Secret computing system, secret computing device, secret computing method, and computer program product

By performing multiplication rotation operation in secret calculation, and multiplication operation and redispersion using the share of the addition secret dispersion method, the problem of low rotation efficiency in the prior art is solved, and a more efficient secret calculation rotation is achieved.

CN116324936BActive Publication Date: 2025-06-27NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080106126.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-16
Publication Date
2025-06-27
Estimated Expiration
2040-10-16

AI Technical Summary

Technical Problem

The rotation efficiency in existing secret calculations is low and there is a problem of poor efficiency.

Method used

By performing multiplication rotation operation in secret calculation, a system composed of n secret computing devices is used to perform multiplication operations on the shares that follow the secret dispersion method of addition, and dispersing the results to the next group of secret computing devices to achieve rotation.

Benefits of technology

It effectively improves the rotation efficiency in secret calculations, reduces the communication series, and improves the overall performance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116324936B_ABST
    Figure CN116324936B_ABST
Patent Text Reader

Abstract

A group SP(i) of k secret computing devices selected from a group PA of n secret computing devices performs a process of multiplying a share following a secret sharing method by a share ρ obtained by secretly sharing ρ based on a replication-type secret sharing method to the power of 2, and disperses the value obtained by this process to a group SP(i+1) of k secret computing devices selected from the group PA of n secret computing devices, and repeats the above process. However, no further dispersion is performed in the last time. Thus, shares of the multiplication rotation result are obtained. (SP(i)) to the power of 2 ρ(SP(i)) and repeats the above process. However, no further dispersion is performed in the last time. Thus, shares of the multiplication rotation result are obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to secret computing technology, and more particularly to rotation technology. Background Art

[0002] Rotation (circular shift) is one of the very basic processes in a computer. In secret computing (for example, refer to Non-Patent Documents 1, 2, etc.), rotation can be performed in a state where the value is hidden.

[0003] Prior Art Documents

[0004] Non-Patent Documents

[0005] Non-Patent Document 1: Takashi Nishide, Takuma Amada, "Multi-Party Computation for Floating-Point Arithmetic with Reduced Communication Volume", Transactions of the Information Processing Society of Japan, Vol. 60 No. 9, pp. 1433-1447 (2019).

[0006] Non-Patent Document 2: Randmets, J., "Programming Languages for Secure Multiparty Computation Application Development", PhD thesis. University of Tartu (2017). Summary of the Invention

[0007] Problems to be Solved by the Invention

[0008] However, the existing rotation in secret computing has a problem of poor efficiency.

[0009] The present invention has been made in view of such problems, and an object thereof is to provide a technique for effectively performing rotation in secret computing.

[0010] Means for Solving the Problems

[0011] Secret Computing Device Performs a unit rotation in which the value obtained by performing the calculation is used as a new share (SP(i)) The secret computing device Uses the share (PA(0)∈SP(i)) and the secret computing device and the random numbers r(i,1),..., r(i,k-1) shared with each of the secret computing devices to obtain the share (PA(k)∈SP(i+1)) and sends it to the secret computing device Secret computing device Perform respectively for j = 1, …, k - 1 using shares (PA(j)∈SP(i)) And random number r(i, j) to obtain shares (PA(j)∈SP(i+1)) Of re - dispersion.

[0012] Where n, k are integers greater than or equal to 2, n > k, N = n C k , PA is a group of n secret computing devices PA(0), …, PA(n - 1), SP(i) is a group of k secret computing devices selected from PA Of the group, i = 0, …, N - 1, i’ = 0, …, N - 2, P is an integer greater than or equal to 1, p is the number of bits of the integer P, a is an element of the residue class ring Z P Of modulo P, the share (SP(i)) Is a group of k shares held by SP(i) obtained by secretly dispersing a according to the secret dispersion method, (PA(θ)∈SP(i)) Is the share held by the secret computing device PA(θ) ∈ SP(i) in the share (SP(i)) . ρ is an element of the residue class ring Z p Of modulo p, the n shares <<ρ>>0, …, <<ρ>> obtained by secretly dispersing ρ according to the replicated - type secret dispersion method n-1 The sub - shares are ρ0, …, ρ N-1 ∈Z p , ρ (SP(i)) Is the sub - share corresponding to the group SP(i) among the sub - shares ρ0, …, ρ N-1 .

[0013] Effects of the invention

[0014] According to the above, rotation can be effectively performed in secret computing. Description of the drawings

[0015] Figure 1 Is a conceptual diagram illustrating the structure of a secret computing system according to an embodiment.

[0016] Figure 2 Is a block diagram illustrating the functional structure of a secret computing device according to an embodiment.

[0017] Figure 3 Is a flowchart for illustrating a secret computing method according to an embodiment.

[0018] Figure 4 Is a block diagram for illustrating the hardware structure of a secret computing device according to an embodiment. Detailed implementation manners

[0019] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings.

[0020] [Principle]

[0021] First, the principle of this embodiment will be described.

[0022] Multiplication by a power of 2 is equivalent to rotation of a bit string. For example, multiplying a residue class ring with the number of bits (number of elements) being a p-bit Mersenne prime by a power of 2 is equivalent to performing rotation of a bit string of length p. In this embodiment, rotation is achieved by performing multiplication by a power of 2 in secure computation. This rotation is called multiplicative rotation.

