Method and device for processing privacy data, storage medium and electronic device

By randomly sorting and rearranging the data between the client and the service provider and secretly sharing the data through the exchange network, the problem of relying on third-party institutions for intersection feature calculation in existing technologies is solved, and low-cost, high-security intersection feature acquisition is achieved.

CN120675815BActive Publication Date: 2025-11-07HANGZHOU FRAUDMETRIX TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511139076.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-14
Publication Date
2025-11-07
Estimated Expiration
2045-08-14

AI Technical Summary

Technical Problem

Existing technologies rely on trusted third-party institutions for intersection feature calculation, resulting in high deployment costs and limited privacy protection and security. They cannot obtain intersection features without disclosing the plaintext of the intersection and the plaintext of the features.

Method used

Anonymous privacy intersection is achieved by using exchangeable encrypted datasets from both the client and the service provider. Secrets are shared through random sorting and rearrangement and exchange networks between the client and the service provider to obtain intersection indexes and feature secret fragments. Statistical functions are then used to calculate the intersection statistical feature values.

Benefits of technology

It reduces deployment costs and improves security. Clients and service providers do not need to rely on third-party institutions. The intersection index is determined only in the encrypted state, ensuring the security and privacy of the feature set.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675815B_ABST
    Figure CN120675815B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a privacy data processing method and device, storage medium and electronic equipment, and relates to the technical field of big data processing. In the scheme, the first data set of the client and the second data set of the service party are used to obtain an intersection index by using exchangeable encryption for intersection of privacy. The second data set is rearranged in a first random order and a second random order by the service party and the client in sequence, and the intersection index indicates the bit sequence of the intersection ciphertext in the rearranged second data set. The client performs secret sharing with the service party by using the first random order to rearrange the feature set through an exchange network according to the second random order, obtains a first feature secret fragment, and the service party obtains a second feature secret fragment. Statistical function calculation is performed based on the intersection index, the first feature secret fragment and the second feature secret fragment to obtain an intersection statistical feature value of the first data set and the second data set. The scheme does not depend on a third party, is convenient to deploy, and does not expose the intersection and feature plaintext, and is high in security.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present disclosure relate to the technical field of big data processing, in particular, to a private data processing method, a private data processing device, a computer readable storage medium and an electronic device. BACKGROUND

[0002] Private computing is an important technology for protecting data privacy and security in the era of big data. To implement vertical federated learning of machine learning modeling, the first step is to implement private set intersection. Private set intersection (PSI) can implement intersection feature calculation without exposing additional data information of participants, and can be applied to various application scenarios such as accurate advertising marketing and contact discovery. PSI technology has gradually matured.

[0003] However, with the diversification of application scenarios, intersection feature calculation usually needs to rely on a third-party trusted institution, which has high deployment cost and can only guarantee that no additional information outside the intersection is exposed, and the security of privacy protection is limited.

[0004] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore it can include information that constitutes prior art known to those skilled in the art, and it can also include information that does not constitute prior art known to those skilled in the art. SUMMARY

[0005] The purpose of the present disclosure is to provide a private data processing method, a private data processing device, a computer readable storage medium and an electronic device, thereby at least partially overcoming the problem of how to obtain intersection features without revealing intersection plaintext and feature plaintext.

[0006] According to one aspect of the present disclosure, a private data processing method is provided, applied to a client side, the private data processing method comprising: based on a first data set, performing private set intersection with a second data set of a server by using commutative encryption, to obtain an intersection index; the second data set is rearranged by a first random order at the server, and then rearranged by a second random order at the client side; the intersection index includes the bit sequence of the intersection ciphertext after commutative encryption and rearrangement at the client side in the second data set; based on the second random order, performing secret sharing with the server by using a feature set rearranged by the first random order through a switching network, to obtain a first feature secret shard; the feature set corresponds to the original second data set; the server obtains a second feature secret shard; and performing statistical function calculation based on the intersection index, the first feature secret shard and the second feature secret shard, to obtain an intersection statistical feature value of the first data set and the second data set.

[0007] In an example embodiment of the present disclosure, the switching network comprises control units and wires, each wire corresponding to a random mask generated by a service party; after the service party rearranges the feature set based on the first random ordering, each feature value is masked with the random mask of the corresponding wire and input into the corresponding wire; based on the second random ordering, the first feature secret share is obtained by secret sharing between the switching network and the service party using the feature set rearranged by the service party based on the first random ordering, comprising: based on the second random ordering, the selection bit of each control unit is determined in sequence, the feature value is masked according to the random mask of the selected wire in sequence, and the first feature secret share is output in the second random ordering after being transmitted along the selected wire in sequence.

[0008] In an example embodiment of the present disclosure, the wire comprises at least one unit input wire and at least one unit output wire corresponding to each control unit, and the wire further comprises a starting input wire and a terminal output wire; after the service party rearranges the feature set based on the first random ordering, each feature value is XORed with the random mask of the corresponding starting input wire to determine the first mask message transmitted on the starting input wire; based on the second random ordering, the selection bit of each control unit is determined in sequence, the feature value is masked according to the random mask of the selected wire in sequence, and the first feature secret share is output in the second random ordering after being transmitted along the selected wire in sequence, comprising: for each control unit, the selection bit is determined in sequence according to the second random ordering; the second mask message transmitted on the local path composed of the unit input wire and the unit output wire is determined according to the selection bit; the second mask message is obtained by XORing the random masks of the unit input wire and the unit output wire on the local path; the first mask message and the second mask message transmitted on each local path are XORed in sequence from the starting input wire to the corresponding terminal output wire on the global path to obtain the first feature secret share.

[0009] In an example embodiment of the present disclosure, the control unit comprises a permutation switch, the permutation switch comprises a first unit input wire and a first unit output wire corresponding to a bit sequence, and a second unit input wire and a second unit output wire corresponding to a bit sequence; for each control unit, the selection bit is determined according to the second random ordering, comprising: based on the second random ordering, the permutation switch is determined to be a direct connection selection bit, the first unit input wire and the first unit output wire form a local path, and the second unit input wire and the second unit output wire form a local path; based on the second random ordering, the permutation switch is determined to be a switching selection bit, the first unit input wire and the second unit output wire form a local path, and the second unit input wire and the first unit output wire form a local path.

[0010] In an example embodiment of the present disclosure, the control unit comprises a multiplexer, the multiplexer comprises kThe plurality of selectable unit input wires and the plurality of target unit output wires; determining, for each control unit, a selection bit according to the second random order, including: determining, based on the second random order, a selection bit for the multiplexer to select one of the plurality of selectable unit input wires k The selected selection bit causes k The selected one of the plurality of selectable unit input wires k The selected one of the plurality of target unit input wires and the target unit output wire form a local path.

[0011] In an example embodiment of the present disclosure, the service party uses a random mask corresponding to the termination output wire as a second feature secret fragment.

