Secret maximum value calculation device, system, method and computer program product

By designing a secret maximum value calculation device, using one comparison to determine the maximum value and flag, the problem of long processing time when calculating the maximum value in the prior art is solved, and a faster processing time is achieved.

CN114945964BActive Publication Date: 2025-05-09NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080092443.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-01-17
Publication Date
2025-05-09
Estimated Expiration
2040-01-17

AI Technical Summary

Technical Problem

In the prior art, when calculating the maximum value, the number of series compared is Θ(n), resulting in a longer processing time.

Method used

A secret maximum value calculation device is designed, including an output unit, a comparison unit, a flag calculation unit and a maximum value calculation unit. The maximum value and flag can be determined by one comparison, reducing the number of comparison series.

Benefits of technology

The processing time is effectively reduced, and the number of series compared is reduced from Θ(n) to level 1.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114945964B_ABST
    Figure CN114945964B_ABST
Patent Text Reader

Abstract

Secret maximum value calculation device, set the set X = {[[x1]], [[x2]],..., [[x n}, the device includes: an output unit (1), when n = 1, respectively output [[x1]] and [[1]] as the largest hidden value [[y]] and the flag [[z(x1)]]; a comparison unit (2), for each group #imgabs0# of elements of X, calculate the comparison result of which one is larger with respect to a specified order; a flag calculation unit (3), for each [[x i , calculate whether all the comparison results related to the respective [[x i are "large", and set the calculated value as the flag [[z(x i )]]; and a maximum value calculation unit (4), using the [[z(x i )]], calculate the maximum value [[y]].
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to cryptographic application technology, and in particular to a method for calculating a maximum value and a flag of the maximum value without disclosing input or output. Background Art

[0002] As a method of obtaining a specific calculation result without restoring the encrypted numerical value, there is a method called secret computing (for example, refer to non-patent document 1). In the method of non-patent document 1, encryption is performed so that fragments of the numerical value are distributed to three secret computing devices, and the three secret computing devices perform collaborative calculations. As a result, the numerical value can be maintained without restoring the value, and the results of addition and subtraction operations, constant addition operations, multiplication operations, constant multiples, logical operations ("not", "and", "or", "exclusive or"), and data format conversion (integer, binary) can be maintained in a state distributed to the three secret computing devices, that is, in an encrypted state. In the case of calculating the maximum value of n encrypted values ​​and the sign of the maximum value by secret computing, there is a method as follows: the current maximum value and the number of the element as the maximum value are maintained as ciphertext, and compared with n ciphertexts in sequence, the maximum value and the number of the element as the maximum value are continuously updated, and finally the sign is calculated based on the number (for example, refer to non-patent document 2).

[0003] Prior art literature

[0004] Non-patent literature

[0005] Non-patent literature 1: Koji Chida, Hiroshi Hamada, Dai Igarashi, Katsumi Takahashi, and Re-examination of the calculation of the possible 3-level secret level number, In CSS, 2010.

[0006] Non-patent literature 2: Sameer Wagh, Divya Gupta, and Nishanth Chandran. Securenn: 3-party secure computation for neural network training. Proceedings on PrivacyEnhancing Technologies, Vol.1, p.24, 2019. Summary of the invention

[0007] Problems to be solved by the invention

[0008] However, in the conventional method, although the total number of comparisons when calculating the maximum value is Θ(n), the number of comparison levels is as large as Θ(n).

[0009] An object of the present invention is to provide a secret maximum value calculation device, method and program that reduce processing time.

[0010] Means for solving problems

[0011] A secret maximum value calculation device according to one embodiment of the present invention is provided, wherein a set X = {[[x1]], [[x2]], ..., [[x n ]]}, the device comprises: an output unit, when n=1, outputting [[x1]] and [[1]] as the maximum hidden value [[y]] and the mark [[z(x1)]] respectively; a comparison unit, for the group of elements of X For each of [[x i ]], calculate the value of each [[x i ]] If all the comparison results are "large", the calculated value is set as the flag [[z(x i )]]; and the maximum value calculation part, using [[z(x i )]], calculate the maximum value [[y]].

[0012] Effects of the Invention

[0013] Can reduce processing time. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 This is a diagram showing an example of the functional structure of the secret maximum value calculation device according to the first embodiment.

[0015] Figure 2 This is a diagram showing an example of the processing procedure of the secret maximum value calculation method according to the first embodiment.

