Extreme and extreme value secrecy calculation method for keyword numerical value sum in cross-chain data exchange
By using the fully homomorphic NTRU encryption algorithm and adding obfuscated elements in cross-chain data exchange, the most value confidential computing protocol for the corresponding elements of the set intersection is designed, which solves the problem of quantum computing attacks in cross-chain interactions and realizes the protection and security enhancement of data privacy.
Patent Information
- Application Number
- CN202510177839.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-02-18
AI Technical Summary
The prior art cannot effectively resist quantum computing attacks during cross-chain interaction, resulting in the most value calculation process of the corresponding numerical sum of keywords.
Using a fully homomorphic NTRU encryption algorithm and the method of adding obfuscated elements, a most value confidential computing protocol for the sum of the corresponding elements of the set intersection under the semi-honest model and the malicious model is designed, and the privacy and security of the calculation process are ensured through a hash function and a public key encryption algorithm.
It realizes the ability to protect data privacy in cross-chain data exchange, enhances security during cross-chain interaction, and can resist malicious adversary attacks and quantum computing attacks.
Smart Images

Figure CN120105455A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a data confidentiality calculation method in cross-chain data exchange. Background Art
[0002] As a decentralized distributed ledger technology, blockchain technology has the characteristics of being tamper-proof, transparent, and secure. With the development of blockchain technology, more and more industries are benefiting from it, driving digital transformation and innovation in the fields of finance, commerce, and healthcare. Although blockchain has significant advantages, different blockchain platforms often use different technologies, consensus mechanisms, and protocol standards, which leads to an "island" effect between blockchains. To solve this problem, cross-chain technology can achieve interoperability between different blockchains. Cross-chain technology is not only about achieving the exchange of assets and data, but also involves the processing, analysis, and calculation of data in cross-chain interactions. In particular, when transferring data between multiple chains, it is inevitable to calculate a specific value as a result.
[0003] In cross-chain interaction, when the calculated specific value is the maximum value of the sum of the associated values corresponding to the keyword, the problem can be transformed into a confidential calculation problem of the maximum value of the sum of the elements corresponding to the intersection of sets. For example, in the joint risk control analysis of finance, two financial institutions, Institution A and Institution B, each owns the data of user loan information. In order to protect data privacy and security, the two institutions respectively build private chains A and B, and upload all users' loan information in the form of encrypted tuple data pairs, such as (ID number, loan amount), to the selected blockchain platform with the help of smart contracts. Under this framework, the two institutions expect to calculate the maximum and minimum amount of the total loan amount of common customers as an important basis for assessing credit risk. To achieve this goal, cross-chain technology is used to realize data transmission, and calculations are performed after receiving the data. Finally, Institution A and Institution B can securely query the required calculation results through the interfaces on their respective chains.
[0004] In essence, the logical core of the process is to confidentially calculate the maximum value of the sum of the elements corresponding to the intersection of two sets. The private chains maintained by institutions A and B can be regarded as two independent sets A and B, and the user loan data stored in the form of tuple data pairs by the two institutions are the elements in the sets. The process of determining whether the two institutions have common customers is essentially the process of solving whether the element keywords in the two sets have an intersection without a full set. If there is an intersection, the associated values corresponding to the intersecting keywords are added, and the maximum and minimum values are generated from it.
[0005] The input data in the above process includes sensitive information such as the user's identity information and amount. If the plaintext data is operated directly or appropriate privacy protection measures are not taken, attackers may infer the user's transaction amount, asset status and other information by monitoring the calculation results and intermediate processes. Data leakage will bring serious privacy protection risks.
[0006] Therefore, in order to protect the privacy of data participants, secure multi-party computing (MPC) has emerged on demand, aiming to enable multiple participants to perform calculations and share data without leaking sensitive information by using technical means such as cryptography and protocol design. MPC was first proposed by YAO and then developed under the research of Goldreich. MPC has been recognized and applied in many aspects such as cloud computing, the Internet of Things, privacy-preserving data mining, and electronic auctions, providing an effective solution for achieving data cooperation, protecting data privacy, and meeting legal requirements.
[0007] "Blockchain-enabled multiparty computation for privacy preserving and public audit in industrial IoT" proposes an MPC framework for implementing privacy protection and public audit in industrial IoT by combining MPC and blockchain technology. "A decentralized private data marketplace using blockchain and secure multi-party computation" provides users with a trusted data transaction solution by applying MPC to blockchain, preventing malicious behavior and supporting privacy protection. "Secure distributed medical record storage using blockchain and emergency sharing using multi-party computation" proposes a secure distributed medical record storage and emergency sharing system based on blockchain and MPC technology. Although there are many research schemes for privacy computing of sets in blockchain, most of the protocols are proposed under the semi-honest model and do not consider the maximum value of the sum of the elements corresponding to the intersection of sets. There is no maximum value confidentiality computing protocol for the sum of the elements corresponding to the intersection of sets that can resist malicious adversary attacks and quantum computing attacks, and it is impossible to ensure the security of the maximum value computing process of the sum of the values corresponding to the keywords in the cross-chain interaction process. Summary of the invention
[0008] The present invention aims to solve the problem that there is currently no method for confidentially calculating the maximum value of the sum of elements corresponding to the intersection of sets that can resist quantum computing attacks, and there is a problem that the security of the maximum value calculation process of the sum of numerical values corresponding to keywords cannot be guaranteed during the cross-chain interaction process.
[0009] A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange. The two parties who need to perform confidentiality calculation in cross-chain data exchange are recorded as Alice and Bob. Assume that Alice has the set Bob owns the set in, and is a set of keywords, and is a set of associated values, l 1 and l 2 Represents the number of elements in a set; Alice and Bob perform confidential computations, including the following steps:
[0010] S1. Alice adds l 3 Keywords and associated values (j i ,0),i=1,2,…,l 3 ,get
[0011] S2, Bob adds l 4 Keywords and associated values (p t ,0),t=1,2,…,l 4 ,get
[0012] S3. Alice substitutes the key in the set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key to obtain Will be in The elements of are randomly permuted and sent to Bob;
[0013] Based on pk 1 The ciphertext generated by encryption using the fully homomorphic NTRU encryption algorithm; Alice uses the fully homomorphic NTRU encryption algorithm to calculate f 1 、h 1 That is the corresponding private key pk 1 、Public key pk 1 ;
[0014] S4. Bob substitutes the key words in the set N' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain After randomly replacing it, send it to Alice;
[0015] Based on pk 2 The ciphertext generated by encryption using the fully homomorphic NTRU encryption algorithm; Bob uses the fully homomorphic NTRU encryption algorithm to calculate f 2 、h 2 That is the corresponding private key sk 2 、Public key pk 2 ;
