Electronic data auditing method and device based on privacy set intersection
Through the method of interchange based on privacy sets, the data is encrypted using six-member offline tuples, which solves the problems of privacy protection and audit accuracy and efficiency in the existing technology, and achieves efficient and secure data auditing.
Patent Information
- Application Number
- CN202510375404.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-07-11
AI Technical Summary
The existing electronic data audit technology cannot ensure the accuracy and efficiency of audit work under the premise of achieving privacy protection, and there are security risks of data leakage.
The method based on privacy set interception is adopted to encrypt the data by generating six-member offline tuples, and auditing is done using encrypted data to ensure data security, and repetitive judgment is made through six-member offline tuples to reduce calculation and communication overhead.
It realizes that without leaking plaintext data, improves the accuracy and timeliness of audits, is suitable for large-scale data audits, protects data privacy and reduces computing and communication overhead.
Smart Images

Figure CN120296766A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of third-party auditing, and particularly to an electronic data auditing method and device based on private set intersection. Background Art
[0002] Electronic data auditing refers to "the process of collecting, preprocessing, and analyzing the electronic data of an audited entity to discover audit clues and obtain audit evidence". In actual auditing work, in order to avoid affecting the normal operation of the information system of the audited entity, maintain the independence of auditing, and avoid audit risks, internal or third-party auditing agencies usually do not directly use the information system of the audited enterprise for query analysis and inspection when conducting electronic data auditing. Instead, they collect the electronic data of the audited entity required, analyze the audit data to discover audit clues, obtain audit evidence, and form an audit conclusion. Among them, audit data analysis is a key step in electronic data auditing. In the big data environment, if the audited data from different data sources contains a large amount of similar or duplicate data, it is very likely to be the suspicious data to be searched for during the audit process. Therefore, searching for similar data for correlation analysis has become an important part of audit data analysis.
[0003] However, electronic data auditing, especially the third-party auditing process, needs to analyze and process a large amount of sensitive data of business secrets of multiple different enterprises or departments and their customers. The audited data faces a serious risk of privacy leakage. With the increasing strictness of data protection regulations, the importance of audit data privacy protection has become more prominent. Once sensitive audited data is leaked or misused during the correlation analysis process, it will seriously threaten the financial security of enterprises and the privacy rights and interests of individuals. Therefore, it is urgent to study how to efficiently and accurately discover similar or duplicate data while effectively protecting the privacy of the private data of all audited enterprises in the data correlation analysis of third-party auditing.
[0004] Most of the existing electronic data auditing work relies on the nature of the database itself and processes data in a way of plaintext transmission and plaintext comparison. However, there will also be information in the audit data that enterprises do not want to be known, such as customer transaction records and customer credit ratings. This approach does not take any protective measures during the data transmission and processing process, and there are serious security risks. Attackers can cause a series of problems such as data leakage and result falsification through malicious behaviors such as wiretapping the channel, man-in-the-middle attack, and data tampering. On the one hand, it affects the accuracy of auditing, and on the other hand, it endangers the security of the original data, which goes against the original intention of the inspection.
[0005] To solve the above technical problems, the prior art proposes to use the Private Set Intersection (PSI) technology to achieve the purpose of privacy protection. To ensure the reliability of the audit results, the audit work still requires the audit department to have a certain amount of data to promote the effective progress of the audit process, and it is impossible to achieve indirect auditing without contacting the audited plaintext data. On the other hand, due to the large amount of data contained in the enterprise's database, the traditional PSI technology is far less performant than the direct comparison of plaintext in achieving the goal of repetitive auditing.
[0006] Therefore, there is an urgent need to provide an electronic data audit method and device based on private set intersection to achieve accurate and efficient audit work on the premise of achieving the purpose of privacy protection. Summary of the Invention
[0007] In view of this, it is necessary to provide an electronic data audit method and device based on private set intersection to solve the technical problem in the prior art that it is impossible to ensure the accuracy and efficiency of the audit work on the premise of achieving privacy protection.
[0008] On the one hand, to solve the above technical problems, the present invention provides an electronic data audit method based on private set intersection, which is applied to an audit system. The audit system includes an auditor, a first service provider, and a second service provider; the method includes:
[0009] Determine the negotiation parameters of the auditor, the first service provider, and the second service provider; the negotiation parameters include a tuple offline generation scheme.
[0010] Generate six - tuple offline tuples that satisfy a preset relationship in the number field based on the tuple offline generation scheme; encrypt the data of the first service provider and the data of the second service provider online based on the six - tuple offline tuples to generate encrypted data.
[0011] Based on the encrypted data and the sixth - element data, the auditor determines the data repetition rate of the first service provider and the second service provider. When the data repetition rate is greater than the repetition rate threshold, it is determined that there is illegal data circulation.
[0012] In a possible implementation, the six - tuple offline tuples include the first metadata, the second metadata, and the third metadata owned by the auditor, the fourth metadata and the fifth metadata owned by the first service provider, and the sixth metadata owned by the second service provider; the preset relationship is:
[0013] R a *R b *(S a′ +S c )=S a+S b
[0014] Wherein, R a is the first metadata; S a is the second metadata; S a′ is the third metadata; R b is the fourth metadata; S b is the fifth metadata; S c is the sixth metadata.