[0012] In an example embodiment of the present disclosure, based on the first data set, the intersection index is obtained by performing an intersection operation on the second data set of the service party using commutative encryption, including: rearranging the first data set according to a third random order, mapping to a predetermined elliptic curve, and encrypting based on a first private key to obtain a first encrypted result; sending the first encrypted result to the service party; obtaining a second encrypted result provided by the service party, the second encrypted result being obtained by the service party by rearranging the second data set according to a first random order, mapping to a predetermined elliptic curve, and encrypting based on a second private key; rearranging the second encrypted result according to a second random order and encrypting based on the first private key to obtain a third encrypted result, and providing the third encrypted result to the service party; obtaining a fourth encrypted result provided by the service party, the fourth encrypted result being obtained by the service party by rearranging the first encrypted result according to a fourth random order and encrypting based on the second private key; comparing the third encrypted result and the fourth encrypted result to obtain the intersection index of the intersection ciphertext in the third encrypted result.

[0013] In an example embodiment of the present disclosure, the statistical function includes at least one of a sum value statistical function, a mean value statistical function, a variance statistical function, a standard deviation statistical function, and an intersection potential statistical function.

[0014] According to one aspect of the present disclosure, there is provided a privacy data processing apparatus applied to a client side, comprising: a private intersection module configured to perform private intersection with a second data set of a server based on a first data set using commutative encryption, to obtain an intersection index; the second data set is rearranged in a first random order at the server side and then rearranged in a second random order at the client side; the intersection index comprises a bit sequence of the intersection ciphertext in the second data set after commutative encryption and rearrangement at the client side; an oblivious transfer module configured to perform secret sharing with the server using the first random order to rearrange a feature set based on the second random order through an exchange network, to obtain a first feature secret shard; the feature set corresponds to the original second data set; the server obtains a second feature secret shard; a feature statistics module configured to perform a statistical function calculation based on the intersection index, the first feature secret shard and the second feature secret shard, to obtain an intersection statistical feature value of the first data set and the second data set.

[0015] According to one aspect of the present disclosure, there is provided a computer readable storage medium having stored thereon a computer program, the computer program being executed by a processor to implement the privacy data processing method of any one of the above.

[0016] According to one aspect of the present disclosure, there is provided an electronic device, comprising:

[0017] a processor; and a memory configured to store executable instructions of the processor;

[0018] wherein the processor is configured to perform the privacy data processing method of any one of the above by executing the executable instructions.

[0019] The privacy data processing method, the privacy data processing apparatus, the computer readable storage medium and the electronic device provided by the embodiments of the present disclosure, in the scheme, the client party can perform intersection operation on the first data set based on local exchangeable encryption and the second data set of the service party to obtain an intersection index; in the intersection operation on the first data set based on local exchangeable encryption and the second data set of the service party, the second data set is rearranged in the service party and the client party in the first random order and the second random order, and the intersection index indicates the bit sequence of the intersection ciphertext after the rearrangement of the client party in the second data set; on this basis, based on the second random order, the first feature secret fragment is obtained by performing secret sharing on the feature set rearranged by the service party in the first random order through the exchange network, the second feature secret fragment is obtained by the service party, and the feature set corresponds to the original second data set before being rearranged in the first random order; the intersection statistical feature value of the first data set and the second data set is obtained by performing statistical function calculation based on the intersection index, the first feature secret fragment and the second feature secret fragment. The client party and the service party holding the data can directly participate in the calculation without relying on a third party, which reduces the deployment cost and improves the deployment convenience; the intersection index is determined in the ciphertext state by the intersection operation on the private set of the two parties, and the plaintext data of the intersection is not obtained, the feature set is rearranged based on the exchange network, and the service party and the client party only obtain the feature secret fragment after the rearrangement and do not obtain the plaintext data of the feature set, so that the feature statistical function calculation is completed safely and efficiently, and the security is further improved.

[0020] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0021] The drawings incorporated into the specification and constituting a part of the specification show embodiments consistent with the present disclosure and, together with the specification, serve to explain the principles of the present disclosure. It is obvious that the drawings in the following description are only some embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor.

[0022] Figure 1 The schematic diagram of the step flow of the privacy data processing method provided by the embodiments of the present disclosure is schematically shown.

[0023] Figure 2 The schematic diagram of the control principle of the permutation switch in the exchange network provided by the embodiments of the present disclosure is schematically shown.

[0024] Figure 3 The schematic diagram of the control principle of the multiplexer in the exchange network provided by the embodiments of the present disclosure is schematically shown.

[0025] Figure 4A schematic diagram of a control flow of an exchange network is shown.

[0026] Figure 5 A schematic diagram of a structure of a device for processing privacy data is shown.

[0027] Figure 6 An electronic device for implementing a method for processing privacy data is shown. DETAILED DESCRIPTION

[0028] Example implementations will now be described more fully with reference to the accompanying drawings. Example implementations can be implemented in any

[0029] In addition, the drawings are only schematic and the dimensions of certain features could be exaggerated for clarity. Like reference numerals may

[0030] The present disclosure applies to a security-based cross-domain statistical function scenario, in which a client party can initiate a statistical function calculation for a specific feature value corresponding to a specific data set to a service party, without showing the intersection plaintext and leaking the feature plaintext in the calculation process, and the calculation result of the statistical calculation is obtained by negotiation by either party or both parties, wherein the client party that initiates the calculation can be obtained by default. Figure 1 A schematic diagram of a step flow of a method for processing privacy data provided by an embodiment of the present disclosure is shown in Figure 1 As shown, the method is applied to a client party, and can include the following steps 101 to 103.

[0031] Step 101, based on the first data set, adopt commutative encryption to perform intersection privacy seeking with the second data set of the service party to obtain an intersection index; the second data set is rearranged in a first random order at the service party and then rearranged in a second random order at the client party; the intersection index includes the bit sequence of the intersection ciphertext in the second data set after the commutative encryption and the rearrangement at the client party.

[0032] In the embodiments of the present disclosure, the client party can initiate feature value calculation of a corresponding statistical function to the service party based on the first data set, the first data set can include object description information of feature value calculation, and can be at least part of the data held locally by the client party.

[0033] For example, the client party can initiate feature value calculation of cumulative total consumption, average monthly consumption, monthly consumption variance, monthly consumption standard deviation, etc. to the service party for part of the users, and the service party holds user information and user consumption feature values. Therefore, the user information of the aforementioned part of the users of the client party is the first data set, the user information held by the service party is the second data set, the client party adopts commutative encryption to perform intersection privacy seeking with the service party to obtain an intersection index to indicate the bit sequence of the intersection ciphertext in the second data set after commutative encryption and rearrangement in the process of intersection privacy seeking. The above scenario is only for example, the first data set can also include object description information of social media, operating agencies, etc., and the feature value calculation can also be statistical calculation of feature values such as registration number, delivery number, conversion number, comment number, transaction number, etc. The client party can analyze and infer based on the feature values obtained by statistical calculation, and perform related businesses in the fields of interest recommendation, credit risk control, medical assistance, etc.

