privacy intersection algorithms unable to be directly migrated and used under quantum computers. Therefore, the problem of how to improve the performance of privacy intersection in resisting quantum attacks needs to be solved urgently. Summary of the invention
[0004] The embodiments of the present application provide an efficient post-quantum private set intersection method and related devices, which can improve the performance of private intersection in resisting quantum attacks.
[0005] In a first aspect, an embodiment of the present application provides an efficient post-quantum privacy set intersection method, which is applied to a two-party computing system, wherein the two-party computing system includes a sender and a receiver, the sender has a first data set, and the receiver has a second data set, and the method includes:
[0006] The sender selects an initial matrix and a pseudo-random function key, updates the initial matrix according to the column information of the first data set to obtain a first matrix, and sends the pseudo-random function key to the receiver; the sender serves as an OT sender;
[0007] Selecting an OT key by the receiver; the receiver serving as an OT receiver;
[0008] The sender and the receiver use a basic OT algorithm based on a grid to perform OT interaction, thereby obtaining a plurality of two-choice OTs;
[0009] Generate a random matrix by the sender, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-choose-one OTs to perform multiple two-choose-one OT operations;
[0010] The receiving party selects a bit string based on the OT key, determines an OT result matrix through the bit string, determines second local column information through column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiving party;
[0011] The receiving party determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0012] In a second aspect, an embodiment of the present application provides a two-party computing system, the two-party computing system comprising a sender and a receiver, the sender having a first data set, the receiver having a second data set, wherein:
[0013] The sender is used to select an initial matrix, select a pseudo-random function key, update the initial matrix according to the column information of the first data set to obtain a first matrix, and send the pseudo-random function key to the receiver; the sender serves as an OT sender;
[0014] The receiver is used to select an OT key; the receiver serves as an OT receiver;
[0015] The sender and the receiver are used to perform OT interaction by using a grid-based basic OT algorithm to obtain multiple two-choice OTs;
[0016] The sender is used to generate a random matrix, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-choose-one OTs to perform multiple two-choose-one OT operations;
[0017] The receiving party is configured to select a bit string based on the OT key, determine an OT result matrix through the bit string, determine second local column information through the column information of the second data set and the pseudo-random function key, determine a first privacy intersection judgment set according to the second local column information and the OT result matrix, and send the first privacy intersection judgment set to the receiving party;
[0018] The receiving party is used to determine first local column information through the column information of the first data set and the pseudo-random function key, determine a second privacy intersection judgment set according to the first local column information and the random matrix, and determine a target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0019] In a third aspect, an embodiment of the present application provides an electronic device, comprising a processor, a memory, a communication interface, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, and the program includes instructions for executing the steps in the first aspect of the embodiment of the present application.
[0020] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program for electronic data exchange, wherein the computer program enables a computer to execute part or all of the steps described in the first aspect of the embodiment of the present application.
[0021] In a fifth aspect, an embodiment of the present application provides a computer program product, wherein the computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute some or all of the steps described in the first aspect of the embodiment of the present application. The computer program product may be a software installation package.
[0022] The implementation of the embodiments of the present application has the following beneficial effects:
[0023] It can be seen that the efficient post-quantum privacy set intersection method and related devices described in the embodiments of the present application are applied to a two-party computing system, which includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, the sender selects an initial matrix, selects a pseudo-random function key, updates the initial matrix according to the column information of the first data set, obtains a first matrix, and sends the pseudo-random function key to the receiver; the sender acts as an OT sender; the receiver selects an OT key; the receiver acts as an OT receiver; the sender and the receiver use a lattice-based basic OT algorithm to perform OT interaction to obtain multiple two-choice OTs; the sender generates a random matrix, determines the second matrix according to the first matrix and the random matrix, and uses each column of the random matrix and the second matrix as each column of the multiple two-choice OTs. Input to perform multiple two-choice OT operations; the receiver selects a bit string based on the OT key, determines the OT result matrix through the bit string, determines the second local column information through the column information of the second data set and the pseudo-random function key, determines the first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver; the receiver determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set. Since the lattice-based basic OT algorithm is used for OT interaction, it can meet the post-quantum security requirements and provide stronger security guarantees, thereby improving the privacy intersection's resistance to quantum attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0025] Figure 1 It is a schematic diagram of the architecture of a two-party computing system provided in an embodiment of the present application;
[0026] Figure 2 It is a flowchart of an efficient post-quantum privacy set intersection method provided in an embodiment of the present application;
[0027] Figure 3 It is a structural schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0029] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices.
[0030] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0031] The sender and receiver described in the embodiments of the present application may include electronic devices, which may include smart phones (such as Android phones, iOS phones, Windows Phone phones, etc.), tablet computers, PDAs, driving recorders, servers, laptops, mobile Internet devices (MID, Mobile Internet Devices) or wearable devices (such as smart watches, Bluetooth headsets), etc. The above are only examples and not exhaustive, including but not limited to the above electronic devices. The electronic device may also be a cloud server, or the electronic device may also be a computer cluster.
