A confidential calculation method for the sum of keyword values ​​in cross-chain data exchange

Through the fully homomorphic NTRU encryption algorithm and secure multi-party computing technology, combined with hash functions and split-selection methods, the problems of quantum computing attacks and privacy leakage in the calculation of the maximum value of the sum of the corresponding elements of the intersection of sets in cross-chain interactions are solved, and the calculation of the sum of keyword values ​​is achieved safely and accurately.

CN120105455BActive Publication Date: 2025-09-30INNER MONGOLIA UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510177839.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-09-30
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

Existing cross-chain interaction technology cannot effectively resist quantum computing attacks when calculating the maximum value of the sum of elements corresponding to the intersection of sets. There is a risk of data privacy leakage and there are no effective privacy protection measures.

Method used

It adopts the fully homomorphic NTRU encryption algorithm and secure multi-party computing technology, protects data privacy by adding obfuscation elements and hash functions, designs confidential computing protocols under semi-honest and malicious models, and uses the split-selection method to verify the correctness of the results to resist malicious attacks.

Benefits of technology

The security of the maximum value calculation process of the sum of the numerical values ​​corresponding to the keywords is achieved in cross-chain interactions, protecting data privacy, resisting quantum computing attacks, and ensuring the accuracy and security of the calculation results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105455B_ABST
    Figure CN120105455B_ABST
Patent Text Reader

Abstract

This invention relates to the field of data confidentiality calculation technology for cross-chain data exchange. To address the current lack of a method for confidentially calculating the maximum value of the sum of elements corresponding to set intersections that is resistant to quantum computing attacks, and the inability to guarantee the security of the maximum value calculation process for the sum of the values ​​corresponding to keywords during cross-chain interactions, this invention transforms the maximum value calculation problem of the sum of the values ​​corresponding to keywords in cross-chain data exchange into the problem of confidentially calculating the maximum value of the sum of elements corresponding to set intersections without a full set. Based on the fully homomorphic NTRU encryption algorithm, a protocol for confidentially calculating the maximum value of the sum of elements corresponding to set intersections under a semi-honest model is designed using the method of adding obfuscating elements. The potential malicious behavior that may occur in the semi-honest model protocol is analyzed, and a protocol for confidentially calculating the maximum value of the sum of elements corresponding to set intersections under a malicious model is designed using the split-selection method to achieve confidentiality calculation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a data confidentiality calculation method in cross-chain data exchange. Background Art

[0002] Blockchain technology, as a decentralized distributed ledger, boasts immutability, transparency, and security. With its development, blockchain is benefiting a growing number of industries, driving digital transformation and innovation in finance, commerce, healthcare, and other fields. Despite its significant advantages, different blockchain platforms often employ varying technologies, consensus mechanisms, and protocol standards, leading to a "blockchain silo" effect. To address this issue, cross-chain technology enables interoperability between different blockchains. Cross-chain technology goes beyond simply enabling the exchange of assets and data; it also involves the processing, analysis, and computation of data during cross-chain interactions. In particular, when transferring data between multiple chains, the computation of specific values ​​as the result is inevitable.

[0003] In cross-chain interactions, when the specific value being calculated is the maximum of the sum of associated values ​​corresponding to a keyword, the problem can be transformed into a confidential calculation problem for the maximum of the sum of the elements corresponding to the intersection of sets. For example, in a joint financial risk management analysis, two financial institutions—Institution A and Institution B—each possess user loan information. To ensure data privacy and security, each institution builds a private blockchain, A, and a private blockchain, B. Using smart contracts, they upload all user loan information to a selected blockchain platform in the form of encrypted tuple data pairs, such as (ID number, loan amount). Within this framework, the two institutions aim to calculate the maximum and minimum total loan amounts for their shared customers, which serves as a key basis for assessing credit risk. To achieve this, cross-chain technology is used to transmit data, and calculations are performed upon receipt. Finally, Institution A and Institution B can securely access the required calculation results through interfaces on their respective chains.

[0004] Essentially, the core logic of this process involves confidentially calculating the maximum sum of the elements corresponding to the intersection of two sets. The private chains maintained by institutions A and B can be considered two independent sets, A and B, with the user loan data stored by the two institutions in the form of tuple pairs representing the elements of the sets. Determining whether the two institutions have common customers essentially involves determining, without a complete set, whether the element keywords in the two sets intersect. If so, the associated values ​​corresponding to the intersecting keywords are summed, generating the maximum and minimum values.

[0005] The input data in the above process includes sensitive information such as the user's identity information and amount. If the plaintext data is operated directly or appropriate privacy protection measures are not taken, attackers may infer the user's transaction amount, asset status and other information by monitoring the calculation results and intermediate processes. Data leakage will bring serious privacy protection risks.

[0006] Therefore, to protect the privacy of data participants, secure multi-party computation (MPC) has emerged. By leveraging cryptography and protocol design, it aims to enable multiple parties to perform computations and share data without leaking sensitive information. MPC was first proposed by Yao and subsequently developed through the research of Goldreich. MPC has gained recognition and practical application in cloud computing, the Internet of Things, privacy-preserving data mining, electronic auctions, and other fields, providing an effective solution for achieving data collaboration, protecting data privacy, and meeting legal requirements.

[0007] "Blockchain-enabled multiparty computation for privacy preserving and public audit in industrial IoT" proposes an MPC framework for achieving privacy preservation and public audit in the industrial IoT by combining MPC and blockchain technologies. "A decentralized private data marketplace using blockchain and secure multi-party computation" applies MPC to blockchain, providing users with a trusted data transaction solution that prevents malicious behavior and supports privacy preservation. "Secure distributed medical record storage using blockchain and emergency sharing using multi-party computation" proposes a secure distributed medical record storage and emergency sharing system based on blockchain and MPC technologies. Although numerous research proposals have been conducted on privacy-preserving computation of sets in blockchains, most protocols are proposed under a semi-honest model and do not consider the maximum value of the sum corresponding to the intersection of sets. There is no protocol for secure computation of the maximum value of the sum corresponding to the intersection of sets that is resistant to malicious adversary attacks and quantum computing attacks, and it is impossible to guarantee the security of the maximum value computation of the sum corresponding to the value of a keyword during cross-chain interactions. Summary of the Invention

[0008] The present invention aims to solve the problem that there is currently no method for confidentially calculating the maximum value of the sum of the elements corresponding to the intersection of sets that can resist quantum computing attacks, and there is an inability to ensure the security of the maximum value calculation process of the sum of the numerical values ​​corresponding to the keywords during cross-chain interaction.

