Secret computing device, secret computing method, and computer program product
By calculating the difference ft(x)-f't(x) between the function ft(x) and its approximate function f't(x) in the secret calculation and shifting it to the right, the problems of overflow and precision reduction in the secret calculation are solved, and high-precision calculation results are achieved.
Patent Information
- Application Number
- CN202080093085.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-01-20
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2040-01-20
AI Technical Summary
In secret calculations, overflow is prone to occur when shifting to the right or division based on public values, resulting in incorrect calculations, and reducing the decimal bit allocation to prevent overflow will lead to reduced accuracy.
By secretly calculating using the secret dispersion value [x] of the real number x, the secret dispersion value of the difference ft(x)-f't(x) between the function ft(x) and its approximate function f't(x), and shift it to the right by secret calculation, maintaining high precision and suppressing overflow.
It realizes maintaining high accuracy and suppressing overflow in secret computing, solving hardware implementation problems and ensuring the accuracy of calculation results.
Smart Images

Figure CN114981858B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to secure computation. Background Art
[0002] In recent years, advanced statistical or machine learning based on secure computation has been actively studied. However, these operations basically involve calculations of elementary function groups such as reciprocals, square roots, exponents, logarithms, etc., and these calculations go beyond addition, subtraction, and multiplication that secure computation is good at. This is a great obstacle from the viewpoint of practicalizing the applied research of secure computation. In contrast, in Non-Patent Document 1, calculation methods for reciprocals, divisor-concealing division, square roots and their reciprocals, exponents, etc. are proposed.
[0003] Prior Art Documents
[0004] Non-Patent Documents
[0005] Non-Patent Document 1: Ohkura Daisuke, "Design and Implementation of Secure Real Number Operation Group for Implementing Secure Computation AI - Right Shift for Real Numbers with O(|p|) Bit Communication Volume and O(1) Rounds", In CSS2019, 2019. Summary of the Invention
[0006] Problems to be Solved by the Invention
[0007] However, in the case of right shift or division based on public values by secure computation, correct calculation may sometimes be impossible due to overflow. On the other hand, if right shift is performed to prevent overflow, the bit allocation to the fractional domain is reduced and the bit allocation to the integer domain is increased, resulting in reduced precision.
[0008] The present invention has been made in view of the above circumstances, and provides a secure computation technique that maintains high precision and suppresses overflow.
[0009] Means for Solving the Problems
[0010] Let x be a real number, [μ] be the secure dispersion value of μ, n be an integer of 1 or more, t = 0,..., n - 1, and u = 1,..., n - 1, f t (x) be a function with respect to the real number x, f' t (x) be an approximation function of the function f t (x), and the secure dispersion value [f'0(x)] of the approximation function f'0(x) be [f'0(x)] = c 0,0 +c 0,1 [x], and the secure dispersion value [f' u (x) be [f' u(x)] is [f' u (x)] = c u,0 + c u,1 [x] + c u,2 [f0(x)] + … + c u,u+1 [f u-1 (x)], c t,0 is a public value, c t,1 , …, c t,n+1 are coefficients. In the present invention, through the secret calculation of the secret dispersion value [x] of the real number x, the secret dispersion value [f t (x) - f' t (x)] of f t (x) - f' t (x) is obtained. By using the secret calculation of the secret dispersion value [f t (x) - f' t (x)], the (f t (x) - f' t (x)) after shifting (f t (x) - f' t (x)) to the right by a specific number of bits r of the secret dispersion value [f t (x) - f' t (x)] r .
[0011] Advantages of the Invention
[0012] In the present invention, high precision can be maintained and overflow can be suppressed. Description of the Drawings
[0013] Figure 1 is a module of the secret calculation device of the exemplary embodiment.
[0014] Figure 2 is a flowchart for explaining the processing of the first embodiment.
[0015] Figure 3 is a flowchart for explaining the processing of the second embodiment.
[0016] Figure 4 is a flowchart for explaining the processing of the third embodiment.
[0017] Figure 5 is a table exemplifying the parameters for which the calculation related to each elementary function is completed.
[0018] Figure 6 is a block diagram for explaining the hardware structure. Detailed Embodiments
[0019] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0020] In recent years, advanced statistical or machine learning based on secure computation has been actively studied. However, these operations basically involve calculations of elementary functions such as reciprocals, square roots, exponents, logarithms, etc., which go beyond the addition, subtraction, and multiplication that secure computation is good at. Function approximation methods for basic functions such as elementary functions include Taylor expansion. Taylor expansion and the like are polynomials. By approximating any function with a polynomial, the approximate calculation of this function can be performed using the addition, subtraction, and multiplication that secure computation is good at.
