Secret computation device, secret computation system, secret computation method, and program

CN117461068BActive Publication Date: 2026-10-09NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180099030.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-08
Publication Date
2026-10-09
Estimated Expiration
2041-06-08

AI Technical Summary

Benefits of technology

[0015]Therefore, it is possible not only to process the hidden information of two sets as direct input, but also to process the hidden information of three or more sets as direct input, and to directly obtain the hidden information of the intersection result of the three or more sets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117461068B_ABST
    Figure CN117461068B_ABST
Patent Text Reader

Abstract

Using L sets X0 = {x 0,0 ,...,x 0,r(0)‑1},...,X L‑1 ={x L‑1,0 ,...,x L‑1,r(L‑1)‑1}The concealed [x 0,0 ],...,[x 0,r(0)‑1 ],...,[x L‑1,0 ],...,[x L‑1,r(L‑1)‑1 ], thus obtaining x for p = 0, ..., m-1 0,0 ,...,x 0,r(0)‑1 ,...,x L‑1,0 ,...,x L‑1,r(L‑1)‑1 The representation of k in p The number of elements c p After being concealed, [c0],...,[c m‑1 ], thus obtaining c for p = 0, ..., m-1 p =L when eq p =T, not c p =L when eq p =F's eq p [eq0],...,[eq] has been concealed m‑1 The output contains interrelated [k] pairs. p ] and [eq p The data structure is X0,...,X L‑1 The result of the concealment operation of the intersection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to encryption technology, and in particular to secret computation technology. Background Technology

[0002] The intersection of sets A and B is expressed as A∩B. A secret intersection calculation method is known as follows: using the hidden information of sets A and B as input, while sets A and B are hidden, the hidden information of the intersection operation result of sets A and B is obtained through secret calculation (for example, see Non-Patent Literature 1, etc.).

[0003] Existing technical documents

[0004] Non-patent literature

[0005] Non-patent document 1: Hiroshi Hamada, Dai Igarashi, Koji Chida, "Improved Algorithms for Computing Relational Algebra Operators for Secure Function Evaluation", Technical Journal of Communications LOIS2012-82, Vol. 112, No. 446, pp. 76-82, 2013. Summary of the Invention

[0006] The problem that the invention aims to solve

[0007] However, existing methods for calculating secret intersections are limited to using the hidden information of two sets as input. Therefore, to obtain the hidden information of the intersection result of three or more sets using their hidden information as input, it is necessary to repeatedly perform secret intersection calculations using the hidden information of two sets as input. However, in this method, as the number of sets involved in the intersection operation increases, the number of rounds increases, and some processing becomes redundant between rounds, thus increasing computational cost.

[0008] The present invention was made in view of the following problem, and its object is to provide a technology that can not only process the hidden information of two sets as direct input, but also process the hidden information of three or more sets as direct input, and can also directly obtain the hidden information of the intersection operation result of the three or more sets.

[0009] Methods for solving problems

[0010] In this invention, as follows, when L sets X0={x 0,0 ,...,x0,r(0)-1},...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1 In the hidden state, we obtain the representation set X0,...,X L-1 The result of the concealment operation on the intersection of the information. Here, L is an integer greater than 2, i = 0, ..., L-1, r(i) is an integer greater than 1, j(i) = 0, ..., r(i)-1, m is an integer greater than 1, k0, ..., k m-1 These are distinct key information, p=0,...,m-1, and [α] is the concealment information of α.

[0011] (A) In the counting section, use the concealed element [x] 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 The counting results [c0],...,[c] are obtained through secret calculation. m-1 Here, each element x i,j(i) Represents key information k0,...,k m-1 any one of them, element x 0,0 ,...,x0, r(0)-1 ,...,x L-1,0 ,...,x L-1 , r(L-1)-1 The key information k in the middle represents p The number of elements is c. p .

[0012] (B) In the equality determination section, the counting results [c0],...,[c m-1 The equality determination result is obtained through secret calculation: [eq0],...,[eq m-1 Here, in c p =L when eq p =T, not c p =L when eq p =F, T, and F are all different from each other.

[0013] (C) In the output flag assignment section, the output contains mutually correlated anonymized key information [k] p And the result of the equality check [eq] p The result of the concealment operation.

[0014] The effects of the invention

[0015] Therefore, it is possible not only to process the hidden information of two sets as direct input, but also to process the hidden information of three or more sets as direct input, and to directly obtain the hidden information of the intersection result of the three or more sets. Attached Figure Description

[0016] Figure 1 This is a block diagram illustrating the functional structure of a secret computing system according to an implementation method.

[0017] Figure 2 This is a block diagram illustrating the functional structure of the secret computing device in an embodiment.

[0018] Figure 3 This is a flowchart illustrating the secret calculation method for implementing the method.

[0019] Figure 4 This is a block diagram illustrating the hardware structure of a secret computing device according to an embodiment. Detailed Implementation

[0020] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings.

[0021] [Definition of the term]

[0022] First, define the notation used in the implementation.

