Secret Computing Device, Secret Computing Method, and Computer Program Product
By using the secret dispersed value [x] of the real number x in secret calculation to handle elementary functions, the problem of difficulty in general handling of multiple elementary functions in the prior art is solved, and efficient general calculation after parameter changes are realized.
Patent Information
- Application Number
- CN202080093455.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-01-20
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2040-01-20
AI Technical Summary
The prior art is difficult to generalize the processing of multiple elementary functions in secret calculations, and different calculation methods need to be selected according to the characteristics of the function.
By operating with the secret dispersion value [x] of the real number x, the secret dispersion value [func(x)] of the approximate value z of the elementary function is obtained, and a general secret calculation of multiple elementary functions is realized through parameter changes.
It realizes that multiple elementary functions can be calculated in a common way through parameter changes alone, simplifying the calculation process and improving efficiency.
Smart Images

Figure CN114981861B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a technique for approximating elementary functions of real numbers in secure computation. Background Art
[0002] In recent years, research on high-level statistics or machine learning based on secure computation has been prevalent. However, most of these operations involve calculations of elementary functions such as reciprocal functions, square root functions, exponential functions, and logarithmic functions, which are beyond the addition, subtraction, and multiplication operations that secure computation is good at. These are a major obstacle in terms of conducting applied research on secure computation.
[0003] In Non-Patent Document 1, a method for calculating elementary functions such as reciprocal, square root and its reciprocal, and exponential function in secure computation is disclosed.
[0004] Prior Art Documents
[0005] Non-Patent Documents
[0006] Non-Patent Document 1: Daisuke Igarashi, "Design and Implementation of Secure Real Number Operation Group for Implementing Secure AI - Real Number Oriented Right Shift with O(|p|) Bit Communication Volume and O(1) Rounds," In CSS2019, 2019 (Daisuke Igarashi, "Design and Installation of Secure Real Number Operation Group for Installing Secure AI - Real Number Oriented Right Shift with O(|p|) Bit Communication Volume and O(1) Rounds," In CSS2019, 2019). Summary of the Invention
[0007] Problems to be Solved by the Invention
[0008] However, in the method described in Non-Patent Document 1, different methods must be selected for application according to the characteristics of the function.
[0009] The present invention has been made in view of such aspects, and an object thereof is to provide a secure computation technique that can be generally applied to many elementary functions only by changing parameters.
[0010] Technical Means for Solving the Problems
[0011] Through secure computation using the secure-shared value [x] of the real number x, the secure-shared value [y]=[δx 2 +ax] is obtained. Through secure computation using the secure-shared value [x] and the secure-shared value [y], the secure-shared value [func(x)]=[y(ζy + b)+cx] of the approximate value z = func(x) of the elementary function of the real number x is obtained and output. Here, x, y, and z are real numbers, a, b, c, δ, and ζ are real number coefficients, and the secure-shared value of · is [·].
[0012] Advantages of the Invention
[0013] In the present invention, many elementary functions can be secretly calculated generically only by changing parameters. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1A FIG. is a block diagram illustrating the secret computing device according to the first embodiment. Figure 1B FIG. is a flowchart for explaining the secret computing method according to the first embodiment.
[0015] Figure 2A FIG. is a block diagram illustrating the secret computing device according to the second embodiment. Figure 2B FIG. is a flowchart for explaining the secret computing method according to the second embodiment.
[0016] Figure 3A FIG. is a block diagram illustrating the secret computing device according to the third embodiment. Figure 3B FIG. is a flowchart for explaining the secret computing method according to the third embodiment.
[0017] Figure 4 FIG. is a block diagram illustrating the secret computing device according to the fourth embodiment.
[0018] Figure 5 FIG. is a flowchart for explaining the secret computing method according to the fourth embodiment.
[0019] Figure 6 FIG. is a table illustrating the parameters after the calculation related to each elementary function is completed.
[0020] Figure 7 FIG. is a block diagram for explaining the hardware structure. DETAILED DESCRIPTION OF THE INVENTION
[0021] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0022] [First Embodiment]
[0023] A description will be given of the first embodiment. In this embodiment, elementary functions are approximated by polynomials to perform secret calculations. Thus, many elementary functions can be secretly calculated generically only by changing parameters. In addition, the elementary functions processed in this method are not limited, but when approximating an exponential function or a logarithmic function with a polynomial, the coefficients of high degrees become very small. In this case, if approximated with only one polynomial, the approximation accuracy of the coefficients decreases. Therefore, in this embodiment, multiple polynomials are used to gradually reduce the degree of high degrees. In addition, an elementary function is a single-variable function of real or complex numbers, and refers to a function obtained by repeatedly performing a finite number of times for creating algebraic functions, exponential functions, logarithmic functions, trigonometric functions, inverse trigonometric functions, and their composite functions. Examples of elementary functions are reciprocal functions, square root functions, exponential functions, logarithmic functions, etc.
[0024] As Figure 1A Illustrated, the secret calculation device 1 of the first embodiment has secret calculation units 11, 12, and a control unit 19. The secret calculation device 1 executes each process under the control of the control unit 19. Hereinafter, x, y, z are real numbers, and a, b, c, δ, ζ are real coefficients. The real coefficients a, b, c, δ, ζ are set according to the desired elementary function. The secret sharing value of · is [·]. The secret sharing method is not limited. For example, an additive secret sharing method or a Shamir secret sharing method can be exemplified. An example of [·] is a secret sharing value (share) obtained by linearly secret sharing the element · on the residue ring. In addition, by determining the publicly known decimal point position for the integers on the ring, it can be regarded as a fixed-point real number. In the embodiment, such a fixed-point real number represented on the ring is simply denoted as a real number.
[0025] As Figure 1B Illustrated, first, the secret sharing value [x] of the real number x is input to the secret calculation device 1 (step S10).
[0026] The secret sharing value [x] is input to the secret calculation unit 11. The secret calculation unit 11 obtains the secret sharing value [y] = [δx 2 + ax] and outputs it through a secret calculation using the secret sharing value [x] (step S11).
[0027] The secret sharing values [x], [y] are input to the secret calculation unit 12. The secret calculation unit 12 obtains the secret sharing value [func(x)] = [y(ζy + b) + cx] of the elementary function approximation value z = func(x) of the real number x through a secret calculation using the secret sharing value [x] and the secret sharing value [y] and outputs it (step S12).
[0028] The secret calculation unit 11 outputs the secret-shared value [func(x)] (step S13).
[0029] [Second Embodiment]
[0030] In the first embodiment, the elementary function was approximated by a fourth-degree polynomial, but in the second embodiment, the elementary function is approximated by an eighth-degree polynomial. Hereinafter, the description will focus on the differences from what has been described so far, and the description of common matters will be simplified.
[0031] As Figure 2A illustrated, the secret computing device 2 of the second embodiment includes secret computing units 11, 22, 23, and a control unit 19. The secret computing device 2 executes each process under the control of the control unit 19. Hereinafter, x, y, z, w are real numbers, and a, b, c, d, f, g, α, β, γ, δ, ζ are real coefficients. The real coefficients a, b, c, d, f, g, α, β, γ, δ, ζ are set according to the desired elementary function.
[0032] As Figure 2B illustrated, first, the secret-shared value [x] of the real number x is input to the secret computing device 2 (step S10).
[0033] The secret-shared value [x] is input to the secret calculation unit 11. The secret calculation unit 11 obtains the secret-shared value [y] = [δx 2 + ax] and outputs it through secret calculation using the secret-shared value [x] (step S11).
[0034] The secret-shared values [x] and [y] are input to the secret calculation unit 22. The secret calculation unit 22 obtains the secret-shared value [z] = [y(ζy + b) + cx] and outputs it through secret calculation using the secret-shared value [x] and the secret-shared value [y] (step S22).
[0035] The secret-shared values [x], [y], and [z] are input to the secret calculation unit 23. The secret calculation unit 23 obtains the secret-shared value [func(x)] = [γ(z(αz + d) + y(βx + f) + gx)] of the elementary function approximation value w = func(x) of the real number x and outputs it through secret calculation using the secret-shared value [x], the secret-shared value [y], and the secret-shared value [z] (step S23).
[0036] The secret computing device 2 outputs the secret-shared value [func(x)] (step S13).
[0037] [Third Embodiment]
[0038] In the third embodiment, the elementary function is approximated by a fourth-degree polynomial in the same manner as in the first embodiment, but it is different from the first embodiment in that the coefficient of the highest degree can be set.
[0039] As Figure 3A illustrated, the secret computing device 3 in the third embodiment includes a secret computing unit 11, 32, and a control unit 19. The secret computing device 3 executes each process under the control of the control unit 19. Hereinafter, x, y, z are real numbers, and a, b, c, γ, δ, ζ are real coefficients. The real coefficients a, b, c, γ, δ, ζ are set according to the desired elementary function.
[0040] As Figure 3B illustrated, first, the secret-shared value [x] of the real number x is input into the secret computing device 3 (step S10).
[0041] The secret-shared value [x] is input into the secret computing unit 11. The secret computing unit 11 obtains the secret-shared value [y]=[δx 2 + ax] by secret computing using the secret-shared value [x] and outputs it (step S11).
[0042] The secret-shared values [x] and [y] are input into the secret computing unit 32. The secret computing unit 32 obtains the secret-shared value [func(x)] = [γ(y(ζy + b)+ cx)] of the approximate value z = func(x) of the elementary function of the real number x by secret computing using the secret-shared value [x] and the secret-shared value [y] and outputs it (step S32).
