Efficient secret shared database connection method based on differential privacy
By employing differential privacy technology and a random permutation protocol, the problems of duplicate connection key values and high communication overhead in existing technologies are solved, enabling efficient secret sharing connections in high-latency, low-bandwidth networks and improving privacy protection.
Patent Information
- Application Number
- CN202511205865.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2025-11-07
AI Technical Summary
Existing technologies do not support cases where the connection key of the input table has duplicate values, have a high number of communication rounds and high communication overhead, are not suitable for networks with high latency and low bandwidth, and require the leakage of specific intermediate computation information.
A secret-sharing connection protocol based on differential privacy is adopted. The data owner sorts and permutes the secret-sharing table of the input table. The server calculates the random code of the connection key and adds differential privacy noise dummy rows. The tables are joined using random permutation and extended permutation protocols to ensure privacy protection.
It supports secret shared connections with repeated connection key values, achieving constant rounds and linear communication overhead, making it suitable for high-latency, low-bandwidth networks and improving privacy protection.
Smart Images

Figure CN120915448A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of secure multi-party computation, and particularly relates to an efficient secret sharing database connection method based on differential privacy. Specifically, it is a communication-efficient secret sharing connection protocol, which allows the connection keys of two tables to have duplicate values, and realizes constant rounds and linear communication overhead by leaking the differential privacy group statistics of the connection keys of one of the servers. BACKGROUND
[0002] The proliferation of digital services has led to the large-scale collection of sensitive user data. When data from multiple organizations can be jointly analyzed, it will bring great value in many fields such as medical research, targeted advertising and financial services. However, such cross-organizational data analysis is severely hindered by legal regulations, user privacy issues and business competition.
[0003] In order to realize secure collaborative analysis, the database and cryptography field has recently focused on designing secret sharing database operator protocols based on the honest majority model. In this model, data owners secret share their input tables among three non-colluding servers, and data queryers initiate query requests, and servers execute secure protocols on secret shares. This system model ensures that three untrusted servers cannot obtain any information about the original data. This framework supports composability, efficient outsourcing computation, and designing more efficient protocols. Among various database operations, the join operator that merges two relational tables based on the connection key is widely studied due to its complexity and optimization potential. Given two tables X and Y, the join operator outputs a new table Z, where each row is the result of joining a row from table X with a row from table Y according to the join condition. The present application mainly considers the equality join operation based on the connection key.
[0004] In the process of implementing secret sharing connection, the existing method has the following problems:
[0005] 1. It does not support the case where the connection keys of the input tables have duplicate values;
[0006] 2. The number of communication rounds is high, the communication overhead is large, and the execution speed is slow under the network with high communication delay and low bandwidth;
[0007] 3. It is necessary to leak specific calculation intermediate information to one of the servers, which may not be applicable to some strong privacy application scenarios. SUMMARY
[0008] To this end, it is necessary to provide a communication efficient secret sharing database connection method. In order to achieve the above object, the present application provides a secret sharing connection protocol based on differential privacy. The protocol inputs the secret sharing table [X] of table X and the secret sharing table [Y] of table Y, and outputs the secret sharing table [Z] of table Z, wherein table Z is the connection result table of table X and table Y. The present application represents three untrusted servers as server P1, server P2 and server P3 respectively.
[0009] The present application provides a secret sharing connection method based on differential privacy, comprising the following steps:
[0010] Step 1: The data owner shares the input table X, table Y and the sorting permutation of each column in the table to the server P1, server P2 and server P3, and the three servers obtain the secret sharing table [X] and the secret sharing table [Y], wherein the server can sort the table according to the sorting permutation of any column with constant rounds and linear overhead, and the three servers sort the secret sharing table according to the connection key of the connection operator in the data query request based on the sorting permutation of the column, and use the oblivious permutation protocol to sort the secret sharing table according to the connection key column.
[0011] Step 2: The server P1 and the server P2 calculate the random encoding of the connection key. Then, two tables are added with false rows satisfying differential privacy quantity respectively. Then, the random encoding column is shuffled and sent to the server P3.
