Unbalanced privacy set union method and union set system based on fully homomorphic encryption
By adopting a fully homomorphic encryption method in the unbalanced privacy collection consolidation scenario, the problems of privacy leakage and slow communication speed are solved, and a more efficient and secure privacy collection consolidation process is achieved.
Patent Information
- Application Number
- CN202510299275.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-13
AI Technical Summary
The existing privacy collection convergence method has problems such as privacy leakage or slow communication speed in unbalanced scenarios.
The unbalanced privacy set consolidation method based on all homomorphic encryption is adopted. The sending end encodes, rearranges, and encrypts the merged sets through the sending end. The receiving end compares the data difference based on the assignment, rotation, and multiplication operations to obtain the ciphertext of the comparison result, and obtains the blinded comparison result through decryption to determine the union of the merged set.
It avoids privacy leakage problems caused by the cuckoo hash structure, enhances communication robustness, and reduces circuit depth and computational complexity by simplifying computing operations, and improves communication speed.
Smart Images

Figure CN120223282A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of encrypted data processing, and particularly relates to a method and a system for non-balanced private set union based on fully homomorphic encryption. Background Art
[0002] In the era of the prosperity of big data and artificial intelligence, data has become a basic resource. Through data sharing, all parties can obtain more resources, mine a large amount of effective information from them, thus bringing a good user experience and creating greater value. However, in the process of massive data mining, the problem of leakage of users' sensitive information is becoming increasingly serious, and the privacy and security of citizens are difficult to be guaranteed. The private set union technology is needed in many scenarios, which has attracted wide attention. For example, in financial risk control, different banks or payment platforms need to share blacklist information without disclosing their respective user data to improve the fraud detection ability. However, in scenarios such as the server-client model and the interaction between small organizations and large platforms, the sizes of the data sets of the participating parties often vary greatly, and the traditional private set union schemes are mainly designed for data sets with similar scales, resulting in inefficient computing and communication costs in non-balanced scenarios. The traditional private set union may bring unnecessary computing overhead to the small set party and make its communication burden too heavy.
[0003] Therefore, a variety of non-balanced private set union protocols have been proposed, and the private set union method based on cuckoo hash table has become typical. However, there is a possibility of information leakage in this method. This is because the sender embeds its smaller data set into the cuckoo hash table, while the receiver stores its larger data set in a simple hash table using the same hash function. The lengths of the cuckoo hash table and the simple hash table are equal and are determined by the scale of the small set. Research shows that it is not suitable for the private set union protocol. And as the degree of non-balance of the data scale increases, the risk of information leakage caused by this method will be further aggravated.
[0004] As for other methods that do not use cuckoo hash tables, they usually use high-order polynomials for comparison. Due to the high order of the polynomials, the circuit depth of the implemented circuit is large, resulting in the problem of slow communication speed caused by overly complex calculations. Summary of the Invention
[0005] The embodiments of the present invention provide a method and a system for non-balanced private set union based on fully homomorphic encryption, which can solve the problems of privacy leakage or slow communication speed existing in the current private set union methods.
[0006] In a first aspect, an unbalanced private set union method based on fully homomorphic encryption provided by an embodiment of the present invention is applied to a union set system, which includes a sending end and a receiving end. The method includes:
[0007] The sending end sends a first ciphertext set to be merged to the receiving end, where the first ciphertext set to be merged is obtained by encoding, rearranging, and encrypting a first set to be merged in sequence;
[0008] Based on assignment, rotation, and multiplication operations, the receiving end compares the data difference between the first set to be merged and a second set to be merged according to the first ciphertext set to be merged, and obtains a comparison result ciphertext; and sends the comparison result ciphertext to the sending end;
[0009] The sending end decrypts the comparison result ciphertext to obtain a blinded comparison result, and sends the blinded comparison result to the receiving end;
[0010] The receiving end determines the union of the first set to be merged and the second set to be merged according to the blinded comparison result.
[0011] In a second aspect, an embodiment of the present invention provides a union set system, including a sending end and a receiving end;
[0012] The sending end is configured to send a first ciphertext set to be merged to the receiving end, where the first ciphertext set to be merged is obtained by encoding, rearranging, and encrypting a first set to be merged;
[0013] The receiving end is configured to compare the data difference between the first set to be merged and a second set to be merged according to the first ciphertext set to be merged based on assignment, rotation, and multiplication operations, and obtain a comparison result ciphertext; and send the comparison result ciphertext to the sending end;
[0014] The sending end is further configured to decrypt the comparison result ciphertext to obtain a blinded comparison result, and send the blinded comparison result to the receiving end;
[0015] The receiving end is further configured to determine the union of the first set to be merged and the second set to be merged according to the blinded comparison result.
