Efficient privacy set intersection method and device based on bucket coding

Through the method based on bucket encoding, the private set of the receiver is encoded into a sparse matrix, and the communication redundancy is reduced by using Gaussian cancellation algorithm and exclusive OR operation, which solves the problem of high communication overhead for the privacy set interception protocol, and realizes efficient private set interception with low traffic.

CN120263393APending Publication Date: 2025-07-04SHANGHAI JIAOTONG UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510412041.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing privacy set request protocol has the problem of excessive communication overhead, especially in large-scale data set scenarios, which seriously restricts the practical application efficiency of the protocol.

Method used

Using a bucket-based encoding method, the private set of the receiver is encoded into a sparse matrix, a linear system of sparse matrix is generated through a hash function, and a Gaussian cancellation algorithm and exclusive OR operation are used to determine the inadvertent key-value pair storage to reduce the communication redundancy rate.

Benefits of technology

It effectively reduces the communication resource demand for privacy collection, and the traffic volume is lower than that of the existing technology. It is suitable for large-scale privacy computing scenarios, especially in low-bandwidth environments, with better performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263393A_ABST
    Figure CN120263393A_ABST
Patent Text Reader

Abstract

The invention provides an efficient privacy set intersection method and device based on bucket coding, and the method comprises the steps: obtaining an input set and a target value set, the input set comprises a private set of a sender and a private set of a receiver, and the target value set is generated based on the private set of the receiver; encoding the private set of the receiver into a sparse matrix composed of a plurality of buckets through a hash function; determining a linear system of the sparse matrix; performing ascending sorting and re-labeling on the linear system according to the initial bit position set to obtain a target linear system; according to a bucket-based Gaussian elimination algorithm, based on a target linear system, through exclusive-or operation, determining oblivious key value pairs for storage; an intersection of the private set of the sender and the private set of the receiver is determined based on the oblivious key-value pair storage according to an oblivious linear evaluation protocol. According to the invention, communication resources required by privacy set intersection in an actual production environment can be further reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to an efficient private set intersection method and apparatus based on bucket encoding. Background Art

[0002] As a key technology in the field of secure multi-party computing, private set intersection can output only the intersection result while protecting the privacy of the participating parties' sets, and is widely used in scenarios such as data security sharing and privacy-preserving matching. Currently, mainstream private set intersection protocols are generally constructed based on oblivious pseudorandom function protocols. Among them, the construction method based on oblivious key-value pair storage is regarded as the best implementation solution due to its high efficiency.

[0003] However, the existing oblivious key-value pair storage technology has a significant redundancy rate problem. The encoded data size usually needs to reach more than 1.3 times the number of original elements. For example, when processing 100 elements, the communication data volume will increase to about 130 elements. This linear expansion characteristic directly leads to excessive communication overhead in the transmission process of the private set intersection protocol, especially severely restricting the actual application efficiency of the protocol in large-scale dataset scenarios.

[0004] Therefore, it can be seen that the private set intersection method in the related technology has the technical problem of excessive communication overhead. Summary of the Invention

[0005] The present invention provides an efficient private set intersection method and apparatus based on bucket encoding to solve the defect of excessive communication overhead in the existing private set intersection method, and to further reduce the communication resources required for private set intersection in the actual production environment.

[0006] The present invention provides an efficient private set intersection method based on bucket encoding, including the following steps. Obtain an input set and a target numerical set, where the input set includes: the private set of the sender and the private set of the receiver, and the target numerical set is generated based on the private set of the receiver; encode the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function, where each bucket contains binary data of a fixed length; determine a linear system of the sparse matrix, where the linear system includes: the sparse matrix, the set of starting bit positions of the sparse matrix, the set of bucket indices of the sparse matrix, and the target numerical set; sort and re-number the linear system in ascending order according to the set of starting bit positions to obtain a target linear system; based on the bucket-based Gaussian elimination algorithm, determine an oblivious key-value pair storage through exclusive-or operations based on the target linear system, where the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the target numerical set, and the redundancy rate of the encoding length of the oblivious key-value pair storage does not exceed a preset value; based on the oblivious linear evaluation protocol and based on the oblivious key-value pair storage, determine the intersection of the private set of the sender and the private set of the receiver.

[0007] According to an efficient private set intersection method based on bucket encoding provided by the present invention, the encoding of the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function includes: obtaining the key set, random numbers, and bucket width of the private set of the receiver; through a first hash function, based on the key set and the random numbers, determine the starting bit position and bucket index of each row, where the bucket index is the ceiling of the ratio of the starting bit position to the bucket width; through a second hash function, generate the buckets of each row based on the starting bit position, the bucket index, the key set, and the random numbers to obtain a sparse matrix, where the number of buckets of the sparse matrix is the ratio of the minimum non-zero length of the row to the bucket width.