[0015] In a possible implementation, when the tuple offline generation scheme is a feasible execution environment scheme, the generation of a six - tuple offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme includes:
[0016] Generating the same auditor six - tuple offline tuple, first service - party six - tuple offline tuple, and second service - party six - tuple offline tuple based on the feasible execution environment system pre - deployed in the auditor, the first service party, and the second service party;
[0017] Obtaining, based on the request of the auditor, the first metadata, the second metadata, and the third metadata that conform to the auditor's permissions from the auditor six - tuple offline tuple;
[0018] Obtaining, based on the request of the first service party, the fourth metadata and the fifth metadata that conform to the first service party's permissions from the first service - party six - tuple offline tuple;
[0019] Obtaining, based on the request of the second service party, the sixth metadata that conforms to the second service party's permissions from the second service - party six - tuple offline tuple.
[0020] In a possible implementation, when the tuple offline generation scheme is a lattice scheme, the generation of a six - tuple offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme includes:
[0021] Obtaining the initial first service - party random tuple randomly generated by the first service party, where the initial first service - party random tuple includes the second metadata and the third metadata;
[0022] Sending the third metadata to the auditor in a lattice - encrypted manner, and sending the product of the second metadata and the third metadata to the second service party in a lattice - encrypted manner;
[0023] Obtaining the initial auditor random tuple randomly generated by the auditor, where the initial auditor random tuple includes the first auditor random metadata and the sixth metadata;
[0024] Determine a first encrypted tuple based on the first auditor metadata and the sixth metadata, transmit the first encrypted tuple to the first service party, and transmit the sixth metadata to the second service party;
[0025] Obtain an initial second service party random tuple randomly generated by the second service party, where the initial second service party random tuple includes the fourth metadata and the fifth metadata;
[0026] Determine a second encrypted tuple based on the fourth metadata, the fifth metadata, and the first auditor random metadata, and send the second encrypted tuple to the first service party;
[0027] Decrypt the first encrypted tuple and the second encrypted tuple respectively to obtain first decryption data and second decryption data, and determine the first metadata based on the first decryption data and the second decryption data.
[0028] In a possible implementation manner, when the tuple offline generation scheme is the oblivious transfer scheme, generating a six - tuple offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme includes:
[0029] Control the first service party to randomly generate a first random tuple, where the first random tuple includes first random data and second random data, and generate the third metadata based on the second random data; transmit the first random data to the auditor bit - by - bit using the oblivious transfer protocol;
[0030] Control the auditor to randomly generate a second random tuple, where the second random tuple includes third random data, determine the sixth metadata according to the 01 characteristic of the third random data, and send the third random data to the second service party;
[0031] Control the first service party to re - randomly generate a third random tuple, where the third random tuple includes the first metadata and the second random data, transmit the product of the first metadata and the first random data to the auditor bit - by - bit, and generate the second metadata based on the second random data;
[0032] Control the second service party to randomly generate a fourth random tuple, where the fourth random tuple includes the fourth metadata, and determine the fifth metadata based on the product of the fourth metadata and the third random data.
[0033] In a possible implementation manner, encrypting the data of the first service party and the data of the second service party online based on the six - tuple offline tuple to generate encrypted data includes:
[0034] Determine the first target ciphertext of the first service party's local data based on the second metadata;
[0035] Send the first target ciphertext and the corresponding tuple number to the second service party through a structured transmission method;
[0036] Extract and determine the first target ciphertext and the tuple number based on a data extraction method, determine the fourth metadata and the fifth metadata based on the tuple number, and determine the second target ciphertext based on the fourth metadata, the fifth metadata, and the first target ciphertext;
[0037] Send the second target ciphertext to the first service party through a structured transmission method;
[0038] Extract the second target ciphertext data and the tuple number based on a data extraction method, determine the first metadata and the third metadata based on the tuple number, and determine the encrypted data based on the first metadata, the third metadata, and the second target ciphertext data.
[0039] In a possible implementation manner, sending the first target ciphertext to the second service party through a structured transmission method includes:
[0040] Put the first target ciphertext into the first empty hash table generated by the first service in sequence;
[0041] Determine the first hash value and the second hash value of the first service party's local data;
[0042] Judge whether the positions corresponding to the first empty hash table generated by the first service party and the first hash value and the second hash value are empty;
[0043] When both are empty, generate a first random number, generate a second random value based on the first random number and the first target ciphertext, fill the first random number into the position corresponding to the first hash value in the first empty hash table, and fill the second random value into the position corresponding to the second hash value in the first empty hash table;
[0044] When the position corresponding to the second hash value in the first empty hash table is empty, keep the original value in the position corresponding to the first hash value in the first empty hash table unchanged, generate a third random value based on the original value and the first target ciphertext, and fill the third random value into the position corresponding to the second hash value in the first empty hash table;
[0045] Fill the empty positions in the first hash table with a preset random number to obtain a first target hash table, and send the first target hash table to the second service party.
[0046] In a possible implementation, extracting and determining the first target ciphertext based on the data extraction method includes:
[0047] Receiving the first target hash table;
[0048] Determining the first hash value and the second hash value of the first service party's local data, and determining the first position of the first hash value and the second position of the second hash value;
[0049] Performing an exclusive OR operation on the values at the first position and the second position to determine the first target ciphertext.