[0016] The beneficial effects of the embodiments of the present invention compared with the prior art are as follows: Since the method provided by the present invention does not use a cuckoo hash structure to compare the data of the first set to be merged and the second set to be merged, the privacy leakage problem caused by the cuckoo hash structure can be avoided, and the communication robustness can be enhanced; moreover, since the system can obtain the comparison result ciphertext only through operations with relatively small computational amounts such as assignment, rotation, and multiplication, compared with the traditional method of using high-order polynomials for comparison, the computational amount of the present invention is smaller, the circuit depth is lower, and the communication speed is higher. Brief Description of the Drawings
[0017] Figure 1 It is a schematic structural diagram of a merging set system provided by an embodiment of the present invention;
[0018] Figure 2 It is a flowchart of the implementation of a method for non - balanced private set union based on fully homomorphic encryption provided by an embodiment of the present invention;
[0019] Figure 3 It is a flowchart of the implementation of a method for comparing the data difference between a first set to be merged and a second set to be merged provided by an embodiment of the present invention;
[0020] Figure 4 It is a schematic diagram of a ciphertext matrix after assignment provided by an embodiment of the present invention. Detailed Embodiments
[0021] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system structures, technologies, etc. are presented to thoroughly understand the embodiments of the present invention. However, those skilled in the art should clearly understand that the present invention can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well - known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present invention.
[0022] It should be understood that when used in the specification and claims of the present invention, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0023] It should also be understood that the term "and / or" as used in the specification and claims of the present invention refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0024] As used in the specification and claims of the present invention, the term "if" can be interpreted as "when", "once", "in response to determining", or "in response to detecting" according to the context. Similarly, the phrase "if determined" or "if [the described condition or event] is detected" can be interpreted as meaning "once determined", "in response to determining", "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]" according to the context.
[0025] In addition, in the description of the specification and claims of the present invention, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0026] References to "one embodiment" or "some embodiments" etc. described in the specification of the present invention mean that specific features, structures, or characteristics described in connection with that embodiment are included in one or more embodiments of the present invention. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "comprising", "including", "having" and their variants all mean "including but not limited to", unless otherwise specifically emphasized.
[0027] The present invention will be further described in detail below in conjunction with specific embodiments, but the embodiments of the present invention are not limited thereto.
[0028] Figure 1 The figure shows a schematic structural diagram of a merging set system provided by an embodiment of the present invention. By way of example and not limitation, system 100 may include a sending end S and a receiving end R.
[0029] Exemplarily, referring to Figure 1 , the sending end S may encode, rearrange, and encrypt its own first set X to be merged in sequence to obtain the first encrypted set Enc f (W X ), and then send Enc f (W X ) to the receiving end. The receiving end may obtain a comparison result ciphertext based on assignment, rotation, and multiplication operations to compare the data difference between Enc f (W X ) and its own second set Y to be merged. Since the comparison result ciphertext is encrypted data, the receiving end sends it to the sending end for decryption to obtain a blinded comparison result, and finally determines the union of X and Y according to the blinded comparison result.
[0030] Since the system provided by the present invention does not use a cuckoo hash structure to compare the data of the first set to be merged and the second set to be merged, it can avoid the privacy leakage problem caused by the cuckoo hash structure and enhance communication robustness; moreover, since the system can obtain the comparison result ciphertext only through operations with relatively small computational amounts such as assignment, rotation, and multiplication, compared with the traditional method of using high-order polynomials for comparison, the present invention has a smaller computational amount, a lower circuit depth, and a higher communication speed.
[0031] Figure 2The following is a flowchart showing the implementation of a method for non - balanced private set union based on fully homomorphic encryption provided by an embodiment of the present invention. By way of example and not limitation, this method can be applied to the above - mentioned system. This method may include steps S201 - S205, which will be described below.
[0032] S201, the sender sends the first encrypted set to be merged to the receiver.
[0033] Correspondingly, the receiver receives the first encrypted set to be merged.