[0032] In the related technologies, the technical solutions for privacy intersection can be divided into three types, as follows:
[0033] The first type: schemes based on classical public key cryptography, which are usually constructed based on factor decomposition or discrete logarithm problems.
[0034] The second type: Based on the Oblivious Transfer (OT) protocol, a variety of cryptographic tools are derived, and these cryptographic tools are used to construct a privacy-seeking protocol.
[0035] The third type: construction based on homomorphic encryption technology.
[0036] The privacy intersection in related technologies has the following defects when facing quantum attacks:
[0037] For the first case, the scheme based on classical public key cryptography is completely immune to quantum attacks.
[0038] For the second case, some efficient privacy intersection algorithms based on oblivious transfer protocols in related technologies have components that cannot resist quantum attacks.
[0039] For the third case, the quantum-resistant privacy intersection algorithm in the relevant technology is only applicable to specific non-equilibrium scenarios. It can only run effectively when the amount of data between the two parties is very different. It is not suitable for general computing scenarios.
[0040] In order to solve the defects of the related art, the embodiment of the present application provides an efficient post-quantum privacy set intersection method, which is applied to a two-party computing system, wherein the two-party computing system includes a sender and a receiver, the sender has a first data set, and the receiver has a second data set, and the method includes:
[0041] The sender selects an initial matrix and a pseudo-random function key, updates the initial matrix according to the column information of the first data set to obtain a first matrix, and sends the pseudo-random function key to the receiver; the sender serves as an OT sender;
[0042] Selecting an OT key by the receiver; the receiver serving as an OT receiver;
[0043] The sender and the receiver use a basic OT algorithm based on a grid to perform OT interaction, thereby obtaining a plurality of two-choice OTs;
[0044] Generate a random matrix by the sender, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-choose-one OTs to perform multiple two-choose-one OT operations;
[0045] The receiving party selects a bit string based on the OT key, determines an OT result matrix through the bit string, determines second local column information through column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiving party;
[0046] The receiving party determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0047] Through the embodiments of the present application, since a lattice-based basic OT algorithm is used for OT interaction, it is possible to meet the post-quantum security requirements and provide stronger security guarantees, thereby improving the performance of privacy intersection in resisting quantum attacks.
[0048] The embodiments of the present application are described in detail below.
[0049] See also Figure 1 , Figure 1 1 is a schematic diagram of the architecture of a two-party computing system provided in an embodiment of the present application. As shown in the figure, the two-party computing system may include a sender and a receiver; the sender has a first data set, and the receiver has a second data set. Based on the two-party computing system, the following functions can be implemented:
[0050] The sender is used to select an initial matrix, select a pseudo-random function key, update the initial matrix according to the column information of the first data set to obtain a first matrix, and send the pseudo-random function key to the receiver; the sender serves as an OT sender;
[0051] The receiver is used to select an OT key; the receiver serves as an OT receiver;
[0052] The sender and the receiver are used to perform OT interaction by using a grid-based basic OT algorithm to obtain multiple two-choice OTs;
[0053] The sender is used to generate a random matrix, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-choose-one OTs to perform multiple two-choose-one OT operations;
[0054] The receiving party is configured to select a bit string based on the OT key, determine an OT result matrix through the bit string, determine second local column information through the column information of the second data set and the pseudo-random function key, determine a first privacy intersection judgment set according to the second local column information and the OT result matrix, and send the first privacy intersection judgment set to the receiving party;
[0055] The receiving party is used to determine first local column information through the column information of the first data set and the pseudo-random function key, determine a second privacy intersection judgment set according to the first local column information and the random matrix, and determine a target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0056] Optionally, the determining the first local column information by using the column information of the first data set and the pseudo-random function key, the receiving party is specifically configured to:
[0057] The receiving party performs a first hash operation on the column information of the first data set to obtain a first hash algorithm result;
[0058] The first local column information is determined according to the pseudo-random function key and the first hash algorithm result.
[0059] Optionally, the determining the second local column information by using the column information of the second data set and the pseudo-random function key includes:
[0060] Perform the first hash operation on the column information of the second data set to obtain a second hash algorithm result;
[0061] The second local column information is determined according to the pseudo-random function key and the second Hash algorithm result.
[0062] Optionally, determining a first privacy intersection judgment set according to the second local column information and the OT result matrix includes:
[0063] Performing an intersection operation on the second local column information and the OT result matrix to obtain a first initial privacy intersection judgment set;
[0064] A second hash operation is performed on the first initial privacy intersection judgment set to obtain the first privacy intersection judgment set.
[0065] Optionally, determining a second privacy intersection judgment set according to the first local column information and the random matrix includes:
[0066] Performing an intersection operation on the first local column information and the random matrix to obtain a second initial privacy intersection judgment set;
[0067] The second initial privacy intersection judgment set is subjected to the second hash operation to obtain the second privacy intersection judgment set.