[0016] Figure 3 This is a diagram showing an example of the functional structure of the secret maximum value calculation device according to the second embodiment.

[0017] Figure 4 This is a diagram showing an example of the processing procedure of the secret maximum value calculation method according to the second embodiment.

[0018] Figure 5 This is a diagram showing an example of the functional structure of the secret maximum value calculation device according to the third embodiment.

[0019] Figure 6 This is a diagram showing an example of the processing procedure of the secret maximum value calculation method according to the third embodiment.

[0020] Figure 7 This is a diagram showing an example of a functional configuration of a computer. DETAILED DESCRIPTION

[0021] Hereinafter, embodiments of the present invention will be described in detail. In addition, in the drawings, structural parts having the same function are denoted by the same reference numerals, and redundant descriptions are omitted.

[0022] [Notation]

[0023] The value obtained by concealing a certain value a through encryption or secret sharing, etc., is called the concealed value of a, denoted as [[a]]. When the concealment is secret sharing, the set of fragments of the secret sharing possessed by each secret computing device is referred to through [[a]].

[0024] [Decoding]

[0025] The process of taking the concealed value [[a]] of a as the input and calculating the value c such that c = a is denoted as c←Open([[a]]).

[0026] [Arithmetic Operations]

[0027] For each of the addition, subtraction, and multiplication operations, the concealed values [[a]] and [[b]] of two values a and b are taken as the inputs, and the concealed values [[c1]], [[c2]], and [[c3]] of the calculation results c1, c2, and c3 of a + b, a - b, and ab are calculated respectively. The execution of these operations is denoted as follows:

[0028] [[c1]]←Add([[a]],[[b]])

[0029] [[c2]]←Sub([[a]],[[b]])

[0030] [[c3]]←Mul([[a]],[[b]]). When there is no concern of misunderstanding, Add([[a]],[[b]]), Sub([[a]],[[b]]), and Mul([[a]],[[b]]) are abbreviated as [[a]] + [[b]],

[0031] [[a]] - [[b]], [[a]] × [[b]] respectively.

[0032] [Comparison]

[0033] For the comparison operation, the concealed values [[a]] and [[b]] of two values a and b are taken as the inputs, and the concealed values [[c1]], [[c2]], and [[c3]] of the truth values c ∈ {0, 1} of a = b, a ≤ b, and a < b are calculated. Regarding the truth values, 1 is set for true and 0 is set for false. The execution of this operation is denoted as:

[0034] [[c0]]←EQ([[a]],[[b]])

[0035] [[c1]]←LE([[a]],[[b]])

[0036] [[c2]]←LT([[a]],[[b]]). In addition, at least one of the inputs of EQ, LE, and LT may not be a hidden value.

[0037] <Select>

[0038] Regarding the selected operation, the hidden value [[c]] of the true or false value c∈{0,1} and the hidden values ​​[[a]] and [[b]] ​​of two values, namely a and b, are used as input to calculate the secret value [[d]] of d that satisfies the following formula.

[0039]

Mathematical formula 1

[0040]

[0041] The execution of this operation is described as:

[0042] [[d]]←IfElse([[c]],[[a]],[[b]]). This operation can be implemented as follows:

[0043] [[d]]←[[c]]×([[a]]-[[b]])+[[b]].

[0044] [First embodiment]

[0045] The first embodiment of the invention is a device and method for calculating the maximum secret value, which is a device and method for calculating the maximum secret value according to a set of secret values ​​X = {[[x1]], [[x2]], ..., [[x n ]]}, calculate the maximum hidden value [[y]] with respect to the predetermined order, and the hidden value [[z(x i )]].

[0046] The notation representing the input, output, and processing of the secret maximum value calculation device and method according to the first embodiment can be described as follows.

[0047] Input: X = {[[x1]],...,[[x n ]]}

[0048] Output: [[y]],[[z(x1)]],...,[[z(x n )]]

[0049] Notation: [[y]],[[z(x1)]],...,[[z(x n )]]←f0([[x1]],...,[[x n ]])

[0050] As Figure 1 shown, the secret maximum value calculation device of the first embodiment includes, for example, an output unit 1, a comparison unit 2, a flag calculation unit 3, and a maximum value calculation unit 4.

[0051] Regarding the secret maximum value calculation method, for example, it is implemented by the following processing of steps S1 to S4 performed by each structural part of the secret maximum value calculation device. Figure 2 shown.

[0052] Hereinafter, each structural part of the secret maximum value calculation device will be described.