[0034] In a possible implementation, before sending the first encrypted set to be merged, the sender can first perform encoding, rearrangement, and encryption operations on the first set to be merged in sequence to obtain the first encrypted set to be merged.
[0035] In an example, if the first set to be merged is short, the sender can directly use the permutation function π S to permute the first set to be merged X, obtaining X′ = π S (X); then perform constant - weight encoding on each element in X′ to generate the encoded first set to be merged W X . After that, extract the data of the t1 - th bit of each codeword in W X to obtain the t1 - th encoded vector; combine each encoded vector together to obtain t combined encoded vectors; finally, use the fully homomorphic encryption scheme to encrypt the combined encoded vectors S1,..., S t to obtain the first encrypted set to be merged Enc f (W X ) = {Enc f (S1),..., Enc f (S t )}, where Enc f (S i ) is the ciphertext of the i - th combined encoded vector S i .
[0036] Exemplarily, the total number of bits of each codeword in the first set to be merged W X can be w, then the total number of encoded vectors (the maximum value of t1) is also w, the number of elements in the first set to be merged can be n, the length of the combined encoded vector can be slot, and the total number of combined encoded vectors (the maximum value of t) can be
[0037] In another example, if the first set to be merged is long, after permuting X, the sender can perform virtual Bloom filter encoding on each element in X′ and split it into two equal - length parts in sequence to obtain where ∥ represents concatenation. Then for each and Implement constant weight coding to obtain equal-length and length-w and Similarly, the sender extracts W X each element in The t1-th bit of forms a coded sub-vector The t1-th bit of is extracted to form a vector For each one and Combined together to obtain a combined coding vector of slot length and Finally, use a fully homomorphic encryption scheme to encrypt and to obtain the first ciphertext set to be merged and
[0038] Exemplarily, denotes the ciphertext of, denotes the ciphertext of.
[0039] S202. The receiving end, based on assignment, rotation, and multiplication operations, compares the data difference between the first set to be merged and the second set to be merged according to the first ciphertext set to be merged, and obtains a comparison result ciphertext.
[0040] In a possible implementation manner, the receiving end can first perform assignment and rotation operations on the original ciphertext matrix according to the first ciphertext set to be merged to obtain an effective ciphertext matrix; then compare each bit of data in the second set to be merged with the effective ciphertext matrix to obtain k updated comparison vectors; perform consecutive multiplication and rotation on the updated comparison vectors to obtain a comparison result ciphertext.
[0041] Specifically, the number of ciphertext matrices can be determined according to the size of the first set to be merged / second set to be merged.
[0042] Exemplarily, the size of the first set to be merged / second set to be merged is the same.
[0043] In an example, to prevent potential attackers from inferring the size of the merged set based on the comparison result ciphertext, the updated comparison vectors can first be multiplied and rotated consecutively to obtain a comparison result ciphertext Enc f (b), and then by adding a random vector r to Enc f (b) to complete the randomization of Enc f (b) to obtain a comparison result ciphertext Enc f (b r ).
[0044] S203. The receiving end sends the ciphertext of the comparison result to the sending end.
[0045] Correspondingly, the sending end receives the ciphertext of the comparison result.
[0046] S204. The sending end decrypts the ciphertext of the comparison result to obtain the blinded comparison result.
[0047] In one example, the sending end S can decrypt the ciphertext of the comparison result to obtain the blinded comparison result b r .
[0048] S205. The sending end sends the blinded comparison result to the receiving end.
[0049] S206. The receiving end determines the union of the first set to be merged and the second set to be merged according to the blinded comparison result.
[0050] In one possible implementation, the receiving end can obtain the comparison result of the original number of bits according to the blinded comparison result b r and the random vector r.
[0051] Exemplarily, each element in the comparison result of the original number of bits can be composed of 0 or 1. If it is 0, it means that the data of this bit in the first set to be merged and the second set to be merged is the same. If it is 1, it means that the data of this bit in the first set to be merged and the second set to be merged is different.
[0052] In one example, if the first set to be merged is smaller, the original number of bits of the comparison result b can be directly obtained according to the formula b = b r - r.
[0053] In another example, if the first set to be merged is larger, the i2-th bit data b r of b r [i2] is subtracted from the i2-th bit data r[i2] of the random number r; if b r [i2] - r[i2] is 0 or 1, the i2-th bit data b[i2] of b is set to 0, and when it is 2, b[i2] is set to 1.
