Two-party and multi-party privacy set intersection method based on casual key value storage and threshold secret sharing

By adopting inadvertent key-value storage and threshold secret sharing methods in the threshold privacy set intersection protocol, the problems of inefficiency of existing protocols and leakage of intersection cardinality are solved, and efficient and secure multi-party privacy set intersection is achieved.

CN120128328APending Publication Date: 2025-06-10HENAN UNIVERSITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510301454.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing threshold privacy set intersection protocol is inefficient and has the problem of intersection cardinality leakage, especially in multi-party scenarios, which is more difficult to construct.

Method used

Using a method based on inadvertent key-value storage and threshold secret sharing, the collection interception is integrated into the process of judging whether the intersection of participants is greater than the threshold value, which simplifies the protocol construction and reduces the computational overhead.

Benefits of technology

It effectively improves the operation efficiency of the threshold privacy set intersection protocol, avoids the leakage of intersection cardinality, and resists conspiracy attacks in multiple scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128328A_ABST
    Figure CN120128328A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of privacy set intersection, and provides a two-party and multi-party privacy set intersection method based on casual key value storage and threshold secret sharing. According to the two-party privacy set intersection method, in order to judge whether an intersection cardinal number reaches a threshold value or not, OKVS is adopted to associate elements with secret sub-shares, when the number of the intersection elements reaches the threshold value, receiving is convenient, enough correct sub-shares can be obtained, then a secret value is reconstructed, and leakage of the intersection cardinal number is effectively prevented. Meanwhile, in order to avoid exponential-level combination among secret shares, a Reed-Solomon decoding algorithm based on fast Fourier transform is adopted to reconstruct a secret value. In addition, on the basis of two parties, an efficient multi-party privacy set intersection method is designed in combination with unconditional zero sharing. According to the method provided by the invention, the calculation complexity can reach # imgabs0 #, the linear communication overhead is kept, and the attack of a semi-honest enemy can be resisted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of private set intersection, and in particular to two-party and multi-party private set intersection methods based on oblivious key-value storage and threshold secret sharing. Background Art

[0002] Private Set Intersection (PSI), as an important branch of Secure Multi-Party Computation (SMPC), has attracted much attention in the academic community in recent years due to its unique capabilities in distributed environments. Specifically, it allows multiple participants, each holding a private data set, to cooperate to calculate the intersection of these sets, while strictly protecting the privacy information of the non-intersection part from being leaked, demonstrating a high level of data protection and secure computing. With the in-depth research of researchers on private set intersection protocols, in addition to traditional two-party PSI protocols, many different variants have been derived, including Circuit PSI (CPSI), Unbalanced PSI (UPSI), Threshold PSI (TPSI), cloud-assisted PSI, and multi-party PSI, etc.

[0003] Threshold Private Set Intersection (TPSI) allows multiple parties, each with a private set, to obtain the intersection content only when the intersection cardinality of each party is greater than or equal to the threshold value t without disclosing their own privacy information, and it has extensive applications in scenarios such as dating websites, online carpooling, and federated learning. However, existing two-party TPSI or multi-party TPSI generally use public key algorithms with high overhead such as homomorphic encryption, resulting in low protocol operation efficiency.

[0004] Most of the current research work on TPSI focuses on the two-party TPSI scenario. There are already some realizable two-party TPSI schemes, but there are still problems such as low operating efficiency and partial intersection cardinality leakage in some research. The main difference between the TPSI protocol and the PSI protocol is that the TPSI protocol needs to perform a secure threshold test before executing the PSI, that is, calculate the cardinality of the intersection and compare it with the threshold value. During this process, the cardinality of the intersection cannot be leaked. And during the secure threshold test process, it often requires multiple rounds of communication interactions and a large number of complex public key operations such as homomorphic encryption and oblivious transfer, which results in low efficiency of the TPSI protocol. And the construction in the multi-party scenario is more difficult than in the two-party scenario. There are still many challenging problems in the implementation of the multi-party TPSI protocol. For example, more public key operations are required in the calculation during the multi-party threshold test, the communication interaction is more complex, and at the same time, the collusion attacks between multiple participants need to be considered. Therefore, designing a two-party and multi-party TPSI protocol that does not leak the intersection cardinality and is simple and efficient is an urgent problem to be solved currently.

[0005] In addition, the common method of existing TPSI protocols, whether two-party or multi-party, is to first calculate the intersection cardinality, and then judge whether the cardinality is greater than or equal to the threshold value t. If the size of the intersection is greater than the threshold value, the participating parties then execute the ordinary PSI protocol to find the intersection of the sets, and the protocol process is relatively cumbersome. Summary of the Invention

[0006] Aiming at the problem that the process of the threshold private set intersection protocol in the prior art is relatively cumbersome, resulting in low operating efficiency, the present invention proposes a two-party and multi-party private set intersection method based on oblivious key-value storage and threshold secret sharing. By integrating the set intersection into the process of judging whether the intersection of the participants is greater than the threshold value, the construction of the protocol is simplified, the calculation overhead can be effectively reduced, and thus the operating efficiency is improved.

[0007] In the first aspect, the present invention proposes a two-party private set intersection method based on oblivious key-value storage and threshold secret sharing, including:

[0008] Step 101: The sender and the receiver respectively generate random seeds and send them to each other. The two parties combine the received random seeds with their own random seeds to generate redundant elements, and add them to their respective private sets to generate pseudo-private sets;

[0009] Step 102: The sender generates multiple secret sub-shares based on threshold secret sharing and the selected secret value, in combination with the secret polynomial and the index, and sends the hash value of the secret value to the receiver;

[0010] Step 103: The sender constructs a data structure based on the secret sub-shares and the index using OKVS encoding, and sends the data structure to the receiver;

[0011] Step 104: After receiving the data structure, the receiver uses OKVS decoding based on the data structure to obtain the reconstructed secret sub-shares and indexes;

[0012] Step 105: The receiver performs polynomial reconstruction based on the reconstructed secret sub-shares and indexes, and determines whether the number of intersections in the two-party private sets reaches the threshold according to the reconstructed polynomial and the hash value of the secret value. If the threshold is reached, the private set intersection is obtained according to the reconstructed secret polynomial.