[0053] <Output unit 1>

[0054] The set X = {[[x1]], [[x2]],..., [[x n} is input to the output unit 1. n is a specified positive integer.

[0055] When n = 1, the output unit 1 outputs [[x1]] and [[1]] respectively as the maximum hidden value [[y]] and the flag [[z(x1)]] (step S1).

[0056] When n ≠ 1, the following processing after step S2 is performed.

[0057] <Comparison unit 2>

[0058] The set X = {[[x1]], [[x2]],..., [[x n} is input to the comparison unit 2.

[0059] The comparison unit 2 calculates the comparison result of which one is larger with respect to a specified order for each group of elements of X (step S2).

[0060] The calculated comparison result is output to the flag calculation unit 3.

[0061] For example, the comparison unit 2 performs [[c i,j ← LE([[x i , [[x j ) for each 1 ≤ i < j ≤ n. In other words, the comparison unit 2 performs LE(x i , x j ) for each (i, j) (i, j ∈ [1, n], i < j), and sets the calculation result [[c i,j as the comparison result.

[0062] Here, LE(x i , x j ) is when x i ≤ xj A function that outputs [[1]] when the condition is the same, and outputs [[0]] when the condition is not the same.

[0063] <Flag calculation unit 3>

[0064] The comparison result calculated by the comparison unit 2 is input to the flag calculation unit 3 .

[0065] The flag calculation unit 3 calculates the value of each [[x i ]], calculate the value of each [[x i ]] Whether all comparison results are "large", and set the calculated value as the flag [[z(x i )]](step S3).

[0066] The calculated sign [[z(x i )]] is output to the maximum value calculation unit 4.

[0067] For example, the flag calculation unit 3 performs 1-[[c j,i ]], and set the result of the calculation to [[c i,j ]], and for each i, perform Π i≠j [[c i,j ]], and set the result of the calculation as the flag [[z(x i )]].

[0068] In addition, the flag calculation unit 3 may perform 1-[[c j,i ]], and set the result of the calculation to [[c i,j ]], and for each i, [[z(x i )]]←EQ(Σ i≠j [[c i,j ]],n-1) and set the result of the calculation as the flag [[z(x i )]]. In addition, n-1 compared by the function EQ may also be a hidden value. That is, the flag calculation unit 3 may perform [[z(x i )]]←EQ(Σ i≠j [[c i,j ]],[[n-1]]) and set the result of the calculation as the flag [[z(x i )]].

[0069] Here, EQ([[a]], [[b]]) is a function that outputs [[1]] when a=b, and outputs [[0]] otherwise.

[0070] <Maximum value calculation unit 4>

[0071] The maximum value calculation unit 4 receives the flag [[z(x i )]].

[0072] The maximum value calculation unit 4 uses [[z(x i )]] to calculate the maximum value [[y]] (step S4).

[0073] For example, the maximum value calculation unit 4 calculates Σ i∈[1,n] ([[x i ]]×[[z(x i )]]), set the calculation result to the maximum value [[y]].

[0074] In the conventional method, since the maximum value is updated sequentially from the set of hidden values ​​while the maximum value is maintained, the number of comparison levels becomes θ(n). In contrast, according to the first embodiment, the number of comparison levels can be 1 by performing comparison once. Thus, the processing time for calculating the hidden value of the maximum value and the hidden value of the flag of whether it is the maximum value from the set of hidden values ​​of size n can be reduced.

[0075] [Second embodiment]

[0076] The second embodiment of the secret maximum value calculation device and method is the following device and method, that is, with the number of comparison levels being 2, according to the set of hidden values ​​X = {[[x1]], [[x2]], ..., [[x n ]]}, to calculate the maximum hidden value [[y]] with respect to the predetermined order, and the hidden value [[z(x i )]] for calculation.

[0077] The notation representing the input, output, and processing of the secret maximum value calculation device and method according to the second embodiment can be described as follows.

[0078] Input: X = {[[x1]],...,[[x n ]]}

[0079] Output: [[y]],[[z(x1)]],...,[[z(x n )]]

[0080] Notation: [[y]],[[z(x1)]],...,[[z(x n )]]←f1([[x1]],...,[[x n ]])

[0081] like Figure 3As shown, the secret maximum value calculation device of the second embodiment includes, for example, an output unit 1, a dividing unit 5, a secret maximum value calculation device 6, and a flag calculation unit 3.