[0054] In one possible implementation, the sending end and the receiving end can call the oblivious transfer extension protocol to transfer the non-intersecting information in the first set to be merged.
[0055] Exemplarily, the sending end S, as the sender of the oblivious transfer extension protocol, its input message is The receiving end R, as the receiver of the oblivious transfer extension protocol, its input is b. After the protocol is executed, R obtains the output
[0056] Specifically, respectively represent the first message and the second message of the i2-th oblivious transfer instance of the oblivious transfer protocol, X′[i2] is the i2-th bit data of X′, when b[i2]=0, when b[i2]=1, ⊥ is a special symbol pre-agreed by S and R for filling data and has no practical meaning.
[0057] Exemplarily, the union Z of the first set to be merged and the second set to be merged satisfies: Z = {m i,b[i] |m i,b[i] ≠⊥} ∪ Y.
[0058] Since the method provided by the present invention does not use the cuckoo hash structure to compare the data of the first set to be merged and the second set to be merged, the privacy leakage problem caused by the cuckoo hash structure can be avoided, and the communication robustness can be enhanced; moreover, since the system can obtain the comparison result ciphertext only through operations with relatively small computational amounts such as assignment, rotation, and multiplication, compared with the traditional method of using high-order polynomials for comparison, the computational amount of the present invention is smaller, the circuit depth is lower, and the communication speed is higher..
[0059] Furthermore, by randomizing the comparison result of the original number of bits, it can be ensured that the size of the data intersection will not be inadvertently exposed, thereby effectively preventing the participating parties from inferring the data distribution of the other party and enhancing the privacy and security of the protocol.
[0060] Figure 3 The figure shows a flowchart of an implementation of a method for comparing the data difference between the first set to be merged and the second set to be merged provided by an embodiment of the present invention. As an example but not a limitation, this method can be a specific possible implementation manner of the above step S202. This method may include steps S301 - S303, and each step will be described below.
[0061] S301, extract the effective information of each encoding vector in the first set of ciphertexts to be merged, and perform assignment and rotation operations on the original ciphertext matrix in sequence to obtain an effective ciphertext matrix.
[0062] Exemplarily, each element in the original ciphertext matrix can be the encrypted value of a preset value. Refer to the pseudocode of this method shown in Table 1 below, each element in the original ciphertext matrix can be Enc f (0), that is, the ciphertext of 0.
[0063] Exemplarily, the dimension of the original ciphertext matrix can be w rows columns. Refer to Table 1 below, when the set to be merged is small, only one original ciphertext matrix needs to be prepared; refer to Table 2 below, when the set to be merged is large, two original ciphertext matrices can be prepared.
[0064] In one example, the receiving end can perform Encf (S i ) After performing homomorphic multiplication, put the multiplication result into the j-th column of the j+(i - 1)·t-th row of the original ciphertext matrix. After circularly processing each encoded vector in each S i , the assigned ciphertext matrix is obtained. See Figure 4 , where the colored filling represents the multiplication results based on different S i . The values represented by the same color are different, only the assignment positions are different.
[0065] Exemplarily, the assigned ciphertext matrix can satisfy the following formula:
[0066] Cipher[j+(i - 1)·t][j]:=Enc f (S i )*ExPlan[j] (1.1)
[0067] where Cipher[j+(i - 1)·t][j] represents the data in the j+(i - 1)·t-th row and j-th column of the assigned ciphertext matrix; Enc f (S i ) represents the ciphertext of the i-th combined encoded vector S i ; ExPlain[j] is a vector of length slot, where the data from the ((j - 1)·n + 1)-th bit to the j·n-th bit is 1 and the rest of the data is 0;
[0068] Specifically, ExPlain[j] can be used to extract the valid information in the encoded vector.
[0069] Particularly, when the set to be merged is large, based on the above formula (1.1), the first original ciphertext matrix can be assigned through , and the second original ciphertext matrix can be assigned through .
[0070] In one example, after obtaining the replicated ciphertext matrix, the assigned position can be rotated left to obtain the valid ciphertext matrix.
[0071] Exemplarily, the valid ciphertext matrix can satisfy the following formula:
[0072]
[0073] where represents the data in the j+(i - 1)·t-th row column of the valid ciphertext matrix Cipher1, and Rotate(Cipher[j+(i - 1)·t][j],o·n) represents rotating Cipher[j+(i - 1)·t][j] by o·n degrees.
