Method and equipment for realizing privacy set intersection, storage medium and program product
By pre-generating and storing the power values involved in the interception of privacy sets, the problem of inefficient computing in traditional methods is solved, and a more efficient interception process and resource utilization of privacy sets is achieved.
Patent Information
- Application Number
- CN202510125534.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-27
AI Technical Summary
The traditional privacy set interchange scheme has insufficient computing efficiency and resource consumption, especially when the demander has a large amount of privacy set data, which will lead to huge computing and low efficiency.
By pre-generating the pre-calculated power values under the powers involved in the verification polynomial by pre-generating the demand-side data, the calculation process is completed in advance, so that these pre-calculated values are directly used during privacy interception calculations to avoid temporary calculations.
This method significantly saves calculation time, improves the processing efficiency of private set interception, and reduces the computing resource consumption of the demand side, so that the same pre-computed power value can be reused.
Smart Images

Figure CN120046191A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the technical field of privacy computing, and in particular, to a method, device, storage medium, and program product for implementing private set intersection. Background Art
[0002] Private Set Intersection (PSI) is a secure multi-party computing protocol whose purpose is to find the intersection of their respective sets among multiple participants without disclosing any additional information. This technology has extensive applications in fields such as data sharing, advertising targeting, and contact synchronization. For example, in medical research, different hospitals can use PSI to determine the common patient population without exposing specific patient information; in marketing, advertisers can find potential customer groups through PSI while protecting user privacy.
[0003] In traditional PSI schemes, the transmission of private set data between participants is an inevitable step. Even though encryption technology ensures the security and privacy of the data, this transmission still consumes a large amount of network bandwidth and computing resources. For this reason, a privacy intersection scheme based on verification polynomials has been proposed in related technologies: Assume A and B, who respectively maintain private sets Dset1 and Dset2. These sets may contain users' personal information, transaction records, or other sensitive data. If A needs to perform a private set intersection with B, then A is the requester and B is the responder. B can interpolate to generate a corresponding verification polynomial based on the private data in the private set Dset2, and inform A of the verification polynomial or its coefficients. A substitutes the private data in the private set Dset1 into the verification polynomial for calculation. If the calculation result after substituting a certain private data is 0, it indicates that this private data belongs to the intersection of the two. If the calculation result after substituting another private data is not 0, it indicates that this private data does not belong to the intersection of the two.
[0004] Assume the number of private data contained in Dset2 is n, then the verification polynomial generated by B can be represented as:
[0005]
[0006] It can be seen that this verification polynomial involves performing power operations 1 to n times for each private data. For A, when the number of private data contained in Dset1 is large, it will bring a huge amount of computation, resulting in low efficiency of private set intersection. Summary of the Invention
[0007] In view of this, this specification provides a method, device, storage medium, and program product for implementing private set intersection to solve the deficiencies in related technologies.
[0008] Specifically, the present specification is implemented through the following technical solutions:
[0009] According to the first aspect of the embodiments of the present specification, a method for implementing private set intersection is provided, which is applied to the requester; the method includes:
[0010] Determine the verification polynomial interpolated by the responder according to the responder's private set maintained by itself;
[0011] For each requester data corresponding to the requester's private set maintained by the requester, obtain the precomputed power values of the requester data at at least one power involved in the verification polynomial;
[0012] Calculate the corresponding values of each requester data in the verification polynomial according to the obtained precomputed power values, and determine the intersection between the requester's private set and the responder's private set according to the calculated values.
[0013] According to the second aspect of the embodiments of the present specification, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the steps of the method described in the first aspect are implemented.
[0014] According to the third aspect of the embodiments of the present specification, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the steps of the method described in the first aspect are implemented.
[0015] According to the fourth aspect of the embodiments of the present specification, a computer program product is provided, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the method described in the first aspect are implemented.