[0013] Further, the specific steps of Step 101 include:

[0014] Step 1011: Sender A and receiver B respectively hold private sets X = {x 1 , x 2 , …, x n} ∈ {0, 1} * and Y = {y 1 , y 2 , …, y n} ∈ {0, 1} * , |X| = |Y| = n;

[0015] Step 1012: Sender A and receiver B respectively generate random seeds seed 1 ∈ {0, 1} λ and seed 2 ∈ {0, 1} λ and send them to each other;

[0016] Step 1013: The two parties use as the seed of the pseudo-random number generator to generate n - t redundant elements and add them to their own private sets, generating pseudo-private sets X' = {x 1 ,..., x n , x n+1 , …, x 2n-t} and Y' = {y 1 ,..., y n , y n+1 , …, y 2n-t}, where t represents the threshold.

[0017] Further, the specific steps of Step 102 include:

[0018] Step 1021: Sender A uses Shamir secret sharing to randomly generate a secret value s;

[0019] Step 1022: Sender A selects a polynomial f(x) that satisfies f(0) = s and has a highest degree of t - 1; where t represents the threshold;

[0020] Step 1023: Randomly select 2n - t fixed points of the polynomial f(x) as indices ind i , and calculate the corresponding secret sub - shares s i = f(ind i ), obtaining 2n - t secret sub - shares (s 1 , s 2 , …, s 2n-t ) ∈ {0, 1} λ , where ind i represents the index corresponding to the i - th secret sub - share;

[0021] Step 1024: Perform a hash operation on the secret value s to obtain the hash value H(s) of the secret value s and send it to the recipient B.

[0022] Furthermore, the step 103 specifically includes:

[0023] Step 1031: The sender A performs a hash operation on the element x i in its own pseudo - private set X′ to obtain H(x i );

[0024] Step 1032: The sender A uses H(x i ) as the key and performs OKVS encoding on the secret sub - share and the corresponding index s i ||ind i as the value to obtain the data structure Q = Encode({(H(x i ), s i ||ind i )|i ∈ [2n - t]}), and sends the data structure Q to the recipient B;

[0025] The step 104 specifically includes:

[0026] Step 1041: After receiving the data structure Q, the recipient B performs a hash operation on the element y i in its own pseudo - private set Y′ to obtain H(y i );

[0027] Step 1042: The recipient B uses H(y i ) as the key and performs OKVS decoding to obtain the reconstructed secret sub - share and index s′ i ||ind′ i = Decode(H(y i ), Q).

[0028] Furthermore, the step 105 specifically includes:

[0029] Step 1051: The recipient B takes the reconstructed secret sub-shares {s′ i |i ∈ [2n - t]} and the indices {ind′ i |i ∈ [2n - t]} as the input of the Reed-Solomon decoding algorithm to obtain the reconstructed polynomial f′(x);

[0030] Step 1052: Calculate whether H(f′(0)) is equal to H(s). If not, terminate the step and output ⊥. If equal, the number of the private set intersections of the two parties reaches the threshold value, and proceed to Step 1053;

[0031] Step 1053: For all the reconstructed secret sub-shares s′ i , i ∈ [n], the recipient B checks whether s′ i is equal to f′(ind′ i ). If equal, add the corresponding y i to the private set intersection I. Finally, the recipient B outputs the private set I.

[0032] On the second aspect, the present invention proposes a multi-party private set intersection method based on oblivious key-value storage and threshold secret sharing, including:

[0033] Step 201: N participants {P 1 , …, P i …, P N} respectively generate random seeds and exchange them with each other. The N participants generate redundant elements according to the received random seeds combined with their own random seeds and add them to their respective private sets to generate pseudo-private sets;

[0034] Step 202: Select P 1 as the recipient. The recipient P 1 generates multiple secret sub-shares based on threshold secret sharing and the selected secret value, in combination with the secret polynomial and the indices;

[0035] Step 203: The participant P i , i ∈ [N] randomly selects the key of the pseudo-random function and sends it to the sender P j , where j > i. The participant P i , i ∈ [N] calculates their respective pseudo-random values sh i (h):

[0036]

[0037] where h ∈ X′ i represents any element in the pseudo-private set of the participant P i ;

[0038] Step 204: Participant P i , i ∈ [2, N] generates its own data structure Q based on its own pseudorandom value sh i (h) constructs its own data structure Q using OKVS encoding i and sends the data structure Q i to the recipient P 1 ; The recipient P 1 calculates its own data structure Q based on the secret sub-share and its own pseudorandom value 1 ;

[0039] Step 205: The recipient P 1 receives the data structures Q of the other N - 1 participants P i , i ∈ [2, N], and performs OKVS decoding based on the data structure Q i to obtain the reconstructed secret sub-share and index; i

[0040] Step 206: The recipient P 1 performs polynomial reconstruction on the reconstructed secret sub-share and index, and determines whether the number of intersections in the multi-party private set reaches the threshold value according to the reconstructed polynomial f'(x) and the secret value. If the threshold value is reached, the private set intersection is obtained according to the reconstructed secret polynomial.

[0041] Furthermore, the specific steps of step 201 include:

[0042] Step 2011: N participants {P 1 , …, P i …, P N}, i ∈ [N] each hold a set |X i | = n, i ∈ [N];

[0043] Step 2012: N participants each generate a random seed seed i ∈ {0, 1} λ and exchange them with each other;

[0044] Step 2013: Participant P i , i ∈ [N] calculates as the seed of the pseudorandom number generator to generate n - t redundant elements and add them to their respective private sets to generate a pseudo-private set where t represents the threshold value.