[0043] The secret computing unit 31 outputs the secret-shared value [func(x)] (step S13).
[0044] [Modifications of the First to Third Embodiments]
[0045] The desired elementary function is approximated by the polynomial function f t (x)= func(x). In addition, the difference f t between the function f t (x) before right shift and the approximate function f' u (x) of this function f t (x)-f' t (x) is calculated for the secret-shared value [f t (x)-f' t (x)], and the secret-shared value [f t (x)-f' t (x)] obtained by right shifting f t (x)-f' t (x) is obtained, that is, (f r (x)-f't (x)-f' t (x)] r , or by secretly distributing the value [f t (x)-f' t (x)] r and the secret distributed value [f' t (x)], and obtain the t (x)-f' t (x) adds f' t (x) and the resulting function f t The secret distributed value of (x) [f t (x)] wherein x is a real number, [·] is the secret shared value of ·, n is an integer greater than 1 (for example, n is an integer greater than 2), t = 0, ..., n-1, u = 1, ..., n-1, f t (x) is a function of real number x, f' t (x) is the function f t (x), approximate function f' 0 The secret distributed value of (x) [f' 0 (x)] is [f' 0 (x)]=c 0,0 +c 0,1 [x], approximate function f' u The secret distributed value of (x) [f' u (x)] is [f' u (x)]=c u,0 +c u,1 [x]+c u,2 [f 0 (x)]+…+[f u-1 (x)],c t,0 is the public value, c t,1 ,…,c t,n+1 is the coefficient. Among them, c t,1 ,…,c t,n+1 is a value with a smaller number of effective bits, even if it is multiplied by c t,1 ,…,c t,n+1 There will be no value that needs to be shifted due to bit overflow. t (x)-f' t (x) is positive. There is no limitation on the secret distribution method, and examples thereof include additive secret distribution method and Shamir secret distribution method. Here, since f t (x)-f' t (x) is smaller than f t (x), so the secret shared value [f t (x)-f' tOverflow of (x). Additionally, due to the difference between the function f t (x) before right shift calculation and the approximate function f' t (x) of this function f u (x), the secret dispersion value of f t (x) - f' t (x) is [f t (x) - f' t (x)], so high precision can be ensured. Overflow is a problem based on the performance of the processor with secret calculation installed, and this method provides a way to solve this problem based on the hardware limitations. Thus, this method has a technical feature in solving the problem of hardware installation rather than a pure mathematical problem. For example, if calculating the secret dispersion value [f t (x)] results in overflow, but in a processor where there is no overflow in the calculation of the secret dispersion value [f t (x) - f' t (x)], its technical feature is significant. Hereinafter, the modified examples of the first to third embodiments will be specifically described.
[0046] "Modified Example of the First Embodiment"
[0047] In the first embodiment, n = 2, a, b, c, δ, i, j, k, s, m are real numbers, f 0 (x) = y = δx 2 + ax, f 1 (x) = z = y(ζy + b) + cx, f 2 (x) = w = γ(z(αz + d) + y(βx + f) + gx), f' 0 (x) = ix + j, f' 1 (x) = ky + sx + m, f' 2 (x) = nz + oy + px + q.
[0048] Input: [x] ∈ [L, R)
[0049] Set parameters: a, b, c, δ, i, j, k, s, m
[0050] Output: Secret dispersion value [func(x)]
[0051] 1: The secret dispersion value [x] is input into the secret calculation device 1 (step S10). The secret calculation unit 11 of the secret calculation device 1 obtains the secret dispersion value [y'] = [x(δx + a - i) - j] through the secret calculation of the product-sum using the secret dispersion value [x], and obtains the secret dispersion value [y'] r of y' with the decimal point position reduced through the secret calculation of right shift r (step S11).
[0052] 2: The secret calculation unit 11 obtains a secret dispersion value [y] = [y'+(ix + j)] through secret calculation using the secret dispersion values [y'] r and [x] (step S11).
[0053] 3: The secret calculation unit 12 obtains a secret dispersion value [z'] = [y(ζy + b - k)+(c - s)x - m] through secret calculation of the product sum using the secret dispersion values [x] and [y], and obtains the secret dispersion value [z'] with the decimal point position reduced through right shift r of [z'] r (step S12).
[0054] 4: The secret calculation unit 12 obtains a secret dispersion value [func(x)] = [z'+(ky + sx + m)] through secret calculation using the secret dispersion value [z'] r (step S12). The secret calculation unit 12 outputs the obtained secret dispersion value [func(x)] (step S13).
[0055] <<Modification Example of the Second Embodiment>>
[0056] In the case of the second embodiment, n = 3, and a, b, c, d, f, g, h, i, j, k, s, m, n, o, p, q, α, β, γ, δ, ζ are real numbers, and f 0 (x)=y = δx 2 + ax, f 1 (x)=z = y(ζy + b)+cx, f 2 (x)=w = γ(z(αz + d)+y(βx + f)+gx), f' 0 (x)=ix + j, f' 1 (x)=ky + sx + m, f' 2 (x)=nz + oy + px + q.
[0057] Input: [x] ∈ [L, R)
[0058] Set parameters: a, b, c, d, f, g, H, i, j, k, s, m, n, o, p, q, α, β, γ, δ, ζ
[0059] Output: Secret dispersion value [func(x)]
[0060] 1: The secret dispersion value [x] is input into the secret computing device 2 (step S10). The secret computing unit 11 of the secret computing device 2 obtains the secret dispersion value [y'] = [x(δx + a - i) - j] through secret computing using the product-sum of the secret dispersion value [x], and obtains y' with the decimal point position reduced through secret computing of right shift. r The secret dispersion value [y'] r (step S11).
[0061] 2: The secret computing unit 11 obtains the secret dispersion value [y] = [y' + (ix + j)] through secret computing using the secret dispersion value [y'] r and [x] (step S11).
[0062] 3: The secret computing unit 22 obtains the secret dispersion value [z'] = [y(ζy + b - k) + (c - s)x - m] through secret computing using the product-sum of the secret dispersion values [x] and [y], and obtains z' with the decimal point position reduced through right shift. r The secret dispersion value [z'] r (step S22).
[0063] 4: The secret computing unit 22 obtains the secret dispersion value [z] = [z' + (ky + sx + m)] through secret computing using the secret dispersion value [z'] r and [x], [y] (step S22).
[0064] 5: The secret computing unit 23 obtains the secret dispersion value [w' / γ] = [z(αz + d - n / γ) + (βx + f - o / γ)y + (g - p)x + (H - q) / γ] through secret computing using the product-sum of the secret dispersion values [x], [y], and [z], performs multiplication operation based on γ and reduction of the decimal point position, and obtains the secret dispersion value [w'] (step S23). The process for obtaining the secret dispersion value [w'] is not limited. However, for example, the secret computing unit 23 can also obtain the public value 2 σ / γ, and obtains the secret dispersion value [w'] through secret computing of public value division operation [w' / γ] / (2 σ / γ) using the public value 2 σ / γ and the secret dispersion value [w' / γ]. Here, σ is a positive integer representing the right shift amount. Thus, the multiplication operation of γ and the secret computing of right shift can be performed simultaneously, so the processing cost can be reduced.
[0065] 6: The secret calculation unit 23 obtains the secret dispersion value [func(x)] = [w’+(nz+oy+px+q)] through secret calculation (step S23). The secret calculation unit 23 outputs the obtained secret dispersion value [func(x)] (step S13).
[0066] <<Modification Example of the Third Embodiment>>
[0067] In the case of the third embodiment, n = 2, a, b, c, γ, δ, i, j, k, s, m are real numbers, and f 0 (x) = y = δx 2 +ax, f 1 (x) = z = γ(y(δy+b)+cx), f’ 0 (x) = ix+j, f’ 1 (x) = ky+sx+m.
[0068] Input: [x] ∈ [L, R)
[0069] Set parameters: a, b, c, γ, δ, i, j, k, s, m
[0070] Output: Secret dispersion value [func(x)]
[0071] 1: The secret calculation device 3 is input with the secret dispersion value [x] (step S10). The secret calculation unit 31 of the secret calculation device 3 obtains the secret dispersion value [y’] = [x(δx+a-i)-j] through secret calculation using the product-sum of the secret dispersion value [x], and obtains the secret dispersion value [y’] with the decimal point position reduced through secret calculation of right shift r of the secret dispersion value [y’] r (step S11).
[0072] 2: The secret calculation unit 31 obtains the secret dispersion value [y] = [y’+(ix+j)] through secret calculation using the secret dispersion value [y’] r (step S11).
[0073] 3: The secret calculation unit 32 obtains [z’ / γ] = [y(ζy+b-k / γ)+(c-s / γ)x-m / γ] through secret calculation using the product-sum of the secret dispersion values [x] and [y] (step S32).
[0074] 4: The secret calculation unit 32 obtains the secret dispersion value [z’] of z’ obtained by multiplying z’ / γ by γ and then right shifting z’ by a specified number of bits through secret calculation using the secret dispersion value [z’ / γ] r of the secret dispersion value [z’] r (step S32). For obtaining the secret dispersion value [z’] rThere is no limitation on the processing of, but for example, the secret calculation unit 32 can also obtain the public value 2 σ / γ, and through the use of the public value 2 σ / γ and the public value division operation of the secret dispersion value [z’ / γ] to perform the secret calculation [z’ / γ] / (2 σ / γ), and obtain the secret dispersion value [z’] r . Thus, the multiplication operation of γ and the secret calculation of the right shift can be performed simultaneously, so the processing cost can be reduced.