[0012] Step 3: The server P3 calculates the connection result according to the random encoding of the connection key of the two tables, and generates the extended permutation of table [X] and table [Y].
[0013] Step 4: The server P1, the server P2 and the server P3 execute the oblivious extended permutation protocol on the secret sharing table [X] and the secret sharing table [Y] according to the extended permutation, and finally obtain the permuted secret sharing table [X] and the secret sharing table [Y] by the server P1 and the server P2, which can be combined by column to obtain the secret sharing table [Z].
[0014] Unlike the prior art, the above method can realize constant rounds and linear communication overhead, and is more suitable for wide area network environment with high delay and low bandwidth. In addition, by using differential privacy technology to publish the random encoding of the connection key, the server P3 can only obtain the noise grouping information of the connection key column, thereby improving the privacy protection level.
[0015] In order to realize the step 2 of adding false rows satisfying differential privacy noise to the two tables in the secret sharing connection query method based on differential privacy, the present application provides a method for adding differential privacy noise to the secret sharing table (SPGDP M ). The method specifically comprises the following three steps:
[0016] Step 21: Indication bit addition. Server P1 and server P2 add a grouping indication bit, denoted as e, to the secret sharing table [X] and the secret sharing table [Y]. The value of e for each row is [0] if the row is the first row of the group that the connection key column belongs to, and [1] otherwise. In addition, server P1 and server P2 add a valid bit, denoted as v, to the secret sharing table [X] and the secret sharing table [Y], and set all the values of v to [1]. In addition, the random encoding of [X[k]] and [Y[k]] is stored in the new attribute column p of the secret sharing table [X] and the secret sharing table [Y]. Where [X[k]] is the attribute column k of the secret sharing table X.
[0017] Step 22: Perturb the number of groups of the connection key of the secret sharing table [X] and the secret sharing table [Y]. For the secret sharing table [X], server P1 samples Δ differentially private noises η1, …, η Δ and sends them to server P2, where Δ is the sensitivity of the connection query. Then, for each noise value η i , server P1 and server P2 generate η i random rows, for each row, copy it i times and add it to the secret sharing table [X], 1 time and add it to the secret sharing table [Y]. In addition, for each fake row, set its v value to [0]. If the fake row is the first row of the group it belongs to, set the e value of the row to [0], otherwise, set it to [1]. Server P1 and server P2 perform similar operations on the secret sharing table [Y].
[0018] Step 23: Perturb the size of each group of the connection key of the secret sharing table [X] and the secret sharing table [Y]. For each row of the secret sharing table [X], server P1 samples a differentially private noise η and sends it to server P2. Then, they copy the row η times, and store the resulting rows in a new temporary table, which has the same structure as the secret sharing table [X]. Server P1 and server P2 randomize each row of the temporary table using the grouping indication bit e. That is, if the indication bit is equal to [1], the row will be set to a random value. Set the v value of each row in the temporary table to [0]. Then, set the e value of the grouping indication bit in the secret sharing table [X] to [0], and merge the temporary table and the secret sharing table [X] row by row to obtain the updated secret sharing table [X]. P1 and P2 perform similar operations on the secret sharing table [Y].
[0019] Step 24: Server P1 and server P2 send the column corresponding to the random encoding of the connection key and the group indication bit e to server P3. After receiving the data, server P3 obtains the plaintext of the random encoding and the group indication bit e column, deletes all the rows with the group indication bit being 1, and the remaining group distribution of the connection key satisfies differential privacy. Since the rows with the group indication bit being 1 are all random values, and the remaining rows are all random encoding, except for the differential privacy group distribution information of the connection keys of table X and table Y, no information is leaked to server P3.
[0020] Further optimization of the technical solution, in step 2, a false row satisfying differential privacy noise is added to each of the two tables, and a differential privacy noise algorithm is added to the secret sharing table.