[0045] Furthermore, the specific steps of step 202 include:

[0046] Step 2021: Select P 1 ​As the recipient, recipient P 1 Randomly generate a secret value s using Shamir secret sharing;

[0047] Step 2022: Recipient P 1 Select a polynomial f(x) that satisfies f(0) = s and has a maximum degree of t - 1; where t represents the threshold value;

[0048] Step 2023: Randomly select 2n - t fixed points as indices ind for the polynomial f(x) i and calculate the corresponding secret sub - shares s i = f(ind i ), obtaining 2n - t secret shares (s 1 , s 2 , …, s 2n-t ) ∈ {0, 1} λ , where ind i represents the index corresponding to the i - th secret sub - share.

[0049] Furthermore, the specific steps of step 204 include:

[0050] Step 2041: Party P i , i ∈ [2, N] performs a hash operation on the elements i in its pseudo - private set X′ to obtain

[0051] Step 2042: Party P i , i ∈ [2, N] uses the as a key and the pseudo - random value sh i (h) as a value to perform OKVS encoding to obtain a data structure and sends Q i to recipient P 1 ;

[0052] Step 2043: Recipient P 1 performs a hash operation on the elements 1 in its pseudo - private set X′ to obtain

[0053] Step 2044: Recipient P 1 uses the as a key and the pseudo - random value as a value to perform OKVS encoding to obtain a data structure

[0054] The specific steps of step 205 include:

[0055] Step 2051: Receiver P 1 receives the data structures Q of the other N - 1 participating parties P i , i ∈ [2, N] i ;

[0056] Step 2052: Using as the key, perform OKVS decoding to obtain the reconstructed secret sub - share index

[0057] Furthermore, the specific steps of step 206 are as follows:

[0058] Step 2061: Receiver P 1 uses the reconstructed secret sub - shares {s′ i |i ∈ [2n - t]} and indices {ind′ i |i ∈ [2n - t]} as the input of the Reed - Solomon decoding algorithm to obtain the reconstructed polynomial f′(x);

[0059] Step 2062: Calculate s′ = f′(0), then determine whether s′ is equal to the secret value s. If not, terminate the steps and output ⊥; if equal, the number of multi - party private set intersections reaches the threshold value, and proceed to step 2063;

[0060] Step 2063: For all the reconstructed secret sub - shares s′ j , j ∈ [n], receiver P 1 checks whether s′ j is equal to f′(ind′ j ). If equal, add the corresponding to the private set intersection I. Finally, receiver P 1 outputs the private set intersection I.

[0061] The beneficial effects of the present invention are as follows:

[0062] The present invention designs two - party and multi - party threshold private set intersection methods for the number of participating parties in the threshold private set intersection protocol, uses a more efficient OKVS data structure, and combines threshold secret sharing based on the Reed - Solomon decoding algorithm to reconstruct the secret value, avoiding exponential combinations between secret shares and also avoiding the use of relatively expensive public - key operations such as homomorphic encryption. For security, the two - party TPSI proposed by the present invention can resist attacks from semi - honest adversaries, and the multi - party TPSI can resist up to N - 1 party collusion attacks without revealing the cardinality of the intersection. Analyze the communication and computational complexity of the two protocols and compare them with other protocols of the same type. The results show that the two protocols proposed by the present invention are more efficient than the previous ones. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 It is a schematic flowchart of the ideal two-party TPSI protocol function provided by the embodiment of the present invention;

[0064] Figure 2 It is a schematic flowchart of the ideal multi-party TPSI protocol function provided by the embodiment of the present invention;

[0065] Figure 3 It is a schematic flowchart of the Shamir threshold secret sharing ideal function provided by the embodiment of the present invention;

[0066] Figure 4 It is a schematic flowchart of a two-party private set intersection method based on oblivious key-value storage and threshold secret sharing provided by the embodiment of the present invention;

[0067] Figure 5 It is a schematic construction diagram of a two-party private set intersection method based on oblivious key-value storage and threshold secret sharing provided by the embodiment of the present invention;

[0068] Figure 6 It is a schematic flowchart of a multi-party private set intersection method based on oblivious key-value storage and threshold secret sharing provided by the embodiment of the present invention;

[0069] Figure 7 It is a schematic construction diagram of a multi-party private set intersection method based on oblivious key-value storage and threshold secret sharing provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0070] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0071] To facilitate the understanding of the present invention, the technologies involved are first explained:

[0072] 1. Symbols

[0073] In the present invention, λ and σ are respectively used to represent the computational security parameter and the statistical security parameter; [n] is used to represent {1,..., n}; in the two-party TPSI scenario, it is assumed that the sender P 1 owns the set X, and the receiver P 2 owns the set Y, and the sizes of both sets are n, where x i , y i ∈{0, 1}* . In the multi-party TPSI scenario, assume there are participating parties {P i} i∈[N] , each having its own set where Assume P 1 acts as the central party in the star network topology and interacts with the other N - 1 parties. Finally, party P 1 outputs the intersection result. Let t be the threshold value, and m represent the length of the data structure Q output using the OKVS encoding algorithm. The hash function is denoted as H: {0, 1} * →{0, 1} λ . Let represent the random secret value in the Shamir secret sharing scheme, s i , ind i ∈{0, 1} λ represent the i-th secret share of s and its corresponding index, satisfying f(ind i ) = s i . Use to ignore any polynomial logarithmic factors, i.e.,

[0074] 2. Oblivious Key - Value Store

[0075] A Key - Value Stores (KVS) scheme consists of a key set K = {k 1 , …, k n}, a value set V = {v 1 , …, v n}, an encoding algorithm Encode(·) and a decoding algorithm Ddecode(·). Where:

[0076] Encode(·): Given a set of (k i , v i ) key - value pairs, output a data structure Q, or output ⊥ with statistically negligible probability.

[0077] Ddecode(·): Given a data structure Q and a key k, output a value v.

