Privacy-protected set containing query method

By adopting encryption scheme and subset division technology in the collection inclusion query method, the problem of leakage of privacy data and query results in the existing technology is solved, efficient privacy protection and data security are achieved, and the privacy protection capability of collection inclusion query is improved.

CN120124094APending Publication Date: 2025-06-10XI'AN POLYTECHNIC UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510075395.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing technology has shortcomings in the field of inquiry collection of privacy protections, and cannot effectively protect the privacy data and query results of participants, which may infringe on the privacy rights of the data owner.

Method used

The set that adopts privacy protection includes query methods. By querying the user to run the encryption scheme to generate public and private keys, the service provider encodes and subsets the private data of both parties involved, and queries the user to calculate the relationship between the integers and the subsets encoded by the query set in parallel, verifying whether the integers encoded by the query set are elements of the candidate set, and finally decryption obtains the set containing the query results.

Benefits of technology

It realizes privacy protection for sensitive data in user query requests, ensuring that service providers cannot obtain user original data and the query results will not be leaked, improving data security and privacy protection capabilities, and improving query efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124094A_ABST
    Figure CN120124094A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection set inclusion query method, which is specifically implemented according to the following steps: step 1, a query user runs an encryption scheme to generate a public key and a private key, and the public key is sent to a service provider; step 2, encoding private data of two parties participating in the method, and performing subset division on an encoded set of a service provider; 3, the query user parallelly and secrecy calculates the relationship between the integer and the subset obtained by encoding the query set to obtain a candidate set; step 4, according to the candidate set obtained in the step 3, verifying whether an integer obtained by querying set coding is an element of the candidate set; and 5, decrypting the verification result obtained in the step 4 to obtain a set containing a query result. According to the method and the device, the problem that privacy data and query results of participants are leaked in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data query methods, and particularly relates to a set inclusion query method for privacy protection. Background Art

[0002] Advances in fields such as the Internet of Things (IoT), social networks, and the application of artificial intelligence have driven the increasing growth of data volume. By 2020, the data volume reached approximately 40 trillion gigabytes, and the big data market grew by 14%. In the era of information explosion, data management and retrieval technologies have become the key to handling massive amounts of information. Set inclusion search, as an efficient data query method, is playing an increasingly important role. This technology is mainly applied to scenarios where it is necessary to quickly find records that meet specific conditions from large datasets. For example, in the recruitment field, the skills possessed by job seekers and the skills required for a job can both be regarded as sets. Then, for a given job recruiter, set inclusion search can help him / her identify which job applicants are qualified for the position. However, the widespread application of this technology is also accompanied by severe data privacy challenges. Given the high sensitivity and commercial value of the data of all parties involved, directly applying set inclusion technology may seriously violate the privacy rights and interests of data owners and even go against their commercial interests, because these data are often regarded as valuable intangible assets of enterprises. Therefore, there is an urgent need to design security guarantee protocols to provide privacy protection for set inclusion query technology.

[0003] However, most existing studies have focused on set inclusion search in the plaintext domain, and there is no existing technology for set inclusion query with privacy protection.

[0004] Therefore, the existing technical framework still has deficiencies in the field of set inclusion query with privacy protection and urgently needs further improvement and optimization to meet the growing data security and privacy protection requirements. Summary of the Invention

[0005] The purpose of the present invention is to provide a set inclusion query method for privacy protection, which solves the problems of leaking the private data of the participating parties and query results existing in the prior art.

[0006] The technical solution adopted by the present invention is that the set inclusion query method for privacy protection is specifically implemented according to the following steps:

[0007] Step 1, the query user runs an encryption scheme to generate public and private keys, and sends the public key to the service provider;

[0008] Step 2, encode the private data of both participating parties and perform subset partitioning on the set encoded by the service provider;

[0009] Step 3: Query the relationship between the integer obtained by the query user through parallel secure computing of the query set encoding and the subset to obtain a candidate set;

[0010] Step 4: According to the candidate set obtained in Step 3, verify whether the integer obtained by encoding the query set is an element of the candidate set;

[0011] Step 5: Decrypt the verification result obtained in Step 4 to obtain the set inclusion query result.