[0021] In the following embodiments, an arbitrary function is approximated by a polynomial function f t (x), and then the difference f t (x) between the function f t (x) before right shift and the approximate function f' u (x) of this function f t (x) - f' t (x) is calculated to obtain the secret sharing value [f t (x) - f' t (x)] of (f t (x) - f' t (x)) after right shift, and the secret sharing value [f t (x) - f' t (x)) r of (f t (x) - f' t (x)] r is obtained. By the secure computation of the secret sharing value [f t (x) - f' t (x)] r and the secret sharing value [f' t (x)], the secret sharing value [f t (x)] of the function f t (x) after adding f' t (x) to f t (x) - f' t (x) is obtained. Among them, x is a real number, [μ] is the secret sharing value of μ, n is an integer greater than or equal to 1 (for example, n is an integer greater than or equal to 2), t = 0,..., n - 1, and u = 1,..., n - 1, f t (x) is a function of the real number x, f' t (x) is the approximate function of the function f t (x), and the secret sharing value [f'0(x)] of the approximate function f'0(x) is [f'0(x)] = c 0,0 + c 0,1 [x], and the approximate function f' uThe secret sharing value of (x) [f' u (x)] is [f' u (x)] = c u,0 + c u,1 [x] + c u,2 [f0(x)] + … + [f u-1 (x)], where c t,0 is a public value, and c t,1 , …, c t,n+1 are coefficients. Among them, c t,1 , …, c t,n+1 are values with small effective bit numbers, such that even when multiplied by c t,1 , …, c t,n+1 , there is no need for shifting due to bit overflow. f t (x) - f' t (x) is positive. In addition, by determining the public decimal point position for integers on the ring, it can be regarded as a fixed-point real number. In the embodiment, the fixed-point real number represented on the ring in this way is simply referred to as a real number. The secret sharing method is not limited, and for example, an additive secret sharing method or a Shamir secret sharing method can be exemplified. An example of [μ] is the secret sharing value (share) obtained by linearly sharing the element μ on the quotient ring.
[0022] Here, the magnitude of f t (x) - f' t (x) is smaller than the magnitude of f t (x). Therefore, it is possible to suppress the overflow of the secret sharing value [f t (x) - f' t (x)]. In addition, since the difference f t (x) between the function f t (x) before the right shift calculation and the approximate function f' u (x) of this function f t (x) - f' t (x) is the secret sharing value [f t (x) - f' t (x)], it is possible to maintain high precision. Overflow is a problem based on the performance of the processor implementing the secret calculation, and this method provides a way to solve the problem based on the constraints on this hardware. Thus, this method does not solve a purely mathematical problem but a problem in hardware implementation, and thus has technical features. For example, in a processor where overflow occurs when calculating the secret sharing value [f t (x)] but does not occur when calculating the secret sharing value [f t (x) - f' t (x)], this technical feature is particularly significant.
[0023] The following describes each embodiment.
[0024] [First Embodiment]
[0025] As Figure 1 illustrated, the secret computing device 1 of the first embodiment has secret computing units 11, 12, 13, and a control unit 19. The secret computing device 1 of this embodiment takes the secret-shared value [x] ∈ [L, R) of the real number x as input, performs secret computing, and outputs the secret-shared value [f n-1 (x)] of the target function f n-1 (x). Additionally, L and R are real numbers satisfying L < R, and [L, R) represents a left-closed and right-open interval of L or more and less than R. An example of the function f n-1 (x) is a polynomial that approximates an elementary function. Denote the functions that appear in the process of obtaining f n-1 (x) as f0(x), …, f n-2 (x). Hereinafter, it will be described in detail using Figure 2 details.
[0026] As Figure 2 illustrated, first, the secret computing unit 11 of the secret computing device 1 is input with the secret-shared value [x] (step S10). Next, the control unit 19 is initialized to t = 0 (step S19a).
[0027] The secret computing unit 11 uses at least the secret-shared value [x], and through the secret computing of the product sum, obtains the difference f t (x) - f' t (x) between the function f u (x) and the approximation function f' t (x) of this function f t (x), and outputs the secret-shared value [f t (x) - f' t (x)]. Among them, [f'0(x)] = c 0,0 + c 0,1 [x], for u = 1, …, n - 1, [f' u (x)] = c u,0 + c u,1 [x] + c u,2 [f0(x)] + … + [f u-1 (x)]. For example, at t = 0, the secret computing unit 11 uses the secret-shared value [x], the function f0(x), and c 0,0 , c 0,1 , to obtain the secret-shared value [f0(x) - f'0(x)]. At t = 1, …, n - 1, the secret computing unit 11 uses the secret-shared values [x], [f0(x)], …, [f t(x)] and c 0,0 , c 0,1 , …, c 0,t+1 , to obtain the secret dispersion value [f t (x) - f' t (x)] (step S11).
