Hybrid homomorphic encryption-based privacy set intersection solving method and related device

Through the hybrid homomorphic encryption method, the combination of symmetric encryption and homomorphic encryption is used to solve the high computational complexity and security problems of the RSA intersection method in large data volume scenarios, and an efficient and secure privacy set intersection is achieved, which is particularly suitable for privacy calculations of large-scale data sets.

CN120433909APending Publication Date: 2025-08-05FOSHAN UNIVERSITY +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510503973.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

The RSA-based privacy set intersection method in the prior art has high computational complexity in large data scenarios, cannot effectively process massive data, and cannot provide security guarantees under the malicious adversary model.

Method used

The method based on hybrid homomorphic encryption is adopted, and the first privacy set is encrypted through a symmetric encryption algorithm, and the symmetric key is encrypted by a homomorphic encryption algorithm and sent to the calculation user. The calculation user performs intersection calculation and returns the result, and the user is requested to perform decryption output.

Benefits of technology

It significantly reduces the computing and communication overhead of requesting users, ensures the accuracy and security of intersecting privacy sets, and is suitable for privacy computing scenarios for large-scale data sets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120433909A_ABST
    Figure CN120433909A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy set intersection solving method based on hybrid homomorphic encryption and a related device, and the method comprises the steps: a request user carries out the encryption processing of a first privacy set through employing a symmetric encryption algorithm, and obtains a symmetric encryption ciphertext corresponding to the first privacy set; the request user encrypts a symmetric key corresponding to the symmetric encryption algorithm by using a homomorphic encryption algorithm and then sends the encrypted symmetric key and the symmetric encryption ciphertext to the calculation user, wherein a second privacy set exists in the calculation user; the calculation user performs intersection calculation processing based on the symmetric encryption ciphertext, the homomorphic encryption symmetric key and the second privacy set, and returns an intersection calculation result set to the request user; and the request user decrypts the received intersection calculation result set, and outputs the decrypted intersection calculation result. According to the embodiment of the invention, the calculation and communication overhead of the requesting user is obviously reduced, meanwhile, the accuracy of the intersection of the privacy set is ensured, and the privacy is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a method for finding the intersection of privacy sets based on hybrid homomorphic encryption and a related device. Background Art

[0002] Intersection of private sets is a classic problem in the field of multi-party secure computing. It requires the participants to jointly calculate the intersection of multiple sets of participants without disclosing their local sets to each other, and no information other than the intersection can be leaked to any participant. In the existing technology, due to the high computational complexity of RSA, the number of RSA calculations in the protocol will increase linearly with the increase in data volume, which makes the RSA-based intersection method have performance problems when the data volume is large. And because the RSA blind signature algorithm only performs RSA encryption on the data at one end during operation, when the difference in the magnitude of the intersection data is large, the end with smaller data volume can be used as the client end, which can obtain a very large performance advantage. In addition, the process of the RSA algorithm is suitable for parallel processing, which facilitates the use of parallel computing to improve performance. The RSA blind signature protocol can provide security for the intersection of private sets under the malicious adversary model, but because the number of asymmetric encryptions increases linearly with the number of comparisons, it cannot handle the scenario of private set intersection with massive data. Summary of the Invention

[0003] The purpose of the present invention is to overcome the shortcomings of the existing technology. The present invention provides a method and related device for finding the intersection of private sets based on hybrid homomorphic encryption, which significantly reduces the computing and communication overhead of the requesting user while ensuring the accuracy of finding the intersection of private sets and ensuring privacy.

[0004] To solve the above technical problems, an embodiment of the present invention provides a method for finding the intersection of private sets based on hybrid homomorphic encryption, the method comprising:

[0005] Requesting the user to encrypt the first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set;

[0006] The requesting user encrypts the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and sends the encrypted ciphertext together with the symmetric key to a computing user, where the computing user has a second privacy set.

[0007] The computing user performs intersection calculation based on the symmetric encryption ciphertext, the homomorphically encrypted symmetric key, and the second privacy set, and returns the intersection calculation result set to the requesting user;

[0008] The requesting user decrypts the received intersection calculation result set and outputs the decrypted intersection calculation result.

[0009] Optionally, the requesting user encrypts the first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set, including:

[0010] Extracting each set element from the first privacy set, and encrypting each set element using the symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set;

[0011] The first privacy set and the second privacy set are both composed of character strings of a preset number of digits, and the set sizes and the preset number of digits of the first privacy set and the second privacy set are public information.

[0012] Optionally, the requesting user encrypts the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and sends the encrypted key together with the symmetric encryption ciphertext to the computing user, including:

[0013] The requesting user extracts the symmetric key corresponding to the symmetric encryption algorithm;

[0014] Calling the homomorphic encryption algorithm to encrypt the symmetric key to obtain a homomorphic encrypted symmetric key;

[0015] The requesting user sends the homomorphically encrypted symmetric key and the symmetric encrypted ciphertext to the computing user.

[0016] Optionally, the computing user performs intersection calculation processing based on the symmetric encryption ciphertext, the homomorphically encrypted symmetric key, and the second privacy set, including:

[0017] The computing user performs a homomorphic decryption operation on the symmetric encrypted ciphertext using a homomorphic encrypted symmetric key, and converts the symmetric encrypted ciphertext into a homomorphic encrypted homomorphic ciphertext through the homomorphic decryption operation;

[0018] Perform intersection calculation on the homomorphically encrypted homomorphic ciphertext and the second privacy set.