[0016] S5. If Alice finds that the keyword hash value of the obfuscated element in M' is the same as the hash value sent by Bob, she will Hash(j) except for this obfuscated element. a )=Hash(p b ) position and the associated value ciphertext corresponding to the position in N' are added to obtain
[0017] S6. If Bob finds that the keyword hash value of the obfuscated element in N' is the same as the hash value sent by Alice, he will Hash(p b )=Hash(j a ) position and the ciphertext of the associated value corresponding to the position in M' are added to obtain
[0018] S7. If Alice and Bob find that Hash(j a )=Hash(p b ), end; otherwise continue execution;
[0019] S8. Alice selects a random number r 1 ,r 2 ,r 3 ,r 4 ,calculate K 1 Send to Bob;
[0020] S9. Bob selects a random number r' 1 ,r' 2 ,r' 3 ,r' 4 ,calculate K 2 Send to Alice;
[0021] S10, if K 1 With K 2 The number of ciphertexts is not equal, terminate; if K 1 With K 2 If the number of ciphertexts is equal, continue to execute;
[0022] S11. Alice decrypts K 2 , find the maximum number and the smallest number And send it to Bob;
[0023] S12. Bob decrypts K 1 , find the maximum number and the smallest number And send it to Alice;
[0024] S13. After Alice receives the maximum and minimum numbers, she performs the following operations:
[0025]
[0026] Get 1 and d' 1 are the maximum and minimum values of the sum of the corresponding elements of the set intersection respectively; if d 1 and d' 1 If it is not an integer, terminate;
[0027] S14. After receiving the maximum and minimum numbers, Bob performs the following operations:
[0028]
[0029] Get 2 and d' 2 are the maximum and minimum values of the sum of the corresponding elements of the set intersection respectively; if d 2 and d' 2 If it is not an integer, terminate;
[0030] S15, for d 1 and d 2 , d' 1 and d' 2 , Alice chooses 4m random polynomials and Bob chooses 4m random polynomials and Where w = 1,…,m, and calculate:
[0031]
[0032] Announced separately
[0033] S16, Alice from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Bob to publish the corresponding Alice uses Bob's public key h 2 verify If the verification passes, proceed to the next step, otherwise stop;
[0034] p is the encryption parameter in the fully homomorphic NTRU encryption algorithm;
[0035] S17, Bob from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Alice to publish the corresponding Bob uses Alice's public key h 1 ,verify If the verification passes, proceed to the next step, otherwise stop;
[0036] S18, Alice and Bob each take the remaining and Randomly select one and From the remaining and Randomly select one and Alice chooses a random polynomial r' x1 , r″ x1 , r' x2 , r″ x2 ; Bob selects a random polynomial r' y1 , r″ y1 , r' y2 , r″ y2 ; then do the following:
[0037] Alice uses Bob's public key h 2 calculate:
[0038] c x'3 =h 2 r′ x1 +pr″ x1 +d 1
[0039] c x'4 =h 2 r′ x2 +pr″ x2 +d′ 1
[0040] Then calculate T 1 ,calculate T 2 , Alice changes T1 and T 2 Send to Bob;
[0041] Bob uses Alice's public key h 1 calculate:
[0042] c y'3 =h 1 r y1 +pry″ 1 +d 2
[0043] c y'4 =h 1 r′ y2 +pr″ y2 +d′ 2
[0044] Then calculate Denoted as G 1 ,calculate Denoted as G 2 , Bob will G 1 and G 2 Send to Alice;
[0045] S19, Alice gets G 1 and G 2 Then, using the private key f 1 , decrypt G 1 and G 2 , and get d 1 +d 2 , d' 1 +d' 2 When d 1 +d 2 =2d 1 , d' 1 +d' 2 =2d' 1 When d 2 =d 1 , d' 2 =d' 1 ; Otherwise, Bob is a malicious participant;
[0046] S20, Bob gets T 1 and T 2 Then, use your own private key f 2 , decrypt T 1 and T 2 , and get d 2 +d 1 , d' 2 +d' 1 ; When d 2 +d 1 =2d2 , d' 2 +d' 1 =2d' 2 When d 1 =d 2 , d' 1 =d' 2 ; Otherwise, Alice is a malicious participant.
[0047] Furthermore, Alice adds l 3 Keywords and associated values (j i ,0), the set is satisfied Bob adds l 4 Keywords and associated values (p t ,0), the set is satisfied
[0048] Furthermore, in step S10, if Bob finds that K 1 With K 2 If the number of ciphertexts is not equal, Alice is a malicious participant; otherwise, Bob is a malicious participant.
[0049] Furthermore, in step S13, if d 1 and d' 1 If it is not an integer, Bob is a malicious participant.
[0050] Furthermore, in step S14, if d 2 and d' 2 If it is not an integer, Alice is a malicious party.
[0051] Furthermore, when stopping in step S16, Bob is a malicious participant.
[0052] Further, when stopping in step S17, Alice is a malicious participant.
[0053] A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange. The two parties who need to perform confidentiality calculation in cross-chain data exchange are recorded as Alice and Bob. Assume that Alice has the set Bob owns the set in, and is a set of keywords, and is a set of associated values, l 1 and l 2 Represents the number of elements in a set; Alice and Bob perform confidential computations, including the following steps:
[0054] Step 1. Alice randomly adds l3 Confusion elements (j i ,0),i=1,2,…,l 3 ,get Confusion elements (j i ,0) in i is the keyword, and 0 is the associated value corresponding to the keyword;
[0055] Step 2: Bob randomly adds l 4 Confusion elements (p t ,0),t=1,2,…,l 4 ,get Confusing elements (p t ,0) in p t is the keyword, and 0 is the associated value corresponding to the keyword;
[0056] Step 3: Alice substitutes the key in set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key to obtain Will The elements in are randomly permuted and sent to Bob;
[0057] E(·) is the ciphertext generated by encryption using the fully homomorphic NTRU encryption algorithm;
[0058] Step 4. Bob substitutes the keywords in the set N' into the hash function Hash(x). If he finds that the keyword hash value of the obfuscated element is equal to a hash value sent by Alice, he does not perform any operation on the associated value of this obfuscated element. He substitutes the keywords in the set N' into the hash function Hash(x). b )=Hash(j a ) The associated value v corresponding to the position b Encrypt and add the ciphertext of the associated value at the corresponding position in M' to obtain E(u a )+E(v b );
[0059] Step 5. Bob chooses a random number r 1 ,r 2 ,r 3 ,r 4 ,calculate And send K to Alice;
[0060] Step 6: Alice decrypts K and finds the maximum number and the smallest number And send it to Bob;
[0061] Step 7. After receiving the maximum and minimum numbers, Bob performs the following operations:
[0062]
[0063] Get 1 and d' 1 , respectively, the maximum and minimum values of the corresponding elements and of the set intersection;
[0064] Step 7. Bob gets d 1 and d' 1 After that, d 1 and d' 1 Send to Alice.
[0065] Furthermore, Alice randomly adds l 3 Confusion elements (j i ,0), the set is satisfied Bob randomly adds l 4 Confusion elements (p t ,0), the set is satisfied
[0066] Beneficial effects:
[0067] In blockchain, privacy protection of the maximum value calculation of the sum of the corresponding values of keywords in cross-chain data exchange is a crucial issue. To address this issue, the present invention makes the following contributions:
[0068] (1) The problem of calculating the maximum value of the sum of the numerical values corresponding to keywords in cross-chain data exchange is transformed into the problem of calculating the maximum value of the sum of the elements corresponding to the intersection of sets in a confidential manner without a full set. The secure multi-party computing technology is used to protect data privacy, thereby enhancing the security of the cross-chain interaction process.
[0069] (2) For the case where there is no complete set of sets, based on the fully homomorphic NTRU encryption algorithm, a confidential calculation protocol for the maximum value of the sum of the elements corresponding to the intersection of sets under a semi-honest model is designed by adding confusing elements. The malicious behaviors that may appear in the semi-honest model protocol are analyzed, and a confidential calculation protocol for the maximum value of the sum of the elements corresponding to the intersection of sets under a malicious model is designed by using the split-selection method, which further transforms the problem into the socialist millionaire problem. The correctness of the protocol is analyzed, and the security of the protocol is proved using an ideal-actual example. This is also one of the few MPC protocols that can resist both malicious adversary attacks and quantum computing attacks.
[0070] (3) Performance comparison with existing solutions shows that the protocols under the two models proposed in the present invention can simultaneously find the maximum and minimum values of the sum of elements corresponding to the intersection of sets while protecting private data and set potential. After adding and subtracting the maximum and minimum numbers in the protocol, it can also be used as a protocol for simultaneously finding the extreme difference and extreme sum of the sum of elements corresponding to the intersection of sets. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] Figure 1 Schematic diagram of the interaction performed in the confidential calculation of the maximum value of the keyword value and in cross-chain data exchange under the semi-honest model.