[0023] X i ={x i,0 ,...,x i , r(i)-1} indicates that x i,0 ,...,x i , r(i)-1 The set of elements. i is the index of the set, i = 0, ..., L-1. L represents the set X0 = {x...} 0,0 ,...,x0, r(0)-1},...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1 The number of elements in set X is an integer greater than or equal to 2. L can also be greater than or equal to 3. r(i) represents the set X. i The number of elements is an integer greater than or equal to 1. r(i) can be either 1 or greater than 2. λ(i) is a set X. i element x i,0 ,...,x i , r(i)-1 The index will be related to set X. i The element corresponding to the index λ(i) is represented as x. i,λ(i) Where λ(i) = 0, ..., r(i) - 1. They belong to the same set X.i element x i,0 ,...,x i , r(i)-1 The content they represent (e.g., numerical values, characters (letters, numbers, etc.), dates, and times) are all different. That is, they belong to the same set X. i element x i,0 ,...,x i , r(i)-1 Each item represents a unique element. This is consistent with the usual definition of a set.

[0024] (κ0,...,κ Θ-1 ) represents Θ elements κ0,...,κ Θ-1 Columns. For example, column (κ0,...,κ Θ-1 ) is a set of elements κ0,...,κ Θ-1 Vectors, but not limited to columns (κ0,...,κ). Θ-1 The implementation method of ).

[0025] [α] represents the hidden information of α. That is, [α] represents the information obtained by hiding α. When α is multiple elements κ0,...,κ... P-1 The columns (κ0,...,κ) P-1 In the case of ), α=(κ0,...,κ P-1 The multiple elements κ0,...,κ possessed by ) P-1 The respective columns of concealed information [κ0],...,[κ] P-1 [α] is also represented as [α]. Here, the concealed information [α] is information capable of secret computation. That is, with α concealed, by using secret computation with the concealed information [α], the concealed information [β] of the computation result β for α can be obtained. Secret computation can be based on secret distribution (e.g., see Non-Patent Document 1, etc.) or on homomorphic encryption. In the former case, [α] is the share obtained by secretly distributing α (sometimes also called a secret share or secret distribution value). In the latter case, [α] is the ciphertext obtained by encrypting α using a homomorphic encryption method.

[0026] <Secret Dispersal>

[0027] Secret distribution refers to an encryption method that divides data into multiple values ​​(shares) and distributes them to multiple parties. An example of secret distribution is the (K,N) threshold secret distribution. The (K,N) threshold secret distribution divides the original data into N random shares and distributes them to multiple parties. It is a secret distribution method with the following property: if more than K shares are collected, the original data can be recovered; however, it is impossible to obtain information about the original data from shares less than K. Here, K and N are positive integers satisfying K ≤ N. Specific examples of the (K,N) threshold secret distribution include the Shamir secret distribution (e.g., see reference 1, etc.) and the replication secret distribution (e.g., see references 2, 3, etc.).

[0028] Reference 1: Adi Shamir, “How to share a secret,” Communications of theACM, Vol. 22, No. 11, pp. 612-613, 1979.

[0029] Reference 2: Mitsuru Ito, Akira Saito, and Takao Nishizeki, “Secretsharing scheme realizing general access structure,” Electronics and Communications in Japan (Part III: Fundamental Electronic Science), Vol. 72, No. 9, pp. 56-64, 1989.

[0030] Reference 3: Ronald Cramer, Ivan Damgard, and Yuval Ishai, “Shareconversion, pseudorandom secret-sharing and applications to securecomputation,” In Theory of Cryptography Conference, pp. 342-362. Springer, 2005.

[0031] The following examples illustrate operations based on secret computation (for example, see Non-Patent Document 1, etc.).

[0032] <Equals sign determination>

[0033] The equality determination of the concealed information [α1], [α2] based on secret computation means the following operation: using the concealed information [α1], [α2] (e.g., shares) of α1 and α2 as input, the output is the concealed information [β] (e.g., shares) of β∈{T,F} that is true or false when α1=α2, β=T (true) and when α1=α2, β=F (false). Here, T and F represent mutually distinct values ​​(T≠F), for example, it can be T=1 and F=0, or it can be T=0 and F=1. The execution of this operation is described as follows.

[0034] [β]←E Q ([α1],[α2])

[0035] <Group-by Count>

[0036] Group-by-counting of the concealed information [A] based on secret computation means processing as follows: taking the concealed information [A] of set A as input, and through secret computation, grouping the elements of set A according to each element representing the same content (e.g., the same numerical value, the same character, the same date and time, etc.), to obtain the group G representing each element belonging to the same set. p The key information k represented by the element p Anonymization information (anonymization key information) [k p ] and belonging to each group G p The number of elements c p The concealed information (counting results) [c p Here, p = 0, ..., m-1, and m is a set of G0, ..., G... m-1 The number of items belonging to the same group G. p Elements representing the same content belong to different groups G. p1 and group G p2 The elements of set A (where p1, p2 ∈ {0, ..., m-1}) represent mutually distinct content. That is, the elements of set A represent key information k0, ..., k m-1 Any element in set A represents the key information k. p The number of elements is c. p The execution of this process is described as follows.

[0037] ([k],[c])←GroupbyCount([A]) (1)

[0038] Here, [k] represents the column ([k0],...,[k]). m-1 [c] represents the column ([c0],...,[c0]). m-1 ]).

[0039] The implementation method for this processing is disclosed in reference 4, etc.

[0040] Reference 4: Ryo Kikuchi, Hiroshi Hamada, Dai Igarashi, Gen Takahashi. "Secret cross-sector customer-flow invention (Secret cross-sector customer-flow analysis)," In SCIS2020, pp. 1-8, 2020.

