Efficient post-quantum private set intersection methods and related apparatuses
By using a lattice-based basic OT algorithm for OT interaction, generating a random matrix for multiple binary-choice OT operations, the problem of insufficient security of existing privacy intersection algorithms under quantum computer attacks is solved, achieving stronger security and resistance to quantum attacks.
Patent Information
- Application Number
- CN202510055823.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2045-01-14
AI Technical Summary
Existing privacy intersection algorithms are not secure enough against quantum computer attacks and cannot effectively resist quantum attacks. In particular, classical public-key cryptography schemes are completely unresistant to quantum attacks, efficient algorithms based on unintentional transmission protocols contain components that cannot resist quantum attacks, and algorithms based on homomorphic encryption technology are only suitable for specific non-equilibrium scenarios.
The OT interaction is performed using a lattice-based basic OT algorithm. The sender and receiver select an initial matrix and a pseudo-random function key to generate a random matrix and perform multiple two-to-one OT operations. The privacy intersection judgment set is determined by combining the pseudo-random function key and the column information of the data set to achieve the target privacy intersection result.
It improves the resistance to quantum attacks in privacy-preserving intersection, provides stronger security guarantees, and meets the security requirements of post-quantum computing.
Smart Images

Figure CN119995852B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of privacy computing and the technical field of computer, in particular to an efficient post-quantum privacy set intersection method and related device. BACKGROUND
[0002] At present, the privacy intersection algorithm plays an increasingly important role in the fields of government affairs, finance, medical treatment and the like, and provides rich application channels for data assets.
[0003] With the continuous development of quantum computers, the security of the current cryptographic algorithm based on classical mathematical difficult problems (factorization, discrete logarithm) is greatly challenged, and the security of some efficient privacy intersection algorithms will be based on such mathematical difficult problems, causing some existing privacy intersection algorithms under quantum computers to be unable to be directly migrated and used. Therefore, the problem of how to improve the quantum attack resistance performance of privacy intersection needs to be solved. SUMMARY
[0004] The embodiments of the present application provide an efficient post-quantum privacy set intersection method and related device, which can improve the quantum attack resistance performance of privacy intersection.
[0005] In a first aspect, the embodiments of the present application provide an efficient post-quantum privacy set intersection method, applied to a two-party computing system, the two-party computing system including a sender and a receiver, the sender having a first data set, the receiver having a second data set, and the method including:
[0006] The sender selects an initial matrix, selects a pseudo-random function key, updates the initial matrix according to column information of the first data set to obtain a first matrix, and sends the pseudo-random function key to the receiver; and the sender acts as an OT sender;
[0007] The receiver selects an OT key; and the receiver acts as an OT receiver;
[0008] The sender and the receiver perform OT interaction by using a lattice-based basic OT algorithm to obtain a plurality of two-choice OTs;
[0009] The sender generates a random matrix, determines a second matrix according to the first matrix and the random matrix, and respectively takes each column of the random matrix and the second matrix as an input of each two-choice OT in the plurality of two-choice OTs to perform a plurality of two-choice OT operations;
[0010] determining a first local column information by the receiver through the column information of the first data set and the pseudo-random function key, determining a second privacy intersection judgment set according to the first local column information and the random matrix, and determining a target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0011] determining a first local column information by the receiver through the column information of the first data set and the pseudo-random function key, determining a second privacy intersection judgment set according to the first local column information and the random matrix, and determining a target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0012] In a second aspect, the embodiments of the present application provide a two-party computing system, the two-party computing system comprising a sender and a receiver, the sender having a first data set, and the receiver having a second data set, wherein,
[0013] the sender is configured to select an initial matrix, select a pseudo-random function key, update the initial matrix according to column information of the first data set to obtain a first matrix, and send the pseudo-random function key to the receiver; and the sender acts as an OT sender;
[0014] the receiver is configured to select an OT key; and the receiver acts as an OT receiver;
[0015] the sender and the receiver are configured to perform OT interaction by using a lattice-based basic OT algorithm to obtain a plurality of binary OTs;
[0016] the sender is configured to generate a random matrix, determine a second matrix according to the first matrix and the random matrix, and take each column of the random matrix and the second matrix as an input of each binary OT in the plurality of binary OTs to perform a plurality of binary OT operations;
[0017] the receiver is configured to select a bit string based on the OT key, determine an OT result matrix through the bit string, determine a second local column information through column information of the second data set and the pseudo-random function key, determine a first privacy intersection judgment set according to the second local column information and the OT result matrix, and send the first privacy intersection judgment set to the receiver;
[0018] The receiver is configured to determine first local column information based on the column information of the first data set and the pseudo-random function key, determine a second privacy intersection judgment set based on the first local column information and the random matrix, and determine a target privacy intersection result based on the first privacy intersection judgment set and the second privacy intersection judgment set.
[0019] In a third aspect, an embodiment of the present application provides an electronic device, including a processor, a memory, a communication interface and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, and the programs include instructions for performing the steps in the first aspect of the embodiments of the present application.
[0020] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program for electronic data exchange, and the computer program causes a computer to perform some or all of the steps described in the first aspect of the embodiments of the present application.
[0021] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes a non-transitory computer readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute some or all of the steps described in the first aspect of the embodiments of the present application. The computer program product can be a software installation package.