[0074] Similarly, when the set to be merged is large, two valid ciphertext matrices can be obtained based on the above formula (1.2).
[0075] S302. According to each piece of data in the second set to be merged, update the k comparison vectors with the valid ciphertext matrix to obtain k updated comparison vectors.
[0076] In a possible implementation, the second set to be merged Y can be subjected to constant weight encoding to obtain the encoded set W Y , and the length of each codeword is also w; see Table 1 below. Then, W can be retrieved cyclically Y for each piece of data in it. If the retrieved is found, then update the preset comparison vector. After all retrievals are completed, k updated comparison vectors can be obtained.
[0077] Exemplarily, the updated comparison vectors can satisfy the following formula:
[0078] Temp[ind]:=Temp0[ind]+Cipher1[t1][j1+1] (1.3)
[0079] where represents the data in the t1-th column of the j1-th row in the encoded second set to be merged, Temp[ind] is the ind-th updated comparison vector, Temp0[ind] is the ind-th comparison vector, Cipher1[t1][j1+1] represents the data in the t1-th row and the (j1 + 1)-th column of the valid ciphertext matrix, ind = 1,..., k, t1 = 1,..., w, t1 = 1,..., w, m is the number of ciphertext slots.
[0080] Exemplarily, each element in the comparison vector can be the encrypted value of a preset value, such as the ciphertext of 0 as well.
[0081] Similarly, when the set to be merged is large, the second set to be merged Y can be divided into two equal-length parts for constant weight encoding, retrieved and based on the above formula (1.3), 2k updated comparison vectors can be obtained. Here v = 1, 2; represents the encoded set of the first part, represents the encoded set of the second part.
[0082] S303. Multiply and rotate the k updated comparison vectors to obtain the comparison result ciphertext.
[0083] Exemplarily, the ciphertext of the comparison result of the original number of bits can satisfy the following formula:
[0084]
[0085] is the ciphertext of the comparison result of the original number of bits;
[0086] where:
[0087] Enc f (b)1 = Enc f (b)0 + Temp j (1.5)
[0088] Enc f (b)0 is a vector of encrypted values with the same dimension as Enc f (b) and each element being the preset value,
[0089] Similarly, when the set to be merged is large, the ciphertexts of the comparison results of two segments of the original number of bits can be obtained based on the above formulas (1.4) and (1.5), and these two ciphertexts can be concatenated together for subsequent randomization processes.
[0090] According to the comparison method provided by the present invention, the ciphertext of the comparison result is obtained through k multiplication operations, which can optimize the calculation process while ensuring privacy and security, and reduce the computational complexity of the protocol. Compared with the existing solutions that avoid revealing both the size of the intersection and the information of cuckoo hashing, the present invention can complete the calculation in a shorter time, reduce the computational and communication overheads, and make it more applicable to large-scale data scenarios.
[0091] Table 1
[0092]
[0093]
[0094]
[0095] Table 2
[0096]
[0097]
[0098]
[0099] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
Claims
1. A method for unbalanced privacy set union based on fully homomorphic encryption, characterized in that: The method is applied to a merge set system, the system includes a sending end and a receiving end, and the method includes: The sending end sends a first ciphertext set to be merged to the receiving end, wherein the first ciphertext set to be merged is obtained by encoding, rearranging, and encrypting the first ciphertext set to be merged in sequence; The receiving end compares the data difference between the first set to be merged and the second set to be merged according to the first set of ciphertexts to be merged based on assignment, rotation and multiplication operations, obtains a comparison result ciphertext, and sends the comparison result ciphertext to the sending end; The sending end decrypts the comparison result ciphertext to obtain a blinded comparison result, and sends the blinded comparison result to the receiving end; The receiving end determines a union of the first set to be merged and the second set to be merged according to the blinded comparison result.
2. The method according to claim 1, characterized in that Before the sending end sends the first ciphertext set to be merged to the receiving end, the method further includes: The transmitting end performs constant weight encoding on the first set to be combined, and extracts the data with the same number of bits of each codeword in the encoded first set to be combined to obtain w encoding vectors, where w is the total number of bits of each codeword in the encoded first set to be combined; Each The coding vectors are combined together to obtain t combined coding vectors, where slot is the length of the combined encoding vector, and n is the number of elements in the first set to be merged; The combined encoding vector is encrypted to obtain the first ciphertext set to be merged.