[0050] In a possible implementation, the encrypted data includes multiple encrypted sub - data; then determining the data duplication rate of the first service party and the second service party based on the encrypted data and the sixth metadata includes:
[0051] When the encrypted sub - data and the sixth metadata are equal, determining the encrypted sub - data as the data intersection;
[0052] Taking the ratio of the total number of the data intersections and the multiple encrypted sub - data as the data duplication rate.
[0053] On the other hand, the present invention also provides an electronic data auditing device, which is applied to an auditing system. The auditing system includes an auditing party, a first service party, and a second service party; the device includes:
[0054] A parameter negotiation unit, configured to determine the negotiation parameters of the auditing party, the first service party, and the second service party; the negotiation parameters include a tuple offline generation scheme;
[0055] An offline tuple generation unit, configured to generate a six - element offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme; the six - element offline tuple includes the first metadata, the second metadata, and the third metadata owned by the auditing party, the fourth metadata and the fifth metadata owned by the first service party, and the sixth metadata owned by the second service party;
[0056] An online encryption and transmission unit, configured to perform online encryption on the data of the first service party and the data of the second service party based on the six - element offline tuple to generate encrypted data;
[0057] An auditing result determination unit, configured to, based on the encrypted data and the sixth metadata, the auditing party determine the data duplication rate of the first service party and the second service party, and when the data duplication rate is greater than the duplication rate threshold, determine that there is illegal data circulation.
[0058] The beneficial effects of the present invention are as follows: The electronic data auditing method based on private set intersection provided by the present invention uses encrypted data in the process of determining illegal data circulation, that is, auditing is implemented based on ciphertext data. The plaintext information of the first service party and the second service party will not appear outside their databases, and there is no operation for other personnel to access the databases, fundamentally protecting the security of the plaintext data and ensuring data privacy during the auditing process. Moreover, compared with the PSI technology that relies on encryption technologies such as homomorphic encryption and public key encryption, the present invention only needs to utilize the generated six - tuple offline tuples to achieve data transmission and encryption, reducing the computational and communication overheads, and thus improving the timeliness of auditing. Further, compared with the PSI technology, the present invention directly uses the six - tuple offline tuples for repeatability judgment, which is more suitable for auditing large - scale data and improves the accuracy of the auditing results.
[0059] Furthermore, the present invention divides the auditing work into two stages: offline and online, improving the flexibility of the selection of the tuple offline generation scheme in the offline stage, and reducing the burden during online computing, and thus further improving the adaptability to large - scale auditing data, that is, further improving the timeliness of the auditing work. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following - described drawings are only some embodiments of the present invention. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0061] Figure 1 It is a schematic flowchart of an embodiment of the electronic data auditing method based on private set intersection provided by the present invention;
[0062] Figure 2 It is a schematic flowchart of an embodiment of step S102 when the tuple offline generation scheme is a feasible execution environment scheme proposed by the present invention;
[0063] Figure 3 It is a schematic flowchart of an embodiment of step S102 when the tuple offline generation scheme is a lattice scheme proposed by the present invention;
[0064] Figure 4 It is a schematic flowchart of an embodiment of step S102 when the tuple offline generation scheme is an oblivious transfer scheme proposed by the present invention;
[0065] Figure 5 For the present invention Figure 1 It is a schematic flowchart of an embodiment of step S103 in
[0066] Figure 6 For the present invention Figure 5 A schematic flowchart of an embodiment of sending the first target ciphertext to a second service party through a structure transmission method in step S502 of the present invention;
[0067] Figure 7 For the present invention Figure 5 A schematic flowchart of an embodiment of extracting and determining the first target ciphertext based on a data extraction method in step S503 of the present invention;
[0068] Figure 8 For the present invention Figure 1 A schematic flowchart of an embodiment of step S104 of the present invention;
[0069] Figure 9 A schematic structural diagram of an embodiment of the electronic data audit device provided by the present invention. Detailed implementation manners
[0070] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.
[0071] It should be understood that the schematic drawings are not drawn to actual scale. The flowcharts used in the present invention illustrate the operations implemented according to some embodiments of the present invention. It should be understood that the operations in the flowcharts may not be implemented in sequence, and the steps without logical context relationships may be reversed or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart or remove one or more operations from the flowchart under the guidance of the content of the present invention. Some of the block diagrams shown in the drawings are functional entities, which do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor systems and / or microcontroller systems.
[0072] Referring to "embodiment" in this article means that the specific features, structures or characteristics described in conjunction with the embodiment may be included in at least one embodiment of the present invention. The phrase appears at various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0073] The present invention provides an electronic data auditing method and apparatus based on private set intersection, which are applied to an auditing system. The auditing system includes an auditing party, a first service party, and a second service party. In other words, the embodiments of the present invention perform auditing work on an auditing system composed of two service parties and one auditing party. The following will be described separately.