[0068] Optionally, the sender has the first data and the second data, and the receiver has the selection bit; the grid-based basic OT algorithm includes the following process:
[0069] Determining public parameters by the sender and the receiver, the public parameters including: distribution of disturbance vectors in the grid, and public random vectors;
[0070] Determine a random vector by the sender, determine a first key vector and a first disturbance vector according to the distribution of the disturbance vector in the lattice, determine a first vector according to the public random vector, the first key vector and the first disturbance vector, and send the first vector and the random vector to the receiver;
[0071] generating, by the receiving party, a second key vector, a second perturbation vector and a third perturbation vector from the distribution of perturbation vectors in the lattice, determining a second vector according to the public random vector, the second key vector and the second perturbation vector, determining a third vector according to the first vector, the second key vector and the third perturbation vector, and determining a fourth vector according to an extended extraction algorithm based on the third vector;
[0072] Determine, by the receiving party, a fifth vector according to the selection bit and the random vector, and send the fifth vector and the fourth vector to the sending party;
[0073] The sender determines a first key by using a key derivation algorithm based on the fifth vector and the fourth vector; determines a second key and a third key according to a key reconciliation algorithm based on the first key vector, the fifth vector, and the fourth vector, encrypts the first data and the second data by using an encryption algorithm with the second key and the third key as keys, respectively, to obtain a first encryption result and a second encryption result, and sends the first encryption result and the second encryption result to the receiver;
[0074] The receiving party performs a decryption operation on the first encryption result and the second encryption result according to the selection bit to obtain a decryption result.
[0075] It can be seen that the two-party computing system described in the embodiment of the present application includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, the sender selects an initial matrix, selects a pseudo-random function key, updates the initial matrix according to the column information of the first data set, obtains a first matrix, and sends the pseudo-random function key to the receiver; the sender acts as an OT sender; the receiver selects an OT key; the receiver acts as an OT receiver; the sender and the receiver use a lattice-based basic OT algorithm to perform OT interaction to obtain multiple two-choice OTs; the sender generates a random matrix, determines the second matrix according to the first matrix and the random matrix, and uses each column of the random matrix and the second matrix as the input of each of the multiple two-choice OTs to execute multiple two-choice OTs. OT operation; the receiver selects a bit string based on the OT key, determines the OT result matrix through the bit string, determines the second local column information through the column information of the second data set and the pseudo-random function key, determines the first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver; the receiver determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set. Since the lattice-based basic OT algorithm is used for OT interaction, it can meet the post-quantum security requirements and provide stronger security guarantees, thereby improving the privacy intersection's resistance to quantum attacks.
[0076] See also Figure 2 , Figure 2 This is a flow chart of an efficient post-quantum privacy set intersection method provided in an embodiment of the present application, which is applied to Figure 1 The two-party computing system shown in the figure includes a sender and a receiver, the sender has a first data set, and the receiver has a second data set. As shown in the figure, the efficient post-quantum privacy set intersection method includes:
[0077] 201. The sender selects an initial matrix and a pseudo-random function key, updates the initial matrix according to the column information of the first data set to obtain a first matrix, and sends the pseudo-random function key to the receiver; the sender serves as an OT sender.
[0078] Among them, the first data set and the second data set can both include multiple data groups, each data group can include multiple data, each data can correspond to a tag information, each data can be understood as an information field, which is used to express the content of the tag information, and the tag information can include at least one of the following: identity card number (ID-CARD), phone number (Phone Number), bank card number (Bank Card), social security account number, social account number, student number, work number, etc., which are not limited here. For example, the sender is P0, the receiver is P1, the first data set is recorded as X, the second data set is recorded as Y, the initial matrix is recorded as D, and the pseudo-random function key is recorded as K.
[0079] Specifically, D∈{1} m×w , D={D1||D2||...||D w}, where {1} m×w Represents an m-row w-column all-1 matrix. Pseudo-random function key K∈{0,1} λ , where λ is the security parameter of the system. Calculate the column information x∈X,v1=F of the local set K (H1(x)), modify the initial matrix D i [v[i]]=0,i∈[w], i represents the i-th column.
[0080] 202. Select an OT key through the receiver; the receiver serves as an OT receiver.
[0081] The receiver can select the OT key uniformly and randomly. Specifically, the OT key S←{0,1} is selected. w .
[0082] Among them, the OT key can be understood as the source of randomness for executing the OT protocol.
[0083] 203. The sender and the receiver perform OT interaction by using a basic OT algorithm based on a grid to obtain a plurality of two-choice OTs.
[0084] Among them, the basic OT algorithm based on the lattice has anti-quantum characteristics, making the overall algorithm meet the anti-quantum characteristics. In the specific implementation, the sender and the receiver use the basic OT algorithm based on the lattice to interact with each other, and obtain multiple two-choice OTs, which can meet the post-quantum security requirements and provide stronger security protection.
[0085] In the specific implementation, complex OT needs to be executed in the privacy intersection, such as n-choose-k OT, and two-choose-one OT is the basic component of complex OT. Complex OT can be realized by executing multiple two-choose-one OTs. In the embodiment of the present application, it is equivalent to realizing the preprocessing work of complex OT by obtaining the parameters of multiple two-choose-one OTs.