[0078] If a KVS scheme is correct, then for any combination of key - value pairs it satisfies:

[0079]

[0080] If a KVS scheme is an Oblivious Key - Value Store (OKVS) scheme, then for any two different key sets and If the Encode algorithm does not output ⊥ for or , then and are computationally indistinguishable, where

[0081]

[0082] for i ∈ [1, n]: do v i ← V

[0083] return Encode({(k 1 , v 1 ), …, (k n , v n )})

[0084] In other words, in the OKVS scheme, two sets of keys K 0 and K 1 are used to encode the same set of random values, obtaining Encode(K 0 , V) and Encode(K 1 , V) respectively. If there exists a probabilistic polynomial-time (PPT) adversary and a non-uniform polynomial-time algorithm D, and there exists a negligible function ε(·) such that:

[0085] |Pr[D(Encode(K 0 , V))] - Pr[D(Encode(K 1 , V))]| ≤ ε(·)

[0086] then the scheme satisfies obliviousness and is thus an OKVS scheme.

[0087] A binary OKVS over a finite field is a special form of a linear OKVS, and we will focus on In this case, the addition operation over

[0088] Encode((x 1 , y 1 ), …, (x n , y n )): Given n pairs (x i , y i ), where x i∈ {0, 1} * , y i ∈ {0, 1} l , let M denote a matrix of size n × m, where the i-th row represents v(x i ). The data structure Q = (q 1 , …, q m ) T ∈ ({0, 1} l ) m can be solved such that M × Q = (y 1 , …, y n ), that is, to solve the following system of linear equations: T , i.e., solve the following system of linear equations:

[0089]

[0090] When v(x i ) is linearly independent, the solution of this system of equations must exist.

[0091] Decode(Q, x): Given the data structure Q and the key x ∈ {0, 1} * , its corresponding value can be retrieved through the following formula:

[0092]

[0093] Probing the key x in Q is equivalent to computing the XOR at a specific position in Q, where the selection of the position is defined by v(x) and depends on x.

[0094] 3. TPSI

[0095] TPSI is a variant of PSI that ensures that when the number of elements in the intersection of all participating parties is greater than or equal to the threshold value t, the receiving party can output the intersection content without revealing the elements of each participating party's respective set. The ideal two-party TPSI protocol requires two participating parties P 1 and P 2 in the protocol, each having a set X and Y of size n. After executing the two-party secure computation protocol Π, if the size of the intersection I = X ∩ Y is greater than or equal to the threshold value t, the receiving party obtains the final intersection I; otherwise, the receiving party outputs ⊥. The formal definition of Figure 1 is as shown. For the ideal multi-party TPSI protocol, it is required to satisfy that in a star network topology, for N participating parties P 1 , …, P N in the protocol, each having a set X 1 , …, X N of size n, after executing a multi-party secure computation protocol Π, if the intersection of all parties I = X 1 ∩ … ∩ X NIf the size is greater than or equal to the threshold value t, the receiver obtains the final intersection I; otherwise, the receiver outputs ⊥. The ideal multi-party TPSI protocol The formal definition is as Figure 2 shown below.

[0096] 4. Threshold Secret Sharing and Reed-Solomon Coding

[0097] Secret Sharing (SS) is a common cryptographic primitive that divides a secret value into multiple parts and distributes them to different participants. Its core idea is to split a secret in an appropriate way, and each split share (or "share") is managed by a different participant. No single participant can recover the complete secret information, and only several participants working together can recover the secret message. The (t, n) threshold secret sharing (TSS) scheme is the most classical secret sharing scheme, which requires at least any t participants to combine to recover the secret, where t and n are the minimum number of participants required to recover the secret and the total number of participants respectively (1 < t < n). This can ensure the security of the secret and has a certain degree of flexibility.

[0098] Shamir threshold secret sharing is a type of TSS scheme that uses polynomial interpolation to reconstruct the secret. It mainly consists of two stages. In the secret share generation stage, a polynomial f(x) that satisfies f(0) = s and has the highest degree of t - 1 is selected, and then for randomly selected fixed points ind i , the corresponding secret sub-share s i = f(ind i ) is calculated. In the secret reconstruction stage, t points ind i and the secret sub-share s′ i are used as inputs, and the Lagrange interpolation method is used to construct the polynomial f′(x). Shamir threshold secret sharing satisfies that when t points ind i and the corresponding secret sub-shares s′ i are correct (that is, for the same points ind i , s′ i = s i ), then f′(x) = f(x). The formal definition of the ideal function of Shamir secret sharing is as Figure 3 shown below.

[0099] Reed-Solomon coding is a block-based error-correcting code widely used in digital communication and storage systems. It aims to improve the reliability of data transmission and storage by adding extra "redundant" bits. The Reed-Solomon decoding algorithm provides an extension and generalization for the reconstruction phase of the Shamir secret sharing scheme. The combination of the two mainly lies in using the redundancy and error-correcting ability of the coding to protect the secret information, and can greatly improve the efficiency of reconstructing the secret. This coding ignores some incorrect shares and outputs a polynomial to reconstruct the secret value s, while using the fast Fourier transform can protect the error share position information from being leaked. The following gives the formal definition of the Reed-Solomon coding algorithm.

[0100] Definition: For integers k, n, and a finite field F, satisfying 0 < k ≤ n < |F|, and there exists a set containing n elements Define the Reed-Solomon algorithm RS F,S [n,k] = (C,D) is an algorithm composed of the encoding function C: F[X] k-1 → F n and the decoding function D: F n → F[X] k-1 where:

[0101] Encoding function C: For the message f(X) ∈ F[X] k-1 , let C(f(X)) = (f(x i )) i∈[n] .

[0102] Decoding function D: For a set of vectors (b n ) i belonging to the finite field F i∈[n] , there exists a polynomial g(X) ∈ F[X] k-1 and satisfying g(x i ) = b i , let D((b i ) i∈[n] ) = g(X).

[0103] 5 Security model

[0104] This invention only focuses on the security of the model in the presence of static semi - honest adversaries. In the static semi - honest security model, the adversary can only decide to control a certain party before the start of the protocol and run strictly according to the protocol requirements, but will try to infer the private information or input data of other parties by analyzing the information obtained during the protocol execution (including intermediate results, interactive information, etc.). If anything that a party can compute can only be obtained from the inputs and outputs of the protocol, then the protocol is secure. It is required that the view of a party during the protocol execution can be simulated given only its input and output. This invention defines the security models for two - party and multi - party scenarios respectively.

