Secret random number generation system, secret computing device, secret random number generation method, and computer program product

The secret random number generation system directly generates random numbers following a discrete Laplace distribution using Bernoulli distributions, addressing the issue of reduced privacy protection in existing methods by avoiding geometric approximations, thereby enhancing output privacy in secret computation.

CN114830211BActive Publication Date: 2025-07-15NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201980103031.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-12-19
Publication Date
2025-07-15
Estimated Expiration
2039-12-19

AI Technical Summary

Technical Problem

The prior art causes the problem of reducing privacy protection intensity through approximate geometric distributions when generating random noise following discrete Laplace distributions.

Method used

By generating a random bit string that follows the Bernoulli distribution and using prefix logic sum and code multiplication operations, random numbers following the discrete Laplace distribution are directly generated to avoid approximate processing.

Benefits of technology

Improve the output privacy protection strength in secret calculations to ensure that the privacy of the calculation results is not lost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114830211B_ABST
    Figure CN114830211B_ABST
Patent Text Reader

Abstract

Generate a secret random number that follows a discrete Laplace distribution without approximation. The secret computing device (1 i ) generates a masked value [r] of a random number r that follows a discrete Laplace distribution with parameter α. The bit string generation unit (11) generates a masked value [b0] of a random number bit b0 that follows a Bernoulli distribution with probability (1-α) / (1+α), and masked values [b1], …, b N of random number bits b1, …, b N that follow a Bernoulli distribution with probability (1-α), respectively, to form columns of masked values [b0], [b1], …, [b N . The absolute value determination unit (12) obtains the masked value [L] of the position L that is set to 1 for the first time when observing from the beginning among the random number bits b0, b1, …, b N . The code determination unit (13) obtains the result [L·s] obtained by multiplying the masked value [L] by a random code s as the masked value [r] of the random number r.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to secure computation technology and privacy protection technology. Background Art

[0002] Recently, in the process of increasing application demands for privacy data represented by personal information, secure computation technology that can perform various computations while keeping information secret is attracting attention. Secure computation is a useful technology with various application examples (for example, refer to Non-Patent Document 1). However, since secure computation guarantees the correctness (legality) of the computation result, it cannot cover the privacy of the computation result called "output privacy". In order to protect output privacy, for example, it is necessary to use techniques such as perturbing the computation result with random noise. In secure computation, such perturbation, and furthermore, the generation of random noise also becomes a technical issue.

[0003] Regarding such a problem, in Non-Patent Document 2, a method of using secure computation to generate secret random noise following a discrete Laplace distribution is disclosed. Since noise following a discrete Laplace distribution is used to satisfy the output privacy protection criterion called differential privacy, Non-Patent Document 2 can be said to be a useful technology for achieving output privacy protection in secure computation.

[0004] Prior Art Documents

[0005] Non-Patent Documents

[0006] Non-Patent Document 1: Naoto Kiritani, Dai Igarashi, Hiroki Hamada, Ryosuke Kikuchi, "Programmable Secure Computation Library MEVAL3", Symposium on Cryptography and Information Security (SCIS), 2018 (Naoto Kiritani, Dai Igarashi, Hiroki Hamada, Ryosuke Kikuchi, "Programmable Secure Computation Library MEVAL3", Symposium on Cryptography and Information Security (SCIS), 2018)

[0007] Non-Patent Document 2: C. Dwork, K. Kenthapadi, F. McSherry, I. Mironov, M. Naor, "Our data, ourselves: privacy via distributed noise generation," Advances in Cryptology, EUROCRYPT, LNCS 4004, pp. 486 - 503, 2006. Summary of the Invention

[0008] Problems to be Solved by the Invention

[0009] However, in Non-Patent Document 2, noise generation is performed by approximating the discrete Laplace distribution using the geometric distribution, and thus there is a problem that the privacy protection strength is reduced compared to the original.

[0010] An object of the present invention is to generate a secret random number that follows a discrete Laplace distribution without approximation in view of the above technical problems.

[0011] Means for Solving the Problem

[0012] In order to solve the above problem, a secret random number generation system according to an aspect of the present invention is a secret random number generation system including a plurality of secret computing devices and generating a hidden value [r] of a random number r that follows a discrete Laplace distribution with a parameter α, where α is a number greater than 0 and less than 1, N is an integer of 2 or more, and the secret computing device includes: a bit string generation unit that generates a hidden value [b0] of a random number bit b0 that follows a Bernoulli distribution with a probability (1 - α) / (1 + α), and hidden values [b1],..., [b N of random number bits b1,..., b N that each follow a Bernoulli distribution with a probability (1 - α) to form a column of hidden values [b0], [b1],..., [b N ; an absolute value determination unit that obtains a hidden value [L] of the position L that is set to 1 for the first time when observing from the beginning among the random number bits b0, b1,..., b N ; and a code determination unit that obtains a result [L·s] obtained by multiplying the hidden value [L] by a random code s as a hidden value [r] of the random number r.