[0028] The secret dispersion value [f t (x) - f' t (x)] is input to the secret calculation unit 12. The secret calculation unit 12 obtains, through secret calculation using the secret dispersion value [f t (x) - f' t (x)], the secret dispersion value of (f t (x) - f' t (x)) after shifting (f t (x) - f' t (x)) to the right by a specific number of bits r of [f t (x) - f' t (x)] r and outputs it. The secret calculation of the right shift can be implemented through the secret operation of division. Thus, the decimal point position of f t (x) - f' t (x) is moved down to a specific number of digits. This decimal point position is determined in advance (step S12).
[0029] The secret dispersion value [f t (x) - f' t (x)] r is input to the secret calculation unit 13. The secret calculation unit 13 obtains the secret dispersion value [f t (x)] of the function f t (x) and outputs it through the secret calculation using the secret dispersion value [f r (x) - f' t (x)] t and the secret dispersion value [f' t (x)]. That is, the secret calculation unit 13 obtains, through the secret calculation of the addition of the secret dispersion value [f t (x) - f' t (x)] r and the secret dispersion value [f' t (x)], f t (x) - f' t (x) + f' t (x) = f t (x)] of the secret dispersion value [f t (x)] (step S13).
[0030] The control unit 19 determines whether t = n - 1 (step S19b). If t ≠ n - 1, the control unit 19 sets the new t to t + 1 and returns the process to step S11 (step S19c). On the other hand, if t = n - 1, the secret calculation unit 13 outputs the secret dispersion value [f n-1 (x)] (step S19d). That is, for t = 0, …, n - 2, each time the processes of steps S11 to S13 of the secret calculation units 11 to 13 are executed, the secret calculation device 1 sets the new t to t + 1, executes the processes of steps S11 to S13 again, and obtains the secret dispersion value [f n-1 (x)].
[0031] [Second Embodiment]
[0032] As Figure 1 illustrated, the secret calculation device 2 of the second embodiment includes secret calculation units 21, 22, 23, and a control unit 19. The secret calculation device 2 of the second embodiment takes the secret dispersion value [x] ∈ [L, R) of the real number x as an input, performs secret calculation, and outputs the secret dispersion value [f n-1 (x)] of the target function f n-1 (x). In the second embodiment, an example where n = 3, a, b, c, d, f, g, h, i, j, k, s, m, n, o, p, q, α, β, γ, δ, ζ are real numbers, f0(x) = y = δx 2 + ax, f1(x) = z = y(ζy + b) + cx, f2(x) = w = γ(z(αz + d) + y(βx + f) + gx), f'0(x) = ix + j, f'1(x) = ky + sx + m, and f'2(x) = nz + oy + px + q will be described. In addition, the setting method and specific examples for the approximate functions f'0(x) = ix + j, f'1(x) = ky + sx + m, and f'2(x) = nz + oy + px + q will be described later.
[0033] As Figure 3 illustrated, first, the secret calculation unit 21 of the secret calculation device 2 is input with the secret dispersion value [x] (step S10).
[0034] The secret calculation unit 21 obtains the secret dispersion value [f0(x) - f'0(x)] = [y'] = [x(δx + a - i) - j] through secret calculation using the product-sum operation of the secret dispersion value [x] and outputs it (step S21a).
[0035] The secret dispersion value [y'] is input to the secret calculation unit 22. The secret calculation unit 22 obtains y' after shifting y' to the right by a specific number of bits through secret calculation using the secret dispersion value [y'] rSecret dispersion value [y'] r and output it (step S22a).
[0036] Secret dispersion value [y'] r is input to the secret calculation unit 23. The secret calculation unit 23 uses the secret dispersion value [y'] r and the secret calculation of the secret dispersion value [f'0(x)] = [ix + j] to obtain the secret dispersion value [y] = [y' + (ix + j)] and output it (step S23a).
[0037] The secret dispersion value [y] is input to the secret calculation unit 21. The secret calculation unit 21 uses the product-sum operation of the secret dispersion value [x] and the secret dispersion value [y] for secret calculation to obtain the secret dispersion value [f1(x) - f'1(x)] = [z'] = [y(ζy + b - k) + (c - s)x - m] and output it (step S21b).
[0038] The secret dispersion value [z'] is input to the secret calculation unit 22. The secret calculation unit 22 uses the secret calculation of the secret dispersion value [z'] to obtain the secret dispersion value [z'] after shifting z' to the right by a specific number of bits r of the secret dispersion value [z'] r and output it (step S22b).