[0086] 204. Generate a random matrix through the sender, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-to-one OTs to perform multiple two-to-one OT operations.
[0087] Among them, the sender generates a random matrix A, determines the second matrix B according to the first matrix D and the random matrix A, and uses each column of the random matrix A and the second matrix B as the input of each of the multiple two-to-one OTs to perform multiple two-to-one OT operations.
[0088] In the specific implementation. A←{0,1} m×w , where {0, 1} m×w represents an m-row w-column 0,1 matrix. Let B=A⊕D, where {A i ,B i} i∈[w] .
[0089] In the embodiment of the present application, A and B can both be random matrices composed of 0 or 1. The two matrices are randomly generated and used to encode the original data when executing the OT protocol.
[0090] 205. The receiving party selects a bit string based on the OT key, determines an OT result matrix through the bit string, determines second local column information through the column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiving party.
[0091] Among them, the receiver selects a bit string based on the OT key, determines the OT result matrix C through the bit string, determines the second local column information through the column information of the second data set and the pseudo-random function key, determines the first privacy intersection judgment set according to the second local column information and the OT result matrix C, and sends the first privacy intersection judgment set to the receiver.
[0092] In the specific implementation, the OT result matrix C can be specifically expressed as C m×w Specifically, calculate the second local column information y∈Y, v2=F K (H1(y)), the first calculation of the privacy intersection judgment set
[0093] 206. The receiver determines first local column information through the column information of the first data set and the pseudo-random function key, determines a second privacy intersection judgment set according to the first local column information and the random matrix, and determines a target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0094] In an embodiment of the present application, the receiving party determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set, thereby ensuring the high efficiency of the privacy intersection.
[0095] Among them, the first local column information x∈X can be calculated, v1=F K (H1(x)), calculate the second privacy intersection judgment set if Output x. At this time, x∈X∩Y.
[0096] Among them, Ψ represents the set of values obtained after all original data Y are hashed by H2. Here It means that the hash value corresponding to x is in the above set. If all x are calculated in this way, what we get is the set of hash values of the original data in both the X and Y sets, that is, the content of the intersection part.
[0097] Optionally, the above step of determining the first local column information by the receiver using the column information of the first data set and the pseudo-random function key may include the following steps:
[0098] The receiving party performs a first hash operation on the column information of the first data set to obtain a first hash algorithm result;
[0099] The first local column information is determined according to the pseudo-random function key and the first hash algorithm result.
[0100] In a specific implementation, the receiver may perform a first hash operation H1 on the column information of the first data set X to obtain a first hash algorithm result v1, and determine the first local column information according to the pseudo-random function key and the first hash algorithm result.
[0101] Specifically, calculate the first local column information x∈X, v1=F K (H1(x)), where H1 represents the first hash operation and x represents an element in the first data set.
[0102] Optionally, the above step of determining the second local column information by using the column information of the second data set and the pseudo-random function key may include the following steps:
[0103] Perform the first hash operation on the column information of the second data set to obtain a second hash algorithm result;
[0104] The second local column information is determined according to the pseudo-random function key and the second Hash algorithm result.
[0105] In the embodiment of the present application, the first hash operation H1 can be performed on the column information of the second data set Y to obtain the second hash algorithm result v2, and the second local column information can be determined according to the pseudo-random function key and the second hash algorithm result. Specifically, y∈Y, v2=F K (H1(y)).
[0106] Optionally, the above step of determining the first privacy intersection judgment set according to the second local column information and the OT result matrix may include the following steps:
[0107] Performing an intersection operation on the second local column information and the OT result matrix to obtain a first initial privacy intersection judgment set;
[0108] A second hash operation is performed on the first initial privacy intersection judgment set to obtain the first privacy intersection judgment set.
[0109] In an embodiment of the present application, an intersection operation can be performed based on the second local column information and the OT result matrix to obtain a first initial privacy intersection judgment set, and then a second hash operation is performed on the first initial privacy intersection judgment set to obtain the first privacy intersection judgment set.
[0110] In the specific implementation, the OT result matrix C can be specifically expressed as C m×w Specifically, calculate the second local column information y∈Y, v2=F K (H1(y)), the first calculation of the privacy intersection judgment set
[0111] Optionally, the above step of determining the second privacy intersection judgment set according to the first local column information and the random matrix may include the following steps:
[0112] Performing an intersection operation on the first local column information and the random matrix to obtain a second initial privacy intersection judgment set;
[0113] The second initial privacy intersection judgment set is subjected to the second hash operation to obtain the second privacy intersection judgment set.
[0114] In a specific implementation, an intersection operation is performed based on the first local column information and the random matrix to obtain a second initial privacy intersection judgment set;
[0115] The second initial privacy intersection judgment set is subjected to the second hash operation to obtain the second privacy intersection judgment set.
[0116] The present invention performs quantum-resistant replacement on the non-quantum-resistant algorithm part of the existing algorithm, so that the overall algorithm meets the quantum-resistant property.