[0008] According to an efficient private set intersection method based on bucket encoding provided by the present invention, the determination of the oblivious key-value pair storage through exclusive-or operations based on the target linear system according to the bucket-based Gaussian elimination algorithm includes: dividing the target linear system into a target number of buckets of a target width; performing Gaussian elimination operations on each bucket to obtain an elimination sparse matrix in which the first non-zero column of each row only includes target elements; when the elimination sparse matrix is a full row rank matrix, output the oblivious key-value pair storage.

[0009] An efficient private set intersection method based on bucket encoding provided by the present invention, which determines the intersection of the private set of the sender and the private set of the receiver based on the oblivious key-value pair storage according to the oblivious linear evaluation protocol, includes: jointly calling the vector oblivious linear evaluation protocol by the sender and the receiver to respectively obtain the partial result of the sender and the partial result of the receiver; determining the intermediate result of the receiver by the receiver based on the partial result of the receiver and the oblivious key-value pair storage; encoding by the receiver based on the partial result of the receiver and the private set of the receiver to obtain the encoded set of the receiver; and sending the intermediate result of the receiver to the sender; determining the encoded set of the sender by the sender based on the partial result of the receiver, the intermediate result of the receiver and the private set of the sender; and sending the encoded set of the sender to the receiver; determining the intersection of the private set of the sender and the private set of the receiver by the receiver based on the encoded set of the receiver and the encoded set of the sender.

[0010] An efficient private set intersection method based on bucket encoding provided by the present invention, which outputs the oblivious key-value pair storage when the elimination sparse matrix is a full row rank matrix, includes: obtaining a target number of key-value pairs and the coding redundancy; when the elimination sparse matrix is a full row rank matrix, encoding based on the target number of key-value pairs and the coding redundancy to obtain the oblivious key-value pair storage.

[0011] An efficient private set intersection method based on bucket encoding provided by the present invention, the method further includes: obtaining the oblivious key-value pair storage, the target key, the random number and the bucket width; determining the starting bit position of the target key based on the target key, the random number and the bucket width through the first hash function; determining the bucket vector of the target key based on the starting bit position of the target key, the target key and the random number through the second hash function; determining the subvector corresponding to the target key in the oblivious key-value pair storage; and performing an inner product operation based on the bucket vector and the subvector to obtain the target value corresponding to the target key.

[0012] The present invention also provides an efficient private set intersection device based on bucket encoding, including the following modules: an acquisition module, configured to acquire an input set and a target numerical set, wherein the input set includes: the private set of the sender and the private set of the receiver, and the target numerical set is generated based on the private set of the receiver; an encoding module, configured to encode the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function, wherein each bucket contains binary data of a fixed length; a determination module, configured to determine a linear system of the sparse matrix, wherein the linear system includes: the sparse matrix, a set of starting bit positions of the sparse matrix, and a set of bucket indexes of the sparse matrix; a rearrangement module, configured to perform ascending sorting and relabeling on the linear system according to the set of starting bit positions to obtain a target linear system; an elimination module, configured to determine an oblivious key-value pair storage based on the bucket-based Gaussian elimination algorithm through exclusive OR operations based on the target linear system, wherein the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the target numerical set, and the redundancy rate of the encoding length of the oblivious key-value pair storage does not exceed a preset value; an intersection module, configured to determine the intersection of the private set of the sender and the private set of the receiver based on the oblivious key-value pair storage according to the oblivious linear evaluation protocol.

[0013] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, it implements the efficient private set intersection method based on bucket encoding as described in any one of the above.

[0014] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the efficient private set intersection method based on bucket encoding as described in any one of the above.

[0015] The present invention also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the efficient private set intersection method based on bucket encoding as described in any one of the above.

[0016] The efficient private set intersection method and device based on bucket encoding provided by the present invention first encode the set of the receiver into a sparse matrix through a hash function, compress the data by using the hash collision controllability and the fixed-length bucket structure, and reduce the storage overhead; then establish a linear system of the matrix, map the data distribution into an analyzable mathematical relationship, and clarify the correlation between the bucket index and the bit position; optimize the linear structure of the matrix by sorting and relabeling according to the starting bit position, reduce the dimension and complexity of subsequent operations; perform an exclusive OR operation on the ordered system based on the bucket-based Gaussian elimination algorithm to generate an oblivious key-value storage that satisfies the redundancy constraint, ensure the reversibility and efficient storage of the product relationship between the sparse matrix and the target numerical set; finally, combine the oblivious linear evaluation protocol, and securely derive the set intersection through matrix multiplication and key-value query in the encrypted state while protecting the privacy of both parties. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art one by one. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0018] Figure 1 It is a schematic flowchart of the efficient private set intersection method based on bucket encoding provided by the present invention.