[0072] Figure 2 Schematic diagram of the interaction performed in the confidential calculation of the maximum value of keyword values and in cross-chain data exchange under the malicious model. DETAILED DESCRIPTION
[0073] The present invention designs a maximum confidentiality calculation protocol for the sum of the elements corresponding to the intersection of sets that can resist both malicious adversary attacks and quantum computing attacks without a full set, effectively improving the security of the maximum calculation process of the sum of the values corresponding to keywords during cross-chain interactions. Before describing the specific implementation methods in detail, the cryptographic knowledge required for the present invention is first described.
[0074] Security of malicious models:
[0075] The attacker in the malicious model is active. Not only does the malicious attacker not abide by the protocol, but he may also adopt various strategies to undermine the security of the protocol. Generally speaking, if a protocol can resist attacks from malicious adversaries, it can also resist potential threats in the semi-honest model.
[0076] Foundations of cryptography: volume 2, basic applications provides a generally accepted definition of security under malicious models, which requires the use of an ideal protocol of a trusted third party (TTP): Assume that P 1 and P 2 With data m' and n', function f(m',n') = (f 1 (m',n'),f 2 (m',n')) is calculated by TTP. After the protocol is executed, P 1 and P 2 Get f without revealing m' and n' 1 (m',n') and f 2 (m',n'). The protocol process can be described as:
[0077] (1) Honest participants will send the correct m' and n' to TTP, while malicious participants may not participate in the protocol execution or send false data m" or n" to TTP.
[0078] (2) After TTP obtains (m',n'), it calculates f(m',n') and converts f 1 (m',n') is sent to P 1 .
[0079] (3) If P1 For malicious participants, they may receive 1 (m',n') and then the protocol is terminated. At this time, TTP gives P 2 Send a symbol ⊥ (indicates termination), otherwise give P 2 Send f 2 (m',n').
[0080] The ideal protocol is the safest protocol because participants can obtain the result f from TTP in addition to i If the actual protocol has the same security as the ideal protocol, then the actual protocol is secure.
[0081] Let F:{0,1} * ×{0,1} * →{0,1} * ×{0,1} * is a probabilistic polynomial time function, F 1 (m',n'),F 2 (m',n') represents the first and second elements of F(m',n'). A pair of probabilistic polynomial-time algorithms that represent the strategies of participants in an ideal protocol. In the ideal model, participants use auxiliary information z and strategies The process of jointly calculating F(m',n') is recorded as The malicious participant selects a random number r, let:
[0082]
[0083] Where γ(m',n',z,r) is defined as follows:
[0084] If P 1 is an honest participant, then:
[0085] γ(m′,n′,z,r)=(f 1 (m′,n″),B 2 (n′,z,r,f 2 (m′,n″))).
[0086] Where n" = B 2 (n',z,r).
[0087] If P 2 is an honest participant, then:
[0088]
[0089] Where m” = B 1 (m',z,r).
[0090] Let Π be a two-party protocol for computing F, A pair of probabilistic polynomial-time algorithms representing the strategies of the players in the realistic model. REAL Π,A(z) (m',n') is defined as A 1 (m',z) and A 2 The output pairs generated by the interaction between (n',z) are based on the strategy Execute the process of Π in the actual model, and z is the auxiliary input.
[0091] Definition 1: Security of the protocol under the malicious model (ideal-practical paradigm)
[0092] If any acceptable In the ideal agreement, acceptable So that the following is true:
[0093]
[0094] This shows that Π can safely calculate F.
[0095] When executing a protocol under a malicious model, one of the participants must be honest, otherwise a secure protocol cannot be designed.
[0096] NTRU encryption algorithm:
[0097] The NTRU encryption algorithm was proposed by Hoffstein, Pipher, and Silverman in 1998. A significant advantage of this algorithm is that its encryption and decryption speed is very fast. It uses truncated polynomial rings for data processing and reduces the computational complexity by optimizing the algorithm structure. In addition, the NTRU encryption algorithm relies on the shortest vector problem (SVP) on the lattice, rather than the traditional discrete logarithm or large number decomposition problem, which enables it to effectively resist quantum computing attacks and is one of the best algorithms in post-quantum encryption algorithms. By optimizing the key generation process, etc., the following NTRU encryption algorithm can be obtained, and its main steps are:
[0098] (1) Parameter setting
[0099] Choose a safety parameter λ, a sufficiently large standard deviation σ, n = n(λ), q = q(λ)∈R q , in, YesR q The set of reversible elements in R q =R / qR=Zq [ x] / Φ.
[0100] (2) Key Generation
[0101] From discrete Gaussian distribution Take polynomials f' and g, if Then reselect g. Let f=p*f'+1, if Then reselect f. Let f be the private key sk and h be the public key pk.
[0102] (3) Encryption
[0103] Randomly select polynomials s and e from the B(λ) bound distribution χ, encrypt the plaintext m, and get the ciphertext c∈R:
[0104] c=hs+pe+m.
[0105] (4) Decryption
[0106] Decrypt using private key f:
[0107] m=fc(mpdp).
[0108] Fully homomorphic NTRU encryption algorithm:
[0109] The fully homomorphic NTRU encryption algorithm has the following main steps:
[0110] (1) Parameter setting
[0111] Choose a safety parameter λ, a sufficiently large standard deviation σ, n = n(λ), q = q(λ)∈R q , in, YesR q The set of reversible elements in R q =R / qR=Z q [x] / Φ.
[0112] (2) Key Generation
[0113] From discrete Gaussian distribution Take polynomials f' and g, if Then reselect g. Let f=p*f'+1, if Then reselect f. Let f be the private key sk and h be the public key pk.
[0114] (3) Encryption
[0115] Using the NTRU encryption algorithm to encrypt 0, we get a vector of ciphertext 0 with a length of l = logq:
[0116] c=(c l-1 ,c l-2 ,…,c 0 ).
[0117] Use BitDecomp to convert c into an l×l matrix C:
[0118]
[0119] Using the Flattening technique, calculate C' = Flatten (I l ·m+C).
[0120] The BitDecomp function decomposes a data element into its bit representation, and the Flatten function converts a multi-layer or nested data structure into a single, continuous layer or linear structure. i =hs i +pe i +0,s i and e i is a polynomial randomly chosen from the B(λ) bounded distribution χ. is a binary polynomial, I l is the l×l unit matrix, and C' is the ciphertext matrix of plaintext m.
[0121] (4) Decryption
[0122] Utilizing BitDecomp -1 The function calculates the last row of the matrix C' (recovery vector) and then recovers the plaintext m:
[0123] BitDecomp -1 (C' (0,l-1) ,C' (0,l-2) ,…,C' (0,0) )=C 0 .
[0124]
[0125] Full homomorphism of the scheme: Assume that the plaintext m 1 and m 2 The corresponding ciphertext matrix is C' 1 and C' 2 , then C' 3 = Flatten(C' 1 +C' 2 ), C' 4 = Flatten(C' 1 ·C' 2 ). Using the decryption algorithm, we can get the plaintext m 1 +m 2 and m 1 ·m 2 .
[0126] Add obfuscation element method:
[0127] Adding obfuscation elements means inserting some non-real, randomly generated or pseudo-randomly generated elements into the original set. These obfuscation elements are similar to real elements in format and structure, but the information they contain is irrelevant or random. The number of obfuscation elements should be determined based on security requirements and available resources. Too many obfuscation elements may increase the complexity and overhead of the MPC protocol, while too few obfuscation elements may not be enough to provide sufficient security. In this way, it is difficult for malicious attackers to distinguish real elements from obfuscated elements in the set, thereby increasing the confidentiality and privacy of the data.