[0009] A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange. The two parties who need to perform confidentiality calculation in cross-chain data exchange are denoted as Alice and Bob. Assume that Alice has the set Bob owns the set in, and is a set of keywords, and is a set of associated values, l1 and l2 represent the number of elements in the set; Alice and Bob perform a confidential computation, which includes the following steps:

[0010] S1, Alice adds l3 keywords and associated values ​​(j i ,0), i=1,2,…,l3, we get

[0011] S2, Bob adds 14 keywords and associated values ​​(p t ,0), t=1,2,…,l4, we get

[0012] S3. Alice substitutes the key words in the set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain will be in The elements of are randomly permuted and sent to Bob;

[0013] is the ciphertext generated by encrypting pk1 using the fully homomorphic NTRU encryption algorithm; f1 and h1 calculated by Alice using the fully homomorphic NTRU encryption algorithm are the corresponding private key pk1 and public key pk1;

[0014] S4. Bob substitutes the key words in the set N' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain Randomly replace it and send it to Alice;

[0015] is the ciphertext generated by encrypting pk2 using the fully homomorphic NTRU encryption algorithm; f2 and h2 calculated by Bob using the fully homomorphic NTRU encryption algorithm are the corresponding private key sk2 and public key pk2;

[0016] S5. If Alice finds that the keyword hash value of the obfuscated element in M' is the same as the hash value sent by Bob, she will Hash(j a )=Hash(p b ) position and the associated value ciphertext corresponding to the position in N' are added to obtain

[0017] S6. If Bob finds that the keyword hash value of the obfuscated element in N' is the same as the hash value sent by Alice, he will Hash(p b )=Hash(j a ) position and the associated value ciphertext corresponding to the position in M' are added to obtain

[0018] S7. If Alice and Bob find that Hash(j a )=Hash(p b ), end; otherwise continue execution;

[0019] S8. Alice selects random numbers r1, r2, r3, r4 and calculates Send K1 to Bob;

[0020] S9. Bob selects random numbers r'1, r'2, r'3, r'4 and calculates Send K2 to Alice;

[0021] S10. If the number of ciphertexts in K1 and K2 is not equal, terminate the process; if the number of ciphertexts in K1 and K2 is equal, continue the process.

[0022] S11. Alice decrypts K2 and finds the maximum number and the smallest number And send it to Bob;

[0023] S12. Bob decrypts K1 and finds the maximum number and the smallest number And send it to Alice;

[0024] S13. After receiving the maximum and minimum numbers, Alice performs the following operations:

[0025]

[0026] Get d1 and d'1 respectively, the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection; if d1 and d'1 are not integers, terminate;

[0027] S14. After receiving the maximum and minimum numbers, Bob performs the following operations:

[0028]

[0029] Get d2 and d'2 respectively, the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection; if d2 and d'2 are not integers, terminate;

[0030] S15. For d1 and d2, d'1 and d'2, Alice selects 4m random polynomials and Bob chooses 4m random polynomials and Where w=1,…,m, and calculate:

[0031]

[0032] Announced separately

[0033] S16, Alice from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Bob to publish the corresponding Alice uses Bob's public key h2 to verify If the verification passes, proceed to the next step, otherwise stop;

[0034] p is the encryption parameter in the fully homomorphic NTRU encryption algorithm;

[0035] S17, Bob from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Alice to publish the corresponding Bob uses Alice's public key h1 to verify If the verification passes, proceed to the next step, otherwise stop;

[0036] S18, Alice and Bob each take and Randomly select one and From the remaining and Randomly select one and Alice chooses a random polynomial r' x1 ,r″ x1 , r'x2 ,r″ x2 ; Bob selects a random polynomial r' y1 ,r″ y1 , r' y2 ,r″ y2 ; then do the following:

[0037] Alice uses Bob's public key h2 to calculate:

[0038] c x'3 =h2r′ x1 +pr″ x1 +d1

[0039] c x'4 =h2r′ x2 +pr″ x2 +d′1

[0040] Then calculate Recorded as T1, calculate Recorded as T2, Alice sends T1 and T2 to Bob;

[0041] Bob uses Alice's public key h1 to calculate:

[0042] c y'3 =h1r y1 +pry″1+d2

[0043] c y'4 =h1r′ y2 +pr″ y2 +d′2

[0044] Then calculate Denoted as G1, calculate Recorded as G2, Bob sends G1 and G2 to Alice;

[0045] S19. After Alice obtains G1 and G2, she uses the private key f1 to decrypt G1 and G2 and obtain d1+d2, d'1+d'2. When d1+d2=2d1, d'1+d'2=2d'1, then d2=d1, d'2=d'1. Otherwise, Bob is a malicious participant.

[0046] S20. After Bob obtains T1 and T2, he uses his private key f2 to decrypt T1 and T2 and obtain d2+d1, d'2+d'1. When d2+d1=2d2, d'2+d'1=2d'2, that is, d1=d2, d'1=d'2. Otherwise, Alice is a malicious participant.

[0047] Furthermore, Alice adds l3 keywords and associated values ​​(j i,0), the set is satisfied Bob adds 14 keywords and associated values ​​(p t ,0), the set is satisfied

[0048] Furthermore, in step S10, if Bob finds that the number of ciphertexts of K1 and K2 is not equal, Alice is a malicious participant; otherwise, Bob is a malicious participant.

[0049] Furthermore, in step S13, if d1 and d'1 are not integers, Bob is a malicious participant.

[0050] Furthermore, in step S14, if d2 and d'2 are not integers, Alice is a malicious participant.

[0051] Furthermore, when stopping in step S16, Bob is a malicious participant.

[0052] Furthermore, when stopping in step S17, Alice is a malicious participant.

[0053] A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange. The two parties who need to perform confidentiality calculation in cross-chain data exchange are denoted as Alice and Bob. Assume that Alice has the set Bob owns the set in, and is a set of keywords, and is a set of associated values, l1 and l2 represent the number of elements in the set; Alice and Bob perform a confidential computation, which includes the following steps:

[0054] Step 1: Alice randomly adds l3 confusing elements (j i ,0), i=1,2,…,l3, we get Confusion elements (j i ,0) in j i is the keyword, and 0 is the associated value corresponding to the keyword;

[0055] Step 2: Bob randomly adds l4 confusing elements (p t ,0), t=1,2,…,l4, we get Confusing elements (p t ,0) in p t is the keyword, and 0 is the associated value corresponding to the keyword;

[0056] Step 3: Alice substitutes the key words in the set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain Will The elements in are randomly permuted and sent to Bob;

[0057] E(·) is the ciphertext generated by encryption using the fully homomorphic NTRU encryption algorithm;

[0058] Step 4. Bob substitutes the keywords in the set N' into the hash function Hash(x). If the hash value of the keyword of the obfuscated element is found to be equal to a hash value sent by Alice, no operation is performed on the associated value of the obfuscated element. Hash(p b )=Hash(j a ) The associated value v corresponding to the position b Encrypt and add the ciphertext of the associated value at the corresponding position in M' to obtain E(u a )+E(v b );

[0059] Step 5. Bob selects random numbers r1, r2, r3, r4 and calculates And send K to Alice;

[0060] Step 6: Alice decrypts K and finds the maximum number and the smallest number And send it to Bob;

[0061] Step 7. After receiving the maximum and minimum numbers, Bob performs the following operations:

[0062]

[0063] Get d1 and d'1, which are the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection respectively;

[0064] Step 7. After Bob obtains d1 and d'1, he sends d1 and d'1 to Alice.

[0065] Furthermore, Alice randomly adds l3 confusing elements (j i ,0), the set is satisfied Bob randomly adds l4 confusing elements (p t ,0), the set is satisfied

[0066] Beneficial effects:

[0067] In blockchain, privacy protection of the maximum value of the sum of the corresponding keywords in cross-chain data exchange is a crucial issue. To address this issue, this paper makes the following contributions:

[0068] (1) The problem of calculating the maximum value of the sum of the numerical values ​​corresponding to keywords in cross-chain data exchange is transformed into the problem of confidentially calculating the maximum value of the sum of the corresponding elements of the intersection of sets without a full set. Secure multi-party computing technology is used to protect data privacy, thereby enhancing the security of the cross-chain interaction process.