[0105] 5.1 Two - Party Secure Computation Model

[0106] In two - party TPSI, the sender and the receiver respectively have sets \(X\) and \(Y\), and execute a two - party secure computation protocol to compute the function \(f\) and output \(f(X,Y)\). Define the function \(f:\{0,1\}\) * \(\times\{0,1\}\) * \(\to\{0,1\}\) * where \(f = X\cap Y\) and \(f\) is a deterministic function. Define \(\pi\) as a secure computation protocol for computing the function \(d\). The real views of the sender and the receiver are respectively denoted as and where \(\lambda\) is the secure computation parameter. The output of the sender is \(\perp\), and the output of the receiver is defined as If \(|X\cap Y|\geq t\), then Otherwise

[0107] Define: Let \(f\) be a deterministic function. If there exist PPT algorithms Sim

[0108]

[0109] and Sim 1 and Sim 2 such that the protocol \(\pi\) can resist semi - honest adversaries and securely compute the function \(f\), where \(X,Y\in\{0,1\}\) * , and \(|X| = |Y|\).

[0110] 5.2 Multi - Party Secure Computation Model

[0111] Different from the two - party security model, in the multi - party setting, the security of the protocol needs to be considered under the collusion of multiple corrupted parties simultaneously. Let For the view of the corrupted parties \(C\) where is the input of the parties.

[0112] Define: Let \(f:(\{0,1\}\) * )N → ({0, 1} * ) N is a deterministic function, and π is a secure multi-party protocol for computing the function f. If there exists a PPT algorithm S such that for any C, it satisfies:

[0113]

[0114] then the protocol π is secure in the presence of semi-honest adversaries.

[0115] Based on the above technology, as Figure 4 shown, an embodiment of the present invention provides a two-party private set intersection method based on oblivious key-value storage and threshold secret sharing. The specific process is as Figure 5 shown, including:

[0116] Step 101: The sender and the receiver respectively generate random seeds and send them to each other. The two parties combine the received random seeds with their own random seeds to generate redundant elements, and add them to their respective private sets to generate pseudo-private sets.

[0117] Specifically, Step 101 includes:

[0118] Step 1011: The sender A and the receiver B respectively hold private sets X = {x 1 , x 2 , …, x n} ∈ {0, 1} * and Y = {y 1 , y 2 , …, y n} ∈ {0, 1} * , |X| = |Y| = n;

[0119] Step 1012: The sender A and the receiver B respectively generate random seeds seed 1 ∈ {0, 1} λ and seed 2 ∈ {0, 1} λ and send them to each other;

[0120] Step 1013: The two parties use as the seed of the pseudo-random number generator to generate n - t redundant elements and add them to their own private sets to generate pseudo-private sets X' = {x 1 ,..., x n , x n+1 , …, x 2n-t} and Y' = {y 1 ,..., y n , y n+1 , …, y 2n-t}, where t represents the threshold value.

[0121] Step 102: The sender generates multiple secret sub-shares based on threshold secret sharing, the selected secret value, in combination with a secret polynomial and indices, and sends the hash value of the secret value to the receiver; wherein, the number of secret sub-shares and indices is the same as the number of elements in the pseudo-private set.

[0122] Specifically, Step 102 includes:

[0123] Step 1021: Sender A randomly generates a secret value s using Shamir secret sharing.

[0124] Step 1022: Sender A selects a polynomial f(x) that satisfies f(0) = s and has a maximum degree of t - 1; where t represents the threshold value.

[0125] Step 1023: Randomly select 2n - t fixed points as indices ind i for the polynomial f(x), and calculate the corresponding secret sub-shares s i = f(ind i ), obtaining 2n - t secret sub-shares (s 1 , s 2 , …, s 2n-t ) ∈ {0, 1} λ , where ind i represents the index corresponding to the i-th secret sub-share.

[0126] Step 1024: Perform a hash operation on the secret value s to obtain the hash value H(s) of the secret value and send it to Receiver B.

[0127] Step 103: The sender constructs a data structure using OKVS encoding based on the secret sub-shares and indices, and sends the data structure to the receiver.

[0128] Specifically, Step 103 includes:

[0129] Step 1031: Sender A performs a hash operation on the element x i in its own pseudo-private set X' to obtain H(x i ).

[0130] Step 1032: Sender A uses H(x i ) as the key, and uses the secret sub-share and the corresponding index s i || ind i as the value to perform OKVS encoding to obtain a data structure Q = Encode({(H(x i ), s i || ind i ) | i ∈ [2n - t]}), and sends the data structure Q to Receiver B.

[0131] Step 104: After the receiver receives the data structure, the reconstructed secret sub-share and index are obtained by decoding using OKVS based on the data structure;

[0132] Specifically, Step 104 includes:

[0133] Step 1041: After receiver B receives the data structure Q, the element y in its own pseudo-private set Y' i is hashed to obtain H(y i );

[0134] Step 1042: Receiver B uses H(y i ) as the key and performs OKVS decoding to obtain the reconstructed secret sub-share and index s' i ||ind' i = Decode(H(y i ), Q).

[0135] Step 105: The receiver performs polynomial reconstruction based on the reconstructed secret sub-share and index, and determines whether the number of intersections in the two-party private sets reaches the threshold according to the reconstructed polynomial and the hash value of the secret value. If the threshold is reached, the private set intersection is obtained according to the reconstructed secret polynomial.

[0136] Specifically, Step 105 includes:

[0137] Step 1051: Receiver B uses the reconstructed secret sub-shares {s' i | i ∈ [2n - t]} and indexes {ind' i | i ∈ [2n - t]} as the input of the Reed-Solomon decoding algorithm to obtain the reconstructed polynomial f'(x);

[0138] Step 1052: Calculate whether H(f'(0)) is equal to H(s). If not, the step terminates and ⊥ is output; if equal, the number of intersections in the two-party private sets reaches the threshold, and Step 1053 is performed;

[0139] Step 1053: For all reconstructed secret sub-shares s' i , i ∈ [n], receiver B checks whether s' i is equal to f'(ind' i ). If equal, the corresponding y i is added to the private set intersection I, and finally receiver B outputs the private set I.