[0012] The features of the present invention also lie in:

[0013] In Step 1, when the query user wants to initiate a query request, the query user runs a homomorphic encryption scheme to generate public and private keys.

[0014] In Step 1, after the query user generates the public and private keys, the query user sends the public key to the service provider through a secure channel to ensure that the query user has the private key of the public key encryption scheme, and the server provider only knows the public key of the encryption scheme.

[0015] Step 2 is specifically implemented according to the following steps:

[0016] Step 2.1: The service provider encodes the power set of the target data set into an integer set according to the quadratic encoding method, and divides the encoded integer set into multiple subsets, and each element in each subset has a value range;

[0017] Step 2.2: The query user encodes the query set according to the same encoding method to obtain a query integer.

[0018] Step 3 is specifically implemented according to the following steps:

[0019] Step 3.1: The query user encrypts the integer obtained by encoding the query set with the public key obtained in Step 1 to obtain a ciphertext and sends the ciphertext to the service provider;

[0020] Step 3.2: After receiving the ciphertext sent by the query user, the service provider performs a homomorphic operation on the maximum and minimum values of the value ranges of the elements in the divided subsets and the ciphertext sent by the query user to obtain a ciphertext result and then sends it to the query user;

[0021] Step 3.3: The query user verifies the ciphertext result. If the verification result is -1, then this subset is the candidate set, and the value of the position of the candidate set in the identification vector is set to 1, otherwise it is set to a random number;

[0022] Step 3.4: The query user encrypts the identification vector and sends it to the service provider.

[0023] Step 4 is specifically implemented according to the following steps:

[0024] Step 4.1: After receiving the identification vector sent by the query user in Step 3, the service provider first performs an addition operation on the elements in the identification vector and the elements in the candidate set, and constructs a polynomial using the calculation result as the root of the polynomial.

[0025] Step 4.2: The service provider encrypts the coefficients of the polynomial obtained in Step 4.1 using the public key obtained in Step 1 and sends them to the query user.

[0026] In Step 5, after receiving the encrypted coefficients sent by the server provider in Step 4.2, the query user uses the private key obtained in Step 1 to decrypt them to obtain the query result.

[0027] In Step 5, if the query set and the target data set are in an inclusion relationship, the decryption result is the unique identifier of the target data set; otherwise, the decryption result is a random number.

[0028] The beneficial effects of the present invention are

[0029] 1) Privacy: Since the user's query request contains the user's sensitive data, during the query process executed by the service provider, it can be ensured that the user's original data is not obtained by the service provider; at the same time, the query result is also private information for other users. Even if the query result is generated by the service provider through calculation, the final query result will not be known to the service provider.

[0030] 2) Confidentiality: Since the target data set is the unique intellectual property of the service provider, the target data set will not be leaked during the entire calculation process.

[0031] 3) High efficiency: The implementation process of the present invention is more concise and clear, and is easy to be applied in engineering. It not only reduces the complexity of technical implementation, but also shortens the product development cycle, which is conducive to the rapid popularization and industrialization process of the technology. Description of the Drawings

[0032] Figure 1 is the calculation overhead diagram of the service provider side in the Kissner scheme;

[0033] Figure 2 is the calculation overhead diagram of the service provider side in the present invention;

[0034] Figure 3 is the calculation overhead diagram of the query user side in the Kissner scheme;

[0035] Figure 4 is the calculation overhead diagram of the query user side in the present invention. Detailed Embodiments

[0036] The present invention will be described in detail below in conjunction with the drawings and specific embodiments.