[0069] (2) For the case where there is no complete set of sets, based on the fully homomorphic NTRU encryption algorithm, a confidential calculation protocol for the maximum value of the sum of the elements corresponding to the intersection of sets under a semi-honest model is designed by adding confusing elements. The possible malicious behaviors in the semi-honest model protocol are analyzed, and a confidential calculation protocol for the maximum value of the sum of the elements corresponding to the intersection of sets under a malicious model is designed using the split-selection method. The problem is further transformed into the socialist millionaire problem. The correctness of the protocol is analyzed, and the security of the protocol is proved using an ideal-realistic example. This is also one of the few MPC protocols that can resist both malicious adversary attacks and quantum computing attacks.

[0070] (3) Performance comparison with existing solutions shows that the protocols under the two models proposed in the present invention can simultaneously find the maximum and minimum values ​​of the sum of the elements corresponding to the intersection of sets while protecting private data and set potential. After adding and subtracting the maximum and minimum numbers in the protocol, it can also be used as a protocol for simultaneously finding the extreme difference and extreme sum of the sum of the elements corresponding to the intersection of sets. BRIEF DESCRIPTION OF THE DRAWINGS

[0071] Figure 1 Schematic diagram of the interaction in the confidential calculation of the maximum value of the sum of keyword values ​​in cross-chain data exchange under the semi-honest model.

[0072] Figure 2 Schematic diagram of the interaction in the confidential calculation of the maximum value of the keyword value and the sum in cross-chain data exchange under the malicious model. DETAILED DESCRIPTION

[0073] This invention designs a confidential computation protocol for the maximum sum of the elements corresponding to the intersection of sets, which is resistant to both malicious adversary attacks and quantum computing attacks without a complete set. This protocol effectively improves the security of the maximum sum of the numerical values ​​corresponding to keywords during cross-chain interactions. Before describing the specific implementation methods, the cryptographic knowledge required for this invention is first explained.

[0074] Security of malicious models:

[0075] The attacker in the malicious model is proactive. Not only does the malicious attacker not abide by the protocol, but they may also adopt various strategies to undermine the security of the protocol. Generally speaking, if a protocol can resist attacks from malicious adversaries, it can also resist potential threats in the semi-honest model.

[0076] "Foundations of Cryptography: Volume 2, Basic Applications" provides a generally accepted definition of security under a malicious model, requiring the use of an ideal protocol involving a trusted third party (TTP): Assume that P1 and P2 possess data m' and n', and the function f(m',n') = (f1(m',n'),f2(m',n')) is computed using the TTP. After the protocol executes, P1 and P2 obtain f1(m',n') and f2(m',n') respectively, without revealing m' and n'. The protocol can be described as follows:

[0077] (1) Honest participants will send the correct m' and n' to the TTP, while malicious participants may not participate in the protocol execution or send false data m" or n" to the TTP.

[0078] (2) After obtaining (m',n'), TTP calculates f(m',n') and sends f1(m',n') to P1.

[0079] (3) If P1 is a malicious participant, it may terminate the protocol after receiving f1(m',n'). In this case, TTP sends a symbol ⊥ (indicating termination) to P2, otherwise it sends f2(m',n') to P2.

[0080] The ideal protocol is the safest protocol because the participants can obtain the result f from TTP. i If the actual protocol has the same security as the ideal protocol, then the actual protocol is secure.

[0081] Let F:{0,1} * ×{0,1} * →{0,1} * ×{0,1} * is a probabilistic polynomial time function, F1(m',n') and F2(m',n') represent the first and second elements of F(m',n'). A pair of probabilistic polynomial-time algorithms that represent the strategies of participants in an ideal protocol. In the ideal model, participants are given auxiliary information z and strategies. The process of jointly calculating F(m',n') is recorded as The malicious participant selects a random number r, and sets:

[0082]

[0083] where γ(m',n',z,r) is defined as follows:

[0084] If P1 is an honest participant, then:

[0085] γ(m′,n′,z,r)=(f1(m′,n″),B2(n′,z,r,f2(m′,n″))).

[0086] Where n" = B2(n',z,r).

[0087] If P2 is an honest participant, then:

[0088]

[0089] Where m″=B1(m',z,r).

[0090] Let Π be a two-party protocol for computing F, A pair of probabilistic polynomial-time algorithms for representing the strategies of participants in a realistic model. REAL Π,A(z) (m',n') is defined as the output pair generated by the interaction between A1(m',z) and A2(n',z), which is based on the strategy Execute the process of Π in the actual model, and z is the auxiliary input.

[0091] Definition 1: Security of the protocol under the malicious model (ideal-practical paradigm)

[0092] If any acceptable In the ideal agreement, acceptable So that the following formula holds:

[0093]

[0094] This shows that π can safely calculate F.

[0095] When executing a protocol under a malicious model, one of the participants must be honest, otherwise a secure protocol cannot be designed.

[0096] NTRU encryption algorithm:

[0097] The NTRU encryption algorithm was proposed by Hoffstein, Pipher, and Silverman in 1998. A significant advantage of this algorithm is its extremely fast encryption and decryption speed. It utilizes a truncated polynomial ring for data processing and reduces computational complexity by optimizing the algorithm structure. Furthermore, the NTRU encryption algorithm relies on the Shortest Vector Problem (SVP) on a lattice, rather than the traditional discrete logarithm or large number factorization problem. This makes it highly resistant to quantum computing attacks and is one of the most advanced post-quantum encryption algorithms. By optimizing the key generation process, the following NTRU encryption algorithm is obtained, whose main steps are:

[0098] (1) Parameter setting

[0099] Choose a safety parameter λ, a sufficiently large standard deviation σ, n = n(λ), q = q(λ)∈R q , in, It is R q The set of reversible elements in R q =R / qR=Zq [ x] / Φ.

[0100] (2) Key Generation

[0101] From discrete Gaussian distribution Take polynomials f' and g, if Then reselect g. Let f=p*f'+1, if Then reselect f. Let f be the private key sk and h be the public key pk.

[0102] (3) Encryption

[0103] Randomly select polynomials s and e from the B(λ) bounded distribution χ, encrypt the plaintext m, and obtain the ciphertext c∈R:

[0104] c=hs+pe+m.

[0105] (4) Decryption

[0106] Decrypt using private key f:

[0107] m=fc(mpdp).

[0108] Fully homomorphic NTRU encryption algorithm:

[0109] The fully homomorphic NTRU encryption algorithm has the following main steps:

[0110] (1) Parameter setting

[0111] Choose a safety parameter λ, a sufficiently large standard deviation σ, n = n(λ), q = q(λ)∈R q , in, It is R q The set of reversible elements in R q =R / qR=Z q [x] / Φ.

[0112] (2) Key Generation

[0113] From discrete Gaussian distribution Take polynomials f' and g, if Then reselect g. Let f=p*f'+1, if Then reselect f. Let f be the private key sk and h be the public key pk.

[0114] (3) Encryption

[0115] Using the NTRU encryption algorithm to encrypt 0, we get a vector of ciphertext 0s with a length of l = logq:

[0116] c=(c l-1 ,c l-2 ,…,c0).

[0117] Use BitDecomp to convert c into an l×l matrix C:

[0118]

[0119] Using Flattening technology, calculate C'=Flatten(I l ·m+C).

[0120] Among them, the BitDecomp function is the process of decomposing a data element into its bit representation, and the Flatten function can convert a multi-layer or nested data structure into a single, continuous layer or linear structure. i =hs i +pe i +0,s i and e i is a polynomial randomly chosen from the B(λ)-bounded distribution χ. is a binary polynomial, I l is the l×l unit matrix, and C' is the ciphertext matrix of plaintext m.