[0039] Secret dispersion value [z'] r is input to the secret calculation unit 23. The secret calculation unit 23 uses the secret dispersion value [z'] r and the secret calculation of the secret dispersion value [f'1(x)] = [ky + sx + m] to obtain the secret dispersion value [z] = [z' + (ky + sx + m)] and output it (step S23b).
[0040] The secret dispersion value [z] is input to the secret calculation unit 21. The secret calculation unit 21 uses the product-sum operation of the secret dispersion value [x], the secret dispersion value [y], and the secret dispersion value [z] for secret calculation to obtain the secret dispersion value [w' / γ] = [z(αz + d - n / γ) + (βx + f - o / γ)y + (g - p)x + (h - q) / γ] and output it (step S21c).
[0041] The secret dispersion value [w' / γ] is input to the secret calculation unit 22. The secret calculation unit 22 uses the secret calculation of the secret dispersion value [w' / γ] to obtain the w' after shifting the w' obtained by multiplying w' / γ by γ to the right by a specific number of bits r of the secret dispersion value [w'] r and output it (step S22c). For obtaining the secret dispersion value [w'] rThere is no limitation on the processing. For example, the secret calculation unit 22 can also obtain the public value 2 σ / γ, and by using the public value 2 σ / γ and the secret calculation of the public value division of the secret dispersion value [w’ / γ] by [w’ / γ] / (2 σ / γ) to obtain the secret dispersion value [w’] r . Among them, σ is a positive integer representing the right shift amount. Thus, the secret calculation of multiplying by γ and right shift can be performed simultaneously, so the processing cost can be reduced.
[0042] The secret dispersion value [w’] r is input to the secret calculation unit 23. The secret calculation unit 23 uses the secret dispersion value [w’] r and the secret calculation of the secret dispersion value [f'2(x)] = [nz + oy + px + q] to obtain the secret dispersion value [w] = [w’+(nz + oy + px + q)] and output it.
[0043] <Exemplification of the search method for the approximation function>
[0044] The search method for the approximation function before right shift is exemplified below.
[0045] Input: Interval [L, R), function y = δx 2 + ax, z = y(ζy + b) + cx, w = γ(z(αz + d) + y(βx + f) + gx)
[0046] Set the parameters: The search minimum values i min , k min , s min , n min , o min , p min of each discrete coefficient i, k, s, n, o, p, and the search maximum values i max , k max , s max , n max , o max , p max
[0047] Output: The approximation function ix + j of y, the maximum value M of y - (ix + j) y , the approximation function ky + sx + m of z, the maximum value M of z - (ky + sx + m) z , the approximation function nz + oy + px + q of w, the maximum value M of w - (nz + oy + px + q) w
[0048] 1: for i = i minfrom i max do
[0049] 2: Calculate the difference between the maximum and minimum values of y - ix in the interval [L, R).
[0050] 3: Output the i for which the difference between the maximum and minimum values of y - ix in the interval [L, R) is the smallest, and the minimum value j of the difference y - ix at this time, and the difference M y ((the maximum value of (y - ix)) - (the minimum value of (y - ix)), in other words, the variation range of the function value of y - ix).
[0051] 4: foreach (k, s) ∈ {k min ,..., k max} × {s min ,..., s max} do
[0052] 5: Calculate the difference between the maximum and minimum values of z - (ky + sx) in the interval [L, R).
[0053] 6: Output the (k, s) for which the difference between the maximum and minimum values of z - (ky + sx) in the interval [L, R) is the smallest, and the minimum value m of the difference z - (ky + sx) at this time, and the difference M z ((the maximum value of (z - (ky + sx))) - (the minimum value of (z - (ky + sx))), in other words, the variation range of the function value of z - (ky + sx)).
[0054] 7: foreach (n, o, p) ∈ {n min ,..., n max} × {o min ,..., o max} × {p min ,..., p max} do
[0055] 8: Calculate the difference between the maximum and minimum values of z - (nz + oy + px) in the interval [L, R).
[0056] 9: Output the (n, o, p) for which the difference between the maximum and minimum values of z - (nz + oy + px) in the interval [L, R) is the smallest, and the minimum value q of the difference z - (nz + oy + px) at this time, and the difference M w ((the maximum value of (z - (nz + oy + px))) - (the minimum value of (z - (nz + oy + px))), in other words, the variation range of the function value of z - (nz + oy + px)).
