Secret search method, secret search system, secret search device, and encryption device

CN117043835BActive Publication Date: 2026-09-22NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202180096064.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-03-22
Publication Date
2026-09-22
Estimated Expiration
2041-03-22

AI Technical Summary

Benefits of technology

[0013]根据本发明,能够高效地进行基于秘密计算的数据检索,且安全地提供所检索的数据。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117043835B_ABST
    Figure CN117043835B_ABST
Patent Text Reader

Abstract

The present application efficiently performs data search based on secret computation, and securely provides the searched data. A searcher terminal (3) acquires condition data (S31). The searcher terminal (3) extracts a feature amount from the condition data (S32). The searcher terminal (3) encrypts the feature amount of the condition data (S33). A secret search device (1 n ) acquires ciphertext of object data corresponding to a feature amount of the object data similar to the feature amount of the condition data, in a state where the feature amount of the object data and the feature amount of the condition data are concealed (S11). The secret search device (1 n ) transmits the search result to an encryption device (2) and the searcher terminal (3) (S13-1). The searcher terminal (3) acquires ciphertext of the object data indicated by the search result (S34). The encryption device (2) transmits a decryption key to the searcher terminal (3) (S25-1). The searcher terminal (3) decrypts the ciphertext of the object data using the decryption key (S35).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to secret computing techniques, and more particularly to techniques for retrieving data similar to the data of the search criteria while concealing the data of the search object. Background Technology

[0002] In recent years, surveillance cameras and IoT (Internet of Things) technologies have become increasingly prevalent, leading to the accumulation of personal privacy data, such as surveillance camera footage. Image retrieval technology can extract image data similar to those used as search criteria from this accumulated surveillance camera footage. This technology is expected to be applicable in various fields, including facility access control and providing information to investigative agencies in the event of an incident or accident. However, the image data being retrieved is personal life data itself and needs to be properly managed to prevent the leakage of privacy.

[0003] Assuming the aforementioned utilization method, secret computing technology is considered as a technique for retrieval while ensuring data confidentiality. Furthermore, Patent Document 1 discloses a technique that involves concealing visitor characteristics extracted from surveillance camera images, etc., through secret sharing, and then retrieving the concealed information to perform a visitor identity comparison.

[0004] Existing technical documents

[0005] Patent documents

[0006] Patent Document 1: Japanese Patent Application Publication No. 2016-71639 Summary of the Invention

[0007] The problem that the invention aims to solve

[0008] However, when applying secret computation techniques, directly inputting image data and performing retrieval through secret computation requires enormous computational costs, which is impractical. Furthermore, the prior art described in Patent Document 1 only outputs verification results and cannot securely provide the user with the original image data.

[0009] In view of the aforementioned technical challenges, the object of the present invention is to efficiently perform data retrieval based on secret computation and to securely provide the retrieved data.

[0010] Methods for solving problems

[0011] One aspect of the secret retrieval method of the present invention is a secret retrieval method performed by a secret retrieval system including at least one secret retrieval device, an encryption device, and a retrieval terminal. The object feature encryption unit of the encryption device encrypts the object feature extracted from the object data that is the retrieval object, and the object data encryption unit of the encryption device encrypts the object data. The condition feature encryption unit of the retrieval terminal encrypts the condition feature extracted from the condition data that is the retrieval condition. The feature retrieval unit of the secret retrieval device uses the ciphertext of the object feature and the ciphertext of the condition feature to obtain a retrieval result representing the ciphertext of the object data corresponding to the object feature similar to the condition feature, while concealing the object feature and the condition feature. The encryption data decryption unit of the retrieval terminal decrypts the ciphertext of the object data represented by the retrieval result and obtains the original object data.

[0012] Invention Effects

[0013] According to the present invention, data retrieval based on secret computation can be performed efficiently, and the retrieved data can be provided securely. Attached Figure Description

[0014] Figure 1 This is a diagram illustrating the functional structure of a secret retrieval system.

[0015] Figure 2 This is a diagram illustrating the functional structure of a secret retrieval device.

[0016] Figure 3 This is a diagram illustrating the functional structure of an encryption device.