[0128] Next, the present invention will be described in detail in conjunction with the specific implementation example 1. The symbols and their meanings in the method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange are shown in Table 1:
[0129] Table 1 Protocol symbol table
[0130]
[0131] Association value: The data stored in the chain is in the form of data pairs, and the keywords correspond to the corresponding association values, indicating a measurement of association. Specific implementation method one:
[0133] The method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange described in this embodiment is a method for calculating the maximum confidentiality of the sum of elements corresponding to the intersection of sets under a semi-honest model. The two parties who need to perform confidentiality calculation in cross-chain data exchange are denoted as Alice and Bob. Assume that Alice has the set Bob owns the set here and is a set of keywords, and is a set of associated values, l 1 and l 2 Represents the number of elements in a set (the number of data pairs in M and N), and confidentially calculates the maximum and minimum values of the sum of the associated values corresponding to the same keyword in sets M and N without revealing the data and potential of both sets.
[0134] Alice and Bob protect the potential of the set by adding confusing elements. Alice executes the fully homomorphic NTRU encryption algorithm, encrypts the associated value, and sends the public key to Bob. Both parties confirm the intersection by calculating the hash value of the keyword. Bob uses the public key to encrypt the associated value corresponding to the keyword that forms the intersection, and calculates the sum of the associated values in the ciphertext state. Using the fully homomorphic nature of the encryption algorithm, he adds a random number and sends it to Alice. Alice then decrypts the ciphertext and Bob recovers the final result.
[0135] like Figure 1 As shown, the method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange described in this embodiment includes the following steps:
[0136] Protocol 1: Confidential calculation protocol for the maximum value of the sum of the corresponding elements of the set intersection under the semi-honest model:
[0137] Input: Alice inputs a set Bob inputs the set
[0138] Output: F max (M,N)=max(u a +v b )(j b =p b ), F min (M,N)=min(u a +vb ) (j a =p b ).
[0139] Preparation stage:
[0140] (a) Execute the fully homomorphic NTRU encryption algorithm. Alice selects polynomials f' and g, and then calculates f = p*f' + 1, using f as the private key sk. Alice calculates the public key pk: h = pgf -1 , and send h to Bob.
[0141] The encryption algorithms used subsequently are all fully homomorphic NTRU encryption algorithms.
[0142] (b) Alice and Bob jointly agree on a hash function Hash(x).
[0143] The protocol begins:
[0144] Step 1. Alice randomly adds l 3 Confusion elements (j i ,0),i=1,2,…,l 3 ,get Confusion elements (j x ,0) in i is the keyword, and 0 is the associated value corresponding to the keyword.
[0145] Step 2: Bob randomly adds l 4 Confusion elements (p t ,0),t=1,2,…,l 4 ,get
[0146] Step 3: Alice substitutes the key in set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key to obtain Will The elements in are randomly permuted and sent to Bob.
[0147] E(·) is the ciphertext generated by encryption using the encryption algorithm based on the secret key pk;
[0148] Step 4: Bob substitutes the keywords in set N' into the hash function Hash(x). If he finds that the keyword hash value of the obfuscated element is equal to a hash value sent by Alice, he does not perform any operation on the associated value of this obfuscated element. b )=Hash(j a ) The associated value v corresponding to the position b Encrypt and add the ciphertext of the associated value at the corresponding position in M' to obtain E(u a )+E(v b ). If Hash(p b )=Hash(j a ), the agreement ends.
[0149] Step 5. Bob chooses a random number r 1 ,r 2 ,r 3 ,r 4 (r1,r 2 >0), calculate And send K to Alice.
[0150] Step 6: Alice uses the private key sk to decrypt K and find the maximum number and the smallest number And send it to Bob.
[0151] Step 7. After receiving the maximum and minimum numbers, Bob performs the following operations:
[0152]
[0153] Get 1 and d' 1 , respectively, the maximum and minimum values of the corresponding elements and of the intersection of the sets, that is, F max (M,N) and F min (M,N).
[0154] Step 8. Bob will maximize d 1 and minimum value d' 1 Send to Alice.
[0155] Protocol 1 ends.
[0156] Correctness analysis:
[0157] (1) In this protocol, the method of adding obfuscated elements may cause the obfuscated elements to intersect with the obfuscated elements added by the other party, and the obfuscated elements to intersect with the data elements of the set. The use of hash functions enables both parties to the protocol to determine whether the above-mentioned intersection exists under the premise of protecting the potential of the set, thereby ensuring the correctness of the maximum value result.
[0158] (2) In step 4 of the protocol, according to the additive homomorphism of the encryption scheme, we have E pk (u a )+E pk (v b )=E pk (u a +v b ), ensuring that the maximum and minimum values only appear in E pk (u a +v b ) in the decryption result.
[0159] (3) The method of adding random numbers ensures that Alice cannot pk (u a +v b ) decryption result to infer the private data in Bob's set. The added random number makes u a +v b The value of is proportionally enlarged, so the maximum and minimum numbers that Alice sends to Bob after decryption correspond to the maximum and minimum values obtained by Bob after restoring the data.
[0160] (4) Alice cannot infer the random number added by Bob from the known maximum number, minimum number, maximum value and minimum value, because the number of unknown numbers is much larger than the number of equations that can be solved for the unknown numbers.
[0161] In summary, Protocol 1 can correctly calculate the maximum and minimum values of the sum of elements corresponding to the intersection of sets during execution, without leaking other set data and set potential.
[0162] Safety Proof:
[0163] Theorem 1 Protocol 1 (denoted as Π 1 ) is safe under the semi-honest model.
[0164] Prove that using the simulation example method, construct a simulator S 1 and S 2 To prove Theorem 1. In Protocol 1:
[0165]
[0166] {N,R 2 ,R 3 ,H 1 ,H 2 ,E(M 1 ),E(N 1 ),E(N 2 ),D max ,D min ,F max2 (M,N),F min 2(M,N)}.
[0167]
[0168] Among them, M and N are the inputs of both parties, R 1 and R 2 are the random polynomial sets selected by both parties during encryption, R 3 is a set of random numbers selected by Bob, H 1 and H 2 are the hash value sets obtained by both parties after substituting the keywords in the set into the hash function, and D max and D min is the maximum and minimum number Alice sends to Bob, K is the set of ciphertexts Bob sends to Alice after adding random numbers for homomorphic operations, is the ciphertext set obtained by Alice after encrypting the associated value corresponding to the keyword, E(N 1 ) is Bob's answer to Hash(p b )=Hash(j a ) The associated value v corresponding to the position b The encrypted ciphertext set, E(N 2 )=E(u a +v b ) is the Hash(p) calculated by Bob b )=Hash(j a ) The result set after adding the ciphertext of the associated value corresponding to the position, F max1 (M,N),F min1 (M,N) and F max2 (M,N),F min2 (M, N) are the output results received by Alice and Bob respectively.
[0169] First, construct the simulator S 1 simulation To prove the security of Bob, S 1 The simulation process is as follows:
[0170] (1)S 1 Receive(M,F max1 (M,N),F min1 (M,N)) as Alice's input, randomly add l to the set M 3 The confusion elements are obtained by set M'. According to F max1 (M,N),F min1 (M,N) value, select any set Randomly add l' to the set N' 4 The confusion elements are collected
[0171] (2)S 1 Substitute the keywords in the set M' into the hash function Hash(x), and encrypt the associated value corresponding to the keyword to obtain Substitute the keywords in the set N" into the hash function Hash(x) and convert Hash(j a )=Hash(p' b ) position, and add the associated value ciphertext corresponding to the position to obtain E(u a +v' b ).