[0013] Effects of the Invention

[0014] According to the present invention, it is possible to generate a secret random number that follows a discrete Laplace distribution without approximation. By using this secret random number to stir the calculation result, it is possible to improve the protection strength of the output privacy in secret calculation. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 is a diagram illustrating the functional structure of a secret random number generation system.

[0016] Figure 2 is a diagram illustrating the functional structure of a secret computing device.

[0017] Figure 3 is a diagram illustrating the processing procedure of a secret random number generation method.

[0018] Figure 4 is a diagram illustrating the functional structure of a computer. DETAILED DESCRIPTION OF THE INVENTION

[0019] First, the prior art that is a prerequisite in the present invention will be described.

[0020] <Secret Computation>

[0021] Secret computation is a technique for performing computations while keeping the values encrypted or hidden (for example, Non-Patent Document 1). Hereinafter, a value obtained by hiding a certain value will be referred to as a "hidden value" and denoted as [·]. In secret computation, it is possible to compute the addition operation [a + b], subtraction operation [a - b], and multiplication operation [a · b] of hidden values [a] and [b]. In particular, when a and b are true / false values (1-bit values), it is possible to compute the exclusive OR [a XOR b], logical product [a AND b], and logical sum [a OR b].

[0022] There are known methods for achieving more complex processing through secret computation by utilizing the above properties. The following shows the processing used in the present invention in such processing.

[0023] 《Prefix Logic Sum (Prefix-OR)》

[0024] If the logical sum calculation is used, for the hidden values ([a1],..., [a n ) of the bit string (a1,..., a n ), it is possible to obtain the hidden values ([b1] = [a1], [b2] = [a1 OR a2],..., [b n ) of the bit string (b1,..., b n ). At this time, for any bit string (a1,..., a n ) in which a i becomes 1 for the first time at a certain i and all of a1,..., a i-1 before that are 0, the bit string (b1,..., b n ) becomes a bit string that satisfies b1,..., b n = 0 and b i-1 ,..., b i ,..., b n = 1.

[0025] 《Uniform Random Number Generation》

[0026] According to References 1 and 2, it is possible to generate the hidden value [r] of a uniform random number r without knowing the original random number r.

[0027] 〔Reference 1〕R. Cramer, I. Damgard, and Y. Ishai, "Share conversion, pseudorandom secret-sharing and applications to secure computation," Theory of Cryptography, LNCS 3378, pp. 342 - 362, 2005.

[0028] 〔Reference 2〕J. Bar-Ilan and D. Beaver, "Non-cryptographic fault-tolerant computing in constant number of rounds of interaction," Proceedings of the 8th annual ACM Symposium on Principles of Distributed Computing, 1989, pp. 201 - 209.

[0029] 《Interval test》

[0030] According to Reference 3, for the hiding value [a] of a certain value a, the hiding value [b] of the hiding bit obtained by determining whether the value a converges within a certain range I can be obtained. At this time, if a ∈ I, then b = 1 is satisfied; otherwise, b = 0 is satisfied.

[0031] 〔Reference 3〕T. Nishide and K. Ohta, "Multiparty computation for interval, equality, and comparison without bit-decomposition protocol," Public Key Cryptography, LNCS 4450, pp. 343 - 360, 2007.

[0032] <Bernoulli distribution>

[0033] The Bernoulli distribution Ber(β) is a distribution that produces 1 with a certain probability β and produces 0 with a probability of 1 - β.

[0034] <Discrete Laplace distribution>

[0035] Suppose the independently tried random variables B0, B1,... respectively satisfy B0 ~ Ber((1 - α) / (1 + α)), B j≥1~Ber(1-α). Here, ~ represents following a distribution. That is, it is assumed that the random variable B0 follows a Bernoulli distribution with probability (1-α) / (1+α), and the random variables B1, B2, … follow a Bernoulli distribution with probability (1-α). At this time, for the position L where, when observing from the beginning, it first becomes B L =1 (that is, B0, …, B L-1 =0 and B L =1 of L), the value obtained by inverting the sign with probability 1 / 2, ~L = L or –L, follows the discrete Laplace distribution DL(α) with parameter α.