[0017] Figure 4 This is a diagram illustrating the functional structure of a searcher's terminal.

[0018] Figure 5 This is a diagram illustrating the process of a secret retrieval method (data registration).

[0019] Figure 6 This is a diagram illustrating the process of a secret retrieval method (data retrieval).

[0020] Figure 7 This is a diagram illustrating the functional structure of a computer. Detailed Implementation

[0021] This invention employs secret computation technology to realize a secure retrieval system for highly confidential data. To ensure efficient retrieval even with computationally expensive secret computation, the system is configured such that, external to the retrieval system (e.g., the surveillance camera itself or an intermediate server between the camera and the retrieval system if the original data being retrieved is surveillance camera footage), feature quantities are extracted from the original data beforehand. These feature quantities and the original data are then encrypted and registered with the retrieval system. The retrieval system performs data retrieval based solely on the encrypted feature quantities. The retrieval system provides the retrieved user with the retrieval results, which are separately stored as encrypted representations of the original data. The user then decrypts the encrypted original data obtained as a retrieval result to retrieve the original data.

[0022] Hereinafter, embodiments of the present invention will be described in detail. Furthermore, in the accompanying drawings, structural parts having the same function are assigned the same reference numerals, and repeated descriptions are omitted.

[0023] [Implementation Method]

[0024] The present invention relates to a secret retrieval system and method that, while concealing the data, secretly calculates and retrieves data similar to the input data used as conditions from accumulated data that is the retrieval target. In this embodiment, the following utilization method is envisioned: image data contained in surveillance camera images captured by a surveillance camera is used as the retrieval target; image data depicting a specific person is used as the retrieval condition; and the image of the person depicted in the image data of the retrieval target and the image data of the retrieval condition, from the accumulated image data as the retrieval target, is output as the retrieval result. In this invention, the data used as the retrieval target is not limited to image data. For example, data that can extract certain features, such as audio data or text data, can be used as the retrieval target regardless of the type of data.

[0025] like Figure 1 As shown, the secret retrieval system 100 of this embodiment includes N (≥1) secret retrieval devices 11, …, 1 N The system includes an encryption device 2, a searcher terminal 3, and a storage device 4. The encryption device 2 and the searcher terminal 3 can each be comprised of multiple units. C (≥1) surveillance cameras 51, …, 5 C The surveillance camera 5 is connected to the encryption device 2 via a wired or wireless interface. In cases involving multiple encryption devices 2, the surveillance camera 5 is connected to each encryption device 2. c The number C of units (c∈=1, …, C) can also be different. This is achieved by installing the functions required by storage device 4 into secret retrieval devices 11, …, 1 N In any one of them, storage device 4 can be omitted.

[0026] Secret retrieval devices 11, …, 1 N The encryption device 2, the searcher terminal 3, and the storage device 4 are respectively connected to the communication network 9. The communication network 9 is a communication network configured to enable the connected devices to communicate with each other using line switching or packet switching, such as the Internet, LAN (Local Area Network), WAN (Wide Area Network), etc.

[0027] In secret retrieval device 1 n (n∈{1, …, N}) represents the case of multiple units (i.e., N≥2), where the secret retrieval device 1 is the first unit. n For example, using secret computing methods based on secret sharing such as Shamir secret sharing or copy secret sharing to compete with other secret retrieval devices. n' (n'∈{1, …, N} and n≠n') cooperatively perform the retrieval. In the secret retrieval device 1 n In the case of 1 unit (i.e., N=1), the secret retrieval device 1 n For example, secret computation methods based on homomorphic encryption can be used to perform retrieval.

[0028] like Figure 2 As shown, secret retrieval device 1 n (n=1, …, N) For example, it includes: an encrypted feature storage unit 10, a feature retrieval unit 11, and a retrieval result transmission unit 12. Figure 3 As shown, the encryption device 2 includes, for example, a decryption key storage unit 20, an object data acquisition unit 21, an object feature extraction unit 22, an object feature encryption unit 23, an object data encryption unit 24, and a decryption key transmission unit 25. Figure 4 As shown, the retrieval terminal 3 includes, for example, a conditional data input unit 31, a conditional feature extraction unit 32, a conditional feature encryption unit 33, an encrypted data acquisition unit 34, and an encrypted data decryption unit 35.