[0034] The principle of commutative encryption (Commutative Encryption) can be represented as formula (1) as follows:

[0035] (1)

[0036] That is, for plaintext data m , the encryption order of the key E k1 and the key E k2 is commutative without affecting the encryption result. When the client party adopts commutative encryption to perform intersection privacy seeking with the service party, both parties first encrypt their local data sets with their own keys, and then encrypt the encrypted results with their own keys. Therefore, in the above process, both parties only transmit ciphertext data, and the first data set is encrypted twice, first at the client party and then at the service party, and the second data set is encrypted twice, first at the service party and then at the client party. In commutative encryption, the encryption order does not affect the encryption result, so when the plaintext data is consistent, the corresponding ciphertext data is also consistent, and then the intersection index can be determined based on the intersection ciphertext.

[0037] Further, in the intersection privacy seeking process, each party can also rearrange the object description information in the data set to hide the ordering of the object description information from the other party, avoiding inferring privacy data based on the ordering. Among them, the second data set can be encrypted after rearrangement based on the first random ordering by the service party, and then encrypted after rearrangement based on the second random ordering after exchange to the customer party. Since each party has performed at least one random rearrangement, the customer party and the service party cannot determine the bit sequence of the object description information corresponding to the intersection ciphertext in the original second data set.

[0038] Step 102, based on the second random ordering, secret sharing is performed with the service party using the feature set rearranged by the first random ordering through the switching network, to obtain the first feature secret fragment; the feature set corresponds to the original second data set; the service party obtains the second feature secret fragment.

[0039] In the embodiments of the present disclosure, the feature set includes the feature value corresponding to each object description information in the original second data set. Since the intersection index indicates the bit sequence of the intersection ciphertext in the second data set after rearrangement according to the first random ordering and the second random ordering, and the feature value in the feature set has a mapping relationship with the object description information in the original second data set. Therefore, the process of rearranging the feature set according to the second data set can be repeated to make the mapping relationship between the intersection ciphertext indicated by the intersection index and the feature value after rearrangement equivalent to the mapping relationship between the original second data set and the feature value before rearrangement.

[0040] Switching Network (SN) is a network structure for data transmission and conversion, which can control the transmission path of data to adjust the sequence bit sequence of input data for rearrangement in the transmission process. The design of the switching network can be adjusted according to specific business needs and network topology. In the embodiments of the present disclosure, the customer party can rearrange the feature set provided by the service party using the first random ordering based on the second random ordering through the switching network. In the switching network, the input data can be blinded to hide the transmission path, and an OSN (Oblivious Switching Network) is constructed for secret sharing, so that the customer party obtains the first feature secret fragment and the service party obtains the second feature secret fragment.

[0041] Step 103, based on the intersection index, the first feature secret fragment and the second feature secret fragment, a statistical function is calculated to obtain the intersection statistical feature value of the first data set and the second data set.

[0042] In the embodiments of the present disclosure, on the basis of obtaining the intersection index and the first feature secret shard obtained by the client and the second feature secret shard obtained by the service, at least one specific statistical function calculation can be performed according to the business requirement to obtain the intersection statistical feature value corresponding to the first data set and the second data set. In the execution process, the client can obtain the feature secret shard of the corresponding bit sequence from the first feature secret shard according to the intersection index, and the service can obtain the feature secret shard of the corresponding bit sequence from the second feature secret shard according to the intersection index, and then the client and the service respectively calculate the preliminary secret statistical feature value based on the feature secret shard, and the client obtains the secret statistical feature value of the service and the local secret statistical feature value to restore the intersection statistical feature value. In the actual calculation process, the corresponding calculation steps can be simplified or increased according to the different statistical functions to obtain the corresponding intersection statistical feature value, and the embodiments of the present disclosure do not make specific limitations.

[0043] In an optional method embodiment of the present disclosure, the exchangeable encryption can be ECDH (Elliptic Curve Diffie-Hellman key Exchange) encryption, and the client and the service can negotiate a predetermined elliptic curve to perform to achieve the intersection of the anonymous privacy. On this basis, the foregoing step 101 can include the following steps A1 to A6.

[0044] Step A1, rearranging the first data set in a third random order, mapping to a predetermined elliptic curve, and encrypting based on a first private key to obtain a first encryption result.

[0045] In the client, the first data set can correspond to the description with reference to the foregoing step 101, and details are not repeated here. The client can rearrange the first data set in a third random order, so that the object description information in the rearranged first data set meets the bit sequence of the third random order, further hash processes the rearranged first data set, maps it to the foregoing predetermined elliptic curve, and encrypts the rearranged and hashed first data set using the local first private key to obtain the first encryption result.

[0046] Step A2, sending the first encryption result to the service.

[0047] In the client, the obtained first encryption result can be provided to the service.

[0048] Step A3, obtaining the second encryption result provided by the service, the second encryption result being obtained by the service by rearranging the second data set in a first random order, mapping to a predetermined elliptic curve, and encrypting based on a second private key.

[0049] At the service side, the second data set can correspond to the relevant description with reference to the foregoing step 101, and details are not repeated here. The service side can rearrange the second data set in the first random order, so that the object description information in the rearranged second data set meets the bit sequence of the first random order. Further, the rearranged second data set is hashed and mapped to the aforementioned predetermined elliptic curve, and the second data set after rearrangement and hashing is encrypted by using the local second private key to obtain a second encryption result.

[0050] At the service side, the second encryption result can be provided to the client side, and the first encryption result can be obtained from the client side.

[0051] At the client side, the second encryption result provided by the service side can be obtained to exchange the first encryption result and the second encryption result.

[0052] Step A4, rearranging the second encryption result in the second random order and encrypting based on the first private key to obtain a third encryption result, and providing the third encryption result to the service side.

[0053] At the client side, the obtained second encryption result can be rearranged in the second random order, so that the ciphertext in the second encryption result meets the bit sequence rearranged in the first random order and the second random order in turn, and the rearranged second encryption result is encrypted by using the local first private key to obtain a third encryption result.

[0054] At the client side, the third encryption result can be provided to the service side.

[0055] Step A5, obtaining the fourth encryption result provided by the service side, the fourth encryption result being obtained by rearranging the first encryption result in the fourth random order and encrypting based on the second private key by the service side.

[0056] At the service side, the obtained first encryption result can be rearranged in the fourth random order, so that the ciphertext in the first encryption result meets the bit sequence rearranged in the third random order and the fourth random order in turn, and the rearranged first encryption result is encrypted by using the local second private key to obtain a fourth encryption result.

[0057] At the service side, the fourth encryption result can be provided to the client side.

[0058] At the client side, the fourth encryption result provided by the service side can be obtained to exchange the third encryption result and the fourth encryption result.

[0059] Step A6, comparing the third encryption result and the fourth encryption result to obtain the intersection index of the intersection ciphertext in the third encryption result.