[0016] In the technical solutions provided in the present specification, for the requester data corresponding to the requester's private set, the requester pre-generates the precomputed power values of the requester data at at least one power, so that the calculation process for these power values is completed in advance, and there is no need to substitute the requester data into the verification polynomial for calculation during the private intersection calculation process, thereby saving the time required for temporarily calculating these power values and helping to improve the processing efficiency of private set intersection. At the same time, since the precomputed power value of the same requester data at a certain power is fixed and unchanged, the pre-generated precomputed power value can be repeatedly applied to different private intersection calculation processes related to the requester data, without repeating the calculation of the power value, thereby helping to reduce the computing resource consumption of the requester. Description of the Drawings
[0017] Figure 1It is a schematic flowchart of a method for implementing private set intersection shown in an exemplary embodiment of this specification;
[0018] Figure 2 It is an interaction schematic diagram of a private set intersection shown in an exemplary embodiment of this specification;
[0019] Figure 3 It is another interaction schematic diagram of a private set intersection shown in an exemplary embodiment of this specification;
[0020] Figure 4 It is a schematic structural diagram of an electronic device shown in an exemplary embodiment of this specification;
[0021] Figure 5 It is a schematic structural diagram of a device for implementing private set intersection shown in an exemplary embodiment of this specification. Detailed implementation manners
[0022] Figure 1 It is a schematic flowchart of a method for implementing private set intersection shown in an exemplary embodiment of this specification. As Figure 1 shown, this method is applied to the requester and may include the following steps:
[0023] Step 102, determine the verification polynomial generated by the responder through interpolation based on the responder's private set maintained by itself.
[0024] The requester and the responder respectively maintain their own private sets. For the sake of distinction, the private set maintained by the requester is called the requester's private set, and the private set maintained by the responder is called the responder's private set. Each private set contains one or more private data.
[0025] The requester can convey its own private intersection demand to the responder. For example, the requester can convey the above-mentioned private intersection demand by phone, email, instant messaging or in-person meeting, etc. For another example, if there are certain demand negotiation platforms, then the requester can convey the above-mentioned private intersection demand based on this negotiation platform. For example, after the requester sees the description information about the responder's private set published by the responder on this demand negotiation platform, the requester can request this demand negotiation platform to convey the private intersection demand to the responder. For another example, the requester can publish its own private intersection demand to this demand negotiation platform, so that the responder can view this private intersection demand on this demand negotiation platform.
[0026] In particular, the demand consultation platform can be built based on a blockchain system. Both the demand side and the response side need to publish their own information or convey messages to each other in the form of blockchain transactions on this platform, so that these information or messages can be stored on the blockchain. Among them, if it is necessary to use the blockchain system to convey messages, for example, if the demand side hopes to convey its privacy intersection demand, then the demand side can initiate a blockchain transaction to this platform and call the smart contract deployed on the chain, so that the smart contract can, according to the privacy intersection demand of the information of the response side contained in this blockchain transaction, transmit the privacy intersection demand to off-chain through the event mechanism for the response side to monitor and obtain. Further, the response side can initiate a blockchain transaction to this platform and call the above-mentioned smart contract to feedback its confirmation of this privacy intersection demand, thereby facilitating the private set intersection between the two parties.
[0027] The responder can generate a corresponding verification polynomial by interpolating the responder data corresponding to the responder's private set based on the PSI protocol in related technologies. For example, the PSI protocol adopted can include: the PSI protocol based on secret sharing proposed in the paper "Efficient Private Matching and Set Intersection", the PSI protocol based on homomorphic encryption proposed in the paper "Efficient and Secure Multi-party Computation on Untrusted Resources", the PSI protocol based on Oblivious Polynomial Evaluation (OPE) proposed in the paper "Improved OT Extension for Transferring Short Secrets", the PSI protocol based on polynomial interpolation and secret sharing proposed in the paper "Practical Secure Aggregation for Privacy-Preserving Machine Learning", the PSI protocol based on Lagrange interpolation proposed in the paper "Fast Private Set Intersection from Homomorphic Encryption", the SpOT protocol proposed in the paper "SpOT: Scalable Private Set Operations Technology", etc. This specification does not limit this.