[0029] The secret retrieval system 100 includes secret retrieval devices 11, …, 1 N The encryption device 2, the searcher terminal 3, and the storage device 4 cooperate with each other and perform [operations / processes]. Figure 5-6 The processing of each step shown thereby realizes the secret retrieval method of the embodiment. The secret retrieval method of the embodiment consists of two stages: data registration processing, which registers data as the retrieval target to the secret retrieval system 100, and data retrieval processing, which retrieves data similar to the data used as the retrieval condition from the data as the retrieval target through secret calculation. Figure 5 This is a flowchart illustrating the data registration process. Figure 6 This is a flowchart illustrating the data retrieval and processing process.

[0030] The devices or terminals included in the secret retrieval system 100 are, for example, special devices configured to read special programs from a known or special-purpose computer equipped with a central processing unit (CPU) and main storage (RAM). Each device or terminal executes a process, for example, under the control of the CPU. Data input to each device or terminal, or data obtained through each process, is stored, for example, in the main storage. Data stored in the main storage is read from the CPU as needed and used for other processes. At least a portion of the processing unit of each device or terminal may be constructed using hardware such as integrated circuits. The storage units of each device or terminal may be constructed, for example, through main storage devices such as RAM, auxiliary storage devices composed of semiconductor memory elements such as hard disks, optical disks, or flash memory, or middleware such as relational databases or key-value stores.

[0031] Specifically, secret retrieval device 1 n The encryption device 2 is an information processing device with data communication capabilities, such as a tower or rack-mount server computer. Specifically, the searcher terminal 3 is an information processing device with data communication capabilities, such as a desktop or laptop personal computer, or a mobile terminal such as a smartphone or tablet. Specifically, the storage device 4 is an information processing device with data communication and data storage capabilities, such as a tower or rack-mount server computer connected to a large-capacity storage device, or a network-connected storage device with built-in large-capacity storage.

[0032] Surveillance camera 5 c For example, a camera is a recording device that captures moving images of a person or object as the subject. For example, factors such as the resolution of the image, the recording medium, the presence or absence of a microphone, and the difference between digital and analog recordings, etc., are relevant to surveillance cameras. c There are no restrictions on the functions it should have; if it is a general camera device capable of capturing moving images, then any device can be used.

[0033] Reference Figure 5 The data registration process in the secret retrieval method executed by the secret retrieval system 100 of the embodiment will be described.

[0034] In step S21, the object data acquisition unit 21 of the encryption device 2 acquires data to be retrieved (hereinafter referred to as "object data"). The object data is, for example, data captured by the surveillance camera 5 c image data included in the surveillance camera video. At this time, a tag with information such as the shooting location and shooting date and time may also be attached to the object data. The object data acquisition unit 21 outputs the acquired object data to the object feature quantity extraction unit 22 and the object data encryption unit 24.

[0035] In step S22, the object feature quantity extraction unit 22 of the encryption device 2 receives the object data from the object data acquisition unit 21, and extracts a feature quantity from the object data (hereinafter referred to as "object feature quantity"). The object feature quantity extraction unit 22 outputs the extracted object feature quantity to the object feature quantity encryption unit 23.

[0036] The feature quantity extraction method can be arbitrarily determined according to the type of object data. For example, when it is assumed that the object data is image data included in a video in which multiple unspecified persons are captured, and the face of a specific person is retrieved from the object data, the feature quantity can be extracted through the following two steps. First, from the surveillance camera 5 c the captured image data extracts a region to be retrieved (for example, a person's face) (step 1). For region extraction, a general method such as principal component analysis can be used (see Reference 1). Then, the extracted face image data is transformed into a feature quantity (step 2). For the feature quantity transformation of face image data, for example, the pixel value of each pixel of the image can be directly used as the feature quantity, or a general edge extraction method can be used to take the variation of each pixel as the feature quantity (see Reference 2).