[0021] Further optimization of the technical solution, step 3 is to calculate the connection permutation by server P3. Server P3 adds an attribute πX and πY to table X and table Y respectively, wherein the value of πX and πY is equal to the serial number of the row, and then server P3 deletes the corresponding row with e value equal to 1. Finally, server P3 calculates the plaintext connection according to the random encoding value, and the result table is represented as table Z. Then πX and πY in table Z are the extended permutation of the result table.
[0022] Further optimization of the technical solution, step 4 is to obtain the connection result by server P1 and server P2. Server P1, server P2 and server P3 respectively perform extended permutation on secret sharing table [X] and secret sharing table [Y] according to πX and πY, and then combine the permuted secret sharing table [X] and secret sharing table [Y] by column to obtain secret sharing connection table [Z].
[0023] Further optimization of the technical solution, in step 1, the implementation of the random permutation protocol is that server P1, server P2 and server P3 have secret sharing table [X] and secret sharing permutation [π]; server P1, server P and server P3 shuffle secret sharing table [X] and secret sharing permutation [π] according to the same random order, and publicly disclose the result of π, which is represented as π'; then server P1, server P2 and server P3 use π' to permute secret sharing table [X] to obtain the permutation result of secret sharing table [X] according to secret sharing permutation [π].
[0024] Further optimization of the technical solution, in step 4, the implementation of the random extended permutation protocol is that server P3 has permutation π, server P1 and server P2 have secret sharing table [X],
[0025] (1) Server P3 generates permutation π1, which satisfies that if π maps an input position i to k output positions, there exists a j such that π1(j) = i, and Where image (pi) is all the non-repeated values in pi, then the server P1, the server P2 and the server P3 permute the secret sharing table [X] according to pi1; specifically, the server P3 generates a random permutation pi', and calculates to obtain pi" such that pi1=pi'·pi", the server P2 sends the share of the secret sharing table [X] to the server P3, the server P3 permutes the share according to pi, then the server P3 sends pi' to the server P1, and sends pi" to the server P2, the server P1 permutes the share of the secret sharing table [X] according to pi', and randomizes sending to the server P2, the latter further permutes the result according to pi", and obtains the result that the server P2 and the server P3 obtain the secret sharing table [X] permuted according to pi1;
[0026] (2) The server P3 generates pi2, which recovers the values in pi1 according to pi, that is, finds the position j in pi1, and then copies the value of the position j from the jth position to the kth position, and the server P1, the server P2 and the server P3 jointly complete the copying operation required by pi2;
[0027] (3) The server P3 generates a permutation pi3, such that the result of (2) after permutation pi3 is equal to the result of the secret sharing table [X] after permutation pi, and the server P1, the server P2 and the server P3 perform the permutation pi3, and the specific permutation method is the same as that of (1).
[0028] Different from the prior art, the above technical solution has the following beneficial effects:
[0029] 1. Support for secret sharing join operators with repeated values in both table join keys.
[0030] 2. The protocol has constant rounds and linear computation and communication overhead, and is suitable for networks with high delay and limited bandwidth.
[0031] 3. Controlled privacy leakage is achieved, and differential privacy is used to protect the grouped data. BRIEF DESCRIPTION OF DRAWINGS
[0032] Figure 1 It is a system model diagram of a secret sharing database;
[0033] Figure 2 It is a flowchart of an efficient secret sharing database join method based on differential privacy.
[0034] Figure 3 It is a flowchart of adding differential privacy noise to a secret sharing data table. DETAILED DESCRIPTION
[0035] In order to describe the technical content, structural features, purposes and effects of the technical solutions in detail, the following will be described in detail in combination with specific embodiments and with reference to the drawings.
[0036] The terms related to the patent are defined as follows:
[0037] Secret sharing: a method of splitting sensitive information into several sub-portions, each of which is held by a participant. The sub-portion is called a secret share, and only when the preset participant set is met can the original information be reconstructed. The definition table X is the plaintext table, and after secret sharing, it is represented as secret sharing table [X]. Similarly, for any value a, after secret sharing, it is represented as [a].