[0022] By implementing the embodiments of the present application, the following beneficial effects are achieved:
[0023] It can be seen that the efficient post-quantum privacy set intersection method and related device described in the embodiments of the present application are applied to a two-party computing system, the two-party computing system includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, an initial matrix is selected by the sender, a pseudo-random function key is selected, the initial matrix is updated according to column information of the first data set to obtain a first matrix, and the pseudo-random function key is sent to the receiver; the sender is an OT sender; the OT key is selected by the receiver; the receiver is an OT receiver; OT interaction is performed between the sender and the receiver by using a lattice-based basic OT algorithm to obtain a plurality of two-choice OTs; a random matrix is generated by the sender, a second matrix is determined according to the first matrix and the random matrix, and each column of the random matrix and the second matrix is taken as an input of each two-choice OT in the plurality of two-choice OTs to perform a plurality of two-choice OT operations; the receiver selects a bit string based on the OT key, and determines an OT result matrix based on the bit string, determines second local column information based on column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set based on the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver; the receiver determines first local column information based on column information of the first data set and the pseudo-random function key, determines a second privacy intersection judgment set based on the first local column information and the random matrix, and determines a target privacy intersection result based on the first privacy intersection judgment set and the second privacy intersection judgment set. Since the lattice-based basic OT algorithm is used for OT interaction, the security requirements of post-quantum can be met, stronger security protection is provided, and the resistance to quantum attack performance of the privacy intersection is improved. BRIEF DESCRIPTION OF DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0025] Figure 1 is an architecture schematic diagram of a two-party computing system provided by an embodiment of the present application;
[0026] Figure 2 is a flowchart schematic diagram of an efficient post-quantum privacy set intersection method provided by an embodiment of the present application;
[0027] Figure 3 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0028] In the following, the technical solutions in the embodiments of the present application will be described clearly and completely in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0029] The terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed or can optionally include other steps or units inherent to the process, method, product or device.
[0030] Reference herein to "embodiments" means that the particular features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase appears at various places in the specification does not necessarily all refer to the same embodiments, nor is it necessary that every embodiment include the particular features, structures or characteristics described in connection with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0031] The sender and the receiver described in the embodiments of the present application can each include an electronic device, which can include a smart phone (such as an Android phone, an iOS phone, a Windows Phone, etc.), a tablet computer, a palm computer, a vehicle event data recorder, a server, a notebook computer, a mobile Internet device (MID), or a wearable device (such as a smart watch, a Bluetooth headset), etc. The above are only examples, and are not exhaustive. The electronic device can include, but is not limited to, the above electronic devices. The electronic device can also be a cloud server, or the electronic device can also be a computer cluster.
[0032] In the related art, the technical solutions of privacy intersection can be divided into three kinds, as follows:
[0033] The first kind: based on classical public key cryptography, such schemes are usually based on factorization or discrete logarithm problems to construct.
[0034] The second kind: based on Oblivious Transfer (OT) protocol as the foundation, a variety of cryptographic tools are derived, and privacy intersection protocols are constructed through these cryptographic tools.
[0035] Third: based on homomorphic encryption technology to construct.
[0036] The privacy intersection in the related art has the following defects when facing quantum attacks:
[0037] For the first case, the scheme based on classical public key cryptography is completely not resistant to quantum attacks.
[0038] For the second case, some efficient privacy intersection algorithms based on the oblivious transfer protocol in the related art have components that cannot resist quantum attacks.
[0039] For the third case, the quantum-resistant privacy intersection algorithm in the related art is only applicable to a specific unbalanced scenario and needs a large difference in data quantity between the two parties to effectively run, and is not suitable for general computing scenarios.
[0040] In order to solve the defects of the related art, an efficient post-quantum privacy set intersection method is provided, which is applied to a two-party computing system, the two-party computing system includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, and the method includes:
[0041] The sender selects an initial matrix, selects a pseudo-random function key, updates the initial matrix according to the column information of the first data set to obtain a first matrix, and sends the pseudo-random function key to the receiver; the sender acts as an OT sender;
[0042] The receiver selects an OT key; the receiver acts as an OT receiver;
[0043] The sender and the receiver perform OT interaction based on a lattice-based basic OT algorithm to obtain a plurality of two-choice OTs;
[0044] The sender generates a random matrix, determines a second matrix according to the first matrix and the random matrix, and respectively takes each column of the random matrix and the second matrix as the input of each two-choice OT in the plurality of two-choice OTs to perform a plurality of two-choice OT operations;
[0045] The receiver selects a bit string based on the OT key, determines an OT result matrix based on the bit string, determines a second local column information based on the column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set based on the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver;
[0046] determining, by the receiver, first local column information through column information of the first data set and the pseudo-random function key, determining a second privacy intersection judgment set according to the first local column information and the random matrix, and determining a target privacy intersection result according to the first privacy intersection judgment set and the second privacy intersection judgment set.
[0047] According to the embodiment of the application, the OT interaction is performed based on the lattice-based basic OT algorithm, the security requirement of post-quantum is met, stronger security guarantee is provided, and the resistance to quantum attack performance of the privacy intersection is improved.
[0048] The embodiment of the application will be described in detail below.
[0049] Please refer to Figure 1 , Figure 1 is a schematic diagram of an architecture of a two-party computing system provided by the embodiment of the application, as shown in the figure, the two-party computing system can include a sender and a receiver; the sender has a first data set, and the receiver has a second data set, and the two-party computing system can realize the following functions:
[0050] The sender is configured to select an initial matrix, select a pseudo-random function key, update the initial matrix according to column information of the first data set to obtain a first matrix, and send the pseudo-random function key to the receiver; the sender acts as an OT sender;
[0051] The receiver is configured to select an OT key; the receiver acts as an OT receiver;
[0052] The sender and the receiver are configured to perform OT interaction based on a lattice-based basic OT algorithm to obtain a plurality of two-choice OTs;
[0053] The sender is configured to generate a random matrix, determine a second matrix according to the first matrix and the random matrix, and take each column of the random matrix and the second matrix as an input of each two-choice OT in the plurality of two-choice OTs to perform a plurality of two-choice OT operations;
[0054] The receiver is configured to select a bit string based on the OT key, determine an OT result matrix through the bit string, determine second local column information through column information of the second data set and the pseudo-random function key, determine a first privacy intersection judgment set according to the second local column information and the OT result matrix, and send the first privacy intersection judgment set to the receiver;
[0055] The receiver is configured to determine first local column information based on the column information of the first data set and the pseudo-random function key, determine a second privacy intersection judgment set based on the first local column information and the random matrix, and determine a target privacy intersection result based on the first privacy intersection judgment set and the second privacy intersection judgment set.