[0037] Example 1

[0038] The present invention provides a privacy - protected set - inclusion query method. Assume that the querying user and the service provider respectively have a query set and a target data set. The querying user wants to obtain the set - inclusion query result without disclosing other information in their own set to the other party. The specific implementation steps are as follows:

[0039] Step 1, the querying user runs an encryption scheme to generate public and private keys, and sends the public key to the service provider;

[0040] Step 2, encode the private data of both parties and partition the set encoded by the service provider into subsets;

[0041] Step 3, the querying user confidentially calculates the relationship between the integer obtained by encoding the query set and the subsets in parallel to obtain a candidate set;

[0042] Step 4, according to the candidate set obtained in Step 3, verify whether the integer obtained by encoding the query set is an element of the candidate set;

[0043] Step 5, decrypt the verification result obtained in Step 4 to obtain the set - inclusion query result.

[0044] The present invention adopts a quadratic encoding technique, which cleverly transforms the set - inclusion search problem into a problem of determining whether the intersection of the query set and the power set of the data set is empty. Then, the power set of the data set is divided into multiple subsets, and the set - inclusion query is efficiently realized during the screening and refinement process. It is worth emphasizing that the query efficiency of this method is linearly related to the size of the data set and has nothing to do with the number of elements in the querying user's set. This characteristic significantly improves the performance of the algorithm when dealing with large - scale data sets. Secondly, through the Paillier homomorphic encryption technique, a privacy - protected set - inclusion query technique can be realized, which can ensure the privacy of user data and the confidentiality of the target data set of the query service provider.

[0045] Example 2

[0046] A privacy - protected set - inclusion query method. In Step 1, when the querying user wants to initiate a query request, the querying user runs a homomorphic encryption scheme to generate public and private keys; after the querying user generates the public and private keys in Step 1, the querying user sends the public key to the service provider through a secure channel, ensuring that the querying user has the private key of the public - key encryption scheme, and the server provider only knows the public key of this encryption scheme.

[0047] Wherein Step 2 is specifically implemented according to the following steps:

[0048] Step 2.1, the service provider encodes the power set of the target data set into an integer set according to the secondary encoding method, and divides the encoded integer set into multiple subsets, where each element in each subset has a value range;

[0049] Step 2.2, the query user encodes the query set according to the same encoding method to obtain a query integer.

[0050] Embodiment 3

[0051] The privacy-preserving set inclusion query method, wherein Step 3 is specifically implemented according to the following steps:

[0052] Step 3.1, the query user encrypts the integer obtained by encoding the query set with the public key obtained in Step 1 to obtain a ciphertext and sends the ciphertext to the service provider;

[0053] Step 3.2, after receiving the ciphertext sent by the query user, the service provider performs a homomorphic operation on the maximum and minimum values of the value ranges of the elements in the divided subsets and the ciphertext sent by the query user to obtain a ciphertext result and sends it to the query user;

[0054] Step 3.3, the query user verifies the ciphertext result. If the verification result is -1, then this subset is a candidate set, and the value of the position of the candidate set in the identification vector is set to 1, otherwise it is set to a random number;

[0055] Step 3.4, the query user encrypts the identification vector and sends it to the service provider.

[0056] Embodiment 4

[0057] The privacy-preserving set inclusion query method, Step 4 is specifically implemented according to the following steps:

[0058] Step 4.1, after receiving the identification vector sent by the query user in Step 3, the service provider first performs an addition operation on the elements in the identification vector and the elements in the candidate set, and constructs a polynomial with the calculation result as the root of the polynomial;

[0059] Step 4.2, the service provider encrypts the coefficients of the polynomial obtained in Step 4.1 with the public key obtained in Step 1 and sends them to the query user.

[0060] In Step 5, after receiving the encrypted coefficients sent by the server provider in Step 4.2, the query user decrypts them using the private key obtained in Step 1 to obtain the query result; if the query set and the target data set are in an inclusion relationship, the decryption result is the unique identifier of the target data set, otherwise the decryption result is a random number.