[0028] For the responder, if the content of its responder privacy set remains unchanged, the corresponding verification polynomial can also remain unchanged. Therefore, the verification polynomial provided by the responder can be temporarily generated based on the requester's request or pre-generated. Of course, to avoid exposing privacy through the verification polynomial, for example, if the verification polynomial remains unchanged for a long time, it indicates that the responder privacy set itself has not changed, which may also be part of privacy. Therefore, the responder can change its verification polynomial regularly or irregularly according to its own settings.
[0029] When the responder provides its verification polynomial to the requester, it can directly provide the verification polynomial to the responder or only provide the coefficients of each term of the polynomial. This specification does not limit this. When transmitting information between the two, secure transmission can be achieved based on methods such as encrypted transmission.
[0030] Step 104: For each requester data corresponding to the requester privacy set maintained by the requester, obtain the precomputed power values of the requester data under at least one power involved in the verification polynomial.
[0031] Step 106: Calculate the corresponding values of each requester data in the verification polynomial based on the obtained precomputed power values, and determine the intersection between the requester privacy set and the responder privacy set according to the calculated values.
[0032] Since the responder generates the verification polynomial by interpolation, assuming that the responder privacy set corresponds to n responder data, then the verification polynomial can specifically contain n + 1 terms, and the i-th term corresponds to the i-th power of the independent variable, where i ∈ [0, n]. For the responder, the above n responder data are the roots of the verification polynomial. Only these roots can make the calculation result of the verification polynomial meet the preset conditions, such as the calculation result being 0, and the calculation results after substituting other values do not meet the preset conditions. Therefore, the requester can respectively determine the calculation results corresponding to each requester data: if it meets the preset conditions, it indicates that the corresponding requester data belongs to the intersection of the two; if it does not meet the preset conditions, it indicates that the corresponding requester data does not belong to the intersection of the two.
[0033] As Figure 2 shown, still taking A and B as an example. Assume that A maintains a privacy set Dset1 and B maintains a privacy set Dset2. If A hopes to perform an intersection of privacy sets for Dset1 and Dset2, then in this scenario: A is the requester, B is the responder, Dset1 is the requester privacy set, and Dset2 is the responder privacy set.
[0034] A can express its privacy intersection demand to B in the manner described above. If a consensus is reached between A and B, then B can provide the verification polynomial f B (x) generated based on Dset2 to A. Then, for each requester data corresponding to Dset1, A can respectively determine the calculation result of substituting it into the verification polynomial f B (x), and based on whether the calculation result meets the preset conditions, determine whether each requester data belongs to their intersection.
[0035] For example, the verification polynomial f B (x) can specifically be:
[0036]
[0037] Assume that the requester data corresponding to Dset1 includes x 1 、x 2 、……、x m , a total of m data. Taking x 1 as an example, if A substitutes it into the above polynomial f B (x), it specifically needs to involve calculating the second power, third power, ……, nth power of this data x 1 , that is, x 1 2 、x 1 3 、……、x 1 n . Each of the other data actually faces the same power operation requirements.
[0038] As can be seen from the above, the value of n is related to the set size of Dset2: when the set size is larger, that is, the number of responder data corresponding is more, the value of n is also larger. In fact, the value of n is the number of responder data corresponding to Dset2. Then, when the value of n is larger, for each requester data, the amount of computation required for the corresponding power operation is also larger, and the time-consuming is longer.
[0039] Since the power operation only involves each requester data itself, for each requester data, the power values of its respective powers actually remain unchanged. Therefore, this specification proposes to pre-calculate the power values of the requester data: for at least one requester data, the calculation of at least a part of its power values can be completed in advance before specifically determining its calculation result corresponding to the verification polynomial f B (x), and may even be completed in advance before A initiates the privacy intersection demand to B. Therefore, when obtaining the verification polynomial f BAfter (x), A doesn't need to perform temporary calculations on the corresponding power values, and only needs to directly substitute the pre-calculated power values.
