WO2022237103A1 - 一种隐私求并集方法及装置 - Google Patents
一种隐私求并集方法及装置 Download PDFInfo
- Publication number
- WO2022237103A1 WO2022237103A1 PCT/CN2021/130448 CN2021130448W WO2022237103A1 WO 2022237103 A1 WO2022237103 A1 WO 2022237103A1 CN 2021130448 W CN2021130448 W CN 2021130448W WO 2022237103 A1 WO2022237103 A1 WO 2022237103A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- participant
- tuple
- commitment
- preset
- information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
Definitions
- the present invention relates to financial technology (Fintech), in particular to a privacy union method and device.
- the privacy union means that each participant has a set, and the participant can obtain the set intersection of all participants after going through the privacy union algorithm, but does not know any other participants except the union and its own set
- the content of the set realizes the effect of protecting the privacy of the set content of the participants in the process of union.
- there is currently no private method for union which is an urgent problem to be solved.
- the invention provides a method and device for obtaining a union of privacy, which solves the problem that there is no method for obtaining a union of privacy in the prior art.
- the present invention provides a privacy union method, including: a first participant generates a first set of judgment rules; the judgment rules correspond to multiple sub-items, and the multiple sub-items are used to determine the judgment rules , the judging rule is used to judge whether any element is an element in the first set;
- the first participant For any subitem of the plurality of subitems, the first participant generates a commitment for the subitem according to a preset commitment algorithm based on the private key and the first confusion information of the subitem; the preset commitment The algorithm has homomorphism, and the commitments of the multiple subitems are used by the second participant to generate at least one tuple;
- the first participant obtains the at least one tuple from the second participant; for any tuple in the at least one tuple, the tuple represents a corresponding element in the second set, the The tuple is the commitment of the second participant according to the element corresponding to the tuple in the second set, the element corresponding to the tuple in the second set, the commitment of the tuple in the second set
- the second obfuscation information of the corresponding element is obtained according to the preset commitment algorithm;
- the first participant obtains elements in the second set other than the first set according to the private key and the at least one tuple, and according to the first set and the second set elements other than the first set, obtain the union of the first set and the second set.
- the judgment rule corresponds to the commitment of multiple sub-items for the second participant to generate at least one tuple, and any tuple in the at least one tuple represents that in the second elements corresponding to the set, the first participant only obtains elements in the second set other than the first set according to the private key and the at least one tuple, but does not know the elements of the first set Which elements are specifically included in the two sets, so that the union of the first set and the second set is obtained, and the multi-party privacy union is realized.
- the elements in the first set are all positive integers
- the judgment rule is a polynomial
- the multiple sub-items are the coefficients of each sub-term of the polynomial
- the preset commitment algorithm is a preset elliptic curve Algorithm
- the preset elliptic curve algorithm corresponds to the first base point, the second base point and the commitment public key
- the commitment public key is obtained according to the private key and the second base point
- the first participant generates a commitment for the subitem according to the private key and the first obfuscation information of the subitem according to a preset commitment algorithm, including:
- the first participant According to the private key, the first obfuscation information of the subitem, the first base point, the second base point, and the commitment public key, the first participant generates The promise of the subkey.
- the elements in the first set are all positive integers, and when the judgment rule is a polynomial, since the preset elliptic curve algorithm has a small amount of calculation and high security performance, the sub-items can be enhanced The generation efficiency of commitments.
- the first participant uses the following formula, according to the private key, the first confusion information of the subitem, the first base point, the second base point, and the commitment public key, according to the The above preset elliptic curve algorithm, generating the commitment of the child:
- x is the sub-item
- E(x) is the commitment of the sub-item
- G1 is the first base point
- G2 is the second base point
- r1 is the first confusion information of the sub-item
- H is the The above-mentioned commitment public key
- sk is the above-mentioned private key.
- the tuple includes a first subpart and a second subpart;
- the first subpart is the commitment of the second participant according to the element corresponding to the tuple in the second set, the element corresponding to the tuple in the second set, and the tuple in the second set.
- the second confusion information of the elements corresponding to the second set is obtained according to the preset commitment algorithm;
- the second subpart is the commitment of the second participant to the element corresponding to the tuple in the second set and the second confusion information of the element corresponding to the tuple in the second set, according to obtained by the preset commitment algorithm.
- both the first sub-part and the second sub-part in the tuple use the commitment of the second participant according to the element corresponding to the tuple in the second set, the tuple in the The second confusion information of the elements corresponding to the second set, and the first sub-part uses the elements corresponding to the tuple in the second set, so the two sub-parts of the tuple can put the tuple in the The corresponding elements of the second set are implicitly included.
- the first participant obtains elements in the second set other than the first set according to the private key and the at least one tuple, including:
- the first participant obtains the denominator analysis item and the numerator of the tuple according to the first subpart of the tuple and the second subpart of the tuple Parse item;
- the first participant and the second participant are on the same block chain, and the method further includes: the first participant sends commitments of the plurality of subitems to the block On the chain: the commitment of the plurality of subitems is used by the second participant to obtain from the blockchain.