[0075] 5: The secret calculation unit 32 obtains the secret dispersion value [func(x)] = [z’+(ky + sx + m)] (step S32) through the secret calculation using the secret dispersion value [z’] r and the secret dispersion values [x], [y]. The secret calculation unit 32 outputs the obtained secret dispersion value [func(x)] (step S13).
[0076] [Fourth Embodiment]
[0077] In the fourth embodiment, the logarithmic function is approximated as an elementary function.
[0078] As Figure 4 illustrated, the secret calculation device 4 of the fourth embodiment has the secret calculation units 45, 46, 47, 48, 49, 410, 411, and any one of the secret calculation devices 1 to 3 or a modified example thereof. Hereinafter, χ is a real number, p is a positive integer, L is an integer of 2 or more, [·] is a secret dispersion value obtained by linearly secretly dispersing the element · on the residue ring modulo p, and {·} is a secret dispersion value obtained by linearly secretly dispersing the element · on the residue ring modulo 2.
[0079] As Figure 5 illustrated, first, the secret dispersion value [χ] of the real number χ is input to the secret calculation device 4 (step S40).
[0080] The secret dispersion value [χ] is input to the secret calculation unit 45. The secret calculation unit 45 obtains the L-bit representation χ 0 …χ L-1 of the real number χ through the secret calculation using the secret dispersion value [χ] and outputs the secret dispersion values {χ 0},…,{χ L-1} (step S45). χ 0 ,…,χ L-1 are integers.
[0081] The secret dispersion values {χ 0},…,{χ L-1}{χ} is input to the secret computing unit 46. The secret computing unit 46 obtains, through secret computing using the secret dispersion values {χ} 0 , …, {χ} L-1 , the secret dispersion values {η} 0 , …, {η} L-1 of the msb flag string η, …, η L-1 where the bit η msb corresponding to the most significant bit (msb) χ msb of the bit string χ 0 …χ L-1 is 1 and the bits η ξ (ξ ∈ {0, …, L - 1}) other than the bit η msb are 0, and outputs them (step S46). Details of step S46 will be described later. 0}, …, {χ L-1} are input to the secret computing unit 46. The secret computing unit 46 obtains, through secret computing using the secret dispersion values {χ} 0 , …, {χ} L-1 , the bit η msb corresponding to the most significant bit (msb) χ msb of the bit string χ 0 …χ L-1 is 1 and the bits η ξ (ξ ∈ {0, …, L - 1}) other than the bit η msb are 0, and outputs them (step S46). Details of step S46 will be described later. 0 …χ L-1 of the bit string χ 0 …χ L-1 is 1 and the bits η ξ (ξ ∈ {0, …, L - 1}) other than the bit η msb are 0, and outputs them (step S46). Details of step S46 will be described later. msb corresponding to the most significant bit (msb) χ msb of the bit string χ 0 …χ L-1 is 1 and the bits η ξ (ξ ∈ {0, …, L - 1}) other than the bit η msb are 0, and outputs them (step S46). Details of step S46 will be described later. msb is 1 and the bits η ξ (ξ ∈ {0, …, L - 1}) other than the bit η msb are 0, and outputs them (step S46). Details of step S46 will be described later. msb other than the bit η msb are 0, and outputs them (step S46). Details of step S46 will be described later. ξ (ξ ∈ {0, …, L - 1}) other than the bit η msb are 0, and outputs them (step S46). Details of step S46 will be described later. 0 , …, η L-1 of the msb flag string η, …, η L-1 where the bit η msb corresponding to the most significant bit (msb) χ msb of the bit string χ 0 …χ L-1 is 1 and the bits η ξ (ξ ∈ {0, …, L - 1}) other than the bit η msb are 0, and outputs them (step S46). Details of step S46 will be described later. 0}, …, {η L-1} and outputs them (step S46). Details of step S46 will be described later.
[0082] The secret dispersion values {χ} 0 , …, {χ} L-1 are input to the secret computing unit 47. The secret computing unit 47 calculates, through secret computing using the secret dispersion values {χ} 0 , …, {χ} L-1 , the secret dispersion values {ρ} i = {ρ} i+1 ∨ χ i and {ρ} L-1 = {χ} L-1 for 0 ≤ i < L - 1 and outputs them (step S47). Details of step S47 will be described later. 0 , …, {χ L-1} are input to the secret computing unit 47. The secret computing unit 47 calculates, through secret computing using the secret dispersion values {χ} 0 , …, {χ} L-1 , the secret dispersion values {ρ} i = {ρ} i+1 ∨ χ i and {ρ} L-1 = {χ} L-1 for 0 ≤ i < L - 1 and outputs them (step S47). Details of step S47 will be described later. 0 , …, {χ L-1} are input to the secret computing unit 47. The secret computing unit 47 calculates, through secret computing using the secret dispersion values {χ} 0 , …, {χ} L-1 , the secret dispersion values {ρ} i = {ρ} i+1 ∨ χ i and {ρ} L-1 = {χ} L-1 for 0 ≤ i < L - 1 and outputs them (step S47). Details of step S47 will be described later. i} = {ρ i+1 ∨ χ i} and the secret dispersion values {ρ} L-1 = {χ} L-1 for 0 ≤ i < L - 1 and outputs them (step S47). Details of step S47 will be described later. L-1} = {χ L-1} and outputs them (step S47). Details of step S47 will be described later.
[0083] The secret dispersion values {ρ} 0 , …, {ρ} L-1 are input to the secret computing unit 48. The secret computing unit 48 obtains, through secret computing using the secret dispersion values {ρ} 0 , …, {ρ} L-1 , the secret dispersion value [θ] of the count value θ representing the number of elements that are 1 in ρ 0 , …, ρ L-1 and outputs it (step S48). 0 , …, {ρ L-1} are input to the secret computing unit 48. The secret computing unit 48 obtains, through secret computing using the secret dispersion values {ρ} 0 , …, {ρ} L-1 , the secret dispersion value [θ] of the count value θ representing the number of elements that are 1 in ρ 0 , …, ρ L-1 and outputs it (step S48). 0 , …, {ρ L-1} are input to the secret computing unit 48. The secret computing unit 48 obtains, through secret computing using the secret dispersion values {ρ} 0 , …, {ρ} L-1 , the secret dispersion value [θ] of the count value θ representing the number of elements that are 1 in ρ 0 , …, ρ L-1 and outputs it (step S48). 0 , …, ρ L-1 in ρ 0 , …, ρ L-1 and outputs it (step S48).
[0084] The secret dispersion values {η} 0 , …, {η} L-1 are input to the secret computing unit 49. The secret computing unit 49 obtains, through secret computing using the secret dispersion values {η} 0 , …, {η} L-1 , the msb flag value ν = η 0 …η obtained by bit - combining the msb flag string η 0 , …, η L-1 . 0 , …, {η L-1} are input to the secret computing unit 49. The secret computing unit 49 obtains, through secret computing using the secret dispersion values {η} 0 , …, {η} L-1 , the msb flag value ν = η 0 …η obtained by bit - combining the msb flag string η 0 , …, η L-1 . 0 , …, {η L-1} are input to the secret computing unit 49. The secret computing unit 49 obtains, through secret computing using the secret dispersion values {η} 0 , …, {η} L-1 , the msb flag value ν = η 0 …η obtained by bit - combining the msb flag string η 0 , …, η L-1 . 0 , …, η L-1 of the msb flag string η 0 , …, η L-1 and outputs it (step S49). 0 …ηL-1 The secret dispersion value [ν] is output (step S49).
[0085] The secret dispersion values [χ] and [ν] are input to the secret calculation unit 410. The secret calculation unit 410 obtains the secret dispersion value [x] = [χ][ν] through secret calculation using the secret dispersion value [χ] and the secret dispersion value [ν] and outputs it (step S410).
[0086] The secret dispersion value [x] is input to any one of the secret calculation devices 1 to 3. Any one of the secret calculation devices 1 to 3 or a modified example thereof that has been input with the secret dispersion value [x] obtains the secret dispersion value [func(x)] through the processing of the first to third embodiments or their modified examples and outputs it (step S420).
[0087] The secret dispersion values [func(x)] and [θ] are input to the secret calculation unit 411. The secret calculation unit 411 obtains [logχ] = [func(x)] - [θ] through secret calculation using the secret dispersion value [func(x)] and the secret dispersion value [θ] and outputs the result (step S411).
[0088] The secret calculation device 4 outputs the secret dispersion value [logχ] (step S412).
[0089] <Details of steps S46 and S47>
[0090] Input: Secret dispersion values {χ 0}, …, {χ L-1}
[0091] Output: Secret dispersion values {η 0}, …, {η L-1}
[0092] 1: The secret calculation unit 46 sets {ρ i} = {ρ i+1 ∨ χ i} for 0 ≤ i < L - 1.
[0093] 2: The secret calculation unit 46 sets {ρ L-1} = {χ L-1}.
[0094] So far, ρ 0 , …, ρ L-1 become a bit string where the bits below the msb are 1 and the bits higher than the msb are 0, such as 0, 0, 0, 1, 1, …, 1.
[0095] 3: The secret calculation unit 46 sets {η i} = {ρi (XOR)ρ i+1}. Among them, α1(XOR)α2 represents the exclusive OR of α1 and α2.
[0096] 4: The secret calculation unit 46 is set to {η L-1} = {χ L-1}}.
[0097] So far, η 0 , …, η L-1 is like 0, 0, 0, 1, 0, …, 0, where only the bit at the msb position is 1 and the other bits are 0.
[0098] [Fifth Embodiment]
[0099] In the fifth embodiment, the processing in the case where the elementary function is a reciprocal function, a reciprocal function of the square root, a square root function, or an exponential function is illustrated.
