Block-based two-party security comparison method
By segmenting and obfuscating private data and utilizing equality testing and oblivious transfer protocols, the problems of high communication and computational overhead in existing technologies are solved, and efficient two-party secure comparison is achieved.
Patent Information
- Application Number
- CN202510845381.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-09-12
AI Technical Summary
Existing two-party secure comparison technologies have high communication and computational overheads, resulting in increased costs and low efficiency.
A block method is used to obfuscate and block private data. The location of the first unequal private data block is found through equality test and shared using the oblivious transfer protocol. Only a preliminary comparison of the private data is performed once, and the final result is calculated in combination with binary search.
It effectively reduces communication and computing overhead, improves comparison efficiency, and ensures that data privacy is not leaked.
Smart Images

Figure CN120639283A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of secure multi-party computing, and particularly relates to a two-party secure comparison method based on chunking. Background Art
[0002] The core principle of two-party secure comparison is to construct a protocol using cryptographic primitives (such as homomorphic encryption, oblivious transfer, secret sharing, garbled circuits, etc.), enabling both parties to collaboratively compute the result of a comparison function (x>y, x=y, x<y) while keeping their respective inputs private. By introducing encryption techniques, secret sharing, or other cryptographic tools, the original data is transformed into a secure intermediate representation form, and through a series of carefully designed protocol steps, the calculation of the target function is completed without revealing the input content. During the whole process, neither party can infer the private data of the other party from the interaction information, thus achieving strict protection of input privacy while ensuring the correctness of the calculation.
[0003] Application scenarios such as comparing bids in online auctions, comparing credit scores between financial institutions, and screening indicator thresholds in medical research require two independent parties to determine the magnitude of a value without disclosing their private data. However, since both parties often hold sensitive information, directly exchanging raw data is both unsafe and difficult to meet compliance requirements. To address this, two-party secure comparison (2PC) technology has emerged. It allows two parties to perform numerical comparisons within an encrypted domain, outputting only the comparison results without leaking any other information. In this way, the effective use of data and collaborative decision-making are achieved, while the privacy and security of all parties are protected to the greatest extent, and the compliance requirements of various laws, regulations and industry standards are met. For example, the patent document applied for by Shandong Blockchain Research Institute (application number: CN202311083269.6 application publication number: CN117056985A) discloses a two-party secure comparison method based on an obfuscated circuit. The implementation steps of the invention are as follows: the data demander calls the obfuscated circuit generation method to generate an encryption key pair and an obfuscated circuit, and combines the data demander's data to calculate a first comparison value and all circuit values, and sends all circuit values to the data provider; the data provider calls the extended oblivious transfer algorithm, processes the data provider's data and the data demander's key pair, obtains the data provider's data key, combines all circuit values, decrypts to obtain a second comparison value, and sends it to the data demander; the data demander compares the first comparison value and the second comparison value to obtain the comparison result of the data demander's data and the data provider's data. The invention can realize a security protocol for comparing secret values under the premise of protecting the privacy of input and calculation results by constructing an obfuscated circuit, without leaking any information, thus ensuring the security and privacy of the data. However, because the data demander will call the obfuscation circuit generation method to generate an encryption key pair and send all circuit values calculated by the obfuscation circuit to the data provider when solving the first comparison value, the communication cost increases, and two comparisons are required when performing security comparison, which results in a large computational overhead. Summary of the Invention
[0004] The purpose of the present invention is to address the deficiencies in the above-mentioned prior art and provide a two-party security comparison method based on block division to solve the technical problem of high communication and computing overhead in the prior art.