[0140] An embodiment of the present invention designs a new two-party TPSI protocol based on Oblivious Key-Value Store (OKVS) and threshold secret sharing. By associating secret sub-shares with set elements and using them to construct the OKVS data structure, it finally checks whether the secret value reconstructed by the receiver is the same as the secret value of the sender to determine whether the intersection reaches the threshold value, and can effectively protect the intersection cardinality from being leaked.

[0141] As Figure 6 shown, an embodiment of the present invention also provides a multi-party private set intersection method based on oblivious key-value storage and threshold secret sharing. The specific process is as Figure 7 shown, including:

[0142] Step 201: N participants {P 1 , …, P i …, P N} respectively generate random seeds and exchange them with each other. The N participants generate redundant elements according to the received random seeds combined with their own random seeds and add them to their respective private sets to generate pseudo-private sets;

[0143] Specifically, step 201 includes:

[0144] Step 2011: N participants {P 1 , …, P i …, P N}, i ∈ [N] respectively hold sets |X i | = n, i ∈ [N];

[0145] Step 2012: The N participants respectively generate random seeds seed i ∈ {0, 1} λ and exchange them with each other;

[0146] Step 2013: Participant P i , i ∈ [N] calculates as the seed of the pseudo-random number generator to generate n - t redundant elements and add them to their respective private sets to generate pseudo-private sets where t represents the threshold value.

[0147] Step 202: Select P 1 as the receiver. The receiver P 1 generates multiple secret sub-shares based on threshold secret sharing and the selected secret value, in combination with the secret polynomial and the index; wherein, the number of secret sub-shares and the index is the same as the number of elements in the pseudo-private set of participant P 1 ;

[0148] Specifically, step 202 includes:

[0149] Step 2021: The receiving party P 1 Randomly generates a secret value s using Shamir secret sharing;

[0150] Step 2022: The receiving party P 1 Selects a polynomial f(x) that satisfies f(0) = s and has a highest degree of 2n - t;

[0151] Step 2023: For a randomly selected fixed point ind of the polynomial f(x) i , calculates the corresponding secret sub-share s i = f(ind i ), obtaining 2n - t secret shares (s 1 , s 2 , …, s 2n-t ) ∈ {0, 1} λ , where ind i represents the index corresponding to the i-th secret sub-share.

[0152] Step 203: The participating party P i , i ∈ [N] randomly selects the key of the pseudorandom function and sends it to the sending party P j , where j > i, and the participating party P i , i ∈ [N] calculates its respective pseudorandom value sh i (h):

[0153]

[0154] where h ∈ X' i represents any element in the pseudoprivate set of the participating party P i ;

[0155] Step 204: The participating party P i , i ∈ [2, N] constructs its own data structure Q using OKVS encoding based on its own pseudorandom value sh i and sends the data structure Q i to the receiving party P i ; The receiving party P 1 calculates its own data structure Q based on the secret sub-share and its own pseudorandom value 1 ; 1 ;

[0156] Specifically, step 204 includes:

[0157] Step 2041: The participating party P i , i ∈ [2, N] places the elements in its own pseudoprivate set X' i in Perform a hashing operation to obtain

[0158] Step 2042: Party P i , i ∈ [2, N] will As the key, use the pseudorandom value sh i (h) as the value to perform OKVS encoding to obtain a data structure And send Q i To the receiving party P 1 ;

[0159] Step 2043: Receiving party P 1 Perform a hashing operation on the elements in its own pseudo-private set X' 1 to obtain Perform a hashing operation to obtain

[0160] Step 2044: Receiving party P 1 Use As the key, and use the pseudorandom value As the value to perform OKVS encoding to obtain a data structure

[0161] Step 205: Receiving party P 1 Receives the data structures Q of the other N - 1 participating parties P i , i ∈ [2, N], and based on the data structure Q i Perform OKVS decoding to obtain the reconstructed secret sub-shares and indices; i Specifically, step 205 includes:

[0162] Specifically, step 205 includes:

[0163] Step 2051: Receiving party P 1 Receives the data structures Q of the other N - 1 participating parties P i , i ∈ [2, N]; i ;

[0164] Step 2052: Use As the key to perform OKVS decoding to obtain the reconstructed secret sub-share index

[0165] Step 206: Receiving party P 1 Perform polynomial reconstruction on the reconstructed secret sub-shares and indices, and based on the reconstructed polynomial f'(x) and the secret value, determine whether the number of intersections in the multi-party private set reaches the threshold value. If the threshold value is reached, obtain the private set intersection according to the reconstructed secret polynomial.

[0166] Specifically, step 206 includes:

[0167] Step 2061: Receiver P 1 uses the reconstructed secret sub-shares {s′ i | i ∈ [2n - t]} and the indices {ind′ i | i ∈ [2n - t]} as the input of the Reed - Solomon decoding algorithm to obtain the reconstructed polynomial f′(x);

[0168] Step 2062: Calculate s′ = f′(0), and then determine whether s′ is equal to the secret value s. If not, the step terminates and ⊥ is output; if equal, the number of multi-party private set intersections reaches the threshold value, and proceed to Step 2063;

[0169] Step 2063: For all the reconstructed secret sub-shares s′ j , j ∈ [n], Receiver P 1 checks whether s′ j is equal to f′(ind′ j ). If equal, the corresponding is added to the private set intersection I, and finally Receiver P 1 outputs the private set intersection I.

[0170] Based on the two-party TPSI protocol, the embodiment of the present invention provides a multi-party TPSI protocol resistant to collusion attacks, which can resist collusion of up to N - 1 parties and will not disclose the cardinality of the intersection. By using the unconditional zero-sharing method to associate the elements in each participating party's set, according to the properties of unconditional zero-sharing, it can be deduced that when an element h belongs to the elements in the intersection of all parties, the exclusive OR of the pseudo-random values sh i (h) calculated by all participating parties will be 0. Further, the receiver can obtain the correct secret sub-shares by processing the calculation results, and then be able to reconstruct the secret value, which also reflects from the side that the cardinality of the intersection reaches the threshold value t. At the same time, in order to speed up the processing speed of the receiver, in the selection of the interaction method between the receiver and other participating parties, the present invention adopts a star network topology structure, and other participating parties can send the encoded OKVS data structure to the receiver simultaneously, thereby greatly improving the network bandwidth.