[0121] (4) Decryption

[0122] Utilizing BitDecomp -1 The function calculates the last row of the matrix C' (recovery vector) and then recovers the plaintext m:

[0123] BitDecomp -1 (C' (0,l-1) ,C' (0,l-2) ,…,C' (0,0) )=C0.

[0124]

[0125] The scheme is fully homomorphic: Assuming that the ciphertext matrices corresponding to plaintext m1 and m2 are C'1 and C'2, then C'3 = Flatten(C'1 + C'2) and C'4 = Flatten(C'1·C'2). Using the decryption algorithm, we can obtain the plaintexts m1+m2 and m1·m2, respectively.

[0126] Add obfuscation element method:

[0127] Adding obfuscation elements involves inserting non-authentic, randomly generated, or pseudo-randomly generated elements into the original set. These obfuscation elements resemble authentic elements in format and structure, but contain irrelevant or random information. The number of obfuscation elements should be determined based on security requirements and available resources. Excessive obfuscation elements may increase the complexity and overhead of the MPC protocol, while too few obfuscation elements may not provide sufficient security. This makes it difficult for malicious attackers to distinguish authentic elements from obfuscated elements in the set, thereby enhancing data confidentiality and privacy.

[0128] Next, the present invention will be described in detail in conjunction with the specific embodiment 1. The symbols and their meanings in the method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange are shown in Table 1:

[0129] Table 1 Protocol symbol table

[0130]

[0131] Association value: The data stored in the chain is in the form of data pairs, and the keywords correspond to the corresponding association values, indicating a related measurement. Specific implementation method one:

[0133] The method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange described in this embodiment is a method for calculating the maximum confidentiality of the sum of corresponding elements of set intersection under a semi-honest model. The two parties who need to perform confidentiality calculation in cross-chain data exchange are denoted as Alice and Bob. Assume that Alice has the set Bob owns the set here and is a set of keywords, and It is a set of associated values, l1 and l2 represent the number of elements in the set (the number of data pairs in M ​​and N). The maximum and minimum values ​​of the sum of the associated values ​​corresponding to the same keyword in sets M and N are calculated confidentially without revealing the data and potential of both sets.

[0134] Alice and Bob protect the set potential by adding obfuscation elements. Alice executes the fully homomorphic NTRU encryption algorithm, encrypts the associated value, and sends the public key to Bob. Both parties confirm the intersection by calculating the hash value of the key. Bob uses the public key to encrypt the associated value corresponding to the key that forms the intersection, calculates the sum of the associated values ​​in the ciphertext state, and uses the fully homomorphic nature of the encryption algorithm to add a random number before sending it to Alice. Alice then decrypts the ciphertext, and Bob recovers the final result.

[0135] like Figure 1 As shown, the method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange described in this embodiment includes the following steps:

[0136] Protocol 1: Confidential calculation protocol for the maximum value of the sum of the corresponding elements of the set intersection under the semi-honest model:

[0137] Input: Alice input set Bob inputs the set

[0138] Output: F max (M,N)=max(u a +v b )(j b =p b ), F min (M,N)=min(u a +vb ) (j a =p b ).

[0139] Preparation stage:

[0140] (a) Executing the fully homomorphic NTRU encryption algorithm, Alice selects polynomials f' and g, then calculates f = p*f' + 1, using f as the private key sk. Alice calculates the public key pk: h = pgf -1 , and send h to Bob.

[0141] The encryption algorithms used subsequently are all fully homomorphic NTRU encryption algorithms.

[0142] (b) Alice and Bob jointly agree on a hash function Hash(x).

[0143] The protocol begins:

[0144] Step 1: Alice randomly adds l3 confusing elements (j i ,0), i=1,2,…,l3, we get Confusion elements (j x ,0) in ji is the keyword, and 0 is the associated value corresponding to the keyword.

[0145] Step 2: Bob randomly adds l4 confusing elements (p t ,0), t=1,2,…,l4, we get

[0146] Step 3: Alice substitutes the key words in the set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain Will The elements in are randomly permuted and sent to Bob.

[0147] E(·) is the ciphertext generated by encryption using the encryption algorithm based on the secret key pk;

[0148] Step 4. Bob substitutes the keywords in the set N' into the hash function Hash(x). If the hash value of the keyword of the obfuscated element is found to be equal to a hash value sent by Alice, no operation will be performed on the associated value of the obfuscated element. b )=Hash(j a ) The associated value v corresponding to the position b Encrypt and add the ciphertext of the associated value at the corresponding position in M' to obtain E(u a )+E(v b ). If Hash(p b )=Hash(j a ), the agreement ends.

[0149] Step 5. Bob selects random numbers r1, r2, r3, r4 (r1, r2>0) and calculates And send K to Alice.

[0150] Step 6. Alice uses the private key sk to decrypt K and find the maximum number and the smallest number And send it to Bob.

[0151] Step 7. After receiving the maximum and minimum numbers, Bob performs the following operations:

[0152]

[0153] Get d1 and d'1, which are the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection, that is, F max (M,N) and F min (M,N).

[0154] Step 8. Bob sends the maximum value d1 and the minimum value d'1 to Alice.

[0155] Protocol 1 ends.

[0156] Correctness analysis:

[0157] (1) When adding obfuscated elements in this protocol, there is a possibility that the obfuscated elements may intersect with the obfuscated elements added by the other party, or intersect with the data elements of the set. The use of a hash function allows both parties to determine whether such intersections exist while protecting the potential of the set, thereby ensuring the correctness of the maximum value result.

[0158] (2) In step 4 of the protocol, according to the additive homomorphism of the encryption scheme, we have E pk (u a )+E pk (v b )=E pk (u a +v b ), ensuring that the maximum and minimum values ​​only appear in E pk (u a +v b ) in the decryption result.

[0159] (3) The method of adding random numbers ensures that Alice cannot pk (u a +v b ) decryption result to infer the private data in Bob’s set. The added random number makes u a +v b The value of is magnified proportionally, so the maximum and minimum numbers that Alice sends to Bob after decryption are the corresponding maximum and minimum values ​​obtained after Bob restores the data.

[0160] (4) Alice cannot infer the random number added by Bob from the known maximum number, minimum number, maximum value and minimum value, because the number of unknown numbers is much greater than the number of equations that can be solved for the unknown numbers.

[0161] In summary, Protocol 1 can correctly calculate the maximum and minimum values ​​of the sum of the elements corresponding to the set intersection during execution without leaking other set data and set potential.

[0162] Safety Proof:

[0163] Theorem 1 Protocol 1 (denoted as Π1) is secure in the semi-honest model.

[0164] Proof Using the simulation example method, we construct simulators S1 and S2 to prove Theorem 1. In Protocol 1:

[0165]

[0166] {N,R2,R3,H1,H2,E(M1),E(N1),E(N2),D max ,D min ,F max2 (M,N),F min 2(M,N)}.

[0167]

[0168] Among them, M and N are the inputs of both parties, R1 and R2 are the random polynomial sets selected by both parties during encryption, R3 is the random number set selected by Bob, H1 and H2 are the hash value sets obtained by both parties after substituting the keywords in the set into the hash function, and D max and D min is the maximum and minimum number Alice sends to Bob, K is the set of ciphertexts Bob sends to Alice after adding random numbers for homomorphic operation, is the ciphertext set obtained by Alice after encrypting the associated value corresponding to the keyword, and E(N1) is Bob's encryption of Hash(p b )=Hash(j a ) The associated value v corresponding to the position b The encrypted ciphertext set, E(N2)=E(u a +v b ) is the Hash(p b )=Hash(j a ) The result set after adding the ciphertext of the associated value corresponding to the position, F max1 (M,N),F min1 (M,N) and F max2 (M,N),F min2 (M, N) are the output results received by Alice and Bob respectively.