[0057] [Third Embodiment]
[0058] As illustrated in the third embodiment, the secret computing device 3 of the third embodiment includes secret computing units 31, 32, 33, and a control unit 19. The secret computing device 3 of the third embodiment takes as input the secret-shared value [x] ∈ [L, R) of the real number x, performs secret computing, and outputs the secret-shared value [f n-1 (x)] of the target function f n-1 (x). In the third embodiment, it is assumed that n = 2, and a, b, c, γ, δ, i, j, k, s, m are real numbers, f0(x) = y = δx 2 + ax, f1(x) = z = γ(y(δy + b) + cx), f'0(x) = ix + j, and f'1(x) = ky + sx + m.
[0059] As Figure 4 illustrated, first, the secret computing unit 31 of the secret computing device 3 is input with the secret-shared value [x] (step S10).
[0060] The secret computing unit 31 performs secret computing using the product-sum operation of the secret-shared value [x] to obtain the secret-shared value [f0(x) - f'0(x)] = [y'] = [x(δx + a - i) - j] and outputs it (step S21a).
[0061] The secret-shared value [y'] is input to the secret computing unit 32. The secret computing unit 32 performs secret computing using the secret-shared value [y'] to obtain the secret-shared value [y'] of [y'] shifted to the right by a specific number of bits r and outputs it (step S22a). r The secret-shared value [y'] is input to the secret computing unit 33. The secret computing unit 33 performs secret computing using the secret-shared value [y']
[0062] and the secret-shared value [f'0(x)] = [ix + j] to obtain the secret-shared value [y] = [y' + (ix + j)] and outputs it (step S23a). r The secret-shared value [y] is input to the secret computing unit 31. The secret computing unit 31 performs secret computing using the product-sum operation of the secret-shared value [x] and the secret-shared value [y] to obtain the secret-shared value [z' / γ] = [y(ζy + b - k / γ) + (c - s / γ)x - m / γ] and outputs it (step S31c). r The secret-shared value [y] is input to the secret computing unit 31. The secret computing unit 31 performs secret computing using the secret-shared value [x] and the secret-shared value [y] to obtain the secret-shared value [z' / γ] = [y(ζy + b - k / γ) + (c - s / γ)x - m / γ] and outputs it (step S31c).
[0063] The secret-shared value [y] is input to the secret computing unit 31. The secret computing unit 31 performs secret computing using the product-sum operation of the secret-shared value [x] and the secret-shared value [y] to obtain the secret-shared value [z' / γ] = [y(ζy + b - k / γ) + (c - s / γ)x - m / γ] and outputs it (step S31c).
[0064] The secret dispersion value [z’ / γ] is input to the secret calculation unit 32. The secret calculation unit 32 obtains z’ after shifting z’ obtained by multiplying z’ / γ by γ to the right by a specific number of bits through secret calculation using the secret dispersion value [z’ / γ] r of the secret dispersion value [z’] r and outputs it (step S32b). The process for obtaining the secret dispersion value [z’] r is not limited. For example, the secret calculation unit 32 can also obtain the public value 2 σ / γ, and through secret calculation of public value division [z’ / γ] / (2 σ / γ) using the public value 2 σ / γ and the secret dispersion value [z’ / γ], obtain the secret dispersion value [z’] r . Thus, the secret calculations of multiplying by γ and shifting to the right can be performed simultaneously, so the processing cost can be reduced.
[0065] The secret dispersion value [z’] r is input to the secret calculation unit 33. The secret calculation unit 33 obtains the secret dispersion value [z] = [z’+(ky + sx + m)] through secret calculation using the secret dispersion value [z’] r and the secret dispersion value [f'1(x)] = [ky + sx + m] and outputs it (step S33b).
[0066] [Parameter examples of calculations completed for each elementary function]
[0067] In Figure 5 are exemplified the parameters of the calculations completed when the function f n-1 (x) is a reciprocal function, square root function, reciprocal of square root function, exponential function, or logarithmic function as an elementary function. In addition, ex, ey, and ez respectively represent the decimal point positions of x, y, and z. Furthermore, e'x, e'y, and e'z respectively represent the decimal point positions of x', y', and z' before shifting to the right. These decimal point positions represent the bit positions of the decimal point counted from the low-order bit. When the value of the bit position is represented starting from 0 and the e1-th bit counted from the low-order bit represents 1, it is denoted that the decimal point position is e1.
[0068] [Hardware structure]
[0069] The secret computing devices 1, 2, and 3 in each embodiment are devices constituted by a general-purpose or dedicated computer including a processor (hardware processor) such as a CPU (central processing unit) and a memory such as a RAM (random-access memory) / ROM (read-only memory). The computer may include one processor or memory, or may include a plurality of processors or memories. The program may be installed in the computer or may be pre-recorded in a ROM or the like. Further, instead of an electronic circuitry that realizes a functional structure by reading a program like a CPU, a part or all of the processing units may be constituted by an electronic circuitry that separately realizes a processing function. Further, the electronic circuitry constituting one device may include a plurality of CPUs.