[0041] Furthermore, in order to group G0,...,G of set A m-1 The number m of hidden information can also be obtained by group-by-counting to obtain [k] and [c] containing dummy information, and a column [f] containing flags to distinguish between valid and dummy information (e.g., see reference 4). That is, the group-by-counting of hidden information [A] based on secret computation can also be a process that takes the hidden information [A] of set A as input and obtains the column ([f], [k], [c]) through secret computation. Here, column [f] contains m valid flags [f0], ..., ... m-1 ] and nm virtual flags [f m ],...,[f n-1 The column is f[0,...,f]. n is an integer greater than m, and f[0,...,f]. m-1 It is B1, f m ,...,f n-1 B0, B1, and B0 are all distinct. B1 and B0 can be arbitrary, but for example, they can be either B1=1 and B0=0, or B1=0 and B0=1. As long as it is concealed, it is preferable not to distinguish between valid flags [f0],...,[f m-1 ] and virtual symbols [f m ],...,[f n-1 ] Column [k] contains m hidden key information [k0],...,[k] m-1 ] and nm virtual information [k m ],...,[k n-1 The columns are defined as follows. As long as the key information is concealed, it is preferable not to distinguish between concealed key information [k0],...,[k]. m-1 ] and virtual information [k m ],...,[k n-1 For example, virtual information [k] m ],...,[k n-1[c] can be randomly selected information (e.g., random numbers) or hidden information of randomly selected information. Column [c] contains m count results [c0],...,[c... m-1 ] and nm virtual information [c m ],...,[c n-1 The column is defined as follows. As long as it is concealed, it is preferable not to distinguish between the counting results [c0],...,[c...]. m-1 ] and virtual information [c m ],...,[c n-1 For example, virtual information [c m ],...,[c n-1 [ ] can be randomly selected information (e.g., random numbers) or hidden information of randomly selected information. Furthermore, for p=0,...,m-1, the effective flag [f p ], Anonymized key information [k p ], Counting results [c p They are interconnected, and for q=m,...,n-1, the virtual flag [f] is used. q Virtual information [k] q Virtual information [c] q They are interconnected. In this case, the group-by-count of the anonymized information [A] based on secret computation is described as follows.

[0042] ([f],[k],[c])←GroupbyCount([A]) (2)

[0043] [First Implementation Method]

[0044] Next, the first embodiment of the present invention will be described.

[0045] <Structure>

[0046] like Figure 1 As illustrated, the secret computing system 1 of the first embodiment has W secret computing devices 11-0,...,11-(W-1) configured to communicate via a network. Here, W is an integer greater than or equal to 1. For example, when the secret computing devices 11-0,...,11-(W-1) perform secret computing based on secret distribution, W is an integer greater than or equal to 2; when performing secret computing based on homomorphic encryption, W is an integer greater than or equal to 1.

[0047] like Figure 2As illustrated, the secret computing device 11-w (where w = 0, ..., W-1) has an input unit 111-w, a connection unit 112-w, a counting unit 113-w, an equality determination unit 114-w, an output flag assignment unit 115-w, a control unit 118-w, and a storage unit 119-w. The secret computing device 11-w executes each process based on the control of the control unit 118-w. Data input to the secret computing device 11-w and data obtained from each process are stored in the storage unit 119-w and can be read out and used for other processes as needed.

[0048] <Processing>

[0049] The secret computing device 11-w (where w = 0, ..., W-1) performs secret computation on L sets X0 = {x 0,0 ,...,x0, r(0)-1},...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1 In the concealed state, obtain and output the representation set X0,...,X L-1 The intersection ∩ 0≤i≤L-1 X i The data structure of the hidden information of the operation result is hidden [Z]. If we represent a specific example, for example, in the case of L=3, r(0)=4, r(1)=2, r(2)=2, the elements of the three sets X0, X1, X2 represent letters, X0={a,b,e,g}, X1={b,e}, X2={a,e}, the intersection of sets X0, X1, X2 is ∩ 0≤i≤2 X i For {e}, the secret computing device 11-w obtains and outputs the concealment operation result [Z] representing [e]. Using... Figure 3 The secret computing process of the secret computing device 11-w will be explained.

[0050] L sets X0={x} are input to the input section 111-w of the secret computing device 11-w. 0,0 ,...,x0, r(0)-1},...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1 The hidden information of} [X0],...,[X L-1 In the specific example above, the input is [X0]={[a],[b],[e],[g]}, [X1]={[b],[e]}, [X2]={[a],[e]}. [X0],...,[X L-1It can be sent from any of the W secret computing devices 11-0,...,11-(W-1), or it can be sent from other devices not shown in the figure (step S111-w).

[0051] [X0],...,[X L-1 The input is fed into the junction 112-w. The junction 112-w receives and outputs [X0],...,[X L-1 The hidden element [x] is formed by combining elements of ] 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 The column [U]. For example, the junction 112-w obtains and outputs the hidden element [x]. 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 The following columns [U] are arranged vertically.

[0052]

[0053] For example, in the specific case mentioned above,

[0054] [X0]={[a],[b],[e],[g]},[X1]={[b],[e]},[X2]={[a],[e]},

[0055] The joint 112-w obtains and outputs the column [U] of the following equation (3).

[0056]

[0057] [X0],...,[X L-1 The number L of [] is sent to the equality determination unit 114-w, and the column [U] is sent to the counting unit 113-w (step S112-w).