[0040] Still taking x 1 as an example, if the pre-calculated power values x 1 2 = a 2 , x 1 3 = a 3 , ……, x 1 n = a n have been pre-calculated in advance, then when A calculates f B (x 1 ), in fact, it only needs to calculate b n *a n + b n-1 *a n-1 +… b 0 , without the need to temporarily calculate the power values x 1 2 , x 1 3 , ……, x 1 n etc., because these power values have been pre-calculated.
[0041] It can be seen that by generating the above pre-calculated power values in advance and storing these pre-calculated power values, the values of these pre-calculated power values can be directly used in the subsequent private intersection calculation process without temporarily calculating these power values. Moreover, the pre-calculated power values are not only applicable to a certain verification polynomial, but as long as the verification polynomial involves the corresponding power, this pre-calculated power value can also be reused, enabling the requester to obtain reusable pre-calculated power values by only performing one calculation, which can reduce the occupation of the requester's computing resources.
[0042] The pre-computed power values mentioned above can be generated by the requesting party independently of the responding party. Specifically, the requesting party can decide on its own which requesting party data to generate corresponding pre-computed power values for, and also decide which power values to generate for a particular piece of requesting party data. For example, pre-computed power values can be generated for all the requesting party data, or only for some of it. Another example is that if pre-computed power values need to be generated for a particular piece of requesting party data, a maximum power (such as k) can be determined, and then pre-computed power values for all powers not greater than this maximum power (such as the k-th power, (k - 1)-th power, …, 2nd power) can be generated, or only some pre-computed powers can be generated, and these can include values with relatively large computational amounts, for example, powers not less than a preset value (for instance, if the preset value is 500, then only the k-th power, (k - 1)-th power, …, 500th power are generated).
[0043] The generation of the pre-computed power values by the requesting party can be related to the responding party. For example, in the case of selecting the responding party as the object for private set intersection, the requesting party can determine the number of elements in the responding party's private set maintained by the responding party as the value of the estimated maximum power; and for each piece of requesting party data corresponding to the requesting party's private set, the requesting party can pre-compute its power values at at least one power not greater than the estimated maximum power as the pre-computed power values corresponding to this piece of requesting party data. For example, when it is determined that the number of elements in the responding party's private set (corresponding to its set size) is n = 1000, the value of the estimated maximum power can be determined to be 1000, and then pre-computed power values for all powers not greater than this maximum power (such as the 1000th power, 999th power, …, 2nd power) can be generated, or only some pre-computed powers can be generated, and these can include values with relatively large computational amounts, for example, powers not less than a preset value (for instance, if the preset value is 500, then only the 1000th power, 999th power, …, 500th power are generated).
[0044] The requester can achieve one-to-many private set intersection with multiple responders simultaneously. Assume the requester is A, and the responders are B, C, and D. This is equivalent to performing private set intersection between the private set of the requester maintained by A and the private sets of the responders maintained by B, C, and D respectively. Then, in the case where the number of responders is multiple, the requester can determine the number of elements in the private sets of the responders maintained by each of the multiple responders, and use the determined maximum number of elements as the value of the estimated highest power. For example, if the number of elements in the private sets of the responders maintained by B, C, and D are 1000, 1500, and 800 respectively, this means that the highest power in the verification polynomial generated by B is 1000, the highest power in the verification polynomial generated by C is 1500, and the highest power in the verification polynomial generated by D is 800. Then A can determine the maximum value of 1500 as the value of the estimated highest power, and generate precomputed power values accordingly. These precomputed power values can be applied to the verification polynomials generated by at least one of B, C, and D. For example, when the power corresponding to the precomputed power value is 1300, it is applicable to the verification polynomial generated by C; when the power corresponding to the precomputed power value is 900, it is applicable to the verification polynomials generated by B and C respectively; when the power corresponding to the precomputed power value is 500, it is applicable to the verification polynomials generated by B, C, and D respectively
[0045] When the requester generates precomputed power values for any requester data in advance, the power values of each power can be calculated in any order or manner, and this specification does not limit this. For example, the power values of each power of the any requester data can be generated one by one. Assume the determined estimated highest power is n, then for the requester data x 1 In the process of generating the corresponding 2 - n power, the x 1 2 、x 1 3 、……x 1 n can be generated one by one. For another example, the precomputed power values of the any requester data at some preset powers can be calculated by the dichotomy method, and then using the precomputed power values that have been calculated, the precomputed power values of the any requester data at the remaining preset powers can be calculated by the exponential scanning method. Still assume the determined estimated highest power is n, then for the requester data x 1 In the process of generating the corresponding 2 - n power, the x 1 2 、x 1 4 、x 1 8 、……、x 1 logn can be generated first by the dichotomy method, and then the remaining powers can be calculated by the exponential scanning method, such as x1 3 = x 1 * x 1 2 , x 1 19 = x 1 16 * x 1 2 * x 1 , and the other powers are not listed one by one.