[0056] Optionally, the receiver is configured to determine the first local column information based on the column information of the first data set and the pseudo-random function key.
[0057] The receiver is configured to perform a first hash operation on the column information of the first data set to obtain a first hash algorithm result.
[0058] The receiver is configured to determine the first local column information based on the pseudo-random function key and the first hash algorithm result.
[0059] Optionally, the receiver is configured to determine the second local column information based on the column information of the second data set and the pseudo-random function key.
[0060] The receiver is configured to perform the first hash operation on the column information of the second data set to obtain a second hash algorithm result.
[0061] The receiver is configured to determine the second local column information based on the pseudo-random function key and the second hash algorithm result.
[0062] Optionally, the receiver is configured to determine the first privacy intersection judgment set based on the second local column information and the OT result matrix.
[0063] The receiver is configured to perform an intersection operation on the second local column information and the OT result matrix to obtain a first initial privacy intersection judgment set.
[0064] The receiver is configured to perform a second hash operation on the first initial privacy intersection judgment set to obtain the first privacy intersection judgment set.
[0065] Optionally, the receiver is configured to determine the second privacy intersection judgment set based on the first local column information and the random matrix.
[0066] The receiver is configured to perform an intersection operation on the first local column information and the random matrix to obtain a second initial privacy intersection judgment set.
[0067] The receiver is configured to perform the second hash operation on the second initial privacy intersection judgment set to obtain the second privacy intersection judgment set.
[0068] Optionally, the sender has the first data and the second data, and the receiver has the selection bits; and the lattice-based OT algorithm includes the following processes.
[0069] Determining public parameters by the sender and the receiver, wherein the public parameters include: distribution of disturbance vectors in the grid and a public random vector;
[0070] Determining a random vector by the sender, determining a first key vector and a first perturbation vector according to the distribution of perturbation vectors in the lattice, determining a first vector according to the public random vector, the first key vector, and the first perturbation vector, and sending the first vector and the random vector to the receiver;
[0071] generating, by the receiver, a second key vector, a second perturbation vector, and a third perturbation vector from a distribution of perturbation vectors in the lattice, determining a second vector based on the public random vector, the second key vector, and the second perturbation vector, determining a third vector based on the first vector, the second key vector, and the third perturbation vector, and determining a fourth vector based on the third vector according to an extended extraction algorithm;
[0072] determining, by the receiver, a fifth vector according to the selection bit and the random vector, and sending the fifth vector and the fourth vector to the sender;
[0073] The sender determines a first key using a key derivation algorithm based on the fifth vector and the fourth vector; determines a second key and a third key using a key reconciliation algorithm based on the first key vector, the fifth vector, and the fourth vector; encrypts the first data and the second data using an encryption algorithm using the second key and the third key as keys, respectively, to obtain a first encryption result and a second encryption result; and sends the first encryption result and the second encryption result to the receiver.
[0074] The receiving party performs a decryption operation on the first encryption result and the second encryption result according to the selection bit to obtain a decryption result.
[0075] It can be seen that the two-party computing system described in the embodiment of the application includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, an initial matrix is selected by the sender, a pseudo-random function key is selected, the initial matrix is updated according to column information of the first data set to obtain a first matrix, and the pseudo-random function key is sent to the receiver; the sender acts as an OT sender; an OT key is selected by the receiver; the receiver acts as an OT receiver; OT interaction is performed between the sender and the receiver by using a lattice-based basic OT algorithm to obtain a plurality of binary OTs; a random matrix is generated by the sender, a second matrix is determined according to the first matrix and the random matrix, and each column of the random matrix and the second matrix is taken as an input of each binary OT in the plurality of binary OTs to perform a plurality of binary OT operations; the receiver selects a bit string based on the OT key, and determines an OT result matrix based on the bit string, determines second local column information based on column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set based on the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver; the receiver determines first local column information based on column information of the first data set and the pseudo-random function key, determines a second privacy intersection judgment set based on the first local column information and the random matrix, and determines a target privacy intersection result based on the first privacy intersection judgment set and the second privacy intersection judgment set. Since the lattice-based basic OT algorithm is used for OT interaction, the security requirement of post-quantum can be met, stronger security protection is provided, and the resistance to quantum attack performance of the privacy intersection is improved.
[0076] Please refer to Figure 2 , Figure 2 is a flowchart of an efficient post-quantum privacy set intersection method provided by the embodiment of the application, which is applied to Figure 1 the two-party computing system shown in the figure, the two-party computing system includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, as shown in the figure, the efficient post-quantum privacy set intersection method includes:
[0077] 201, an initial matrix is selected by the sender, a pseudo-random function key is selected, the initial matrix is updated according to column information of the first data set to obtain a first matrix, and the pseudo-random function key is sent to the receiver; the sender acts as an OT sender.
[0078] The first data set and the second data set may each include multiple data groups, each data group may include multiple data, each data may correspond to a tag information, and each data may be understood as an information field used to express the content of the tag information. The tag information may include at least one of the following: identity card number (ID-CARD), phone number (Phone Number), bank card number (Bank Card), social security account number, social account number, student ID number, work ID number, etc., without limitation. For example, the sender is P0, the receiver is P1, the first data set is denoted as X, the second data set is denoted as Y, the initial matrix is denoted as D, and the pseudo-random function key is denoted as K.