[0070] Figure 6 is a block diagram illustrating the hardware configurations of the secret computing devices 1, 2, and 3 in each embodiment. As Figure 6As illustrated, the secret computing devices 1, 2, and 3 in this example have a CPU (Central Processing Unit) 10a, an input unit 10b, an output unit 10c, a RAM (Random Access Memory) 10d, a ROM (Read Only Memory) 10e, an auxiliary storage device 10f, and a bus 10g. The CPU 10a in this example has a control unit 10aa, an arithmetic unit 10ab, and a register 10ac, and executes various arithmetic processes in accordance with various programs read into the register 10ac. In addition, the output unit 10c is an output terminal for outputting data, a display, etc., or a LAN card controlled by the CPU 10a that has read a specific program. In addition, the RAM 10d is an SRAM (Static Random Access Memory), a DRAM (Dynamic Random Access Memory), etc., and has a program area 10da for storing a specific program and a data area 10db for storing various data. In addition, the auxiliary storage device 10f is, for example, a hard disk, an MO (Magneto-Optical disc), a semiconductor memory, etc., and has a program area 10fa for storing a specific program and a data area 10fb for storing various data. In addition, the bus 10g connects the CPU 10a, the input unit 10b, the output unit 10c, the RAM 10d, the ROM 10e, and the auxiliary storage device 10f in such a way that they can exchange information. The CPU 10a writes the program stored in the program area 10fa of the auxiliary storage device 10f into the program area 10da of the RAM 10d in accordance with the read OS (Operating System) program. Similarly, the CPU 10a writes the various data stored in the data area 10fb of the auxiliary storage device 10f into the data area 10db of the RAM 10d. And the address on the RAM 10d to which the program or data is written is stored in the register 10ac of the CPU 10a. The control unit 10ab of the CPU 10a sequentially reads out these addresses stored in the register 10ac, reads out the program or data from the area on the RAM 10d indicated by the read address, causes the arithmetic unit 10ab to sequentially execute the arithmetic indicated by the program, and stores the arithmetic result in the register 10ac. Through such a structure, the functional structure of the secret computing devices 1, 2, and 3 is realized.
[0071] The above program can be pre-recorded on a computer-readable recording medium. Examples of computer-readable recording media are non-transitory recording media. Examples of such recording media are magnetic recording devices, optical discs, magneto-optical recording media, semiconductor memories, etc.
[0072] The distribution of the program is carried out, for example, by selling, transferring, lending, etc. removable recording media such as DVDs and CD-ROMs on which the program is recorded. Further, it can also be configured such that the program is pre-stored in the storage device of a server computer, and via a network, the program is forwarded from the server computer to other computers, thereby circulating the program. As described above, a computer that executes such a program, for example, first temporarily stores the program recorded on a removable recording medium or the program forwarded from a server computer in its own storage device. And at the time of execution processing, the computer reads the program stored in its own storage device and executes the processing according to the read program. In addition, as another execution mode of the program, the computer can also directly read the program from a removable recording medium and execute the processing according to the program. Further, each time the program is forwarded from the server computer to the computer, the processing according to the obtained program can be successively executed. In addition, it can also be configured such that, instead of forwarding the program from the server computer to the computer, a so-called ASP (Application Service Provider) type service that realizes a processing function only through its execution instruction and result acquisition is used to execute the above processing. In addition, in the program in this mode, it is assumed to include information equivalent to the program for use by an electronic computer (data, etc. that, although not a direct instruction for a computer, has the nature of prescribing the processing of the computer).
[0073] In each embodiment, the present device is configured by executing a specific program on a computer, but at least a part of these processing contents can also be implemented by hardware.
[0074] <Other modification examples, etc.>
[0075] In addition, the present invention is not limited to the above embodiments. For example, the secret computing devices 1, 2, and 3 in the embodiments can also perform secret computing using the secret sharing value [x] of the real number x to obtain the secret sharing value of f t (x) - f' t (x), and perform secret computing using the secret sharing value of f t (x) - f' t (x) to obtain the secret sharing value of f t (x) - f' t (x), and perform secret computing using the secret sharing value of f t (x) - f't (f after shifting (x) to the right by a specific number of bits t (x) - f' t (x)) r of the secret dispersion value [f t (x) - f' t (x)] r , by using the secret dispersion value [f t (x) - f' t (x)] r and the secret dispersion value [f' t (x)] to secretly calculate the function f t (x) of the secret dispersion value [f t (x)]. Among them, the secret dispersion value [f t (x)] can also be used for other secret calculations before obtaining the secret dispersion value [f t (x) - f' t (x)] r .