[0037] [Reference 1] Mante Opel, "Face Recognition Using Principal Component Analysis", [online], [Retrieved March 9, Reiwa 2], Internet<URL: https: / / qiita.com / manteopel / items / 703e9946e1903c6e2aa3>

[0038] [Reference 2] SUNSHINE, "Summary of "Feature Quantity" of "Image Recognition" (2): What is "Edge Detection"? How does it work? What is "Spatial Filter"? How is it used?", [online], [Retrieved March 9, Reiwa 2], Internet<URL: https: / / it-mint.com / 2018 / 11 / 05 / feature-value- in-image-recognition-whats-edge-detection-and-spatial-filter-1839.html >

[0039] When the object data is audio data, well-known audio features can be extracted. When the object data is text data, well-known features such as word embedding vectors can be extracted.

[0040] In step S23-1, the object feature encryption unit 23 of the encryption device 2 receives the object feature from the object feature extraction unit 22 and encrypts the object feature. The object feature encryption unit 23 encrypts the object feature using any encryption method or secret sharing method capable of performing secret computation. Specifically, examples of encryption methods capable of performing secret computation include homomorphic encryption, and examples of secret sharing methods capable of performing secret computation include Shamir secret sharing and copy secret sharing. If an encryption method is used, the generated ciphertext is a single ciphertext; if a secret sharing method is used, the generated ciphertext is a distributed value composed of multiple shares. The object feature encryption unit 23 sends the ciphertext of the object feature to each secret retrieval device 1. n Here, "send the ciphertext to each secret retrieval device 1" n If the ciphertext is encrypted using a cryptographic method, it means sending one ciphertext to one secret retrieval device 11. If the ciphertext is shared using a secret method, it means sending it to multiple secret retrieval devices 11, ..., 1 N The distribution of values ​​is done by maintaining a single share for each value, without any overlap. This principle will be followed in subsequent explanations.

[0041] In step S23-2, each secret retrieval device 1 n The encryption device 2 receives the ciphertext of the object feature quantity and stores the ciphertext of the object feature quantity in the encryption feature quantity storage unit 10.

[0042] In step S24-1, the object data encryption unit 24 of the encryption device 2 receives object data from the object data acquisition unit 21 and encrypts the object data. The encryption method used by the object data encryption unit 24 is a different encryption method from the encryption method used by the object feature encryption unit 23; it is an encryption method in which the original data cannot be obtained without a valid decryption key. Such an encryption method can be either public key encryption or public key encryption. The object data encryption unit 24 associates information representing the ciphertext of the object data with information representing the decryption key required to decrypt the ciphertext of the object data and stores it in the decryption key storage unit 20. The information representing the decryption key can be the decryption key itself or information that identifies the decryption key and has been securely exchanged between the encryption device 2 and the retrieval terminal 3 beforehand. The object data encryption unit 24 sends the ciphertext of the object data to the storage device 4.

[0043] In step S24-2, the storage device 4 receives the ciphertext of the object data from the encryption device 2 and stores the ciphertext of the object data.

[0044] Reference Figure 6 The processing procedure during data retrieval in the secret retrieval method executed by the secret retrieval system 100 of the embodiment will be described.

[0045] In step S31, the condition data input unit 31 of the searcher terminal 3 acquires data (hereinafter referred to as "condition data") input by the searcher using the searcher terminal 3 as search conditions. Condition data may be, for example, image data of the face of the person to be searched. The condition data input unit 31 outputs the acquired condition data to the condition feature extraction unit 32.

[0046] In step S32, the condition feature extraction unit 32 of the retrieval terminal 3 receives condition data from the condition data input unit 31 and extracts feature values ​​(hereinafter referred to as "condition feature values") from the condition data. The feature values ​​extracted by the condition feature extraction unit 32 are the same as the feature values ​​extracted by the object feature extraction unit 22 of the encryption device 2. The condition feature extraction unit 32 outputs the extracted condition feature values ​​to the condition feature encryption unit 33.