[0036] [Embodiment]

[0037] Hereinafter, the embodiments of the present invention will be described in detail. In addition, in the drawings, the structural parts having the same functions are denoted by the same reference numerals, and redundant descriptions are omitted.

[0038] The secret random number generation system of the embodiment is coordinated by n (≥2) secret computing devices to calculate the hidden value of a random value following the discrete Laplace distribution. In this embodiment, secret computing on the finite field Z p with p bits is envisioned, but the present invention is not limited thereto, and it can also be similarly applied to secret computing on other fields.

[0039] For example, as Figure 1 shown, the secret random number generation system 100 of the embodiment includes n (≥2) secret computing devices 11, …, 1 n . In this embodiment, the secret computing devices 11, …, 1 n are respectively connected to the communication network 9. The communication network 9 is a communication network configured in a circuit switching manner or a packet switching manner in which the connected devices can communicate with each other. For example, the Internet or a LAN (Local Area Network), a WAN (Wide Area Network), etc. can be used. In addition, it is not necessary for each device to be able to communicate online via the communication network 9. For example, it can also be configured to store the information input to the secret computing devices 11, …, 1 n in a portable recording medium such as a magnetic tape or a USB memory, and input it to the secret computing devices 11, …, 1 n from the portable recording medium in an offline manner.

[0040] For example, as Figure 2 shown, the secret computing device 1 i(i = 1, …, n) has a parameter storage unit 10, a bit string generation unit 11, an absolute value determination unit 12, a code determination unit 13, and an output unit 14. The bit string generation unit 11 includes an interval setting unit 111, a random number generation unit 112, and an interval test unit 113. The absolute value determination unit 12 includes a prefix logical sum unit 121 and a bit reversal sum unit 122. The code determination unit 13 includes a code generation unit 131 and a code multiplication operation unit 132. This secret computing device 1 i (i = 1, …, n) and other secret computing devices 1 j (j = 1, …, n, where i ≠ j) while coordinating, perform the processing of each step described later, thereby implementing the secret random number generation method of this embodiment.

[0041] Secret computing device 1 i For example, it is a special device formed by reading a special program into a known or dedicated computer having a central processing unit (CPU: Central Processing Unit), a main storage device (RAM: Random Access Memory), etc. Secret computing device 1 i For example, executes each process under the control of the central processing unit. The data input to the secret computing device 1 i or the data obtained through each process is, for example, stored in the main storage device, and the data stored in the main storage device is read out to the central processing unit as needed for other processes. Secret computing device 1 i At least a part of each processing unit of can also be constituted by hardware such as an integrated circuit. Secret computing device 1 i Each storage unit included can be, for example, a main storage device such as a RAM (Random Access Memory), an auxiliary storage device constituted by a semiconductor storage element such as a hard disk, an optical disk, or a flash memory, or middleware such as a relational database or a key value store.

[0042] Hereinafter, while referring to Figure 3 while explaining the processing procedure of the secret random number generation method executed by the secret random number generation system 100 of the embodiment.

[0043] In the parameter storage unit 10, the parameter α of the predetermined discrete Laplace distribution DL(α) and a sufficiently large natural number N are stored. Among them, α is a number greater than 0 and less than 1.

[0044] In step S11, the bit string generation unit 11 generates random number bits b0, b1, …, b that follow the Bernoulli distribution NColumns [b0], [b1], …, [b of the hidden values N . At this time, it is assumed that b0 ~ Ber((1-α) / (1+α)), b1, …, b N ~ Ber(1-α). That is, it is assumed that the random number bits b1, …, b N follow the Bernoulli distribution with probability (1-α). The hidden value [b i of the random number bit b i (i = 0, …, N) is generated by performing the following steps S111 to S113 for each integer i.

[0045] In step S111, the interval setting unit 111 selects an interval I = [γ1, γ2] on the finite field Zp such that β ≒ |I| / p. Here, β is the probability of the Bernoulli distribution. That is, when i = 0, β = (1-α) / (1+α), and when i ≥ 1, β = (1-α). The interval setting unit 111 outputs the selected interval I to the interval test unit 113.

[0046] In step S112, the random number generation unit 112 generates a random number r i on the finite field Zp i of the hidden value. The random number generation unit 112 outputs the hidden value [r i of the generated random number r i to the interval test unit 113.

[0047] In step S113, the interval test unit 113 determines whether r i ∈ I through an interval test. That is, using the hidden value [r i of the random number r i , the hidden value [b] of the result b obtained by determining whether the random number r i is included in the interval I is generated. The determination result b follows the Bernoulli distribution Ber(β) with probability β. That is, b ~ Ber(β). The interval test unit 113 outputs the hidden value [b] of the determination result b as the hidden value [b i of the random number bit b i .