[0100] <Example 1: Example of Reciprocal Function>
[0101] In Example 1, the secret sharing value of the reciprocal function value 1 / χ of the real number χ is calculated. Let the positive integer representing the difference between the decimal point position of the bit string of 0.5 when the input real number χ is represented in binary and the highest bit (msb) of χ be e, and the real number χ is deformed as follows.
[0102] [Mathematical Formula 1]
[0103]
[0104] That is, multiply by 2 e , normalize it to the interval [0.5, 1), and when finding the reciprocal
[0105] [Mathematical Formula 2]
[0106]
[0107] then multiply by 2 eThe processing is performed through secret calculation. In the reciprocal operation, in the normalization to the standard [0.5, 1), through an 8-degree polynomial approximation, the precision becomes about 21 bits. Since generally 23 bits of precision are required in single precision, it is necessary to introduce a technology to further improve the precision. Usually, the leftmost bit is shifted and normalized to [0.5, 1), but if the bit immediately following the leftmost bit is 0 afterwards (i.e., if the value is in [0.5, 0.75)), it is multiplied by 1.5. Then, since [0.5, 0.75) is shifted to [0.75, 1.125), if it is in [0.75, 1), no action is taken, and correspondingly, it is normalized to [0.75, 1.125). [0.75, 1.125) is a narrower interval than [0.5, 1), so it is an effective technique in the interpolation polynomial approximation where the precision is higher as the approximation interval is narrower.
[0108] 《Reciprocal Normalization Protocol》
[0109] Input: [χ]
[0110] Output: [x], [ν]
[0111] Among them, if the decimal point position when χ is represented in binary is set to ι, then x is the value obtained by moving the msb of χ to the ι position and then multiplying by 1.5 if the bit immediately following the msb of χ is 0. x is normalized to [0.75, 1.125). ν is the value satisfying x = χν.
[0112] 1: The secret computing device obtains the bit string χ of χ represented in binary through bit decomposition based on secret calculation using the secret split value [χ] 0 …χ L-1 of the bit representation χ 0 ,…,χ L-1 of the secret split values {χ 0},…,{χ L-1}.
[0113] 2: The secret computing device obtains, through secret calculation using the secret split values {χ 0},…,{χ L-1}, the msb flag string η where the bit η corresponding to the most significant bit (msb) χ 0 …χ L-1 of the bit string χ msb is 1 and the bits η msb other than the bit η msb are 0 (ξ ∈ {0,…, L - 1}) ξ ,…,η 0 ,…,η L-1 of the secret split values {η 0},…,{ηL-1}. This process is the same as the above-mentioned step S46.
[0114] 3: The secret computing device uses the secret distributed value { 0},…,{χ L-1},{η 0},…,{η L-1} secret computation, in 2≤i <L下得到{ω i}={(¬χ i-2 ∧η i-1 )(XOR)η i}.
[0115] 4: The secret computing device uses the secret distributed value {η 0},…,{η L-1} is calculated by secret, and the secret distributed value {ω 0}={ω 1}={0},{ω L}={¬η L-2 ∧η L-1}. If the bit string x 0 … L-1 If the input bit of the lower 1 bit of the MSB is 1, then the ω of the upper 1 bit of the MSB i is 1. In order to convert {ω 0},{ω 1},{ω 2},…,{ω L-1} are combined by reversing the upper and lower bits. Here, the upper and lower bits are reversed to set the secret distributed value {ω 0},{ω 1},{ω 2},…,{ω L-1}.
[0116] 5: The secret computing device uses a secret distributed value {ω 0},{ω 1},{ω 2},…,{ω L-1} of the secret computation, and {ω L-1},…,{ω 0} are combined to obtain [ν] and output. When ν is multiplied by χ, the MSB of χ is moved to a certain position, and further, if the bit next to the MSB of χ is 0, the result is a number obtained by multiplying 1.5 by χ.
[0117] 6: The secret computing device obtains the secret distributed value [x] = [χ][ν].
[0118] The Countdown Protocol
[0119] Input: [χ]
[0120] Output: [1 / χ]
[0121] 1: The secret computing device obtains the secret share [x] of the value x obtained by normalizing the real number χ to the range [0.75, 1.125) using the reciprocal-based normalization protocol described above, and the secret share [ν] multiplied by the secret share [χ] for this normalization.
[0122] 2: The secret computing device obtains the secret share [func(x)] from the secret share [x] through secret computing. Here, func(x) in Embodiment 1 is a polynomial that approximates the reciprocal function of x. The secret computing device obtains the secret share [w] = [func(x)] using, for example, the method of the first to third embodiments or their modified examples.
[0123] 3: The secret computing device obtains the secret share [w][ν] through secret computing using the secret shares [w] and [ν], and outputs it.
[0124] <Embodiment 2: Example of the reciprocal function of the square root>
[0125] In Embodiment 2, the secret share of the reciprocal function value 1 / √χ of the real number χ is calculated. In the reciprocal function of the square root, normalization to the range [0.5, 1) is performed using the same idea as the above reciprocal function. Here, multiply by √(2 e ) instead of 2 e . In Embodiment 2, the real number χ is transformed as follows.
[0126]
Mathematical formula 3
[0127]
[0128] That is, multiply the real number χ by 2 e for normalization, and find the reciprocal of the square root of 2 e χ
[0129]
Mathematical formula 4
[0130]
[0131] After that, the process of multiplying by √(2 e ) is performed through secret computing.
[0132] 《Normalization protocol for the reciprocal of the square root》
[0133] Input: [χ]
[0134] Output:
[0135] Among them, if the decimal point position in the case where χ is represented by a binary number is set to ι, then x is the value obtained by moving the msb of χ to the ι - 1 position. In Embodiment 2, is a true value indicating whether it is necessary to multiply the calculated value by √2 at the end. ν’ is the power value of 2 to be multiplied at the end.
[0136] 1: The secret computing device obtains the bit string χ of χ represented in binary through bit decomposition of the secret computation based on the secret dispersion value [χ] 0 …χ L-1 in terms of its bit representation χ 0 ,…,χ L-1 and the secret dispersion values {χ 0},…,{χ L-1}.
[0137] 2: The secret computing device obtains L’ = ceil(L / 2). Among them, ceil is the ceiling function.
[0138] 3: The secret computing device obtains the secret dispersion value {χ’ 0},…,{χ’ L-1} through secret computation using the secret dispersion values {χ i}={χ i ∨χ i+1} under 0 ≤ i < floor(L / 2). Among them, floor is the floor function.
[0139] 4: If L is odd, the secret computing device sets {χ’ L’-1}={χ L-1}.
[0140] 5: The secret computing unit obtains, through secret computation using the secret dispersion values {χ’ 0},…,{χ’ L-1}, the secret dispersion values {η 0 …χ’ L-1} corresponding to the most significant bit (msb) χ’ msb of the bit string χ’ msb being 1 and the bits η msb other than the bit η ξ (ξ ∈ {0,…, L’ - 1}) being 0, that is, the msb flag string η 0 ,…,η L-1 and outputs them. This process is the same as the above step S46 where χ 0 is set to χ’ L’-1 and L is set to L’. i and L is set to L’. i is the same as the above step S46.
[0141] 6: The secret computing unit obtains the secret sharing value [ν'] of the msb flag value ν' obtained by bitwise combining the msb flag strings η 0}, …, {η L’-1} through bitwise combination in secret computing using the secret sharing values {η L’-1 , …, η 0} and outputs it.
[0142] 7: The secret computing unit sets {χ” i} = {χ 2i} when 0 ≤ i < floor(L / 2).
[0143] 8: If L is odd, the secret computing unit sets {χ” L’-1} = {χ L-1}.
[0144] 9: The secret computing unit obtains the secret sharing value 0}, …, {χ” L’-1}, {η 0}, …, {η L’-1} through secret computing of the product-sum using the secret sharing values {{χ”
[0145] 10: The secret computing unit transforms the secret sharing value into the secret sharing value and outputs it. is the truth value indicating whether the msb of χ is in the even bit. When the msb of χ is in the even bit, in the case where it is not,
[0146] 11: The secret computing unit obtains the secret sharing value through secret computing using the secret sharing value and outputs it. Among them, is 2χ when , and is χ when .
[0147] "Reciprocal of Square Root Protocol"
[0148] Input: [χ]
[0149] Output: [1 / √χ]
[0150] 1: The secret computing unit obtains the secret sharing value [x] of the value x obtained by normalizing the real number χ to [0.5, 1) using the above reciprocal of square root normalization protocol, and the secret sharing value [ν'] required for the inverse operation of normalization,
[0151] 2: The secret computing unit uses the method of the second embodiment or the third embodiment or a modified example thereof, and through secret computing, obtains the secret-shared value [func(x)] from the secret-shared value [x]. Here, func(x) is a polynomial that approximates the reciprocal function of the square root of x. And in step S23, when γ is replaced by √2γ (step S23’). Similarly, in step S32, when γ is replaced by √2γ (step S32’). The details of the processing in steps S23’ and S32’ will be described later.
[0152] 3: The secret computing unit obtains the secret-shared value [1 / √χ] = [func(x)][ν’] through secret computing using the secret-shared values [func(x)] and [ν’], and outputs it.
[0153] Hereinafter, the processing contents of steps S23’ and S32’ will be exemplified.
[0154] 《In the case of using the method of the second embodiment (step S23’)》
[0155] The secret computing unit executes steps S10, S11, and S22 of the above-described second embodiment for the secret-shared value [x] of the value x normalized to [0.5, 1) as described above. Then, the secret computing unit executes the following processing of step S232 instead of step S23.