[0117] Among them, calculate the first local column information x∈X, v1=F K (H1(x)), calculate the second privacy intersection judgment set if Output x. At this time, x∈X∩Y.
[0118] Optionally, the sender has the first data and the second data, and the receiver has the selection bit; the grid-based basic OT algorithm includes the following process:
[0119] Determining public parameters by the sender and the receiver, the public parameters including: distribution of disturbance vectors in the grid, and public random vectors;
[0120] Determine a random vector by the sender, determine a first key vector and a first disturbance vector according to the distribution of the disturbance vector in the lattice, determine a first vector according to the public random vector, the first key vector and the first disturbance vector, and send the first vector and the random vector to the receiver;
[0121] generating, by the receiving party, a second key vector, a second perturbation vector and a third perturbation vector from the distribution of perturbation vectors in the lattice, determining a second vector according to the public random vector, the second key vector and the second perturbation vector, determining a third vector according to the first vector, the second key vector and the third perturbation vector, and determining a fourth vector according to an extended extraction algorithm based on the third vector;
[0122] Determine, by the receiving party, a fifth vector according to the selection bit and the random vector, and send the fifth vector and the fourth vector to the sending party;
[0123] The sender determines a first key by using a key derivation algorithm based on the fifth vector and the fourth vector; determines a second key and a third key according to a key reconciliation algorithm based on the first key vector, the fifth vector, and the fourth vector, encrypts the first data and the second data by using an encryption algorithm with the second key and the third key as keys, respectively, to obtain a first encryption result and a second encryption result, and sends the first encryption result and the second encryption result to the receiver;
[0124] The receiving party performs a decryption operation on the first encryption result and the second encryption result according to the selection bit to obtain a decryption result.
[0125] The sender has the first data and the second data, the receiver has a selection bit, the participants are divided into the sender and the receiver, the sender has two data, specifically the first data M0 and the second data M1, the receiver has a selection bit σ, and at the end of the protocol, the receiver obtains one of the data of the sender according to the selection bit. M0 and M1 represent plaintext messages or plaintext data.
[0126] In the embodiment of the present application, the sender and the receiver determine the public parameters, which include: the distribution of the perturbation vector in the lattice, and the public random vector. Both parties determine the public parameters, which may include: the parameters of the polynomial ring, the distribution of the perturbation vector in the lattice χ, and the public random vectors a and q (modulo).
[0127] Next, the sender can determine the random vector T, determine the first key vector s and the first disturbance vector e according to the distribution χ of the disturbance vector in the lattice, and determine the first vector A according to the public random vector a, the first key vector s and the first disturbance vector e. Specifically, A=as+e, and send the first vector A and the random vector T to the receiver.
[0128] Among them, the receiving party can generate a second key vector s′, a second perturbation vector e′ and a third perturbation vector e″ from the distribution χ of the perturbation vector in the lattice, and determine the second vector b′ according to the public random vector a, the second key vector s′ and the second perturbation vector e′, that is, b′=as′+e′. Then determine the third vector z according to the first vector A, the second key vector s′ and the third perturbation vector e″, z=As′+e″. Based on the third vector z, the fourth vector c is determined according to the extended extraction algorithm.
[0129] The extended extraction algorithm can be understood as a hash function or a lattice-based encoding algorithm, the purpose of which is to extract sufficient information while maintaining a certain level of security. Extended extraction algorithms such as SHA-256 algorithm, SM3 algorithm, etc. are not limited here.
[0130] The receiving party determines the fifth vector B according to the selection bit σ and the random vector T, and sends the fifth vector B and the fourth vector c to the sending party. Specifically, if σ=0, let B=b′, if σ=1, let B=b′+T, and then send B and c to the sending party.
[0131] The sender may determine the first key k′ by using a key derivation algorithm based on the fifth vector B and the fourth vector c.
[0132] Specifically, based on B and c, the key derivation algorithm is then called to generate the key k'. In the embodiment of the present application, the key derivation algorithm includes two functions, one is a random doubling function, which will expand the pattern of the integer ring by twice the original, and the other is a cross-rounding function, which will follow the formula Perform coefficient-by-coefficient calculations.
[0133] In the specific implementation, the key derivation algorithm is used to convert the receiver's calculation result B and the extracted bit string c into a key k' for subsequent decryption operations. This operation can use any existing key derivation algorithm, such as the KDF algorithm in the national encryption standard, which is not limited here.
[0134] Among them, based on the first key vector s, the fifth vector B, and the fourth vector c, the second key k0 and the third key k1 are determined according to the key reconciliation algorithm, and the first data M0 and the second data M1 are encrypted with the second key k0 and the third key k1 as keys respectively through the encryption algorithm to obtain the first encryption result e0 and the second encryption result e1, and the first encryption result e0 and the second encryption result e1 are sent to the recipient.
[0135] Specifically, the sender derives the keys k0 and k1 through the key reconciliation algorithm, where k0 = key reconciliation algorithm (2Bs, c) and k1 = key reconciliation algorithm (2(BT)s, c). The key reconciliation algorithm contains two functions, one is the reconciliation function, which is used for key extraction, and the other is the hash function, which is used to derive the key of the encryption function.