[0082] Regarding the secret maximum value calculation method, for example, the following is performed by each component of the secret maximum value calculation device: Figure 4 The processing from step S1 to step S3 shown is implemented.

[0083] The following describes the various components of the secret maximum value calculation device.

[0084] <Output section 1>

[0085] The set X={[[x1]],[[x2]],...,[[x n ]]}. n is a specified positive integer.

[0086] When n=1, the output unit 1 outputs [[x1]] and [[1]] as the maximum concealed value [[y]] and the flag [[z(x1)]], respectively (step S1).

[0087] When n is not 1, the following processing of step S5 and subsequent steps is performed.

[0088] <Division 5>

[0089] The segmentation unit 5 receives as input the set X={[[x1]],[[x2]],...,[[x n ]]}.

[0090] The dividing unit 5 divides X into two or more partial sets (step S5).

[0091] The obtained two or more partial sets are output to the secret maximum value calculation device 6.

[0092] For example, the dividing unit 5 divides X into θ(n 2 / 3 ) of the partial sets. More specifically, the division unit 5 divides X into L = ┌n 2 / 3 ┐Partial set X1,...,X L . ┌n 2 / 3 ┐ is n 2 / 3 Here, (|X i |≥1(i∈[1,L]),∪ i∈[1,L] X i =X, For example, the dividing unit 5 calculates 1=s0. <s1<···<s L =n+1 such s i (i∈[0,L]), let X i={[[x s_(i-1) ]],...,[[x s_i-1 ]]}(i∈[1,L]). Here, the subscript s_(i-1) of x means s i-1 In addition, the subscript s_i-1 of X means s i -1.

[0093] <Secret Maximum Calculation Device 6>

[0094] The two or more partial sets obtained by the dividing unit 5 are input to the secret maximum value calculation device 6 .

[0095] The secret maximum calculation device 6 performs processing on each of more than two partial sets, calculates the hidden value and flag of the maximum value corresponding to each partial set, and processes the set of maximum values ​​corresponding to each partial set, calculates the maximum value [[y]] and the flag of each partial set (step S6).

[0096] The secret maximum value calculation device 6 is the secret maximum value calculation device of the first embodiment. If the notation of the secret maximum value calculation device of the first embodiment is used, the processing of the secret maximum value calculation device 6 can be described as follows.

[0097] [[y i ]],[[z(x s_(i-1) )]],...,[[z(x s_i-1 )]]←f0([[x s_(i-1) ]],...,[[x s_i-1 ]])(i∈[1,L])

[0098] [[y]],[[z(y1)]],...,[[z(y L )]]←f0([[y1]],...,[[y L ]])

[0099] That is, the secret maximum value calculation device 6 performs the operation of converting X=[[x s_(i-1) ]],...,[[x s_i-1 ]] takes as input and outputs [[y i ]],[[z(x s_(i-1) )]],...,[[z(x s_i-1 )]], and then [[y1]],...,[[y L ]] takes as input and outputs [[y]], [[z(y1)]], ..., [[z(y L )]]’s processing.

[0100] The calculated hidden value of the maximum value corresponding to each partial set i [[y i ]] and the symbol [[z(x s_(i-

[0101] 1) )]],...,[[z(x s_i-1 )]], and the calculated maximum value [[y]] and the label of each partial set [[z(y1)]],...,[[z(y L )]] is output to the flag calculation unit 3.

[0102] <Flag calculation unit 3>

[0103] The symbol calculation unit 3 receives the symbol [[z(x s_(i-1) )]],...,[[z(x s_i-1 )]] and the symbols [[z(y1)]],...,[[z(y L )]].

[0104] The flag calculation unit 3 calculates a flag obtained by multiplying the calculated flag by the flag of each partial set (step S3).

[0105] For example, the label calculation unit 3 performs [[z(x j )]]←[[z(x j )]]×[[z(y i )]](j∈[s i-1 ,s i -1]) such processing.

[0106] According to the second embodiment of the secret maximum value calculation device and method, the number of comparison levels is 2, but the total number of comparisons can be set to Θ(n 4 / 3 Thus, the processing time for calculating the maximum value hidden value and the hidden value of the flag of whether it is the maximum value from the set of hidden values ​​of size n can be reduced.

[0107] [Third Embodiment]

[0108] The third embodiment of the secret maximum value calculation device and method is as follows: the number of comparison levels is k+1, according to the set of hidden values ​​X = {[[x1]], [[x2]], ..., [[x n ]]}, to calculate the maximum hidden value [[y]] with respect to the predetermined order, and the hidden value [[z(x i )]] for calculation.