[0046] In the embodiments described above, in some cases, it may cause the demander to involve one or more pre-computed power values that do not exist under one or more powers when determining the calculation result corresponding to the verification polynomial for one or more demander data. Then: if any demander data does not have a corresponding pre-computed power value under any power involved in the verification polynomial, the demander temporarily calculates the power value corresponding to the any demander data under the any power during the process of calculating the value corresponding to the any demander data in the verification polynomial; then, stores the temporarily calculated power value to add it as the newly added pre-computed power value corresponding to the any demander data. In this way, the demander can continuously accumulate the pre-computed power values stored by itself, and ensure that such temporarily calculated power values can be used as pre-computed power values in the calculation process of subsequent other verification polynomials, so that there is no need to perform temporary calculations again. Even more, from the very beginning, the demander may not specifically generate pre-computed power values in advance. When it first calculates the verification polynomial, it needs to temporarily calculate each power value, but through the accumulation in the above manner, the number of times of temporarily calculating power values can be gradually reduced during the subsequent calculation of the verification polynomial. Of course, if the demander specifically generates pre-computed power values in advance from the very beginning, then starting from the first calculation of the verification polynomial, efficient private set intersection can be achieved based on the pre-computed power values.
[0047] As mentioned above, the verification polynomial is generated by interpolating the responder data corresponding to the responder's private set, and the demander brings the demander data corresponding to the demander's private set into the verification polynomial to obtain the calculation result to verify whether it belongs to the intersection. In one embodiment, the responder data corresponding to the responder's private set may be the original responder data contained in the responder's private set, that is, the private data itself maintained by the responder; correspondingly, the demander data corresponding to the demander's private set may be the original demander data contained in the demander's private set, that is, the private data itself maintained by the demander. For example, in Figure 2 the embodiment shown, B directly generates the verification polynomial f based on the private data contained in the private set Dset2 B(x), and A directly substitutes and calculates based on the private data contained in the private set Dset1 of privacy to obtain the intersection. In another embodiment, in the case where the verification polynomial is generated by interpolating the blinded responder data obtained by performing a preset blinding process on the original responder data contained in the responder's private set of privacy, the requester data corresponding to the requester's private set of privacy is obtained by performing the preset blinding process on the original requester data contained in the requester's private set of privacy. For example, in the embodiment shown in Figure 3 , B first performs a blinding process on the private data in the private set Dset2 to obtain a secure private set Enc-Dset2 whose elements are all blinded responder data, and then generates a verification polynomial f B (x), and A needs to adopt the same blinding process scheme. First, perform a blinding process on the private data in the private set Dset1 to obtain a secure private set Enc-Dset1 whose elements are all blinded requester data, and then substitute and calculate based on the private data contained in this secure private set Enc-Dset1 to obtain the intersection. Through the blinding process, the hiding and protection of the corresponding private data can be improved, which helps to further enhance the security of private set intersection. Among them, there are many ways of blinding process, such as homomorphic encryption, hash calculation, etc., and this specification does not limit this.