[0136] The receiving party may perform a decryption operation on the first encryption result e0 and the second encryption result e1 according to the selection bit σ to obtain a decryption result.
[0137] To illustrate, in the specific implementation, the participants are divided into senders and receivers. The sender has two data M0 and M1, and the receiver has a selection bit σ. At the end of the protocol, the receiver obtains one of the sender's data based on the selection bit. Specifically, the two parties determine the public parameters, including the parameters of the polynomial ring, the distribution of the perturbation vector χ in the lattice, and the public random vector a. The sender randomly selects T, generates s, e from χ, calculates A=as+e, and then sends A, T to the receiver. The receiver generates s′, e′, e″ from χ, and then calculates b′=as′+e′, z=As′+e″. c is calculated based on v through an extended extraction algorithm. If σ=0, let B=b′, if σ=1, let B=b′+T, and then send B, c to the sender. The key derivation algorithm is then called to generate the key k′. The key derivation algorithm here contains two functions, one is a random doubling function, which will expand the pattern of the integer ring by twice the original, and the other is a cross integer function, which will follow the formula Perform coefficient-by-coefficient calculations. The sender derives keys k0 and k1 through a key reconciliation algorithm, where k0 = key reconciliation algorithm (2Bs,c) and k1 = key reconciliation algorithm (2(BT)s,c). The key reconciliation algorithm contains two functions, one is a reconciliation function used for key extraction, and the other is a hash function. Used to derive the key of the encryption function. The sender encrypts M0 and M1 using the encryption algorithm with k0 and k1 as keys respectively, and the results are recorded as e0 and e1 and sent to the receiver. The receiver decrypts e0 and e1 using the key k′ to obtain the decrypted content. In this way, by selecting appropriate extended extraction, key derivation, and key reconciliation algorithms, it can be ensured that the receiver can extract the information he wants.
[0138] It can be seen that the efficient post-quantum privacy set intersection method described in the embodiment of the present application is applied to a two-party computing system, which includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, the sender selects an initial matrix, selects a pseudo-random function key, updates the initial matrix according to the column information of the first data set, obtains a first matrix, and sends the pseudo-random function key to the receiver; the sender acts as an OT sender; the receiver selects an OT key; the receiver acts as an OT receiver; the sender and the receiver use a lattice-based basic OT algorithm to perform OT interaction to obtain multiple two-choice OTs; the sender generates a random matrix, determines the second matrix according to the first matrix and the random matrix, and uses each column of the random matrix and the second matrix as the input of each of the multiple two-choice OTs. To perform multiple two-choice OT operations; the receiver selects a bit string based on the OT key, and determines the OT result matrix through the bit string, determines the second local column information through the column information of the second data set and the pseudo-random function key, determines the first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver; the receiver determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set. Since the lattice-based basic OT algorithm is used for OT interaction, it can meet the post-quantum security requirements and provide stronger security guarantees, thereby improving the privacy intersection's resistance to quantum attacks.
[0139] In accordance with the above embodiment, please refer to Figure 3 , Figure 3 : is a structural schematic diagram of an electronic device provided in an embodiment of the present application. As shown in the figure, the electronic device includes a processor, a memory, a communication interface and one or more programs. The one or more programs are stored in the memory and are configured to be executed by the processor. The two-party computing system includes a sender and a receiver. The sender has a first data set, and the receiver has a second data set. In the embodiment of the present application, the program includes instructions for executing the following steps:
[0140] The sender selects an initial matrix and a pseudo-random function key, updates the initial matrix according to the column information of the first data set to obtain a first matrix, and sends the pseudo-random function key to the receiver; the sender serves as an OT sender;
[0141] Selecting an OT key by the receiver; the receiver serving as an OT receiver;
[0142] The sender and the receiver use a basic OT algorithm based on a grid to perform OT interaction, thereby obtaining a plurality of two-choice OTs;
[0143] Generate a random matrix by the sender, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-choose-one OTs to perform multiple two-choose-one OT operations;
[0144] The receiving party selects a bit string based on the OT key, determines an OT result matrix through the bit string, determines second local column information through column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiving party;
[0145] The receiving party determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0146] Optionally, in the aspect of determining the first local column information by the receiver using the column information of the first data set and the pseudo-random function key, the program includes instructions for performing the following steps:
[0147] The receiving party performs a first hash operation on the column information of the first data set to obtain a first hash algorithm result;
[0148] The first local column information is determined according to the pseudo-random function key and the first hash algorithm result.
[0149] Optionally, in the aspect of determining the second local column information by using the column information of the second data set and the pseudo-random function key, the program includes instructions for performing the following steps:
[0150] Perform the first hash operation on the column information of the second data set to obtain a second hash algorithm result;
[0151] The second local column information is determined according to the pseudo-random function key and the second Hash algorithm result.