[0019] Optionally, performing intersection calculation processing on the homomorphically encrypted homomorphic ciphertext and the second privacy set includes:

[0020] Sampling each encrypted element in the homomorphic ciphertext of homomorphic encryption to obtain a random non-zero plaintext element corresponding to each encrypted element;

[0021] An intersection calculation is performed using the homomorphic plaintext, the random non-zero plaintext element, and the second privacy set.

[0022] Optionally, the homomorphic calculation formula for performing intersection calculation processing using the homomorphic ciphertext, the random non-zero plaintext element, and the second privacy set is as follows:

[0023] d i =r i ∏ x∈X (c i -x);

[0024] Where, (d1,…,d i ) is the intersection calculation result set, d i is the i-th intersection calculation result element in the intersection calculation result set, where i is the number of elements in the first privacy set; r i is the i-th random non-zero plaintext element; c i is the i-th encrypted element in the homomorphic ciphertext; X is the second private set; x is an element in the second private set.

[0025] Optionally, the requesting user decrypts the received intersection calculation result set and outputs the decrypted intersection calculation result, including:

[0026] The requesting user confirms whether the corresponding encryption element in the symmetric encryption ciphertext is in the second privacy set based on the value of each intersection calculation result element in the intersection calculation result set, and obtains a confirmation result;

[0027] Obtaining, according to the confirmation result, an intersection set corresponding to the encrypted elements in the second privacy set;

[0028] The requesting user decrypts the elements in the intersection set using the symmetric key, and outputs the decrypted intersection set.

[0029] In addition, an embodiment of the present invention further provides a device for finding intersection of private sets based on hybrid homomorphic encryption, the device comprising:

[0030] Encryption processing module: used to request the user to encrypt the first privacy set using a symmetric encryption algorithm to obtain the symmetric encrypted ciphertext corresponding to the first privacy set;

[0031] A sending module is used to request the user to encrypt the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and send it together with the symmetric encryption ciphertext to a computing user, where the computing user has a second privacy set;

[0032] Intersection calculation module: used for the computing user to perform intersection calculation processing based on the symmetric encryption ciphertext, the homomorphically encrypted symmetric key and the second privacy set, and return the intersection calculation result set to the requesting user;

[0033] Decryption output module: used for the requesting user to decrypt the received intersection calculation result set and output the decrypted intersection calculation result.

[0034] In addition, an embodiment of the present invention further provides an electronic device, including a processor and a memory, wherein the processor runs a computer program or code stored in the memory to implement the method for finding the intersection of private sets as described in any one of the above.

[0035] In addition, an embodiment of the present invention further provides a computer-readable storage medium for storing a computer program or code. When the computer program or code is executed by a processor, the method for finding the intersection of privacy sets as described in any one of the above is implemented.

[0036] In an embodiment of the present invention, by utilizing the high computational efficiency and zero-expansion characteristics of the symmetric cryptographic algorithm in hybrid homomorphic encryption, the communication and computing overhead of the requesting user is significantly reduced; by utilizing the characteristics of symmetric encryption, some calculations are performed in plain text, greatly improving the efficiency of the protocol; these applications enable the solution to have significant performance advantages while maintaining security, and is particularly suitable for privacy computing scenarios of large-scale data sets. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0038] Figure 1 1 is a flow chart of a method for finding intersection of private sets based on hybrid homomorphic encryption in an embodiment of the present invention;

[0039] Figure 2 1 is a flow chart of a method for finding the intersection of private sets based on hybrid homomorphic encryption in another embodiment of the present invention;

[0040] Figure 3 Schematic diagram of the structure of a device for finding intersection of private sets based on hybrid homomorphic encryption in an embodiment of the present invention;

[0041] Figure 4 It is a schematic diagram of the structure of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION

[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0043] For example 1, please refer to Figure 1 , Figure 1 This is a flowchart of a method for finding the intersection of private sets based on hybrid homomorphic encryption in an embodiment of the present invention.

[0044] like Figure 1 As shown, a method for finding the intersection of private sets based on hybrid homomorphic encryption includes:

[0045] S101: Requesting a user to encrypt a first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set;

[0046] In a specific implementation of the present invention, the requesting user encrypts the first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set, including: extracting each set element in the first privacy set, and encrypting each set element using the symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set; wherein the first privacy set and the second privacy set are both composed of a character string of a preset number of bits, and the set size and the preset number of bits of the first privacy set and the second privacy set are public information.

[0047] Specifically, in an embodiment of the present application, the requesting user can be regarded as the receiver and the computing user can be regarded as the sender. Before performing set intersection, the encryption scheme that the requesting user and the computing user need to use in subsequent encryption is first configured, mainly the homomorphic encryption scheme (FHE) and the homomorphic-friendly symmetric encryption scheme (SYM), and the public key-private key pair (pk, sk) of the homomorphic encryption scheme is generated on the requesting user side, and the private key is retained and the key k in the generated symmetric encryption scheme is generated.

[0048] At the same time, the winning requesting user holds the first privacy set Y, and the calculating user holds the second privacy set X; both privacy sets are composed of strings of a preset number of bits σ, and the set sizes of the first privacy set Y and the second privacy set X are public, as are the preset number of bits σ; however, the first privacy set Y and the second privacy set X are respectively private data sets held by both parties, and are sets of any information that does not wish to reveal the private data.

[0049] At this time, the requesting user needs to use the symmetric encryption algorithm in the homomorphic friendly symmetric encryption scheme to perform encryption processing on the first privacy set Y, that is, use the symmetric encryption algorithm to encrypt each element y in the first privacy set Y. i By encrypting, the symmetric encrypted ciphertext corresponding to the first privacy set Y can be obtained, where the encrypted ciphertext can be expressed as: i =SYM.Encrypt(k,y i ).