[0074] Figure 1 It is a schematic flowchart of an embodiment of the electronic data auditing method based on private set intersection provided by the present invention, as Figure 1 shown, the electronic data auditing method based on private set intersection includes:
[0075] S101. Determine the negotiation parameters of the auditing party, the first service party, and the second service party; the negotiation parameters include the tuple offline generation scheme;
[0076] S102. Generate six - tuple offline tuples that satisfy a preset relationship in a number field based on the tuple offline generation scheme; the six - tuple offline tuples include the first metadata, the second metadata, and the third metadata owned by the auditing party, the fourth metadata and the fifth metadata owned by the first service party, and the sixth metadata owned by the second service party;
[0077] S103. Perform online encryption on the data of the first service party and the data of the second service party based on the six - tuple offline tuples to generate encrypted data;
[0078] S104. Based on the encrypted data and the sixth metadata, the auditing party determines the data intersection of the first service party and the second service party, and takes the ratio of the cardinality of the data intersection to the total amount of data as the data duplication rate. When the data duplication rate is greater than the duplication rate threshold, it is determined that there is illegal data circulation.
[0079] Among them, the cardinality of the data intersection refers to the number of elements in the set of the data intersection.
[0080] Among them, the tuple offline generation scheme includes, but is not limited to, the trusted execution environment (TEE) scheme, the lattice - based encryption (LBE) scheme, and the oblivious transfer (OT) scheme.
[0081] It should be understood that: in addition to the tuple offline generation scheme, the negotiation parameters may also include other parameters. For example, the auditing party notifies the first service party and the second service party of the audit request, and the first service party and the second service party respectively count and return the database size and the tuple offline generation scheme they support. The auditing party comprehensively considers the information feedback by the first service party and the second service party, and obtains the size of the number field for subsequent operations, the capacity of the hash table, the number of tuples required, and the tuple offline generation scheme according to the accuracy requirements of its own needs. Subsequently, determine the hash function for mapping the database data to the domain and the two hash functions in the data transmission stage. Finally, share these requirements with the audited first service party and second service party.
[0082] In summary, the negotiation parameters may also include the size range, accuracy, and hash function of the database. The size range of the database can be determined by the service provider itself or through negotiation between both parties. The accuracy requirement refers to the probability of successful insertion during the online encryption process, usually required to be above 99.9%. However, for extremely poor computing conditions or overly large data, it can be reduced according to the increase in the final duplicate rate tolerance. The hash function for mapping database data to the domain needs to satisfy the property of collision resistance. Before mapping, each field in the database needs to be normalized and then mapped. The specific specifications are proposed by the auditing unit.
[0083] Compared with the prior art, the electronic data auditing method based on private set intersection provided by the embodiments of the present invention uses encrypted data during the process of determining illegal data circulation, that is, audits are implemented based on ciphertext data. The plaintext information of the first service party and the second service party will not appear outside their databases, and there are no operations for other personnel to access the databases, fundamentally protecting the security of the plaintext data and ensuring data privacy during the auditing process. Moreover, compared with PSI technology that relies on encryption technologies such as homomorphic encryption and public key encryption, the embodiments of the present invention only need to utilize the generated six - tuple offline tuples to achieve data transmission and encryption, reducing the computing and communication overhead, and thus improving the timeliness of auditing. Further, compared with PSI technology, the embodiments of the present invention directly use six - tuple offline tuples for duplicate determination, which is more suitable for auditing large - scale data and improves the accuracy of the audit results.
[0084] Furthermore, the embodiments of the present invention divide the auditing work into two stages: offline and online, improving the flexibility of the selection of the tuple offline generation scheme in the offline stage and reducing the burden during online computing, and thus further improving the adaptability to large - scale auditing data, that is, further improving the timeliness of the auditing work.
[0085] In some embodiments of the present invention, the preset relationship is:
[0086] R a *R b *(S a′ +S c )=S a +S b
[0087] In the formula, R a is the first metadata; S a is the second metadata; S a′ is the third metadata; R b is the fourth metadata; S b is the fifth metadata; S c is the sixth metadata.
[0088] In some embodiments of the present invention, when the tuple offline generation scheme is a Trusted Execution Environment (TEE) scheme, as Figure 2 shown, step S102 includes:
[0089] S201. Generate the same auditor six - tuple offline tuple, first service - provider six - tuple offline tuple, and second service - provider six - tuple offline tuple based on the Trusted Execution Environment system pre - deployed in the auditor, the first service provider, and the second service provider;
[0090] S202. Obtain the first metadata, second metadata, and third metadata that conform to the auditor's permissions from the auditor six - tuple offline tuple based on the auditor's request; that is: {R a ,S a′ ,S a}.
[0091] S203. Obtain the fourth metadata and fifth metadata that conform to the first service provider's permissions from the first service - provider six - tuple offline tuple based on the first service provider's request; that is: {R b ,S b}.
[0092] S204. Obtain the sixth metadata that conforms to the second service provider's permissions from the second service - provider six - tuple offline tuple based on the second service provider's request; that is: {S c}.
[0093] Among them, in step S201, the TEE system comes with the same random - seed generator, and based on the same random - seed generator, the same auditor six - tuple offline tuple, first service - provider six - tuple offline tuple, and second service - provider six - tuple offline tuple can be generated.