- the first participant sends the commitments of the multiple subitems to the blockchain, so that there is no need to frequently send the commitments of the multiple subitems, even if the second participant needs to acquire multiple times, It can also be obtained directly from the block chain, thereby improving the efficiency of obtaining the commitments of the multiple subitems.
- the first participant is any one of multiple participants, and the first participant obtains the private key in the following manner:
- the first participant obtains the fragmentation homomorphism information of at least one participant through a preset privacy interaction protocol according to the fragmentation homomorphism information of the first participant, wherein the fragmentation homomorphism information of any participant
- the information is obtained according to the preset homomorphic encryption operation according to the shard key of the participant; the at least one participant is a participant of the plurality of participants except the first participant;
- the first participant acquires the private key according to the preset homomorphic encryption operation according to the fragment homomorphic information of the first participant and the fragment homomorphic information of the at least one participant.
- the first participant can The fragmented homomorphic information of each party, through the preset privacy interaction protocol, obtains the fragmented homomorphic information of at least one participant, so as to jointly obtain the private key through a joint method, avoiding a single participant from doing evil, and improving the privacy of the union. safety.
- the present invention provides a privacy union device, including:
- a generating module configured to generate a judgment rule of the first set; the judgment rule corresponds to a plurality of subitems, and the plurality of subitems are used to determine the judgment rule, and the judgment rule is used to judge whether any element is the first elements of a set;
- the preset commitment algorithm has the same Stateful, the commitment of the plurality of subitems is used by the second participant to generate at least one tuple;
- An acquisition module configured to acquire the at least one tuple from the second participant; for any tuple in the at least one tuple, the tuple represents the corresponding element in the second set, and the tuple
- the group is the second participant’s commitment according to the element corresponding to the tuple in the second set, the element corresponding to the tuple in the second set, and the commitment of the element corresponding to the tuple in the second set
- the second obfuscation information of the element is obtained according to the preset commitment algorithm;
- the elements in the first set are all positive integers
- the judgment rule is a polynomial
- the multiple sub-items are the coefficients of each sub-term of the polynomial
- the preset commitment algorithm is a preset elliptic curve Algorithm
- the preset elliptic curve algorithm corresponds to the first base point, the second base point and the commitment public key
- the commitment public key is obtained according to the private key and the second base point
- the generating module is specifically used for:
- the first confusion information of the subitem, the first base point, the second base point, and the commitment public key According to the private key, the first confusion information of the subitem, the first base point, the second base point, and the commitment public key, according to the preset elliptic curve algorithm, generate the commitment of the subitem .
- the generation module is specifically configured to: according to the following formula, according to the private key, the first obfuscation information of the subitem, the first base point, the second base point, and the commitment public key, According to the preset elliptic curve algorithm, generate the commitment of the child:
- x is the sub-item
- E(x) is the commitment of the sub-item
- G1 is the first base point
- G2 is the second base point
- r1 is the first confusion information of the sub-item
- H is the The above-mentioned commitment public key
- sk is the above-mentioned private key.
- the tuple includes a first subpart and a second subpart;
- the first subpart is the commitment of the second participant according to the element corresponding to the tuple in the second set, the element corresponding to the tuple in the second set, and the tuple in the second set.
- the second confusion information of the elements corresponding to the second set is obtained according to the preset commitment algorithm;
- the second subpart is the commitment of the second participant to the element corresponding to the tuple in the second set and the second confusion information of the element corresponding to the tuple in the second set, according to obtained by the preset commitment algorithm.
- the acquiring module is specifically used for:
- any tuple in the at least one tuple according to the first subpart of the tuple and the second subpart of the tuple, obtain the denominator analysis item and the numerator analysis item of the tuple;
- the device is executed by the first participant, and the first participant and the second participant are on the same block chain, and the device also includes a sending module, and the sending module specifically uses In: sending the commitments of the multiple subitems to the blockchain; the commitments of the multiple subitems are used by the second participant to obtain from the blockchain.
- the device is a device executed by a first participant, and the first participant is any one of multiple participants, and the acquisition module specifically acquires the private key in the following manner:
- the sharding homomorphic information of the first participant is obtained through a preset privacy interaction protocol, wherein the sharding homomorphic information of any participant is based on the participant
- the shard key is obtained according to the preset homomorphic encryption operation; the at least one participant is a participant of the plurality of participants except the first participant;
- the private key is obtained according to the preset homomorphic encryption operation according to the fragment homomorphic information of the first participant and the fragment homomorphic information of the at least one participant.
- the present invention provides a computer device, including a program or an instruction, and when the program or instruction is executed, is used to execute the above-mentioned first aspect and each optional method of the first aspect.