[0050] S102: The requesting user encrypts the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and sends the encrypted ciphertext together with the symmetric key to a computing user, where the computing user has a second privacy set.

[0051] In the specific implementation process of the present invention, the requesting user encrypts the symmetric key corresponding to the symmetric encryption algorithm using the homomorphic encryption algorithm and sends it together with the symmetric encryption ciphertext to the computing user, including: the requesting user extracts the symmetric key corresponding to the symmetric encryption algorithm; calls the homomorphic encryption algorithm to encrypt the symmetric key to obtain the encrypted symmetric key; the requesting user sends the encrypted symmetric key and the symmetric encryption ciphertext to the computing user.

[0052] Specifically, the computing user will hold the second privacy set X. The requesting user needs to encrypt the key k in the symmetric encryption algorithm using the homomorphic encryption algorithm corresponding to the homomorphic encryption scheme. The encrypted symmetric key is FHE.Encrypt(pk,k); then the encrypted symmetric key FHE.Encrypt(pk,k) and the encrypted ciphertext (s1,…,s i ),s i =SYM.Encrypt(k,y i ) is sent to the computing user (sender) at the same time; the computing user can subsequently convert the data into a homomorphic encrypted form through a homomorphic decryption operation, and then homomorphically calculate the product of the difference between each element in the first privacy set Y and all elements in the second privacy set X, and randomize the results by multiplying them by a random factor, and finally return these randomized results to the requesting user; compared with the traditional privacy set intersection algorithm, replacing homomorphic encryption with symmetric encryption to process the first privacy set Y only requires transmitting information equal to the original data and a homomorphic ciphertext (homomorphic encryption of symmetric keys), which will significantly reduce the computing and communication overhead of the receiver.

[0053] S103: The computing user performs intersection calculation based on the symmetric encryption ciphertext, the homomorphically encrypted symmetric key, and the second privacy set, and returns the intersection calculation result set to the requesting user;

[0054] In the specific implementation process of the present invention, the computing user performs intersection calculation processing based on the symmetric encrypted ciphertext, the homomorphically encrypted symmetric key and the second privacy set, including: the computing user uses the homomorphically encrypted symmetric key to perform decryption operation processing on the symmetric encrypted ciphertext, and converts the symmetric encrypted ciphertext into homomorphically encrypted homomorphic ciphertext through the decryption operation; and performs intersection calculation processing on the homomorphically encrypted homomorphic ciphertext and the second privacy set.

[0055] Furthermore, the intersection calculation processing of the homomorphic encrypted homomorphic ciphertext and the second privacy set includes: sampling each encrypted element in the homomorphic encrypted homomorphic ciphertext to obtain a random non-zero plaintext element corresponding to each encrypted element; and performing intersection calculation processing using the homomorphic ciphertext, the random non-zero plaintext element and the second privacy set.

[0056] Furthermore, the homomorphic calculation formula for performing intersection calculation processing using the homomorphic plaintext, the random non-zero plaintext element, and the second privacy set is as follows:

[0057] d i =r i ∏ x∈X (c i -x);

[0058] Where, (d1,…,d i ) is the intersection calculation result set, d i is the i-th intersection calculation result element in the intersection calculation result set, where i is the number of elements in the first privacy set; r i is the i-th random non-zero plaintext element; c i is the i-th encrypted element in the homomorphic ciphertext; X is the second private set; x is an element in the second private set.

[0059] Specifically, after the computing user receives the encrypted ciphertext, it is necessary to perform the ciphertext-to-encryption operation; that is, the computing user will use the homomorphic encryption symmetric key FHE.Encrypt(pk,k) to encrypt the ciphertext (s1,…,s i ) performs a homomorphic decryption operation, and then converts the result of the decryption operation into a homomorphic encrypted homomorphic ciphertext (c1,…,c i ); then the homomorphic encrypted homomorphic ciphertext (c1,…,c i ) and the second privacy set X for intersection calculation.

[0060] First, the homomorphic encryption of the homomorphic ciphertext (c1,…,c i ) in each encrypted element c i Sampling, sampling a random non-zero plaintext element ri , you can get each encrypted element c i The corresponding random non-zero plaintext element r i ; Then use homomorphic ciphertext and random non-zero plaintext element r i And the second privacy set performs intersection calculation processing.

[0061] During calculation, the homomorphic calculation formula for intersection calculation is as follows:

[0062] d i =r i ∏ x∈X (c i -x);

[0063] Where, (d1,…,d i ) is the intersection calculation result set, d i is the i-th intersection calculation result element in the intersection calculation result set, where i is the number of elements in the first privacy set; r i is the i-th random non-zero plaintext element; c i is the i-th encrypted element in the homomorphic ciphertext; X is the second private set; x is an element in the second private set.

[0064] For each set element y in the first privacy set held by the requesting user i Each element c of the corresponding homomorphic ciphertext i , the computing user needs to calculate d homomorphically i , where if d i = 0, then the element c of the homomorphic ciphertext can be determined i The corresponding set element y in the first privacy set i In the second privacy set X, otherwise the element c of the homomorphic ciphertext i The corresponding set element y in the first privacy set i is not in the second privacy set X; in order to optimize the computational efficiency, we first need to i =r i ∏ x∈X (c i -x); converted to where a i is the expanded coefficient. Since the calculation is performed on the user side, the user is calculated for each element x in the second privacy set X held by the user. i are all known, so a i It is certain.