3. The method according to claim 2, characterized in that The receiving end compares the data difference between the first set to be merged and the second set to be merged according to the first set of ciphertexts to be merged based on assignment, rotation, and multiplication operations to obtain a comparison result ciphertext, including Extracting effective information of each of the encoding vectors in the first ciphertext set to be merged, and sequentially performing assignment and rotation operations on the original ciphertext matrix to obtain a valid ciphertext matrix, wherein each element in the original ciphertext matrix is an encrypted value of a preset value; According to each bit of data in the second set to be merged, update k comparison vectors using the valid ciphertext matrix to obtain k updated comparison vectors; The k updated comparison vectors are multiplied and rotated to obtain the comparison result ciphertext.
4. The method according to claim 3, characterized in that The ciphertext matrix after assignment satisfies the following formula: Cipher[j+(i-1)·t][j]:=Enc f (S i )*ExPlain[j] Where Cipher[j+(i-1)·t][j] represents the data in the j+(i-1)·tth row and jth column in the ciphertext matrix after the assignment; Enc f (S i ) represents the i-th combined encoding vector S i ciphertext; ExPlain[j] is a vector of length slot, which is the encoding of a vector of length slot with the data from the (j-1)·n+1th to the j·nth bits being 1 and the rest being 0; 5. The method according to claim 4, characterized in that The effective ciphertext matrix satisfies the following formula: in, Represents the j+(i-1)·tth row in the valid ciphertext matrix Cipher1 Column data, Rotate(Cipher[j+(i-1)·t][j],o·n) means rotating Cipher[j+(i-1)·t][j] by o·n degrees.
6. The method according to claim 3, characterized in that like Then the updated comparison vector satisfies the following formula: Temp[ind]:=Temp0[ind]+Cipher1[t1][j1+1] in, Indicates the first The data in row t1 and column t2, Temp[ind] is the indth updated comparison vector, Temp0[ind] is the indth comparison vector, Cipher1[t1][j1+1] represents the data in row t1 and column j1+1 in the effective ciphertext matrix, ind = 1, ..., k, t1=1,...,w, m is the number of ciphertext slots.
7. The method according to claim 6, characterized in that The step of multiplying and rotating the k updated comparison vectors to obtain the comparison result ciphertext includes: Multiply and rotate the k updated comparison vectors to obtain a comparison result ciphertext of the original number of bits; The comparison result ciphertext of the original bit number is randomized to obtain the comparison result ciphertext.
8. The method according to claim 7, characterized in that The ciphertext of the comparison result of the original number of bits satisfies the following formula: is the ciphertext of the comparison result of the original number of bits; in: Enc f (b)1=Enc f (b)0+Temp j Enc f (b) 0 is a f (b) a vector of the same dimension and each element of which is an encrypted value of the preset value, 9. The method according to claim 7, characterized in that: The comparison result ciphertext satisfies the following formula: Enc f (b r )=Enc f (b)+r Among them, Enc f (b r ) is the comparison result ciphertext, and r is a random vector.
10. A merge set system, characterized in that: Includes the sending end and the receiving end; The sending end is used for sending a first ciphertext set to be merged to a receiving end, wherein the first ciphertext set to be merged is obtained by encoding, rearranging, and encrypting the first ciphertext set to be merged; The receiving end is used to compare the data difference between the first set to be merged and the second set to be merged according to the first set of ciphertexts to be merged based on assignment, rotation, and multiplication operations, obtain a comparison result ciphertext; and send the comparison result ciphertext to the sending end; The sending end is also used to decrypt the comparison result ciphertext to obtain a blinded comparison result, and send the blinded comparison result to the receiving end; The receiving end is further configured to determine a union of the first set to be merged and the second set to be merged according to the blinded comparison result.
Citation Information
Patent Citations
Multi-party security computing all-in-one machine
CN111931250A
Privacy set operation method and system based on fully homomorphic encryption
CN115529118A
Method and device for imbalance privacy set intersection
CN115733602A
Efficient unbalanced PSI based on Bloom filter and Hash
CN116361649A
Multi-party privacy set operation method and system based on homomorphic encryption
CN116401686A