[0061] Embodiment 5

[0062] The set inclusion query method for privacy protection is feasible, which means that given a query set, the set inclusion query result can be correctly calculated by the present invention. The present invention transforms the set inclusion search problem into the problem of determining whether the intersection of the query set and the power set of the target data set is empty. If the intersection of the query set and the power set of the target data set is not empty, it means that the query set is included in the target data set; otherwise, the query set is not included in the target data set. To improve the query efficiency, the present invention divides the target data set into multiple subsets. In the query set screening stage, the query user performs parallel secure calculations to obtain the relationship between the integer encoded by the query set and the subsets to obtain an identification vector; in the set inclusion query calculation stage and the query result parsing stage, the query user verifies whether the integer encoded by the query set is an element of the candidate set, and obtains the final query result from the calculation result in the query result parsing stage. The feasibility of the present invention is guaranteed by the correctness of the query set screening algorithm and the set inclusion query algorithm. Specifically,

[0063] Correctness of the query set screening algorithm: The query set screening algorithm essentially solves the problem of secure comparison of the relationship between a number and two numbers in the same process, that is, the problem of securely calculating the size relationship between the ratio of two numbers and "1". If the integer encoded by the query set belongs to the candidate subset, then its value must be within the range of this subset, neither less than the lower bound of the range nor greater than the upper bound of the range, that is, a specific proportional relationship is satisfied between this integer and the upper and lower bounds of the range: the ratio of the lower bound of the range to this integer is less than or equal to 1, and the ratio of the upper bound of the range to this number is greater than or equal to 1.

[0064] Correctness of the set inclusion query algorithm: After the query set screening is completed, the query user sends the identification set to the service provider. If the integer encoded by the query set may be located in the candidate set, the value at the position of the candidate set in the identification vector is 1. The service provider performs an addition operation on the elements in the candidate set and the elements at the corresponding positions in the identification set, and constructs a polynomial using the calculation result as the root of the polynomial. If the integer encoded by the query set is an element in the candidate set, then the value of the polynomial at this integer is equal to the unique identifier of the target set; otherwise, the result is a random number.

[0065] Example 6

[0066] Suppose the set |X i | = m in the service provider, and the query set |Q| = n of the query user.

[0067] (1) Time consumption at the service provider side

[0068] The experimental data shows that when the size m of the service provider set increases from 50 to 100 and the number n of elements in the query set increases from 10 to 50, the computational overhead of the present invention shows a linear growth trend. For example, when m = 50 and n = 10, the computational overhead of the service provider is 2411 ms; when m = 100 and n = 50, the overhead increases to 4435 ms. In the Kissner protocol, the main computational overhead of the service provider is the two parts of encrypting polynomial coefficients and decrypting to obtain the query result. The experimental data shows that the computational overhead of this protocol is also linearly related to m. For example, when m = 50 and n = 10, the computational overhead of the service provider is 2372 ms; when m = 100 and n = 50, the overhead increases to 4575 ms.

[0069] Figure 1-2 The computational costs of the service provider varying with the sizes of m and n are plotted respectively. From these figures, it can be seen that the computational costs of the present invention and the improved Kissner scheme are only linearly related to m, and the growth rate of the improved Kissner scheme is basically the same as that of the present invention. Therefore, the present invention does not bring too much additional computational overhead at the service provider side compared with the improved Kissner scheme. For example, when m = 50 and n = 10, the computational cost of the service provider in this scheme is about 2410 ms, while that of the improved Kissner scheme is about 2370 ms.

[0070] (2) Time consumption at the query user side

[0071] In the present invention, the main computational overhead of the query user is encrypting the query number, decrypting to obtain and decrypting to obtain the diagnostic result. The experimental data shows that when the size m of the service provider set increases from 50 to 100 and n increases from 10 to 50, the computational time consumption of the present invention is only linearly related to m. No matter how much n increases, the performance of the present invention remains stable. When m = 100, the maximum time consumption at the client side is about 329 milliseconds.

[0072] In the Kissner protocol, the main overhead of the query user is that for each element, m modular exponentiation operations and m modular multiplication operations need to be performed to calculate the value of the encrypted polynomial. The experimental data shows that the time consumption of this scheme increases exponentially with the growth of n. For example, when n = 50, the time consumption of the improved Kissner scheme reaches 34310 milliseconds.