[0023] The key points of the multiplicative rotation in this embodiment are as follows.

[0024] Step I: The group SP(i) of k secure computing devices selected from the group PA of n secure computing devices performs multiplication of the shares following the additive secret sharing scheme by the share ρ obtained by secretly sharing ρ following the replication-type secret sharing scheme with 2 as the power of 2 used as the exponent. (SP(i)) 2 as the power of 2 for the exponent ρ(SP(i)) for unit rotation.

[0025] Step II: The value obtained in Step I is re-shared to the group SP(i + 1) of k secure computing devices selected from the group PA of n secure computing devices.

[0026] Step III: Steps I and II are repeatedly performed for all groups. However, re-sharing is not performed in the last time. Thus, shares of the multiplicative rotation result are obtained.

[0027] A more detailed description will be given. The secure computing system of this embodiment has n secure computing devices PA(0), …, PA(n - 1). Here, the group of n secure computing devices PA(0), …, PA(n - 1) is denoted as PA, and the group of k secure computing devices selected from PA is denoted as SP(i). The group SP(i) performs the i-th unit rotation. Among them, n and k are integers of 2 or more, n > k, N = n C k , and i = 0, …, N - 1. n C k represents the total number of combinations when selecting k mutually different ones from n mutually different ones. In addition, is the function value of α and β, satisfying SP(0), ..., SP(N-1) are different from each other, and SP(0), ..., SP(N-1) is configured so that for i' = 0, ..., N-2, | SP(i') ∩ SP(i'+1) c |=1. Here, α c represents the complement of α, and |α| represents the number of elements of α. That is, the group SP(i') that performs the i'th unit rotation is a group that is different from the group SP(i'+1) that performs the i'+1th unit rotation by only one secure computing device.

[0028] The value a that is the object of the multiplication rotation is the remainder class ring Z modulo P P Here, P is an integer greater than 1, and p is the number of bits of the integer P. For example, when P is a Mersenne number P, P = 2 p -1 holds, and p is the number of bits of P. An example of P is a prime number, for example, P is a Mersenne prime. The k shares obtained by distributing the secret a according to the (k,k)-addition secret distribution method are expressed as 0,…, k-1 That is, a=0+…+ k-1 ∈Z P (That is, a=0+…+ k-1 mod P). In addition, the (k, k)-addition secret sharing method is a (k, n)-copy type secret sharing method when n=k (for example, refer to Reference 1, etc.).

[0029] Reference 1: Dai Igarashi, Hiroki Hamada, Ryo Kikuchi, Hiroshi Chida, "Improvement of secret computation radix ranking with the goal of statistical processing of 1-second response in Internet environment", SCIS2014, 2014.

[0030] Share (SP(i)) are the k shares maintained by group SP(i) following the (k,k)-additive secret distribution method, in particular, share (SP(0)) is the k shares obtained by distributing the secret a according to the (k,k)-addition secret distribution method 0,…, k-1 . (PA(θ)∈SP(i)) Is the share (SP(i)) The share held by the secret computing device PA(θ)∈SP(i) in .

[0031] The exponent (power exponent) ρ in the multiplication cycle is the residue class ring Z modulo p. p The n shares obtained by distributing the ρ secret according to the (k,n)-replication secret distribution method are <<ρ>>0,…,<<ρ>>n-1 The sub - shares are denoted as ρ0, …, ρχ N -1 ∈ Z p . That is, it satisfies ρ = ρ0 + … + ρχ N -1 ∈ Z p (that is, ρ = ρ0 + … + ρχ N -1 mod p). For w = 0, …, n - 1, the share <<ρ>> w is a proper subset of the sub - shares ρ0, …, ρχ N -1 Any k shares selected from the shares <<ρ>>0, …, <<ρ>>χ N-1 contain all the sub - shares ρ0, …, ρχ N -1. However, the information of ρ cannot be obtained from less than k shares. Here, the sub - shares of ρ0, …, ρχ N -1 corresponding to the group SP(i) are denoted as ρι (SP(i)) . That is, ρι (SP(i)) represents the shares corresponding to the k secret computing devices belonging to the group SP(i) and contained in the share

[0032] The important point is that SP(0), …, SP(N - 1) are constructed such that for i’ = 0, …, N - 2, |SP(i’) ∩ SP(i’ + 1) c | = 1. Here, represents the secret computing devices contained in the group SP(i’) but not in the group SP(i’ + 1). In addition, represents the secret computing devices not contained in the group SP(i’) but contained in the group SP(i’ + 1). Furthermore, for j = 1, …, k - 1, represents the secret computing devices contained in both the group SP(i’) and the group SP(i’ + 1).

[0033] <Unit rotation>

[0034] The i - th (i = 0, …, N - 1) unit rotation is the following process: The secret computing device uses 2 ρ(SP(i)) and (SP(i)) to perform the calculation of 2 ρ(SP(i)) (SP(i)) ∈ Z P (that is, 2 ρ(SP(i)) (SP(i)) mod P), and takes the resulting value as the new share (SP(i)).