[0076] In the above embodiment, the secret calculation unit 11 secretly calculates the secret dispersion value [f t (x) - f' t (x)] through the secret calculation of the sum of products operation using the secret dispersion value [x], but the secret dispersion value [f t (x) - f' t (x)] can also be obtained through secret calculations other than the sum of products operation.
[0077] In addition, the above various processes can not only be executed in time series as described, but also be executed in parallel or separately according to the processing capacity or requirements of the device performing the processing. Obviously, other appropriate changes can be made without departing from the spirit of the present invention.
[0078] Industrial Applicability
[0079] The present invention can be used, for example, in the calculation of elementary functions such as reciprocal functions, square root functions, exponential functions, and logarithmic functions in machine learning or data mining that conceal data and perform secret calculations.
[0080] Reference Numeral Explanation
[0081] 1, 2, 3 Secret calculation devices
[0082] 11, 21, 31, 12, 22, 32, 13, 23, 33 Secret calculation units
Claims
1. A secret computing device, x is a real number, [μ] is the secret sharing value of μ, n is an integer greater than or equal to 1, t = 0, …, n - 1, and u = 1, …, n - 1, f t (x) is a function of the real number x, f' t (x) is the approximate function of the function f t (x). The secret sharing value [f'0(x)] of the approximate function f'0(x) is [f'0(x)] = c 0,0 +c 0,1 [x], the secret sharing value [f' u (x)] of the approximate function f' u (x) is [f' u (x)] = c u,0 +c u,1 [x]+c u,2 [f0(x)]+…+c u,u+1 [f u-1 (x)], c t,0 is a public value, c t,1 , …, c t,n+1 are coefficients. The secret computing device has: The first secret computing unit obtains f t (x) - f' t (x) of the secret dispersion value [f t (x) - f' t (x)]; The second secret computing unit, through the secret computing using the secret dispersion value [f t (x) - f' t (x)], obtains the secret dispersion value [f t (x) - f' t (x)] after shifting (f t (x) - f' t (x)) to the right by a specific number of bits r ; and t (x) - f' t (x)] r ; and The third secret calculation unit, by using the secret dispersion value [f t (x) - f' t (x)] r and the secret calculation of the secret dispersion value [f' t (x)], obtains the secret dispersion value [f t (x)] of the function f t (x).
2. The secret computing device according to claim 1, The first secret calculation unit obtains the secret dispersion value [f t (x) - f' t (x)] through secret calculation using the product-sum operation of the secret dispersion value [x].
3. The secret computing device according to claim 1, n is an integer greater than or equal to 2, For t = 0, …, n - 2, each time the processing of the first secret computing unit, the second secret computing unit, and the third secret computing unit is performed, set t + 1 as the new t, and perform the processing of the first secret computing unit, the second secret computing unit, and the third secret computing unit again to obtain the secret dispersion value [f n-1 (x)].
4. The secret computing device according to claim 1, n=3, a, b, c, d, f, g, h, i, j, k, s, m, n, o, p, q, α, β, γ, δ, ζ are real numbers, f0(x) = y = δx 2 + ax, f1(x) = z = y(ζy + b) + cx, f2(x) = w = γ(z(αz + d) + y(βx + f) + gx), f'0(x) = ix + j, f'1(x) = ky + sx + m, f'2(x) = nz + oy + px + q.
5. The secret computing device according to claim 4, The first secret computing unit obtains the secret dispersion value [f0(x) - f'0(x)] = [y'] = [x(δx + a - i) - j] through secret computing using the product-sum operation of the secret dispersion value [x], The second secret computing unit obtains the secret dispersion value [y’] of y’ after shifting y’ to the right by a specific number of bits through secret computing using the secret dispersion value [y’]. r of the secret dispersion value [y’] r , The third secret calculation unit obtains a secret dispersion value [y] = [y'+(ix + j)] by using the secret dispersion value [y'] r and performing a secret calculation of the secret dispersion value [f'0(x)] = [ix + j]. The first secret computing unit obtains the secret dispersion value [f1(x) - f'1(x)] = [z'] = [y(ζy + b - k) + (c - s)x - m] through secret computing using the secret dispersion value [x] and the product-sum operation of the secret dispersion value [y], The second secret computing unit obtains [z’] which is [z’] shifted to the right by a specific number of bits through secret computing using the secret dispersion value [z’]. r of the secret dispersion value [z’] r , The third secret computing unit obtains a secret dispersion value [y] = [z’+(ky+sx+m)] by using the secret dispersion value [z’] r and performing secret computing on the secret dispersion value [f'1(x)] = [ky+sx+m] The first secret computing unit obtains the secret dispersion value [w' / γ] = [z(αz + d - n / γ) + (βx + f - o / γ)y + (g - p)x + (h - q) / γ] through secret computing using the secret dispersion value [x], the secret dispersion value [y], and the product-sum operation of the secret dispersion value [z], The second secret calculation unit obtains a secret dispersion value [w'] of w' obtained by shifting w' obtained by multiplying w' / γ by γ to the right by a specific number of bits through secret calculation using the secret dispersion value [w' / γ]. r of the secret dispersion value [w'] r , The third secret computing unit obtains a secret dispersion value [w] = [w'+(nz + oy + px + q)] by using the secret dispersion value [w'] r and through secret computing of the secret dispersion value [f'2(x)] = [nz + oy + px + q].