[0038] Random encoding: used to encode input values into output representations with randomness, thereby hiding all information of the input data and only retaining the output value. Among them, the same input will produce the same random output.
[0039] Blind permutation protocol: a data permutation protocol that supports one-to-one index mapping, the key of which is to ensure that the permutation process maintains input and output privacy for each participant. Blind extended permutation protocol is an extension of the blind permutation protocol, which supports one-to-many index mapping.
[0040] Truncated Laplace mechanism: the mechanism is represented as TLap(ε,δ,Δ). Given a query c:D→N, the mechanism adds a non-negative number max(η,0) to the query result. Where, the distribution of η is represented as L(ε,δ,Δ), and its probability density function is:
[0041]
[0042] Where, ε,δ are the privacy budget of differential privacy, Δ is the query sensitivity, D is the input database, N is an integer, and max(η,0) represents the maximum of η and 0.
[0043] Referring to Figure 1 The system model diagram of the secret sharing database is shown in the figure. The use process of a complete secret sharing database includes:
[0044] 1. Data table sharing and initiating query request. Multiple data owners secret share their data tables to three servers, which do not collude with each other and are in a semi-honest model, that is, they will honestly execute the protocol, but try to obtain privacy information from the messages of the protocol. The data analyst provides a query request to the server, which is in the form of a relational database query statement.
[0045] 2. Query protocol execution. The three servers execute the query protocol on the secret sharing data table to obtain the secret shares of the query result.
[0046] 3. Query result returns. The three servers send secret shares to the data analyst. The data analyst combines the received secret shares to obtain the final query result.
[0047] When the data analyst provides a query request containing a join operator to the servers, the present application provides an efficient secret sharing database join method based on differential privacy. The join method can combine other secret sharing database operator protocols to jointly implement the query request of the data analyst.
[0048] Referring to Figure 2 FIG. 1 shows a flowchart of an efficient secret sharing database join method based on differential privacy. The join protocol proposed by the present application is mainly applied to the "query protocol execution" in the process of using the secret sharing database. In addition, the "data table sharing and initiating a query request" is modified to some extent, so that the data owner additionally shares the related information of the data table. Specifically, the present application uses an efficient secret sharing join method based on differential privacy. Step 1 of the method implements the "data table sharing and initiating a query request" in the process of using the secret sharing database; steps 2, 3, and 4 implement the "query protocol execution" in the process of using the secret sharing database.
[0049] Step 1: Data sharing and initiating a query request: The data owner secretly shares the table X, the table Y, and the ordering permutation of each column in the table to the server P1, the server P2, and the server P3. After receiving the query request from the data analyst (the query contains a join operation), the server P1, the server P2, and the server P3 respectively perform the oblivious permutation protocol on the secret sharing table [X] and the secret sharing table [Y] according to the ordering permutation corresponding to the join key column, to obtain the secret sharing table [X] and the secret sharing table [Y] sorted according to the join key.
[0050] Step 2: The server P1 and the server P2 calculate the random encoding of the join key of the secret sharing table [X] and the secret sharing table [Y]. Then, the server P1 and the server P2 add fake rows to the secret sharing table [X] and the secret sharing table [Y] to make the grouped data of the random encoding satisfy differential privacy. Then, they send the random encoding and the corresponding grouping indication bits to the server P3.
[0051] In order to add fake rows to the secret sharing table [X] and the secret sharing table [Y] to satisfy differential privacy in step 2, the present application provides a grouped data publishing algorithm based on differential privacy (Privacy-Preserving Grouped Data Publishing with Sensitivity-Based Padding Algorithm, abbreviated as SPGDP). By adding fake rows according to the algorithm, the published random encoding grouped data can satisfy differential privacy.