[0172] (3)S 1 Select r' 1 ,r' 2 ,r' 3 ,r' 4 (r' 1 ,r' 2 >0), and calculate
[0173] (4)S 1 Decrypt K' to get the maximum number and the smallest number
[0174] (5)S 1 After getting the maximum and minimum numbers, execute:
[0175]
[0176] Get the maximum value d″ 1 and the minimum value d″′ 1 According to the above construction process, we can know that F max1 (M,N)=F max1 (M,N”), F min1 (M,N)=F min1 (M,N″).
[0177] because:
[0178]
[0179] S 1 (M,F max1 (M,N),F min1 (M,N))={M,R 1 ,K′,F max1 (M,N″),F min1 (M,N″)}.
[0180] K' is the ciphertext after Bob performs homomorphic operation by adding random numbers. Alice can decrypt it, but cannot deduce the data before the homomorphic operation. So Because F max1 (M,N)=F max1 (M,N”), F min1 (M,N)=F min1 (M,N”), so that the following equation holds:
[0181]
[0182] Similarly, construct the simulator S 2 simulation To prove the security of Alice, the following equation is true:
[0183]
[0184] In summary, Theorem 1 holds and Protocol 1 is secure. Specific implementation method 2:
[0186] The method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange described in this embodiment is a method for calculating the maximum confidentiality of the sum of elements corresponding to the intersection of sets under a malicious model.
[0187] In protocol 1, possible malicious behaviors include:
[0188] (1) Alice has both the public key and private key of the fully homomorphic NTRU encryption algorithm, while Bob only has the public key. This means that the decryption operation in step 6 of the protocol can only be completed by Alice, and Bob can only passively receive the maximum and minimum numbers informed by Alice, which lacks fairness for Bob.
[0189] (2) In step 3 and step 5, Alice may not send the correct hash value and ciphertext information to Bob, and Bob may not send the correct ciphertext information to Alice. This situation is unavoidable and will not be considered.
[0190] (3) In step 6, Alice may not send the correct maximum and minimum numbers after decryption to Bob.
[0191] (4) Step 8: Bob already knows the correct maximum and minimum values, but may not send them to Alice. At this point, Alice will not get the result or will receive an incorrect result.
[0192] In response to the above malicious behavior, the following solution is proposed: Alice and Bob simultaneously execute the fully homomorphic NTRU encryption algorithm to generate public keys and private keys, and separately calculate the maximum and minimum values of the corresponding elements of the intersection of the sets in secret. Then, the split-selection method is used to transform the problem into the socialist millionaire problem, and finally the correctness of the result is jointly verified.
[0193] The process of confidential calculation of the maximum value of the sum of the corresponding elements of the set intersection under the malicious model is as follows: Figure 2 shown.
[0194] Protocol 2: Confidential calculation protocol for the maximum value of the sum of the corresponding elements of the set intersection under the malicious model:
[0195] Input: Alice inputs a set Bob inputs the set
[0196] Output: F max (M,N)=max(u a +v b )(j a =p b ), F min (M,N)=min(u a +v b )(j a =p b ).
[0197] Preparation stage:
[0198] (1) Execute the fully homomorphic NTRU encryption algorithm, Alice chooses the polynomial f' 1 , g 1 , calculate f 1 =p*f' 1 +1,h 1 =pg 1 f' 1 , f 1 As the private key sk 1 , h 1 As the public key pk 1 and sends it to Bob. Bob chooses the polynomial f' 2 , g 2 , calculate f 2 =p*f'2 +1,h 2 =pg 2 f' 2 , f 2 As the private key sk 2 , h 2 As the public key pk 2 And send it to Alice.
[0199] (2) Alice and Bob jointly agree on a hash function Hash(x).
[0200] The protocol begins:
[0201] S1. Alice adds l 3 Keywords and associated values (j i ,0)(i=1,2,…,l 3 ),get
[0202] S2, Bob adds l 4 Keywords and associated values (p t ,0)(t=1,2,…,l 4 ),get
[0203] S3. Alice substitutes the key in the set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key to obtain Randomly permute it and send it to Bob.
[0204] Based on the secret key pk 1 The ciphertext generated by encryption using a fully homomorphic encryption algorithm.
[0205] S4. Bob substitutes the key words in the set N' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain After randomly replacing it, send it to Alice.
[0206] Based on the secret key pk 2 The ciphertext generated by encryption using a fully homomorphic encryption algorithm.
[0207] S5. If Alice finds that the keyword hash value of the obfuscated element in M' is the same as the hash value sent by Bob, she will Hash(j) except for this obfuscated element. a )=Hash(p b ) position and the associated value ciphertext corresponding to the position in N' are added to obtain
[0208] S6. If Bob finds that the keyword hash value of the obfuscated element in N' is the same as the hash value sent by Alice, he will Hash(p b )=Hash(j a ) position and the ciphertext of the associated value corresponding to the position in M' are added to obtain
[0209] S7. If Alice and Bob find that Hash(j a )=Hash(p b ), the protocol ends. Otherwise, the protocol continues.
[0210] S8. Alice selects a random number r 1 ,r 2 ,r 3 ,r 4 (r 1 ,r 2 >0), calculate K 1 Send to Bob.
[0211] S9. Bob selects a random number r' 1 ,r' 2 ,r' 3 ,r' 4 (r' 1 ,r' 2 >0), calculate K 2 Send to Alice.
[0212] S10, if Bob finds K 1 With K 2 If the number of ciphertexts is not equal, Alice is a malicious participant. Otherwise, Bob is a malicious participant and the protocol terminates. 1 With K 2 If the number of ciphertexts is equal, the protocol continues.
[0213] S11. Alice uses private key sk 1 Decrypt K 2 , find the maximum number and the smallest number And send it to Bob.
[0214] S12. Bob uses private key sk 2 Decrypt K 1 , find the maximum number and the smallest number And send it to Alice.
[0215] S13. After Alice receives the maximum and minimum numbers, she performs the following operations:
[0216]
[0217] Get 1 and d' 1 are the maximum and minimum values of the sum of the corresponding elements of the set intersection. 1 and d' 1 If it is not an integer, Bob is a malicious participant and the protocol is terminated.
[0218] S14. After receiving the maximum and minimum numbers, Bob performs the following operations:
[0219]
[0220] Get 2 and d' 2 are the maximum and minimum values of the sum of the corresponding elements of the set intersection. 2 and d' 2 If it is not an integer, Alice is a malicious participant and the protocol is terminated.
[0221] S15, for d 1 and d 2 , d' 1 and d' 2 , Alice chooses 4m random polynomials and Bob chooses 4m random polynomials and Where w = 1,…,m, and calculate:
[0222]
[0223] Announced separately
[0224] m is the amount of data used in an arbitrary split-selection method.
[0225] S16. Using the split-selection method, Alice selects m from the group Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Bob to publish the corresponding Alice uses Bob's public key h 2 verify If the verification passes, the next step is executed, otherwise the protocol is stopped and Bob is a malicious participant.
[0226] S17, Bob from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Alice to publish the corresponding Bob uses Alice's public key h 1 ,verify If the verification passes, the next step is executed, otherwise the protocol is stopped and Alice is a malicious participant.
[0227] S18, Alice and Bob each take the remaining and Randomly select one and From the remaining and Randomly select one and Alice chooses a random polynomial r' x1 , r″ x1 , r' x2 , r″ x2 . Bob selects a random polynomial r' y1 , r″ y1 , r' y2 , r″ y2 . Then do the following:
[0228] Alice uses Bob's public key h 2 calculate:
[0229] c x'3 =h 2 r′ x1 +pr″ x1 +d 1
[0230] c x'4 =h 2 r′ x2 +pr″ x2 +d′ 1
[0231] Then calculate T 1 ,calculate T 2 , Alice changes T 1 and T 2 Send to Bob.