[0079] Specifically, D∈{1} m×w , D={D1||D2||...||D w}, where {1} m×w Represents an m-row w-column all-1 matrix. Pseudo-random function key K∈{0,1} λ , where λ is the security parameter of the system. Calculate the column information of the local set x∈X,v1=F K (H1(x)), modify the initial matrix D i [v[i]]=0,i∈[w], i represents the i-th column.
[0080] 202. The receiver selects an OT key; the receiver serves as an OT receiver.
[0081] The receiver can select the OT key uniformly and randomly. Specifically, the OT key S←{0,1} is selected. w .
[0082] Among them, the OT key can be understood as the source of randomness for executing the OT protocol.
[0083] 203. The sender and the receiver perform OT interaction by using a grid-based basic OT algorithm to obtain multiple two-choice OTs.
[0084] The lattice-based OT algorithm possesses quantum-resistant properties, making the overall algorithm quantum-resistant. In specific implementations, the sender and receiver use the lattice-based OT algorithm for OT interaction, generating multiple binary OTs. This can meet post-quantum security requirements and provide stronger security guarantees.
[0085] In the specific implementation, complex OT needs to be executed in the privacy intersection, such as n-choose-k OT, and two-choose-one OT is the basic component of complex OT. Complex OT can be achieved by executing multiple two-choose-one OTs. In the embodiment of the present application, it is equivalent to achieving the preprocessing work of complex OT by obtaining the parameters of multiple two-choose-one OTs.
[0086] 204. generating a random matrix by the sender, determining a second matrix according to the first matrix and the random matrix, and taking each column of the random matrix and the second matrix as input of each one of the multiple OTs to perform multiple OT operations.
[0087] wherein the sender generates a random matrix A, determines a second matrix B according to the first matrix D and the random matrix A, and takes each column of the random matrix A and the second matrix B as input of each one of the multiple OTs to perform multiple OT operations.
[0088] In a specific implementation, A←{0,1} m×w wherein {0,1} m×w represents a 0,1 matrix of m rows and w columns. Let B=A i ,B i i∈[w] .
[0089] In the embodiments of the present application, A and B can be random matrices composed of 0 or 1, which are randomly generated and used to encode the original data when performing the OT protocol.
[0090] 205. selecting a bit string based on the OT key by the receiver, determining an OT result matrix by the bit string, determining second local column information by the column information of the second data set and the pseudo-random function key, determining a first privacy intersection judgment set according to the second local column information and the OT result matrix, and sending the first privacy intersection judgment set to the receiver.
[0091] wherein the receiver selects a bit string based on the OT key, determines an OT result matrix C by the bit string, determines second local column information by the column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set according to the second local column information and the OT result matrix C, and sends the first privacy intersection judgment set to the receiver.
[0092] In a specific implementation, the OT result matrix C can be specifically represented as C m×w Specifically, the second local column information y∈Y, v2=F K (H1(y)) is calculated, and the first privacy intersection judgment set
[0093] 206、determining, by the receiver, first local column information according to column information of the first data set and the pseudo-random function key, determining a second private intersection judgment set according to the first local column information and the random matrix, and determining a target private intersection result according to the first private intersection judgment set and the second private intersection judgment set.
[0094] In the embodiment of the application, the receiver determines first local column information according to column information of the first data set and the pseudo-random function key, determines a second private intersection judgment set according to the first local column information and the random matrix, and determines a target private intersection result according to the first private intersection judgment set and the second private intersection judgment set, thereby ensuring the efficiency of the private intersection.
[0095] wherein the first local column information x e X, v1 = F K (H1(x)) can be calculated, and the second private intersection judgment set If Output x. At this time, x e X n Y.
[0096] wherein Y represents a set of values obtained by performing H2 hashing on all original data Y, and Y represents the hash value corresponding to x in the above set, and all x are calculated in this way. The set of hash values of the original data in the intersection set X n Y is obtained, that is, the content of the intersection set.
[0097] Optionally, the step of determining, by the receiver, first local column information according to column information of the first data set and the pseudo-random function key can include the following steps.
[0098] Performing, by the receiver, first hash operation according to column information of the first data set to obtain a first hash algorithm result;
[0099] Determining the first local column information according to the pseudo-random function key and the first hash algorithm result.
[0100] In a specific implementation, the receiver can perform first hash operation H1 according to column information of the first data set X to obtain a first hash algorithm result v1, and determine the first local column information according to the pseudo-random function key and the first hash algorithm result.
[0101] Specifically, the first local column information x e X, v1 = F K (H1(x)) can be calculated, wherein H1 represents first hash operation, and x represents an element in the first data set.
[0102] Optionally, the step of determining the second local column information according to the column information of the second data set and the pseudo-random function key can comprise the following steps:
[0103] performing the first hash operation on the column information of the second data set to obtain a second hash algorithm result;
[0104] determining the second local column information according to the pseudo-random function key and the second hash algorithm result.
[0105] In the embodiments of the present application, the first hash operation H1 can be performed on the column information of the second data set Y to obtain a second hash algorithm result v2, and the second local column information can be determined according to the pseudo-random function key and the second hash algorithm result. Specifically, y∈Y, v2=F K (H1(y)).
[0106] Optionally, the step of determining the first private intersection judgment set according to the second local column information and the OT result matrix can comprise the following steps:
[0107] performing an intersection operation on the second local column information and the OT result matrix to obtain a first initial private intersection judgment set;
[0108] performing a second hash operation on the first initial private intersection judgment set to obtain the first private intersection judgment set.
[0109] In the embodiments of the present application, the intersection operation can be performed on the second local column information and the OT result matrix to obtain a first initial private intersection judgment set, and then a second hash operation is performed on the first initial private intersection judgment set to obtain the first private intersection judgment set.