[0019] Figure 2 It is a schematic diagram of the matrix initialization algorithm provided by the present invention.

[0020] Figure 3 It is a schematic diagram of the bucket-based Gaussian elimination algorithm provided by the present invention.

[0021] Figure 4 It is a schematic diagram of the OKVS encoding algorithm provided by the present invention.

[0022] Figure 5 It is a schematic diagram of the OKVS decoding algorithm provided by the present invention.

[0023] Figure 6 It is a schematic structural diagram of the efficient private set intersection device based on bucket encoding provided by the present invention.

[0024] Figure 7 It is a schematic physical structure diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0026] The following explains the term explanations in the embodiments of the present invention.

[0027] Secure Multi-Party Computation (MPC): A cryptographic technique that allows multiple parties to jointly compute the output of a function without revealing their respective private inputs. MPC is widely used in scenarios such as privacy-preserving data analysis, federated learning, and electronic voting.

[0028] Private Set Intersection (PSI): PSI is a cryptographic protocol that enables two parties to compute the intersection of two sets without revealing the non-intersection elements in their respective sets. PSI is widely used in scenarios such as privacy advertising, medical data cooperation, and threat intelligence sharing.

[0029] Oblivious Key-Value Store (OKVS): OKVS is an encoding mechanism that can compress a set of key-value pairs into a fixed-length array, allowing any party to correctly decode the corresponding value through a given key without knowing other key information and without being able to obtain any information other than that key. OKVS is an important tool for constructing efficient PSI protocols.

[0030] Oblivious Pseudorandom Function (OPRF): OPRF is a protocol that enables a client to obtain the calculation result of a certain pseudorandom function on an input without knowing the key, while the server participates in the calculation without knowing the client's input. This structure is often used in constructing applications such as PSI, anonymous authentication, and cryptographic indexing.

[0031] Vector Oblivious Linear Evaluation (VOLE): VOLE allows two parties to perform linear calculations on hidden vectors, satisfying the relationship , where the sender knows and , and the receiver knows and VOLE is one of the key components for implementing an efficient PSI protocol.

[0032] Private Set Intersection (PSI) is a widely used secure multi-party computation technology, whose function is to calculate the intersection of participating parties without revealing additional information. Existing PSI protocols are generally constructed based on Oblivious Pseudo-Random Function (OPRF) protocols. And the best construction method for OPRF protocols used in PSI is currently based on Oblivious Key-Value Store (OKVS). The present invention proposes a new OKVS based on bucket encoding, and thus obtains an efficient private set intersection based on bucket encoding.

[0033] The defect of the existing solution is the high communication cost brought by the redundancy rate (1.3) of OKVS. That is, if there are 100 elements, it needs to be encoded into about 130 elements for communication. Therefore, the communication cost of existing PSI protocols is too high.

[0034] The present invention proposes an efficient private set intersection method based on bucket encoding, whose communication volume is lower than that of existing private set intersection technologies.

[0035] Optionally, the efficient private set intersection method based on bucket encoding in the embodiments of the present application can be executed by a server, or can be executed by a terminal device, or can also be jointly executed by a server and a terminal device. Taking the execution of the efficient private set intersection method based on bucket encoding in this embodiment by a server as an example.

[0036] Figure 1 is a schematic flowchart of the efficient private set intersection method based on bucket encoding provided by the present invention. As Figure 1 shown, the method includes the following steps.

[0037] Step 101, obtain an input set and a target numerical set.

[0038] Among them, the input set includes: the private set of the sender and the private set of the receiver, and the target numerical set is generated based on the private set of the receiver.

[0039] In the embodiments of the present invention, the receiver holds a private set , where U is the universal set (i.e., the input set), and each element x i belongs to the domain U (such as a string or an integer).

[0040] The sender holds a private set , which is isomorphic to X .

[0041] The recipient generates a set of target values through the following steps Z : Select a pseudorandom function (PRF): Use a secure pseudorandom function H F : U → F where F is a finite field (such as GF(2λ)).

[0042] Calculate Z value: For each x ∈ X , calculate v = H F (x) to obtain a set of target values where represents a binary field.

[0043] Construction of the key-value pair set I : Associate X with Z to form a key-value pair set for subsequent encoding.

[0044] Step 102, encode the recipient's private set into a sparse matrix composed of multiple buckets through a hash function, where each bucket contains binary data of a fixed length.

[0045] In the embodiments of the present invention, the hash function includes a first hash function and a second hash function.

[0046] The first hash function is used to map each element of the recipient's private set to the starting bit position in the sparse matrix.

[0047] The second hash function is used to generate the non-zero bucket content of each row, that is, fill the buckets of the sparse matrix. Each row contains α buckets, and each bucket occupies β bits.