[0232] Bob uses Alice's public key h 1 calculate:
[0233] c y'3 =h 1 r′ y1 +pr″ y1 +d 2 .
[0234] c y'4 =h 1 r′ y2 +pr″ y2 +d 2 .
[0235] Then calculate Denoted as G 1 ,calculate Denoted as G 2 , Bob will G 1 and G 2 Send to Alice.
[0236] S19, Alice gets G 1 and G 2 Then, using the private key f 1 , decrypt G 1 and G 2 , and get d 1 +d 2 , d' 1 +d' 2 When d 1 +d 2 =2d 1 , d' 1 +d' 2 =2d' 1 When d 2 =d 1 , d' 2 =d' 1 . Otherwise, Bob is a malicious participant.
[0237] S20, Bob gets T 1 and T 2 Then, use your own private key f 2 , decrypt T 1 and T 2 , and get d 2 +d 1 , d' 2 +d' 1 When d 2 +d 1 =2d 2 , d' 2 +d' 1 =2d' 2 When d 1 =d 2 , d'1 =d' 2 . Otherwise, Alice is a malicious participant.
[0238] S21, Alice and Bob output the maximum and minimum values.
[0239] End of Protocol 2.
[0240] Correctness analysis:
[0241] (1) Regarding the processing of keywords in a set, the first-primordial property of a hash function shows that for a calculated hash value k, it is difficult to find its original input x within a reasonable time, so that Hash(x) = k. Therefore, in this protocol, if there is a keyword j a =p b , we will get Hash(j a )=Hash(p b ). From the anti-second-primitive property of the hash function, we know that for the input value x 1 , it is difficult to find another different input value x in a reasonable time 2 So that Hash(x 1 )=Hash(x 2 ). So for this protocol, there exists Hash(j a )=Hash(p b )But a ≠p b However, in the actual implementation of the protocol, this probability is so small that it can be scientifically ignored and safely assumed that when Hash(j a )=Hash(p b ),j a =p b .
[0242] (2) Regarding the processing of associated values in a set, the fully homomorphic NTRU encryption algorithm ensures that for any computation on the ciphertext, the decrypted result is equal to the result of the corresponding computation on the plaintext. 1 ,u 1 =2), (p 1 ,v 1 =4), r β =2(β=1,…,4) as an example, for u 1 ,v 1 The encryption and homomorphic operation process is as follows:
[0243] 2[E(2)+E(4)+E(2)] 2 +E(2)=2[E(8)×E(8)]+E(2)=E(64)+E(64)+E(2)=E(130).
[0244] Therefore, the process of removing the random number and restoring the data after decryption will definitely find the maximum and minimum values.
[0245] (3) Steps S1-S14 are mainly for Alice and Bob to calculate the maximum and minimum values of the sum of the corresponding elements of the set intersection. The correctness analysis of this process is the same as the specific implementation method, and will not leak private information.
[0246] (4) Steps S15 to S20 have transformed the problem of calculating the maximum value of the sum of the elements corresponding to the intersection of sets into the Socialist Millionaire Problem, which has correctness and security under the malicious model.
[0247] (5) Steps S16 to S20 use a split-select method to determine whether there are malicious participants. Both parties use the public key to verify data integrity, thus avoiding the occurrence of unfairness. From a probabilistic perspective, as long as the selection of both parties is random and the number of selected subsets is large enough, the probability of hiding malicious operations on unselected subsets without being discovered is very small.
[0248] Safety Proof:
[0249] Theorem 2 Protocol 2 (denoted as Π 2 ) is safe under malicious models.
[0250] Analysis of Protocol 2 Steps S1-S14 are that Alice and Bob each secretly calculate the maximum and minimum values and convert d 1 ,d 2 , d' 1 , d' 2 The problem was then transformed into the socialist millionaire problem (i.e., d 1 Is it equal to d 2 , d' 1 Is it equal to d' 2 ), and finally jointly verify the result. Therefore, the security after step S14 of the protocol will be proved.
[0251] In this process, Alice must meet a series of conditions to successfully perform malicious operations: First, in step S15, and does not meet the requirements. Secondly, it is not discovered in the verification process of step S17. Finally, it is selected by Bob in step S18. Only when these conditions are met at the same time can Bob reach a wrong conclusion. However, Alice cannot obtain any information about Bob because the G obtained in step S18 is 1 and G 2There is no solution for Alice. Similarly, Bob cannot obtain any private information about Alice, so Protocol 2 is secure. The security of the protocol is demonstrated by an ideal-practical example.
[0252] Proof: According to the above security definition, at least one of the two parties in the agreement is honest, so the proof is divided into two cases.
[0253] Case 1: A 1 Honesty, A. 2 It is malicious.
[0254] In the execution 2 When:
[0255]
[0256] In an ideal model, if an acceptable strategy can be found Output and The calculation is indistinguishable, then B 2 The strategy and A 2 The strategy is consistent.
[0257] (1) In the ideal model, A 1 Honesty 1 Also honest, so B 1 Send the correct d to TTP 1 and d' 1 .
[0258] (2)B 2 D 2 and d' 2 Send to A 2 , from A 2 Get Π 2 In actual implementation process A 2 Privacy Information 2 (d 2 ) and A 2 (d' 2 ).
[0259] (3)B 2 Send A to TTP 2 (d 2 ) and A 2 (d' 2 ), B 2 and B 1 From TTP, we can get F(d 1 ,A 2 (d 2 )) and F(d' 1 ,A 2 (d'2 )).
[0260] (4)B 2 Get F(d 1 ,A 2 (d 2 )) and F(d' 1 ,A 2 (d' 2 ))After that, try to get a Π 2 In actual execution, 2 What you get and Computationally indistinguishable and And put and Give it to A 2 , get A 2 Output.
[0261] Simulator B 2 Randomly select d″ 1 and d″′ 1 , so that F(d″ 1 ,A 2 (d 2 ))=F(d 1 ,A 2 (d 2 )), F(d″′ 1 ,A 2 (d' 2 ))=F(d' 1 ,A 2 (d' 2 )), with d″ 1 and d″′ 1 Simulation protocol, simulator B 2 The execution process is as follows:
[0262] (1)B 2 Execute 2 , send Π 2 Step S15 and Give A 2 .
[0263] (2)A 2 In Π 2 Step S16: After the information is published, 2 to verify.
[0264] (3)B 2 In Π 2 Step S17: Publish A 2 Request for release of information.
[0265] (4)B 2 In Π 2 Step S18, select information from the remaining groups and calculate T' 1 and T' 2 And announce it.
[0266] In simulator B 2 Execute 2 When , we can get:
[0267]
[0268] In the protocol steps S15-S18, for A 2 For example, because they all use the fully homomorphic NTRU encryption algorithm, Then the following formula holds:
[0269]
[0270] Case 2: A 1 It's malicious, 2 honest.
[0271] At this time, execute 2 There are two situations:
[0272] (1) When A 1 When TTP is no longer considered, TTP gives A 2 Send the symbol ⊥, then:
[0273]
[0274] (2) If A 1 Announcement, TTP to A 2 Send a message, at this time:
[0275]
[0276] In an ideal model, if an acceptable strategy can be found Output and and The calculation is indistinguishable, then B 1 The strategy and A 1 The strategy is consistent, so according to A 1 (d 1 ) and A 1 (d' 1 ) to verify the protocol.
[0277] (1) Dishonest B 1 Send input information A to TTP 1 (d 1 ) and A1 (d' 1 ).
[0278] (2) Honest B 2 Send real input information to TTP 2 and d' 2 .