[0110] In a specific implementation, the OT result matrix C can be specifically represented as C m×w Specifically, the second local column information y∈Y, v2=F K (H1(y)) is calculated, and a first calculation private intersection judgment set
[0111] Optionally, the step of determining the second private intersection judgment set according to the first local column information and the random matrix can comprise the following steps:
[0112] performing an intersection operation on the first local column information and the random matrix to obtain a second initial private intersection judgment set;
[0113] performing a second hash operation on the second initial private intersection judgment set to obtain the second private intersection judgment set.
[0114] In a particular implementation, an intersection operation is performed according to the first local column information and the random matrix to obtain a second initial privacy intersection judgment set;
[0115] The second initial privacy intersection judgment set is subjected to the second hash operation to obtain the second privacy intersection judgment set.
[0116] The present application replaces the non-quantum algorithm part of the existing algorithm with a quantum-resistant algorithm, so that the overall algorithm meets the quantum-resistant characteristic.
[0117] wherein a first local column information x is calculated, v1=F K (H1(x)) to obtain a second privacy intersection judgment set If Output x. At this time, x X∩Y.
[0118] Optionally, the sender has first data and second data, and the receiver has selection bits; the lattice-based OT algorithm includes the following processes:
[0119] Determine common parameters by the sender and the receiver, and the common parameters include: distribution of a perturbation vector in a lattice, a common random vector;
[0120] Determine a random vector by the sender, determine a first key vector and a first perturbation vector according to the distribution of the perturbation vector in the lattice, determine a first vector according to the common random vector, the first key vector and the first perturbation vector, and send the first vector and the random vector to the receiver;
[0121] Generate a second key vector, a second perturbation vector and a third perturbation vector from the distribution of the perturbation vector in the lattice by the receiver, determine a second vector according to the common random vector, the second key vector and the second perturbation vector, determine a third vector according to the first vector, the second key vector and the third perturbation vector, and determine a fourth vector according to an expansion extraction algorithm based on the third vector;
[0122] Determine a fifth vector according to the selection bits and the random vector by the receiver, and send the fifth vector and the fourth vector to the sender;
[0123] determining a first key by the sender based on the fifth vector and the fourth vector by using a key derivation algorithm; determining a second key and a third key based on the first key vector, the fifth vector and the fourth vector according to a key reconciliation algorithm, and encrypting the first data and the second data by using the second key and the third key as keys respectively by an encryption algorithm to obtain a first encryption result and a second encryption result, and sending the first encryption result and the second encryption result to the receiver;
[0124] decrypting the first encryption result and the second encryption result according to the selection bit by the receiver to obtain a decryption result.
[0125] wherein the sender has the first data and the second data, the receiver has the selection bit, the participants are divided into the sender and the receiver, the sender has two data, specifically the first data M0 and the second data M1, the receiver has one selection bit σ, and the receiver obtains one data of the sender according to the selection bit at the end of the protocol. M0 and M1 represent plaintext messages or plaintext data.
[0126] In the embodiments of the present application, the sender and the receiver determine the public parameters, and the public parameters include: the distribution of the perturbation vector in the lattice, the public random vector. Both parties determine the public parameters, and the public parameters can include: the parameters of the polynomial ring, the distribution χ of the perturbation vector in the lattice, the public random vector a, and q (modulus).
[0127] Then, the sender can determine a random vector T, determine a first key vector s and a first perturbation vector e according to the distribution χ of the perturbation vector in the lattice, determine a first vector A according to the public random vector a, the first key vector s and the first perturbation vector e, specifically A = as + e, and send the first vector A and the random vector T to the receiver.
[0128] The receiver can generate a second key vector s', a second perturbation vector e' and a third perturbation vector e'' from the distribution χ of the perturbation vector in the lattice, determine a second vector b' according to the public random vector a, the second key vector s' and the second perturbation vector e', that is, b' = as' + e', and then determine a third vector z according to the first vector A, the second key vector s' and the third perturbation vector e'', that is, z = As' + e''. The fourth vector c is determined based on the third vector z according to an expansion extraction algorithm.
[0129] The expansion extraction algorithm can be understood as a hash function or a certain lattice-based encoding algorithm, and the purpose is to extract sufficient information while maintaining a certain security. The expansion extraction algorithm is not limited to, for example, SHA-256 algorithm, SM3 algorithm, etc.
[0130] Wherein, the receiver determines the fifth vector B according to the selection bit σ and the random vector T, and sends the fifth vector B and the fourth vector c to the sender. Specifically, if σ = 0, let B = b', if σ = 1, let B = b' + T, and then send B, c to the sender.
[0131] Wherein, the sender can determine the first key k' based on the fifth vector B and the fourth vector c by using a key derivation algorithm.
[0132] Specifically, the key derivation algorithm is then called to generate the key k' based on B, c. In the embodiments of the application, the key derivation algorithm includes two functions, one is a random double function which will expand the mode of the integer ring by multiplying the original two times, and the other is an integer cross function which will perform coefficient-by-coefficient calculation according to the formula .
[0133] In the specific implementation, the key derivation algorithm is used to convert the calculation result B of the receiver and the extracted bit string c into a key k' for subsequent decryption operation. This operation can use any existing key derivation algorithm, such as the KDF algorithm in the national standard, which is not limited here.
[0134] Wherein, the second key k0 and the third key k1 are determined based on the first key vector s, the fifth vector B, and the fourth vector c according to a key reconciliation algorithm, the first data M0 and the second data M1 are encrypted by using the second key k0 and the third key k1 as the keys respectively by using an encryption algorithm, and the first encryption result e0 and the second encryption result e1 are sent to the receiver.