[0109] The notation for representing the input, output, and processing of the secret maximum value calculation device and method of the third embodiment can be described as follows: When k=1, the description is the same as that of the second embodiment.

[0110] Input: X = {[[x1]],...,[[x n ]]}

[0111] Output: [[y]],[[z(x1)]],...,[[z(x n )]]

[0112] Notation: [[y]],[[z(x1)]],...,[[z(x n )]]←f k ([[x1]],...,[[x n ]])

[0113] like Figure 5 As shown, the secret maximum value calculation device of the third embodiment includes, for example, an output unit 1, a dividing unit 5, a secret maximum value calculation device 6, a secret maximum value calculation device 7, and a flag calculation unit 3.

[0114] Regarding the secret maximum value calculation method, for example, the following is performed by each component of the secret maximum value calculation device: Figure 6 The processing from step S1 to step S3 shown is implemented.

[0115] The following describes the various components of the secret maximum value calculation device.

[0116] <Output section 1>

[0117] The set X={[[x1]],[[x2]],...,[[x n ]]}. n is a specified positive integer.

[0118] When n=1, the output unit 1 outputs [[x1]] and [[1]] as the maximum secret value [[y]] and the flag [[z(x1)]], respectively (step S1).

[0119] When n is not 1, the following processing of step S5 and subsequent steps is performed.

[0120] <Division 5>

[0121] The segmentation unit 5 receives as input the set X={[[x1]],[[x2]],...,[[x n ]]}.

[0122] The dividing unit 5 divides X into two or more partial sets (step S5).

[0123] The obtained two or more partial sets are output to the secret maximum value calculation device 6.

[0124] For example, split X into L = ┌n^(2 k / (2 k+1 -1)┐partial set X1,...,X L ┌n^(2 k / (2 k+1 -1)┐ is n^(2 k / (2 k+1 -1). Here, (|X i |≥1(i∈[1,L]),∪ i∈[1,L] X i =X, For example, the dividing unit 5 calculates 1=s0. <s1<···<s L =n+1 such s i (i∈[0,L]), let X i ={[[x s_(i-1) ]],...,[[x s_i-1 ]]}(i∈[1,L]). Here, the subscript s_(i-1) of x means s i-1 In addition, the subscript s_i-1 of X means s i -1.

[0125] Thus, in the mth recursion, X is divided into n^(2 k+1-m / (2 k+2-m -1) partial collection.

[0126] <Secret Maximum Calculation Device 6>

[0127] The two or more partial sets obtained by the dividing unit 5 are input to the secret maximum value calculation device 6 .

[0128] The secret maximum value calculation device 6 performs processing on each of the two or more partial sets, and calculates the confidentiality value and flag of the maximum value corresponding to each partial set (step S6).

[0129] The secret maximum value calculation device 6 is the secret maximum value calculation device of the third embodiment. If the notation of the secret maximum value calculation device of the third embodiment is used, the processing of the secret maximum value calculation device 6 can be described as follows. In this way, the secret maximum value calculation device of the third embodiment performs processing recursively.

[0130] [[y i ]],[[z(x s_(i-1) )]],...,[[z(x s_i-1)]]←f k-1 ([[x s_(i-1) ]],...,[[x s_i-1 ]])(i∈[1,L])

[0131] That is, the secret maximum value calculation device 6 performs the operation of converting X=[[x s_(i-1) ]],...,[[x s_i-1 ]] takes as input and outputs [[y i ]],[[z(x s_(i-1) )]],...,[[z(x s_i-1 )]]’s processing.

[0132] The calculated hidden value of the maximum value corresponding to each partial set i [[y i ]] and the symbol [[z(x s_(i-1) )]],...,[[z(x s_i-1 )]], is output to the secret maximum calculation device 7.

[0133] <Secret Maximum Calculation Device 7>

[0134] The secret maximum value calculation device 7 is input with the maximum value [[y i ]] and the symbol [[z(x s_(i-1) )]],...,[[z(x s_i-1 )]].

[0135] The secret maximum value calculation device 7 processes the set of maximum values ​​corresponding to each partial set, and calculates the maximum value [[y]] and the flag of each partial set (step S7).

[0136] The secret maximum value calculation device 7 is the secret maximum value calculation device of the first embodiment. If the notation of the secret maximum value calculation device of the first embodiment is used, the processing of the secret maximum value calculation device 7 can be described as follows.