[0065] That is, by introducing a layering strategy, the original expression is reconstructed into the sum of multiple sub-expressions with shallower depths. By properly setting the parameters L and H (for example, if the original depth is 512, L = 32 and H = 16 can be used), the calculation is decomposed into several layers, each requiring only a small multiplication depth. This reconstruction allows calculations that originally required a deeper homomorphic depth to be converted to a form that only requires L layers of homomorphic depth:

[0066]

[0067] In order to further reduce the depth of L, we can The calculation of the multiplication depth is also layered, which reduces the multiplication depth from B to 4 or less. At the same time, the receiver uses a symmetric encryption algorithm to send messages, and can use the calculation of part c in the plain text state. i The complexity of this part of the calculation and communication is negligible compared to the homomorphic encryption operation, which can greatly reduce the homomorphic operation when the sender calculates the intersection; this optimization scheme not only significantly reduces the depth requirement of homomorphic calculation, but also maintains a low communication overhead; through the combination of pre-computation and batch processing technology, the scheme greatly improves the computational efficiency of the protocol while ensuring security, and is particularly suitable for processing the intersection operation of private sets of large-scale data sets.

[0068] S104: The requesting user decrypts the received intersection calculation result set and outputs the decrypted intersection calculation result.

[0069] In a specific implementation of the present invention, the requesting user decrypts the received intersection calculation result set and outputs the decrypted intersection calculation result, including: the requesting user confirms whether the corresponding encrypted element in the symmetric encryption ciphertext is in the second privacy set based on the numerical value of each intersection calculation result element in the intersection calculation result set, and obtains a confirmation result; obtains the intersection set corresponding to the encrypted element in the second privacy set based on the confirmation result; the requesting user decrypts the elements in the intersection set using the symmetric key, and outputs the decrypted intersection set.

[0070] Specifically, the requesting user receives the intersection calculation result (d1,…,d i ), and the intersection calculation result, then judge d i Is it equal to 0 to confirm whether the corresponding encrypted element in the symmetric encrypted ciphertext is in the second privacy set, and obtain the confirmation result; then obtain the intersection set corresponding to the encrypted elements in the second privacy set X according to the confirmation result; request the user to decrypt the elements in the intersection set using the symmetric key, and output the decrypted intersection set, the output of which is in the form of: X∩Y={yi |FHE.Decrypt(sk,d i )=0}.

[0071] In this embodiment of the present invention, the experimental implementation of the PSI protocol using hybrid homomorphic encryption adopts the BGV homomorphic encryption scheme, implemented based on the HElib 2.2.2 open-source library. HElib provides complete support for the BGV scheme, enabling efficient processing of integer operations, making it particularly well-suited for the PSI protocol scenario. The symmetric encryption portion is implemented in C / C++ for optimal performance. The experimental parameters are set strictly in accordance with the homomorphic encryption standard, with a security parameter of λ = 128 bits and a polynomial ring modulus q large enough to support the required multiplication depth. These parameters are dynamically adjusted during the experimental testing process to ensure sufficient security redundancy in the protocol.

[0072] The experiment plans to adopt a layered and progressive design approach, first realizing the correctness of the basic protocol verification function, and then introducing a series of optimization strategies to improve performance; when implementing the homomorphic decryption circuit, full use is made of the SIMD features provided by the HElib library to implement efficient batch processing technology, specifically using two methods based on state: State-Sliced packaging and sequential Packed packaging to process data, and packing multiple collection elements in the same ciphertext of the BGV scheme to achieve parallel computing; this technical solution will implement these two packaging methods separately, and evaluate their execution efficiency in the PSI protocol through comparative tests.

[0073] At the same time, the computational advantages of the BGV scheme in finite fields are fully utilized, and the computational complexity is further reduced through innovative technologies such as pre-computation and polynomial coefficient reconstruction. In terms of depth optimization, the newly proposed layered strategy is used to reconstruct the polynomial calculation with an original depth of 512 in typical test cases into a depth of less than 4 layers. Through the comprehensive application of these optimization measures, it is expected that the overall performance of the protocol can be significantly improved while ensuring security.

[0074] In terms of hybrid homomorphic PSI protocol optimization, this technical solution proposes an innovative multi-level deep optimization strategy by leveraging the high computational efficiency and zero-expansion of symmetric cryptographic algorithms in hybrid homomorphic encryption, significantly reducing communication and computing overheads; and adopts a layered computing strategy to reduce the multiplication depth from B to 4 or below; and innovatively utilizes the characteristics of symmetric encryption to enable some calculations to be performed in plaintext, greatly improving protocol efficiency; the combined application of these optimization strategies enables the solution to have significant performance advantages while maintaining security, making it particularly suitable for privacy computing scenarios of large-scale data sets.

[0075] In an embodiment of the present invention, by utilizing the high computational efficiency and zero-expansion characteristics of the symmetric cryptographic algorithm in hybrid homomorphic encryption, the communication and computing overhead of the requesting user is significantly reduced; by utilizing the characteristics of symmetric encryption, some calculations are performed in plain text, greatly improving the efficiency of the protocol; these applications enable the solution to have significant performance advantages while maintaining security, and is particularly suitable for privacy computing scenarios of large-scale data sets.

[0076] For example 2, please refer to Figure 2 , Figure 2 This is a flowchart of a method for finding the intersection of private sets based on hybrid homomorphic encryption in another embodiment of the present invention.

[0077] like Figure 2 As shown, a method for finding the intersection of private sets based on hybrid homomorphic encryption includes:

[0078] S201: Requesting a user to encrypt a first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set;

[0079] S202: The requesting user encrypts the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and sends the encrypted ciphertext together with the symmetric key to a computing user, where the computing user has a second privacy set.