[0169] First, construct simulator S1 to simulate To prove Bob’s security, the simulation process of S1 is as follows:

[0170] (1) S1 receives (M,F max1 (M,N),F min1 (M,N)) is Alice’s input, and l3 confusing elements are randomly added to the set M to obtain the set M’. max1 (M,N),F min1 (M,N) value, select any set Randomly add 1'4 confusing elements to the set N' to obtain the set

[0171] (2) S1 substitutes the key words in the set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain Substitute the keywords in the set N" into the hash function Hash(x) and Hash(j a )=Hash(p' b ) position, and add the associated value ciphertext corresponding to the position to obtain E(u a +v' b ).

[0172] (3) S1 selects r'1, r'2, r'3, r'4 (r'1, r'2>0) and calculates

[0173] (4) S1 decrypts K' to obtain the maximum number and the smallest number

[0174] (5) After S1 obtains the maximum and minimum numbers, it executes:

[0175]

[0176] The maximum value d″1 and the minimum value d″′1 are obtained. According to the above construction process, we can know that F max1 (M,N)=F max1 (M,N”), F min1 (M,N)=F min1 (M,N″).

[0177] because:

[0178]

[0179] S1(M,F max1 (M,N),F min1 (M,N))={M,R1,K′,F max1 (M,N″),F min1 (M,N″)}.

[0180] K' is the ciphertext after Bob performs homomorphic operation by adding random numbers. Alice can decrypt it, but cannot deduce the data before homomorphic operation. So And because F max1 (M,N)=F max1 (M,N”), F min1 (M,N)=F min1 (M,N”), so that the following equation holds:

[0181]

[0182] Similarly, construct simulator S2 to simulate To prove Alice's security, the following equation is true:

[0183]

[0184] In summary, Theorem 1 holds and Protocol 1 is secure. Specific implementation method 2:

[0186] The method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange described in this embodiment is a method for calculating the maximum confidentiality of the sum of corresponding elements of set intersection under a malicious model.

[0187] In Protocol 1, possible malicious behaviors include:

[0188] (1) Alice possesses both the public and private keys of the fully homomorphic NTRU encryption algorithm, while Bob only possesses the public key. This means that the decryption operation in step 6 of the protocol can only be completed by Alice, and Bob can only passively receive the maximum and minimum numbers informed by Alice, which lacks fairness for Bob.

[0189] (2) In steps 3 and 5, Alice may not send the correct hash value and ciphertext information to Bob, and Bob may not send the correct ciphertext information to Alice. This situation is unavoidable and will not be considered.

[0190] (3) In step 6, Alice may not send the correct maximum and minimum numbers after decryption to Bob.

[0191] (4) In step 8, Bob already knows the correct maximum and minimum values, but may not send them to Alice. In this case, Alice will not get the result or will receive an incorrect result.

[0192] To address the above malicious behavior, the following solution is proposed: Alice and Bob simultaneously execute the fully homomorphic NTRU encryption algorithm to generate public and private keys, and separately calculate the maximum value of the sum of the corresponding elements of the set intersection. Then, they use the split-selection method to transform the problem into the Socialist Millionaire Problem, and finally jointly verify the correctness of the result.

[0193] The process of confidential calculation of the maximum value of the sum of the corresponding elements of the set intersection under the malicious model is as follows: Figure 2 shown.

[0194] Protocol 2: Confidential calculation protocol for the maximum value of the sum of the corresponding elements of the set intersection under the malicious model:

[0195] Input: Alice input set Bob inputs the set

[0196] Output: F max (M,N)=max(u a +v b )(j a =p b ), F min (M,N)=min(u a +v b )(j a =p b ).

[0197] Preparation stage:

[0198] (1) Execute the fully homomorphic NTRU encryption algorithm. Alice selects polynomials f'1 and g1, calculates f1 = p*f'1+1, h1 = pg1f'1, uses f1 as the private key sk1, uses h1 as the public key pk1, and sends them to Bob. Bob selects polynomials f'2 and g2, calculates f2 = p*f'2+1, h2 = pg2f'2, uses f2 as the private key sk2, uses h2 as the public key pk2, and sends them to Alice.

[0199] (2) Alice and Bob jointly negotiate a hash function Hash(x).

[0200] The protocol begins:

[0201] S1, Alice adds l3 keywords and associated values ​​(j i ,0)(i=1,2,…,l3), we get

[0202] S2, Bob adds 14 keywords and associated values ​​(p t ,0)(t=1,2,…,l4), we get

[0203] S3. Alice substitutes the key words in the set M' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain Randomly permute it and send it to Bob.

[0204] The ciphertext is generated by encrypting with the fully homomorphic encryption algorithm based on the secret key pk1.

[0205] S4. Bob substitutes the key words in the set N' into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain After random replacement, send it to Alice.

[0206] The ciphertext is generated by encrypting with the fully homomorphic encryption algorithm based on the secret key pk2.

[0207] S5. If Alice finds that the keyword hash value of the obfuscated element in M' is the same as the hash value sent by Bob, she will Hash(j a )=Hash(p b ) position and the associated value ciphertext corresponding to the position in N' are added to obtain

[0208] S6. If Bob finds that the keyword hash value of the obfuscated element in N' is the same as the hash value sent by Alice, he will Hash(p b )=Hash(j a ) position and the associated value ciphertext corresponding to the position in M' are added to obtain

[0209] S7. If Alice and Bob find that Hash(j a )=Hash(p b ), the protocol ends. Otherwise, the protocol continues.

[0210] S8. Alice selects random numbers r1, r2, r3, r4 (r1, r2>0) and calculates Send K1 to Bob.

[0211] S9. Bob selects random numbers r'1, r'2, r'3, r'4 (r'1, r'2>0) and calculates Send K2 to Alice.

[0212] S10. If Bob discovers that the number of ciphertexts in K1 and K2 is not equal, Alice is considered a malicious participant. Otherwise, Bob is considered a malicious participant and the protocol aborts. If the number of ciphertexts in K1 and K2 is equal, the protocol continues.

[0213] S11. Alice uses the private key sk1 to decrypt K2 and find the maximum number and the smallest number And send it to Bob.

[0214] S12. Bob decrypts K1 using the private key sk2 and finds the maximum number and the smallest number And send it to Alice.

[0215] S13. After receiving the maximum and minimum numbers, Alice performs the following operations:

[0216]

[0217] We obtain d1 and d'1 as the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection. If d1 and d'1 are not integers, Bob is a malicious participant and the protocol is terminated.

[0218] S14. After receiving the maximum and minimum numbers, Bob performs the following operations:

[0219]

[0220] The obtained values ​​d2 and d'2 are the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection respectively. If d2 and d'2 are not integers, Alice is a malicious participant and the protocol is terminated.

[0221] S15. For d1 and d2, d'1 and d'2, Alice selects 4m random polynomials and Bob chooses 4m random polynomials and Where w=1,…,m, and calculate:

[0222]

[0223] Announced separately

[0224] m is the amount of data used in an arbitrary split-selection method.

[0225] S16, using the split-selection method, Alice selects m groups Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Bob to publish the corresponding Alice uses Bob's public key h2 to verify If the verification passes, the next step is executed; otherwise, the protocol is stopped and Bob is considered a malicious participant.