[0035] <Re - dispersion>

[0036] Whenever the i'-th (i' = 0, …, N - 2) unit rotation is executed, the i'-th reshuffle is performed. No reshuffle is performed after the (N - 1)-th unit rotation.

[0037] In the i'-th reshuffle, first, the secret computing device and the secret computing device share random numbers r(i', 1), …, r(i', k - 1) ∈ Z P . The method of sharing the random numbers r(i', 1), …, r(i', k - 1) is not limited. For example, it may be that the secret computing device generates the random numbers r(i', 1), …, r(i', k - 1) and sends them to the secret computing device Alternatively, it may be that the secret computing device generates the random numbers r(i', 1), …, r(i', k - 1) separately and sends them to the secret computing device Alternatively, it may be that a seed is shared between the secret computing device and the secret computing device , and the random numbers r(i', 1), …, r(i', k - 1) are generated by a prescribed process using the seed.

[0038] Furthermore, in the i'-th reshuffle, the secret computing device uses the share (PA(0)∈SP(i’)) and the random numbers r(i', 1), …, r(i', k - 1) to obtain the share (PA(k)∈SP(i’+1)) . That is, the secret computing device obtains the share through the following formula (PA(k)∈SP(i’+1)) .

[0039] [Mathematical formula 1]

[0040]

[0041] The secret computing device sends the share obtained as described above (PA(k)∈SP(i’+1)) to the secret computing device

[0042] In addition, in the i'-th reshuffle, the secret computing device uses the share (PA(j)∈SP(i’)) and the random number r(i', j) respectively for j = 1, …, k - 1 to obtain the share (PA(j)∈SP(i’+1)) . That is, the secret computing device obtains the share respectively through the following formula (PA(j)∈SP(i'+1)) .

[0043] [Mathematical formula 2]

[0044] (PA(j)∈SP(i′+1))

[0045] = (PA(j)∈SP(i′)) +r(i′, j)

[0046] <Repeated process>

[0047] As described above, the group SP(i) performs reshuffling after each unit rotation for each of i = 0 to i = N - 2, and performs a unit rotation for i = N - 1. That is, this repeated process is a repetition of unit rotation → reshuffling → unit rotation → reshuffling →... → unit rotation. The unit rotation is performed N times, and the reshuffling is performed N - 1 times. If it is simply performed, the number of communication levels is directly the number of reshufflings, which becomes N - 1 levels. However, the unit rotation and the reshuffling can be parallelized for communication. This is because the secret computing device is not included in the group SP(i') that performs the i'-th reshuffling, and the other secret computing devices of the group SP(i' + 1) that perform the (i' + 1)-th reshuffling do not need to wait for the reception of the data to be reshuffled, and can transfer to the next unit rotation process by performing only offline processing. The number of shares following the (k, k)-additive secret sharing scheme is k. Therefore, if the order of the groups SP(0),..., SP(N - 1) is appropriately set, the maximum number of unit rotations of k times can be performed at 1 level. Thus, the number of communication levels can be reduced to (N - 1) / k levels.

[0048] [First Embodiment]

[0049] Next, a first embodiment of the present invention will be described.

[0050] <Structure>

[0051] As Figure 1 As exemplified, the secret computing system 1 of the present embodiment has n secret computing devices PA(0), …, PA(n−1). The secret computing devices PA(0), …, PA(n−1) are configured to be able to exchange data. In the present embodiment, the secret computing devices PA(0), …, PA(n−1) are configured to be able to communicate via a network, and an example of exchanging data via the network will be described. However, this does not limit the present invention, and the secret computing devices PA(0), …, PA(n−1) may also be configured to be able to exchange data via a removable recording medium and may exchange data via a removable recording medium.

[0052] As Figure 2 exemplified, the secret computing device PA(j) (where j = 0, …, n−1) has a communication unit 11−j, a pre-transformation unit 12−j, a unit rotation unit 13−j, a re-dispersion unit 14−j, a post-transformation unit 15−j, a control unit 16−j, and a storage unit 17−j. In addition, unless otherwise specified, the secret computing device PA(j) executes each process under the control of the control unit 16−j, and the data obtained in each process is stored in the storage unit 17−j and read out and used as needed. In addition, the exchange of data between the secret computing devices PA(0), …, PA(n−1) is performed by each communication unit 11−j.

[0053] <Process>

[0054] Next, the process of the present embodiment will be described.

[0055] <<Premise>>

[0056] As a premise, n shares [a]0, …, [a] n-1 of the value a secretly dispersed in accordance with the (k, n)-secret sharing scheme or the public value a and n shares <<ρ>>0, …, <<ρ>> w secretly dispersed in accordance with the (k, n)-replicated secret sharing scheme of ρ n-1 each share <<ρ>> w are stored in the storage unit 17−j of each secret computing device PA(w). The (k, n)-secret sharing scheme is not limited. For example, it may be a (k, n)-replicated secret sharing scheme or a (k, n)-Shamir secret sharing scheme (for example, refer to Reference 2, etc.).

[0057] Reference 2: A. Shamir, "How to share a secret," Communications of the ACM, Vol. 22, No. 11, pp. 612 - 613, 1979.