[0048] As mentioned above, the requester may perform one-to-many private set intersection for multiple responders. In one embodiment, the requester may only need to determine the intersections between the requester's private set of privacy and each responder's private set of privacy respectively, then each intersection can be obtained through the foregoing method. In another embodiment, the requester needs to perform multi-party private intersection with these multiple responders, that is, determine the global intersection between the requester's private set of privacy and each responder's private set of privacy. Then, the requester can obtain the intersections between the requester's private set of privacy and each responder's private set of privacy maintained by these multiple responders respectively through the foregoing method, and then perform an intersection operation on the obtained multiple intersections to obtain the global intersection between the requester's private set of privacy and each responder's private set of privacy maintained by these multiple responders.
[0049] It should be noted that: regarding the requester and responder involved in this specification, in some contexts, they represent the holders of the corresponding private sets of privacy, while in other contexts, especially when referring to processing steps, they represent the processing devices corresponding to the corresponding holders. Those skilled in the art clearly understand this and can make a clear distinction according to the actual situation.
[0050] In summary, in the technical solution provided in this specification, for the requester data corresponding to the requester's private set, the requester pre-generates pre-computed power values at at least one power, so that the calculation process for this part of the power values is completed in advance, without temporarily substituting the requester data into the verification polynomial during the private set intersection calculation process, thereby saving the time required for temporarily calculating this part of the power values and helping to improve the processing efficiency of private set intersection. At the same time, since the pre-computed power value of the same requester data at a certain power is fixed and unchanged, the pre-generated pre-computed power value can be repeatedly applied to different private set intersection calculation processes related to the requester data, without repeating the calculation of the power value, thereby helping to reduce the computing resource consumption of the requester.
[0051] Figure 4 is a schematic structural diagram of an electronic device in an exemplary embodiment. Please refer to Figure 4 , at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, it may also include other required hardware. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a device for hiding the recipient address or verifying the transaction attribution at the logical level. Of course, in addition to the software implementation method, this specification does not exclude other implementation methods, such as logical devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logical unit, and can also be hardware or logical devices.
[0052] Corresponding to the foregoing embodiments of the method for implementing private set intersection, this specification also provides an embodiment of a device for implementing private set intersection.
[0053] Please refer to Figure 5 , the device is applied to the requester; the device may include:
[0054] A polynomial determination unit 501 that determines a verification polynomial interpolated by the responder according to the responder's private set maintained by itself;
[0055] A power value acquisition unit 502 that, for each requester data corresponding to the requester's private set maintained by the requester, acquires a pre-computed power value of the requester data at at least one power involved in the verification polynomial;
[0056] An intersection determination unit 503 that calculates the corresponding values of each requester data in the verification polynomial according to the acquired pre-computed power values, and determines the intersection between the requester's private set and the responder's private set according to the calculated values.
[0057] Optionally, it further includes:
[0058] A quantity determination unit 504, when selecting the responder as the object of private set intersection, determines the number of elements in the responder's private set maintained by the responder as the value of the estimated highest power.
[0059] A pre-computation unit 505 pre-computes the power values of each requester data corresponding to the requester's private set at at least one power not greater than the estimated highest power as the pre-computed power values corresponding to the requester data.
[0060] Optionally, the quantity determination unit 504 is specifically configured to:
[0061] If there are multiple responders, determine the number of elements in the private sets of the responders maintained by each of the multiple responders;
[0062] Take the determined maximum number of elements as the value of the estimated highest power.
[0063] Optionally, it further includes:
[0064] A temporary calculation unit 506, if there is no corresponding pre-computed power value for any requester data at any power involved in the verification polynomial, temporarily calculates the power value corresponding to the any requester data at the any power during the process of calculating the value corresponding to the any requester data in the verification polynomial;
[0065] A storage unit 507 stores the temporarily calculated power values to add them as the newly added pre-computed power values corresponding to the any requester data.
[0066] Optionally, when the verification polynomial is generated by interpolating the blinded responder data obtained by performing a preset blinding process on the original responder data contained in the responder's private set, the requester data corresponding to the requester's private set is obtained by performing the preset blinding process on the original requester data contained in the requester's private set.