[0052] The randomly encoded grouped data of the join key contains two pieces of information, the number of groups and the size of each group. The sensitivity of the query for the number of groups is 1. The sensitivity of the query for the size of each group of the result table is the maximum frequency of the join key in table X or table Y, which is equal to the sensitivity of the join query, Δ. SPGDP uses the truncated Laplace mechanism to add positive noise to the grouped data, and proposes a data padding strategy based on the sensitivity Δ to reduce the total amount of noise.
[0053] The SPGDP algorithm is divided into two steps:
[0054] 1. Noise addition for the number of groups: two noise values are sampled from the truncated Laplace mechanism TLap(ε, δ, 1) with sensitivity 1, and a number of virtual rows with unique keys are generated, where (ε, δ) is the privacy budget. The first number of virtual rows is added to table X, and the remaining virtual rows are added to table Y. In addition, it is assumed that the join key k in table Y is not unique. Consider the worst case, assume that table X' is a neighboring table of table X, that is, it contains one additional row than table X, and the join key of X' does not match any key in table X, but matches exactly i rows in table Y, where 1≤i≤Δ, Δ is the maximum frequency of the join key in table X or table Y. In this case, the generated join table Z' (i.e., the join of table X' and table Y) will contain one more group than table Z (i.e., the join of table X and table Y). This extra group will take the form of 1×i blocks, containing one row from table X' and i matching rows from table Y. The present invention fills tables X and Y by generating virtual groups also in the form of 1×i, the number of which is sampled from the truncated Laplace mechanism TLap(ε, δ, 1) with sensitivity 1.
[0055] 2. Noise addition for the size of each group: the first step fills tables X and Y according to the sensitivity Δ, supporting the sensitivity of each group size query to be only 1. Therefore, for each group, a noise is sampled from the truncated Laplace mechanism TLap(ε, δ, 1) with sensitivity 1, and the join key of the group is copied the same number of times as the sampled noise.
[0056] The SPGDP algorithm requires adding noise to the data in a grouped manner. However, since the server does not know which rows of the secret shared table belong to a group, it cannot directly implement the noise addition described in the SPGDP algorithm. The present invention proposes a multi-party grouped data publishing protocol based on differential privacy (Privacy-Preserving Grouped Data Publishing with Sensitivity-Based Padding Protocol, abbreviated as SPGDPM This protocol is used to indiscriminately add noise conforming to the SPGDP algorithm to a secret shared data table, ensuring that the randomly encoded grouped data of the join key satisfies differential privacy. The protocol consists of three steps; see [link to relevant documentation]. Figure 3 As shown.
[0057] Step 21: Add indicator bits. P1, P2, and P3 reshare the data to P1 and P2. P1 and P2 add group indicator bits e and valid bits v to the secret sharing table [X] and secret sharing table [Y], and calculate the random encoding value of the connection key and store it in the new attribute p. Among them, the valid bits are all set to v as [1], the first row indicator bit e of the connection key group is set to [0], and the rest are set to [1].
[0058] Step 22: Servers P1 and P2 add noise to the number of groups in the join key columns of the secret shared table [X] and secret shared table [Y]. Servers P1 and P2 sample two noise values η from TLap(ε,δ,1). x ,η y Then, generate η. x +η y 1 random row. The first η rows... x One row is added to the secret shared table [X], and the remaining rows are added to the secret shared table [Y]. Next, for the secret shared table [X], for i ∈ [Δ], servers P1 and P2 sample noise from TLap(ε,δ,1) and generate 1×i virtual groups of that noise, adding them to the secret shared table [X] and the secret shared table [Y]. Specifically, Δ noises are sampled, denoted as η1,…,η Δ Then, for each noise value η i Servers P1 and P2 generate η i Each row contains a set of random values for all attributes. For each row, it is copied i times and added to the secret shared table [X], and once and added to the secret shared table [Y]. Servers P1 and P2 set the group indicator bits in the virtual groups according to the group settings, setting the first row of each group to [0], otherwise setting it to [1]. Then, all valid bits of the rows in these virtual groups are set to [0]. Servers P1 and P2 perform the same operation on the secret shared table [Y].