[0226] S17, Bob from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Alice to publish the corresponding Bob uses Alice's public key h1 to verify If the verification passes, the next step is executed; otherwise, the protocol is stopped and Alice is considered a malicious participant.

[0227] S18, Alice and Bob each take and Randomly select one and From the remaining and Randomly select one and Alice chooses a random polynomial r' x1 ,r″ x1 , r' x2 ,r″ x2 Bob selects a random polynomial r' y1 ,r″ y1 , r' y2 ,r″ y2 . Then do the following:

[0228] Alice uses Bob's public key h2 to calculate:

[0229] c x'3 =h2r′ x1 +pr″ x1 +d1

[0230] c x'4 =h2r′ x2 +pr″ x2 +d′1

[0231] Then calculate Recorded as T1, calculate Recorded as T2, Alice sends T1 and T2 to Bob.

[0232] Bob uses Alice's public key h1 to calculate:

[0233] c y'3 =h1r′ y1 +pr″ y1 +d2.

[0234] c y'4 =h1r′ y2 +pr″ y2 +d2.

[0235] Then calculate Denoted as G1, calculate Recorded as G2, Bob sends G1 and G2 to Alice.

[0236] S19. After Alice obtains G1 and G2, she uses private key f1 to decrypt G1 and G2, obtaining d1 + d2, d'1 + d'2. When d1 + d2 = 2d1, d'1 + d'2 = 2d'1, then d2 = d1, d'2 = d'1. Otherwise, Bob is a malicious actor.

[0237] S20. After obtaining T1 and T2, Bob uses his private key f2 to decrypt T1 and T2, obtaining d2 + d1 and d'2 + d'1. If d2 + d1 = 2d2 and d'2 + d'1 = 2d'2, then d1 = d2 and d'1 = d'2. Otherwise, Alice is a malicious actor.

[0238] S21, Alice and Bob output the maximum and minimum values.

[0239] End of Protocol 2.

[0240] Correctness analysis:

[0241] (1) Regarding the processing of keywords in the set, it is known from the first-preimage resistance of the hash function that for the calculated hash value k, it is difficult to find its original input x within a reasonable time, so that Hash(x) = k. Therefore, in this protocol, if there is a keyword j a =p b , you will get Hash(j a )=Hash(p b ). According to the anti-second preimage property of the hash function, for an input value x1, it is difficult to find another different input value x2 such that Hash(x1)=Hash(x2) within a reasonable time. Therefore, for this protocol, there exists a Hash(j a )=Hash(p b ) But j a ≠p b However, in the actual implementation of the protocol, this probability is so small that it can be ignored scientifically and it is safe to assume that when Hash(j a )=Hash(p b ) when j a =p b .

[0242] (2) Regarding the processing of associated values ​​in the set, the fully homomorphic NTRU encryption algorithm ensures that any calculation on the ciphertext will result in the same result after decryption as the corresponding operation on the plaintext. β =2(β=1,…,4) as an example, the encryption process of u1,v1 and the homomorphic operation is as follows:

[0243] 2[E(2)+E(4)+E(2)]2 +E(2)=2[E(8)×E(8)]+E(2)=E(64)+E(64)+E(2)=E(130).

[0244] Therefore, the process of removing the random number and restoring the data after decryption will definitely find the maximum and minimum values.

[0245] (3) Steps S1-S14 mainly involve Alice and Bob calculating the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection. The correctness analysis of this process is the same as the specific implementation method, and no private information will be leaked.

[0246] (4) In steps S15 to S20, the problem of calculating the maximum value of the sum of the corresponding elements of the intersection of sets has been converted into the Socialist Millionaire Problem. The Socialist Millionaire Problem has correctness and security under the malicious model.

[0247] (5) In steps S16-S20, a split-selection method is used to determine whether there are malicious participants. Both parties use the public key to verify data integrity, thus avoiding the occurrence of unfairness. From a probabilistic perspective, as long as the selection of both parties is random and the number of selected subsets is large enough, the probability of malicious operations being hidden in the unselected subsets without being discovered is very small.

[0248] Safety Proof:

[0249] Theorem 2 Protocol 2 (denoted as Π2) is secure under the malicious model.

[0250] In analyzing steps S1-S14 of Protocol 2, Alice and Bob independently calculate the maximum and minimum values ​​in secret, using d1, d2, d'1, and d'2 as the basic input data for the subsequent protocol execution. They then transform the problem into a socialist millionaire's problem (i.e., whether d1 equals d2, and whether d'1 equals d'2), and finally jointly verify the results. This demonstrates the security of the protocol after step S14.

[0251] In this process, Alice must meet a series of conditions to successfully perform malicious operations: First, in step S15, and The requirements are not met. Secondly, it is not detected during the verification phase in step S17. Finally, it is selected by Bob in step S18. Only when these conditions are met simultaneously can Bob reach an incorrect conclusion. However, Alice cannot obtain any information about Bob because G1 and G2 obtained in step S18 are unsolvable for Alice. Similarly, Bob cannot obtain any private information about Alice, so Protocol 2 is secure. The following demonstrates the security of the protocol through an ideal-realistic example.

[0252] Proof: According to the above security definition, at least one of the two parties in the agreement is honest, so the proof is divided into two cases.

[0253] Case 1: A1 is honest and A2 is malicious.

[0254] When executing Π2, we have:

[0255]

[0256] In an ideal model, if an acceptable strategy can be found for Output and The calculation is indistinguishable. At this time, the strategy of B2 is consistent with the strategy of A2.

[0257] (1) In the ideal model, if A1 is honest, then B1 is also honest, so B1 sends the correct d1 and d'1 to TTP.

[0258] (2) B2 sends d2 and d'2 to A2, and obtains A2's private information A2(d2) and A2(d'2) during the actual execution of Π2 from A2.

[0259] (3) B2 sends A2(d2) and A2(d'2) to TTP. B2 and B1 obtain F(d1, A2(d2)) and F(d'1, A2(d'2)) from TTP.

[0260] (4) After B2 obtains F(d1, A2(d2)) and F(d'1, A2(d'2)), it tries to obtain a π2. When it is actually executed, it is the same as the one obtained by A2. and Computationally indistinguishable and And put and Submit it to A2 and get the output of A2.

[0261] Simulator B2 randomly selects d″1 and d″′1 so that F(d″1, A2(d2)) = F(d1, A2(d2)), F(d″′1, A2(d'2)) = F(d'1, A2(d'2)), and simulates the protocol with d″1 and d″′1. The execution process of simulator B2 is as follows:

[0262] (1) B2 executes Π2 and sends Π2 step S15 and Give A2.

[0263] (2) After A2 publishes the information in step S16 of PI2, B2 performs verification.

[0264] (3) B2 publishes the information requested by A2 in step S17 of UI2.

[0265] (4) In step S18 of Π2, B2 selects information from the remaining groups, calculates T'1 and T'2, and publishes them.

[0266] When simulator B2 executes Π2, we can get:

[0267]

[0268] In the protocol steps S15-S18, for A2, since the fully homomorphic NTRU encryption algorithm is used, Then the following formula holds:

[0269]

[0270] Case 2: A1 is malicious and A2 is honest.

[0271] At this time, when executing Π2, there are the following two situations:

[0272] (1) When A1 no longer pays attention to TTP, TTP sends the symbol ⊥ to A2. At this time:

[0273]

[0274] (2) If A1 announces a message, TTP sends a message to A2. At this time:

[0275]

[0276] In an ideal model, if an acceptable strategy can be found for Output and and The calculation is indistinguishable. At this time, the strategy of B1 is consistent with the strategy of A1, so the protocol should be verified based on A1(d1) and A1(d'1).