[0156] Step S232: The secret computing unit obtains the secret-shared value [func(x)] = [(√2)γ(z(αz + d) + y(βx + f) + gx)] through secret computing using the secret-shared values [x], [y], [z], and outputs it when and obtains the secret-shared value [func(x)] = [γ(z(αz + d) + y(βx + f) + gx)] and outputs it when .
[0157] The secret computing unit executes the processing of step S232 (steps S232a to S232c) as follows, for example.
[0158] The secret computing unit uses the multipliers m 0 = 1, m 1 = √2 and positive integers σ0, σ1, and obtains the public values 2 σ0 / m 0 , 2 σ1 / m 1 and outputs them. Here, σ0 and σ1 respectively represent the multipliers m 0 , m 1The number of bits of the right shift amount required in the case of being larger, that is, a positive integer (step S232a).
[0159] The secret computing device performs a secret computation of the public value division operation using the secret dispersion values [x], [y], [z] and the public value 2 obtained in step S232a σ0 / m 0 、2 σ1 / m 1 of [γ(z(αz + d)+y(βx + f)+gx)] / (2 σ0 / m 0 ), [γ(z(αz + d)+y(βx + f)+gx)] / (2 σ1 / m 1 ), and obtains the secret dispersion value of the value obtained by shifting γ(z(αz + d)+y(βx + f)+gx) to the right by σ0 bits [m 0 γ(z(αz + d)+y(βx + f)+gx)] 0 γ(z(αz + d)+y(βx + f)+gx)] r 、and the secret fractional value of the value obtained by shifting γ(z(αz + d)+y(βx + f)+gx) to the right by σ1 bits [m 1 γ(z(αz + d)+y(βx + f)+gx)] 1 γ(z(αz + d)+y(βx + f)+gx)] r and outputs them (step S232b).
[0160] The secret computing device obtains [m 0 γ(z(αz + d)+y(βx + f)+gx)] r 、[m 1 γ(z(αz + d)+y(βx + f)+gx)] r through a secret computation and obtains the secret dispersion value of and outputs it. That is, the secret computing unit obtains [func(x)] = [γ(z(αz + d)+y(βx + f)+gx)] and outputs it in the case of , and obtains [func(x)] = [(√2)γ(z(αz + d)+y(βx + f)+gx)] and outputs it in the case of (step S232c).
[0161] 《In the case of using the method of the modification of the second embodiment (step S23’)》
[0162] The secret computing unit performs steps S10, S11, and S22 of the modified example of the second embodiment described above on the secret-shared value [x] of the value x that has been normalized to [0.5, 1) as described above. After that, the secret computing unit performs the following processing of step S232' instead of step S23.
[0163] Step S232': The secret computing unit obtains the secret-shared value [w' / γ] = [z(αz + d - n / γ) + (βx + f - o / γ)y + (g - p)x + (H - q) / γ] through secret computing using the product-sum of the secret-shared values [x], [y], [z], and when , performs a multiplication operation based on (√2)γ and a shift of the decimal point position, and when , performs a multiplication operation based on γ and a shift of the decimal point position to obtain the secret-shared value [w']. Further, the secret computing unit obtains the secret-shared value [func(x)] = [w' + (nz + oy + px + q)] through secret computing using the secret-shared values [w'], [x], [y], [z].
[0164] The secret computing unit performs the processing of step S232' (steps S232a' to S232e') as follows, for example.
[0165] The secret computing unit obtains the secret-shared value [w' / γ] = [z(αz + d - n / γ) + (βx + f - o / γ)y + (g - p)x + (H - q) / γ] through secret computing using the product-sum of the secret-shared values [x], [y], [z] (step S232a').
[0166] The secret computing unit uses the multipliers m 0 = 1, m 1 = √2 and positive integers σ0, σ1 to obtain the public values 2 σ0 / m 0 、2 σ1 / m 1 and outputs them (step S232b').
[0167] The secret computing device performs secret computing of public value division operations [w' / γ] / (2 σ0 / m 0 、2 σ1 / m 1 ) using the secret-shared value [w' / γ] and the public values 2 σ0 / γm 0 、[w' / γ] / (2 σ1 / γm 1 ) to obtain m 0The secret sharing value of the value obtained by shifting w’ to the right by σ0 bits [m 0 w’] r and the secret sharing value of the value obtained by shifting w’ to the right by σ1 bits [m 1 w’] 1 w’] r and outputs it (step S232c’).
[0168] The secret computing device obtains, through secret computing using the secret sharing values [m 0 w’] r 、[m 1 w’] r and obtains the secret sharing value of and outputs it. That is, the secret computing unit obtains the secret sharing value [func’(x)] = [w’] and outputs it when , and obtains the secret sharing value [func’(x)] = [(√2)w’] and outputs it when (step S232d’).
[0169] The secret computing unit obtains the secret sharing value [func(x)] = [func’(x)+(nz + oy + px + q)] through secret computing using the secret sharing values [func’(x)], [x], [y], [z] (step S232e’).
[0170] 《In the case of using the method of the third embodiment (step S32’)》
[0171] The secret computing unit performs steps S10 and S11 of the above-mentioned third embodiment on the secret sharing value [x] of the value x normalized to [0.5, 1) as described above. Then, the secret computing unit performs the following processing of step S323 instead of step S32.
[0172] Step S323: The secret computing unit obtains the secret sharing value [func(x)] = [(√2)γ(y(ζy + b)+cx)] and outputs it when through secret computing using the secret sharing values [x], [y], . The secret sharing value [func(x)] = [γ(y(ζy + b)+cx)] is obtained and output when .
[0173] The secret computing unit executes the processing of step S323 as follows, for example (steps 323a to S323c).
[0174] The secret computing unit uses the multiplier m 0 = 1, m1 = √2 and positive integers σ0, σ1, to obtain the public value 2 σ0 / m 0 、2 σ1 / m 1 and output it (step S323a).
[0175] The secret computing device performs a secret computation of the public value division operation using the secret-shared values [x], [y] and the public value 2 σ0 / m 0 、2 σ1 / m 1 obtained in step S323a, [γ(y(ζy + b) + cx)] / (2 σ0 / m 0 ), [γ(y(ζy + b) + cx)] / (2 σ1 / m 1 ), to obtain the secret-shared values of the value obtained by shifting m 0 γ(y(ζy + b) + cx) to the right by σ0 bits, [m 0 γ(y(ζy + b) + cx)] r 、and the secret-shared values of the value obtained by shifting m 1 γ(y(ζy + b) + cx) to the right by σ1 bits, [m 1 γ(y(ζy + b) + cx)] r and output them (step S323b).
[0176] The secret computing device obtains [m 0 γ(y(ζy + b) + cx)] r 、[m 1 γ(y(ζy + b) + cx)] r through secret computation, and obtains the secret-shared value of and outputs it. That is, the secret computing unit obtains [func(x)] = [γ(y(ζy + b) + cx)] and outputs it when , and obtains [func(x)] = [(√2)γ(y(ζy + b) + cx)] and outputs it when (step S323c).
[0177] 《In the case of using the method of the modification of the third embodiment (step S32’)》
[0178] The secret computing unit performs steps S10 and S11 of the modified example of the third embodiment described above on the secret-shared value [x] of the value x obtained by normalizing to [0.5, 1) as described above. After that, the secret computing unit performs the following processing of step S323' instead of step S32.
[0179] Step S323': The secret computing unit obtains [z' / γ] = [y(ζy + b - k / γ) + (c - s / γ)x - m / γ] through secret computing of the product-sum using the secret-shared values [x], [y], . When , perform a multiplication operation based on (√2)γ and a shift of the decimal point position. When , perform a multiplication operation based on γ and a shift of the decimal point position to obtain the secret-shared value [func'(x)]. The secret computing unit 32 obtains the secret-shared value [func(x)] = [func'(x) + (ky + sx + m)] through secret computing using the secret-shared value [func'(x)] and the secret-shared values [x], [y], and outputs it.
[0180] The secret computing unit performs the processing of step S323' (steps S323a' to S323c') as follows, for example.
[0181] The secret computing unit obtains [z' / γ] = [y(ζy + b - k / γ) + (c - s / γ)x - m / γ] through secret computing of the product-sum using the secret-shared values [x], [y] (step S323a').
[0182] The secret computing unit uses the multiplier m 0 = 1, m 1 = √2 and positive integers σ0, σ1 to obtain the public values 2 σ0 / m 0 , 2 σ1 / m 1 and outputs them (step S323b').
[0183] The secret computing unit performs secret computing of the public value division operation [w' / γ] / (2 σ0 / m 0 , 2 σ1 / m 1 ) using the secret-shared value [w' / γ] and the public values 2 σ0 / γm 0 ), [w' / γ] / (2 σ1 / γm 1 ) to obtain the secret fractional value [m 0 w'] of the value obtained by shifting m 0 w' to the right by σ0 bits.r and the secret fractional value of the value obtained by right-shifting m 1 w’ by σ1 bits [m 1 w’] r and output (step S323c’).
[0184] The secret computing device obtains, through secret computing using the secret dispersion value [m 0 w’] r 、[m 1 w’] r and outputs the secret dispersion value of . That is, the secret computing unit obtains the secret dispersion value [func’(x)] = [w’] and outputs it when , and obtains the secret dispersion value [func’(x)] = [(√2)w’] and outputs it when (step S323d’).