[0005] To achieve the above object, the technical solution adopted by the present invention includes the following steps:
[0006] (1) Initialization parameters:
[0007] Initialize the N-bit binary private data to be compared held by the sender P0 and the receiver P1 to be x and y respectively, where N ≥ 2, and the n-th bit binary private data of x and y are x respectively. nand y n ;
[0008] (2) The two parties confuse the data to be compared:
[0009] The sender P0 and the receiver P1 have binary privacy data x for each bit n and y n Execute the convert protocol to obtain the obfuscated results s and t of x and y;
[0010] (3) The two participants divide the private data into blocks and obtain the location of the first unequal private data block:
[0011] The sender P0 and the receiver P1 divide the private data x and y into J private data blocks of equal length, and use the equality test confusion circuit to test each private data block. and Corresponding obfuscated data block and The sum of the values of [d j ]0 and [d j ]1 performs an equality test and then compares the shared value of the test result and Update and get the location identifier of the first private data block whose data in x and y are not equal and in, j∈[0,J);
[0012] (4) The two participants share the first unequal private data block:
[0013] The sender P0 and the receiver P1 have a private data block The location identifier of the first private data block that is not equal to the data in x and y and Execute the two-choice oblivious transfer protocol respectively to obtain the shared value of the first unequal private data block [x j ]0, [x j ]1 and [y j ]0、[y j ]1;
[0014] (5) The two parties calculate the comparison value of the private data:
[0015] The shared value of the first unequal private data block of sender P0 and receiver P1 respectively [x j ]0 and [y j ]0, [x j ]1 and [y j]1. Calculate the preliminary comparison values x' and y' of the private data x and y, and calculate the comparison value x of the private data x and y through x' and y' * and y * ;
[0016] (6) The two parties obtain the security comparison results:
[0017] The sender P0 and the receiver P1 calculate the shared values [T]0 and [T]1 of the binary search data T, and at the same time, respectively calculate the comparison value x * 、y * The initial offsets w0 and w1 of the calculated private data x and y calculated with random numbers ε0 and ε1 are sent to each other and compared with the calculated results through [T]0 and [T]1 Among them, ε0∈[0,n), ε1∈[0,n).
[0018] Compared with the prior art, the present invention has the following advantages:
[0019] 1. This invention obtains the location of the first unequal private data block after dividing the private data into blocks, and uses cryptographic techniques such as oblivious transmission to directly compare the block-by-block data. This avoids the defects of the existing technology of calling the obfuscated circuit and sending all circuit values, effectively reducing communication overhead.
[0020] 2. In the present invention, the two participants calculate the comparison values of private data x and y based on the preliminary comparison value of the private data, and only perform one comparison, avoiding the defect of the existing technology that requires two comparisons when performing security comparison, and effectively reducing the computational overhead. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a flow chart for implementing the present invention. DETAILED DESCRIPTION
[0022] The present invention will be described in further detail below with reference to the accompanying drawings and specific embodiments.
[0023] Reference Figure 1 , the present invention comprises the following steps:
[0024] Step 1) Initialize parameters:
[0025] Initialize the N-bit binary private data to be compared held by the sender P0 and the receiver P1 to be x and y respectively, where N ≥ 2, and the n-th bit binary private data of x and y are x respectively. n and y n ,Here it is assumed that both parties want to compare their bids and obtain the identity of the higher bidder, but do not disclose the specific auction prices x and y.,In this embodiment, N = 100;
[0026] Step 2) The two parties confuse the data to be compared:
[0027] The sender P0 and the receiver P1 have binary privacy data x for each bit n and y n Execute the convert protocol to obtain the obfuscated results s and t of x and y. The convert protocol steps are:
[0028] (2a) The sender P0 generates a 1-bit random number and a binary random number of length l+1 and through and x n Calculate the two selected messages m0 and m1, and the offset Afterwards, Send to P1, where:
[0029]
[0030] in, Represents exclusive OR operation;
[0031] (2b) The receiver P1 generates a 1-bit random number As the selection bit, the sender P0 passes two to-be-selected messages m0 and m1, and both parties jointly execute the two-choose-one oblivious transfer protocol. P1 gets one of the two to-be-selected messages m0 and m1. and through Calculating the offset Then sent to P0, where:
[0032]
[0033] (2c) The sender P0 and the receiver P1 pass and The calculated total offset w' is calculated x n 、y n Obfuscated data n , t n , get the confusion results s and t of x and y, where:
[0034]
[0035] Step 3) The two participants divide the private data into blocks and obtain the location of the first unequal private data block:
[0036] The sender P0 and the receiver P1 divide the private data x and y into J private data blocks of equal length, and use the equality test confusion circuit to test each private data block. and Corresponding obfuscated data block and The sum of the values of [d j ]0 and [d j ]1 performs equality test. When performing data security comparison, we follow this idea: only compare the size of the first different block to get the comparison result of the two data sizes. For example, the two data are 101010110 and 101001100, which are divided into three blocks. The left side is 101, 010 and 110, and the right side is 101, 001 and 100. The comparison result of the first different block is 010>001, and the corresponding data size relationship is 101010110>101001100. At this time, we only need to compare 3 bits of data, which reduces the comparison length and improves efficiency. Then, the shared value of the test result is and Update and get the location identifier of the first private data block whose data in x and y are not equal and in, j∈[0,J). In this embodiment, J=10, that is, we divide the original data into 10 data blocks of length 10. The equality test obfuscation circuit includes an input layer, an equality test layer, and a result output layer. The equality test is implemented as follows:
[0037] The sender P0 and the receiver P1 will [d j ]0 and [d j ]1 is input into the input layer of the equality test confusion circuit. The input layer receives the bit strings input by the sender and the receiver and passes them to the equality test layer. The equality test layer compares the two sets of values received bit by bit through the logic gate circuit and generates an intermediate comparison result [d j ]'0 and [d j ]'1; the result output layer is for all [d j ]'0 and [d j ]'1 Perform logical AND operation to obtain the shared value of the test result and Through this calculation, the two bidders find the location identifier of the first unequal private data block without exposing the original price privacy data. They can then directly use this identifier to find the first unequal private data block and perform subsequent comparisons, reducing the length of the original comparison value.