[0058] <<Multiplication Rotation Processing>>

[0059] Use Figure 3 The multiplication rotation processing of this embodiment will be described.

[0060] k secret computing devices belonging to group SP(0) of the prior transformation unit The shares held in group SP(0) or the public value a is transformed into shares 0,..., obtained by secretly sharing a in accordance with the (k, k)-additive secret sharing scheme k-1 (Share [[]] (SP(0)) ). In the secret computing device belonging to group SP(0) The share is stored in storage unit 17 - θ θ (Step S11).

[0061] The control unit 16 - w of all secret computing devices PA(w) is set to i = 0 (Step S12).

[0062] k secret computing devices belonging to group SP(i) of the unit rotation unit Each performs 2 ρ(SP(i)) (sP(i)) ∈Z P The calculation, and use the resulting value as the new share (SP(i)) Stored in the storage unit (Step S13).

[0063] The control unit 16-j determines whether i≥N-1 (Step S14). If i≥N-1, proceed to the process of Step S17. If i≥N-1 does not hold, proceed to the process of Step S15.

[0064] In Step S15, first, the re-dispersion unit of the secret computing device shares random numbers r(i, 1),..., r(i, k-1)∈Z with each of the re-dispersion units of the secret computing device . Furthermore, the re-dispersion unit P of the secret computing device uses the shares ​ (PA(0)∈sP(i)) and random numbers r(i, 1),..., r(i, k - 1) to obtain shares (PA(k)∈sP(i+1)) That is, the secret computing device Obtain shares through the following formula (PA(k)∈SP(i+1)) 。

[0065] [Mathematical formula 3]

[0066]

[0067] Secret computing device Sent to the secret computing device obtained as described above

[0068] In addition, the secret computing device of the re-dispersion unit Uses shares respectively for j = 1,..., k - 1 (PA(j)∈sP(i)) and a random number r(i, j) to obtain the share (PA(j)∈SP(i+1)) . That is, the secret computing device 's re-dispersion unit respectively obtains shares through the following formula (PA(j)∈SP(i+1)) (Step S15).

[0069] [Mathematical formula 4]

[0070] (PA(j)∈SP(i+1))

[0071] = (PA(j)∈SP(i)) +r(i, j)

[0072] The control unit 16-w of the entire secret computing device PA(w) sets i + 1 as the new i (step S16), and the process proceeds to step S13.

[0073] In step S17, which is executed when i ≥ N - 1 in step S14, the post-transformation unit of the secret computing device stores in the storage unit in step S13 the share (SP(N - 1)) is transformed into the desired data. For example, the post - transformation unit can either take the share (SP(N-1)) transformed into shares [a] that follow the (k, n)-secret sharing scheme (SP(N-1)) and output (Reference 3), can also be transformed (reconstructed) into the restored value (2 ρ a ∈ Z P ) and output.

[0074] Reference 3: Kikuchi, R., Ikarashi, D., Matsuda, T., Hamada, K. and Chida, K.: Efficient Bit-Decomposition and Modulus-Conversion Protocols with an Honest Majority, Information Security and Privacy - 23rd Australasian Conference, ACISP 2018, Wollongong, NSW, Australia, July 11 - 13, 2018, Proceedings (Susilo, W. and Yang, G., eds.), Lecture Notes in Computer Science, Vol. 10946, Springer, pp. 64 - 82 (online), DOI: 10.1007 / 978 - 3 - 319 - 93638 - 3 5(2018).

[0075] [Second Embodiment]

[0076] In the second embodiment, a specific example of the first embodiment will be described.

[0077] In this embodiment, a specific example in the case of k = 2 and n = 3 will be described. In this case, N = 3, i = 0, 1, 2. In addition, in this embodiment, let SP(0) = (PA(0), PA(1)), SP(1) = (PA(1), PA(2)), SP(2) = (PA(0), PA(2)). The share (SP(0)) is a0 and a1, a = a0 + a1 ∈ Z P , ρ = ρ 01 + ρ 12 + ρ 20 ∈ Z p , ρ (SP(0)) = ρ (SP(1)) = ρ (SP(1)) = ρ 01 , ρ 12 , ρ 20 . In addition, r(0, 1) = r 01 , r(1, 1) = r 12 .

[0078] In this case, as follows, it is possible to parallelize unit rotation and re-scattering, and reduce the number of communication levels.

[0079] In step S11, the pre-transformation units 12-0 and 12-1 of the two secret computing devices PA(0) and PA(1) belonging to the group SP(0) transform the shares [a]0, …, [a]1 or the public value a held in the group SP(0) into shares 0 = a0, 1 = a1 obtained by secretly scattering a in accordance with the (2, 2)-additive secret sharing scheme (shares (SP(0)) ). The storage unit 17-0 of the secret computing device PA(0) stores a0, and the storage unit 17-1 of the secret computing device PA(1) stores a1.

[0080] The unit rotation unit 13-0 and the re-scattering unit 14-0 of the secret computing device PA(0) use ρ 01 , a0, r 01 to obtain

[0081] [Equation 5]

[0082]

[0083] and send it to the secret computing device PA(2) (steps S13 and S15 corresponding to i = 0).