[0080] S203: The computing user performs a decryption operation on the symmetric encrypted ciphertext using the homomorphically encrypted symmetric key, and converts the symmetric encrypted ciphertext into homomorphically encrypted homomorphic ciphertext through the decryption operation;

[0081] S204: Sampling each encrypted element in the homomorphically encrypted homomorphic ciphertext to obtain a random non-zero plaintext element corresponding to each encrypted element;

[0082] S205: Performing intersection calculation using the homomorphic ciphertext, the random non-zero plaintext element, and the second privacy set, and returning the intersection calculation result set to the requesting user;

[0083] S206: The requesting user decrypts the received intersection calculation result set and outputs the decrypted intersection calculation result.

[0084] The specific implementation of the second embodiment can be found in the first embodiment, which will not be described in detail here.

[0085] For example three, please refer to Figure 3 , Figure 3 This is a schematic diagram of the structural composition of a private set intersection device based on hybrid homomorphic encryption in an embodiment of the present invention.

[0086] like Figure 3 As shown, a device for finding intersection of private sets based on hybrid homomorphic encryption, the device comprising:

[0087] Encryption processing module 301: used to request the user to encrypt a first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set;

[0088] In a specific implementation of the present invention, the requesting user encrypts the first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set, including: extracting each set element in the first privacy set, and encrypting each set element using the symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set; wherein the first privacy set and the second privacy set are both composed of a character string of a preset number of bits, and the set size and the preset number of bits of the first privacy set and the second privacy set are public information.

[0089] Specifically, in an embodiment of the present application, the requesting user can be regarded as the receiver and the computing user can be regarded as the sender. Before performing set intersection, the encryption scheme that the requesting user and the computing user need to use in subsequent encryption is first configured, mainly the homomorphic encryption scheme (FHE) and the homomorphic-friendly symmetric encryption scheme (SYM), and the public key-private key pair (pk, sk) of the homomorphic encryption scheme is generated on the requesting user side, and the private key is retained and the key k in the generated symmetric encryption scheme is generated.

[0090] At the same time, the winning requesting user holds the first privacy set Y, and the calculating user holds the second privacy set X; both privacy sets are composed of strings of a preset number of bits σ, and the set sizes of the first privacy set Y and the second privacy set X are public, as are the preset number of bits σ; however, the first privacy set Y and the second privacy set X are respectively private data sets held by both parties, and are sets of any information that does not wish to reveal the private data.

[0091] At this time, the requesting user needs to use the symmetric encryption algorithm in the homomorphic friendly symmetric encryption scheme to perform encryption processing on the first privacy set Y, that is, use the symmetric encryption algorithm to encrypt each element y in the first privacy set Y. i By encrypting, the symmetric encrypted ciphertext corresponding to the first privacy set Y can be obtained, where the encrypted ciphertext can be expressed as: i =SYM.Encrypt(k,y i ).

[0092] Sending module 302: configured to request the user to encrypt the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and send the encrypted ciphertext together with the symmetric key to a computing user, where the computing user has a second privacy set;

[0093] In the specific implementation process of the present invention, the requesting user encrypts the symmetric key corresponding to the symmetric encryption algorithm using the homomorphic encryption algorithm and sends it together with the symmetric encryption ciphertext to the computing user, including: the requesting user extracts the symmetric key corresponding to the symmetric encryption algorithm; calls the homomorphic encryption algorithm to encrypt the symmetric key to obtain the encrypted symmetric key; the requesting user sends the encrypted symmetric key and the symmetric encryption ciphertext to the computing user.

[0094] Specifically, the computing user will hold the second privacy set X. The requesting user needs to encrypt the key k in the symmetric encryption algorithm using the homomorphic encryption algorithm corresponding to the homomorphic encryption scheme. The encrypted symmetric key is FHE.Encrypt(pk,k); then the encrypted symmetric key FHE.Encrypt(pk,k) and the encrypted ciphertext (s1,…,s i ),s i =SYM.Encrypt(k,y i ) is sent to the computing user (sender) at the same time; the computing user can subsequently convert the data into a homomorphic encrypted form through a homomorphic decryption operation, and then homomorphically calculate the product of the difference between each element in the first privacy set Y and all elements in the second privacy set X, and randomize the results by multiplying them by a random factor, and finally return these randomized results to the requesting user; compared with the traditional privacy set intersection algorithm, replacing homomorphic encryption with symmetric encryption to process the first privacy set Y only requires transmitting information equal to the original data and a homomorphic ciphertext (homomorphic encryption of symmetric keys), which will significantly reduce the computing and communication overhead of the receiver.

[0095] Intersection calculation module 303: used for the computing user to perform intersection calculation processing based on the symmetric encryption ciphertext, the homomorphically encrypted symmetric key and the second privacy set, and return the intersection calculation result set to the requesting user;

[0096] In the specific implementation process of the present invention, the computing user performs intersection calculation processing based on the symmetric encrypted ciphertext, the homomorphically encrypted symmetric key and the second privacy set, including: the computing user uses the homomorphically encrypted symmetric key to perform decryption operation processing on the symmetric encrypted ciphertext, and converts the symmetric encrypted ciphertext into homomorphically encrypted homomorphic ciphertext through the decryption operation; and performs intersection calculation processing on the homomorphically encrypted homomorphic ciphertext and the second privacy set.