[0059] Step 23: Server P1 and Server P2 add noise to the group size of the join key column of the secret sharing table [X], secret sharing table [Y]. For each row in the table, sample noise from TLap(ε, δ, 1), duplicate the noise number of times, and randomize each row of the table according to the group indication bit. That is, when the row indication bit is [1], it is randomized to an invalid row. Then, set all the group indication bits e in the original table to [0], and set all the valid bits v of the duplicated rows to [0]. Merge the duplicated data with the original table data to obtain the expanded secret sharing table [X], secret sharing table [Y].
[0060] Finally, Server P1 and Server P2 randomly shuffle the secret sharing table [X] and secret sharing table [Y], and send the columns corresponding to the random encoding attribute p and the group indication bit e to Server P3.
[0061] Step 3: Server P3 calculates the join permutation. Server P3 obtains the plaintext of the random encoding attribute p and the group indication bit e column of table X and table Y. Add an attribute πX and πY to table X and table Y respectively. The value of πX and πY is equal to the serial number of the row. Then Server P3 deletes the corresponding row whose e value is equal to 1. Server P3 finally calculates the plaintext join according to the random encoding value of table X and table Y. The result table is denoted as table Z, then πX and πY in table Z are the extended permutations of secret sharing table [X], secret sharing table [Y] respectively.
[0062] Step 4: Server P1, Server P2 get the join result. Server P1, Server P2 and Server P3 perform the oblivious extended permutation protocol, and respectively permute secret sharing table [X], secret sharing table [Y] according to πX, πY. The permuted secret sharing table [X], secret sharing table [Y] are combined by column to obtain secret sharing table [Z].
[0063] If there are other operations after the join operation, such as group aggregation, Server P1, Server P2 and Server P3 continue to perform calculations on secret sharing table [Z]. When all the operators of the query are executed, the secret sharing of the result is returned to the data analyst. The data analyst combines the secret sharing result to obtain the final query result.
[0064] In the above step 1, the implementation of the oblivious permutation protocol is as follows: the server P1, the server P2 and the server P3 possess the secret sharing table [X] and the secret sharing permutation [π] (one-to-many index). The server P1, the server P2 and the server P3 shuffle the secret sharing table [X] and the secret sharing permutation [π] according to the same random order, and disclose the result of [π], denoted as π'. Then the server P1, the server P2 and the server P3 permute the secret sharing table [X] using π', obtaining the result of the permutation of the secret sharing table [X] according to the secret sharing permutation [π].
[0065] In the above step 4, the implementation of the oblivious permutation protocol is as follows: the server P3 possesses the permutation π (one-to-many index), and the server P1 and the server P2 possess the secret sharing table [X].
[0066] (1) The server P3 generates a permutation π1, which satisfies that if π maps an input position i to k output positions, there exists a j such that π1(j) = i, and {π1(j+1),..., π1(j+k-1)}∩image(π) = φ, where image(π) is all the non-repeated values in π, and then the server P1, the server P2 and the server P3 permute the secret sharing table [X] according to π1; specifically, the server P3 generates a random permutation π' and calculates π" such that π1=π'·π", the server P2 sends the share of the secret sharing table [X] to the server P3, the server P3 permutes the share according to π, then the server P3 sends π' to the server P1 and π" to the server P2, the server P1 permutes the share of the secret sharing table [X] according to π' and randomizes it and sends it to the server P2, and the server P2 further permutes the result according to π", obtaining the result of the permutation of the secret sharing table [X] according to π1by the server P2 and the server P3;
[0067] (2) The server P3 generates π2, which recovers the values in π1according to π, i.e. finding the position j in π1, and then copying the value of the position j from the j-th position to the k-th position successively, and the server P1, the server P2 and the server P3 jointly complete the copying operation required by π2;
[0068] (3) The server P3 generates a permutation π3, such that the result of (2) after the permutation π3 is equal to the result of the permutation of the secret sharing table [X] according to π, and the server P1, the server P2 and the server P3 perform the permutation π3, and the specific permutation method is the same as that in (1).