[0038] Step 4) The two participants share the first unequal private data block:
[0039] The sender P0 and the receiver P1 have a private data block The location identifier of the first private data block that is not equal to the data in x and y and Execute the two-choice oblivious transfer protocol respectively to obtain the shared value of the first unequal private data block [x j ]0, [x j ]1 and [y j ]0、[y j ]1, where the sender P0 and the receiver P1 have a The location identifier of the first private data block that is not equal to the data in x and y and The implementation steps for executing the two-choice oblivious transfer protocol are:
[0040] (4a) The sender P0 generates a 1-bit random number r j and privacy data blocks as well as Calculate two messages k0 and k1 to be selected, and r j As the shared value of the first unequal private data block in:
[0041]
[0042]
[0043] (4b) The receiver P1 will As the selection bit, the sender P0 passes two to-be-selected messages k0 and k1, and both parties jointly execute the two-choose-one oblivious transfer protocol. P1 obtains one of the two to-be-selected messages k0 and k1. and will As the shared value of the first unequal private data block
[0044] right and The update formula for updating is:
[0045]
[0046] Through this step of calculation, the two parties transmit the first unequal private data block without knowing its location;
[0047] Step 5) The two parties calculate the comparison value of the private data:
[0048] The shared value of the first unequal private data block of sender P0 and receiver P1 respectively [x j ]0 and [y j ]0, [x j ]1 and [y j]1. Calculate the preliminary comparison values x' and y' of the private data x and y, and calculate the comparison value x of the private data x and y through x' and y' * and y * , where the preliminary comparison values x', y' of the private data x and y, and the comparison value x of the private data x and y are * and y * , the calculation formulas are:
[0049] x'=[h]0mod2 l
[0050] y'=2 l -([h]1mod2 l )
[0051]
[0052] l = logN
[0053] x * =-x'-[x"]0+[y"]0
[0054] y * =y'-[x"]1+[y"]1
[0055] Where mod is the modulo operation, [h]0 represents the shared value of the first unequal private data block [y j ]0 and [x j ]0 and and The difference between [h]1 and [y]1 represents the shared value of the first unequal private data block. j ]1 and [x j ]1 and the sum of shared values and The difference between [x”]0, [y”]0 and [x”]1, [y”]1 are the half values of x’, y’ of the sender P0 and the receiver P1. and its length identifier and Perform the shared value of the length of x' and y' obtained by inadvertently transmitting the result of the binary selection. Through this step, we reduce the length of the data to be compared to half of the original length, and we get a set of comparison values. Only one final comparison is needed to obtain the result of the secure comparison between the two parties, which improves efficiency.