[0073] Figure 3-4The computational costs of query users are plotted separately as they vary with the magnitudes of m and n. As can be seen from the figure, the computational cost of this scheme only increases with the increase of m, while the computational cost of the improved Kissner scheme is related to the product of mn. Therefore, the computational cost of the improved Kissner scheme is higher than that of this scheme, and the growth rate of the improved Kissner scheme is much greater than that of this scheme. For example, when m = 100 and n = 50, the computational cost of the query user in this scheme is approximately 324 ms, while that of the improved Kissner scheme is approximately 44310 ms.

[0074] Example 7

[0075] Some background knowledge related to the privacy - protected set - inclusion query method provided by the present invention is described as follows:

[0076] 1. Paillier Encryption Scheme

[0077] The Paillier homomorphic encryption algorithm was proposed by cryptographer P. Paillier in 1999. It is an encryption scheme with additive homomorphism and is widely used in privacy - protected computing, encrypted databases, and ciphertext - based machine learning.

[0078] The Paillier encryption algorithm includes three stages: key generation, encryption process, and decryption process.

[0079] (1) Key - generation stage

[0080] Public key: (n, g)

[0081] Private key: (λ, μ)

[0082] a. Randomly select two large prime numbers p and q, where p, q ∈ Z N , and it is required that:

[0083] gcd(pq, (p - 1)(q - 1)) = 1;

[0084] b. Calculate n = pq;

[0085] c. λ = lcm(p - 1, q - 1), where lcm(·) is the function to find the least common multiple;

[0086] d. Then randomly select satisfying: gcd(L(g λ mod n 2 ), n) = 1, where the function L(·) is defined as

[0087] e. Calculate μ = L(g λ mod n 2 ) -1 .

[0088] (2) Encryption process. For any plaintext message m ∈ Z N , randomly select a random number and calculate the ciphertext c:

[0089] c = Enc(m) = g m r n mod n 2

[0090] (3) Decryption process. For the ciphertext calculate the plaintext m:

[0091]

[0092] The Paillier encryption scheme has good additive homomorphic property. For any plaintext

[0093] 2. Encoding scheme

[0094] The set (where u 1 < … < u m ) is encoded into a 0 / 1 vector U i = (u i1 , … u im ) as follows:

[0095]

[0096] Suppose there is a target data set X i (|X i | = n), and there are 2 n subsets Encode each subset into a vector U i = (u i1 , … u im ) using the 0 / 1 encoding method, and then convert each vector U i into a decimal number to obtain an integer set representing the power set of the set X i .

[0097] Based on the above encoding method and homomorphic encryption algorithm, an efficient set inclusion query scheme is given. The specific implementation steps are as follows:

[0098] Step 1, the participating parties run the encryption scheme to generate public and private keys:

[0099] Step 1.1, query the user to run the key generation algorithm of the Paillier homomorphic encryption scheme Obtain the public and private keys (K pk , K sk );

[0100] Step 1.2, when the query user wants to initiate a query request, send the public key K pk to the service provider through a secure channel.

[0101] Step 2, encode the private data of both participating parties and partition the set encoded by the service provider into subsets:

[0102] Step 2.1, the service provider encodes the power set of the set X i (1 ≤ i ≤ n) into an integer set The query user encodes the query set Q according to the above encoding method to obtain Q′ = {q};

[0103] Step 2.2, the service provider divides the set X i ′ into j subsets The value range of the elements in

[0104] Step 3, the query user performs parallel secure calculations to obtain the relationship between the integer encoded by the query set and the subset to obtain the candidate set:

[0105] Step 3.1, the query user encrypts q to generate C q and sends it to the service provider;

[0106] Step 3.2, after the service provider receives C q , performs a homomorphic operation to obtain and then sends it to the query user;

[0107] Step 3.3, the query user verifies the received from the service provider in Step 3.2. If the product after the function acts satisfies then q is in the subset , set the j-th position of the identification vector T to 1, otherwise it is a random number r;

[0108] Step 3.4, the query user encrypts the identification vector T and sends it to the service provider.