[0069] It is to be noted that, in the present text, terms such as first and second, and the like, merely serve to identify a difference between one entity or action and another entity or action, and do not necessarily require or imply that there is any such actual relationship or order between these entities or actions. Moreover, the terms "comprising", "including", or any other variant thereof are intended to cover a non-exclusive inclusion, such that processes, methods, articles, or apparatuses that comprise a list of elements are not required to comprise only those elements, but can include other elements not expressly listed or inherent to such processes, methods, articles, or apparatuses. Without further limitation, an element preceded by "comprises a" or "comprises" does not, without more limitations, preclude the existence of further elements of the process, method, article, or apparatus that includes the element. Furthermore, in the present text, "greater than", "less than", "exceed", and the like are understood to exclude the number itself; "and above", "and below", "and within", and the like are understood to include the number itself.
[0070] Although the above-mentioned embodiments have been described, those skilled in the art can make further changes and modifications to these embodiments once they know the basic inventive concept, so the above description is only for the embodiments of the present application, and does not limit the patent protection scope of the present application, and any equivalent structure or equivalent process transformation using the content of the present application specification and drawings, or direct or indirect application in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. An efficient secret sharing database connection method based on differential privacy, characterized in that, The method comprises the following steps. Step 1: the data owner performs secret sharing of an input table X, a table Y and an order permutation of each column in the table to servers P1, P2 and P3, and the three servers obtain secret sharing table [X] and secret sharing table [Y], wherein the servers can sort the table according to the order permutation of any column with constant rounds and linear overhead, and the three servers sort the secret sharing table according to the connection key column of the secret sharing table using a oblivious permutation protocol based on the order permutation of the column according to the connection operator in the data query request; Step 2: the servers P1 and P2 calculate random encoding of the connection key of the secret sharing table [X] and the secret sharing table [Y], then add false rows satisfying differential privacy noise to the two tables respectively, and then shuffle the random encoding columns and send them to the server P3; Step 3: the server P3 generates an extended permutation of the secret sharing table [X] and the secret sharing table [Y] according to the random encoding of the connection key of the two tables; Step 4: the servers P1 and P2 obtain a connection result, the servers P1, P2 and P3 perform an oblivious extended permutation protocol to obtain an extended permutation result of the secret sharing table [X] and the secret sharing table [Y], combine the extended permutation result according to columns, and obtain a secret sharing table [Z].
2. The differentially privacy based efficient secret sharing database connection method of claim 1, wherein, In the step 2, the false rows satisfying differential privacy noise are added to the two tables respectively by using a secret sharing table differential privacy noise adding algorithm.
3. The differentially privacy based efficient secret sharing database connection method of claim 2, wherein, The secret sharing table differential privacy noise adding algorithm comprises the following steps. Step 21: indication bit adding, the servers P1 and P2 add a grouping indication bit e to the secret sharing table [X] and the secret sharing table [Y], the value of e of each row is [0] only when the row belongs to the first row of the connection key column grouping, and the value of e of other rows is [1], in addition, the servers P1 and P2 add a valid bit v to the secret sharing table [X] and the secret sharing table [Y], and the value of v is set to [1] in total, in addition, the random encoding of [x[k]] and [Y[k]] is stored in a new attribute column p of the secret sharing table [X] and the secret sharing table [Y], wherein X[k] is the connection key column k of the table X; Step 22: perturb the number of groups of the join key of the secret sharing table [X] and the secret sharing table [Y], for the secret sharing table [X], the server P1 samples Δ differentially private noises η1,…,η Δ and sends them to the server P2, where Δ is the sensitivity of the join query, then, for each noise value η i , the server P1 and the server P2 generate η i random rows, for each row, copy it i times and add it to the secret sharing table [X], 1 time and add it to the secret sharing table [Y], in addition, for each fake row, set its v value equal to [0], if the fake row is the first row of the group it belongs