[0097] Furthermore, the intersection calculation processing of the homomorphic encrypted homomorphic ciphertext and the second privacy set includes: sampling each encrypted element in the homomorphic encrypted homomorphic ciphertext to obtain a random non-zero plaintext element corresponding to each encrypted element; and performing intersection calculation processing using the homomorphic ciphertext, the random non-zero plaintext element and the second privacy set.

[0098] Furthermore, the homomorphic calculation formula for performing intersection calculation processing using the homomorphic plaintext, the random non-zero plaintext element, and the second privacy set is as follows:

[0099] d i =r i ∏ x∈X (c i -x);

[0100] Where, (d1,…,d i ) is the intersection calculation result set, d i is the i-th intersection calculation result element in the intersection calculation result set, where i is the number of elements in the first privacy set; r i is the i-th random non-zero plaintext element; c i is the i-th encrypted element in the homomorphic ciphertext; X is the second private set; x is an element in the second private set.

[0101] Specifically, after the computing user receives the encrypted ciphertext, it is necessary to perform the ciphertext-to-encryption operation; that is, the computing user will use the homomorphic encryption symmetric key FHE.Encrypt(pk,k) to encrypt the ciphertext (s1,…,s i ) performs a homomorphic decryption operation, and then converts the result of the decryption operation into a homomorphic encrypted homomorphic ciphertext (c1,…,c i ); then the homomorphic encrypted homomorphic ciphertext (c1,…,c i ) and the second privacy set X for intersection calculation.

[0102] First, the homomorphic encryption of the homomorphic ciphertext (c1,…,c i ) in each encrypted element c i Sampling, sampling a random non-zero plaintext element r i , you can get each encrypted element c i The corresponding random non-zero plaintext element r i ; Then use homomorphic ciphertext and random non-zero plaintext element r i And the second privacy set performs intersection calculation processing.

[0103] During calculation, the homomorphic calculation formula for intersection calculation is as follows:

[0104] di =r i ∏ x∈X (c i -x);

[0105] Where, (d1,…,d i ) is the intersection calculation result set, d i is the i-th intersection calculation result element in the intersection calculation result set, where i is the number of elements in the first privacy set; r i is the i-th random non-zero plaintext element; c i is the i-th encrypted element in the homomorphic ciphertext; X is the second private set; x is an element in the second private set.

[0106] For each set element y in the first privacy set held by the requesting user i Each element c of the corresponding homomorphic ciphertext i , the computing user needs to calculate d homomorphically i , where if d i = 0, then the element c of the homomorphic ciphertext can be determined i The corresponding set element y in the first privacy set i In the second privacy set X, otherwise the element c of the homomorphic ciphertext i The corresponding set element y in the first privacy set i is not in the second privacy set X; in order to optimize the computational efficiency, we first need to i =r i ∏ x∈X (c i -x); converted to where a i is the expanded coefficient. Since the calculation is performed on the user side, the user is calculated for each element x in the second privacy set X held by the user. i are all known, so a i It is certain.

[0107] That is, by introducing a layered strategy, the original expression is reconstructed into the sum of multiple shallower sub-expressions. By properly setting the parameters L and H (e.g., if the original depth is 512, L = 32 and H = 16 can be used), the calculation is decomposed into several layers, each requiring only a small multiplication depth. This reconstruction allows calculations that originally required a deeper homomorphic depth to be converted to a form that only requires L layers of homomorphic depth:

[0108]

[0109] In order to further reduce the depth of L, we can The calculation of the multiplication depth is also layered, which reduces the multiplication depth from B to 4 or less. At the same time, the receiver uses a symmetric encryption algorithm to send messages, and can use the calculation of part c in the plain text state. i The complexity of this part of the calculation and communication is negligible compared to the homomorphic encryption operation, which can greatly reduce the homomorphic operation when the sender calculates the intersection; this optimization scheme not only significantly reduces the depth requirement of homomorphic calculation, but also maintains a low communication overhead; through the combination of pre-computation and batch processing technology, the scheme greatly improves the computational efficiency of the protocol while ensuring security, and is particularly suitable for processing the intersection operation of private sets of large-scale data sets.

[0110] The decryption output module 304 is used for the requesting user to decrypt the received intersection calculation result set and output the decrypted intersection calculation result.

[0111] In a specific implementation of the present invention, the requesting user decrypts the received intersection calculation result set and outputs the decrypted intersection calculation result, including: the requesting user confirms whether the corresponding encrypted element in the symmetric encryption ciphertext is in the second privacy set based on the numerical value of each intersection calculation result element in the intersection calculation result set, and obtains a confirmation result; obtains the intersection set corresponding to the encrypted element in the second privacy set based on the confirmation result; the requesting user decrypts the elements in the intersection set using the symmetric key, and outputs the decrypted intersection set.

[0112] Specifically, the requesting user receives the intersection calculation result (d1,…,d i ), and the intersection calculation result, then judge d i Is it equal to 0 to confirm whether the corresponding encrypted element in the symmetric encrypted ciphertext is in the second privacy set, and obtain the confirmation result; then obtain the intersection set corresponding to the encrypted elements in the second privacy set X according to the confirmation result; request the user to decrypt the elements in the intersection set using the symmetric key, and output the decrypted intersection set, the output of which is in the form of: X∩Y={y i |FHE.Decrypt(sk,d i )=0}.