[0185] The secret computing unit obtains, through secret computing using the secret dispersion values [func’(x)], [x], and [y], the secret dispersion value [func(x)] = [func’(x)+(ky+sx+m)] and outputs it (step S323e’).
[0186] <Example 3: Example of Square Root Function>
[0187] In Example 3, the secret dispersion value of the square root of the real number χ is calculated. In the reciprocal function of the square root, normalization to [1, 2) is performed using the same idea as the above reciprocal function. In Example 3, the real number χ is transformed as follows.
[0188]
Mathematical Formula 5
[0189]
[0190] That is, the real number χ is multiplied by 2 e for normalization, and the process of finding the square root √(2 e χ) of 2 e χ and then dividing by √(2 e ) is performed through secret computing.
[0191] "Normalization Protocol for Square Root"
[0192] Input: [χ]
[0193] Output:
[0194] Here, if the decimal point position when χ is represented as a binary number is set to ι, then x is the value obtained by moving the msb of χ to the ι position. In Embodiment 3, is the true value indicating whether the calculated value needs to be divided by √2 at the end. ν' is the power of 2 to be multiplied at the end.
[0195] 1: The secret computing device obtains, through bit decomposition of the secret computation using the secret dispersion value [χ], the bit string χ of χ when represented in binary 0 …χ L-1 in terms of its bit representation χ 0 ,…,χ L-1 and the secret dispersion values {χ 0},…,{χ L-1}.
[0196] 2: The secret computing device obtains, through the secret computation using the secret dispersion values {χ 0},…,{χ L-1}, the msb flag string η where the bit η corresponding to the most significant bit (msb) χ of the bit string χ 0 …χ L-1 is 1 and the bits η msb other than the bit η msb are 0 for ξ ∈ {0,…,L - 1}, i.e., η msb …,η ξ and the secret dispersion values {η 0 ,…,η L-1},…,{η 0},…,{η L-1}. This process is the same as the above step S46.
[0197] 3: The secret computing device obtains L' = ceil(L / 2). Here, ceil is the ceiling function.
[0198] 4: The secret computing device obtains, through the secret computation using the secret dispersion values {η 0},…,{η L-1}, the secret dispersion values {ω i} = {η 2i} (XOR) {η 2i+1} for each i < L'. When L is odd, {ω L-1} = {η 2i}.
[0199] 5: The secret computing device obtains the secret dispersion values through the secret computation using the secret dispersion values {η 0},…,{η L-1} In the case where the calculated value needs to be divided by √2 at the end In the case where it is not necessary to divide the calculated value by √2 at the end,
[0200] 6: The secret computing device distributes the secret value transforms it into a secret distributed value
[0201] 7: The secret computing device combines {ω 0}, {ω 1}, {ω 2}, …, {ω L-1} through bit combination of secret calculations using them, combines {ω 0}, …, {ω L’-1} to obtain [ν’] and outputs it.
[0202] 8: The secret computing device combines {η 0}, …, {η L-1} through secret calculations using them, combines {η L-1}, …, {η 0} to obtain [ν] and outputs it.
[0203] 9: The secret computing device obtains the secret distributed value [x] = [χ][ν] through secret calculations using the secret distributed values [χ] and [ν] and outputs it.
[0204] "Square Root Protocol"
[0205] Input: [χ]
[0206] Output: [√χ]
[0207] 1: The secret computing device obtains the secret distributed value [x] of the value x obtained by normalizing the real number χ to [1, 2) and the secret distributed value [ν’] required for the inverse operation of normalization through the above-mentioned square root normalization protocol,
[0208] 2: The secret computing device obtains L’ = ceil(L / 2).
[0209] 3: If l is odd, the secret computing device sets If it is even, the secret computing device sets
[0210] 4: The secret computing unit uses the method of the second embodiment or the third embodiment or a modified example thereof to obtain the secret distributed value [func(x)] from the secret distributed value [x] through secret calculations. Here, func(x) is a polynomial that approximates the square root function of x. In addition, in step S23, when γ is replaced with At , γ is replaced by (Step S23”). Similarly, in Step S32, at , γ is replaced by At , γ is replaced by (Step S32”). The processing details of Steps S23” and S32” will be described later.
[0211] 5: The secret computing unit obtains and outputs the secret-shared value [√χ] = [func(x)][ν’] through secret computing using the secret-shared values [func(x)] and [ν’].
[0212] The following illustrates the processing contents of Steps S23” and S32”.
[0213] 《In the case of using the method of the second embodiment (Step S23”)》
[0214] The secret computing unit executes Steps S10, S11, and S22 of the second embodiment described above for the secret-shared value [x] of the value x normalized to [1, 2) as described above. After that, the secret computing unit executes the following processing of Step S234 instead of Step S23.
[0215] Step S234: The secret computing unit obtains and outputs the secret-shared value at through secret computing using the secret-shared values [x], [y], [z], and outputs the secret-shared value at .
[0216] The secret computing unit executes the processing of Step S234 (Steps S234a to S234c) as follows, for example.
[0217] The secret computing unit uses the multiplier and positive integers σ0 and σ1 to obtain the public values 2 σ0 / m 0 , 2 σ1 / m 1 and outputs them (Step S234a).
[0218] The secret computing device performs secret computing using the secret-shared values [x], [y], [z] and the public values 2 σ0 / m 0 , 2 σ1 / m 1Secret calculation of the public value division operation: [γ(z(αz + d) + y(βx + f) + gx)] / (2 σ0 / m 0 ), [γ(z(αz + d) + y(βx + f) + gx)] / (2 σ1 / m 1 ), and obtains the secret sharing value of the value obtained by shifting [γ(z(αz + d) + y(βx + f) + gx)] to the right by σ0 bits by m 0 [m 0 γ(z(αz + d) + y(βx + f) + gx)] r , and the secret sharing value of the value obtained by shifting [γ(z(αz + d) + y(βx + f) + gx)] to the right by σ1 bits by m 1 [m 1 γ(z(αz + d) + y(βx + f) + gx)] r and outputs them (step S234b).
[0219] The secret calculation device obtains [m 0 γ(z(αz + d) + y(βx + f) + gx)] r , [m 1 γ(z(αz + d) + y(βx + f) + gx)] r through secret calculation using the secret sharing values, and obtains the secret sharing value of and outputs it. That is, the secret calculation unit obtains and outputs it in the case of , and obtains and outputs it in the case of (step S234c).
[0220] "In the case of using the method of the modification of the second embodiment (step S23")"
[0221] The secret calculation unit performs steps S10, S11, and S22 of the modification of the second embodiment described above on the secret sharing value [x] of the value x normalized to [1, 2) as described above. After that, the secret calculation unit performs the following processing of step S234' instead of step S23.
[0222] Step S234': The secret calculation unit obtains the secret sharing value [w' / γ] = [z(αz + d - n / γ) + (βx + f - o / γ)y + (g - p)x + (H - q) / γ] through secret calculation using the product sum of the secret sharing values [x], [y], [z], , and when , performs based on The multiplication operation and the downward shift of the decimal point are performed at to obtain a secretly-shared value [w'] through the multiplication operation and the downward shift of the decimal point based on . Furthermore, the secret computing unit obtains a secretly-shared value [func(x)] = [w'+(nz + oy + px + q)] through secret computing using the secretly-shared values [w'], [x], [y], and [z].
[0223] The secret computing unit executes the processing of step S234' (steps S234a' to S234e') as follows, for example.
[0224] The secret computing unit obtains a secretly-shared value [w' / γ] = [z(αz + d - n / γ)+(βx + f - o / γ)y+(g - p)x+(H - q) / γ] through secret computing of the product sum using the secretly-shared values [x], [y], and [z] (step S234a').
[0225] The secret computing unit uses the multiplier and positive integers σ0 and σ1 to obtain the public values 2 σ0 / m 0 and 2 σ1 / m 1 and outputs them (step S234b').
[0226] The secret computing device performs secret computing of public value division operations [w' / γ] / (2 σ0 / m 0 ), [w' / γ] / (2 σ1 / m 1 ) using the secretly-shared value [w' / γ] and the public values 2 σ0 / γm 0 , 2 σ1 / γm 1 to obtain the secretly-shared values [m 0 w'] 0 of the value obtained by shifting m r w' to the right by σ0 bits and the secretly-shared value [m 1 w'] 1 of the value obtained by shifting m r w' to the right by σ1 bits and outputs them (step S234c')
[0227] The secret computing device obtains [m 0 w'] r and [m 1 w'] r through secret computing using the secretly-shared values of and outputs. That is, the secret computing unit obtains the secret-shared value in the case of and outputs, and obtains the secret-shared value in the case of and outputs (step S234d’).
[0228] The secret computing unit obtains the secret-shared value [func(x)] = [func’(x)+(nz + oy + px + q)] through secret computing using the secret-shared values [func’(x)], [x], [y], [z] (step S234e’).
[0229] (In the case of using the method of the third embodiment (step S32”))
[0230] The secret computing unit executes steps S10 and S11 of the above-described third embodiment for the secret-shared value [x] of the value x normalized to [1, 2) as described above. After that, the secret computing unit executes the following processing of step S325 instead of step S32.
[0231] Step S325: The secret computing unit obtains the secret-shared value through secret computing using the secret-shared values [x], [y], and outputs at and obtains the secret-shared value at and outputs.
[0232] The secret computing unit executes the processing of step S325 as follows, for example (steps S325a to S325c).
[0233] The secret computing unit uses the multiplier and the positive integers σ0, σ1 to obtain the public values 2 σ0 / m 0 、2 σ1 / m 1 and outputs (step S325a).