[0048] According to an efficient private set intersection method based on bucket encoding provided by the present invention, encoding the recipient's private set into a sparse matrix composed of multiple buckets through a hash function includes: Obtain the key set, random number, and bucket width of the recipient's private set; Through the first hash function, based on the key set and random number, determine the starting bit position and bucket index of each row, where the bucket index is the ceiling of the ratio of the starting bit position to the bucket width; Through the second hash function, generate the buckets of each row based on the starting bit position, bucket index, key set, and random number to obtain a sparse matrix, where the number of buckets in the sparse matrix is the ratio of the minimum non-zero length of the row to the bucket width.

[0049] Before executing the bucket-based Gaussian elimination algorithm designed by the present invention, the matrix must be initialized into the form of buckets. Therefore, a matrix initialization algorithm is designed to construct a sparse matrix H .

[0050] Refer to Figure 2 , Figure 2 which is a schematic diagram of the matrix initialization algorithm (i.e., Algorithm 1, MatrixInitialization) provided by the present invention.

[0051] In some embodiments, through the first hash function , the second hash function , the key set of the recipient's private set is converted into a sparse matrix , and the sparse matrix consists of rows and buckets with a width of .

[0052] Among them, represents the first hash function, represents the input set (universal set), represents the key, represents the encoding length of OKVS, represents the length of the random block (random number), represents the second hash function, represents the width of the bucket, represents the number of buckets.

[0053] The key set of the recipient's private set of this algorithm and the parameter , among which, represents the random number, represents the redundancy rate, represents the minimum length of the non-zero block, and its output is a sparse matrix composed of buckets H . The output also includes the actual starting bit position of each row, and the actual bucket index of the first bucket in each row. Each bucket in each row of the sparse matrix H occupies bits, where the number of buckets is defined as rounded up.

[0054] Through the embodiments of the present invention, the recipient's private set is efficiently encoded as a sparse bucket matrix, taking into account both low communication overhead and computational efficiency, and is applicable to large-scale privacy computing scenarios.

[0055] Step 103, determine the linear system of the sparse matrix, where the linear system includes: a sparse matrix, a set of starting bit positions of the sparse matrix, a set of bucket indexes of the sparse matrix, and a set of target numerical values.

[0056] In the embodiment of the present invention, the linear system of the sparse matrix includes: The sparse matrix , each row corresponding to an element X in the private set of the recipient .

[0057] The set of starting bit positions of the sparse matrix , where each represents the starting column position (in bits) of the element in the sparse matrix.

[0058] The set of bucket indexes , where each represents the row position index of the first bucket of the element in the sparse matrix.

[0059] Step 104, sort and re-number the linear system in ascending order according to the set of starting bit positions to obtain the target linear system.

[0060] In the embodiment of the present invention, by sorting the rows of the linear system in ascending order according to the starting bit positions , it is ensured that the subsequent Gaussian elimination operation can process the non-zero elements column by column in column order, thereby reducing the computational complexity and improving the algorithm efficiency. The sorted system is called the target linear system.

[0061] After sorting, the non-zero block positions of each row increase from left to right, avoiding repeated modification of the left-eliminated columns when processing the right columns. By processing the non-zero blocks in an orderly manner, the probability of the matrix having linearly dependent rows is reduced, ensuring that the Gaussian elimination algorithm can solve an effective solution.

[0062] Step 105, based on the bucket-based Gaussian elimination algorithm, determine the oblivious key-value pair storage through exclusive OR operation based on the target linear system.

[0063] Among them, the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the set of target numerical values, and the redundancy rate of the coding length of the oblivious key-value pair storage does not exceed a preset value.

[0064] In the embodiment of the present invention, after obtaining the sparse matrix through the matrix initialization algorithm, the vector P can be solved, , where represents the sparse matrix, represents the oblivious key-value pair storage, Represents a set of target values. When is a full-row matrix, it is a valid OKVS.

[0065] An efficient private set intersection method based on bucket encoding provided by the present invention determines oblivious key-value pair storage through exclusive OR operations based on a target linear system according to a bucket-based Gaussian elimination algorithm, including: Dividing the target linear system into a target number of buckets with a target width; Performing Gaussian elimination operations on each bucket to obtain an elimination sparse matrix in which the first non-zero column of each row only includes target elements; When the elimination sparse matrix is a full-row rank matrix, outputting oblivious key-value pair storage.

[0066] Refer to Figure 3 , Figure 3 is a schematic diagram of the bucket-based Gaussian elimination algorithm (i.e., Algorithm 2, Bucket-Based Efficient GE) provided by the present invention.

[0067] In an embodiment of the present invention, for the bucket-based Gaussian elimination algorithm, as Figure 3 shown, the entire calculation process only depends on efficient XOR operations.