[0084] In addition, in the unit rotation unit 13-1 and the re-scattering unit 14-1 of the secret computing device PA(1), the secret computing device PA(1) uses ρ 01 , ρ 12 , a1, r 01 , r 12 to obtain

[0085] [Equation 6]

[0086] and send it to the secret computing device PA(0) (steps S13 and S15 corresponding to i = 0 and steps S13 and S15 corresponding to i = 1).

[0087] In addition, the unit rotation unit 13-1 of the secret computing device PA(0) uses ρ 20 , B1 to obtain

[0088] [Equation 7]

[0089]

[0090] (Step S13 corresponding to i = 2).

[0091] The unit rotation unit 13-2 and the re-dispersion unit 14-2 of the secret computing device PA(2) use ρ 20 , ρ 12 , B0, r 12 to obtain

[0092] [Mathematical formula 8]

[0093]

[0094] (Step S13 corresponding to i = 1, step S15, and step S13 corresponding to i = 2).

[0095] As shown below, <c>0 and <c>2 becomes a share that follows the (2, 2)-additive secret sharing scheme, 2Pa ∈ Z P of the share.

[0096] [Equation 9]

[0097]

[0098] [Equation 10]

[0099]

[0100] Therefore, <c> 0+ <c>2 = 2 ρ (a0 + a1) = 2 ρ a ∈ Z P holds

[0101] [Modification Example 1 of the Second Embodiment]

[0102] Modification Example 1 of the second embodiment is a specific example when k = 3 and n = 5. In this case, N = 10, i = 0, 1,..., 9. Further, in this modification example, SP(0) = (PA(0), PA(1), PA(2)), SP(1) = (PA(1), PA(2), PA(3)), SP(2) = (PA(2), PA(3), PA(4)), SP(3) = (PA(0), PA(3), PA(4)), SP(4) = (PA(0), PA(1), PA(4)), SP(5) = (PA(1), PA(3), PA(4)), SP(6) = (PA(0), PA(1), PA(3)), SP(7) = (PA(0), PA(2), PA(3)), SP(8) = (PA(0), PA(2), PA(4)), SP(9) = (PA(1), PA(2), PA(4)). Thus, it is possible to parallelize unit rotation and re-scattering and reduce the communication level in the same manner as in the second embodiment.

[0103] [Hardware Structure]

[0104] The secret computing device PA(j) in the embodiment is constituted by, for example, a general-purpose or dedicated computer including a processor (hardware, controller) such as a CPU (central processing unit), a memory such as a RAM (random-access memory) and a ROM (read-only memory), and executing a prescribed program. The computer may include one processor and memory, or may include a plurality of processors and memories. The program may be installed in the computer, or may be pre-recorded in a ROM or the like. Further, instead of using an electronic circuit (circuitry) that realizes a functional structure by reading a program such as a CPU, a part or all of the processing units may be constituted by an electronic circuit that separately realizes a processing function. Further, the electronic circuit constituting one device may include a plurality of CPUs.

[0105] < / c> < / c> < / c> < / c> Figure 4 is a block diagram illustrating the hardware structure of the secret computing device PA(j) in the embodiment. As Figure 4As illustrated, the secret computing device PA(j) of this example has a CPU (Central Processing Unit) 10a, an input unit 10b, an output unit 10c, a RAM (Random Access Memory) 10d, a ROM (Read Only Memory) 10e, an auxiliary storage device 10f, and a bus 10g. The CPU 10a of this example has a control unit 10aa, an arithmetic unit 10ab, and a register 10ac, and executes various arithmetic processes according to various programs read into the register 10ac. In addition, the input unit 10b is a communication device for inputting data, an input terminal, a keyboard, a mouse, a touch panel, etc. In addition, the output unit 10c is a communication device for outputting data, an output terminal, a display, etc. In addition, the RAM 10d is an SRAM (Static Random Access Memory), a DRAM (Dynamic Random Access Memory), etc., and has a program area 10da for storing a prescribed program and a data area 10db for storing various data. In addition, the auxiliary storage device 10f is, for example, a hard disk, an MO (Magneto-Optical disc), a semiconductor memory, etc., and has a program area 10fa for storing a prescribed program and a data area 10fb for storing various data. In addition, the bus 10g connects the CPU 10a, the input unit 10b, the output unit 10c, the RAM 10d, the ROM 10e, and the auxiliary storage device 10f so that information can be exchanged. The CPU 10a writes the program in the program area 10fa of the auxiliary storage device 10f into the program area 10da of the RAM 10d according to the read OS (Operating System) program. Similarly, the CPU 10a writes various data in the data area 10fb of the auxiliary storage device 10f into the data area 10db of the RAM 10d. Then, the addresses on the RAM 10d into which the program and data are written are stored in the register 10ac of the CPU 10a. The control unit 10aa of the CPU 10a sequentially reads out these addresses stored in the register 10ac, reads out the program and data from the area on the RAM 10d indicated by the read addresses, causes the arithmetic unit 10ab to sequentially execute the arithmetic indicated by the program, and stores the arithmetic result in the register 10ac. With such a structure, the functional structure of the secret computing device PA(j) is realized.