[0277] (1) Dishonest B1 sends input information A1(d1) and A1(d'1) to TTP.

[0278] (2) Honest B2 sends real input information d2 and d'2 to TTP.

[0279] (3) TTP obtains the input information (A1(d1), d2) and (A1(d'1), d'2) and calculates F(A1(d1), d2) and F(A1(d'1), d'2).

[0280] (4) B1 obtains F(A1(d1), d2) and F(A1(d'1), d'2) from TTP and tries to get a value that is consistent with the value obtained by A1 when the agreement is actually executed. and Computationally indistinguishable and And put and Submit it to A1 and get the output of A1.

[0281] Simulator B1 randomly selects d″2 and d″'2 so that F(A1(d1), d″2) = F(A1(d1), d2) and F(A1(d1), d″'2) = F(A1(d1), d′2). The execution process of simulator B1 is as follows when d″2 and d″'2 are used to simulate the protocol:

[0282] (1) B1 executes Π2 and sends step S15 in Π2 and To A1.

[0283] (2) B1 publishes the information requested by A1 in step S16 of UI2.

[0284] (3) After A1 publishes the information in step S17 of PI2, B1 verifies it.

[0285] (4) In step S18 of Π2, B1 selects information from the remaining groups, calculates G'1 and G'2, and publishes them.

[0286] When simulator B1 executes Π2, the following two situations can be obtained:

[0287] (1) When A1 no longer cares about the TTP (A1 terminates the agreement), there are:

[0288]

[0289] (2) If the news continues to be released, there will be:

[0290]

[0291] In the protocol steps S15 to S18, for A1, since the fully homomorphic NTRU encryption algorithm is used, Then the following formula holds:

[0292]

[0293] According to the above proof, the strategy in the actual model is Under the ideal model, an acceptable strategy can be found. Make it computationally indistinguishable, therefore, Theorem 2 holds and Π2 is secure.

[0294] Protocol efficiency analysis:

[0295] A. Computational complexity analysis:

[0296] In order to facilitate comparative analysis, the main modular exponential operation M e and polynomial multiplication M k The total number of times is taken as the key indicator for evaluating computational complexity, and other operations involved are ignored here.

[0297] Protocol 2 in the Securely Computing Protocol of Set Intersection under the Malicious Model uses the Paillier encryption algorithm (encryption requires 2 modular exponential operations, decryption requires 1 modular exponential operation) to encrypt and decrypt data. A total of 4mQ encryption times and 2Q decryption times, so the computational complexity is [(8m+2)Q]M e Where Q is the number of elements in the set, and m is the amount of split-selection data. Protocol 2 in "Secret Computation of the Sum of Intersection Elements of Sets" uses the Paillier encryption algorithm to encrypt and decrypt data. The protocol encrypts 2(l2+l4)+l1 times and decrypts l1(l2+l4)+1 times, so the computational complexity is [(l1+4)(l2+l4)+2l1+1]M e Protocol 2 of "Secure Calculation of the Maximum Sum of Corresponding Elements of Intersection" uses the Paillier encryption algorithm to encrypt and decrypt plaintext. Second, decryption times, so the computational complexity is

[0298] The protocol of the present invention uses the fully homomorphic NTRU encryption algorithm (encryption requires logq times of polynomial multiplication operations, decryption requires 1 times of polynomial multiplication operations). Protocol 1 performs a total of Second encryption operation and decryption operations, so the computational complexity is Protocol 2 performs l1+l2+l3+l4+4m+4 encryption operations during execution. decryption operations, so the computational complexity is Among them, l1 and l2 are the number of set elements owned by both parties to the agreement, and l3 and l4 are the number of obfuscated elements added by both parties to the agreement.

[0299] B. Communication complexity analysis:

[0300] In secure multi-party computation protocols, the number of communication rounds is usually used to measure communication complexity. In the "Securely Computing Protocol of Set Intersection under the Malicious Model", Protocol 2 requires 5 rounds of communication when calculating the intersection of sets. In the "Confidential Computation of the Sum of the Elements of Set Intersection", Protocol 2 requires 3 rounds of communication when calculating the sum of the associated values ​​of the elements of the intersection of sets. In the "Confidential Computation of the Maximum Sum of the Corresponding Elements of the Intersection", Protocol 2 requires 4 rounds of communication when calculating the maximum sum of the corresponding elements of the intersection of sets. Protocol 1 of the present invention requires 3 rounds of communication when exchanging homomorphic operation results and ciphertext. To improve the security of the protocol, Protocol 2 requires the participating parties to jointly execute the protocol and introduces a split-select verification process, with 7 communication rounds.

[0301] C. Performance comparison:

[0302] The detailed performance comparison is shown in Table 2:

[0303] Table 2 Performance comparison

[0304]

[0305]

[0306] The references [1] to [3] in the table above correspond to “Securely Computing Protocol of Set Intersection under the Malicious Model”, “Secure Computation of the Sum of Set Intersection Elements”, and “Secure Computation of the Maximum Sum of the Corresponding Elements of the Intersection”. e M is the modular exponential operation. k is a polynomial multiplication operation, m is the amount of split-selection data, Q is the number of elements in the full set, l1 and l2 are the number of set elements owned by both parties to the agreement, and l3 and l4 are the number of obfuscated elements added by both parties to the agreement.

[0307] The comparative analysis results in Table 2 show that the protocols of the present invention are all constructed without a full set. The efficiency of Protocol 1 is significantly improved compared to the protocols in the literature, and it can resist quantum computing attacks, but it cannot resist attacks from malicious adversaries. Although Protocol 2 has increased communication complexity due to the use of the split-selection method, the encryption and decryption process does not require encryption of keywords, and there is no need to determine the intersection through subtraction of keyword ciphertexts, thereby reducing computational complexity and showing obvious advantages over the comparison protocols. In particular, compared with Protocol 2 of the "Securely Computing Protocol of Set Intersection under the Malicious Model" under the same malicious model, the efficiency is significantly improved. Protocol 2 of the present invention not only enhances the ability to resist malicious adversary attacks and quantum computing attacks, but also has a higher security that makes the application range of the protocol wider, with higher application value and potential.

[0308] The present invention transforms the maximum value calculation problem of the sum of numerical values ​​corresponding to keywords in cross-chain data exchange into the maximum value confidential calculation problem of the sum of elements corresponding to set intersection, which can provide valuable information for many fields such as finance, medical care, and archive management under the premise of protecting data privacy. Based on the fully homomorphic NTRU encryption algorithm, the present invention proposes a confidential calculation protocol for the maximum value of the sum of elements corresponding to set intersection under two models, semi-honest and malicious. The protocol under the malicious model avoids the emergence of unfairness and can resist malicious adversary attacks and quantum computing attacks at the same time. The security of the protocol is demonstrated using an ideal-actual example, and the efficiency of the protocol is analyzed through complexity analysis and experimental simulation. The proposed protocol has high practicality and has important research significance in strengthening the security of cross-chain data exchange and the application of secure multi-party computing in blockchain.

[0309] The present invention may have many other embodiments. Without departing from the spirit and essence of the present invention, those skilled in the art may make various corresponding changes and modifications based on the present invention, but these corresponding changes and modifications should all fall within the scope of protection of the claims attached to the present invention.