[0068] The goal of the bucket-based Gaussian elimination algorithm is to solve the vector P satisfying , and the input is the sorted target linear matrix , such that , and the bucket-based Gaussian elimination algorithm includes: Bucket elimination: Divide the sparse matrix into columns by buckets (each bucket has bits) and perform row transformations independently.

[0069] Exclusive OR operation: Only use exclusive OR (XOR) operations for elimination to avoid finite field multiplication and division operations and improve efficiency.

[0070] Back substitution to solve: Back substitute from the last row upwards to solve the P value bucket by bucket.

[0071] The input of the bucket-based Gaussian elimination algorithm includes the output result of the matrix initialization algorithm and the numerical set , and its output is the vector , satisfying . First, sort the rows in the linear system according to the starting bit position , and then relabel them as , such that . Subsequently, Gaussian elimination operations are performed on each bucket with a width of of buckets. Intuitively, lines 3 to 22 of the algorithm ensure that during the elimination process, the first non-zero column of each row in the sparse matrix contains only one "1". Therefore, the computational overhead of the bucket-based Gaussian elimination algorithm is linearly related to the number of columns , where , where . If the sparse matrix is not a full row-rank matrix, that is, all rows are not linearly independent, the algorithm will return an empty set, indicating that the bucket-based Gaussian elimination algorithm fails to run.

[0072] In addition, the linear property of the bucket-based Gaussian elimination algorithm can be naturally extended to a large prime finite field, but it may cause performance degradation. Specifically, the reason for the performance degradation is that when OKVS is extended from the binary field to a large prime field, the original simple exclusive OR (XOR) operation needs to be replaced by addition and multiplication operations in the prime field, and at the same time, a modular inverse operation is introduced. Compared with the XOR operation, these finite field operations have significantly greater computational overhead, resulting in performance degradation. In particular, performing the modular inverse operation in a large prime field introduces non-negligible additional computational overhead. However, this extension is natural and only requires replacing the operations in the binary field with the corresponding operations in the prime field.

[0073] Through the embodiments of the present invention, the bucket-based Gaussian elimination algorithm reduces the linear solution complexity of the sparse matrix to linear through block XOR operations, and realizes OKVS encoding with a redundancy rate as low as 1.01.

[0074] According to an efficient private set intersection method based on bucket encoding provided by the present invention, when the elimination sparse matrix is a full row-rank matrix, the output oblivious key-value pair storage includes: Obtaining a target number of key-value pairs and the coding redundancy; When the elimination sparse matrix is a full row-rank matrix, encoding based on the target number of key-value pairs and the coding redundancy to obtain oblivious key-value pair storage.

[0075] Refer to Figure 4 , Figure 4 is a schematic diagram of the OKVS encoding algorithm (i.e., Algorithm 3, Encoding of OKVS) provided by the present invention.

[0076] In the embodiments of the present invention, the input conditions of the OKVS encoding algorithm include: a set of key-value pairs: , where is the key (the private element of the receiver), is the corresponding value (usually the output of a pseudo-random function H F ( ))). Coding redundancy: , used to control the redundancy rate of OKVS (such as corresponding to a redundancy rate of 1.01). Other parameters: random number (random seed) (statistical security parameter = 128 or 256). Non-zero block length = O(λ), bucket width (default value).

[0077] The goal of the OKVS coding algorithm is to generate OKVS vectors P , satisfying , and for any , decoding Decoder(P, )= .

[0078] The input of the OKVS coding algorithm is n key-value pairs (where all keys are different) as input, and outputs an OKVS vector P . First, the encoder needs to set the desired coding redundancy, that is, set the value of the parameter , and this value is determined by the encoder itself.

[0079] In addition, the encoder does not need to set the bucket width , because this parameter depends on the specific OKVS implementation. For example, if one byte is used to represent a bucket element, then there is , and . In the OKVS implemented in the present invention, is also selected.

[0080] According to an efficient private set intersection method based on bucket coding provided by the present invention, the above method further includes: Obtain oblivious key-value pair storage, target key, random number, and bucket width; Determine the starting bit position of the target key based on the target key, random number, and bucket width through the first hash function; Determine the bucket vector of the target key based on the starting bit position of the target key, target key, and random number through the second hash function; Determine the subvector corresponding to the target key in the oblivious key-value pair storage; Perform an inner product operation based on the bucket vector and the subvector to obtain the target value corresponding to the target key.

[0081] Refer to Figure 5 , Figure 5It is a schematic diagram of the OKVS decoding algorithm (i.e., Algorithm 4, Decoding of OKVS) provided by the present invention.

[0082] In an embodiment of the present invention, the OKVS decoding algorithm can be regarded as the reverse process of the encoding algorithm. The decoding algorithm receives an OKVS vector P, a key k, and parameters , where represents a random number, represents the redundancy rate, represents the minimum length of non-zero blocks, and outputs the corresponding value v .