[0135] Specifically, the sender derives the keys k0, k1 by using the key reconciliation algorithm, wherein k0 = key reconciliation algorithm (2Bs, c), and k1 = key reconciliation algorithm (2(B-T)s, c). The key reconciliation algorithm includes two functions, one is a reconciliation function used for key extraction, and the other is a hash function used for deriving the key of the encryption function.
[0136] Wherein, the receiver can perform decryption operation on the first encryption result e0 and the second encryption result e1 according to the selection bit σ, and obtain the decryption result.
[0137] For example, in a specific implementation, the participants are divided into a sender and a receiver, the sender has two data M0, M1, and the receiver has a selection bit σ. The receiver obtains one of the sender's data according to the selection bit at the end of the protocol. Specifically, both parties determine public parameters, including the parameters of the polynomial ring, the distribution χ of the perturbation vector in the lattice, and the public random vector a. The sender randomly selects T, generates s, e from χ, calculates A = as + e, and then sends A, T to the receiver. The receiver generates s', e', e" from χ, then calculates b' = as' + e', and z = As' + e". Calculate c according to v through an extended extraction algorithm. If σ = 0, let B = b', if σ = 1, let B = b' + T, then send B, c to the sender. Then call the key derivation algorithm to generate the key k'. Here the key derivation algorithm contains two functions, one is a random double function that will expand the mode of the integer ring by multiplying the original two times, and the other is an integer cross function that will perform coefficient-by-coefficient calculation according to the formula The sender derives the keys k0, k1 through the key reconciliation algorithm, where k0 = key reconciliation algorithm (2Bs, c), k1 = key reconciliation algorithm (2(B-T)s, c). The key reconciliation algorithm contains two functions, a reconciliation function for key extraction, and a hash function for key derivation. The sender encrypts M0, M1 with k0, k1 as the keys through the encryption algorithm, and the results are denoted as e0, e1 and sent to the receiver. The receiver decrypts e0, e1 through the key k' to obtain the decrypted content. In this way, by selecting appropriate extended extraction, key derivation, and key reconciliation algorithms, the receiver can extract the information he wants.
[0138] It can be seen that the efficient post-quantum private set intersection method described in the embodiments of the present application is applied to a two-party computing system, the two-party computing system includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, an initial matrix is selected by the sender, a pseudo-random function key is selected, the initial matrix is updated according to column information of the first data set to obtain a first matrix, and the pseudo-random function key is sent to the receiver; the sender acts as an OT sender; an OT key is selected by the receiver; the receiver acts as an OT receiver; OT interaction is performed between the sender and the receiver by using a lattice-based basic OT algorithm to obtain a plurality of two-choice OTs; a random matrix is generated by the sender, a second matrix is determined according to the first matrix and the random matrix, and each column of the random matrix and the second matrix is taken as an input of each two-choice OT in the plurality of two-choice OTs to perform a plurality of two-choice OT operations; the receiver selects a bit string based on the OT key, and determines an OT result matrix based on the bit string, determines a second local column information based on column information of the second data set and the pseudo-random function key, determines a first private intersection judgment set based on the second local column information and the OT result matrix, and sends the first private intersection judgment set to the receiver; the receiver determines a first local column information based on column information of the first data set and the pseudo-random function key, determines a second private intersection judgment set based on the first local column information and the random matrix, and determines a target private intersection result based on the first private intersection judgment set and the second private intersection judgment set. Since the lattice-based basic OT algorithm is used for OT interaction, the security requirements of post-quantum can be met, stronger security protection is provided, and the resistance to quantum attack performance of the private intersection is improved.
[0139] Consistent with the above embodiments, please refer to Figure 3 , Figure 3 is a structural schematic diagram of an electronic device provided by the embodiments of the present application, as shown in the figure, the electronic device includes a processor, a memory, a communication interface and one or more programs, the above-mentioned one or more programs are stored in the above-mentioned memory and are configured to be executed by the above-mentioned processor, and are applied to a two-party computing system, the two-party computing system includes a sender and a receiver, the sender has a first data set, the receiver has a second data set, in the embodiments of the present application, the above-mentioned program includes instructions for executing the following steps:
[0140] The initial matrix is selected by the sender, the pseudo-random function key is selected, the initial matrix is updated according to the column information of the first data set to obtain the first matrix, and the pseudo-random function key is sent to the receiver; the sender acts as an OT sender;
[0141] The OT key is selected by the receiver; the receiver acts as an OT receiver;
[0142] The sender and the receiver use a basic OT algorithm based on a grid to perform OT interaction, thereby obtaining multiple two-choice OTs;
[0143] Generate a random matrix by the sender, determine a second matrix according to the first matrix and the random matrix, and use each column of the random matrix and the second matrix as input of each of the multiple two-choose-one OT operations to perform multiple two-choose-one OT operations;
[0144] The receiver selects a bit string based on the OT key, determines an OT result matrix using the bit string, determines second local column information using the column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set based on the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver;
[0145] The receiver determines first local column information using the column information of the first data set and the pseudo-random function key, determines a second privacy intersection judgment set based on the first local column information and the random matrix, and determines a target privacy intersection result based on the first privacy intersection judgment set and the second privacy intersection judgment set.
[0146] Optionally, in the aspect of determining, by the receiver, the first local column information using the column information of the first data set and the pseudo-random function key, the program includes instructions for performing the following steps:
[0147] Performing a first hash operation on the column information of the first data set by the receiver to obtain a first hash algorithm result;
[0148] The first local column information is determined according to the pseudo-random function key and the first hash algorithm result.
[0149] Optionally, in determining the second local column information using the column information of the second data set and the pseudo-random function key, the program includes instructions for performing the following steps:
[0150] Performing the first hash operation on the column information of the second data set to obtain a second hash algorithm result;
[0151] The second local column information is determined according to the pseudo-random function key and the second hash algorithm result.