- the present invention provides a storage medium, including a program or an instruction, and when the program or instruction is executed, is used to execute the above-mentioned first aspect and each optional method of the first aspect.
- FIG. 1 is a schematic flowchart corresponding to a privacy union method provided by an embodiment of the present invention
- Fig. 2 is a schematic structural diagram of a privacy union device provided by an embodiment of the present invention.
- a*G Indicates the dot multiplication operation of scalar a and any point G on the elliptic curve, * is the dot multiplication operation, and the operation result is still a point on the elliptic curve.
- the privacy union means that each participant has a set, and the participant can obtain the set intersection of all participants after going through the privacy union algorithm, but does not know any other participants except the union and its own set
- the content of the set realizes the effect of protecting the privacy of the set content of the participants in the process of union.
- Blockchain is a chain composed of a series of blocks. In addition to recording the data of this block, each block also records the Hash value of the previous block. In this way, a chain is formed.
- cryptography technology There are two core concepts of the blockchain, one is cryptography technology, and the other is the idea of decentralization. Based on these two concepts, the historical information on the blockchain cannot be tampered with.
- blockchain technology can be used to disclose the characteristics of accessibility and tamper-proof, as a public database for securely storing data.
- the present invention provides a privacy union method.
- Step 101 The first participant generates a first set of judgment rules.
- Step 102 For any subitem of the plurality of subitems, the first participant generates a commitment for the subitem according to a preset commitment algorithm according to the private key and the first obfuscation information of the subitem.
- Step 103 The first participant obtains the at least one tuple from the second participant.
- Step 104 The first participant obtains elements in the second set other than the first set according to the private key and the at least one tuple, and according to the first set and the For elements in the second set other than the first set, obtain the union of the first set and the second set.
- the judgment rule corresponds to a plurality of sub-items, and the multiple sub-items are used to determine the judgment rule, and the judgment rule is used to judge whether any element is an element in the first set element.
- the preset commitment algorithm has homomorphism, and the commitments of the multiple subitems are used by the second participant to generate at least one tuple. For any tuple in the at least one tuple, the tuple represents the corresponding element in the second set, and the tuple is the corresponding element in the second set according to the tuple of the second participant.
- the element, the commitment of the element corresponding to the tuple in the second set, and the second confusion information of the element corresponding to the tuple in the second set are obtained according to the preset commitment algorithm.
- the participants are P1, P2, ..., Pn, where n can be any positive integer.
- the set owned by the participant Pi is Si, and the elements in the set are any numbers.
- P1 is the first participant, and the set owned by P1 is the first set S1;
- P2 is the second participant, and the set owned by P2 is the second set S2.
- described judging rule can have multiple situations, can adopt regular expression as judging rule, can judge whether certain element is the element in the first set through regular expression, and regular expression corresponds to Multiple subitems of can be character strings and metacharacters in regular expressions, or information that can be mapped to character strings and metacharacters in regular expressions, such as using a0a0 to map " ⁇ ".
- Judgment rules can also use logical expressions, and multiple sub-items corresponding to logical expressions can use logical conjunctions such as "and", "or” and “not” and logical conditions, so as to determine whether an element is an element in the first set, or There are many forms, as long as it can be determined whether any element is an element in the first set.
- the commitment of the subitem can be a zero-knowledge proof of the subitem, and the subitem can be represented in an implicit form, and the commitment of the element corresponding to the tuple in the second set can be the zero of the element corresponding to the tuple in the second set In the proof of knowledge, the element corresponding to the tuple in the second set may be represented in an implicit form.
- the elements in the first set are all positive integers
- the judgment rule is a polynomial
- the multiple sub-items are the coefficients of each sub-term of the polynomial
- the preset commitment algorithm is A preset elliptic curve algorithm
- the preset elliptic curve algorithm corresponds to the first base point, the second base point, and the commitment public key
- the commitment public key is obtained according to the private key and the second base point.
- n is a positive integer
- the first participant generates a commitment for the subitem according to the private key and the first obfuscation information of the subitem according to a preset commitment algorithm, including:
- the first participant According to the private key, the first obfuscation information of the subitem, the first base point, the second base point, and the commitment public key, the first participant generates The promise of the subkey.
- the elements in the first set are all positive integers, and when the judgment rule is a polynomial, since the preset elliptic curve algorithm has a small amount of calculation and high security performance, the sub-items can be enhanced The generation efficiency of commitments.
- the first participant uses the following formula, according to the private key, the first confusion information of the subitem, the first base point, the second base point, and the commitment public key, according to the The above preset elliptic curve algorithm, generating the commitment of the child:
- x is the sub-item
- E(x) is the commitment of the sub-item
- G1 is the first base point
- G2 is the second base point
- r1 is the first confusion information of the sub-item
- H is the The above-mentioned commitment public key
- sk is the above-mentioned private key.