to, set the e value of the row to [0], otherwise, set it to [1], for the secret sharing table [Y], the server P1 and the server P2 perform similar operations; Step 23: perturbing the size of each group of the connection key of the secret sharing table [X] and the secret sharing table [Y], for each row of the secret sharing table [X], the server P1 samples differential privacy noise η and sends it to the server P2, then they copy the row η times, store the result rows in a new temporary table, and the structure of the temporary table is the same as that of the secret sharing table [X], the servers P1 and P2 randomize each row of the temporary table using the grouping indication bit e, that is, if the indication bit is equal to [1], the row will be set to a random value, the value of v of each row in the temporary table is set to [0], then the value of the grouping indication bit e in the secret sharing table [X] is set to [0], and the temporary table and the secret sharing table [X] are combined by rows to obtain the final secret sharing table [X], and P1 and P2 perform similar operations on the secret sharing table [Y]. Step 24: Server P1 and server P2 send the column corresponding to the random encoding of the connection key and the group indication bit e of server P3, after receiving the data, server P3 deletes all rows with group indication bit 1, and the remaining group distribution of the connection key meets differential privacy, since the rows with group indication bit 1 are all random values, and the remaining rows are all random encoding, therefore, except for the differential privacy group distribution information of the connection key column of table X and table Y, no information will be leaked to server P3.
4. The differentially privacy based efficient secret sharing database connection method of claim 3, wherein, The step 3 is to calculate the connection permutation of server P3, server P3 adds an attribute πX and πY to table X and table Y respectively, wherein the value of πX and πY is equal to the serial number of the row, then server P3 deletes the corresponding row with e value equal to 1, and server P3 finally calculates the plaintext connection according to the random encoding value, and the result table is represented as table Z, then πX and πY in table Z are the extended permutation of the result table.
5. The differentially privacy based efficient secret sharing database connection method of claim 4, wherein, The step 4 is to obtain the connection result of server P1 and server P2, server P1, server P2 and server P3 respectively perform extended permutation on secret sharing table [X] and secret sharing table [Y] according to πX and πY, and then combine the permuted secret sharing table [X] and secret sharing table [Y] by column to obtain secret sharing connection table [Z].
6. The differentially private, efficient, secret sharing database join method of claim 1, wherein, In the step 1, the implementation of the dazed permutation protocol is that: server P1, server P2 and server P3 have secret sharing table [X] and secret sharing permutation [π]; server P1, server P2 and server P3 shuffle secret sharing table [X] and secret sharing permutation [π] according to the same random order, and publicly disclose the result of [π], which is represented as π'; then server P1, server P2 and server P3 use π' to permute secret sharing table [X] to obtain the permutation result of secret sharing table [X] according to secret sharing permutation [π].
7. The differentially private, efficient, secret sharing database join method of claim 1, wherein, In the step 4, the implementation of the dazed extended permutation protocol is that: server P3 has permutation π, server P1 and server P2 have secret sharing table [X], (1) Server P3 generates a permutation π1, which satisfies that if π maps an input position i to k output positions, then there exists a j such that π1(j) = i, and where image(π) is all non-repeated values in π, then server P1, server P2 and server P3 permute the secret sharing table [X] according to π1; specifically, server P3 generates a random permutation π' and calculates π" such that π1=π'·π", server P2 sends the share of the secret sharing table [X] to server P3, server P3 permutes the share according to π, then server P3 sends π' to server P1 and π" to server P2, server P1 permutes the share of the secret sharing table [X] according to π' and randomizes and sends to server P2, the latter further permutes the result according to π" to obtain the final result that server P2 and server P3 obtain the secret sharing table [X] permuted according to π1; (2) server P3 generates π2, which restores the value in π1 according to π, that is, finds the position j in π1, and then copies the value of position j from j to the next k positions, and server P1, server P2 and server P3 complete the copying operation required by π2 together; (3) server P3 generates permutation π3, so that the result of (2) after permutation π3 is equal to the result of secret sharing table [X] after permutation π, and server P1, server P2 and server P3 perform permutation π3, and the specific permutation method is the same as (1).