[0067] Optionally, the pre-computed power values of any requester data at each preset power are calculated by the following method:
[0068] Calculate the pre-computed power values of the any requester data at some preset powers by the bisection method;
[0069] Use the already calculated pre-computed power values to calculate the pre-computed power values of the any requester data at the remaining preset powers by the exponential scanning method.
[0070] Optionally, the intersection determination unit 503 is specifically configured to:
[0071] When the number of the responding parties is multiple and the demanding party needs to perform multi-party private set intersection with the multiple responding parties, obtain the intersection between the private set of the demanding party and the private sets of the respective responding parties maintained by the multiple responding parties;
[0072] Perform intersection on the obtained multiple intersections to obtain the global intersection between the private set of the demanding party and the private sets of the respective responding parties maintained by the multiple responding parties.
[0073] The implementation processes of the functions and roles of the respective units in the above device are specifically detailed in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.
[0074] Based on the same concept as the above method, this specification also provides an electronic device, including: a processor; a memory for storing processor-executable instructions; wherein, the processor runs the executable instructions to implement the steps of the method as described in any one of the above embodiments.
[0075] Based on the same concept as the above method, this specification also provides a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method as described in any one of the above embodiments are implemented.
[0076] Based on the same concept as the above method, this specification also provides a computer program product, including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the method as described in any one of the above embodiments are implemented.
Claims
1. A method for implementing private set intersection, applied to a demand side; the method comprises: Determine a verification polynomial generated by interpolation based on the responder's privacy set maintained by the responder; For each demand side data corresponding to the demand side privacy set maintained by the demand side, obtaining a pre-calculated power value of the demand side data under at least one power involved in the verification polynomial; The corresponding value of each demander's data in the verification polynomial is calculated according to the obtained pre-calculated power value, and the intersection between the demander's privacy set and the responder's privacy set is determined according to the calculated value.
2. The method according to claim 1, further comprising: In the case where the responder is selected as the object of the privacy set intersection, the number of elements of the responder privacy set maintained by the responder is determined as the value of the estimated highest power; For each demand-side data corresponding to the demand-side privacy set, pre-calculate its power value at at least one power not greater than the estimated highest power as the pre-calculated power value corresponding to the demand-side data.
3. The method according to claim 2, wherein, when the responder is selected as the object for intersection of privacy sets, determining the number of elements of the responder privacy set maintained by the responder as the value of the estimated highest power comprises: If there are multiple responders, determine the number of elements of the responder privacy set maintained by each of the multiple responders; The determined maximum number of elements is used as the value of the estimated highest power.
4. The method according to claim 1, further comprising: If there is no corresponding pre-calculated power value for any demand-side data under any power involved in the verification polynomial, then in the process of calculating the corresponding value of any demand-side data in the verification polynomial, temporarily calculate the power value corresponding to any demand-side data under the any power; The temporarily calculated power value is stored to be added as a newly added pre-calculated power value corresponding to any demand-side data.
5. According to the method of claim 1, when the verification polynomial is generated by interpolating the blinded responder data obtained by subjecting the original responder data contained in the responder privacy set to a preset blinding process, the demander data corresponding to the demander privacy set is obtained by subjecting the original demander data contained in the demander privacy set to the preset blinding process.
6. The method according to claim 1, wherein the pre-calculated power value of any demand-side data at each preset power is calculated in the following manner: Calculate the pre-calculated power value of any demand-side data in some preset powers by binary division; The calculated pre-calculated power values are used to calculate the pre-calculated power values of any demand-side data at the remaining preset powers through an exponential scanning method.
7. According to the method of claim 1, the step of determining the intersection between the privacy set of the demander and the privacy set of the responder according to the calculated values comprises: In the case where there are multiple responders and the demander needs to perform multi-party privacy intersection with the multiple responders, obtaining the intersection between the demander privacy set and the privacy sets of each responder maintained by the multiple responders respectively; The obtained multiple intersections are intersected to obtain a global intersection between the demander privacy set and the privacy sets of each responder maintained by the multiple responders.
8. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any method according to claim 1 when executing the program.
9. A computer-readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the steps of the method according to any one of claims 1 to 7.
10. A computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 7.