[0113] In this embodiment of the present invention, the experimental implementation of the PSI protocol using hybrid homomorphic encryption adopts the BGV homomorphic encryption scheme, implemented based on the HElib 2.2.2 open-source library. HElib provides complete support for the BGV scheme, enabling efficient processing of integer operations, making it particularly well-suited for the PSI protocol scenario. The symmetric encryption portion is implemented in C / C++ for optimal performance. The experimental parameters are set strictly in accordance with the homomorphic encryption standard, with a security parameter of λ = 128 bits and a polynomial ring modulus q large enough to support the required multiplication depth. These parameters are dynamically adjusted during the experimental testing process to ensure sufficient security redundancy in the protocol.

[0114] The experiment plans to adopt a layered and progressive design approach, first realizing the correctness of the basic protocol verification function, and then introducing a series of optimization strategies to improve performance; when implementing the homomorphic decryption circuit, full use is made of the SIMD features provided by the HElib library to implement efficient batch processing technology, specifically using two methods based on state: State-Sliced packaging and sequential Packed packaging to process data, and packing multiple collection elements in the same ciphertext of the BGV scheme to achieve parallel computing; this technical solution will implement these two packaging methods separately, and evaluate their execution efficiency in the PSI protocol through comparative tests.

[0115] At the same time, the computational advantages of the BGV scheme in finite fields are fully utilized, and the computational complexity is further reduced through innovative technologies such as pre-computation and polynomial coefficient reconstruction. In terms of depth optimization, the newly proposed layered strategy is used to reconstruct the polynomial calculation with an original depth of 512 in typical test cases into a depth of less than 4 layers. Through the comprehensive application of these optimization measures, it is expected that the overall performance of the protocol can be significantly improved while ensuring security.

[0116] In terms of hybrid homomorphic PSI protocol optimization, this technical solution cleverly utilizes the high computational efficiency and zero-expansion characteristics of symmetric cryptographic algorithms in hybrid homomorphic encryption to propose an innovative multi-level deep optimization strategy, significantly reducing communication and computing overheads; and adopts a layered computing strategy to reduce the multiplication depth from B to 4 or below; and innovatively utilizes the characteristics of symmetric encryption to enable some calculations to be performed in plaintext, greatly improving the protocol efficiency; the combined application of these optimization strategies enables the solution to have significant performance advantages while maintaining security, which is particularly suitable for privacy computing scenarios of large-scale data sets.

[0117] In an embodiment of the present invention, by utilizing the high computational efficiency and zero-expansion characteristics of the symmetric cryptographic algorithm in hybrid homomorphic encryption, the communication and computing overhead of the requesting user is significantly reduced; by utilizing the characteristics of symmetric encryption, some calculations are performed in plain text, greatly improving the efficiency of the protocol; these applications enable the solution to have significant performance advantages while maintaining security, and is particularly suitable for privacy computing scenarios of large-scale data sets.

[0118] An embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the method for finding the intersection of private sets according to any of the above embodiments is implemented. The computer-readable storage medium includes, but is not limited to, any type of disk (including floppy disks, hard disks, optical disks, CD-ROMs, and magneto-optical disks), ROM (Read-Only Memory), RAM (Random Access Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory, magnetic cards, or optical cards. In other words, a storage device includes any medium that can store or transmit information in a readable form by a device (e.g., a computer or a mobile phone), and can be a read-only memory, a disk, or an optical disk.

[0119] An embodiment of the present invention further provides a computer application program that runs on a computer and is used to execute the method for finding the intersection of private sets of any one of the above embodiments.

[0120] also, Figure 4 It is a schematic diagram of the structure of an electronic device in an embodiment of the present invention.

[0121] The embodiment of the present invention further provides an electronic device, such as Figure 4 The electronic device includes a processor 402, a memory 403, an input unit 404, a display unit 405 and other components. Those skilled in the art will understand that Figure 4The structural components of the electronic device shown do not constitute a limitation on all devices, and may include more or fewer components than shown, or combine certain components. The memory 403 can be used to store the application 401 and various functional modules, and the processor 402 runs the application 401 stored in the memory 403, thereby executing various functional applications and data processing of the device. The memory can be an internal memory or an external memory, or include both internal and external memories. The internal memory may include a read-only memory (ROM), a programmable ROM (PROM), an electrically programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, or a random access memory. The external memory may include a hard disk, a floppy disk, a ZIP disk, a USB flash drive, a magnetic tape, etc. The memory disclosed in the present invention includes but is not limited to these types of memories. The memory disclosed in the present invention is only an example and not a limitation.

[0122] The input unit 404 is used to receive input signals and keywords entered by the user. The input unit 404 may include a touch panel and other input devices. The touch panel can collect user touch operations on or near it (such as operations performed by the user using a finger, stylus, or any other suitable object or accessory on or near the touch panel) and drive the corresponding connected device according to a pre-set program; other input devices may include, but are not limited to, one or more of a physical keyboard, function keys (such as playback control keys, on / off keys, etc.), a trackball, a mouse, a joystick, etc. The display unit 405 can be used to display information entered by the user or information provided to the user, as well as various menus of the terminal device. The display unit 405 can be in the form of a liquid crystal display, an organic light-emitting diode, etc. The processor 402 is the control center of the terminal device, connecting the various parts of the entire device using various interfaces and lines. It performs various functions and processes data by running or executing software programs and / or modules stored in the memory 403 and calling data stored in the memory.

[0123] As an embodiment, the electronic device includes: one or more processors 402, a memory 403, and one or more applications 401, wherein the one or more applications 401 are stored in the memory 403 and are configured to be executed by the one or more processors 402, and the one or more applications 401 are configured to execute the corresponding privacy set intersection method in any of the above embodiments.