[0106] The above program can be pre-recorded in a computer-readable recording medium. Examples of computer-readable recording media are non-transitory recording media. Examples of such recording media are magnetic recording devices, optical discs, magneto-optical recording media, semiconductor memories, and the like.

[0107] The distribution of the program is carried out, for example, by selling, transferring, or leasing removable recording media such as DVDs and CD-ROMs on which the program is recorded. Further, it can be configured such that the program is stored in a storage device of a server computer, and the program is forwarded from the server computer to other computers via a network, thereby distributing the program. As described above, a computer that executes such a program first temporarily stores, for example, the program recorded on a removable recording medium or the program forwarded from the server computer in its own storage device. Then, at the time of execution processing, the computer reads the program stored in its own storage device and executes the processing according to the read program. In addition, as another execution mode of the program, it can also be that the computer directly reads the program from a removable recording medium and executes the processing according to the program. Further, it can also be that each time the program is forwarded from the server computer to the computer, the processing according to the received program is successively executed. In addition, it can be configured such that the above processing is executed by a so-called ASP (Application Service Provider) type service that realizes the processing function only through the execution instruction and result acquisition without forwarding the program from the server computer to the computer. In addition, it is assumed that the program in this mode includes information provided for processing based on an electronic computer and information based on the program (data etc. that are not direct instructions for the computer but have the nature of prescribing the processing of the computer).

[0108] In each embodiment, it is assumed that this device is configured by executing a prescribed program on a computer, but at least a part of these processing contents can also be realized by hardware.

[0109] [Other Variants]

[0110] In addition, the present invention is not limited to the above embodiments. For example, the re-dispersion of the above embodiments can be further generalized as follows.

[0111] Input: The share sha(a, i) of a that follows the (k, k)-secret sharing scheme and can be restored by linear combination operations. Here, k secret computing devices have the share sha(a, i).

[0112] Output: Share [a(i)] that follows the (k,n)-secret sharing method and has additive homomorphic property

[0113] Processing:

[0114] 1. A secret computing device with share sha(a,i) (where i’ = 0,…,k - 1) distributes its own share sha(a,i) according to the (k,n)-secret sharing method to obtain shares secretly distributed. Thus, the shares are shared among k secret computing devices This becomes the shares after double secret distribution of a, that is, the shares of the shares of a.

[0115] 2. Each secret computing device performs linear combination by adding and multiplying the public value of the secretly computed shares to restore the sha(a,i) component inherent in each share. Thus, each secret computing device obtains share [a(i)] that follows the (k,n)-secret sharing method.

[0116] In addition, in this processing, the share of the above embodiment (PA(0)∈SP(i)) is generalized to share sha(a), and the share (PA(k)∈SP(i+1)) is generalized to the shares of any k secretly selected computing devices among the shares [a(i)] that follow the (k,n)-secret sharing method. In addition, in the embodiment, SP(0),…,SP(N - 1) are configured such that for i’ = 0,…,N - 2, |SP(i’) ∩ SP(i’ + 1) c | = 1, but it may not be configured in this way. In addition, it may not be limited to the (k,k)-secret sharing method, but may be an additive secret sharing method or other secret sharing methods such as the Shamir secret sharing method. The above various processes can be executed not only in the recorded order but also in parallel or separately according to the processing capacity of the device executing the process or as needed. In addition, of course, appropriate changes can be made without departing from the gist of the present invention.

[0117] Description of Reference Numerals

[0118] 1 Secret computing system

[0119] PA(j) Secret computing device

[0120] 13 - j Unit rotation unit

[0121] 14 - j Re - distribution unit

Claims

1. A secret computing system, having n secret computing devices PA(0), …, PA(n - 1), n and k are integers greater than or equal to 2, n > k, N = n C k , n C k represents the total number of combinations in the case of selecting k distinct ones from n distinct ones. PA is a group of n secret computing devices PA(0), …, PA(n - 1), and SP(i) is a group of k secret computing devices selected from PA , where i = 0, …, N - 1, and SP(0), …, SP(N - 1) are configured such that for i’ = 0, …, N - 2, |SP(i’) ∩ SP(i’ + 1) c | = 1. P is an integer greater than or equal to 1, p is the number of bits of the integer P, and a is an element of the residue class ring Z P modulo P, and the share (SP(i)) is one of the k shares maintained by the group SP(i) that follow the additive secret sharing scheme, and the share (SP(0)) is the share obtained by secretly sharing a according to the additive secret sharing scheme, (PA(θ)∈SP(i)) is the share (SP(i)) held by the secret computing device PA(θ) ∈ SP(i) in the share ρ is an element of the residue class ring \(Z_p\) p and \(n\) shares \(\langle\rho\rangle_0,\ldots,\langle\rho\rangle\) n-1 obtained by secretly sharing \(\rho\) according to the replication-based secret sharing method, and the sub-shares are \(\rho_0,\ldots,\rho\) N-1 \(\in Z_p\) p and \(\rho\) (SP(i)) is the sub-share corresponding to the group \(SP(i)\) among the sub-shares \(\rho_0,\ldots,\rho\) N-1 ​ is a secret computing device that is included in the group SP(i') but not included in the group SP(i'+1), is a secret computing device that is not included in the group SP(i') but is included in the group SP(i'+1), for j = 1,..., k-1 is a secret computing device that is included in both the group SP(i') and the group SP(i'+1), Secret computing device Perform the calculation that will be 2 ρ(SP(i)) (SP(i)) ∈Z P The value obtained by the calculation as the new share (SP(i)) Unit rotation of The secret computing device uses the share (PA(0)∈SP(i’)) and the secret computing device shares the random numbers r(i’,1),…,r(i’,k - 1) with each of the secret computing devices to obtain the share (PA(k)∈SP(i’+1)) and sends it to the secret computing device The secret computing device respectively performs the re - dispersion for j = 1,…,k - 1 using the share (PA(j)∈SP(i’)) and the random number r(i’,j) to obtain the share (PA(j)∈SP(i’+1)) of the re - dispersion in the said re - dispersion, The secret computing device obtains the share through the following formula (PA(k)∈SP(i’+1)) , The secret computing device obtains the share respectively through the following formula (PA(j)∈SP(i’+1)) , (PA(j)∈SP(i′+1)) = (PA(j)∈SP(i′)) + r(i′, j).