- the private key and public key are used to cover up the information released by the first participant, and the private key is also used to restore the masked value at the end to obtain the union of the set of other participants and the first set of the first participant.
- the elements in the first set are all positive integers
- the judgment rule is a polynomial
- the multiple sub-items are the coefficients of each sub-term of the polynomial
- the preset commitment algorithm is a preset elliptic curve Algorithm
- the preset elliptic curve algorithm corresponds to the first base point, the second base point and the commitment public key
- the commitment public key is obtained according to the private key and the second base point
- the first participant generates a commitment for the subitem according to the private key and the first obfuscation information of the subitem according to a preset commitment algorithm, including:
- the first participant According to the private key, the first obfuscation information of the subitem, the first base point, the second base point, and the commitment public key, the first participant generates The promise of the subkey.
- the elements in the first set are all positive integers, and when the judgment rule is a polynomial, since the preset elliptic curve algorithm has a small amount of calculation and high security performance, the sub-items can be enhanced The generation efficiency of commitments.
- the first participant uses the following formula, according to the private key, the first confusion information of the subitem, the first base point, the second base point, and the commitment public key, according to the The above preset elliptic curve algorithm, generating the commitment of the child:
- x is the sub-item
- E(x) is the commitment of the sub-item
- G1 is the first base point
- G2 is the second base point
- r1 is the first confusion information of the sub-item
- H is the The above-mentioned commitment public key
- sk is the above-mentioned private key.
- the multiple sub-items that is, the coefficients of each sub-item are: 1, -6, 11, 6 respectively.
- the first participant and the second participant are on the same blockchain.
- the first participant sends the commitments of the multiple subitems to the blockchain; the commitments of the multiple subitems are used by the second participant to obtain them from the blockchain.
- the first participant sends the commitments of the multiple subitems to the blockchain, so that there is no need to frequently send the commitments of the multiple subitems, even if the second participant needs to acquire multiple times, It can also be obtained directly from the block chain, thereby improving the efficiency of obtaining the commitments of the multiple subitems.
- the tuple includes a first subpart and a second subpart;
- the first subpart is the commitment of the second participant according to the element corresponding to the tuple in the second set, the element corresponding to the tuple in the second set, and the tuple in the second set.
- the second confusion information of the elements corresponding to the second set is obtained according to the preset commitment algorithm;
- the second sub-part is the commitment of the second participant to the element corresponding to the tuple in the second set, and the second confusion information of the element corresponding to the tuple in the second set, according to obtained by the preset commitment algorithm.
- the second participant can obtain at least one tuple in the following manner:
- the second set S2 of the second participants P2 ⁇ 3,4,5 ⁇ .
- P2 will calculate the commitment E(f1(3)) of f1(3) according to the homomorphic property of the preset commitment algorithm.
- coefficients are respectively the coefficient commitments of each sub-item obtained from the first participant.
- P2 calculates elements 4 and 5 according to the homomorphic property of the default commitment algorithm to obtain E(f1(4)) and E(f(5)).
- the second participant P2 selects (second obfuscation information) a random number r2_1 for element 3, selects a random number r2_2 for element 4, and selects a random number r2_3 for element 5.
- r2_i represents the random number selected by P2 for its i-th element).
- Second subpart Z1 E(f1(3)*r2_1)
- both the first sub-part and the second sub-part in the tuple use the commitment of the second participant according to the element corresponding to the tuple in the second set, the tuple in the The second confusion information of the elements corresponding to the second set, and the first sub-part uses the elements corresponding to the tuple in the second set, so the two sub-parts of the tuple can put the tuple in the The corresponding elements of the second set are implicitly included.
- the first participant obtains elements in the second set other than the first set according to the private key and the at least one tuple, including:
- the first participant obtains the denominator analysis item and the numerator of the tuple according to the first subpart of the tuple and the second subpart of the tuple Parse item;
- Y1 (3 3 -6*3 2 +11*3+6)*3*r2_1*G1+(3 3 *r1_1+3 2 *r1_2+3*r1_3+r1_4)*3*r2_1*H, (3 3 *r1_1+3 2 *r1_2+3*r1_3+r1_4)*3*r2_1*G2.
- P1 only knows that some elements of P2 are the intersection elements of both parties but does not know what these elements of P2 are. Therefore, P1 only obtains the final union result, but does not know the set content of P2; P2 cannot know the set elements of P1, so the effect of privacy union is realized.
- the program flow of more (at least three) participants is basically the same as that of the above two participants, except that the interaction of more participants is involved, and any participant To find the union based on the tuples of multiple parties.
- one or several parties can be designated to obtain the final union result.
- each participant will agree on which party or parties jointly own the private key x.
- the threshold determines the final result of the union. Several parties can obtain the union result. Example: If the threshold is (n,3), it means that among n participants, less than 3 participants cannot recover, and more than or equal to 3 participants can jointly recover to obtain the result.