[0094] In some embodiments of the present invention, when the tuple offline generation scheme is a Lattice - Based Encryption (LBE) scheme, as Figure 3 shown, step S102 includes:
[0095] S301. Obtain the initial first service - provider random tuple randomly generated by the first service provider. The initial first service - provider random tuple includes the second metadata and the third metadata {S a′ ,S a};
[0096] S302. Send the third metadata S a′ to the auditor in a lattice - encrypted manner, and send the product of the second metadata and the third metadata to the second service provider in a lattice - encrypted manner; that is: send S a′ *S a to the second service provider;
[0097] S303. Obtain the initial auditor random tuple randomly generated by the auditor. The initial auditor random tuple includes the first auditor random metadata and the sixth metadata, {S c ,R c};
[0098] S304. Determine the first encrypted tuple based on the first auditor metadata and the sixth metadata, and transmit the first encrypted tuple to the first service party, and transmit the sixth metadata to the second service party;
[0099] Among them, the first encrypted tuple c c is: c c =(c + E(S c )) * R c -1 ; E() is lattice encryption; c is the ciphertext received by the auditor;
[0100] S305. Obtain the initial second service party random tuple randomly generated by the second service party. The initial second service party random tuple includes the fourth metadata and the fifth metadata, {S b ,R b};
[0101] S306. Determine the second encrypted tuple based on the fourth metadata, the fifth metadata and the first auditor random metadata, and send the second encrypted tuple to the first service party;
[0102] Among them, the second encrypted tuple c b is: c b =(c + E(S b )) * R b -1 *R c , where c is the ciphertext received by the second service party;
[0103] S307. Decrypt the first encrypted tuple and the second encrypted tuple respectively to obtain the first decrypted data and the second decrypted data, and determine the first metadata based on the first decrypted data and the second decrypted data.
[0104] Specifically, the calculation formula of the first metadata R a is:
[0105]
[0106] In the formula, S a′ is the first decrypted data; S a ’’ is the second decrypted data.
[0107] In some embodiments of the present invention, when the tuple offline generation scheme is the oblivious transfer (OT) scheme, as Figure 4 shown, step S102 includes:
[0108] S401. Control the first service party to randomly generate a first random tuple {R a′ , {ρ i}}, where the first random tuple includes first random data R a′ and second random data {ρ i}, and generate third metadata based on the second random data; transmit the first random data bit - by - bit to the auditor via an oblivious transfer protocol;
[0109] Specifically, transmit each R a′ bit - by - bit to the auditor via the OT protocol, and the choice for each transmission is - ρ i or R a’i *2 i-1 -ρ i . Where S a′ = ∑ρ i . In the formula, R a ’ i represents the i - th bit of R a ’ in binary.
[0110] Among them, the OT protocol means that each time two numbers are transmitted, the other party can and can only choose one to obtain, and this choice is unknown to the sender.
[0111] S402. Control the auditor to randomly generate a second random tuple, where the second random tuple includes third random data {R c}, determine the sixth metadata according to the 0 - 1 characteristic of the third random data, and send the third random data to the second service party;
[0112] Specifically, determine whether to choose - ρ ci or R i *2 a’i -ρ i-1 according to the 0 - 1 property of R i , and record it in order as t i , S c = ∑t i . The auditor shares R c with the second service party.
[0113] S403. Control the first service party to re - randomly generate a third random tuple {R a , {ρ i}}, where the third random tuple includes first metadata and second random data, transmit the product of the first metadata and the first random data bit - by - bit to the auditor, and generate second metadata based on the second random data;
[0114] Specifically, S a = ∑ρ i .
[0115] S404. Control the second service party to randomly generate a fourth random tuple {R b}, the fourth random tuple includes fourth metadata, and determine fifth metadata based on the product of the fourth metadata and the third random data.
[0116] Specifically, R B =R b *R c , determine whether to select -ρ Bi or R i *2 Ai -ρ i-1 according to the 01 property of R i , and record them in order as q i , S b =∑q i .
[0117] It should be noted that each six - tuple offline tuple corresponds to a piece of data to be audited.
[0118] In some embodiments of the present invention, as Figure 5 shown, step S103 includes:
[0119] S501. Determine the first target ciphertext of the first service party's local data based on the second metadata;
[0120] Specifically, the first target ciphertext c 1i is: c 1i =x i +S si ;
[0121] Among them, c 1i is the first target ciphertext corresponding to the i - th local data in the first service party.
[0122] S502. Send the first target ciphertext and the corresponding tuple number to the second service party through the structure transmission method;
[0123] S503. Extract and determine the first target ciphertext and the tuple number based on the data extraction method, determine the fourth metadata and the fifth metadata based on the tuple number, and determine the second target ciphertext based on the fourth metadata, the fifth metadata, and the first target ciphertext;
[0124] Specifically, the second target cipher c 2i text is:
[0125] Among them, y i is the i - th local data of the second service party.
[0126] S504. Send the second target ciphertext to the first service party through the structure transmission method;
[0127] S505. Extract the second target ciphertext data and tuple number based on the data extraction method, determine the first metadata and the third metadata based on the tuple number, and determine the encrypted data based on the first metadata, the third metadata, and the second target ciphertext data.
[0128] Specifically, the encrypted data c 3i is:
[0129] where c′ 2i is the ciphertext corresponding to the first party's local data found in the first service party.