[0279] (3) TTP obtains input information (A 1 (d 1 ),d 2 ) and (A 1 (d' 1 ),d' 2 ), calculate F(A 1 (d 1 ),d 2 ) and F(A 1 (d' 1 ),d' 2 ).
[0280] (4)B 1 Obtain F(A) from TTP 1 (d 1 ),d 2 ) and F(A 1 (d' 1 ),d' 2 ) and then try to get an agreement with the actual implementation, 1 What you get and Computationally indistinguishable and And put and Give it to A 1 , get A 1 Output.
[0281] Simulator B 1 Randomly select d″ 2 and d″' 2 , so that F(A 1 (d 1 ),d″ 2 )=F(A 1 (d 1 ),d 2 ), F(A 1 (d 1 ),d″' 2 )=F(A 1 (d 1 ),d' 2 ). 2 and d″' 2 Simulation protocol, simulator B1 The execution process is as follows:
[0282] (1)B 1 Execute 2 , send Π 2 In step S15 and Give A 1 .
[0283] (2)B 1 In Π 2 Step S16 publishes A 1 Request for release of information.
[0284] (3)A 1 In Π 2 Step S17: After the information is published, 1 to verify.
[0285] (4)B 1 In Π 2 Step S18, select information from the remaining groups and calculate G' 1 and G' 2 And announce it.
[0286] In simulator B 1 Execute 2 When , the following two situations can be obtained:
[0287] (1) When A 1 When TTP is no longer considered (A 1 Termination Agreement), there are:
[0288]
[0289] (2) If the news continues to be released, there will be:
[0290]
[0291] In the protocol steps S15 to S18, for A 1 For example, because they all use the fully homomorphic NTRU encryption algorithm, Then the following formula holds:
[0292]
[0293] According to the above proof, the strategy in the actual model Under the ideal model, an acceptable strategy pair can be found. So the computation is indistinguishable, so Theorem 2 holds, Π 2 Safety.
[0294] Protocol efficiency analysis:
[0295] A. Computational complexity analysis:
[0296] In order to facilitate comparative analysis, the main modular exponential operation M e and polynomial multiplication M k The total number of times is taken as the key indicator for evaluating the computational complexity, and other operations involved are neglected here.
[0297] Protocol 2 in "Securely Computing Protocol of Set Intersection under the Malicious Model" uses the Paillier encryption algorithm (encryption requires 2 modular exponential operations, decryption requires 1 modular exponential operation) to encrypt and decrypt data, a total of 4mQ encryption times and 2Q decryption times, so the computational complexity is [(8m+2)Q]M e Where Q is the number of elements in the set, and m is the amount of split-selection data. Protocol 2 in "Secret Computation of the Sum of Intersection Elements of Sets" uses the Paillier encryption algorithm to encrypt and decrypt data. The protocol encrypts 2 (l 2 +l 4 )+l 1 Second, decrypt l 1 (l 2 +l 4 )+1 times, so the computational complexity is [(l 1 +4)(l 2 +l 4 )+2l 1 +1]M e Protocol 2 of "Securely Compute the Maximum Sum of Corresponding Elements of Intersection" uses the Paillier encryption algorithm to encrypt and decrypt plaintext. Second, decrypt times, so the computational complexity is
[0298] The protocol of the present invention uses the fully homomorphic NTRU encryption algorithm (encryption requires logq polynomial multiplication operations, decryption requires 1 polynomial multiplication operation). Protocol 1 performs a total of Second encryption operation and decryption operations, so the computational complexity is Protocol 2 is performed during execution 1 +l 2 +l 3 +l 4 +4m+4 encryption operations and decryption operations, so the computational complexity is Among them, l 1 and l 2 is the number of set elements owned by both parties to the agreement, l 3 and l 4 The number of obfuscation elements added for both parties of the agreement.
[0299] B. Communication complexity analysis:
[0300] In secure multi-party computing protocols, the number of communication rounds is usually used to measure the complexity of communication. In the "Securely Computing Protocol of Set Intersection under the Malicious Model", Protocol 2 requires 5 rounds of communication in the process of calculating the intersection of sets. In the "Confidential Computation of the Sum of the Elements of Set Intersection", Protocol 2 requires 3 rounds of communication in the process of calculating the sum of the associated values of the elements of the intersection of sets. In the "Confidential Computation of the Maximum Sum of the Corresponding Elements of the Intersection", Protocol 2 requires 4 rounds of communication in the process of calculating the maximum value of the sum of the corresponding elements of the intersection of sets. Protocol 1 of the present invention requires 3 rounds of communication in the process of exchanging homomorphic operation results and ciphertext. In order to improve the security of the protocol, Protocol 2 requires the participating parties to jointly execute the protocol and introduces a split-select verification process, with 7 communication rounds.
[0301] C. Performance comparison:
[0302] The detailed performance comparison is shown in Table 2:
[0303] Table 2 Performance comparison
[0304]
[0305]
[0306] The references [1] to [3] in the table above correspond to "Securely Computing Protocol of Set Intersection under the Malicious Model", "Secure Computation of the Sum of Set Intersection Elements", and "Secure Computation of the Maximum Sum of Corresponding Elements of Intersection". e M is the modular exponential operation. k is a polynomial multiplication operation, m is the amount of split-selection data, Q is the number of elements in the full set, l 1 and l 2 is the number of set elements owned by both parties to the agreement, l 3 and l 4 The number of obfuscation elements added for both parties of the agreement.
[0307] The comparative analysis results in Table 2 show that the protocols of the present invention are all constructed without a full set. The efficiency of Protocol 1 is significantly improved compared to the protocol efficiency in the literature, and it can resist quantum computing attacks, but it cannot resist attacks from malicious adversaries. Although Protocol 2 has increased communication complexity due to the use of the split-selection method, the encryption and decryption process does not require encryption of keywords, and there is no need to determine the intersection through subtraction operations of keyword ciphertexts, thereby reducing the computational complexity and showing obvious advantages over the comparison protocols. In particular, compared with Protocol 2 of the "Securely Computing Protocol of Set Intersection under the Malicious Model" under the same malicious model, the efficiency is significantly improved. Protocol 2 of the present invention not only enhances the ability to resist malicious adversary attacks and quantum computing attacks, but also has a wider range of applications with higher security, and has higher application value and potential.
[0308] The present invention transforms the problem of calculating the maximum value of the sum of numerical values corresponding to keywords in cross-chain data exchange into the problem of calculating the maximum value of the sum of elements corresponding to the intersection of sets in a confidential manner, and can provide valuable information for many fields such as finance, medical care, and archive management under the premise of protecting data privacy. Based on the fully homomorphic NTRU encryption algorithm, the present invention proposes a confidential calculation protocol for the maximum value of the sum of elements corresponding to the intersection of sets under two models, semi-honest and malicious. The protocol under the malicious model avoids the emergence of unfairness and can resist both malicious adversary attacks and quantum computing attacks. The security of the protocol is demonstrated using an ideal-actual example, and the efficiency of the protocol is analyzed through complexity analysis and experimental simulation. The proposed protocol has high practicality and has important research significance in strengthening the security of cross-chain data exchange and the application of secure multi-party computing in blockchain.
[0309] The present invention may also have many other embodiments. Without departing from the spirit and essence of the present invention, those skilled in the art may make various corresponding changes and modifications based on the present invention, but these corresponding changes and modifications should all fall within the scope of protection of the claims attached to the present invention.