2. The secret computing system according to claim 1, wherein, SP(0), …, SP(N - 1) are mutually different, the group SP(i) performs the said re - dispersion after each unit rotation for i = 0 to i = N - 2, and performs the unit rotation for i = N - 1.

3. The secret computing system according to claim 1 or 2, wherein, k = 2, n = 3, N = 3, i = 0, 1, 2, SP(0) = (PA(0), PA(1)), SP(1) = (PA(1), PA(2)), SP(2) = (PA(0), PA(2)), Share (SP(0)) are a0 and a1, a = a0 + a1 ∈ Z P , ρ = ρ 01 + ρ 12 + ρ 20 ∈ Z p , ρ (SP(0)) = ρ (SP(1)) = ρ (SP(2)) = ρ 01 , ρ 12 , ρ 20 ∈ Z p , r(0,1)=r 01 、r(1,1)=r 12 , The secret computing device PA(0) uses ρ 01 , a0, r 01 to obtain [Mathematical formula 13] and send it to the secret computing device PA(2), The secret computing device PA(1) uses ρ 01 , ρ 12 , a1, r 01 , r 12 to obtain [Mathematical formula 14] and send it to the said secret computing device PA(0), The secret computing device PA(0) uses ρ 20 , B1 to obtain The secret computing device PA(2) uses ρ 20 , ρ 12 , B0, r 12 to obtain 4. The secret computing system according to claim 1 or 2, wherein, k = 3, n = 5, N = 10, i = 0, 1, …, 9, SP(0) = (PA(0), PA(1), PA(2)), SP(1) = (PA(1), PA(2), PA(3)), SP(2) = (PA(2), PA(3), PA(4)), SP(3) = (PA(0), PA(3), PA(4)), SP(4) = (PA(0), PA(1), PA(4)), SP(5) = (PA(1), PA(3), PA(4)), SP(6) = (PA(0), PA(1), PA(3)), SP(7) = (PA(0), PA(2), PA(3)), SP(8) = (PA(0), PA(2), PA(4)), SP(9) = (PA(1), PA(2), PA(4)).

5. A secret computing system, having n secret computing devices PA(0), …, PA(n - 1), n and k are integers greater than or equal to 2, n > k, N = n C k , n C k represents the total number of combinations in the case of selecting k distinct ones from n distinct ones. PA is a group of n secret computing devices PA(0), …, PA(n - 1), and SP(i) is a group of k secret computing devices selected from PA , where i = 0, …, N - 1 and i’ = 0, …, N - 2. P is an integer greater than or equal to 1, p is the number of bits of the integer P, and a is an element of the residue class ring Z modulo P P The share (SP(i)) are k shares that follow the secret sharing scheme and are held by the group SP(i). The share (SP(0)) is a share obtained by secretly sharing a according to the secret sharing scheme. (PA(θ)∈SP(i)) is the share (SP(i)) held by the secret computing device PA(θ) ∈ SP(i) in the share . ρ is an element of the residue class ring \(Z_p\) p and \(n\) shares \(\langle\rho\rangle_0,\ldots,\langle\rho\rangle_{n - 1}\) obtained by secretly sharing \(\rho\) according to the replication-based secret sharing method n-1 where the sub-shares are \(\rho_0,\ldots,\rho_{n - 1}\) N-1 \(\in Z_p\) p and \(\rho_j\) (SP(i)) is the sub-share corresponding to the group \(SP(i)\) among the sub-shares \(\rho_0,\ldots,\rho_{n - 1}\) N-1 ​ Secret computing device Perform the calculation to be carried out 2 ρ(SP(i)) (SP(i)) ∈Z P The value obtained by the calculation as a new share (SP(i)) Unit rotation of The secret computing device uses share (PA(0)∈SP(i’)) to obtain share (PA(k)∈SP(i’+1)) and sends it to the secret computing device The secret computing device respectively performs re - dispersion for j = 1, …, k - 1 using share (PA(j)∈SP(i’)) to obtain share (PA(j)∈SP(i’+1)) of in the said re - dispersion, The secret computing device obtains the share through the following formula (PA(k)∈SP(i’+1)) , The secret computing device obtains the share respectively through the following formula (PA(j)∈SP(i’+1)) , (PA(j)∈SP(i′+1)) = (PA(j)∈SP(i′)) + r(i′, j).