[0130] It should be noted that: the transmission methods of the first target ciphertext, the tuple number, and the second target ciphertext are the same. The following takes the transmission process of the first target ciphertext as an example for introduction. Similarly, the methods of extracting the first target ciphertext, extracting the tuple number, and extracting the second target ciphertext data are the same. The following takes the extraction method of the first target ciphertext as an example for introduction.
[0131] In a specific embodiment of the present invention, as Figure 6 shown, sending the first target ciphertext to the second service party through the structure transmission method in step S502 includes:
[0132] S601. Put the first target ciphertext into the first empty hash table H generated by the first service in sequence;
[0133] S602. Determine the first hash value h1 and the second hash value h2 of the first service party's local data;
[0134] S603. Determine whether the positions corresponding to the first hash value and the second hash value in the first empty hash table generated by the first service party are empty;
[0135] S604. When both are empty, generate a first random number p, and generate a second random value i based on the first random number p and the first target ciphertext c and fill the first random number p into the position corresponding to the first hash value in the first empty hash table, and fill the second random value into the position corresponding to the second hash value in the first empty hash table;
[0136] S605. When the position corresponding to the second hash value in the first empty hash table is empty, keep the original value q in the position corresponding to the first hash value in the first empty hash table unchanged, and generate a third random value based on the original value and the first target ciphertext and fill the third random value
[0137] S606. Fill the empty positions in the first hash table with preset random numbers to obtain a first target hash table, and send the first target hash table to the second service party.
[0138] It should be noted that when the positions corresponding to the first empty hash table and the second hash value are both not empty, the insertion fails and no modification is made.
[0139] In some embodiments of the present invention, such as Figure 7 , extracting and determining the first target ciphertext based on the data extraction method in step S503 includes:
[0140] S701. Receive the first target hash table;
[0141] S702. Determine the first hash value and the second hash value of the local data of the first service party, and determine the first position of the first hash value and the second position of the second hash value;
[0142] S703. Perform an exclusive OR operation on the values at the first position and the second position to determine the first target ciphertext.
[0143] In summary, in the data structure transmission and extraction process of the embodiments of the present invention, the six - element offline tuple generated offline is used. Using the six - element offline tuple to protect the data does not need to be restored, effectively avoiding information leakage. At the same time, this algorithm is collusion - resistant, reducing the trust requirements among the three parties and improving the application scope of the audit scenario.
[0144] In a specific embodiment of the present invention, taking the data transmission interaction between the first service party and the second service party as an example, in this process, the first service party and the second service party perform an interaction according to the process, encrypt and transmit the plaintext information in the database relying on the generated tuple, and the second service party performs an integration. The specific process is as follows:
[0145] Step 1. The first service party A constructs two empty hash tables H1 and H2.
[0146] The position structure of the hash table is the same as the ciphertext structure, and the size is determined by the auditing unit.
[0147] Step 2. Calculate two hash values h1, h2 of the local data x i and the target ciphertext c 1i = x i + S ai . Observe whether the positions of h1 and h2 are both empty. If so, jump to step 3; if only one is empty, jump to step 4; if both are not empty, skip this data, record it in the log, and repeat step 2 to calculate the next data until there is no uncalculated data.
[0148] Step 3: Generate two random numbers and insert them into the positions of h1 in two hash tables respectively.
[0149] Step 4: For hash table H1, obtain the value p at the non-empty position and insert it into the empty position. For hash table H2, obtain the value q at the non-empty position and insert it into the empty position. Repeat Step 2 until there is no uncalculated data.
[0150] Step 5: Fill the empty positions in the hash table with random values and transmit them to the second service party B in sequence. The second service party B receives H1 and H2 and constructs an empty hash table H.
[0151] Step 6: Calculate the two hash values h1 and h2 of the local data y i and obtain y through the exclusive OR operation of the values at h1 and h2 in H1. i The corresponding ciphertext c′ 1i is obtained through the exclusive OR operation of the values at h1 and h2 in H2. 1i The tuple number j used i . Calculate Observe whether both positions h1 and h2 in H are empty. If so, jump to Step 7; if only one is empty, jump to Step 8; if neither is empty, skip this data, record it in the log, and repeat Step 6 to calculate the next data until there is no uncalculated data.
[0152] Among them, the ciphertext c′ 1i is actually equal to c 1ji .
[0153] Step 7: Generate a random number and insert it into the position of h1 in hash table H.
[0154] Step 8: For hash table H, obtain the value p at the non-empty position and insert it into the empty position. Repeat Step 2 until there is no uncalculated data.
[0155] Step 9: Fill the empty positions in hash table H with random values and transmit them to the first service party A.
[0156] In some embodiments of the present invention, the encrypted data includes multiple encrypted sub-data; then as Figure 8 shown, Step S104 includes:
[0157] S801: When the encrypted sub-data is equal to the sixth metadata, determine that the encrypted sub-data is the data intersection.
[0158] S802: Use the ratio of the cardinality of the data intersection to the multiple encrypted sub-data as the data repetition rate.