[0047] In step S33, the conditional feature encryption unit 33 of the retrieval terminal 3 receives the conditional feature from the conditional feature extraction unit 32 and encrypts the conditional feature. The encryption method used by the conditional feature encryption unit 33 is the same as the encryption method used by the object feature encryption unit 23 of the encryption device 2. The conditional feature encryption unit 33 sends the ciphertext of the conditional feature to each secret retrieval device 1. n .

[0048] In step S11, each secret retrieval device 1 n The feature retrieval unit 11 receives the ciphertext of conditional features from the retrieval terminal 3, and uses the ciphertext of object features stored in the encrypted feature storage unit 10 and the ciphertext of conditional features received from the retrieval terminal 3 to retrieve object features similar to the conditional features through secret computation. That is, while concealing the object features and conditional features, the ciphertext of object features similar to the conditional features is extracted. The feature retrieval unit 11 outputs information representing the ciphertext of object data corresponding to the ciphertext of the extracted object features (hereinafter referred to as the "retrieval result") to the retrieval result sending unit 12.

[0049] Feature retrieval based on secret computation can be performed by calculating the Euclidean distance between all object data and conditional data based on secret computation, and then comparing the result with a pre-set threshold. The Euclidean distance is calculated as follows: The data to be retrieved (object data) and the data to be retrieved (conditional data) are n×m pixel image data. Let the pixel value (feature) of the data to be retrieved be x=[x... ij ], set the pixel value of the retrieved data to y=[y ij When (i=1, …, m, j=1, …, n), the Euclidean distance D is expressed by the following formula (see reference 3).

[0050]

Formula 1

[0051]

[0052] [Reference 3] Inoue Mitsuhei, Urahama Kiichi, "The lower limit of the distance and the lower limit of the distance, the image of the base and the image," Journal of the Image Information Society, Vol. 59, No. 11, pp. 1701-1704, 2005

[0053] The secret computation of the Euclidean distance D mentioned above can be easily achieved by utilizing secret computation with additive homomorphism.

[0054] The Euclidean distance D is calculated for all object data. By comparing this result with a predetermined threshold, search results can be generated. For example, object data with an Euclidean distance D below the predetermined threshold, or object data with a predetermined number of items from the beginning when sorted in ascending order by Euclidean distance D, can be output as search results. The sorting calculation in secret computing can, for example, use the method described in Reference 4.

[0055] [Reference 4] Igarashi Dai, Hamada Hiroshi, Kikuchi Ryo, Chida Koji, "Ultra-high-speed secret calculation design and installation: secret "Cryptozoological Computing", Cryptozoology System (CSS), 2017

[0056] In step S12-1, each secret retrieval device 1 n The search result sending unit 12 receives the search results from the feature quantity search unit 11 and sends the search results to the searcher terminal 3. In addition, the search result sending unit 12 sends the search results and information representing the searcher terminal 3 to the encryption device 2.

[0057] In step S12-2, the retrieval terminal 3 retrieves information from each secret retrieval device 1. nThe system receives the search results and obtains encrypted information representing the object data based on the search results. When the feature retrieval unit 11 performs a search using a secret calculation method based on secret sharing, the information is retrieved from each secret retrieval device 1. n The received search results are used to obtain the encrypted information representing the target data. When the feature retrieval unit 11 performs a search using an encryption-based secret calculation method, the encrypted information representing the target data is obtained by decrypting the search results received from the secret retrieval device 11 according to a prescribed decryption method. The searcher terminal 3 then inputs the obtained encrypted information representing the target data into the encrypted data acquisition unit 34.

[0058] In step S12-3, the encryption device 2 retrieves information from each secret retrieval device 1. n The encryption device 2 receives the search results and information representing the searcher terminal 3, and similarly obtains the encrypted information representing the object data based on the search results. The encryption device 2 then inputs the obtained encrypted information representing the object data and the information representing the searcher terminal 3 into the decryption key sending unit 25.

[0059] In step S34, the encrypted data acquisition unit 34 of the retrieval terminal 3 retrieves the ciphertext of the object data represented by the input information from the storage device 4. The encrypted data acquisition unit 34 outputs the retrieved ciphertext of the object data to the encrypted data decryption unit 35.