Claims

1. A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange, characterized by: The two parties who need to perform confidential computation in cross-chain data exchange are denoted as Alice and Bob. Assume that Alice has the set Bob owns the set in, and is a set of keywords, and is a set of associated values, l1 and l2 represent the number of elements in the set; Alice and Bob perform a confidential computation, which includes the following steps: S1, Alice adds l3 keywords and associated values ​​(j i ,0), i=1,2,…,l3, we get S2, Bob adds 14 keywords and associated values ​​(p t ,0), t=1,2,…,l4, we get S3. Alice substitutes the key words in the set M′ into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain will be in The elements of are randomly permuted and sent to Bob; is the ciphertext generated by encrypting pk1 using the fully homomorphic NTRU encryption algorithm; f1 and h1 calculated by Alice using the fully homomorphic NTRU encryption algorithm are the corresponding private key sk1 and public key pk1; S4. Bob substitutes the key words in the set N′ into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain Randomly replace it and send it to Alice; is the ciphertext generated by encrypting pk2 using the fully homomorphic NTRU encryption algorithm; f2 and h2 calculated by Bob using the fully homomorphic NTRU encryption algorithm are the corresponding private key sk2 and public key pk2; S5. If Alice finds that the keyword hash value of the obfuscated element in M′ is the same as the hash value sent by Bob, she will Hash(j a )=Hash(p b ) position and the associated value ciphertext corresponding to the position in N′ are added to obtain S6. If Bob finds that the keyword hash value of the obfuscated element in N′ is the same as the hash value sent by Alice, he will Hash(p b )=Hash(j a ) position and the associated value ciphertext corresponding to the position in M′ are added to obtain S7. If Alice and Bob find that Hash(j a )=Hash(p b ), end; otherwise continue execution; S8. Alice selects random numbers r1, r2, r3, r4 and calculates Send K1 to Bob; S9. Bob selects random numbers r′1, r′2, r′3, r′4 and calculates Send K2 to Alice; S10. If the number of ciphertexts in K1 and K2 is not equal, terminate the process; if the number of ciphertexts in K1 and K2 is equal, continue the process. S11. Alice decrypts K2 and finds the maximum number and the smallest number And send it to Bob; S12. Bob decrypts K1 and finds the maximum number and the smallest number And send it to Alice; S13. After receiving the maximum and minimum numbers, Alice performs the following operations: Get d1 and d′1 as the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection respectively; if d1 and d′1 are not integers, terminate; S14. After receiving the maximum and minimum numbers, Bob performs the following operations: Get d2 and d′2 as the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection respectively; if d2 and d′2 are not integers, terminate; S15. For d1 and d2, d′1 and d′2, Alice selects 4m random polynomials and Bob chooses 4m random polynomials and Where w=1,…,m, and calculate: Announced separately S16, Alice from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Bob to publish the corresponding Alice uses Bob's public key h2 to verify If the verification passes, proceed to the next step, otherwise stop; p is the encryption parameter in the fully homomorphic NTRU encryption algorithm; S17, Bob from group m Randomly select m / 2 groups From group m Randomly select m / 2 groups Ask Alice to publish the corresponding Bob uses Alice's public key h1 to verify If the verification passes, proceed to the next step, otherwise stop; S18, Alice and Bob each take and Randomly select one and From the remaining and Randomly select one and Alice chooses a random polynomial r′ x1 ,r″ x1 , r′ x2 ,r″ x2 ; Bob selects a random polynomial r′ y1 ,r″ y1 , r′ y2 ,r″ y2 ; then do the following: Alice uses Bob's public key h2 to calculate: c x′3 =h2r′ x1 +pr″ x1 +d1 c x′4 =h2r′ x2 +pr″ x2 +d′1 Then calculate Recorded as T1, calculate Recorded as T2, Alice sends T1 and T2 to Bob; Bob uses Alice's public key h1 to calculate: c y′3 =h1r′ y1 +pr″ y1 +d2 c y′4 =h1r′ y2 +pr″ y2 +d′2 Then calculate Denoted as G1, calculate Recorded as G2, Bob sends G1 and G2 to Alice; S19. After Alice obtains G1 and G2, she uses the private key f1 to decrypt G1 and G2 and obtain d1+d2, d′1+d′2. When d1+d2=2d1, d′1+d′2=2d′1, then d2=d1, d′2=d′1. Otherwise, Bob is a malicious participant. S20. After Bob obtains T1 and T2, he uses his private key f2 to decrypt T1 and T2 and obtain d2+d1, d′2+d′1; when d2+d1=2d2, d′2+d′1=2d′2, that is, d1=d2, d′1=d′2; otherwise, Alice is a malicious participant.

2. The method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange according to claim 1, characterized in that: Alice adds l3 keywords and associated values ​​(j i ,0), the set is satisfied Bob adds 14 keywords and associated values ​​(p t ,0), the set is satisfied 3. A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: In step S10, if Bob finds that the number of ciphertexts of K1 and K2 is not equal, Alice is a malicious participant; otherwise, Bob is a malicious participant.

4. A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: In step S13, if d1 and d′1 are not integers, Bob is a malicious participant.

5. A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: In step S14, if d2 and d′2 are not integers, Alice is a malicious participant.

6. A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: When stopping in step S16, Bob is a malicious participant.

7. A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange according to any one of claims 1 to 2, characterized in that: When stopping in step S17, Alice is a malicious participant.

8. A method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange, characterized by: The two parties who need to perform confidential computation in cross-chain data exchange are denoted as Alice and Bob. Assume that Alice has the set Bob owns the set in, and is a set of keywords, and is a set of associated values, l1 and l2 represent the number of elements in the set; Alice and Bob perform a confidential computation, which includes the following steps: Step 1: Alice randomly adds l3 confusing elements (j i ,0), i=1,2,…,l3, we get Confusing elements (l i ,0) in j i is the keyword, and 0 is the associated value corresponding to the keyword; Step 2: Bob randomly adds l4 confusing elements (p t ,0), t=1,2,…,l4, we get Confusing elements (p t ,0) in p t is the keyword, and 0 is the associated value corresponding to the keyword; Step 3: Alice substitutes the key words in the set M′ into the hash function Hash(x) and encrypts the associated value corresponding to the key words to obtain Will The elements in are randomly permuted and sent to Bob; E(·) is the ciphertext generated by encryption using the fully homomorphic NTRU encryption algorithm; Step 4. Bob substitutes the keywords in the set N′ into the hash function Hash(x). If the hash value of the keyword of the obfuscated element is found to be equal to a hash value sent by Alice, no operation is performed on the associated value of the obfuscated element. Hash(p b )=Hash(j a ) The associated value v corresponding to the position b Encrypt and add the ciphertext of the associated value at the corresponding position in M′ to obtain E(u a )+E(v b ); Step 5. Bob selects random numbers r1, r2, r3, r4 and calculates And send K to Alice; Step 6: Alice decrypts K and finds the maximum number and the smallest number And send it to Bob; Step 7. After receiving the maximum and minimum numbers, Bob performs the following operations: Get d1 and d′1, which are the maximum and minimum values ​​of the sum of the corresponding elements of the set intersection respectively; Step 7: After Bob obtains d1 and d′1, he sends d1 and d′1 to Alice.

9. The method for calculating the maximum confidentiality of the sum of keyword values ​​in cross-chain data exchange according to claim 8, characterized in that: Alice randomly adds l3 confusing elements (j i ,0), the set is satisfied Bob randomly adds l4 confusing elements (p t ,0), the set is satisfied