[0083] In an embodiment of the present invention, can be calculated by the inner product between P and the bucket vector of a certain row in the sparse matrix H v . Therefore, the decoding algorithm actually only needs to complete the inner product operation between two vectors with a length of .

[0084] Through the embodiment of the present invention, the first hash function maps the target key to the starting bit position in the OKVS to directly locate the data storage area, avoiding full matrix scanning. The second hash function generates a bucket vector with a fixed length, and only one hash calculation is required to extract the sparse coding information of the key.

[0085] Step 106, determine the intersection of the private set of the sender and the private set of the receiver based on the oblivious key-value pair storage according to the oblivious linear evaluation protocol.

[0086] In an embodiment of the present invention, the proposed OKVS can be used to implement the PSI protocol in the semi-honest model and the malicious model. For the sake of simplicity, the PSI protocol process in the semi-honest model is given here.

[0087] According to an efficient private set intersection method based on bucket coding provided by the present invention, determine the intersection of the private set of the sender and the private set of the receiver based on the oblivious key-value pair storage according to the oblivious linear evaluation protocol, including: By jointly calling the vector oblivious linear evaluation protocol by the sender and the receiver, respectively obtain the partial result of the sender and the partial result of the receiver; By the receiver, based on the partial result of the receiver and the oblivious key-value pair storage, determine the intermediate result of the receiver; By the receiver, encode based on the partial result of the receiver and the private set of the receiver to obtain the encoded set of the receiver; and send the intermediate result of the receiver to the sender; By the sender, based on the partial result of the receiver, the intermediate result of the receiver, and the private set of the sender, determine the encoded set of the sender; and send the encoded set of the sender to the receiver; Based on the receiver's encoding set and the sender's encoding set, the receiver determines the intersection of the sender's private set and the receiver's private set.

[0088] In the embodiments of the present invention, the participants in the VOLE protocol and the input include: the receiver's private set X , and the sender's private set Y . The receiver is used to calculate X ∩ Y without revealing X the non-intersection elements, and the sender is used to assist in calculating the intersection without revealing the non-intersection elements of Y.

[0089] First, the receiver calculates Encode(I), where , represents oblivious key-value pair storage, represents key-value pairs, Encode represents encoding, represents the elements of the receiver's private set, represents the value generated by a secure pseudorandom function corresponding to .

[0090] Subsequently, the sender and the receiver jointly call the VOLE protocol to respectively obtain the sender's partial result and the receiver's partial result , satisfying 。

[0091] The receiver calculates the receiver's intermediate result , and sends the receiver's intermediate result to the sender, where is a random vector, represents oblivious key-value pair storage.

[0092] For each , , where represents a collision-resistant hash function, , and then sends the sender's encoding set to the receiver.

[0093] The receiver calculates the receiver's encoding set . The receiver calculates the intersection of the receiver's encoding set and the sender's encoding set , and the result is the intersection of the sender's private set and the receiver's private set Through the embodiments of the present invention, the communication overhead in the PSI protocol can be effectively reduced because the receiver only needs to encode an OKVS vector with a length of 1.01n The redundancy rate of the designed OKVS of the present invention is only 1.01. That is, if there are 100 elements, only the traffic of 101 elements needs to be encoded. In an actual production environment, the cost of communication resources is often higher than that of computing resources. Therefore, the present invention with lower traffic is beneficial to further reduce the communication resources required for private set intersection in the actual production environment. At the same time, the present invention with lower traffic will have better performance than the existing environment in the actual production environment, especially in a low-bandwidth environment.

[0094] The following describes the efficient private set intersection device based on bucket encoding provided by the present invention. The efficient private set intersection device based on bucket encoding described below can be correspondingly referred to the efficient private set intersection method based on bucket encoding described above.

[0095] Reference Figure 6 , Figure 6 is a schematic structural diagram of the efficient private set intersection device based on bucket encoding provided by the present invention.

[0096] An acquisition module 601 is configured to acquire an input set and a target numerical set, where the input set includes: a private set of a sender and a private set of a receiver, and the target numerical set is generated based on the private set of the receiver; An encoding module 602 is configured to encode the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function, where each bucket contains binary data of a fixed length; A determination module 603 is configured to determine a linear system of the sparse matrix, where the linear system includes: the sparse matrix, a set of starting bit positions of the sparse matrix, a set of bucket indexes of the sparse matrix, and the target numerical set; A rearrangement module 604 is configured to sort and re-number the linear system in ascending order according to the set of starting bit positions to obtain a target linear system; An elimination module 605 is configured to determine an oblivious key-value pair storage based on the target linear system through exclusive OR operations according to a bucket-based Gaussian elimination algorithm, where the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the target numerical set, and the redundancy rate of the encoding length of the oblivious key-value pair storage does not exceed a preset value; An intersection module 606 is configured to determine the intersection of the private set of the sender and the private set of the receiver based on the oblivious key-value pair storage according to an oblivious linear evaluation protocol.