Claims
1. A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange, characterized by: The two parties who need to perform confidential calculations in cross-chain data exchange are recorded as Alice and Bob. Assume that Alice has the set Bob owns the set in, and is a set of keywords, and is a set of associated values, l1 and l2 represent the number of elements in the set; Alice and Bob perform confidential computations, including the following steps: S1, Alice adds l3 keywords and associated values (j i ,0), i=1,2,…,l3, we get S2, Bob adds 14 keywords and associated values (p t ,0),t=1,2,…,l4, we get S3. Alice substitutes the key in the set M′ into the hash function Hash(x) and encrypts the associated value corresponding to the key to obtain Will be in The elements of are randomly permuted and sent to Bob; is the ciphertext generated by encrypting pk1 using the fully homomorphic NTRU encryption algorithm; f1 and h1 calculated by Alice using the fully homomorphic NTRU encryption algorithm are the corresponding private key sk1 and public key pk1; S4. Bob substitutes the key in the set N′ into the hash function Hash(x) and encrypts the associated value corresponding to the key to obtain After randomly replacing it, send it to Alice; is the ciphertext generated by encrypting pk2 using the fully homomorphic NTRU encryption algorithm; f2 and h2 calculated by Bob using the fully homomorphic NTRU encryption algorithm are the corresponding private key sk2 and public key pk2; S5. If Alice finds that the keyword hash value of the obfuscated element in M′ is the same as the hash value sent by Bob, she will Hash(j) except for this obfuscated element. a )=Hash(p b ) position and the associated value ciphertext corresponding to the position in N′ are added to obtain S6. If Bob finds that the keyword hash value of the obfuscated element in N′ is the same as the hash value sent by Alice, he will Hash(p b )=Hash(j a ) position and the associated value ciphertext corresponding to the position in M′ are added to obtain S7. If Alice and Bob find that Hash(j a )=Hash(p b ), end; otherwise continue execution; S8. Alice selects random numbers r1, r2, r3, r4 and calculates Send K1 to Bob; S9. Bob selects random numbers r′1, r′2, r′3, r′4 and calculates Send K2 to Alice; S10, if the number of ciphertexts of K1 and K2 is not equal, terminate; if the number of ciphertexts of K1 and K2 is equal, continue to execute; S11. Alice decrypts K2 and finds the maximum number and the smallest number And send it to Bob; S12. Bob decrypts K1 and finds the maximum number and the smallest number And send it to Alice; S13. After Alice receives the maximum and minimum numbers, she performs the following operations: Get d1 and d′1 as the maximum and minimum values of the sum of the corresponding elements of the intersection of the sets respectively; if d1 and d′1 are not integers, terminate; S14. After receiving the maximum and minimum numbers, Bob performs the following operations: Get d2 and d′2 as the maximum and minimum values of the sum of the corresponding elements of the intersection of the sets respectively; if d2 and d′2 are not integers, terminate; S15. For d1 and d2, d′1 and d′2, Alice selects 4m random polynomials and Bob chooses 4m random polynomials and Where w = 1,…,m, and calculate: Announced separately S16, Alice from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Bob to publish the corresponding Alice uses Bob's public key h2 to verify If the verification passes, proceed to the next step, otherwise stop; p is the encryption parameter in the fully homomorphic NTRU encryption algorithm; S17, Bob from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Alice to publish the corresponding Bob uses Alice's public key h1 to verify If the verification passes, proceed to the next step, otherwise stop; S18, Alice and Bob each take the remaining and Randomly select one and From the remaining and Randomly select one and Alice chooses a random polynomial r′ x1 , r″ x1 , r′ x2 , r″ x2 ; Bob selects a random polynomial r′ y1 , r″ y1 , r′ y2 , r″ y2 ; then do the following: Alice uses Bob's public key h2 to calculate: c x′3 =h2r′ x1 +pr″ x1 +d1 c x′4 =h2r′ x2 +pr″ x2 +d′1 Then calculate Denoted as T1, calculate Note it as T2, Alice sends T1 and T2 to Bob; Bob uses Alice's public key h1 to calculate: c y′3 =h1r′ y1 +pr″ y1 +d2 c y′4 =h1r′ y2 +pr″ y2 +d′2 Then calculate Denoted as G1, calculate Denoted as G2, Bob sends G1 and G2 to Alice; S19. After Alice obtains G1 and G2, she uses the private key f1 to decrypt G1 and G2 and obtain d1+d2, d′1+d′2. When d1+d2=2d1, d′1+d′2=2d′1, then d2=d1, d′2=d′1. Otherwise, Bob is a malicious participant. S20. After Bob obtains T1 and T2, he uses his private key f2 to decrypt T1 and T2 and obtain d2+d1, d′2+d′1. When d2+d1=2d2, d′2+d′1=2d′2, that is, d1=d2, d′1=d′2. Otherwise, Alice is a malicious participant.
2. According to claim 1, a method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange, characterized in that: Alice adds l3 keywords and associated values (j i ,0), the set is satisfied Bob adds l4 keywords and associated values (p t ,0), the set is satisfied 3. A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: In step S10, if Bob finds that the number of ciphertexts of K1 and K2 is not equal, Alice is a malicious participant; otherwise, Bob is a malicious participant.
4. A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: In step S13, if d1 and d′1 are not integers, Bob is a malicious participant.
5. A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: In step S14, if d2 and d′2 are not integers, Alice is a malicious participant.
6. A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: When stopping in step S16, Bob is a malicious participant.
7. A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: When stopping in step S17, Alice is a malicious participant.
8. A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange, characterized by: The two parties who need to perform confidential calculations in cross-chain data exchange are recorded as Alice and Bob. Assume that Alice has the set Bob owns the set in, and is a set of keywords, and is a set of associated values, l1 and l2 represent the number of elements in the set; Alice and Bob perform confidential computations, including the following steps: Step 1: Alice randomly adds l3 confusing elements (j i ,0), i=1,2,…,l3, we get Confusing elements i ,0) in i is the keyword, and 0 is the associated value corresponding to the keyword; Step 2: Bob randomly adds l4 confusing elements (p t ,0),t=1,2,…,l4, we get Confusing elements (p t ,0) in p t is the keyword, and 0 is the associated value corresponding to the keyword; Step 3: Alice substitutes the key in the set M′ into the hash function Hash(x) and encrypts the associated value corresponding to the key to obtain Will The elements in are randomly permuted and sent to Bob; E(·) is the ciphertext generated by encryption using the fully homomorphic NTRU encryption algorithm; Step 4: Bob substitutes the keywords in the set N′ into the hash function Hash(x). If the hash value of the keyword of the obfuscated element is found to be equal to a hash value sent by Alice, no operation is performed on the associated value of the obfuscated element. Hash(p b )=Hash(j a ) The associated value v corresponding to the position b Encrypt and add the ciphertext of the associated value at the corresponding position in M′ to obtain E(u a )+E(v b ); Step 5. Bob selects random numbers r1, r2, r3, r4 and calculates And send K to Alice; Step 6: Alice decrypts K and finds the maximum number and the smallest number And send it to Bob; Step 7. After receiving the maximum and minimum numbers, Bob performs the following operations: Get d1 and d′1, which are the maximum and minimum values of the corresponding elements and the intersection of the sets respectively; Step 7: After Bob obtains d1 and d′1, he sends d1 and d′1 to Alice.
9. A method for calculating the maximum confidentiality of the sum of keyword values in cross-chain data exchange according to claim 8, characterized in that: Alice randomly adds l3 confusing elements (j i ,0), the set is satisfied Bob randomly adds l4 confusing elements (p t ,0), the set is satisfied
Citation Information
Patent Citations
A public key encryption method supporting multi-keyword search against keyword guess attack
CN109086615A
Set intersection secrecy calculation method under malicious model
CN116915396A
Automatic selection of algorithmic modules for examination of a specimen
KR102360769B1
System and method using a fitness-gradient blockchain consensus and providing advanced distributed ledger capabilities via specialized data records
US20200396065A1