[0048] In step S12, the absolute value determination unit 12 obtains the hidden value [L] of the position L that is the position set to 1 for the first time when observing the random number bits b0, b1, …, b N from the beginning. The hidden value [L] of the position L can be obtained by performing the following steps S121 to S122.

[0049] In step S121, the prefix logical sum unit 121 obtains the logical sum of the hidden values of the columns [b0], [b1], …, [bN The result obtained after performing Prefix-OR serves as the columns [c0], [c1], …, [c N of the hidden values. Specifically, for each integer i, [b0] OR … OR [b i will be calculated and the result will be used as the hidden value [c i , obtaining [c0] = [b0], [c1] = [b0] OR [b1], …, [c N = [b0] OR … OR [b N . The prefix logic and unit 121 outputs the columns [c0], [c1], …, [c N of the hidden values to the bit-reversal sum unit 122.

[0050] In step S122, the bit-reversal sum unit 122 calculates [L] = Σ i (1 - [c i ). L is the position L where, starting from the beginning of the random number bits b0, b1, …, b N , b L becomes 1 for the first time. The bit-reversal sum unit 122 outputs the hidden value [L] of the calculated position L.

[0051] In step S13, the code determination unit 13 obtains the result [L·s] by multiplying the hidden value [L] of the position L by the hidden value [s] of the random code s. The multiplication result [L·s] can be obtained by performing the following steps S131 to S132.

[0052] In step S131, the code generation unit 131 generates the hidden value [s] of the random code s by calculating [s] ← R {-1, 1}. Here, ← R represents the operation of randomly selecting an element of the set. The code generation unit 131 outputs the generated hidden value [s] of the code s to the code multiplication unit 132.

[0053] In step S132, the code multiplication unit 132 multiplies the hidden value [L] of the position L by the hidden value [s] of the code s. The hidden value [L·s] of this multiplication result becomes the hidden value of a random number following the discrete Laplace distribution DL(α). The code multiplication unit 132 outputs the hidden value [L·s] of the multiplication result.

[0054] In step S14, the output unit 14 outputs the hidden value [L·s] of the multiplication result as the hidden value [r] of a random number r following the discrete Laplace distribution DL(α) with parameter α.

[0055] In the present invention, by secretly calculating random number bits following a Bernoulli distribution, the secret calculation of random numbers following a discrete Laplace distribution is realized. At this time, instead of performing an approximation based on a geometric distribution, random numbers based on a discrete Laplace distribution are directly generated, thereby avoiding a reduction in the privacy protection strength due to the approximation. Thus, according to the present invention, it is possible to generate secret random numbers following a discrete Laplace distribution that can be used for output privacy protection of secret calculation results without approximation. In the existing methods, an approximation using a geometric distribution has always been required.

[0056] As described above, the embodiments of the present invention have been described, but the specific structure is not limited to these embodiments. Without departing from the gist of the present invention, even with appropriate design changes, etc., they are of course included in the present invention. The various processes described in the embodiments can be executed in chronological order according to the recorded order, or can be executed in parallel or individually according to the processing capabilities of the devices executing the processes.

[0057] [Program, recording medium]

[0058] In the case where the various processing functions in each device described in the above embodiments are implemented by a computer, the processing contents of the functions that each device should have are described by a program. Then, by reading this program into Figure 4 the storage unit 1020 of the computer shown, the control unit 1010, the input unit 1030, the output unit 1040, etc. are operated, and the various processing functions in the above-mentioned respective devices are implemented on the computer.

[0059] The program describing the processing contents can be recorded in a computer-readable recording medium. As a computer-readable recording medium, for example, any medium such as a magnetic recording device, an optical disc, a magneto-optical recording medium, a semiconductor memory, etc. can be used.

[0060] In addition, the distribution of this program is, for example, carried out by selling, transferring, or lending portable recording media such as DVDs and CD-ROMs on which this program is recorded. Furthermore, it can also be configured to store this program in the storage device of a server computer and forward this program from the server computer to other computers through a network, thereby distributing this program.