[0124] In an embodiment of the present invention, by utilizing the high computational efficiency and zero-expansion characteristics of the symmetric cryptographic algorithm in hybrid homomorphic encryption, the communication and computing overhead of the requesting user is significantly reduced; by utilizing the characteristics of symmetric encryption, some calculations are performed in plain text, greatly improving the efficiency of the protocol; these applications enable the solution to have significant performance advantages while maintaining security, and is particularly suitable for privacy computing scenarios of large-scale data sets.

[0125] In addition, the above is a detailed introduction to a method for finding the intersection of private sets based on hybrid homomorphic encryption and related devices provided in an embodiment of the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A method for finding the intersection of private sets based on hybrid homomorphic encryption, characterized in that: The method comprises: Requesting the user to encrypt the first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set; The requesting user encrypts the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and sends the encrypted ciphertext together with the symmetric key to a computing user, where the computing user has a second privacy set. The computing user performs intersection calculation based on the symmetric encryption ciphertext, the homomorphically encrypted symmetric key, and the second privacy set, and returns the intersection calculation result set to the requesting user; The requesting user decrypts the received intersection calculation result set and outputs the decrypted intersection calculation result.

2. The method for finding intersection of private sets according to claim 1, characterized in that: The requesting user encrypts the first privacy set using a symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set, including: Extracting each set element from the first privacy set, and encrypting each set element using the symmetric encryption algorithm to obtain a symmetric encrypted ciphertext corresponding to the first privacy set; The first privacy set and the second privacy set are both composed of character strings of a preset number of digits, and the set sizes and the preset number of digits of the first privacy set and the second privacy set are public information.

3. The method for finding intersection of private sets according to claim 1, wherein: The requesting user encrypts the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and sends the symmetric key and the symmetric encryption ciphertext to the computing user, including: The requesting user extracts the symmetric key corresponding to the symmetric encryption algorithm; Calling the homomorphic encryption algorithm to encrypt the symmetric key to obtain a homomorphic encrypted symmetric key; The requesting user sends the homomorphically encrypted symmetric key and the symmetric encrypted ciphertext to the computing user.

4. The method for finding intersection of private sets according to claim 1, wherein: The computing user performs intersection calculation processing based on the symmetric encryption ciphertext, the homomorphically encrypted symmetric key, and the second privacy set, including: The computing user performs a homomorphic decryption operation on the symmetric encrypted ciphertext using a homomorphic encrypted symmetric key, and converts the symmetric encrypted ciphertext into a homomorphic encrypted homomorphic ciphertext through the homomorphic decryption operation; Perform intersection calculation on the homomorphically encrypted homomorphic ciphertext and the second privacy set.

5. The method for finding intersection of private sets according to claim 4, characterized in that: The performing intersection calculation processing on the homomorphically encrypted homomorphic ciphertext and the second privacy set includes: Sampling each encrypted element in the homomorphic ciphertext of homomorphic encryption to obtain a random non-zero plaintext element corresponding to each encrypted element; An intersection calculation is performed using the homomorphic ciphertext, the random non-zero plaintext element, and the second privacy set.

6. The method for finding intersection of private sets according to claim 5, characterized in that: The homomorphic calculation formula for performing intersection calculation using the homomorphic ciphertext, the random non-zero plaintext element, and the second privacy set is as follows: d i =r i ∏ x∈X (c i -x); Where (d1,…,d i ) is the intersection calculation result set, d i is the i-th intersection calculation result element in the intersection calculation result set, where i is the number of elements in the first privacy set; r i is the i-th random non-zero plaintext element; c i is the i-th encrypted element in the homomorphic ciphertext; X is the second private set; x is an element in the second private set.

7. The method for finding intersection of private sets according to claim 1, wherein: The requesting user decrypts the received intersection calculation result set and outputs the decrypted intersection calculation result, including: The requesting user confirms whether the corresponding encryption element in the symmetric encryption ciphertext is in the second privacy set based on the value of each intersection calculation result element in the intersection calculation result set, and obtains a confirmation result; Obtaining, according to the confirmation result, an intersection set corresponding to the encrypted elements in the second privacy set; The requesting user decrypts the elements in the intersection set using the symmetric key, and outputs the decrypted intersection set.

8. A device for finding intersection of private sets based on hybrid homomorphic encryption, characterized in that: The device comprises: Encryption processing module: used to request the user to encrypt the first privacy set using a symmetric encryption algorithm to obtain the symmetric encrypted ciphertext corresponding to the first privacy set; A sending module is used to request the user to encrypt the symmetric key corresponding to the symmetric encryption algorithm using a homomorphic encryption algorithm and send it together with the symmetric encryption ciphertext to a computing user, where the computing user has a second privacy set; Intersection calculation module: used for the computing user to perform intersection calculation processing based on the symmetric encryption ciphertext, the homomorphically encrypted symmetric key and the second privacy set, and return the intersection calculation result set to the requesting user; Decryption output module: used for the requesting user to decrypt the received intersection calculation result set and output the decrypted intersection calculation result.

9. An electronic device comprising a processor and a memory, characterized in that: The processor runs the computer program or code stored in the memory to implement the privacy set intersection method according to any one of claims 1 to 7.

10. A computer-readable storage medium for storing a computer program or code, characterized in that: When the computer program or code is executed by a processor, the privacy set intersection method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Data sharing method and device, equipment and system

    CN113434888A

  • Anti-quantum-attack privacy set intersection method, medium and anti-quantum-attack privacy set intersection system

    CN118316607A

  • N-to-k casual transmission method based on homomorphic encryption

    CN119232351A

  • Data homomorphic encryption and decryption method and apparatus for implementing privacy protection

    WO2020253234A1