[0152] Optionally, in the aspect of determining the first privacy intersection judgment set according to the second local column information and the OT result matrix, the above program includes instructions for executing the following steps:
[0153] Performing an intersection operation on the second local column information and the OT result matrix to obtain a first initial privacy intersection judgment set;
[0154] A second hash operation is performed on the first initial privacy intersection judgment set to obtain the first privacy intersection judgment set.
[0155] Optionally, in the aspect of determining the second privacy intersection judgment set according to the first local column information and the random matrix, the program includes instructions for executing the following steps:
[0156] Performing an intersection operation on the first local column information and the random matrix to obtain a second initial privacy intersection judgment set;
[0157] The second initial privacy intersection judgment set is subjected to the second hash operation to obtain the second privacy intersection judgment set.
[0158] Optionally, the sender has the first data and the second data, and the receiver has the selection bit; the grid-based basic OT algorithm includes the following process:
[0159] Determining public parameters by the sender and the receiver, the public parameters including: distribution of disturbance vectors in the grid, and public random vectors;
[0160] Determine a random vector by the sender, determine a first key vector and a first disturbance vector according to the distribution of the disturbance vector in the lattice, determine a first vector according to the public random vector, the first key vector and the first disturbance vector, and send the first vector and the random vector to the receiver;
[0161] generating, by the receiving party, a second key vector, a second perturbation vector and a third perturbation vector from the distribution of perturbation vectors in the lattice, determining a second vector according to the public random vector, the second key vector and the second perturbation vector, determining a third vector according to the first vector, the second key vector and the third perturbation vector, and determining a fourth vector according to an extended extraction algorithm based on the third vector;
[0162] Determine, by the receiving party, a fifth vector according to the selection bit and the random vector, and send the fifth vector and the fourth vector to the sending party;
[0163] The sender determines a first key by using a key derivation algorithm based on the fifth vector and the fourth vector; determines a second key and a third key according to a key reconciliation algorithm based on the first key vector, the fifth vector, and the fourth vector, encrypts the first data and the second data by using an encryption algorithm with the second key and the third key as keys, respectively, to obtain a first encryption result and a second encryption result, and sends the first encryption result and the second encryption result to the receiver;
[0164] The receiving party performs a decryption operation on the first encryption result and the second encryption result according to the selection bit to obtain a decryption result.
[0165] It can be seen that the electronic device described in the embodiment of the present application is applied to a two-party computing system, which includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, the sender selects an initial matrix, selects a pseudo-random function key, updates the initial matrix according to the column information of the first data set, obtains a first matrix, and sends the pseudo-random function key to the receiver; the sender acts as an OT sender; the receiver selects an OT key; the receiver acts as an OT receiver; the sender and the receiver use a lattice-based basic OT algorithm to perform OT interaction to obtain multiple two-choice OTs; the sender generates a random matrix, determines the second matrix according to the first matrix and the random matrix, and uses each column of the random matrix and the second matrix as the input of each of the multiple two-choice OTs to execute multiple times. Two-choice OT operation; the receiver selects a bit string based on the OT key, determines the OT result matrix through the bit string, determines the second local column information through the column information of the second data set and the pseudo-random function key, determines the first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver; the receiver determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set. Since the lattice-based basic OT algorithm is used for OT interaction, it can meet the post-quantum security requirements and provide stronger security guarantees, thereby improving the privacy intersection's resistance to quantum attacks.
[0166] An embodiment of the present application also provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, wherein the computer program enables a computer to execute part or all of the steps of any method described in the above method embodiments, and the above computer includes an electronic device.
[0167] The embodiment of the present application also provides a computer program product, the computer program product includes a non-transitory computer-readable storage medium storing a computer program, the computer program is operable to cause a computer to execute some or all of the steps of any method described in the method embodiment. The computer program product may be a software installation package, and the computer includes an electronic device.
[0168] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0169] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0170] In the several embodiments provided in the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are only schematic, such as the division of the above-mentioned units, which is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical or other forms.
[0171] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0172] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0173] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a memory, including a number of instructions to enable a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the above-mentioned methods of each embodiment of the present application. The aforementioned memory includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or CD-ROM and other media that can store program codes.
[0174] A person skilled in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable memory, and the memory can include: a flash drive, a read-only memory (English: Read-Only Memory, abbreviated as: ROM), a random access memory (English: Random Access Memory, abbreviated as: RAM), a magnetic disk or an optical disk, etc.
[0175] The embodiments of the present application are introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of the present application. At the same time, for general technical personnel in this field, according to the idea of the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. An efficient post-quantum privacy set intersection method, characterized in that: Applied to a two-party computing system, the two-party computing system includes a sender and a receiver, the sender has a first data set, and the receiver has a second data set, the method includes: The sender selects an initial matrix and a pseudo-random function key, updates the initial matrix according to the column information of the first data set to obtain a first matrix, and sends the pseudo-random function key to the receiver; the sender serves as an OT sender; Selecting an OT key by the receiver; the receiver serving as an OT receiver; The sender and the receiver use a basic OT algorithm based on a grid to perform OT interaction, thereby obtaining a plurality of two-choice OTs; Generate a random matrix by the sender, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-choose-one OTs to perform multiple two-choose-one OT operations; The receiving party selects a bit string based on the OT key, determines an OT result matrix through the bit string, determines second local column information through column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set according to the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiving party; The receiving party determines the first local column information through the column information of the first data set and the pseudo-random function key, determines the second privacy intersection judgment set according to the first local column information and the random matrix, and determines the target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
2. The method according to claim 1, characterized in that The determining, by the receiving party, the first local column information by using the column information of the first data set and the pseudo-random function key comprises: The receiving party performs a first hash operation on the column information of the first data set to obtain a first hash algorithm result; The first local column information is determined according to the pseudo-random function key and the first hash algorithm result.