[0060] On the client's side, the third and fourth encryption results, which have been rearranged and encrypted by both parties respectively, can be compared. Based on the principle of commutative encryption, the intersection index of the intersection ciphertext in the third encryption result can be determined. This is equivalent to the index of the intersection element between the original second dataset and the original first dataset after being rearranged by the first and second random sorts. However, no plaintext data is leaked during the interaction process of steps A1 to A6.

[0061] On the service side, the third and fourth encryption results, which have been rearranged and encrypted by both parties respectively, can be compared to obtain the intersection index. To avoid duplication, this will not be elaborated here.

[0062] For example, referring to steps A1 to A6 above, assume the customer side C (Client) and service provider S (Service), Client C Holding the first dataset including n User ID; Service Provider S Holding a second dataset and feature set including n Each user identifier corresponds to a unique identifier. n Feature values, customer side C With service provider S Negotiate designated client C Obtain the intersection statistical feature values. The anonymous privacy intersection protocol is then executed as shown in Table 1 below:

[0063] Table 1

[0064]

[0065] It should be noted that some of the steps executed locally on the client and server sides in Table 1 above can be executed in parallel or sequentially. For example, the execution order of steps 1 to 4 and steps 5 to 8 is not specifically restricted between the two parties. In the anonymity and privacy intersection process shown in Table 1, the client and server sides perform double encryption on the user identifier through local computation and communication. Since ECDH encryption is a exchangeable encryption, therefore... The intersection elements are This allows for the correct output of the intersection index without exposing plaintext data. Furthermore, both the first and second datasets are rearranged twice based on random sorting, allowing the service provider to hide the original position of user identifiers from the client. When the client compares the results after the second rearrangement, they are unaware of this. The mapping relationship applies to the client side as well.

[0066] In an alternative method embodiment of the present disclosure, the aforementioned switching network can comprise control units and wires. The wires enable data exchange between the switching network and the outside world, and the data can be input into the switching network from the wires, transmitted through the paths in the switching network, and then output from the wires. In the switching network, the wires are also connected to the control units to form a topology, and the types and number of control units can be set according to actual needs. By adjusting the control units, the transmission path of the data in the switching network can be controlled.

[0067] In the switching network, each wire corresponds to a random mask generated by the service party, and the mask processing can be performed based on the random mask during data transmission. After the service party rearranges the feature set based on the first random ordering, each feature value is masked with the random mask of the corresponding wire, and is input into the corresponding wire. When the feature value after the mask processing is transmitted to the control unit through the wire, the aforementioned step 102 can specifically include the following step B.

[0068] Step B, based on the second random ordering, determines the selection bit of each control unit in turn, so that the feature value is masked according to the random mask of the selected wire in turn, and is transmitted along the selected wire in turn and output in the second random ordering, to obtain the first feature secret fragment of the ciphertext.

[0069] In the embodiment of the present disclosure, after the service party inputs the feature value after the first random ordering and the mask processing, the client party can determine the selection bit of each control unit on the transmission path based on the second random ordering, so that the feature value is transmitted along the wire pointed to by the selection bit, and is processed according to the random mask of the selected wire at each control unit. In the switching network, after being transmitted along the selected wire in turn, the feature value can be output in the second random ordering, and the first feature secret fragment of the ciphertext can be obtained based on the mask processing of the random mask. Since in the switching network, the output wire of each control unit is also the input wire of the next control unit, and the wire corresponds to a random mask, the random masks of the adjacent control units in the entire transmission path can cancel each other out; further, the input wire of the first control unit in the entire transmission path can be cancelled by the random mask of the service party performing the mask processing before inputting, and the output wire of the last control unit no longer has the input wire of the next control unit to cancel the random mask, so the first feature secret fragment is in the form of each feature value being masked with the random mask corresponding to the output wire of the last control unit, and the output bit sequence conforms to the bit sequence rearranged by the second random ordering based on the rearrangement by the first random ordering.

[0070] In an alternative method embodiment of the present disclosure, the wires include at least one unit input wire and at least one unit output wire corresponding to each control unit, and the wires also include a starting input wire and a terminal output wire.

[0071] In the embodiments of the present disclosure, each control unit can have at least one unit input wire and at least one unit output wire, which are flexibly adjusted according to the type of the control unit and the network topology. For the control units adjacent to each other and connected to each other in the network topology, the unit output wire of each control unit is also the unit input wire of the next control unit, and the unit input wire of each control unit is also the unit output wire of the previous control unit.

[0072] On this basis, the wires can also be divided into starting input wires and terminating output wires based on the way of data transmission with the outside of the switching network. The starting input wire is a wire that respectively receives the input of external data of each transmission path in the network topology, and the terminating output wire is a wire that respectively outputs data to the outside of each transmission path in the network topology. It should be noted that each starting input wire is also the unit input wire of the first control unit on the corresponding transmission path, and each terminating output wire is also the unit output wire of the last control unit on the corresponding transmission path.

[0073] After the service party rearranges the feature set based on the first random ordering, the service party respectively performs XOR operation on each feature value and the random mask corresponding to the starting input wire to determine the first mask message transmitted on the starting input wire.

[0074] In the embodiments of the present disclosure, the random mask corresponding to each wire is generated by the service party. After rearranging the feature set based on the first random ordering, the service party can determine the starting input wire corresponding to each feature value. The number of starting input wires and terminating output wires in the switching network can correspond to the number of feature values in the feature set, so that each feature value corresponds to a starting input wire. The correspondence between the feature value and the starting input wire can be determined based on the bit sequence correspondence, for example, after rearranging the feature set based on the first random ordering, the feature value with the first bit sequence corresponds to the starting input wire with the first bit sequence, the feature value with the second bit sequence corresponds to the starting input wire with the second bit sequence, and the subsequent is similar. On this basis, the service party respectively performs XOR operation on each feature value and the random mask corresponding to the starting input wire to determine the first mask message transmitted on the starting input wire.

[0075] The foregoing step B can include the following step B1 to step B3.

[0076] Step B1, for each control unit, sequentially determine the selection bit according to the second random ordering.

[0077] In the embodiments of the present disclosure, the client can determine the selection bit of each control unit in turn based on the second random sorting. For example, the feature value corresponding to the first bit sequence after the feature set is rearranged based on the first random sorting is the fifth bit sequence after the second random sorting. The client determines the selection bit of the control unit with the starting input lead of the first bit sequence as the unit input lead and the control units on the subsequent transmission path in turn, so that the unit output lead of the last control unit on the global path of the feature value is the terminating output lead of the fifth bit sequence. The selection bit of other control units can be determined in the same way. The global path includes the entire transmission path from the starting input lead to the terminating output lead.

[0078] In step B2, the second mask message transmitted on the local path composed of the unit input lead and the unit output lead is determined according to the selection bit. The second mask message is obtained by performing XOR operation on the random masks of the unit input lead and the unit output lead on the local path.