- the first participant is any one of multiple participants, and the first participant obtains the private key in the following manner:
- the first participant obtains the fragmentation homomorphism information of at least one participant through a preset privacy interaction protocol according to the fragmentation homomorphism information of the first participant, wherein the fragmentation homomorphism information of any participant
- the information is obtained according to the preset homomorphic encryption operation according to the shard key of the participant; the at least one participant is a participant of the plurality of participants except the first participant;
- the first participant acquires the private key according to the preset homomorphic encryption operation according to the fragment homomorphic information of the first participant and the fragment homomorphic information of the at least one participant.
- the first participant can The fragmented homomorphic information of each party, through the preset privacy interaction protocol, obtains the fragmented homomorphic information of at least one participant, so as to jointly obtain the private key through a joint method, avoiding a single participant from doing evil, and improving the privacy of the union. safety.
- the judgment rule corresponds to the commitment of multiple subitems for the second participant to generate at least one tuple, and any tuple in the at least one tuple is characterizes the corresponding elements in the second set, and the first participant only obtains elements in the second set other than the first set according to the private key and the at least one tuple, but does not It is not known which elements are specifically included in the second set, so that the union of the first set and the second set is obtained, and a multi-party privacy union is realized.
- the present invention provides a privacy union device, including:
- the generating module 201 is configured to generate a first set of judging rules; the judging rules correspond to multiple sub-items, and the multiple sub-items are used to determine the judging rules, and the judging rules are used to judge whether any element is the elements in the first set;
- the preset commitment algorithm has the same Stateful, the commitment of the plurality of subitems is used by the second participant to generate at least one tuple;
- An acquisition module 202 configured to acquire the at least one tuple from the second participant; for any tuple in the at least one tuple, the tuple represents the corresponding element in the second set, the The tuple is the commitment of the second participant according to the element corresponding to the tuple in the second set, the element corresponding to the tuple in the second set, the commitment of the tuple in the second set
- the second obfuscation information of the corresponding element is obtained according to the preset commitment algorithm;
- the elements in the first set are all positive integers
- the judgment rule is a polynomial
- the multiple sub-items are the coefficients of each sub-term of the polynomial
- the preset commitment algorithm is a preset elliptic curve Algorithm
- the preset elliptic curve algorithm corresponds to the first base point, the second base point and the commitment public key
- the commitment public key is obtained according to the private key and the second base point
- the generating module 201 is specifically used for:
- the first confusion information of the subitem, the first base point, the second base point, and the commitment public key According to the private key, the first confusion information of the subitem, the first base point, the second base point, and the commitment public key, according to the preset elliptic curve algorithm, generate the commitment of the subitem .
- the generating module 201 is specifically configured to: according to the following formula, according to the private key, the first obfuscation information of the subitem, the first base point, the second base point, and the commitment public key , according to the preset elliptic curve algorithm, generate the commitment of the child:
- x is the sub-item
- E(x) is the commitment of the sub-item
- G1 is the first base point
- G2 is the second base point
- r1 is the first confusion information of the sub-item
- H is the The above-mentioned commitment public key
- sk is the above-mentioned private key.
- the tuple includes a first subpart and a second subpart;
- the first subpart is the commitment of the second participant according to the element corresponding to the tuple in the second set, the element corresponding to the tuple in the second set, and the tuple in the second set.
- the second confusion information of the elements corresponding to the second set is obtained according to the preset commitment algorithm;
- the second subpart is the commitment of the second participant to the element corresponding to the tuple in the second set and the second confusion information of the element corresponding to the tuple in the second set, according to obtained by the preset commitment algorithm.
- the acquiring module 202 is specifically used for:
- any tuple in the at least one tuple according to the first subpart of the tuple and the second subpart of the tuple, obtain the denominator analysis item and the numerator analysis item of the tuple;
- the device is executed by the first participant, and the first participant and the second participant are on the same block chain, and the device also includes a sending module, and the sending module specifically uses In: sending the commitments of the multiple subitems to the blockchain; the commitments of the multiple subitems are used by the second participant to obtain from the blockchain.
- the device is a device executed by a first participant, and the first participant is any one of multiple participants, and the acquisition module 202 specifically acquires the private key in the following manner:
- the sharding homomorphic information of the first participant is obtained through a preset privacy interaction protocol, wherein the sharding homomorphic information of any participant is based on the participant
- the shard key is obtained according to the preset homomorphic encryption operation; the at least one participant is a participant of the plurality of participants except the first participant;
- the private key is obtained according to the preset homomorphic encryption operation according to the fragment homomorphic information of the first participant and the fragment homomorphic information of the at least one participant.
- an embodiment of the present invention also provides a computer device, including a program or an instruction.
- the program or instruction When the program or instruction is executed, the privacy union method and any optional method provided by the embodiment of the present invention be executed.
- an embodiment of the present invention also provides a computer-readable storage medium, including a program or an instruction.