[0056] Step 6) Both parties obtain the security comparison results:
[0057] The sender P0 and the receiver P1 calculate the shared values [T]0 and [T]1 of the binary search data T, and at the same time, respectively calculate the comparison value x * 、y * The initial offsets w0 and w1 of the calculated private data x and y calculated with random numbers ε0 and ε1 are sent to each other and compared with the calculated results through [T]0 and [T]1 Among them, ε0∈[0,n), ε1∈[0,n), calculate the shared values [T]0 and [T]1 of T, use the VOSE algorithm, and the implementation steps are:
[0058] (6a) The sender P0 and the receiver P1 jointly execute a random oblivious transfer protocol of length (N-1, N). P0 obtains N binary vector messages m0, m1, ..., m n ,…,m N-1 , P1 gets all the vectors except ε0+ε1 All N-1 vectors outside, where ε0 and ε1 represent random numbers;
[0059] (6b) The sender P0 constructs an N×N matrix M, whose nth row is the vector m n , and construct a displacement matrix M' whose nth row is m n The result after circular right shift n bits, then P0 calculates vectors U and V, whose nth element u n and v n are the exclusive OR sum of all elements in the n-th column of M' and the exclusive OR sum of all elements in the n-th row of M';
[0060] (6c) The receiver P1 obtains the displacement matrix G' in the same way, and then calculates the vectors U' and V', whose nth element u' n and v' n are the exclusive OR sum of all elements in the n-th column of G' and the exclusive OR sum of all elements in the n-th row of G';
[0061] (6d) The receiver P1 calculates the vector W from the vectors U' and V', whose nth element is w n , the sender P0 calculates vector S' through binary lookup data T and vector U, and sends it to P1, and uses vector V as its own shared value [T]0. Finally, P1 calculates its own shared value [T]1 through vector S' and vector W, where:
[0062]
[0063] The binary search data T is held by the sender P0 and includes N-bit binary search data with the left half being 1 and the right half being 0. shift(·) is a circular right shift.
[0064] Comparison results The calculation formulas are:
[0065]
[0066] in, Indicates the sign bit of [h]0, [h]1. Through this step of calculation, we get the comparison result (0 or 1) that can be found on the search vector T. At this point, the two bidders have achieved a safe comparison of auction prices without revealing their own auction prices, and obtained the identity of the party with the higher bid.
Claims
1. A two-party security comparison method based on block division, characterized in that: The following steps are involved: (1) Initialization parameters: Initialize the N-bit binary private data to be compared held by the sender P0 and the receiver P1 to be x and y respectively, where N ≥ 2, and the n-th bit binary private data of x and y are x respectively. n and y n ; (2) The two parties confuse the data to be compared: The sender P0 and the receiver P1 have binary privacy data x for each bit n and y n Execute the convert protocol to obtain the obfuscated results s and t of x and y; (3) The two participants divide the private data into blocks and obtain the location of the first unequal private data block: The sender P0 and the receiver P1 divide the private data x and y into J private data blocks of equal length, and use the equality test confusion circuit to test each private data block. and Corresponding obfuscated data block and The sum of the values of [d j ]0 and [d j ]1 performs an equality test and then compares the shared value of the test result and Update and get the location identifier of the first private data block whose data in x and y are not equal and in, j∈[0,J); (4) The two participants share the first unequal private data block: The sender P0 and the receiver P1 have a private data block The location identifier of the first private data block that is not equal to the data in x and y and Execute the two-choice oblivious transfer protocol respectively to obtain the shared value of the first unequal private data block [x j ]0, [x j ]1 and [y j ]0、[y j ]1; (5) The two parties calculate the comparison value of the private data: The shared value of the first unequal private data block of sender P0 and receiver P1 respectively [x j ]0 and [y j ]0, [x j ]1 and [y j ]1. Calculate the preliminary comparison values x' and y' of the private data x and y, and calculate the comparison value x of the private data x and y through x' and y' * and y * ; (6) The two parties obtain the security comparison results: The sender P0 and the receiver P1 calculate the shared values [T]0 and [T]1 of the binary search data T, and at the same time, respectively calculate the comparison value x * 、y * The initial offsets w0 and w1 of the calculated private data x and y calculated with random numbers ε0 and ε1 are sent to each other and compared with the calculated results through [T]0 and [T]1 Among them, ε0∈[0,n), ε1∈[0,n).
2. The method according to claim 1, characterized in that The sender P0 and the receiver P1 in step (2) perform binary privacy data x on each bit. n and y n Execute the convert protocol. The implementation steps are: (2a) The sender P0 generates a 1-bit random number and a binary random number of length l+1 and through and x n Calculate the two selected messages m0 and m1, and the offset Afterwards, Send to P1, where: in, Represents exclusive OR operation; (2b) The receiver P1 generates a 1-bit random number As the selection bit, the sender P0 passes two to-be-selected messages m0 and m1, and both parties jointly execute the two-choose-one oblivious transfer protocol. P1 gets one of the two to-be-selected messages m0 and m1. and through Calculating the offset Then sent to P0, where: (2c) The sender P0 and the receiver P1 pass and The calculated total offset w' is calculated x n 、y n Obfuscated data n , t n , get the confusion results s and t of x and y, where:
3. The method according to claim 1, characterized in that The equality test obfuscation circuit described in step (3) includes an input layer, an equality test layer and a result output layer.