[0152] Optionally, in determining the first privacy intersection judgment set according to the second local column information and the OT result matrix, the program includes instructions for executing the following steps:
[0153] performing intersection operation according to the second local column information and the OT result matrix to obtain a first initial privacy intersection judgment set;
[0154] performing second hash operation on the first initial privacy intersection judgment set to obtain the first privacy intersection judgment set.
[0155] Optionally, in the aspect of determining the second privacy intersection judgment set according to the first local column information and the random matrix, the program includes instructions for performing the following steps:
[0156] performing intersection operation according to the first local column information and the random matrix to obtain a second initial privacy intersection judgment set;
[0157] performing the second hash operation on the second initial privacy intersection judgment set to obtain the second privacy intersection judgment set.
[0158] Optionally, the sender has first data and second data, and the receiver has selection bits; the lattice-based OT algorithm includes the following processes:
[0159] determining common parameters by the sender and the receiver, the common parameters including distribution of perturbation vectors in a lattice, and a common random vector;
[0160] determining, by the sender, a random vector, determining a first key vector and a first perturbation vector according to the distribution of perturbation vectors in the lattice, determining a first vector according to the common random vector, the first key vector and the first perturbation vector, and sending the first vector and the random vector to the receiver;
[0161] generating, by the receiver, a second key vector, a second perturbation vector and a third perturbation vector from the distribution of perturbation vectors in the lattice, determining a second vector according to the common random vector, the second key vector and the second perturbation vector, determining a third vector according to the first vector, the second key vector and the third perturbation vector, and determining a fourth vector according to an expansion extraction algorithm based on the third vector;
[0162] determining, by the receiver, a fifth vector according to the selection bits and the random vector, and sending the fifth vector and the fourth vector to the sender;
[0163] determining a first key by the sender based on the fifth vector and the fourth vector by using a key derivation algorithm; determining a second key and a third key based on the first key vector, the fifth vector and the fourth vector according to a key reconciliation algorithm, encrypting the first data and the second data by an encryption algorithm respectively with the second key and the third key as keys to obtain a first encryption result and a second encryption result, and sending the first encryption result and the second encryption result to the receiver;
[0164] decrypting the first encryption result and the second encryption result according to the selected bits by the receiver to obtain a decryption result.
[0165] It can be seen that the electronic device described in the embodiments of the present application is applied to a two-party computing system, the two-party computing system includes a sender and a receiver, the sender has a first data set, and the receiver has a second data set, the sender selects an initial matrix, selects a pseudo-random function key, updates the initial matrix according to column information of the first data set to obtain a first matrix, and sends the pseudo-random function key to the receiver; the sender is an OT sender; the receiver selects an OT key; the receiver is an OT receiver; OT interaction is performed between the sender and the receiver by using a lattice-based basic OT algorithm to obtain a plurality of two-choice OTs; the sender generates a random matrix, determines a second matrix according to the first matrix and the random matrix, and takes each column of the random matrix and the second matrix as an input of each two-choice OT in the plurality of two-choice OTs to perform a plurality of two-choice OT operations; the receiver selects a bit string based on the OT key, determines an OT result matrix based on the bit string, determines second local column information based on column information of the second data set and the pseudo-random function key, determines a first privacy intersection judgment set based on the second local column information and the OT result matrix, and sends the first privacy intersection judgment set to the receiver; the receiver determines first local column information based on column information of the first data set and the pseudo-random function key, determines a second privacy intersection judgment set based on the first local column information and the random matrix, and determines a target privacy intersection result based on the first privacy intersection judgment set and the second privacy intersection judgment set, and since the OT interaction is performed by using the lattice-based basic OT algorithm, the security requirement of post-quantum can be met, stronger security protection is provided, and thus the resistance to quantum attack performance of the privacy intersection can be improved.
[0166] The embodiments of the present application also provide a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, the computer program causes a computer to execute part or all steps of any method described in the above method embodiments, and the computer includes the electronic device.
[0167] The embodiment of the present application further provides a computer program product, the computer program product comprising a non-transitory computer-readable storage medium storing a computer program, the computer program being operable to cause a computer to execute some or all of the steps of any of the methods described in the above method embodiments. The computer program product can be a software installation package, and the computer comprises an electronic device.
[0168] It should be noted that, for the above-mentioned method embodiments, in order to simply describe, they are all described as a combination of a series of actions, but those skilled in the art should know that the present application is not limited to the order of the actions described, because according to the present application, some steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions and modules involved are not necessarily necessary for the present application.
[0169] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.
[0170] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented by other means. For example, the device embodiments described above are only illustrative, for example, the division of the above units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical or other forms.
[0171] The units described as separate components above can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, some or all of the units can be selected to achieve the purpose of the embodiment.
[0172] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit.
[0173] If the above integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable memory. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the above-mentioned method of each embodiment of the present application. The aforementioned memory includes: a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0174] A person of ordinary skill in the art can understand that all or part of the steps in the above-mentioned embodiments can be completed by programs instructing relevant hardware, and the programs can be stored in a computer readable memory, which can include a flash disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0175] The embodiments of the present application are described in detail above, and the specific examples are applied to the principles and implementation modes of the present application. The above embodiment description is only used to help understand the method of the present application and its core idea; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation mode and application range will be changed; in summary, the content of the specification should not be understood as a limitation of the present application.