- the program or instruction is executed, the privacy union method provided by the embodiment of the present invention and any The optional method is executed.
- the embodiments of the present invention may be provided as methods or computer program products. Accordingly, the present invention can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) having computer-usable program code embodied therein.
- a computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
- These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing apparatus to operate in a specific manner, such that the instructions stored in the computer-readable memory produce an article of manufacture comprising instruction means, the instructions
- the device realizes the function specified in one or more procedures of the flowchart and/or one or more blocks of the block diagram.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Databases & Information Systems (AREA)
- Storage Device Security (AREA)
- Mobile Radio Communication Systems (AREA)
- Complex Calculations (AREA)
Abstract
Description
Claims (10)
- 一种隐私求并集方法,其特征在于,包括:第一参与方生成第一集合的判断规则;所述判断规则对应多个子项,所述多个子项用于确定所述判断规则,所述判断规则用于判断任一元素是否为所述第一集合中的元素;针对所述多个子项任一子项,所述第一参与方根据私钥和所述子项的第一混淆信息,按照预设承诺算法,生成所述子项的承诺;所述预设承诺算法具有同态性,所述多个子项的承诺用于第二参与方生成至少一个元组;所述第一参与方获取来自所述第二参与方的所述至少一个元组;针对所述至少一个元组中任一元组,所述元组表征了在第二集合对应的元素,所述元组是所述第二参与方根据所述元组在所述第二集合对应的元素、所述元组在所述第二集合对应的元素的承诺、所述元组在所述第二集合对应的元素的第二混淆信息,按照所述预设承诺算法得到的;所述第一参与方根据所述私钥和所述至少一个元组,获得所述第二集合中除所述第一集合之外的元素,并根据所述第一集合和所述第二集合中除所述第一集合之外的元素,获得所述第一集合和所述第二集合的并集。
- 如权利要求1所述的方法,其特征在于,所述第一集合中的元素均为正整数,所述判断规则为多项式,所述多个子项为所述多项式的各次项系数;所述预设承诺算法为预设椭圆曲线算法;所述预设椭圆曲线算法对应第一基点、第二基点和承诺公钥;所述承诺公钥是根据所述私钥和所述第二基点得到的;所述第一参与方根据私钥和所述子项的第一混淆信息,按照预设承诺算法,生成所述子项的承诺,包括:所述第一参与方根据所述私钥、所述子项的第一混淆信息、所述第一基点、所述第二基点和所述承诺公钥,按照所述预设椭圆曲线算法,生成所述子项的承诺。
- 如权利要求2所述的方法,其特征在于,所述第一参与方按照以下公式,根据所述私钥、所述子项的第一混淆信息、所述第一基点、所述第二基点和所述承诺公钥,按照所述预设椭圆曲线算法,生成所述子项的承诺:E(x)=(x*G1+r1*H,sk*G2);H=sk*G2;x为所述子项,E(x)为所述子项的承诺,G1为所述第一基点,G2为所述第二基点,r1为所述子项的第一混淆信息,H为所述承诺公钥,sk为所述私钥。
- 如权利要求2所述的方法,其特征在于,针对所述至少一个元组中任一元组,所 述元组包括第一子部分和第二子部分;所述第一子部分是所述第二参与方根据所述元组在所述第二集合对应的元素、所述元组在所述第二集合对应的元素的承诺、所述元组在所述第二集合对应的元素的第二混淆信息,按照所述预设承诺算法得到的;所述第二子部分是所述第二参与方根据所述元组在所述第二集合对应的元素的承诺、所述元组在所述第二集合对应的元素的第二混淆信息,按照所述预设承诺算法得到的。
- 如权利要求4所述的方法,其特征在于,所述第一参与方根据所述私钥和所述至少一个元组,获得所述第二集合中除所述第一集合之外的元素,包括:针对所述至少一个元组中任一元组,所述第一参与方根据所述元组的第一子部分和所述元组的第二子部分,获得所述元组的分母解析项和分子解析项;若所述分母解析项和所述分子解析项均不为0,则将所述分子解析项除以所述分母解析项的商,作为所述第二集合中除所述第一集合之外的元素。
- 如权利要求1至5任一项所述的方法,其特征在于,所述第一参与方和所述第二参与方在同一区块链上,所述方法还包括:所述第一参与方将所述多个子项的承诺发送到所述区块链上;所述多个子项的承诺用于所述第二参与方从所述区块链上获取。
- 如权利要求1至5任一项所述的方法,其特征在于,所述第一参与方为多个参与方中任一参与方,所述第一参与方按照以下方式获取所述私钥:所述第一参与方根据所述第一参与方的分片同态信息,通过预设隐私交互协议,获取至少一个参与方的分片同态信息,其中,任一参与方的分片同态信息是根据该参与方的分片密钥,按照预设同态加密运算得到的;所述至少一个参与方为所述多个参与方除了所述第一参与方之外的参与方;所述第一参与方根据所述第一参与方的分片同态信息和所述至少一个参与方的分片同态信息,按照所述预设同态加密运算,获取所述私钥。
- 一种隐私求并集装置,其特征在于,包括:生成模块,用于生成第一集合的判断规则;所述判断规则对应多个子项,所述多个子项用于确定所述判断规则,所述判断规则用于判断任一元素是否为所述第一集合中的元素;以及用于针对所述多个子项任一子项,根据私钥和所述子项的第一混淆信息,按照预设承诺算法,生成所述子项的承诺;所述预设承诺算法具有同态性,所述多个子项的承诺用于第二参与方生成至少一个元组;获取模块,用于获取来自所述第二参与方的所述至少一个元组;针对所述至少一个元 组中任一元组,所述元组表征了在第二集合对应的元素,所述元组是所述第二参与方根据所述元组在所述第二集合对应的元素、所述元组在所述第二集合对应的元素的承诺、所述元组在所述第二集合对应的元素的第二混淆信息,按照所述预设承诺算法得到的;以及用于根据所述私钥和所述至少一个元组,获得所述第二集合中除所述第一集合之外的元素,并根据所述第一集合和所述第二集合中除所述第一集合之外的元素,获得所述第一集合和所述第二集合的并集。