[0137] [[y]],[[z(y1)]],...,[[z(y L )]]←f0([[y1]],...,[[y L ]])

[0138] That is, the secret maximum value calculation device 7 performs the operation of converting [[y1]], ..., [[y L ]] takes as input and outputs [[y]], [[z(y1)]], ..., [[z(y L )]]’s processing.

[0139] The calculated labels for each partial set are [[z(y1)]],...,[[z(y L )]] is output to the flag calculation unit 3.

[0140] <Flag calculation unit 3>

[0141] The symbol calculation unit 3 receives the symbol [[z(x s_(i-1) )]],...,[[z(x s_i-1 )]], the symbol [[z(y1)]], ..., [[z(y L )]].

[0142] The flag calculation unit 3 calculates a flag obtained by multiplying the calculated flag by the flag of each partial set (step S3).

[0143] For example, the label calculation unit 3 performs [[z(x j )]]←[[z(x j )]]×[[z(y i )]](j∈[s i-1 ,s i -1]) such processing.

[0144] According to the secret maximum value calculation device and method of the third embodiment, the number of comparison levels becomes k+1, but the total number of comparisons can be set to Θ(n^(1+1 / (2 k+1 Thus, the processing time for calculating the maximum value hidden value and the hidden value of the flag of whether it is the maximum value from the set of hidden values ​​of size n can be reduced.

[0145] [Modifications]

[0146] Although the embodiments of the present invention have been described above, the specific configuration is not limited to these embodiments, and appropriate design changes and the like are naturally included in the present invention without departing from the gist of the present invention.

[0147] The various processes described in the embodiments may be executed not only in time series according to the order described but also in parallel or individually according to the processing capability or need of a device executing the processes.

[0148] For example, data exchange between components of the secret maximum value calculation device may be performed directly or via a storage unit (not shown).

[0149] [Program, recording medium]

[0150] When the various processing functions in the above-described devices are implemented by a computer, the processing contents of the functions that each device should have are described by a program. Then, by executing the program on the computer, the various processing functions in the above-described devices are implemented on the computer. For example, the above-described various processing functions can be implemented by having the program to be executed read into a computer. Figure 7 The recording unit 2020 of the computer shown is implemented by operating the control unit 2010, the input unit 2030, the output unit 2040, etc.

[0151] The program describing the processing contents can be recorded in a computer-readable recording medium. The computer-readable recording medium may be any medium such as a magnetic recording device, an optical disk, a magneto-optical recording medium, or a semiconductor memory.

[0152] In addition, the program can be circulated by selling, transferring, or lending a portable recording medium such as a DVD or CD-ROM on which the program is recorded. Furthermore, the program can also be stored in a storage device of a server computer and forwarded from the server computer to other computers via a network, thereby circulating the program.

[0153] The computer executing such a program, for example, first temporarily stores the program stored in a portable recording medium or the program forwarded from a server computer in its own storage device. Then, when executing the process, the computer reads the program stored in its own storage device and executes the process according to the read program. In addition, as another execution mode of the program, the computer can also directly read the program from the portable storage medium and execute the process according to the program, and can also execute the process according to the received program in sequence whenever the program is forwarded from the server computer to the computer. In addition, it can also be configured so that the program is not forwarded from the server computer to the computer, but the processing function is realized only by the execution instruction and the result acquisition, that is, the above-mentioned process is executed by the so-called ASP (Application Service Provider, Application Service Provider) type service. In addition, in the program of this method, it is set to include information used for the processing of the electronic computer and information in accordance with the program (not a direct instruction to the computer, but data with the nature of the processing of the computer, etc.).

[0154] In this embodiment, the present device is configured by executing a predetermined program on a computer, but at least a part of the processing contents may be realized only on hardware.

[0155] Description of symbols

[0156] 1 Output section

[0157] 2Comparison

[0158] 3. Logo calculation unit

[0159] 4 Maximum value calculation unit

[0160] 5 Division

[0161] 6 Secret Maximum Calculation Device

[0162] 7. Secret maximum value calculation device.