[0079] In the embodiments of the present disclosure, the local path includes the unit input lead and the unit output lead of the control unit based on the selection bit. When the unit input lead includes at least one unit input lead and at least one unit output lead, the combination of the unit input lead and the unit output lead on one local path can be determined based on the selection bit determined by the client, so as to perform XOR operation on the random mask corresponding to the unit input lead and the random mask corresponding to the unit output lead, and determine the second mask message transmitted on the local path.

[0080] In step B3, the first mask message and the second mask message transmitted on each local path are sequentially subjected to XOR operation from the starting input lead to the corresponding terminating output lead to obtain the first feature secret fragment.

[0081] In the embodiments of the present disclosure, each feature value corresponds to a global path from the starting input lead to the corresponding terminating output lead. The global path includes the first mask message provided by the server and the second mask message transmitted on the local path corresponding to each control unit. On this basis, the first mask message and the second mask message are sequentially subjected to XOR operation, and the intermediate random masks cancel each other to obtain the first feature secret fragment obtained by performing XOR operation on the feature value and the random mask corresponding to the terminating output lead.

[0082] In an optional method embodiment of the present disclosure, Figure 2 A control principle diagram of the permutation switch in the switching network is provided in the embodiments of the present disclosure. As shown in Figure 2 The control unit includes the permutation switch 200. The permutation switch 200 includes the first unit input lead 211 and the first unit output lead 212 corresponding to the bit sequence, and the second unit input lead 221 and the second unit output lead 222 corresponding to the bit sequence.

[0083] For example, when the first unit input conductor 211 corresponds to a bit sequence of one, the first unit output conductor 212 also corresponds to a bit sequence of one; when the second unit input conductor 221 corresponds to a bit sequence of two, the second unit output conductor 222 also corresponds to a bit sequence of two. The above specific bit sequences are only for illustration, and can be adjusted according to actual exchange network structure and random rearrangement requirements.

[0084] The foregoing step B1 includes the following step B11 or step B12.

[0085] The step B11 determines, based on the second random sequence, that the permutation switch is a direct connection selection bit, and causes the first unit input conductor and the first unit output conductor to form a local path, and causes the second unit input conductor and the second unit output conductor to form a local path.

[0086] In the embodiment of the present disclosure, the customer side determines, based on the second random sequence, that the permutation switch is a direct connection selection bit, and the permutation switch does not perform bit sequence switching. The first unit input conductor and the first unit output conductor form a local path, and the second mask message transmitted on the local path is obtained by exclusive-OR of the random mask of the first unit input conductor and the random mask of the first unit output conductor; the second unit input conductor and the second unit output conductor form a local path, and the second mask message transmitted on the local path is obtained by exclusive-OR of the random mask of the second unit input conductor and the random mask of the second unit output conductor.

[0087] As shown in FIG. 2, when the permutation switch is a direct connection selection bit, the first unit input conductor 211 with a bit sequence of one and the first unit output conductor 212 form a local path; the second unit input conductor 221 with a bit sequence of two and the second unit output conductor 222 form a local path. At this time, the transmission path is directly connected from the bit sequence one to the bit sequence one, and directly connected from the bit sequence two to the bit sequence two at the permutation switch 200. Figure 2

[0088] The step B12 determines, based on the second random sequence, that the permutation switch is a switching selection bit, and causes the first unit input conductor and the second unit output conductor to form a local path, and causes the second unit input conductor and the first unit output conductor to form a local path.

[0089] In the embodiment of the present disclosure, the customer side determines, based on the second random sequence, that the permutation switch is a switching selection bit, and the permutation switch performs bit sequence switching. The first unit input conductor and the second unit output conductor form a local path, and the second mask message transmitted on the local path is obtained by exclusive-OR of the random mask of the first unit input conductor and the random mask of the second unit output conductor; the second unit input conductor and the first unit output conductor form a local path, and the second mask message transmitted on the local path is obtained by exclusive-OR of the random mask of the second unit input conductor and the random mask of the first unit output conductor. ​

[0090] As Figure 2 shown, when the permutation switch is the exchange selection bit, the first unit input wire 211 with bit sequence one and the second unit output wire 222 with bit sequence two form a local path; the second unit input wire 221 with bit sequence two and the first unit output wire 212 with bit sequence one form a local path. At this time, the transmission path is exchanged from bit sequence one to bit sequence two and from bit sequence two to bit sequence one in the permutation switch 200.

[0091] In an optional method embodiment of the present disclosure, Figure 3 the control principle diagram of the multiplexer in the exchange network provided by the embodiment of the present disclosure is as shown in Figure 3 the control unit includes a multiplexer 300, and the multiplexer includes k an optional unit input wire 310 and a target unit output wire 320.

[0092] The number of the optional unit input wire 310 can be greater than one, so that k a selected local path selection is formed at the multiplexer 300. k

[0093] The foregoing step B1 includes the following step B13.

[0094] Step B13, based on the second random sequence, the multiplexer is determined to be k a selected selection bit, so that k a selected target unit input wire in the k optional unit input wire and the target unit output wire form a local path.

[0095] In the embodiment of the present disclosure, the customer party selects a target unit input wire in the k optional unit input wire of the multiplexer based on the second random sequence, to determine k a selected selection bit. On this basis, the target unit input wire and the target unit output wire form a local path, and the second mask message transmitted on the local path is obtained by exclusive-OR of the random mask of the target unit input wire and the random mask of the target unit output wire.

[0096] For example, as Figure 3 shown, the customer party selects a target unit input wire 311 in the k optional unit input wire 310 of the multiplexer 300 based on the second random sequence, to determine k a selected selection bit. At this time, the target unit input wire 311 and the target unit output wire 320 form a local path.

[0097] ​In an alternative method embodiment of the present disclosure, based on the client obtaining the first feature secret shard, the server provides a random mask corresponding to the termination output wire as the second feature secret shard.

[0098] For example, referring to the foregoing steps B1 to B3, after the anonymous privacy intersection is performed in the foregoing table 1, the oblivious exchange network protocol can be used to implement the feature rearrangement based on secret sharing, the client can provide the second random order , and the server can provide the obtained in step 6 of the foregoing table 1.

[0099]

[0100] The output in steps 5 and 6 and can be restored by arithmetic addition . Thus, the bit sequence corresponds to . In the actual execution of the foregoing table 2, a programmable, rearrangeable, and oblivious transmission calculation executable switching network such as a Benes network or a Waksman network can be selected, and the switching network can also be constructed and adjusted according to actual requirements.

[0101] For example, Figure 4 is the control flow diagram of the switching network provided by the embodiment of the present disclosure. Assuming that the provided by the server, the client rearranges the feature values using , and the order of the rearranged feature values should be . As shown in Figure 4 , the switching network includes a starting input wire , a termination output wire , a permutation switch in the switching network is represented by an oval box, and the switching selection bit or the direct connection selection bit of each permutation switch is labeled; a square box represents the corresponding starting input, and the bit sequence is rearranged after passing through each group of permutation switches, and the output is obtained after passing through the last group of permutation switches, and the output after the second random rearrangement is obtained. Based on the second random order, the global path (shown by a black line), (shown by a red line), (shown by a yellow line), (shown by a green line) can be determined. Among them, on a global path, at the direct connection selection bit, the unit input wire i and the unit output wire j have the same subscript, indicating that the bit sequences are the same; at the switching selection bit, the unit input wire i and the unit output wire jThe superscript exchange indicates the bit sequence exchange.