[0159] In summary, the electronic data auditing method and device based on private set intersection proposed in the embodiments of the present invention utilize an improved scheme of tuple verification based on private set intersection to implement a third-party auditing scheme that ensures data security, that is, the third party calculates the duplication rate of the set based on the encrypted private data without accessing the plaintext data. Since the third party cannot directly compare the plaintext data, the embodiments of the present invention design a three-party structured verification mode, which can compare the ciphertext and the preset value based on the preset tuple to determine whether there is a duplication. During the offline preset value process, the embodiments of the present invention adopt three different technologies based on Trusted Execution Environment (TEE), Lattice-based Encryption (LBE), and Oblivious Transfer (OT), and propose different methods for dealing with various scenarios. In the online stage, through reasonable construction and in combination with the overall process requirements, the performance of online calculation is effectively improved while ensuring security.
[0160] To better implement the electronic data auditing method based on private set intersection in the embodiments of the present invention, correspondingly, the embodiments of the present invention also provide an electronic data auditing device, which is applied to an auditing system. The auditing system includes an auditor, a first service provider, and a second service provider; as Figure 9 shown, the electronic data auditing device 900 includes:
[0161] A parameter negotiation unit 901, configured to determine negotiation parameters of the auditor, the first service provider, and the second service provider; the negotiation parameters include a tuple offline generation scheme;
[0162] An offline tuple generation unit 902, configured to generate a six-element offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme; the six-element offline tuple includes first metadata, second metadata, and third metadata owned by the auditor, fourth metadata and fifth metadata owned by the first service provider, and sixth metadata owned by the second service provider;
[0163] An online encryption transmission unit 903, configured to perform online encryption on the data of the first service provider and the data of the second service provider based on the six-element offline tuple to generate encrypted data;
[0164] An audit result determination unit 904, configured to, based on the encrypted data and the sixth metadata, the auditor determine the data intersection of the first service provider and the second service provider, and use the ratio of the cardinality of the data intersection to the total amount of data as the data duplication rate. When the data duplication rate is greater than the duplication rate threshold, it is determined that there is illegal data circulation.
[0165] The electronic data auditing device 900 provided in the above embodiments can implement the technical solutions described in the embodiments of the above Internet of Things device identification method. The specific implementation principles of the above modules or units can be referred to the corresponding content in the embodiments of the above Internet of Things device identification method, which will not be elaborated here.
[0166] Those skilled in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware (such as a processor, a controller, etc.) through a computer program. The computer program can be stored in a computer-readable storage medium. Among them, the computer-readable storage medium is a disk, an optical disc, a read-only memory or a random access memory, etc.
[0167] The above has introduced in detail a method and device for electronic data auditing based on private set intersection provided by the present invention. Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The descriptions of the above embodiments are only used to help understand the method and its core idea of the present invention; at the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. An electronic data audit method based on private set intersection, characterized in that Applied to an audit system, the audit system includes an auditor, a first service provider, and a second service provider; the method includes: Determine the negotiation parameters of the auditor, the first service provider, and the second service provider; the negotiation parameters include a tuple offline generation scheme; Generate a six - tuple offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme; Online encrypt the data of the first service provider and the data of the second service provider based on the six - tuple offline tuple to generate encrypted data; Based on the encrypted data and the sixth - tuple data, the auditor determines the data intersection of the first service provider and the second service provider, and takes the ratio of the cardinality of the data intersection to the total amount of data as the data duplication rate. When the data duplication rate is greater than the duplication rate threshold, it is determined that there is illegal data circulation.
2. The electronic data auditing method based on private set intersection according to claim 1, characterized in that The six - tuple offline tuple includes the first metadata, the second metadata, and the third metadata owned by the auditor, the fourth metadata and the fifth metadata owned by the first service provider, and the sixth metadata owned by the second service provider; the preset relationship is: R a *R b *(S a′ +S c ) = S a +S b Wherein, R a is the first metadata; S a is the second metadata; S a′ is the third metadata; R b is the fourth metadata; S b is the fifth metadata; S c is the sixth metadata.
3. The electronic data auditing method based on private set intersection according to claim 1, wherein When the tuple offline generation scheme is a feasible execution environment scheme, the generating a six - tuple offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme includes: Generate the same auditor six - tuple offline tuple, first service provider six - tuple offline tuple, and second service provider six - tuple offline tuple based on the feasible execution environment systems pre - deployed in the auditor, the first service provider, and the second service provider; Based on the request of the auditor, obtain the first metadata, the second metadata, and the third metadata that conform to the auditor's permissions from the auditor six - tuple offline tuple; Based on the request of the first service provider, obtain the fourth metadata and the fifth metadata that conform to the first service provider's permissions from the first service provider six - tuple offline tuple; Based on the request of the second service provider, obtain the sixth metadata that conforms to the second service provider's permissions from the second service provider six - tuple offline tuple.
4. The electronic data auditing method based on private set intersection according to claim 1, wherein, When the tuple offline generation scheme is a lattice scheme, the generating a six - tuple offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme includes: Obtain the initial first service provider random tuple randomly generated by the first service provider, where the initial first service provider random tuple includes the second metadata and the third metadata; Send the third metadata to the auditor in a lattice - encrypted manner, and send the product of the second metadata and the third metadata to the second service provider in a lattice - encrypted manner; Obtain the initial auditor random tuple randomly generated by the auditor, where the initial auditor random tuple includes the first auditor random metadata and the sixth metadata; Determine a first encrypted tuple based on the first auditor metadata and the sixth metadata, and transmit the first encrypted tuple to the first service provider, and transmit the sixth metadata to the second service provider; Obtain the initial second service provider random tuple randomly generated by the second service provider, where the initial second service provider random tuple includes the fourth metadata and the fifth metadata; Determine a second encrypted tuple based on the fourth metadata, the fifth metadata, and the first auditor random metadata, and send the second encrypted tuple to the first service party; Decrypt the first encrypted tuple and the second encrypted tuple respectively to obtain first decrypted data and second decrypted data, and determine the first metadata based on the first decrypted data and the second decrypted data.