[0058] Input column [U] into counting unit 113-w. Counting unit 113-w uses the hidden element [x] of column [U]. 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 The counting results [c0],...,[c] are obtained and output through secret calculation. m-1 The column [c] = ([c0],...,[c]) m-1Where j(i) = 0, ..., r(i) - 1, m is an integer greater than or equal to 1, and k = 0, ..., k m-1 These are mutually exclusive key information, p=0,...,m-1. Each element x i,j(i) Represents key information k0,...,k m-1 any one of them, element x 0,0 ,...,x0, r(0)-1 ,...,x L-1,0 ,...,x L-1 , r(L-1)-1 The key information k in the middle represents p The number of elements is c. p .

[0059] Furthermore, the counting unit 113-w can also use the concealment element [x] 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 The anonymized key information [k0],...,[k] is obtained through secret computation. m-1 The column [k] = ([k0],...,[k]) m-1 That is, the counting unit 113-w can also obtain and output the column ([k],[c]) of the following equation (4).

[0060] ([k],[c])=([k0],...,[k m-1 ],[c0],...,[c m-1 (4)

[0061] For example, the counting unit 113-w can also obtain columns ([k],[c]) in the following manner by group-by count as shown in equation (1).

[0062] ([k],[c])←GroupbyCount([U]) (5)

[0063] For example, in the case of column [U] exemplified by equation (3), the following column ([k], [c]) is obtained by equation (5).

[0064] ([k],[c])=([a],[b],[e],[g],[2],[2],[3],[1]) (6)

[0065] Here, [k]=([a],[b],[e],[g]),[c]=([2],[2],[3],[1]).

[0066] With key information k0,...,k m-1 The corresponding column [k] = ([k0],...,[k]) m-1 The output flag assignment is sent to the output flag assignment section 115-w, column [c] = ([c0], ..., [c0]). m-1 The result is sent to the equality determination unit 114-w (step S113-w).

[0067] Input [X0],...,[X] into the equality determination unit 114-w L-1 The number of L and the column [c] = ([c0],...,[c]) m-1 The equality determination unit 114-w uses the number L and the counting results [c0],...,[c m-1 The equality determination result [eq0],...,[eq] is obtained and output through secret calculation. m-1 ]. Among them, in c p =L when eq p =T, not c p =L when eq p =F, T, and F are all different. For example, it can be either T=1 and F=0, or T=0 and F=1. For example, the equality determination part 114-w is for p=0,...,m-1 (that is, for [c p The following calculations are performed on p ∈ [c] (e.g., in parallel for p = 0, ..., m-1).

[0068] [eq p ]←E Q ([c p ],L)

[0069] For example, in the case of column [c] illustrated in equation (6), if T=1 and F=0 are set, the equality determination result shown in equation (7) is obtained.

[0070] [eq0]=[0],[eq1]=[0],[eq2]=[1],[eq3]=[0],[eq4]=[0] (7)

[0071] The result of the equality check is [eq0],...,[eq m-1 The column [eq] is sent to the output flag assignment section 115-w (step S114-w).

[0072] Assign the output flag to the 115-w input column [k]=([k0],...,[k m-1 ]) and column [eq]=([eq0],...,[eq m-1The output flag assignment section 115-w outputs concealed key information [k] that is correlated with each other for p=0,...,m-1. p And the result of the equality check [eq] p The result of the concealment operation [Z] is ([eq], [k]). For example, the output flag assignment unit 115-w outputs the following result of the concealment operation [Z].

[0073]

[0074] For example, in the case of [k]=([a],[b],[e],[g]) as exemplified by Equation (6) and [eq0]=[0],[eq1]=[0],[eq2]=[1],[eq3]=[0],[eq4]=[0] as exemplified by Equation (7), the following obfuscation operation result [Z] is output.

[0075]

[0076] In the result of this concealment operation [Z], [1] intersects with the set X0, X1, X2. 0≤i≤2 X i That is, {e} is associated with [e], and [0] is associated with other [a][b][g].

[0077] <Features of this embodiment>

[0078] Suppose that for the set X0={x 0,0 ,...,x0, r(0)-1},...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1}, belonging to the same set X i element x i,0 ,...,x i , r(i)-1 If there are no repetitions in the contents represented respectively, then the count result obtained from the counting unit 113-w [c] is compared with the count result obtained from the counting unit 113-w. p The number of corresponding elements c p (represents key information k) p (elements) and set X0,...,X L-1 The number L of the same value is equal, which means that in the set X0,...,X L-1 Each of them contains a key information k that represents the same key. p The element. Therefore, in the equality decision part 114-w, it becomes [eq p The key information k of [T] = [T] (e.g., [1]) p It is a set X0,...,XL-1 The intersection ∩ 0≤i≤L-1 X i The result of the operation is the element of the set. Therefore, it contains the hidden key information [k] that is interconnected. p And the result of the equality check [eq] p The data structure representing the intersection ∩ of the concealment operation result [Z]=([eq],[k]) is: 0≤i≤L- 1X i The information hidden in the result of the operation.

[0079] The method of this embodiment, regardless of the set X0,...,X L-1 The method can be applied directly regardless of whether the number L is 2 or 3 or more, and it can also be applied to sets X0,...,X... L-1 The hidden information is processed as direct input, and it is also possible to directly obtain the three or more X0,...,X L-1 The hidden information of the result of the intersection operation of sets X0,...,X. The processing of the counting unit 113-w is to hide the information of the result of the intersection operation of sets X0,...,X. L-1 The processing of the concealed information [U] of the combined U is independent of the value of L and can be performed directly by a single group-by-count. Furthermore, the number of bits of L compared by the equality determination unit 114-w is small (log2(L)), thus reducing computational cost. In [c p The equality determination of [] and L has no order dependency related to p, therefore it can be computed in parallel for p=0,...,m-1, enabling high-speed computation. In particular, the method of this embodiment is applicable to sets X0,...,X L-1 It is particularly effective in situations with a large number of processes or in environments where the length of execution time has a significant impact, such as in network environments with high latency.