[0061] A computer that executes such a program, for example, first temporarily stores the program stored in a portable recording medium or the program forwarded from a server computer in its own storage device. Then, when performing processing, the computer reads the program stored in its own storage device and executes the processing according to the read program. Additionally, as another execution mode of this program, the computer can also directly read the program from the portable storage medium, execute the processing according to the program, and can also sequentially execute the processing according to the received program each time the program is forwarded from the server computer to the computer. Furthermore, it can also be configured such that the program is not forwarded from the server computer to the computer, and the processing function is achieved only through the execution instruction and result acquisition, that is, the above processing is executed through a so-called ASP (Application Service Provider) type of service. Additionally, in the program of this mode, it is assumed to include information that complies with the program (not a direct instruction to the computer, but data with the nature of prescribing the processing of the computer, etc.) as information for use in the processing of the electronic computer.

[0062] Furthermore, in this mode, it is assumed that this device is configured by executing a prescribed program on a computer, but it can also be assumed that at least a part of these processing contents is implemented only in hardware.

Claims

1. A secret random number generation system, which is a secret random number generation system including a plurality of secret computing devices and generating a hidden value [r] of a random number r that follows a discrete Laplace distribution with parameter α, where, α is set to a number greater than 0 and less than 1, and N is an integer of 2 or more. The secret computing device includes: A bit string generation unit generates a column of hidden values [b0], [b1], …, [b N consisting of a hidden value [b0] of a random number bit b0 following a Bernoulli distribution with probability (1-α) / (1+α), and hidden values [b1], …, [b N of random number bits b1, …, b N that follow a Bernoulli distribution with probability (1-α) respectively; The absolute value determination unit obtains the hidden value [L] of the position L where 1 is initially set when observing from the beginning among the random number bits b0, b1, …, b; and N ​ A code determination unit that obtains a result [L·s] obtained by multiplying the hidden value [L] by a hidden value [s] of a random code s as the hidden value [r] of the random number r.

2. The secret random number generation system according to claim 1, where, Set Z p as a finite field of bit number p, and set i as each integer from 0 or more to N or less. The bit string generation unit includes: An interval setting unit that sets an interval I near the probability where |I| / p follows a Bernoulli distribution. A random number generation unit generates, for each integer i, a random number r on the finite field Z p and a hiding value [r i of the random number r i ; and Interval test unit, for each integer i, using the hidden value [r i , generates a result obtained by determining whether the random number r i is included in the interval I, as the hidden value [b i .

3. The secret random number generation system according to claim 2, where, The absolute value determination unit includes: Prefix logic and section, for each integer i, will calculate [b0] OR … OR [b i and use the resulting value as the hidden value [c i , generating columns [c0], [c1], …, [c N ; and Bit-reversal summing unit, generating the calculation Σ i (1 - [c i ) to obtain the result as the steganographic value [L].

4. A secret computing device, which is a secret computing device used in a secret random number generation system that generates a hidden value [r] of a random number r that follows a discrete Laplace distribution with parameter α, where, α is set to a number greater than 0 and less than 1, and N is an integer of 2 or more. The secret computing device includes: A bit string generation unit generates a column of hidden values [b0], [b1], …, [b], which consists of the hidden value [b0] of a random number bit b0 following a Bernoulli distribution with probability (1-α) / (1+α), and random number bits b1, …, b following a Bernoulli distribution with probability (1-α) respectively. N of the hidden values [b1], …, [b N ; N ​ The absolute value determination unit obtains the hidden value [L] of the position L that is set to 1 for the first time when observing from the beginning among the random number bits b0, b1, …, b; and N ​ A code determination unit that obtains a result [L·s] obtained by multiplying the hidden value [L] by a hidden value [s] of a random code s as the hidden value [r] of the random number r.

5. A secret random number generation method, which is a secret random number generation method executed by a secret random number generation system that generates a hidden value [r] of a random number r that follows a discrete Laplace distribution with parameter α, where, α is set to a number greater than 0 and less than 1, and N is an integer of 2 or more. The bit string generation unit generates a column of hidden values [b0], [b1], …, [b N consisting of the hidden value [b0] of a random number bit b0 following a Bernoulli distribution with probability (1 - α) / (1 + α), and random number bits b1, …, b N each following a Bernoulli distribution with probability (1 - α); N ; The absolute value determination unit obtains the hidden value [L] of the position L that is set to 1 for the first time when observing from the beginning among the random number bits b0, b1, …, b; and N ​ A code determination unit obtains a result [L·s] obtained by multiplying the hidden value [L] by a hidden value [s] of a random code s as the hidden value [r] of the random number r.

6. A computer program product, including a computer program for causing a computer to function as the secret computing device according to claim 4.

Citation Information

Patent Citations

  • Secret calculation system, aggregate function device, secret calculation method, and program

    JP2014081475A

  • Secret random number synthesizing device, secret random number synthesizing method, and program

    US20180261133A1