[0102] The global path may include the input starting wire The first mask message transmitted on the global path The second mask message transmitted on the local path The second mask message transmitted on the local path The second mask message transmitted on the local path The second mask message transmitted on the local path The second mask message transmitted on the local path The second mask message transmitted on the local path It can be seen that the local path , is the exchange selection bit, and the local path is the direct connection selection bit.

[0103] In the global path , and , and , and , and are actually the same wire, and their corresponding random masks are also the same and cancel each other out in the XOR operation, thereby performing the XOR operation of the first mask message and the second mask message .

[0104] The global path , , and so on, so that the client obtains the first feature secret fragment , and the service side obtains the second feature secret fragment .

[0105] In an optional method embodiment of the present disclosure, the statistical function includes at least one of a sum value statistical function, a mean value statistical function, a variance statistical function, a standard deviation statistical function, and an intersection potential statistical function.

[0106] In the embodiments of the present disclosure, the client can initiate the calculation of one or more statistical functions to the service, different statistical functions have corresponding calculation requirements, so that the step implementation details of the foregoing steps 101 to 103 can be adaptively adjusted. Among them, the intersection potential statistical function is used to calculate the number of intersection elements between the first data set and the second data set; and the value statistical function is used to calculate the intersection statistical sum of the corresponding feature values of the intersection elements between the first data set and the second data set; the mean statistical function is used to calculate the intersection statistical mean of each intersection element on the basis of the sum of values and the intersection potential; the variance statistical function is used to calculate the intersection statistical variance on the basis of the corresponding feature values and the mean of the intersection elements between the first data set and the second data set; and the standard deviation statistical function is used to calculate the intersection statistical standard deviation based on the arithmetic square root of the variance.

[0107] For example, the intersection potential statistical function can determine the number of intersection elements from the intersection index.

[0108] The sum value statistical function based on the intersection of the privacy set (PSI-SUM, Private Set Intersection Summation) can be statistically calculated on the basis of the first feature secret fragment obtained by the client in the foregoing table 2 and the second feature secret fragment obtained by the service, and the specific execution process can be shown in the following table 3:

[0109] Table 3

[0110]

[0111] Referring to the above table 3, the mean statistical function based on the intersection of the privacy set (PSI-MEAN) can calculate the intersection statistical mean on the basis of the intersection potential and the feature statistical sum value by using the following formula (2) :

[0112] (2)

[0113] Referring to the above table 2 and table 3, the variance statistical function based on the intersection of the privacy set (PSI-VAR, PSI-Variance) and the standard deviation statistical function (PSI-SD, PSI-Standard Deviation) can square the feature value in the execution process of table 2 Also perform the inadvertent exchange network protocol, realize the feature value square rearrangement based on secret sharing, so that the client obtains the first feature square secret fragment, and the service obtains the second feature square secret fragment. On this basis, the feature statistical variance According to the following formula (3):

[0114] (3)

[0115] and, the feature statistical standard deviation According to the following formula (4):

[0116] (4)

[0117] The method for processing private data provided by the embodiment of the present disclosure, in the scheme, the client party can use the commutative encryption to perform the intersection of private sets with the second data set of the service party based on the first data set of the local, obtain the intersection index; in the intersection of private sets, the second data set is rearranged in the first random order and the second random order by the service party and the client party in turn, and the intersection index indicates the bit sequence of the intersection ciphertext after the commutative encryption and the rearrangement of the client party in the second data set; on this basis, based on the second random order, the first feature secret fragment is obtained by the service party using the feature set rearranged in the first random order through the exchange network and the secret sharing, the service party obtains the second feature secret fragment, and the feature set corresponds to the original second data set before being rearranged in the first random order; the intersection statistical feature value of the first data set and the second data set is obtained by performing the statistical function calculation based on the intersection index, the first feature secret fragment and the second feature secret fragment. The client party and the service party holding the data can directly participate in the calculation without relying on the third party, which reduces the deployment cost and improves the deployment convenience; the intersection index is determined by the intersection of private sets of the two parties in the ciphertext state without obtaining the plaintext data of the intersection, the feature set is rearranged based on the exchange network, the service party and the client party only obtain the feature secret fragment after the rearrangement and do not obtain the plaintext data of the feature set, the feature statistical function calculation is completed safely and efficiently, and the security is further strengthened.

[0118] The following is an apparatus embodiment of the present disclosure, which can be used to execute the method embodiments of the present disclosure. For details not disclosed in the apparatus embodiment of the present disclosure, refer to the method embodiments of the present disclosure.

[0119] The example embodiments of the present disclosure further provide a processing apparatus for private data, which is applied to a client party. Specifically, refer to Figure 5As shown, the privacy data processing apparatus can include: an oblivious privacy intersection module 501, configured to perform, based on the first data set, an oblivious privacy intersection with the second data set of the service party by using commutative encryption, to obtain an intersection index; the second data set is rearranged in the service party in a first random order, and then is rearranged in the client party in a second random order; the intersection index includes a bit sequence of the intersection ciphertext after commutative encryption and client party rearrangement in the second data set; an oblivious transfer module 502, configured to perform, based on the second random order, secret sharing with the service party by using the feature set rearranged in the first random order through an exchange network, to obtain a first feature secret shard; the feature set corresponds to the original second data set; the service party obtains a second feature secret shard; and a feature statistical module 503, configured to perform statistical function calculation based on the intersection index, the first feature secret shard, and the second feature secret shard, to obtain an intersection statistical feature value of the first data set and the second data set.

[0120] In an example embodiment of the present disclosure, the exchange network includes control units and wires, and each wire corresponds to a random mask generated by a service party; after the service party rearranges the feature set based on the first random order, each feature value is respectively masked with the random mask of the corresponding wire and is input into the corresponding wire; the oblivious transfer module 502 is specifically configured to determine, based on the second random order, a selection bit of each control unit in sequence, so that the feature value is masked with the random mask of the selected wire in sequence and is output in the second random order after being transmitted along the selected wire, to obtain the first feature secret shard.

[0121] In an example embodiment of the present disclosure, the wire includes at least one unit input wire and at least one unit output wire corresponding to each control unit, and the wire further includes a starting input wire and a terminal output wire; after the service party rearranges the feature set based on the first random order, each feature value is respectively exclusive-ORed with the random mask of the corresponding starting input wire to determine a first mask message transmitted on the starting input wire; the oblivious transfer module 502 is specifically configured to determine, for each control unit, a selection bit according to the second random order in sequence; determine a second mask message transmitted on a local path composed of the unit input wire and the unit output wire according to the selection bit; the second mask message is obtained by exclusive-ORing the random masks of the unit input wire and the unit output wire on the local path; and the first mask message and the second mask message transmitted on each local path are exclusive-ORed in sequence on a global path from the starting input wire to the corresponding terminal output wire, to obtain the first feature secret shard.