[0171] Next, the present invention will be compared with other methods of the same type, and the comparison results are shown in Table 1:

[0172] Table 1 Comparison of Computational and Communication Complexities of Two-Party and Multi-Party TPSI Protocols

[0173]

[0174]

[0175] Note: Protocol A and Protocol B are the two-party and multi-party TPSI protocols proposed in this invention, λ is the computational security parameter, t is the threshold value, N is the number of participants, n is the number of set elements, m is the length of the OKVS data structure, and k is the number of hash functions used. is polynomial logarithmic time.

[0176] Protocol ①: Hallgren P, Orlandi C, Sabelfeld A. PrivatePool: Privacy-preserving ridesharing[C] / / 2017 IEEE 30th Computer Security Foundations Symposium(CSF). IEEE, 2017:276-291.

[0177] Protocol ②: Zhao Y, Chow S S M. Can you find the one for me?[C] / / Proceedings of the 2018 Workshop on Privacy in the Electronic Society. 2018:54-65.

[0178] Protocol ③: Ghosh S, Nilges T. An algebraic approach to maliciously secure private set intersection[C] / / Annual international conference on the theory and applications of cryptographic techniques. Cham: Springer International Publishing, 2019:154-185.

[0179] Protocol ④: Ghosh S, Simkin M. The communication complexity of threshold private set intersection[C] / / Annual International Cryptology Conference. Cham: Springer International Publishing, 2019:3-29.

[0180] Protocol ⑤: Badrinarayanan S, Miao P, Raghuraman S, et al. Multi-party threshold private set intersection with sublinear communication[C] / / IACR International Conference on Public-Key Cryptography. Cham: Springer International Publishing, 2021: 349-379.

[0181] Protocol ⑥: Branco P, N, Pu S. Multiparty cardinality testing for threshold private intersection[C] / / IACR International Conference on Public-Key Cryptography. Cham: Springer International Publishing, 2021: 32-60.

[0182] Protocol ⑦: Ghosh S, Simkin M. Threshold private set intersection with better communication complexity[C] / / IACR International Conference on Public-Key Cryptography. Cham: Springer Nature Switzerland, 2023: 251-272.

[0183] The present invention designs two efficient two-party and multi-party TPSI protocols. Compared with previous TPSI protocols, the two TPSI protocols of the present invention avoid using public key operations with high overheads, such as Threshold Key Encapsulation Mechanism (T-KEM), Oblivious Linear Function Evaluation (OLE), etc., and instead use the OKVS data structure with lower computational overheads. As shown in Table 1, for both two-party and multi-party TPSI protocols, the computational complexity is Compared with the computational overhead of the prior art, the computational overhead of the protocol proposed by the present invention has been reduced by an order of magnitude. Although the communication overhead has not been significantly reduced compared with the previous work, it remains basically unchanged.

[0184] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A two-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing, characterized in that: include: Step 101: The sender and the receiver generate random seeds respectively and send them to each other. The two parties combine the received random seeds with their own random seeds to generate redundant elements, and add them to their own privacy sets to generate pseudo-privacy sets; Step 102: The sender generates a plurality of secret sub-shares based on the threshold secret sharing and the selected secret value, in combination with the secret polynomial and the index, and sends the hash value of the secret value to the receiver; Step 103: The sender constructs a data structure using OKVS encoding based on the secret sub-share and the index, and sends the data structure to the receiver; Step 104: After receiving the data structure, the receiver uses OKVS decoding based on the data structure to obtain the reconstructed secret sub-share and index; Step 105: The receiver reconstructs the polynomial based on the reconstructed secret sub-share and the index, and determines whether the number of intersections in the privacy sets of the two parties reaches a threshold value according to the hash value of the reconstructed polynomial and the secret value. If the threshold value is reached, the intersection of the privacy sets is obtained according to the reconstructed secret polynomial.

2. The two-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing according to claim 1, characterized in that: The step 101 specifically includes: Step 1011: The sender A and the receiver B each hold a privacy set X = {x1, x2, …, x n }∈{0,1} * and Y={y1,y2,…,y n }∈{0,1} * ,|X|=|Y|=n; Step 1012: The sender A and the receiver B generate random seeds seed1∈{0,1} respectively. λ and seed2∈{0,1} λ And send it to the other party; Step 1013: Both parties will As the seed of the pseudo-random number generator, it generates nt redundant elements and adds them to its own privacy set, generating a pseudo-privacy set X′={x1,...,x n ,x n+1 ,…,x 2n-t } and Y′={y1,...,y n ,y n+1 ,…,y 2n-t }, where t represents the threshold value.

3. The two-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing according to claim 1, characterized in that: The step 102 specifically includes: Step 1021: The sender A uses Shamir secret sharing to randomly generate a secret value s; Step 1022: The sender A selects a polynomial f(x) that satisfies f(0)=s and has a highest degree of t-1; where t represents a threshold value; Step 1023: Randomly select 2n-t fixed points as index ind for the polynomial f(x) i , calculate the corresponding secret sub-share s i =f(ind i ), and obtain 2n-t secret sub-shares (s1, s2, …, s 2n-t )∈{0,1} λ , where ind i Represents the index corresponding to the i-th secret sub-share; Step 1024: Perform a hash operation on the secret value s to obtain a hash value H(s) of the secret value s and send it to the recipient B.