6. A secret computing device, which is the secret computing device of the secret computing system according to claim 1 or 2.

7. A secret computing method, n, k are integers greater than 2, n>k, N= n C k , n C k represents the total number of combinations when k different ones are selected from n different ones, PA is a group of n secret computing devices PA(0), ..., PA(n-1), SP(i) is the number of k secret computing devices selected from PA The group, i = 0, ..., N-1, SP (0), ..., SP (N-1) is formed so that for i' = 0, ..., N-2, | SP (i') ∩ SP (i' + 1) c |=1, P is an integer greater than or equal to 1, p is the number of bits of the integer P, and a is an element of the residue class ring Z modulo P P The share (SP(i)) are k shares maintained by the group SP(i) that follow the additive secret sharing scheme. The share (SP(0)) is a share obtained by secretly sharing a according to the additive secret sharing scheme. (PA(θ)∈SP(i)) is the share (SP(i)) held by the secret computing device PA(θ) ∈ SP(i) in the share . ρ is an element of the residue class ring Z modulo p, and n shares <<ρ>>0, …, <<ρ>> obtained by secretly sharing ρ according to the replication-based secret sharing method p The sub-shares are ρ0, …, ρ n-1 ∈Z N-1 where ρ p is the sub-share corresponding to the group SP(i) in the sub-shares ρ0, …, ρ (SP(i)) N-1 ​​ is a secret computing device that is included in the group SP(i') but not included in the group SP(i'+1), is a secret computing device that is not included in the group SP(i') but is included in the group SP(i'+1), for j = 1, …, k-1 is a secret computing device that is included in both the group SP(i') and the group SP(i'+1), the said secret computing method has: Unit rotation step, secret computing device Will perform 2 ρ(SP(i)) (SP(i)) ∈Z P The value obtained by the calculation is used as the new share (SP(i)) ; and Re - dispersion step, the secret computing device uses share (PA(0)∈SP(i)) and the secret computing device and the secret computing device and the shared random numbers r(i,1),…,r(i,k - 1) for each of them to obtain share (PA(k)∈SP(i+1)) and sends it to the secret computing device the secret computing device respectively uses share for j = 1,…,k - 1 (PA(j)∈SP(i)) and the random number r(i,j) to obtain share (PA(j)∈SP(i+1)) , in the said re - dispersion, The secret computing device obtains the share through the following formula (PA(k)∈SP(i’+1)) , The secret computing device obtains the share respectively through the following formula (PA(j)∈SP(i’+1)) , (PA(j)∈SP(i′+1)) = (PA(j)∈SP(i′)) + r(i′, j).

8. A secret computing method, having n secret computing devices PA(0), …, PA(n - 1), n and k are integers greater than or equal to 2, n > k, N = n C k , n C k represents the total number of combinations in the case of selecting k distinct elements from n distinct elements. PA is a set of n secret computing devices PA(0), …, PA(n - 1), and SP(i) is a set of k secret computing devices selected from PA , where i = 0, …, N - 1 and i’ = 0, …, N - 2. P is an integer greater than or equal to 1, p is the number of bits of the integer P, and a is an element of the residue class ring Z P modulo P, and the share (SP(i)) is one of the k shares held by the group SP(i) that follow the secret sharing method, and the share (SP(0)) is the share obtained by secretly sharing a according to the secret sharing method, (PA(θ)∈SP(i)) is the share (SP(i)) held by the secret computing device PA(θ) ∈ SP(i) in the share ρ is an element of the residue class ring Z modulo p, and n shares <<ρ>>0, …, <<ρ>> obtained by secretly sharing ρ according to the replication-based secret sharing method p The sub-shares of are ρ0, …, ρ n-1 N-1 ∈Z p ρ (SP(i)) is the sub-share corresponding to the group SP(i) in the sub-shares ρ0, …, ρ N-1 ​​ Secret computing device Execute to perform 2 ρ(SP(i)) (SP(i)) ∈Z P The value obtained by the calculation is used as the new share (SP(i)) Unit rotation of The secret computing device uses share (PA(0)∈SP(i’)) to obtain share (PA(k)∈SP(i’+1)) and sends it to the secret computing device The secret computing device respectively performs the re - dispersion for j = 1, …, k - 1 using share (PA(j)∈SP(i’)) to obtain share (PA(j)∈SP(i’+1)) of in the said re - dispersion, The secret computing device obtains the share through the following formula (PA(k)∈SP(i’+1)) , The secret computing device respectively obtains the share through the following formula (PA(j)∈SP(i’+1)) , (PA(j)∈SP(i′+1)) = (PA(j)∈SP(i′)) + r(i′, j).

9. A computer program product, including a computer program for causing a computer to function as the secret computing device according to claim 6.

Citation Information

Patent Citations

  • Solid state drive(SSD)-based file layout method in large-scale storage system

    CN103135946A

  • Secure computation method, secure computation system, random substitution device, and program

    CN105900165A