Claims
1. An efficient post-quantum private set intersection method, characterized in that, The method is applied to a two-party computing system including a sender and a receiver, the sender has a first data set, and the receiver has a second data set, and the method comprises the following steps: An initial matrix is selected by the sender, a pseudo-random function key is selected, the initial matrix is updated according to column information of the first data set to obtain a first matrix, and the pseudo-random function key is sent to the receiver; the sender acts as an OT sender; An OT key is selected by the receiver; the receiver acts as an OT receiver; OT interaction is performed between the sender and the receiver by using a lattice-based basic OT algorithm to obtain a plurality of two-choice OTs; A random matrix is generated by the sender, a second matrix is determined according to the first matrix and the random matrix, and each column of the random matrix and the second matrix is taken as an input of each two-choice OT in the plurality of two-choice OTs to perform a plurality of two-choice OT operations; A bit string is selected by the receiver based on the OT key, an OT result matrix is determined by the bit string, second local column information is determined by column information of the second data set and the pseudo-random function key, a first privacy intersection judgment set is determined according to the second local column information and the OT result matrix, and the first privacy intersection judgment set is sent to the receiver; First local column information is determined by the receiver according to column information of the first data set and the pseudo-random function key, second privacy intersection judgment sets are determined according to the first local column information and the random matrix, and a target privacy intersection result is determined according to the first privacy intersection judgment set and the second privacy intersection judgment set.
2. The method of claim 1, wherein, The first local column information is determined by the receiver according to the column information of the first data set and the pseudo-random function key, and comprises the following steps: A first hash operation is performed on the column information of the first data set by the receiver to obtain a first hash algorithm result; The first local column information is determined according to the pseudo-random function key and the first hash algorithm result.
3. The method of claim 2, wherein, The second local column information is determined according to the column information of the second data set and the pseudo-random function key, and comprises the following steps: The first hash operation is performed on the column information of the second data set to obtain a second hash algorithm result; The second local column information is determined according to the pseudo-random function key and the second hash algorithm result.
4. The method of claim 3, wherein, The first privacy intersection judgment set is determined according to the second local column information and the OT result matrix, and comprises the following steps: Intersection operation is performed on the second local column information and the OT result matrix to obtain a first initial privacy intersection judgment set; The first initial privacy intersection judgment set is subjected to a second hash operation to obtain the first privacy intersection judgment set.
5. The method of claim 4, wherein, The second privacy intersection judgment set is determined according to the first local column information and the random matrix, and comprises the following steps: Intersection operation is performed on the first local column information and the random matrix to obtain a second initial privacy intersection judgment set; The second initial privacy intersection judgment set is subjected to the second hash operation to obtain the second privacy intersection judgment set.
6. The method according to any one of claims 1 to 5, characterized in that, The sender owns first data and second data, and the receiver owns selection bits; the lattice-based basic OT algorithm includes the following processes: The sender and the receiver determine common parameters, which include: distribution of a perturbation vector in a lattice, and a common random vector; The sender determines a random vector, determines a first key vector and a first perturbation vector according to the distribution of the perturbation vector in the lattice, determines a first vector according to the common random vector, the first key vector and the first perturbation vector, and sends the first vector and the random vector to the receiver; The receiver generates a second key vector, a second perturbation vector and a third perturbation vector from the distribution of the perturbation vector in the lattice, determines a second vector according to the common random vector, the second key vector and the second perturbation vector, determines a third vector according to the first vector, the second key vector and the third perturbation vector, and determines a fourth vector according to an expansion extraction algorithm based on the third vector; The receiver determines a fifth vector according to the selection bits and the random vector, and sends the fifth vector and the fourth vector to the sender; The sender determines a first key based on the fifth vector and the fourth vector by using a key derivation algorithm, determines a second key and a third key according to a key reconciliation algorithm based on the first key vector, the fifth vector and the fourth vector, respectively encrypts the first data and the second data by using the second key and the third key as keys by using an encryption algorithm, obtains first and second encryption results, and sends the first and second encryption results to the receiver; The receiver decrypts the first and second encryption results according to the selection bits to obtain a decryption result.
7. A two-party computation system, characterized by The two-party computing system includes a sender and a receiver, the sender owns a first data set, and the receiver owns a second data set, wherein The sender is configured to select an initial matrix, select a pseudo-random function key, update the initial matrix according to column information of the first data set to obtain a first matrix, and send the pseudo-random function key to the receiver; and the sender is an OT sender. The receiver is configured to select an OT key; and the receiver is an OT receiver. The sender and the receiver are configured to perform OT interaction by using a lattice-based basic OT algorithm to obtain a plurality of binary OTs. The sender is configured to generate a random matrix, determine a second matrix according to the first matrix and the random matrix, and take each column of the random matrix and the second matrix as an input of each binary OT in the plurality of binary OTs to perform a plurality of binary OT operations. The receiver is configured to select a bit string based on the OT key, determine an OT result matrix based on the bit string, determine second local column information based on column information of the second data set and the pseudo-random function key, determine a first privacy intersection judgment set based on the second local column information and the OT result matrix, and send the first privacy intersection judgment set to the sender. The receiver is configured to determine first local column information based on column information of the first data set and the pseudo-random function key, determine a second privacy intersection judgment set based on the first local column information and the random matrix, and determine a target privacy intersection result based on the first privacy intersection judgment set and the second privacy intersection judgment set.
8. The system of claim 7, wherein, The receiver is configured to determine the first local column information based on the column information of the first data set and the pseudo-random function key. The receiver is configured to perform a first hash operation based on the column information of the first data set to obtain a first hash algorithm result. The receiver is configured to determine the first local column information based on the pseudo-random function key and the first hash algorithm result.
9. An electronic device, comprising: A computer program product for electronic data exchange, wherein the computer program product causes a computer to perform the method of any one of claims 1-6.
10. A computer-readable storage medium, characterized in that, A computer program product for electronic data exchange, wherein the computer program product causes a computer to perform the method of any one of claims 1-6.