[0097] Specifically, the above-mentioned efficient private set intersection device based on bucket encoding provided by the present invention can implement all the method steps implemented by the above-mentioned method embodiment of the efficient private set intersection based on bucket encoding, and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiment will not be specifically described herein again.

[0098] Figure 7 It is a schematic physical structure diagram of an electronic device provided by the present invention. As Figure 7 shown, the electronic device may include: a processor 710, a communication interface 720, a memory 730, and a communication bus 740. Among them, the processor 710, the communication interface 720, and the memory 730 complete mutual communication through the communication bus 740. The processor 710 can call the logical instructions in the memory 730 to execute the efficient private set intersection method based on bucket encoding. The method includes: obtaining an input set and a target numerical set, where the input set includes: the private set of the sender and the private set of the receiver, and the target numerical set is generated based on the private set of the receiver; encoding the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function, where each bucket contains binary data of a fixed length; determining a linear system of the sparse matrix, where the linear system includes: the sparse matrix, the starting bit position set of the sparse matrix, the bucket index set of the sparse matrix, and the target numerical set; sorting and re-numbering the linear system in ascending order according to the starting bit position set to obtain a target linear system; determining an oblivious key-value pair storage based on the target linear system through exclusive-or operations according to the bucket-based Gaussian elimination algorithm, where the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the target numerical set, and the redundancy rate of the encoding length of the oblivious key-value pair storage does not exceed a preset value; determining the intersection of the private set of the sender and the private set of the receiver based on the oblivious key-value pair storage according to the oblivious linear evaluation protocol.

[0099] In addition, when the logical instructions in the above-mentioned memory 730 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0100] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the efficient private set intersection method based on bucket encoding provided by the above-mentioned various methods. The method includes: obtaining an input set and a target numerical set, where the input set includes: the private set of the sender and the private set of the receiver, and the target numerical set is generated based on the private set of the receiver; encoding the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function, where each bucket contains binary data of a fixed length; determining a linear system of the sparse matrix, where the linear system includes: the sparse matrix, the set of starting bit positions of the sparse matrix, the set of bucket indices of the sparse matrix, and the target numerical set; sorting and re-numbering the linear system in ascending order according to the set of starting bit positions to obtain a target linear system; based on the bucket-based Gaussian elimination algorithm, determining an oblivious key-value pair storage through exclusive OR operations based on the target linear system, where the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the target numerical set, and the redundancy rate of the encoding length of the oblivious key-value pair storage does not exceed a preset value; based on the oblivious linear evaluation protocol and the oblivious key-value pair storage, determining the intersection of the private set of the sender and the private set of the receiver.

[0101] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements an efficient private set intersection method based on bucket encoding provided by the above-mentioned various methods. The method includes: obtaining an input set and a target numerical set, where the input set includes: the private set of the sender and the private set of the receiver, and the target numerical set is generated based on the private set of the receiver; encoding the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function, where each bucket contains binary data of a fixed length; determining a linear system of the sparse matrix, where the linear system includes: the sparse matrix, the set of starting bit positions of the sparse matrix, the set of bucket indices of the sparse matrix, and the target numerical set; sorting and re-numbering the linear system in ascending order according to the set of starting bit positions to obtain a target linear system; determining an oblivious key-value pair storage based on the target linear system through exclusive OR operations according to the bucket-based Gaussian elimination algorithm, where the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the target numerical set, and the redundancy rate of the encoding length of the oblivious key-value pair storage does not exceed a preset value; determining the intersection of the private set of the sender and the private set of the receiver based on the oblivious key-value pair storage according to the oblivious linear evaluation protocol.

[0102] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.

[0103] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, also by hardware. Based on such an understanding, the above technical solutions, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0104] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An efficient private set intersection method based on bucket encoding, characterized in that Including: Obtain an input set and a target value set, where the input set includes: the private set of the sender and the private set of the receiver, and the target value set is generated based on the private set of the receiver; Encode the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function, where each bucket contains binary data of a fixed length; Determine the linear system of the sparse matrix, where the linear system includes: the sparse matrix, the set of starting bit positions of the sparse matrix, the set of bucket indices of the sparse matrix, and the target value set; Sort and re-number the linear system in ascending order according to the set of starting bit positions to obtain a target linear system; According to the bucket-based Gaussian elimination algorithm, determine the oblivious key-value pair storage through exclusive OR operations based on the target linear system, where the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the target value set, and the redundancy rate of the encoding length of the oblivious key-value pair storage does not exceed a preset value; Determine the intersection of the private set of the sender and the private set of the receiver according to the oblivious linear evaluation protocol based on the oblivious key-value pair storage.