- 一种计算机设备,其特征在于,包括程序或指令,当所述程序或指令被执行时,如权利要求1至7中任意一项所述的方法被执行。
- 一种计算机可读存储介质,其特征在于,包括程序或指令,当所述程序或指令被执行时,如权利要求1至7中任意一项所述的方法被执行。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202110530000.2A CN113158253B (zh) | 2021-05-14 | 2021-05-14 | 一种隐私求并集方法及装置 |
| CN202110530000.2 | 2021-05-14 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022237103A1 true WO2022237103A1 (zh) | 2022-11-17 |
Family
ID=76876085
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2021/130448 Ceased WO2022237103A1 (zh) | 2021-05-14 | 2021-11-12 | 一种隐私求并集方法及装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN113158253B (zh) |
| WO (1) | WO2022237103A1 (zh) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115865306A (zh) * | 2022-11-25 | 2023-03-28 | 深圳市洞见智慧科技有限公司 | 可扩展的多方隐私保护集合求交方法、系统及相关设备 |
| CN116545773A (zh) * | 2023-07-05 | 2023-08-04 | 北京天润基业科技发展股份有限公司 | 一种处理隐私数据的方法、介质及电子设备 |
| CN120223282A (zh) * | 2025-03-13 | 2025-06-27 | 西安电子科技大学 | 基于全同态加密的非平衡隐私集合并集方法及合并集系统 |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113158253B (zh) * | 2021-05-14 | 2023-05-12 | 深圳前海微众银行股份有限公司 | 一种隐私求并集方法及装置 |
| CN115473707A (zh) * | 2022-08-29 | 2022-12-13 | 贵州华云信安科技有限公司 | 一种隐私交集求和的方法和装置 |
| CN115913539A (zh) * | 2022-11-17 | 2023-04-04 | 天翼电子商务有限公司 | 一种多方隐私数据集合求并集的方法及系统 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090307045A1 (en) * | 2008-06-10 | 2009-12-10 | International Business Machines Corporation | System and method for optimization of meetings based on subject/participant relationships |
| CN109104413A (zh) * | 2018-07-17 | 2018-12-28 | 中国科学院计算技术研究所 | 用于安全多方计算的私有数据求交集的方法及验证方法 |
| CN110719159A (zh) * | 2019-09-24 | 2020-01-21 | 河南师范大学 | 抗恶意敌手的多方隐私集合交集方法 |
| CN111885079A (zh) * | 2020-07-31 | 2020-11-03 | 支付宝(杭州)信息技术有限公司 | 保护数据隐私的多方联合处理数据的方法及装置 |
| CN113158253A (zh) * | 2021-05-14 | 2021-07-23 | 深圳前海微众银行股份有限公司 | 一种隐私求并集方法及装置 |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109559122B (zh) * | 2018-12-07 | 2021-02-02 | 北京瑞卓喜投科技发展有限公司 | 区块链数据传输方法及区块链数据传输系统 |
| CN109951443B (zh) * | 2019-01-28 | 2021-06-04 | 湖北工业大学 | 一种云环境下隐私保护的集合交集计算方法及系统 |
| CN111931207B (zh) * | 2020-08-07 | 2024-04-09 | 北京百度网讯科技有限公司 | 获得隐私集合交集的方法、装置、设备及存储介质 |
| CN112003695B (zh) * | 2020-08-11 | 2024-01-05 | 天翼电子商务有限公司 | 隐私集合求交方法、系统、介质及装置 |
| CN112597524B (zh) * | 2021-03-03 | 2021-05-18 | 支付宝(杭州)信息技术有限公司 | 隐私求交的方法及装置 |
-
2021
- 2021-05-14 CN CN202110530000.2A patent/CN113158253B/zh active Active
- 2021-11-12 WO PCT/CN2021/130448 patent/WO2022237103A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090307045A1 (en) * | 2008-06-10 | 2009-12-10 | International Business Machines Corporation | System and method for optimization of meetings based on subject/participant relationships |
| CN109104413A (zh) * | 2018-07-17 | 2018-12-28 | 中国科学院计算技术研究所 | 用于安全多方计算的私有数据求交集的方法及验证方法 |