6. The secret computing device according to claim 5, σ is a positive integer, The second secret computing unit obtains the public value 2 σ / γ, and through the use of the public value 2 σ / γ and the secret computation of the public value division of the secret dispersion value [w’ / γ], [w’ / γ] / (2 σ / γ), the secret dispersion value [w’] is obtained r .
7. The secret computing device according to claim 1, n=2, a, b, c, γ, δ, i, j, k, s, m are real numbers, f0(x) = y = δx 2 + ax, f1(x) = z = γ(y(δy + b) + cx), f'0(x) = ix + j, f'1(x) = ky + sx + m.
8. The secret computing device according to claim 7, The first secret computing unit obtains the secret dispersion value [f0(x) - f'0(x)] = [y'] = [x(δx + a - i) - j] through secret computing using the product-sum operation of the secret dispersion value [x], The second secret computing unit obtains the secret dispersion value [y'] of y' after shifting y' to the right by a specific number of bits through secret computing using the secret dispersion value [y'] r of the secret dispersion value [y'] r , The third secret calculation unit obtains the secret dispersion value [y] = [y'+(ix + j)] by using the secret dispersion value [y'] r and the secret calculation of the secret dispersion value [f'0(x)] = [ix + j]. The first secret computing unit obtains the secret dispersion value [z' / γ] = [y(ζy + b - k / γ) + (c - s / γ)x - m / γ] through secret computing using the secret dispersion value [x] and the product-sum operation of the secret dispersion value [y], The second secret calculation unit obtains a secret dispersion value [z'] of z' obtained by shifting z' obtained by multiplying z' / γ by γ to the right by a specific number of bits through secret calculation using the secret dispersion value [z' / γ]. r of the secret dispersion value [z'] r , The third secret computing unit obtains a secret dispersion value [z] = [z'+(ky + sx + m)] by using the secret dispersion value [z'] r and performing secret computing on the secret dispersion value [f'1(x)] = [ky + sx + m].
9. The secret computing device according to claim 8, σ is a positive integer, The second secret computing unit obtains the public value 2 σ / γ, and through the use of the public value 2 σ / γ and the secret computing of the public value division of the secret dispersion value [z’ / γ], [z’ / γ] / (2 σ / γ), the secret dispersion value [z’] is obtained r .
10. A secret computing method, x is a real number, [a] is the secret sharing value of a, n is an integer greater than or equal to 1, t = 0, …, n - 1, and u = 1, …, n - 1, F t (x) is a function of the real number x, f' t (x) is the approximate function of the function f t (x). The secret sharing value [f'0(x)] of the approximate function f'0(x) is [f'0(x)] = c 0,0 +c 0,1 [x], the secret sharing value [f' u (x)] of the approximate function f' u (x) is [f' u (x)] = c u,0 +c u,1 [x]+c u,2 [f0(x)]+…+c u,u+1 [f u-1 (x)], c t,0 is a public value, c t,1 , …, c t,n+1 are coefficients, The secret computing method has: The first secret calculation step, where the first secret calculation unit obtains f t (x) - f' t (x) of the secret dispersion value [f t (x) - f' t (x)]; The second secret calculation step, in which the second secret calculation unit obtains, through secret calculation using the secret dispersion value [f t (x) - f' t (x)], the secret dispersion value [f t (x) - f' t (x)] after shifting (f t (x) - f' t (x)) to the right by a specific number of bits; and r the secret dispersion value [f t (x) - f' t (x)] r ; and The third secret calculation step, where the third secret calculation unit obtains the secret dispersion value [f t (x) - f' t (x)] r and performs a secret calculation on the secret dispersion value [f' t (x)] to obtain the secret dispersion value [f t (x)] of the function f t (x).
11. A computer program product comprising a computer program that causes a computer to function as the secret computing device according to any one of claims 1 to 9.