[0080] In addition, the result of the concealment operation [Z] can be used to restore Z, or it can be used as an operand in subsequent secret computations.

[0081] [Second Implementation]

[0082] Next, the second embodiment of the present invention will be described. The column [k] obtained by the counting unit 113-w of the first embodiment is [k] = ([k0],...,[k...]. m-1 ]) is the key information k0,...,k m-1 Obtained by concealment, the column [c] = ([c0], ..., [c m-1 ]) is to set element x 0,0 ,...,x0, r(0)-1 ,...,x L-1,0 ,...,xL-1 , r(L-1)-1 The key information k0,...,k is respectively associated with the key information k0,...,k m-1 The number of identical elements c0,...,c m-1 It is obtained covertly. Therefore, the key information k0,...,k m-1 The entity itself and the number of its elements c0,...,c m-1 It is concealed, but [k0],...,[k m-1 The number m of [c0],...,[c m-1 The number m of [], i.e., the set X0,...,X L-1 The case where the elements are divided into m groups is not concealed. To conceal this, virtual information can be added. The following description focuses on the differences from the first embodiment, using the same reference numerals and notations for previously described items to simplify the explanation.

[0083] <Structure>

[0084] like Figure 1 As illustrated, the secret computing system 2 of the second embodiment has W secret computing devices 21-0,...,21-(W-1) configured to communicate via a network. Here, W is an integer greater than or equal to 1. For example, when the secret computing devices 21-0,...,21-(W-1) perform secret computing based on secret distribution, W is an integer greater than or equal to 2; when performing secret computing based on homomorphic encryption, W is an integer greater than or equal to 1.

[0085] like Figure 2 As illustrated, the secret computing device 21-w (where w = 0, ..., W-1) has an input unit 111-w, a connection unit 112-w, a counting unit 213-w, an equality determination unit 214-w, an output flag assignment unit 215-w, a control unit 118-w, and a storage unit 119-w. The secret computing device 21-w executes each process based on the control of the control unit 118-w. Data input to the secret computing device 11-w and data obtained from each process are stored in the storage unit 119-w and can be read out and used for other processes as needed.

[0086] <Processing>

[0087] L sets X0={x} are input to the input section 111-w of the secret computing device 21-w. 0,0 ,...,x0, r(0)-1},...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1 The hidden information of} [X0],...,[XL-1 (Step S111-w).

[0088] [X0],...,[X L-1 The input is fed into the junction 112-w. The junction 112-w receives and outputs [X0],...,[X L-1 The hidden element [x] is formed by combining elements of ] 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 ] column [U] (step S112-w).

[0089] Input column [U] into counting unit 213-w. Counting unit 213-w uses the hidden element [x] of column [U]. 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 The column [f] is obtained and output through secret computation ([f], [k], [c]). Column [f] contains m valid flags [f0], ..., [f...]. m-1 ] and nm virtual flags [f m ],...,[f n-1 The columns f0,...,f m-1 It is B1, f m ,...,f n-1 B0, B1, and B0 are all different. Here, n is an integer greater than m. Column [k] contains m hidden key information [k0],...,[k m-1 ] and nm virtual information [k m ],...,[k n-1 The column of ] and virtual information [k m ],...,[k n-1 The corresponding k m ,...,k n-1 Each of them can be associated with key information k0,...,k m-1 It can match any one of the following, or it can match the key information k0,...,k m-1 None of them are consistent. Column [c] contains m count results [c0],...,[c... m-1 ] and nm virtual information [c m ],...,[c n-1 The column [f] is valid for p=0,...,m-1. p ], Anonymized key information [k p], Counting results [c p They are interconnected. [c] with virtual information m ],...,[c n-1 The corresponding c m ,...,c n-1 They differ from L. Furthermore, for q=m,...,n-1, the virtual flag [f]... q Virtual information [k] q Virtual information [c] q They are interconnected. For example, the counting unit 213-w obtains and outputs the following column ([f],[k],[c]) of equation (9).

[0090] ([f],[k],[c])=([B1],...,[B1],[B0],...,[B0],[k0],...,[k m-1 ],[k m ],...,[k n-1 ],[c0],...,[c m-1 ],[c m ],...,[c n-1 ])

[0091] For example, the counting unit 213-w can also obtain columns ([f],[k],[c]) in the following manner by group-by count as shown in equation (2).

[0092] ([f],[k],[c])←GroupbyCount([U]) (9)

[0093] For example, with m=4 and n=5, in the case of column [U] exemplified by equation (3), the following column ([f],[k],[c]) is obtained by equation (9).

[0094] ([f],[k],[c])=([1],[1],[1],[1],[0],[a],[b],[e],[g],[*],[2],[2],[3],[1],[*]) (10)

[0095] here,

[0096] [f]=([1],[1],[1],[1],[0]),

[0097] [k]=([a],[b],[e],[g],[*]),

[0098] [c]=([2],[2],[3],[1],[*]),

[0099] [*] indicates virtual information.

[0100] column[k]=([k0],...,[k m-1 ],[k m ],...,[k n-1 The column [c] is sent to the output flag assignment section 215-w, column [c] = ([c0], ..., [c0]). m-1 ],[c m ],...,[c n-1 The result is sent to the equality determination unit 214-w (step S213-w).