| CN110719159A (zh) * | 2019-09-24 | 2020-01-21 | 河南师范大学 | 抗恶意敌手的多方隐私集合交集方法 |
| CN111885079A (zh) * | 2020-07-31 | 2020-11-03 | 支付宝(杭州)信息技术有限公司 | 保护数据隐私的多方联合处理数据的方法及装置 |
| CN113158253A (zh) * | 2021-05-14 | 2021-07-23 | 深圳前海微众银行股份有限公司 | 一种隐私求并集方法及装置 |
Non-Patent Citations (1)
| Title |
|---|
| SUN MAO-HUA, ZHE GONG: "A Privacy-preserving Outsourcing Set Union Protocol", JOURNAL OF CRYPTOLOGIC RESEARCH, vol. 3, no. 3, 30 April 2016 (2016-04-30), pages 114 - 125, XP093003967, ISSN: 2095-7025, DOI: 10.13868/j.cnki.jcr.000114 * |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115865306A (zh) * | 2022-11-25 | 2023-03-28 | 深圳市洞见智慧科技有限公司 | 可扩展的多方隐私保护集合求交方法、系统及相关设备 |
| CN116545773A (zh) * | 2023-07-05 | 2023-08-04 | 北京天润基业科技发展股份有限公司 | 一种处理隐私数据的方法、介质及电子设备 |
| CN116545773B (zh) * | 2023-07-05 | 2023-09-08 | 北京天润基业科技发展股份有限公司 | 一种处理隐私数据的方法、介质及电子设备 |
| CN120223282A (zh) * | 2025-03-13 | 2025-06-27 | 西安电子科技大学 | 基于全同态加密的非平衡隐私集合并集方法及合并集系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN113158253B (zh) | 2023-05-12 |
| CN113158253A (zh) | 2021-07-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN113158253B (zh) | 一种隐私求并集方法及装置 | |
| US10778410B2 (en) | Homomorphic data encryption method and apparatus for implementing privacy protection | |
| CN110348231B (zh) | 实现隐私保护的数据同态加解密方法及装置 | |
| Wu et al. | Secure and efficient outsourced k-means clustering using fully homomorphic encryption with ciphertext packing technique | |
| Luo et al. | SVFL: Efficient secure aggregation and verification for cross-silo federated learning | |
| CN112446052B (zh) | 一种适用于涉密信息系统的聚合签名方法及系统 | |
| CN113114454B (zh) | 一种高效隐私的外包k均值聚类方法 | |
| CN113708927B (zh) | 基于sm2数字签名的泛指定验证者签名证明系统 | |
| CN102263636A (zh) | 一种融合神经网络与混沌映射的流密码密钥控制方法 | |
| CN111162912B (zh) | 一种适用于区块链的验证方法、装置及存储介质 | |
| CN111639367B (zh) | 基于树模型的两方联合分类方法、装置、设备及介质 | |
| CN111325535A (zh) | 基于椭圆曲线偏移的区块链私钥管理方法、系统及存储介质 | |
| WO2023056763A1 (zh) | 一种隐私数据共享方法及装置 | |
| WO2021109718A1 (zh) | 一种基于区块链系统的验证方法及装置 | |
| Li et al. | Secure and efficient bloom-filter-based image search in cloud-based Internet of Things | |
| CN115987479B (zh) | 一种用于自然语言处理的深度学习模型的同态加密方法 | |
| CN114553395B (zh) | 一种风控场景下的纵向联邦特征衍生方法 | |
| CN117235342A (zh) | 基于同态哈希函数和虚拟索引的动态云审计方法 | |
| CN116527281A (zh) | 一种通用的两方适配器签名方法 | |
| CN114398662B (zh) | 基于安全多方计算的隐私保护机器学习推理方法及系统 | |
| CN113691371B (zh) | 区块链上基于身份的环签密方法 | |
| CN104852799B (zh) | 基于分段序列的数字音频伪装及重构方法 | |
| CN116595562B (zh) | 数据处理方法和电子设备 | |
| Huang et al. | A federated learning framework with blockchain-based auditable participant selection | |
| CN112580071A (zh) | 一种数据处理方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21941667 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21941667 Country of ref document: EP Kind code of ref document: A1 |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: OTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 13.05.2024) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21941667 Country of ref document: EP Kind code of ref document: A1 |