[0234] The secret computing device performs secret computing of public value division operation [γ(y(ζy + b)+cx)] / (2 σ0 / m 0 ), [γ(y(ζy + b)+cx)] / (2 σ1 / m 1 ) using the secret-shared values [x], [y] and the public values 2 σ0 / m 0 、2 σ1 / m 1 ) obtained in step S325a, and obtains m0 The secret sharing value [m of the value obtained by shifting γ(y(ζy + b) + cx) to the right by σ0 bits 0 γ(y(ζy + b) + cx)] r , and the secret sharing value [m 1 of the value obtained by shifting γ(y(ζy + b) + cx) to the right by σ1 bits 1 γ(y(ζy + b) + cx)] r and outputs it (step S325b).
[0235] The secret computing device obtains, through secret computing using the secret sharing values [m 0 γ(y(ζy + b) + cx)] r , [m 1 γ(y(ζy + b) + cx)] r , the secret sharing value of and outputs it. That is, the secret computing unit obtains and outputs it when , and obtains and outputs it when , and obtains and outputs it (step S325c).
[0236] 《In the case of using the method of the modification of the third embodiment (step S32”)》
[0237] The secret computing unit executes steps S10 and S11 of the modification of the third embodiment described above for the secret sharing value [x] of the value x normalized to [1, 2) as described above. After that, the secret computing unit executes the following processing of step S325’ instead of step S32.
[0238] Step S325’: The secret computing unit obtains [z’ / γ] = [y(ζy + b - k / γ) + (c - s / γ)x - m / γ] through secret computing using the product sum of the secret sharing values [x], [y], . When , perform multiplication based on and the shift of the decimal point position. When , perform multiplication based on and the shift of the decimal point position to obtain the secret sharing value [func’(x)]. The secret computing unit 32 obtains the secret sharing value [func(x)] = [func’(x) + (ky + sx + m)] through secret computing using the secret sharing value [func’(x)] and the secret sharing values [x], [y] and outputs it.
[0239] The secret computing unit performs the processing of step S325’ (steps S325a’ to S325c’) as follows.
[0240] The secret computing unit obtains [z’ / γ] = [y(ζy + b - k / γ) + (c - s / γ)x - m / γ] through secret computing using the product-sum of the secret dispersion values [x] and [y] (step S325a’).
[0241] The secret computing unit uses the multiplier and positive integers σ0 and σ1 to obtain the public values 2 σ0 / m 0 、2 σ1 / m 1 and outputs them (step S325b’).
[0242] The secret computing unit performs secret computing of the division operation using the secret dispersion value [w’ / γ] and the public values 2 σ0 / m 0 、2 σ1 / m 1 [w’ / γ] / (2 σ0 / γm 0 ), [w’ / γ] / (2 σ1 / γm 1 ) to obtain the secret dispersion value of the value obtained by shifting m 0 w’ to the right by σ0 bits [m 0 w’] r 、and the secret dispersion value of the value obtained by shifting m 1 w’ to the right by σ1 bits [m 1 w’] r and outputs them (step S325c’).
[0243] The secret computing device obtains [m 0 w’] r 、[m 1 w’] r through secret computing and obtains the secret dispersion value of and outputs it. That is, the secret computing unit obtains the secret dispersion value and outputs it in the case of , and obtains the secret dispersion value and outputs it in the case of (step S325d’).
[0244] The secret computing unit obtains the secret-shared value [func(x)] = [func’(x) + (ky + sx + m)] by performing secret computing using the secret-shared values [func’(x)], [x], and [y], and outputs it (step S325e’).
[0245] <Example 4: Example of Exponential Function>
[0246] In Example 4, the secret-shared value of the exponential function value exp(x) of the real number x is calculated. Since the input of the exponential function has additivity, the input is decomposed into the following three parts.
[0247] I. The minimum value μ of the assumed input
[0248] II. The upper u bits x of t bits or more after the decimal point of x - μ 0 ,…,x u-1
[0249] III. The number x represented by all the lower bits compared with x of x - μ 0 ρ
[0250] Let exp x = expμ exp 2 -t x 0 ,…,exp 2 u-t-1 x u-1 exp x ρ . expμ is a public value, and exp 2 - t x 0 ,…,exp 2 u-t-1 x u-1 is table-based calculation. exp x ρ is the part calculated by approximation and is normalized to [0, 2 -t ).
[0251] Input: [x]
[0252] Output: [exp(x)]
[0253] Set parameters: t = -1
[0254] 1: The secret computing device obtains [x’] = [x] - μ by secret computing. Here, μ is the minimum value of the assumed x.
[0255] 2: The secret computing device performs secret computing, uses bit decomposition, extracts the bits higher than t bits after the decimal point, and performs a mod p transformation to obtain [x’ 0 ,…,[x’ u-1 .
[0256] 3: Through secret computation, the secret computing device sets f i , ε i as the mantissa part and exponent part of exp(2 i-t ), respectively, for each 0 ≤ i < u.
[0257] 4: Through secret computation, for i = 0, …, u - 1, if x’ i’ = 0, the secret computing device sets F i = 1; if x’ i’ = 1, the secret computing device sets F i = f i .
[0258]
Mathematical formula 6
[0259]
[0260] 5: Through secret computation, for each 0 ≤ i < u, the secret computing device calculates [ε’ i = if[x’ i then 2 εi else 1 through the publicly disclosed if-then-else gate.
[0261] 6: Through secret computation, the secret computing device obtains the product [ε’](ε’ = ε’ i …ε’ 0 …ε’ u-1 ) of [ε’ i related to each i. This is the power of 2 of the exponent part of the high-order bit part of exp(x’).
[0262] 7: Through secret computation, the secret computing device obtains
[0263]
Mathematical formula 7
[0264] This is the number represented by the low-order bit part of exp(x’).
[0265] 8: Through secret computation, the secret computing device obtains the secret-shared value [w] = [func(x)] from the secret-shared value [x’ ρ . Here, w = func(x) is a polynomial that approximates the exponential function exp x of x. The secret computing device uses, for example, the method of the first to third embodiments or their modified examples with x = x’ ρ to obtain the secret-shared value [w] = [func(x)].
[0266] 9: Through secret computation, the secret computing device obtains [w][f’][ε’]exp(μ) and outputs it. For example, through secret computation, the secret computing device obtains the public value 2σ / exp(μ), the secret calculation [w][f’][ε’] / (2 σ / exp(μ)) that uses the secret dispersion value [w][f’][ε’] and the obtained public value 2 and performs a public value division operation of / exp(μ) is carried out, and the secret dispersion value [w][f’][ε’]exp(μ) of the value obtained by shifting wf’ε’exp(μ) to the right by α bits is obtained and output. σ / exp(μ)) to obtain the secret dispersion value [w][f’][ε’]exp(μ) of the value obtained by shifting wf’ε’exp(μ) to the right by α bits and output it.
[0267] [Examples of parameters for which calculations related to each elementary function are completed]
[0268] Figure 6 Examples of the completed parameters in the case where the elementary functions are the reciprocal function, the square root function, the reciprocal of the square root function, the exponential function, and the logarithmic function are illustrated. In addition, ex, ey, and ez respectively represent the decimal point positions of x, y, and z. In addition, e’x, e’y, and e’z respectively represent the decimal point positions of x’, y’, and z’ before the right shift. These decimal point positions represent the bit positions of the decimal point counted from the low-order bits. The value representing the bit position starts from 0, and when the e1-th bit counted from the low-order bits represents 1, it is marked that the decimal point position is e1.
[0269] [Hardware structure]
[0270] The secret calculation devices 1 to 4 in each embodiment and the secret calculation devices in each example are, for example, devices constituted by a general-purpose or dedicated computer having a processor (hardware processor) such as a CPU (central processing unit) and a memory such as a RAM (random-access memory) and a ROM (read-only memory) executing a prescribed program. The computer may have one processor or memory, or may have multiple processors or memories. The program may be installed in the computer or may be pre-recorded in a ROM or the like. In addition, instead of using an electronic circuit (circuitry) that realizes a functional structure by reading a program such as a CPU, an electronic circuit that separately realizes a processing function may be used to constitute a part or all of the processing unit. In addition, the electronic circuit constituting one device may include multiple CPUs.
[0271] Figure 5 is a block diagram illustrating the hardware structure of the secret calculation devices 1 to 4 in each embodiment and the secret calculation devices in each example. As Figure 7As illustrated, the secret computing devices 1 to 4 in this example have a CPU (Central Processing Unit), an output unit 10b, an output unit 10c, a RAM (Random Access Memory) 10d, a ROM (Read Only Memory) 10e, an auxiliary storage device 10f, and a bus 10g. The CPU 10a in this example has a control unit 10aa, an arithmetic unit 10ab, and a register 10ac, and executes various arithmetic processes according to various programs read into the register 10ac. In addition, the output unit 10b is an output terminal, a display, etc. to which data is output. And the output unit 10c is a LAN card or the like controlled by the CPU 10a that has read a prescribed program. In addition, the RAM 10d is an SRAM (Static Random Access Memory), a DRAM (Dynamic Random Access Memory), etc., and has a program area 10da for storing prescribed programs and a data area 10db for storing various data. In addition, the auxiliary storage device 10f is, for example, a hard disk, an MO (Magneto-Optical disc), a semiconductor memory, etc., and has a program area 10fa for storing prescribed programs and a data area 10fb for storing various data. In addition, the bus 10g connects the CPU 10a, the output unit 10b, the output unit 10c, the RAM 10d, the ROM 10e, and the auxiliary storage device 10f so that information exchange can be performed. The CPU 10a writes the programs stored in the program area 10fa of the auxiliary storage device 10f into the program area 10da of the RAM 10d according to the read OS (Operating System) program. Similarly, the CPU 10a writes various data stored in the data area 10fb of the auxiliary storage device 10f into the data area 10db of the RAM 10d. Then, the addresses on the RAM 10d into which the program or data has been written are stored in the register 10ac of the CPU 10a. The control unit 10ab of the CPU 10a sequentially reads out these addresses stored in the register 10ac, reads out the program or data from the area on the RAM 10d indicated by the read address, causes the arithmetic unit 10ab to sequentially execute the arithmetic indicated by the program, and stores the arithmetic result in the register 10ac. With such a structure, the secret computing devices 1 to 4 illustrated in FIG. 1 and the functional structures of the secret computing devices in each embodiment are realized. Figure 4 The secret computing devices 1 to 4 illustrated and the functional structures of the secret computing devices in each embodiment.