[0101] Input [X0],...,[X] into the equality determination unit 214-w L-1 The number of L and the column [c] = ([c0],...,[c]) m-1 ],[c m ],...,[c n-1 The equality determination unit 214-w uses column ([f],[k],[c]) to secretly calculate the equality determination result [eq0],...,[eq0],... m-1 ] and virtual information [eq m ],...,[eq n-1 ], get and output the column containing them [eq]=([eq0],...,[eq m-1 ],[eq m ],...,[eq n-1 For p=0,...,m-1, [eq0],...,[eq m-1 Same as the first implementation. For q=m,...,n-1, [eq m ],...,[eq n-1 ] is eq m ,...,eq n-1 The hidden information. Among them, in c q =L when eq q =T, not c q =L when eq q =F, T and F for q=m,...,n-1 are the same as for p=0,...,m-1, but T and F are different from each other. As mentioned above, c m ,...,c n-1 They are inconsistent with L, therefore eq m =...=eq n-1 =F,([eq m ],...,[eq n-1 ])=([F],...,[F]).

[0102] For example, the equality determination part 214-w applies to u=0,...,n-1 (i.e., for [c u The following computations are performed on u ∈ [c] (e.g., computations are performed in parallel for u = 0, ..., n-1).

[0103] [eq u ]←E Q ([c u ],L)

[0104] For example, in the case of column [c] exemplified by equation (10), if T=1 and F=0, the following equation (11) shows the result of the equality determination.

[0105] [eq0]=[0],[eq1]=[0],[eq2]=[1],[eq3]=[0],[eq4]=[0],[eq5]=[0] (11)

[0106] The result of the equality check is [eq0],...,[eq n-1 The column [eq] is sent to the output flag assignment section 215-w (step S214-w).

[0107] Assign the output flag to the 215-w input column [k]=([k0],...,[k n-1 ]) and column [eq]=([eq0],...,[eq n-1 The output flag assignment unit 215-w outputs the anonymization operation result [Z]=([eq],[k]), which contains the anonymization key information [k] that has been correlated with each other for p=0,...,m-1. p And the result of the equality check [eq] p ], and virtual information [k] that is correlated with each other for q=m,...,n-1. q ] and virtual information [eq q For example, the output flag assignment unit 215-w outputs the following concealment operation result [Z].

[0108]

[0109] For example, in the case of [k]=([a],[b],[e],[g],[*]) as exemplified by Equation (10) and [eq0]=[0],[eq1]=[0],[eq2]=[1],[eq3]=[0],[eq4]=[0],[eq5]=[0] as exemplified by Equation (11), the following obfuscation operation result [Z] is output.

[0110]

[0111] In the result of this concealment operation [Z], [1] intersects with the set X0, X1, X2. 0≤i≤2 X i That is, {e} is associated with [e], and [0] is associated with other [a][b][g][*].

[0112] <Features of this embodiment>

[0113] Suppose that for the set X0={x 0,0 ,...,x0, r(0)-1},...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1}, belonging to the same set X i element x i,0 ,...,x i , r(i)-1 If there are no repetitions in the contents represented respectively, then the count result obtained from the counting unit 213-w [c] is compared with the count result obtained from the counting unit 213-w. p The number of elements c corresponding to p = 0, ..., m-1 p (represents key information k) p (elements) and set X0,...,X L-1 The number L of the same value is equal, which means that in the set X0,...,X L-1 Each of them contains a key information k that represents the same key. p The elements. Furthermore, with virtual information [c m ],...,[c n-1 The corresponding c m ,...,c n-1 They are different from L. Therefore, in the equality determination part 214-w, it becomes [eq u The key information k of ]=[T] (where u=0,...,n-1) u It is a set X0,...,X L-1 The intersection ∩ 0≤i≤L-1 X i The result of the operation is the element of the set. Furthermore, it relates to virtual information [k] m ],...,[k n-1 The corresponding k m ,...,k n-1 Each of the sets X0,...,X L-1 The actual key information k0,...,k m-1 None of them are consistent. Therefore, it contains concealed key information [k] that is correlated with each other. u And the result of the equality check [eq] uThe data structure representing the intersection ∩ of the concealment operation result [Z]=([eq],[k]) is: 0≤i≤L-1 X i The information hidden in the result of the operation.

[0114] The method of this embodiment, regardless of the set X0,...,X L-1 The method can be applied directly regardless of whether the number L is 2 or 3 or more, and it can also be applied to sets X0,...,X... L-1 The hidden information is processed as direct input, and it is also possible to directly obtain the three or more X0,...,X L-1 The hidden information of the result of the intersection operation of sets X0,...,X. The processing of the counting unit 213-w is to hide the information of the result of the intersection operation of sets X0,...,X. L-1 The processing performed on the hidden information [U] of U obtained by combining them is independent of the value of L and can be directly executed by a single group-by-count. Furthermore, the number of bits of L compared by the equality determination unit 214-w is small (log2(L)), thus reducing computational cost. In [c u The equality determination of ] and L has no order dependency related to u, therefore it can be computed in parallel for u=0,...,n-1, enabling high-speed computation. The method of this embodiment also applies to the set X0,...,X L-1 This method is particularly effective in situations with a large number of elements or in environments where the execution time has a significant impact, such as in high-latency network environments. Furthermore, the columns ([f],[k],[c]), column [eq], and the concealment operation result [Z] obtained by this implementation all contain virtual information, and the set X0,...,X... L-1 The case where the elements are divided into m groups is also concealed. Therefore, the method of this implementation is more secure.