[0060] In step S25-1, the decryption key sending unit 25 of the encryption device 2 obtains information representing the decryption key used to decrypt the ciphertext of the object data represented by the input information from the decryption key storage unit 20. The decryption key sending unit 25 then sends the obtained information representing the decryption key to the retrieval terminal 3.

[0061] In step S25-2, the retrieval terminal 3 receives information representing the decryption key from the encryption device 2 and obtains the decryption key. The retrieval terminal 3 then inputs the obtained decryption key into the encrypted data decryption unit 35.

[0062] In step S35, the encryption data decryption unit 35 of the retrieval terminal 3 receives the ciphertext of the object data from the encryption data acquisition unit 34 and decrypts the ciphertext of the object data using the input decryption key. The encryption data decryption unit 35 outputs the original object data obtained through decryption. If the object data acquisition unit 21 has added information such as shooting location and shooting date and time to the object data, this information is appended to the original object data and output.

[0063] With the above-described configuration, the secret retrieval devices 11, ..., 1 NBy using only feature quantities to retrieve the data being retrieved, the computational cost of data retrieval based on secret computation can be reduced. Furthermore, the retriever terminal 3 can obtain the original data itself, which is similar to the data used as the search criteria, from the data being retrieved. In this case, the original data is encrypted using an encryption method that cannot be decrypted without the decryption key, thus preventing information related to the original data from being disclosed to the secret retrieval devices 11, …, 1. N This allows for the secure provision of raw data as search results to the user's terminal.

[0064] [Variation Example]

[0065] In the secret retrieval system of the implementation method, the encryption device 2 is configured to detect signals from multiple surveillance cameras 51, ..., 5 C Feature quantities are extracted from the captured image data, and these feature quantities and the original image data are encrypted and stored in a manner that can be accessed from secret computing devices 11, …, 1. N Utilization. However, through surveillance cameras 51, …, 5 C The system itself incorporates feature extraction and encryption functions, thus eliminating the need for encryption device 2. In this case, surveillance cameras 51, …, 5 C The encryption device 2 according to the embodiment includes a decryption key storage unit 20, an object feature extraction unit 22, an object feature encryption unit 23, an object data encryption unit 24, and a decryption key transmission unit 25. That is, in the secret retrieval system of the modified example, surveillance cameras 51, ..., 5 C Each of these constitutes an encryption device 2.

[0066] The embodiments of the present invention have been described above, but the specific structure is not limited to these embodiments. Any appropriate design changes that do not depart from the spirit of the present invention are also included in the present invention. The various processes described in the embodiments are not only executed in the order described in time sequence, but can also be executed in parallel or individually depending on the processing capability of the device executing the process or as needed.

[0067] [Program, Recording Medium]

[0068] When the various processing functions in the devices described in the above embodiments are implemented using a computer, the processing content of the functions that each device should have is described by a program. Furthermore, this program is read into... Figure 7 The storage unit 1020 of the computer shown enables the arithmetic processing unit 1010, the input unit 1030, the output unit 1040, etc. to perform operations, thereby realizing various processing functions in the aforementioned devices on the computer.

[0069] The program describing this processing can be recorded on a computer-readable recording medium. Such a computer-readable recording medium can be, for example, a non-transitory recording medium, a magnetic recording device, an optical disc, etc.

[0070] Furthermore, the program can be distributed, for example, through the sale, transfer, or lending of removable recording media such as DVDs and CD-ROMs containing the program. Alternatively, it can be configured such that the program is pre-stored in a storage device on a server computer and then forwarded from the server computer to other computers via a network, thereby distributing the program.