[0272] The above program can be recorded on a computer-readable recording medium. Examples of computer-readable recording media are non-transitory recording media. Examples of such recording media are magnetic recording devices, optical discs, magneto-optical recording media, semiconductor memories, and the like.
[0273] In addition, the distribution of the program is carried out, for example, by selling, transferring, or lending portable recording media such as DVDs and CD-ROMs that record the program. Furthermore, it can also be configured to store the program in the storage device of a server computer and forward the program from the server computer to other computers via a network, thereby distributing the program. As described above, a computer that executes such a program first temporarily stores the program recorded on a portable recording medium or the program forwarded from a server computer in its own storage device. Then, when performing processing, the computer reads the program stored in its own storage device and executes the processing according to the read program. Additionally, as another execution mode of the program, the computer can also directly read the program from a portable storage medium, execute the processing according to the program, and can also sequentially execute the processing according to the received program each time the program is forwarded from the server computer to the computer. Moreover, it can also be configured to implement the processing function only through the execution instruction and result acquisition without forwarding the program from the server computer to the computer, that is, to execute the above processing through a so-called ASP (Application Service Provider) type of service. Additionally, in the program of this mode, it is assumed to include information that follows the program (data that is not a direct instruction to the computer but has the nature of specifying the processing of the computer) as information for use in the processing of an electronic computer.
[0274] In each embodiment, it is assumed that this device is configured by executing a specified program on a computer. However, it can also be assumed that at least a part of these processing contents is implemented in hardware.
[0275] Furthermore, the present invention is not limited to the above embodiments. For example, the present invention can also be used in the case of secretly calculating elementary functions other than the specific examples shown. In addition, the above various processes can be executed not only in the order described but also in parallel or individually according to the processing capabilities of the device performing the processing or as needed. Moreover, of course, appropriate changes can be made without departing from the gist of the present invention.
[0276] Industrial Applicability
[0277] The present invention can be utilized, for example, in the calculation of elementary functions such as reciprocal functions, square root functions, exponential functions, and logarithmic functions in machine learning or data mining that perform secret calculations while anonymizing data.
[0278] Description of reference numerals
[0279] 1 to 4 secret computing devices
Claims
1. A secret computing device, where x, y, and z are real numbers, a, b, c, δ, and ζ are real coefficients, and the secret dispersion value of · is [·], the secret computing device includes: The first secret calculation unit obtains a secret-shared value [y] = [δx 2 + ax] through secret calculation using the secret-shared value [x] of the real number x; and A second secret computing unit that obtains the secret dispersion value [func(x)] = [y(ζy + b) + cx] of the elementary function approximation value z = func(x) of the real number x through a secret computation using the secret dispersion value [x] and the secret dispersion value [y], and outputs it.
2. A secret computing device, where x, y, z, and w are real numbers, a, b, c, d, f, g, α, β, γ, δ, and ζ are real coefficients, and the secret dispersion value of · is [·], the secret computing device includes: The first secret calculation unit obtains a secret-shared value [y] = [δx 2 + ax] through secret calculation using the secret-shared value [x] of the real number x; A second secret computing unit that obtains the secret dispersion value [z] = [y(ζy + b) + cx] through a secret computation using the secret dispersion value [x] and the secret dispersion value [y]; and A third secret computing unit that obtains the secret dispersion value [func(x)] = [γ(z(αz + d) + y(βx + f) + gx)] of the elementary function approximation value w = func(x) of the real number x through a secret computation using the secret dispersion value [x], the secret dispersion value [y], and the secret dispersion value [z], and outputs it.
3. A secret computing device, where x, y, and z are real numbers, a, b, c, γ, δ, and ζ are real coefficients, and the secret dispersion value of · is [·], the secret computing device includes: The first secret calculation unit obtains a secret-shared value [y] = [δx 2 + ax] through secret calculation using the secret-shared value [x] of the real number x; and A second secret computing unit that obtains the secret dispersion value [func(x)] = [γ(y(ζy + b) + cx)] of the elementary function approximation value z = func(x) of the real number x through a secret computation using the secret dispersion value [x] and the secret dispersion value [y], and outputs it.
4. The secret computing device according to any one of claims 1 to 3, wherein, χ is a real number, p is a positive integer, L is an integer greater than or equal to 2, [·] is the secret dispersion value obtained by linearly secretly dispersing the element · on the residue ring modulo p, and {·} is the secret dispersion value obtained by linearly secretly dispersing the element · on the residue ring modulo 2, the secret computing device includes: The fifth secret calculation unit obtains the L-bit representation χ of the real number χ through secret calculation using the secret-shared value [χ] of the real number χ 0 …χ L-1 of the secret-shared value {χ 0},…,{χ L-1}; The 6th secret calculation unit obtains, through secret calculation using the secret dispersion values {χ 0}, …, {χ L-1}, the secret dispersion values {η 0}, …, {η L-1} of the msb flag strings η 0 , …, η L-1 where the bit η msb corresponding to the most significant bit χ msb of the bit string χ 0 …χ L-1 is 1 and the bits η ξ (ξ ∈ {0, …, L - 1}) other than the bit η msb are 0; The seventh secret calculation unit obtains, through secret calculation using the secret dispersion values {χ 0}, …, {χ L-1}, the secret dispersion values {ρ i} = {ρ i+1 ∨ χ i} and the secret dispersion value {ρ L-1} = {χ L-1} for 0 ≤ i < L - 1; The 8th secret calculation unit obtains a secret-shared value [θ] of a count value θ indicating the number of elements that are 1 in ρ 0}, …, {ρ L-1} through secret calculation using the secret-shared values {ρ 0 , …, ρ L-1 ; The 9th secret calculation unit obtains, through secret calculation using the secret dispersion values {η 0}, …, {η L-1}, the secret dispersion value [ν] of the msb flag value ν = η 0 , …, η L-1 obtained by bit combination of the msb flag strings η 0 …η L-1 ; A tenth secret computing unit that obtains the secret dispersion value [x] = [χ][ν] through a secret computation using the secret dispersion value [χ] and the secret dispersion value [ν]; and An eleventh secret computing unit that obtains [logχ] = [func(x)] - [θ] through a secret computation using the secret dispersion value [func(x)] and the secret dispersion value [θ], and outputs it.
5. A secret computing method, where x, y, and z are real numbers, a, b, c, δ, and ζ are real coefficients, and the secret dispersion value of · is [·], the secret computing method includes: In the first secret calculation step, the first secret calculation unit obtains a secret distributed value [y] = [δx 2 2 + ax] through secret calculation using the secret distributed value [x] of the real number x; and In the second secret calculation step, the second secret calculation unit obtains the secret dispersion value [func(x)] = [y(ζy + b) + cx] of the elementary function approximation value z = func(x) of the real number x through secret calculation using the secret dispersion value [x] and the secret dispersion value [y], and outputs it.
6. A secret calculation method, where x, y, z, and w are real numbers, a, b, c, d, f, g, α, β, γ, δ, and ζ are real number coefficients, and the secret dispersion value of · is [·], the secret calculation method includes: First secret calculation step, the first secret calculation unit obtains a secret dispersion value [y] = [δx 2 + ax] through secret calculation using the secret dispersion value [x] of the real number x; a second secret calculation step, where the second secret calculation unit obtains the secret dispersion value [z] = [y(ζy + b) + cx] through secret calculation using the secret dispersion value [x] and the secret dispersion value [y]; and a third secret calculation step, where the third secret calculation unit obtains the secret dispersion value [func(x)] = [γ(z(αz + d) + y(βx + f) + gx)] of the elementary function approximation value w = func(x) of the real number x through secret calculation using the secret dispersion value [x], the secret dispersion value [y], and the secret dispersion value [z], and outputs it.
7. A secret calculation method, where x, y, and z are real numbers, a, b, c, γ, δ, and ζ are real number coefficients, and the secret dispersion value of · is [·], the secret calculation method includes: In the first secret calculation step, the first secret calculation unit obtains a secret distributed value [y] = [δx 2 + ax] through secret calculation using the secret distributed value [x] of the real number x; and a second secret calculation step, where the second secret calculation unit obtains the secret dispersion value [func(x)] = [γ(y(ζy + b) + cx)] of the elementary function approximation value z = func(x) of the real number x through secret calculation using the secret dispersion value [x] and the secret dispersion value [y], and outputs it.
8. A computer program product storing a program for causing a computer to function as the secret calculation device according to any one of claims 1 to 3.
Citation Information
Patent Citations
Secret sharing system, sharing apparatus, sharing management apparatus, acquiring apparatus, secret sharing method, program and recording medium
CN103003857A
Secure computation method, secure computation system, sorting device, and program
CN105900164A