[0115] Furthermore, the obfuscation result [Z] can be used to restore Z or as the pass operator for subsequent secret computations. For example, invalid elements (rows) corresponding to virtual information can be deleted from the obfuscation result [Z] using the methods disclosed in Reference 5, etc., and the obtained result can be used for other database operations.

[0116] Reference 5: Hiroki Sudo, Dai Igarashi, "The secret calculation of the number of lines and the secret calculation of the management system," In SCIS2021, pp. 1-6, 2021.

[0117] [Hardware Structure]

[0118] The secret computing devices 11-w and 21-w in each embodiment are, for example, devices configured to execute a predetermined program using a general-purpose or special-purpose computer equipped with a processor (hardware processor) such as a CPU (central processing unit), a memory such as RAM (random-access memory), and a memory such as ROM (read-only memory). That is, the secret computing devices 11-w and 21-w in each embodiment, for example, have processing circuitry configured to implement their respective components. The computer may have one processor and memory, or it may have multiple processors and memories. The program may be installed in the computer or pre-recorded in ROM or the like. Furthermore, instead of using an electronic circuitry that implements the functional structure by loading a program like a CPU, a separate electronic circuitry that implements the processing function may be used to constitute part or all of the processing unit. Furthermore, the electronic circuitry constituting a single device may include multiple CPUs.

[0119] Figure 4 This is a block diagram illustrating the hardware structure of the secret computing devices 11-w and 21-w in various embodiments. For example... Figure 4As illustrated, the secret computing devices 11-w and 21-w in this example include a CPU (Central Processing Unit) 10a, an input unit 10b, an output unit 10c, RAM (Random Access Memory) 10d, ROM (Read Only Memory) 10e, auxiliary storage device 10f, and a bus 10g. The CPU 10a in this example includes a control unit 10aa, an arithmetic unit 10ab, and a register 10ac, performing various arithmetic operations based on programs read into the register 10ac. Furthermore, the input unit 10b includes input terminals for inputting data, a keyboard, a mouse, a touch panel, etc. Furthermore, the output unit 10c includes output terminals for outputting data, a display, a LAN card controlled by the CPU 10a which has a predefined program loaded into it, etc. Furthermore, RAM 10d is SRAM (Static Random Access Memory), DRAM (Dynamic Random Access Memory), etc., and has a program area 10da for storing a specified program and a data area 10db for storing various data. Furthermore, auxiliary storage device 10f is, for example, a hard disk, MO (Magneto-Optical Disc), semiconductor memory, etc., and has a program area 10fa for storing a specified program and a data area 10fb for storing various data. Furthermore, bus 10g connects CPU 10a, input unit 10b, output unit 10c, RAM 10d, ROM 10e, and auxiliary storage device 10f to enable information exchange. CPU 10a writes the program stored in program area 10fa of auxiliary storage device 10f into program area 10da of RAM 10d according to the read OS (Operating System) program. Similarly, CPU 10a writes various data stored in data area 10fb of auxiliary storage device 10f into data area 10db of RAM 10d. Then, the address on RAM 10d where the program and data are written is stored in register 10ac of CPU 10a. Control unit 10aa of CPU 10a sequentially reads these addresses stored in register 10ac, reads the program and data from the area on RAM 10d represented by the read address, causes arithmetic unit 10ab to sequentially execute the operation represented by the program, and stores the operation result in register 10ac. With this structure, the functional structure of secret computing devices 11-w and 21-w is realized.

[0120] The above-described program can be pre-recorded on a computer-readable recording medium. Examples of computer-readable recording media are non-transitory recording media. Examples of such recording media include magnetic recording devices, optical discs, optical-magnetic recording media, and semiconductor memories.

[0121] The program can be distributed, for example, through the sale, transfer, or rental of removable recording media such as DVDs and CD-ROMs containing the program. Alternatively, the program can be stored in the server computer's storage device and forwarded from the server computer to other computers via a network, thus distributing the program. As described above, a computer executing such a program may first temporarily store the program recorded on a removable recording medium or the program forwarded from the server computer in its own storage device. Then, during processing, the computer reads the program stored in its own storage device and executes the processing according to the read program. Furthermore, as another method of executing the program, the computer may directly read the program from the removable recording medium and execute the processing according to the program; or, each time the program is forwarded from the server computer to the computer, the processing according to the received program is executed sequentially. Alternatively, the program may not be forwarded from the server computer to the computer, but the above processing may be performed through a so-called ASP (Application Service Provider) type service that only obtains the execution instructions and results to achieve the processing function. Furthermore, it is assumed that the program in this method includes information provided for computer-based processing and is subject to the program (data, etc., which, although not direct instructions to the computer, have the nature of specifying the computer's processing).

[0122] In various embodiments, the device is configured to be constructed by executing a prescribed program on a computer, but at least a portion of these processing contents may also be implemented by hardware.

[0123] Furthermore, the present invention is not limited to the embodiments described above. For example, it can be executed not only in a time sequence as described, but also in parallel or individually depending on the processing capability of the device performing the processing or as needed. Moreover, appropriate modifications can, of course, be made without departing from the spirit of the present invention.

[0124] Industrial applicability

[0125] This invention can be applied to the use of secret computation to perform product sum operations on two or more sets. For example, this invention can be used to perform product sum operations using an RDBMS (Relational Database Management System) via secret computation.