[0109] Step 4, according to the candidate set obtained in Step 3, verify whether the integer encoded by the query set is an element of the candidate set:

[0110] Step 4.1, after the service provider receives the identity vector T sent by the query user, first perform an addition operation on the j-th element of the identity vector T with the elements in the set , and use the calculation result as the root of the polynomial to construct the polynomial P(x);

[0111] Step 4.2, the server encrypts the coefficients of the polynomial obtained in Step 4.1 and sends them to the query user.

[0112] Step 5, decrypt the verification result obtained in Step 4 to obtain a set containing the query result:

[0113] Step 5.1, after the query user receives the encrypted coefficients {Enc(a 0 ), … Enc(a k )} sent by the service provider, decrypt to obtain Dec(Enc(P(q))). If Dec(Enc(P(q))) = id i , it represents Conversely, Dec(Enc(P(q))) is a random number.

Claims

1. A privacy-preserving set-inclusion query method, characterized in that: Please follow the steps below to implement: Step 1: The query user runs the encryption scheme to generate public and private keys, and sends the public key to the service provider; Step 2, encode the private data of both parties and subset the encoded set of the service provider; Step 3, the query user calculates the relationship between the integer obtained by encoding the query set and the sub-set in parallel and confidentially to obtain the candidate set; Step 4: Based on the candidate set obtained in step 3, verify whether the integer obtained by encoding the query set is an element of the candidate set; Step 5, decrypt the verification result obtained in step 4 to obtain the set inclusion query result.

2. The privacy-preserving set inclusion query method according to claim 1, characterized in that: In step 1, when the querying user wants to initiate a query request, the querying user runs a homomorphic encryption scheme to generate public and private keys.

3. The privacy-preserving set inclusion query method according to claim 2, characterized in that: In step 1, after the querying user generates the public and private keys, the querying user sends the public key to the service provider through a secure channel to ensure that the querying user has the private key of the public key encryption scheme, and the service provider only knows the public key of the encryption scheme.

4. The privacy-preserving set inclusion query method according to claim 1, characterized in that: The step 2 is specifically implemented according to the following steps: Step 2.1, the service provider encodes the power set of the target data set into an integer set according to the secondary encoding method, and divides the encoded integer set into multiple subsets, and the elements in each subset have a value range; Step 2.2: The query user encodes the query set in the same encoding method to obtain a query integer.

5. The privacy-preserving set inclusion query method according to claim 1, characterized in that: The step 3 is specifically implemented according to the following steps: Step 3.1, the querying user encrypts the integer after the query set is encoded using the public key obtained in step 1 to obtain the ciphertext and sends the ciphertext to the service provider; Step 3.2, after receiving the ciphertext sent by the querying user, the service provider uses the maximum and minimum values ​​of the value range of the elements in the divided subset to perform a homomorphic operation with the ciphertext sent by the querying user, and then sends the ciphertext result to the querying user; Step 3.3, the query user verifies the ciphertext result. If the verification result is -1, the subset is a candidate set, and the value of the position of the candidate set of the identification vector is set to 1, otherwise it is set to a random number; In step 3.4, the querying user encrypts the identification vector and sends it to the service provider.

6. The privacy-preserving set inclusion query method according to claim 1, characterized in that: The step 4 is specifically implemented according to the following steps: Step 4.1, after receiving the identification vector sent by the querying user in step 3, the service provider first adds the elements in the identification vector to the elements in the candidate set, and uses the calculation result as the root of the polynomial to construct a polynomial; Step 4.2: The service provider encrypts the coefficients of the polynomial obtained in step 4.1 using the public key obtained in step 1 and sends the encrypted data to the querying user.

7. The privacy-preserving set inclusion query method according to claim 1, characterized in that: In step 5, after receiving the encryption coefficient sent by the server provider in step 4.2, the querying user uses the private key obtained in step 1 to decrypt and obtain the query result.

8. The privacy-preserving set inclusion query method according to claim 7, characterized in that: In step 5, if the query set and the target data set are in a containment relationship, the decryption result is a unique identifier of the target data set, otherwise the decryption result is a random number.