4. The method according to claim 3, characterized in that The equality test confusion circuit described in step (3) is used to test each private data block. and Corresponding obfuscated data block and The sum of the values of [d j ]0 and [d j ]1Perform equality test, the implementation steps are: The input layer takes each private data block input by sender P0 and receiver P1 and Corresponding obfuscated data block and The sum of the values of [d j ]0 and [d j ]1 is transmitted to the equality test layer; the equality test layer compares it bit by bit through the logic gate circuit and generates an intermediate comparison result [d j ]'0 and [d j ]'1; the result output layer is for all [d j ]'0 and [d j ]'1 Perform logical AND operation to obtain the shared value of the test result and 5. The method according to claim 1, wherein The shared value of the test result described in step (3) and Update, the update formula is:
6. The method according to claim 1, wherein The sender P0 and the receiver P1 in step (4) have to calculate each private data block. The location identifier of the first private data block that is not equal to the data in x and y and Execute the two-choose-one oblivious transfer protocol separately. The implementation steps are as follows: (4a) The sender P0 generates a 1-bit random number r j and privacy data blocks as well as Calculate two messages k0 and k1 to be selected, and r j As the shared value of the first unequal private data block in: (4b) The receiver P1 will As the selection bit, the sender P0 passes two to-be-selected messages k0 and k1, and both parties jointly execute the two-choose-one oblivious transfer protocol. P1 obtains one of the two to-be-selected messages k0 and k1. and will As the shared value of the first unequal private data block 7. The method according to claim 1, characterized in that The preliminary comparison values x', y' of the private data x and y described in step (5), and the comparison value x of the private data x and y * and y * , the calculation formulas are: x'=[h]0mod2 l y'=2 l -([h]1mod2 l ) l = logN x * =-x'-[x”]0+[y”]0 and * =y'-[x”]1+[y”]1 Where mod is the modulo operation, [h]0 represents the shared value of the first unequal private data block [y j ]0 and [x j ]0 and and The difference between [h]1 and [y]1 represents the shared value of the first unequal private data block. j ]1 and [x j ]1 and the sum of shared values and The difference between [x”]0, [y”]0 and [x”]1, [y”]1 are the half values of x’, y’ of the sender P0 and the receiver P1. and its length identifier and Perform an oblivious transfer of the lengths of x' and y' to obtain the shared value.
8. The method according to claim 1, characterized in that The calculation of the shared values [T]0 and [T]1 of T described in step (6) uses the VOSE algorithm and the implementation steps are: (6a) The sender P0 and the receiver P1 jointly execute a random oblivious transfer protocol of length (N-1, N). P0 obtains N binary vector messages m0, m1, ..., m n ,,m N-1 , P1 gets all the vectors except ε0+ε1 All N-1 vectors outside, where ε0 and ε1 represent random numbers; (6b) The sender P0 constructs an N×N matrix M, whose nth row is the vector m n , and construct a displacement matrix M' whose nth row is m n The result after circular right shift n bits, then P0 calculates vectors U and V, whose nth element u n and v n are the exclusive OR sum of all elements in the n-th column of M' and the exclusive OR sum of all elements in the n-th row of M'; (6c) The receiver P1 obtains the displacement matrix G' in the same way, and then calculates the vectors U' and V', whose nth element u' n and v' n are the exclusive OR sum of all elements in the n-th column of G' and the exclusive OR sum of all elements in the n-th row of G'; (6d) The receiver P1 calculates the vector W from the vectors U' and V', whose nth element is w n , the sender P0 calculates vector S' through binary lookup data T and vector U, and sends it to P1, and uses vector V as its own shared value [T]0. Finally, P1 calculates its own shared value [T]1 through vector S' and vector W, where: Among them, shift(·) is a circular right shift.
9. The method according to claim 8, characterized in that The binary search data T is N-bit binary search data held by the sender P0, with the left half being 1 and the right half being 0.
10. The method according to claim 8, characterized in that The comparison result described in step (6) The calculation formulas are: in, Indicates the sign bit of [h]0 and [h]1.
Citation Information
Patent Citations
Two-party safety comparison method and system based on obfuscation circuit
CN117056985A