[0122] In an example embodiment of the present disclosure, the control unit includes a permutation switch, the permutation switch including a first unit input wire and a first unit output wire corresponding to a bit sequence, and a second unit input wire and a second unit output wire corresponding to a bit sequence; the passive transmission module 502 is specifically configured to determine, based on the second random sequence, that the permutation switch is a direct selection bit, so that the first unit input wire and the first unit output wire form a local path, and the second unit input wire and the second unit output wire form a local path; determine, based on the second random sequence, that the permutation switch is a swap selection bit, so that the first unit input wire and the second unit output wire form a local path, and the second unit input wire and the first unit output wire form a local path.

[0123] In an example embodiment of the present disclosure, the control unit includes a multiplexer, the multiplexer including k an optional unit input wire and a target unit output wire; the passive transmission module 502 is specifically configured to determine, based on the second random sequence, that the multiplexer is k a selected selection bit, so that k an optional unit input wire in k a selected target unit input wire and the target unit output wire form a local path.

[0124] In an example embodiment of the present disclosure, the service party uses a random mask corresponding to the termination output wire as a second feature secret fragment.

[0125] In an example embodiment of the present disclosure, the anonymous privacy intersection module 501 is specifically configured to rearrange the first data set according to a third random sequence, map to a predetermined elliptic curve, and encrypt based on a first private key to obtain a first encryption result; send the first encryption result to the service party; obtain the second encryption result provided by the service party, the second encryption result being obtained by the service party by rearranging the second data set according to a first random sequence, mapping to a predetermined elliptic curve, and encrypting based on a second private key; rearrange the second encryption result according to a second random sequence and encrypt based on a first private key to obtain a third encryption result, and provide the third encryption result to the service party; obtain the fourth encryption result provided by the service party, the fourth encryption result being obtained by the service party by rearranging the first encryption result according to a fourth random sequence and encrypting based on a second private key; compare the third encryption result and the fourth encryption result to obtain the intersection index of the intersection ciphertext in the third encryption result.

[0126] In an example embodiment of the present disclosure, the statistical function includes at least one of a sum value statistical function, a mean value statistical function, a variance statistical function, a standard deviation statistical function, and an intersection potential statistical function.

[0127] The specific details of the modules in the above privacy data processing apparatus have been described in detail in the corresponding privacy data processing method, and thus will not be described here again.

[0128] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, such division is not mandatory. Indeed, according to embodiments of the disclosure, the features and functionalities of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functionalities of one module or unit described above can be further divided into embodied by multiple modules or units.

[0129] Furthermore, although the various steps of the methods in the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all of the illustrated steps must be performed to achieve the desired results. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into one step, one step can be split into multiple steps, etc.

[0130] In exemplary embodiments of the present disclosure, an electronic device capable of implementing the above method is also provided. Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, a method or a program product. Therefore, various aspects of the present disclosure can be embodied as a complete hardware embodiment, a complete software embodiment (including firmware, microcode, etc.), or an embodiment combining hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system" herein.

[0131] The electronic device 600 according to this embodiment of the present disclosure will be described below with reference to Figure 6 Figure 6 The electronic device 600 shown is merely an example and should not impose any limitation on the functions and use range of the embodiments of the present disclosure.

[0132] As shown in Figure 6 The electronic device 600 is in the form of a general computing device. The components of the electronic device 600 can include, but are not limited to, the at least one processing unit 610 described above, the at least one storage unit 620 described above, a bus 630 connecting different system components (including the storage unit 620 and the processing unit 610), and a display unit 640.

[0133] The storage unit stores program code that can be executed by the processing unit 610, so that the processing unit 610 performs the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of the present specification. For example, the processing unit 610 can execute the steps described in the above "Exemplary Method" section of the present specification. Figure 1 ​The method for processing privacy data shown in the middle.

[0134] The storage unit 620 can include a readable medium in the form of volatile storage such as random access memory (RAM) 6201 and / or cache memory 6202, and further can include a non-volatile storage such as read-only memory (ROM) 6203.

[0135] The storage unit 620 can also include a program / utility 6204 having a set (at least one) of program modules 6205, including but not limited to an operating system, one or more application programs, other program modules, and program data, each of which or a combination thereof can include an implementation of a network environment.

[0136] The bus 630 can represent one or more of several types of bus structures, including a storage bus or bus controller, a peripheral bus, an accelerated graphics port, a processor or local bus using any of a variety of bus architectures.

[0137] The electronic device 600 can also communicate with one or more external devices 700 such as a keyboard or pointing device, a Bluetooth device, etc.; other devices that enable a user to interact with the electronic device 600; and / or one or more devices that enable the electronic device 600 to communicate with one or more other computing devices. Such communication can be via the input / output (I / O) interface 650. Similarly, the electronic device 600 can communicate with one or more networks, such as a local area network (LAN), a wide area network (WAN), and / or the Internet, via the network adapter 660. As indicated above, the network adapter 660 can be communicatively coupled to the other components of the electronic device 600 via the bus 630. It will be appreciated that other hardware and / or software modules can be used in conjunction with the electronic device 600, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.

[0138] From the above description of the embodiments, those skilled in the art will readily appreciate that the example embodiments described herein can be implemented by software and / or by hardware coupled with software. Accordingly, the technical solutions of the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, etc.) or a network, and includes a number of instructions to make a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) execute the methods according to the embodiments of the present disclosure.

[0139] In exemplary embodiments of the present disclosure, a computer readable storage medium having stored thereon a program product capable of implementing the above-described methods of the present specification is also provided. In some possible implementations, various aspects of the present disclosure can also be implemented in the form of a program product including a program code that, when run on a terminal device, causes the terminal device to perform the steps described in the above "Exemplary Methods" section according to various exemplary embodiments of the present disclosure.

[0140] The program product for implementing the above-described methods according to embodiments of the present disclosure can take the form of a portable compact disc read-only memory (CD-ROM) and include a program code, and can be run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto, and in the present document, a readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0141] The program product can take any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (non-exhaustive list) of the readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0142] The computer readable signal medium can include a data signal propagated in a baseband or propagated as a carrier wave in a propagated data signal, in which a readable program code is borne. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination thereof. The readable signal medium can also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0143] The program code contained on the readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0144] Program code to implement an operation of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the user's device and partly on a remote computing device or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider.

[0145] Further, the above-described diagrams are merely schematic illustrations of processes included in the method according to the exemplary embodiments of the present disclosure, and are not intended for a limitation purpose. It is readily understood that the processes illustrated in the above-described diagrams do not indicate or limit the time sequence of the processes. In addition, it is readily understood that the processes can be executed synchronously or asynchronously, for example, in a plurality of modules.