5. The electronic data auditing method based on private set intersection according to claim 1, characterized in that, When the tuple offline generation scheme is the oblivious transfer scheme, the six - tuple offline tuple that satisfies a preset relationship in the number field generated based on the tuple offline generation scheme includes: Control the first service party to randomly generate a first random tuple, the first random tuple includes first random data and second random data, and generate the third metadata based on the second random data; transmit the first random data to the auditor bit - by - bit through the oblivious transfer protocol; Control the auditor to randomly generate a second random tuple, the second random tuple includes third random data, determine the sixth metadata according to the 01 characteristic of the third random data, and send the third random data to the second service party; Control the first service party to re - randomly generate a third random tuple, the third random tuple includes the first metadata and the second random data, transmit the product of the first metadata and the first random data to the auditor bit - by - bit, and generate the second metadata based on the second random data; Control the second service party to randomly generate a fourth random tuple, the fourth random tuple includes the fourth metadata, and determine the fifth metadata based on the product of the fourth metadata and the third random data.
6. The electronic data auditing method based on private set intersection according to claim 1, wherein The online encryption of the data of the first service party and the data of the second service party based on the six - tuple offline tuple to generate encrypted data includes: Determine a first target ciphertext of the local data of the first service party based on the second metadata; Send the first target ciphertext and the corresponding tuple number to the second service party through the structure transmission method; Extract and determine the first target ciphertext and the tuple number based on the data extraction method, determine the fourth metadata and the fifth metadata based on the tuple number, and determine a second target ciphertext based on the fourth metadata, the fifth metadata, and the first target ciphertext; Send the second target ciphertext to the first service party through the structure transmission method; Extract the second target ciphertext data and the tuple number based on the data extraction method, determine the first metadata and the third metadata based on the tuple number, and determine the encrypted data based on the first metadata, the third metadata, and the second target ciphertext data.
7. The electronic data auditing method based on private set intersection according to claim 6, characterized in that Sending the first target ciphertext to the second service party through the structure transmission method includes: Put the first target ciphertext into the first empty hash table generated by the first service in sequence; Determine the first hash value and the second hash value of the local data of the first service party; Judge whether the position corresponding to the first empty hash table generated by the first service party and the first hash value and the second hash value is empty; When both are empty, generate a first random number, generate a second random value based on the first random number and the first target ciphertext, fill the first random number into the position corresponding to the first hash value in the first empty hash table, and fill the second random value into the position corresponding to the second hash value in the first empty hash table; When the position corresponding to the second hash value in the first empty hash table is empty, keep the original value in the position corresponding to the first hash value in the first empty hash table unchanged, generate a third random value based on the original value and the first target ciphertext, and fill the third random value into the position corresponding to the second hash value in the first empty hash table; Fill the empty positions in the first hash table with preset random numbers to obtain a first target hash table, and send the first target hash table to the second service party.
8. The electronic data auditing method based on private set intersection according to claim 7, characterized in that, The extracting and determining the first target ciphertext based on the data extraction method includes: Receive the first target hash table; Determine the first hash value and the second hash value of the first service party's local data, and determine the first position of the first hash value and the second position of the second hash value; Perform an exclusive OR operation on the values at the first position and the second position to determine the first target ciphertext.
9. The electronic data auditing method based on private set intersection according to claim 1, characterized in that The encrypted data includes multiple encrypted sub-data; then the determining the data duplication rate of the first service party and the second service party based on the encrypted data and the sixth metadata includes: When the encrypted sub-data is equal to the sixth metadata, determine the encrypted sub-data as the data intersection; Take the ratio of the cardinality of the data intersection to the multiple encrypted sub-data as the data duplication rate.
10. An electronic data auditing device, characterized in that, Applied to an audit system, the audit system includes an auditing party, a first service party, and a second service party; the apparatus includes: A parameter negotiation unit for determining the negotiation parameters of the auditing party, the first service party, and the second service party; the negotiation parameters include a tuple offline generation scheme; An offline tuple generation unit for generating a six-tuple offline tuple that satisfies a preset relationship in a number field based on the tuple offline generation scheme; the six-tuple offline tuple includes the first metadata, the second metadata, and the third metadata owned by the auditing party, the fourth metadata and the fifth metadata owned by the first service party, and the sixth metadata owned by the second service party; An online encryption and transmission unit for online encrypting the data of the first service party and the data of the second service party based on the six-tuple offline tuple to generate encrypted data; An audit result determination unit for, based on the encrypted data and the sixth metadata, the auditing party determining the data intersection of the first service party and the second service party, taking the ratio of the cardinality of the data intersection to the total amount of data as the data duplication rate, and when the data duplication rate is greater than the duplication rate threshold, determining that there is illegal data circulation.