Claims

1. A secret maximum value calculation device, wherein: Let the set X = {[[x1]],[[x2]],...,[[x n ]]},in, [[x1]],[[x2]],...,[[x n ]] are x1, x2, ..., x n The hidden value of n is a specified positive integer. The secret maximum value calculation device comprises: The output unit, when n=1, outputs [[x1]] and [[1]] as the maximum hidden value [[y]] and the flag [[z(x1)]], respectively; The comparison unit, when n is not 1, compares the elements of X For each of them, calculate the comparison result which is greater in the specified order; The flag calculation unit takes the comparison result calculated by the comparison unit as input, and for each [[x i ]], calculate the value of each [[x i ]] If all the comparison results are "large", set the calculated value as the flag [[z(x i )]];as well as The maximum value calculation unit uses the [[z(x i )]], calculate the maximum value [[y]], Will be at x i ≤x j Let LE(x) be a function that outputs [[1]] when the condition is true and [[0]] when the condition is false. i ,x j ), The comparison unit performs LE(x) for each (i, j). i ,x j ) and the result of the calculation [[c i,j ]] is set as the comparison result, where i,j∈[1,n], and i <j, The flag calculation unit performs 1-[[c j,i ]], and set the result of the calculation to [[c i,j ]]; for each i, perform Π i≠j [[c i,j ]], and set the result of the calculation as the flag [[z(x i )]], where i,j∈[1,n] and i>j, The maximum value calculation unit calculates Σ i∈[1,n] ([[x i ]]×[[z(x i )]]), and set the result of the calculation to the maximum value [[y]].

2. A secret maximum value calculation device, wherein: Let the set X = {[[x1]],[[x2]],...,[[x n ]]},in, [[x1]],[[x2]],...,[[x n ]] are x1, x2, ..., x n The hidden value of n is a specified positive integer. The secret maximum value calculation device comprises: The output unit, when n=1, outputs [[x1]] and [[1]] as the maximum hidden value [[y]] and the flag [[z(x1)]], respectively; The comparison unit, when n is not 1, compares the elements of X For each of them, calculate the comparison result which is greater in the specified order; The flag calculation unit takes the comparison result calculated by the comparison unit as input, and for each [[x i ]], calculate the value of each [[x i ]] If all the comparison results are "large", set the calculated value as the flag [[z(x i )]];as well as The maximum value calculation unit uses the [[z(x i )]], calculate the maximum value [[y]], Will be at x i ≤x j Let LE(x) be a function that outputs [[1]] when the condition is true and [[0]] when the condition is false. i ,x j ), The comparison unit performs LE(x) for each (i, j). i ,x j ) and the result of the calculation [[c i,j ]] is set as the comparison result, where i,j∈[1,n], and i <j, Let EQ([[a]],[[b]]) be a function that outputs [[1]] when a=b and [[0]] when it is not the case. The flag calculation unit performs 1-[[c j,i ]], and set the result of the calculation to [[c i,j ]]; for each i, perform [[z(x i )]]←EQ(Σ i≠j [[c i,j ]],n-1) and set the result of the calculation as the flag [[z(x i )]], where i,j∈[1,n] and i>j, The maximum value calculation unit calculates Σ i∈[1,n] ([[x i ]]×[[z(x i )]]), and set the result of the calculation to the maximum value [[y]].

3. A secret maximum calculation system, wherein: Let the set X = {[[x1]],[[x2]],...,[[x n ]]}, where [[x1]], [[x2]], ..., [[x n ]] are x1, x2, ..., x n The hidden value of n is a specified positive integer. The secret maximum value calculation system includes: The output unit, when n=1, outputs [[x1]] and [[1]] as the maximum value [[y]] and the flag [[z(x1)]], respectively; A partitioning part, which partitions X into two or more partial sets; The secret maximum value calculation device of claim 1 or claim 2 processes each of the two or more partial sets to calculate the hidden value and the flag of the maximum value corresponding to each partial set, and processes the set of maximum values ​​corresponding to each partial set to calculate the maximum value [[y]] and the flag of each partial set; and The flag calculation unit calculates a flag obtained by multiplying the calculated flag by the flag of each of the partial sets.

4. A secret maximum value calculation system, which calculates the maximum value [[y]] of the hidden values ​​contained in the set of hidden values ​​inputted and a flag indicating whether each hidden value is the maximum value, wherein: Let the set X = {[[x1]],[[x2]],...,[[x n ]]}, where [[x1]], [[x2]], ..., [[x n ]] are x1, x2, ..., x n The hidden value of n is a specified positive integer. The secret maximum value calculation system comprises: an output unit that, when n=1, outputs [[x1]] and [[1]] as the maximum hidden value [[y]] and the flag [[z(x1)]], respectively; and The division part divides X into two or more partial sets. The secret maximum value calculation system processes each of the two or more partial sets, calculates the hidden value and the flag of the maximum value corresponding to each partial set, The secret maximum value calculation system also includes: The secret maximum value calculation device of claim 1 or claim 2 processes the set of maximum values ​​corresponding to each partial set, calculates the maximum value [[y]] and the sign of each partial set; and The flag calculation unit calculates a flag obtained by multiplying the calculated flag by the flag of each of the partial sets.