4. The two-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing according to claim 1, characterized in that: The step 103 specifically includes: Step 1031: The sender A sends the element x in its pseudo-private set X′ i Perform a hash operation to obtain H(x i ); Step 1032: The sender A sends H(x i ) as the key, and the secret sub-share and the corresponding index s i ||ind i As the value, OKVS encoding is performed to obtain the data structure Q=Encode({(H(x i ),s i ||ind i )|i∈[2n-t]}), sending the data structure Q to the receiver B; The step 104 specifically includes: Step 1041: After receiving the data structure Q, the receiver B adds the element y in its own pseudo-private set Y′ i Perform hash operation to get H(y i ); Step 1042: Receiver B sends H(y i ) as the key, and perform OKVS decoding to obtain the reconstructed secret sub-share and index s′ i ||ind′ i =Decode(H(y i ),Q).

5. The two-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing according to claim 1, characterized in that: The step 105 specifically includes: Step 1051: Receiver B sends the reconstructed secret sub-share {s′ i |i∈[2n-t]} and index {ind′ i |i∈[2n-t]} is used as the input of the Reed-Solomon decoding algorithm to obtain the reconstructed polynomial f′(x); Step 1052: Calculate whether H(f′(0)) is equal to H(s). If not, the step is terminated and ⊥ is output; if equal, the number of intersections of the two privacy sets reaches the threshold value, and step 1053 is performed. Step 1053: For all reconstructed secret sub-shares s′ i ,i∈[n], the receiver B checks s′ i Is it equal to f′(ind′ i ), if they are equal, then the corresponding y i The privacy set intersection I is added, and finally the receiver B outputs the privacy set I.

6. A multi-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing, characterized in that: include: Step 201: N participants {P1,…,P i …,P N Generate random seeds separately and exchange them with each other. N participants generate redundant elements based on the received random seeds and their own random seeds, and add them to their own privacy sets to generate pseudo-privacy sets; Step 202: P1 is selected as the receiver. The receiver P1 generates multiple secret sub-shares based on the threshold secret sharing and the selected secret value, combined with the secret polynomial and the index; Step 203: Participant P i ,i∈[N] randomly selects the key of the pseudo-random function And send it to the sender P j , where j>i, the participant P i ,i∈[N] calculate their respective pseudo-random values ​​sh i (h): Where h∈X′ i Represents the participant P i Any element in the pseudo-private set of ; Step 204: Participant P i ,i∈[2,N] is based on its own pseudo-random value sh i (h) Use OKVS encoding to construct its own data structure Q i And the data structure Q i Send to the receiver P1; the receiver P1 calculates its own data structure Q1 based on the secret sub-share and its own pseudo-random value; Step 205: The receiver P1 receives the data from other N-1 participants P i , i∈[2,N] data structure Q i , based on the data structure Q i Perform OKVS decoding to obtain the reconstructed secret sub-share and index; Step 206: The receiver P1 performs polynomial reconstruction on the reconstructed secret sub-share and index, calculates the reconstructed secret value according to the reconstructed polynomial f′(x), and determines whether the number of intersections in the multi-party privacy set reaches a threshold value by combining the reconstructed secret value with the secret value; if the threshold value is reached, the intersection of the privacy sets is obtained according to the reconstructed secret polynomial.

7. The multi-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing according to claim 6, characterized in that: The step 201 specifically includes: Step 2011: N participants {P1,…,P i …,P N }, i∈[N] respectively hold the set |X i |=n,i∈[N]; Step 2012: N participants generate random seeds respectively i ∈{0,1} λ and exchanged with each other; Step 2013: Participant P i ,i∈[N]calculation Generate nt redundant elements as the seed of the pseudo-random number generator and add them to their respective privacy sets to generate a pseudo-privacy set Where t represents the threshold value.

8. The multi-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing according to claim 6, characterized in that: The step 202 specifically includes: Step 221: P1 is selected as the receiver, and the receiver P1 uses Shamir secret sharing to randomly generate a secret value s; Step 2022: The receiver P1 selects a polynomial f(x) that satisfies f(0)=s and has a highest degree of t-1; where t represents a threshold value; Step 2023: Randomly select 2n-t fixed points as index ind for the polynomial f(x) i , calculate the corresponding secret sub-share s i =f(ind i ), and get 2N-t secret shares (s1, s2, …, s 2n-t )∈{0,1} λ , where ind i Represents the index corresponding to the i-th secret sub-share.

9. The multi-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing according to claim 6, characterized in that: The step 204 specifically includes: Step 2041: Party P i ,i∈[2,N] takes its own pseudo-privacy set X′ i Elements in Perform a hash operation to obtain Step 2042: Party P i ,i∈[2,N] will be the As a key, the pseudo-random value sh i (h) OKVS encoding is performed as a value to obtain a data structure And Q i Send to the receiver P1; Step 2043: The receiver P1 adds the elements in its pseudo-private set X′1 Perform a hash operation to obtain Step 2044: The receiver P1 sends the As the key, the pseudo-random value Perform OKVS encoding as a value to obtain the data structure The step 205 specifically includes: Step 2051: The receiver P1 receives the data structure Q of the other N-1 participants P,i∈[2,N] i ; Step 2052: As the key, perform OKVS decoding to obtain the reconstructed secret sub-share index 10. The multi-party privacy set intersection method based on oblivious key-value storage and threshold secret sharing according to claim 6, characterized in that: The step 206 specifically includes: Step 2061: The receiver P1 sends the reconstructed secret sub-share {s′ i |i∈[2n-t]} and index {ind′ i |i∈[2n-t]} is used as the input of the Reed-Solomon decoding algorithm to obtain the reconstructed polynomial f′(x); Step 2062: Calculate s′=f′(0), and then determine whether s′ is equal to the secret value s. If not, the step is terminated and ⊥ is output; if equal, the number of intersections of multi-party privacy sets reaches the threshold value, and step 2063 is performed; Step 2063: For all reconstructed secret sub-shares s′ j ,j∈[n], the receiver P1 checks s′ j Is it equal to f′(ind′ j ), if they are equal, then the corresponding The privacy set intersection I is added, and finally the receiver P1 outputs the privacy set intersection I.

Citation Information

Cited By

  • Hidden transmission method based on oblivious key value pair storage, storage medium and system

    CN120415724A