2. The efficient private set intersection method based on bucket encoding according to claim 1, wherein The encoding of the private set of the receiver into a sparse matrix composed of multiple buckets through a hash function includes: Obtain the key set, random number, and bucket width of the private set of the receiver; Through a first hash function, based on the key set and the random number, determine the starting bit position and bucket index of each row, where the bucket index is the ceiling of the ratio of the starting bit position to the bucket width; Through a second hash function, generate the buckets of each row based on the starting bit position, the bucket index, the key set, and the random number to obtain a sparse matrix, where the number of buckets of the sparse matrix is the ratio of the minimum non-zero length of the row to the bucket width.

3. The efficient private set intersection method based on bucket encoding according to claim 1, characterized in that The determining of the oblivious key-value pair storage through exclusive OR operations based on the target linear system according to the bucket-based Gaussian elimination algorithm includes: Divide the target linear system into a target number of buckets of a target width; Perform Gaussian elimination operations on each bucket to obtain an elimination sparse matrix in which the first non-zero column of each row only includes target elements; When the elimination sparse matrix is a full row rank matrix, output the oblivious key-value pair storage.

4. The efficient private set intersection method based on bucket encoding according to claim 3, characterized in that The outputting of the oblivious key-value pair storage when the elimination sparse matrix is a full row rank matrix includes: Obtain a target number of key-value pairs and the encoding redundancy; When the elimination sparse matrix is a full row rank matrix, perform encoding based on the target number of key-value pairs and the encoding redundancy to obtain the oblivious key-value pair storage.

5. The efficient private set intersection method based on bucket encoding according to claim 1, wherein The determining of the intersection of the private set of the sender and the private set of the receiver according to the oblivious linear evaluation protocol based on the oblivious key-value pair storage includes: The sender and the receiver jointly call the vector oblivious linear evaluation protocol to respectively obtain the sender partial result and the receiver partial result; Through the recipient, based on the recipient partial result and the oblivious key-value pair storage, determine the recipient intermediate result; Through the recipient, encode based on the recipient partial result and the recipient's private set to obtain the recipient encoded set; and send the recipient intermediate result to the sender; Through the sender, based on the recipient partial result, the recipient intermediate result, and the sender's private set, determine the sender encoded set; and send the sender encoded set to the recipient; Through the recipient, based on the recipient encoded set and the sender encoded set, determine the intersection of the sender's private set and the recipient's private set.

6. The efficient private set intersection method based on bucket encoding according to claim 1, wherein The method further includes: Obtain oblivious key-value pair storage, a target key, a random number, and a bucket width; Through a first hash function, based on the target key, the random number, and the bucket width, determine the starting bit position of the target key; Through a second hash function, based on the starting bit position of the target key, the target key, and the random number, determine the bucket vector of the target key; Determine the subvector corresponding to the target key in the oblivious key-value pair storage; Based on the inner product operation of the bucket vector and the subvector, obtain the target value corresponding to the target key.

7. An efficient private set intersection device based on bucket encoding, characterized in that, Includes: An acquisition module, configured to acquire an input set and a target numerical set, where the input set includes: the sender's private set and the recipient's private set, and the target numerical set is generated based on the recipient's private set; An encoding module, configured to encode the recipient's private set into a sparse matrix composed of multiple buckets through a hash function, where each bucket contains binary data of a fixed length; A determination module, configured to determine a linear system of the sparse matrix, where the linear system includes: the sparse matrix, the starting bit position set of the sparse matrix, the bucket index set of the sparse matrix, and the target numerical set; A rearrangement module, configured to perform ascending sorting and re-numbering on the linear system according to the starting bit position set to obtain a target linear system; An elimination module, configured to determine oblivious key-value pair storage through exclusive OR operations based on the target linear system according to a bucket-based Gaussian elimination algorithm, where the product of the sparse matrix and the transposed matrix of the oblivious key-value pair storage is the target numerical set, and the redundancy rate of the encoding length of the oblivious key-value pair storage does not exceed a preset value; An intersection module, configured to determine the intersection of the sender's private set and the recipient's private set based on the oblivious key-value pair storage according to the oblivious linear evaluation protocol.

8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the efficient private set intersection method based on bucket encoding according to any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the efficient private set intersection method based on bucket encoding according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the efficient private set intersection method based on bucket encoding according to any one of claims 1 to 6.

Citation Information

Cited By

  • Two-party privacy intersection method and system supporting any data scale

    CN120632942A

  • Super-threshold data set intersection method and system for security information processing

    CN121056117A

  • Coding and decoding method and device, solving method and device, encryption method, learning method and chip

    CN121561946A