[0071] A computer executing such a program may first temporarily store the program recorded on a removable recording medium or the program forwarded from a server computer in its own non-temporary storage device, specifically in the auxiliary recording unit 1050. Furthermore, during processing, the computer reads the program stored in its own non-temporary storage device, in the auxiliary recording unit 1050, into the temporary storage device, namely the storage unit 1020, and executes the processing according to the read program. Alternatively, as another method of executing the program, the computer may directly read the program from the removable recording medium and execute the processing according to that program; or, each time a program is forwarded from the server computer to the computer, the processing according to the obtained program may be executed sequentially. Furthermore, the above processing may be executed using a so-called ASP (Application Service Provider) type service, which performs the processing function solely through its execution instructions and result acquisition, without forwarding the program from the server computer to the computer. Additionally, in this method, the program is provided to contain information equivalent to the program for the computer to process (data, etc., which, although not direct instructions to the computer, have the nature of specifying the computer's processing).

[0072] Furthermore, in this method, the device is constructed by executing a prescribed program on a computer, but at least a portion of these processing contents can also be implemented by hardware.

Claims

1. A covert retrieval method, which is a covert retrieval method executed by a covert retrieval system comprising at least one covert retrieval device, an encryption device, and a retrieval user terminal. The object feature encryption unit of the encryption device encrypts the object feature data extracted from the object data that is the retrieval target. The object data encryption unit of the encryption device encrypts the object data. The condition feature encryption unit of the searcher terminal encrypts the condition features extracted from the condition data used as search conditions. The feature retrieval unit of the secret retrieval device uses the ciphertext of the object feature and the ciphertext of the condition feature to obtain retrieval results of ciphertext representing the object data corresponding to the object feature similar to the condition feature, while concealing the object feature and the condition feature. The encryption and decryption unit of the searcher terminal decrypts the ciphertext of the object data represented by the search results and obtains the original object data. The ciphertext of the object feature quantity and the ciphertext of the condition feature quantity are ciphertexts encrypted using a first encryption method capable of secret computation. The ciphertext of the object data is encrypted using a second encryption method that is different from the first encryption method and requires a decryption key for decryption. The decryption key sending unit of the encryption device sends information to the retrieval terminal, representing a decryption key used to decrypt the ciphertext of the object data represented by the retrieval result. The encrypted data decryption unit uses the decryption key to decrypt the ciphertext of the object data represented by the search result.

2. The secret retrieval method as described in claim 1, wherein, The object data refers to the image data contained in the images captured by the surveillance camera. The conditional data refers to image data of a specific person's face being captured.

3. A covert retrieval system, comprising at least one covert retrieval device, an encryption device, and a retrieval user terminal. The encryption device includes: The object feature encryption unit encrypts the object features extracted from the object data that is the object to be retrieved; as well as The object data encryption unit encrypts the object data. The searcher terminal includes: The conditional feature encryption unit encrypts the conditional features extracted from the conditional data used as search conditions; and The encrypted data decoding unit decrypts the ciphertext of the object data represented by the retrieval results and obtains the original object data. The secret retrieval device includes: The feature retrieval unit uses the ciphertext of the object feature and the ciphertext of the conditional feature to obtain retrieval results of ciphertext representing object data corresponding to the object feature similar to the conditional feature, while concealing the object feature and the conditional feature. The ciphertext of the object feature quantity and the ciphertext of the condition feature quantity are ciphertexts encrypted using a first encryption method capable of secret computation. The ciphertext of the object data is encrypted using a second encryption method that is different from the first encryption method and requires a decryption key for decryption. The decryption key sending unit of the encryption device sends information to the retrieval terminal, representing a decryption key used to decrypt the ciphertext of the object data represented by the retrieval result. The encrypted data decryption unit uses the decryption key to decrypt the ciphertext of the object data represented by the search result.

4. A secret retrieval device, which is the secret retrieval device used in the secret retrieval system described in claim 3.

5. An encryption device, which is the encryption device used in the secret retrieval system described in claim 3.

6. A searcher terminal, which is the searcher terminal used in the secret search system described in claim 3.

7. A computer program product storing a program for causing a computer to perform the steps of the secret retrieval method as described in claim 1 or claim 2.

Citation Information

Patent Citations

  • Monitoring information sharing system, collation device, monitoring device, and program

    JP2016071639A

  • Retrieval method, retrieval system and program

    JP2017111793A

  • System for confidentially searching for similarity, and method for confidentially searching for similarity

    WO2016203555A1