3. The method according to claim 2, characterized in that The determining the second local column information by using the column information of the second data set and the pseudo-random function key comprises: Perform the first hash operation on the column information of the second data set to obtain a second hash algorithm result; The second local column information is determined according to the pseudo-random function key and the second Hash algorithm result.
4. The method according to claim 3, characterized in that The determining a first privacy intersection judgment set according to the second local column information and the OT result matrix includes: Performing an intersection operation on the second local column information and the OT result matrix to obtain a first initial privacy intersection judgment set; A second hash operation is performed on the first initial privacy intersection judgment set to obtain the first privacy intersection judgment set.
5. The method according to claim 4, characterized in that The determining a second privacy intersection judgment set according to the first local column information and the random matrix includes: Performing an intersection operation on the first local column information and the random matrix to obtain a second initial privacy intersection judgment set; The second initial privacy intersection judgment set is subjected to the second hash operation to obtain the second privacy intersection judgment set.
6. The method according to any one of claims 1 to 5, characterized in that: The sender has first data and second data, and the receiver has a selection bit; the grid-based basic OT algorithm includes the following process: Determining public parameters by the sender and the receiver, the public parameters including: distribution of disturbance vectors in the grid, and public random vectors; Determine a random vector by the sender, determine a first key vector and a first disturbance vector according to the distribution of the disturbance vector in the lattice, determine a first vector according to the public random vector, the first key vector and the first disturbance vector, and send the first vector and the random vector to the receiver; generating, by the receiving party, a second key vector, a second perturbation vector and a third perturbation vector from the distribution of perturbation vectors in the lattice, determining a second vector according to the public random vector, the second key vector and the second perturbation vector, determining a third vector according to the first vector, the second key vector and the third perturbation vector, and determining a fourth vector according to an extended extraction algorithm based on the third vector; Determine, by the receiving party, a fifth vector according to the selection bit and the random vector, and send the fifth vector and the fourth vector to the sending party; The sender determines a first key by using a key derivation algorithm based on the fifth vector and the fourth vector; determines a second key and a third key according to a key reconciliation algorithm based on the first key vector, the fifth vector, and the fourth vector, encrypts the first data and the second data by using an encryption algorithm with the second key and the third key as keys, respectively, to obtain a first encryption result and a second encryption result, and sends the first encryption result and the second encryption result to the receiver; The receiving party performs a decryption operation on the first encryption result and the second encryption result according to the selection bit to obtain a decryption result.
7. A two-party computing system, characterized in that: The two-party computing system includes a sender and a receiver, the sender has a first data set, and the receiver has a second data set, wherein: The sender is used to select an initial matrix, select a pseudo-random function key, update the initial matrix according to the column information of the first data set to obtain a first matrix, and send the pseudo-random function key to the receiver; the sender serves as an OT sender; The receiver is used to select an OT key; the receiver serves as an OT receiver; The sender and the receiver are used to perform OT interaction by using a grid-based basic OT algorithm to obtain multiple two-choice OTs; The sender is used to generate a random matrix, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-choose-one OTs to perform multiple two-choose-one OT operations; The receiving party is configured to select a bit string based on the OT key, determine an OT result matrix through the bit string, determine second local column information through the column information of the second data set and the pseudo-random function key, determine a first privacy intersection judgment set according to the second local column information and the OT result matrix, and send the first privacy intersection judgment set to the receiving party; The receiving party is used to determine first local column information through the column information of the first data set and the pseudo-random function key, determine a second privacy intersection judgment set according to the first local column information and the random matrix, and determine a target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
8. The system according to claim 7, characterized in that The first local column information is determined by using the column information of the first data set and the pseudo-random function key, and the receiving party is specifically configured to: The receiving party performs a first hash operation on the column information of the first data set to obtain a first hash algorithm result; The first local column information is determined according to the pseudo-random function key and the first hash algorithm result.
9. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory is used to store one or more programs and is configured to be executed by the processor, wherein the program comprises instructions for executing the steps in the method according to any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that: A computer program for electronic data exchange is stored, wherein the computer program enables a computer to execute the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
OPRF protocol implementation method and device and electronic equipment
CN113364577A
Privacy set intersection calculation method, device and system
CN115333721A
Method for safely calculating inner product of vectors held by two parties based on lattice
CN117675210A
Oblivious transfer from key encapsulation mechanisms
US20240235842A1