[0146] Other embodiments of the present disclosure will be readily apparent to those skilled in the art upon considering the description herein, the drawings, and the annexed claims. The present application is intended to cover any variations, uses, or adaptations of the present disclosure following, in general, the principles of the present disclosure and including such departures from the present disclosure that come within the known and customary practice in the art to which the present disclosure pertains. The application is to be limited only by the claims specifically set forth.

Claims

1. A method of processing private data, characterized by, The privacy data processing method applied to the client side comprises: Based on the first data set, the intersection index is obtained by performing intersection operation on the second data set of the service side with exchangeable encryption; the second data set is rearranged in the first random order at the service side, and then rearranged in the second random order at the client side; the intersection index includes the bit sequence of the exchangeable encrypted intersection ciphertext of the client side after rearrangement in the second random order in the second data set; Based on the second random order, the first feature secret fragment is obtained by performing secret sharing on the feature set rearranged by the service side in the first random order through the exchange network; the feature set corresponds to the original second data set; the service side obtains the second feature secret fragment; Based on the intersection index, the first feature secret fragment and the second feature secret fragment, the intersection statistical feature value of the first data set and the second data set is obtained by performing statistical function calculation; The exchange network comprises a control unit and a wire, and each wire corresponds to a random mask generated by the service side; the wire comprises at least one unit input wire and at least one unit output wire corresponding to each control unit; After rearranging the feature set based on the first random order, the service side performs mask processing on each feature value respectively with the random mask corresponding to the wire, and inputs the corresponding wire; based on the second random order, the first feature secret fragment is obtained by performing secret sharing on the feature set rearranged by the service side in the first random order through the exchange network, which comprises: Based on the second random order, the selection bit of each control unit is determined in sequence, so that the feature value is masked in sequence according to the random mask of the selected wire, and then transmitted along the selected wire to be output in the second random order, thereby obtaining the first feature secret fragment; Wherein, based on the selection bit determined by the client side, the combination of the unit input wire and the unit output wire on a local path is determined.

2. The method of claim 1, wherein, The wire further comprises a starting input wire and a terminal output wire; After rearranging the feature set based on the first random order, the service side performs XOR operation on each feature value respectively with the random mask corresponding to the starting input wire to determine the first mask message transmitted on the starting input wire; based on the second random order, the selection bit of each control unit is determined in sequence, so that the feature value is masked in sequence according to the random mask of the selected wire, and then transmitted along the selected wire to be output in the second random order, thereby obtaining the first feature secret fragment, which comprises: The selection bit of each control unit is determined in sequence according to the second random order; According to the selection bit, the second mask message transmitted on the local path composed of the unit input wire and the unit output wire is determined; the second mask message is obtained by XOR operation of the random mask of the unit input wire and the unit output wire on the local path; XORing the first mask message and the second mask message transmitted on each of the local paths in turn obtains a first feature secret shard on a global path from the start input wire to the corresponding end output wire.

3. The method of claim 2, wherein, The control unit comprises a permutation switch, the permutation switch comprises a first unit input wire and a first unit output wire corresponding in bit sequence, and a second unit input wire and a second unit output wire corresponding in bit sequence; The method comprises: Based on the second random sequence, the permutation switch is determined to be a direct connection selection bit, the first unit input wire and the first unit output wire form the local path, and the second unit input wire and the second unit output wire form the local path. Based on the second random sequence, the permutation switch is determined to be a direct connection selection bit, the first unit input wire and the first unit output wire form the local path, and the second unit input wire and the second unit output wire form the local path.

4. The method of claim 2, wherein, The control unit comprises a multiplexer, which comprises k a bar optional unit input wire and a target unit output wire; The method comprises: determining the multiplexer to be k a selected selection bit of the selected selection bits k a selected target cell input lead of the selected target cell input leads k a selected target cell input lead of the selected target cell input leads and the target cell output lead 5. The method of claim 2, wherein, The service party takes the random mask corresponding to the end output wire as a second feature secret shard.

6. The method of claim 1, wherein, The method comprises: The first data set is rearranged according to a third random sequence, mapped to a predetermined elliptic curve, and encrypted based on a first private key to obtain a first encrypted result; The first encrypted result is sent to the service party; A second encrypted result provided by the service party is obtained, the second encrypted result being obtained by the service party by rearranging the second data set according to the first random sequence, mapping to a predetermined elliptic curve, and encrypting based on a second private key; The second encrypted result is rearranged according to the second random sequence and encrypted based on the first private key to obtain a third encrypted result, and the third encrypted result is provided to the service party; A fourth encrypted result provided by the service party is obtained, the fourth encrypted result being obtained by the service party by rearranging the first encrypted result according to a fourth random sequence and encrypting based on the second private key; The third encrypted result and the fourth encrypted result are compared to obtain an intersection index of the intersection ciphertext in the third encrypted result.

7. The method of claim 1 to 6, wherein, The statistical function comprises at least one of a sum value statistical function, a mean value statistical function, a variance statistical function, a standard deviation statistical function, and an intersection potential statistical function.

8. An apparatus for processing private data, characterized by The privacy data processing apparatus applied to a client party comprises: An anonymous privacy intersection module is configured to perform anonymous privacy intersection with a second data set of a service party based on a first data set by using commutative encryption to obtain an intersection index; the second data set is rearranged at the service party according to a first random sequence and then rearranged at the client party according to a second random sequence; the intersection index comprises a bit sequence of an intersection ciphertext of the client party after rearrangement in the second data set after commutative encryption. an oblivious transmission module configured to obtain first feature secret shares by exchanging a feature set with the service parties employing a first random permutation based on the second random permutation, wherein the feature set corresponds to the original second data set, and wherein the service parties obtain second feature secret shares; a feature statistics module configured to obtain intersection statistical feature values of the first data set and the second data set by performing statistical function calculation based on the intersection index, the first feature secret shares, and the second feature secret shares; the exchange network comprises control units and wires, and each wire corresponds to a random mask generated by a service party; each control unit corresponds to at least one unit input wire and at least one unit output wire; after the service parties rearrange the feature set based on the first random permutation, each feature value is respectively masked with the random mask corresponding to the wire and input into the corresponding wire; the oblivious transmission module is specifically configured to determine the selection bit of each control unit in sequence based on the second random permutation, so that the feature values are masked with the random mask of the selected wire in sequence, and then transmitted along the selected wire in sequence and output in the second random permutation to obtain the first feature secret shares; wherein the combination of the unit input wire and the unit output wire on a local path is determined based on the selection bit determined by the client party.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by a processor, implements the processing method of the private data according to any one of claims 1-7.

10. An electronic device, comprising: comprise: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the processing method of the private data according to any one of claims 1-7 by executing the executable instructions.

Citation Information

Patent Citations

  • Sample alignment method and device in hidden tracing federal modeling, medium and electronic equipment

    CN116684158A