5. A secret maximum calculation method, wherein: Let the set X = {[[x1]],[[x2]],...,[[x n ]]},in, [[x1]],[[x2]],...,[[x n ]] are x1, x2, ..., x n The hidden value of n is a specified positive integer. The secret maximum value calculation method comprises: an output step, in the case of n=1, the output unit outputs [[x1]] and [[1]] as the maximum hidden value [[y]] and the flag [[z(x1)]], respectively; In the comparison step, when n is not 1, the comparison unit compares the elements of X. For each of them, calculate the comparison result which is greater in the specified order; In the flag calculation step, the flag calculation unit takes the comparison result calculated by the comparison unit as input, and calculates the flag calculation result for each [[x i ]] and calculate the same as the [[x i ]] If all the comparison results are "large", set the calculated value as the flag [[z(x i )]];as well as The maximum value calculation step uses the maximum value calculation unit [[z(x i )]], calculate the maximum value [[y]], Will be at x i ≤x j Let LE(x) be a function that outputs [[1]] when the condition is true and [[0]] when the condition is false. i ,x j ), In the comparison step, the comparison unit performs LE(x i ,x j ) and the result of the calculation [[c i,j ]] is set as the comparison result, where i,j∈[1,n], and i <j, In the flag calculation step, the flag calculation unit performs 1-[[c j,i ]], and set the result of the calculation to [[c i,j ]]; for each i, perform Π i≠j [[c i,j ]], and set the result of the calculation as the flag [[z(x i )]], where i,j∈[1,n] and i>j, In the maximum value calculation step, the maximum value calculation unit calculates Σ i∈[1,n] ([[x i ]]×[[z(x i )]]), and set the result of the calculation to the maximum value [[y]].

6. A method for calculating the maximum value of a secret, wherein: Let the set X = {[[x1]],[[x2]],...,[[x n ]]},in, [[x1]],[[x2]],...,[[x n ]] are x1, x2, ..., x n The hidden value of n is a specified positive integer. The secret maximum value calculation method comprises: an output step, in the case of n=1, the output unit outputs [[x1]] and [[1]] as the maximum hidden value [[y]] and the flag [[z(x1)]], respectively; In the comparison step, when n is not 1, the comparison unit compares the elements of X. For each of them, calculate the comparison result which is greater in the specified order; In the flag calculation step, the flag calculation unit takes the comparison result calculated by the comparison unit as input, and calculates the flag calculation result for each [[x i ]] and calculate the same as the [[x i ]] If all the comparison results are "large", set the calculated value as the flag [[z(x i )]];as well as The maximum value calculation step uses the maximum value calculation unit [[z(x i )]], calculate the maximum value [[y]], Will be at x i ≤x j Let LE(x) be a function that outputs [[1]] when the condition is true and [[0]] when the condition is false. i ,x j ), In the comparison step, the comparison unit performs LE(x i ,x j ) and the result of the calculation [[c i,j ]] is set as the comparison result, where i,j∈[1,n], and i <j, Let EQ([[a]],[[b]]) be a function that outputs [[1]] when a=b and [[0]] when it is not the case. In the flag calculation step, the flag calculation unit performs 1-[[c j,i ]], and set the result of the calculation to [[c i,j ]]; for each i, perform [[z(x i )]]←EQ(Σ i≠j [[c i,j ]],n-1) and set the result of the calculation as the flag [[z(x i )]], where i,j∈[1,n] and i>j, In the maximum value calculation step, the maximum value calculation unit calculates Σ i∈[1,n] ([[x i ]]×[[z(x i )]]), and set the result of the calculation to the maximum value [[y]].

7. A computer program product, comprising a computer program for causing a computer to function as each part of the secret maximum value calculation device of claim 1 or claim 2.

Citation Information

Patent Citations

  • Homomorphically encrypted private data protection based editing distance calculation system

    CN105488422A

  • Input person's device, computation assisting device, device, secret computing device, and program

    JP2019144405A