[0126] Explanation of reference numerals in the attached figures

[0127] 1. Secret Computing System

[0128] 11-w, 21-w secret computing devices

[0129] 113-w, 213-w counting units

[0130] 114-w, 214-w equality determination section

[0131] 115-w, 215-w Output Flag Assignment Section

Claims

1. A secret computing device, which, when processing L sets X0={x...} 0,0 ,...,x0, r(0)-1 },...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1 In the hidden state, we obtain a representation of the set X0,...,X L-1 The result of the concealment operation of the intersection of the concealed information. L is an integer greater than or equal to 2, i = 0, ..., L-1, r(i) is an integer greater than or equal to 1, j(i) = 0, ..., r(i)-1, m is an integer greater than or equal to 1, k = 0, ..., k m-1 These are distinct key information, p=0,...,m-1, and [α] is the concealment information obtained after concealing element α. The secret computing device includes a counting unit, an equality determination unit, and an output flag assignment unit. Each element x i,j(i) This represents the key information k0,...,k m-1 any one of them, element x 0,0 ,...,x0, r(0)-1 ,...,x L-1,0 ,...,x L-1 , r(L-1)-1 The key information k in the middle represents p The number of elements is c. p , The counting section uses the concealment element [x] 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 The counting results [c0],...,[c] are obtained through secret calculation. m-1 ], The equality determination unit uses the counting results [c0],...,[c m-1 The equality determination result is obtained through secret calculation: [eq0],...,[eq m-1 ], in c p =L when eq p =T, in c p When not equal to L, eq p =F, T, and F represent the true and false values, respectively. The output flag assignment section outputs hidden key information [k] that is correlated with each other. p ] and the result of the equality check [eq p The result of the concealment operation, The counting unit uses the concealment element [x] 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 ], and further anonymization key information [k0],...,[k] is obtained through secret computation. m-1 ].

2. The secret computing device as claimed in claim 1, wherein, n is an integer greater than m. The counting unit obtains a column ([f],[k],[c]). Column [f] contains m valid flags [f0],...,[f m-1 ] and nm virtual flags [f m ],...,[f n-1 The columns f0,...,f m-1 It is B1, f m ,...,f n-1 B0, B1, and B0 are the same or different. Column [k] contains m anonymization key information [k0],...,[k] m-1 ] and nm virtual information [k m ],...,[k n-1 ] column, Column [c] contains m count results [c0],...,[c...] m-1 ] and nm virtual information [c m ],...,[c n-1 ] column, For p=0,...,m-1, the effective flag [f] p ], Anonymized key information [k p ] and counting results [c p They are interconnected. For q=m,...,n-1, the virtual flag [f q Virtual information [k] q ] and virtual information [c q They are interconnected. The equality determination unit uses the column ([f],[k],[c]) to secretly calculate the equality determination result [eq0],...,[eq0] m-1 ] and virtual information [eq m ],...,[eq n-1 ], The output flag assignment unit outputs the anonymization operation result, which includes the anonymization key information [k] that has been correlated with each other for p=0,...,m-1. p ] and the result of the equality determination [eq p ], and virtual information [k] that is correlated with each other for q=m,...,n-1. q ] and virtual information [eq q ].

3. The secret computing device as described in claim 1 or 2, wherein, L is an integer greater than or equal to 3.

4. A secret computing system comprising the secret computing device as described in any one of claims 1 to 3.

5. A secret computing method for a secret computing device, wherein L sets X0={x 0,0 ,...,x0, r(0)-1 },...,X L-1 ={x L-1,0 ,...,x L-1 , r(L-1)-1 In the hidden state, we obtain a representation of the set X0,...,X L-1 The result of the concealment operation of the intersection of the concealed information. L is an integer greater than or equal to 2, i = 0, ..., L-1, r(i) is an integer greater than or equal to 1, j(i) = 0, ..., r(i)-1, m is an integer greater than or equal to 1, k = 0, ..., k m-1 These are distinct key information, p=0,...,m-1, and [α] is the concealment information obtained after concealing element α. The secret calculation method includes a counting step, an equality check step, and an output flag assignment step. Each element x i,j(i) This represents the key information k0,...,k m-1 any one of them, element x 0,0 ,...,x0, r(0)-1 ,...,x L-1,0 ,...,x L-1 , r(L-1)-1 The key information k in the middle represents p The number of elements is c. p , In the counting step, the counting unit uses the concealment element [x] 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 The counting results [c0],...,[c] are obtained through secret calculation. m-1 ], In the equality determination step, the equality determination unit uses the counting results [c0],...,[c m-1 The equality determination result is obtained through secret calculation: [eq0],...,[eq m-1 ], in c p =L when eq p =T, in c p When not equal to L, eq p =F, T, and F represent the true and false values, respectively. In the output flag assignment step, the output flag assignment unit outputs obfuscated key information [k] that is correlated with each other. p ] and the result of the equality check [eq p The result of the concealment operation, In the counting step, the counting unit uses the concealment element [x] 0,0 ],...,[x0, r(0)-1 ],...,[x L-1,0 ],...,[x L-1 , r(L-1)-1 ], and further anonymization key information [k0],...,[k] is obtained through secret computation. m-1 ].

6. A computer-readable recording medium storing a program for enabling a computer to function as a secret computing device as claimed in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Device and process for the signature, the marking and the authentication of computer programs

    US20060010430A1

  • Systems and methods for establishing a link between identifiers without disclosing specific identifying information

    US20180254893A1