Secret-combining device, secret-combining method, and recording medium
Patent Information
- Application Number
- CN202180099886.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-07-02
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2041-07-02
AI Technical Summary
[0003]此外,在使用被保存在数据库中的表格来进行计算的情况下,存在在一个表格中计算所需要的信息不全面,从多个表格收集信息并计算的情况
[0019]由此,即使在作为等结合对象的2个表格之中的一方的表格的键列包含值彼此相同的多个键,并且另一方的表格的键列也包含值相同的多个键的情况下,也能够在隐匿表格的信息的状态下快速地等结合2个表格。
Smart Images

Figure CN117561557B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to secret computing technology, and particularly to a secret equal-joining technology for equal-joining two tables while concealing the information in the tables. Background Technology
[0002] In conventional encryption methods, even if data intended to be hidden is anonymized (encrypted) and stored on a server, it is decrypted before computation can be performed. However, secret computation exists as a technique that allows computation to be performed while data is anonymized. In secret computation, a value is transformed into multiple anonymized shares, and multiple secret computing devices possess each share, performing addition, multiplication, logical operations, etc. (multi-party protocol) without revealing their own share information.
[0003] Furthermore, when performing calculations using tables stored in a database, there are situations where the information required for calculation in a single table is incomplete, necessitating the collection of information from multiple tables for calculation. Therefore, it is necessary to perform preprocessing that combines multiple tables. Patent Document 1 discloses a technique that, while concealing the table information, uses the elements (keys) of the selected key column as key attributes to equally combine two tables.
[0004] Existing technical documents
[0005] Patent documents
[0006] Patent Document 1: International Publication No. 2018 / 061800 Summary of the Invention
[0007] The problem that the invention aims to solve
[0008] The technology in Patent Document 1 can also be applied when the key column of one of the two tables that are equally combined contains multiple keys (key attributes) with the same value.
[0009] However, the technique of Patent Document 1 cannot be directly applied when one party's table has multiple keys with the same values in its key column, and the other party's table also has multiple keys with the same values in its key column.
[0010] Here, when the maximum number of keys with the same value contained in the key column of one side's table is set to KL, by dividing the table of one side into KL tables whose key columns do not contain keys with the same value, and using the technique of Patent Document 1 to perform KL sub-secret combinations, the output can be obtained by combining the KL tables that are output as a result.
[0011] However, partitioning the table while hiding values is difficult, and the process of partitioning leads to the leakage of information related to the partitioned tables (e.g., information related to the number of keys with identical values in the original tables). Furthermore, in this method, in addition to secret binding, the processing time for partitioning the table before secret binding and binding the table after secret binding is expensive. In particular, the table binding processing cannot be parallelized, thus becoming a bottleneck for processing performance.
[0012] In this invention, a technique is provided that enables the rapid equal combination of two tables even when one of the tables being combined contains multiple keys with the same values, and the other table also contains multiple keys with the same values, while concealing the table information.
[0013] Methods for solving problems
[0014] The first hidden table is the hidden information of a first table containing a first key column with multiple first keys and a first arbitrary element column with multiple first arbitrary elements. The second hidden table is the hidden information of a second table containing a second key column with multiple second keys and a second arbitrary element column with multiple second arbitrary elements. The following processing is performed on the first hidden table and the second hidden table.
[0015] The first subkey column appending section obtains a first hidden appending table by using secret calculations of the first hidden table. This first hidden appending table serves as the hidden information of the first appended table obtained by appending the first subkey column to the first table. The first subkey column has multiple first subkeys, and each first subkey corresponds to each of the first keys. The maximum number of first keys in the first key column with identical values is KL, where KL is an integer greater than or equal to 2. First subkeys with distinct values correspond to first keys with identical values.
[0016] The second subkey column appending section obtains a second concealed appending table by using secret computation of the second concealed table. This second concealed appending table serves as the concealed information of the second appending table obtained by appending the second subkey column to the third table. The third table is obtained by appending multiple copied records to the second table, resulting from copying each record of the second table K times (where K≥KL). Each record in the second table contains a second key and a second arbitrary element. The third table contains a third key column and a third arbitrary element column. The third key column has multiple third keys containing the second key and copies of the second key, and the third arbitrary element column has multiple third arbitrary elements containing the second arbitrary element and copies of the second arbitrary element. The second subkey column has multiple second subkeys. Each second subkey corresponds to each of the third keys. When the third key column contains a third key representing a common value identical to any first key, the second subkeys with the same first subkey value as the first key representing the common value correspond to at least a portion of the third keys representing the common value.
[0017] The secret combination part obtains a hidden combination table by using the secret calculation of the first hidden append table and the second hidden append table. In this hidden combination table, the group of the first key and the first subkey is set as the key attribute of the first append table, and the group of the third key and the second subkey is set as the key attribute of the second append table. This hidden combination table serves as the hidden information of the combination table obtained by combining the first append table and the second append table.
[0018] Invention Effects
[0019] Therefore, even if one of the two tables being combined contains multiple keys with the same values in its key column, and the other table also contains multiple keys with the same values in its key column, the two tables can be quickly combined without concealing the information of the tables. Attached Figure Description
[0020] Figure 1 It is a block diagram used to illustrate the structure of the secret combination system of the implementation method.
[0021] Figure 2 This is a block diagram illustrating the structure of a secret or other connecting device used to illustrate an embodiment.
[0022] Figure 3 This is a flowchart illustrating the combination method of secrets, etc., in the implementation of the method.
[0023] Figure 4A This is a diagram used to illustrate combined objects such as Table 110 (the first table). Figure 4B This is a diagram used to illustrate combined objects such as Table 120 (the second table).
[0024] Figure 5A This is a diagram used to illustrate the appended table 130 (first appended table) obtained by adding a subkey column (first subkey column) to table 110 (first table). Figure 5B This is a diagram used to illustrate a table 140 (third table) obtained by adding multiple copied records to table 120 (second table) by copying each record of table 120.
[0025] Figure 6 This is a diagram used to illustrate the appended table 150 (second appended table) obtained by adding subkey column 151 (second subkey column) to table 140 (third table).
[0026] Figures 7A to 7C It is a diagram used to illustrate tables and other combined objects. Figure 7D It is used to illustrate pairs Figures 7A to 7C A table diagram obtained by combining tables, etc.
[0027] Figure 8 It is a diagram used to illustrate combinations such as examples.
[0028] Figure 9A It is used to demonstrate Figure 7B The table (first appended table) is a diagram of the table (first table) with the sequence number (SeqNo) column (first subkey column) added. Figure 9B It is used to illustrate Figure 7C The diagram shows a table (second appended table) obtained by copying each record of the table (second table) and appending multiple copied records to the table, and then adding a sequence number column (second subkey column).
[0029] Figure 10 This is used to demonstrate setting the identifier (ID) and sequence number (SeqNo) as key attributes, and combining them. Figure 9A The table (first supplementary table) and Figure 9B A diagram of a table obtained from the table (the second supplementary table).
[0030] Figure 11 This is a block diagram illustrating the hardware structure of the secret combination device in an illustrative embodiment. Detailed Implementation
[0031] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings.
[0032] [Definitions of terms and symbols]
[0033] The following defines the terms and notations used in this embodiment.
[0034] The following notation is used in the markings of tables.
[0035] TX: A column X in table T is labeled TX.
[0036] The j-th record in table T is labeled T. j J is an integer greater than or equal to 0.
[0037] The value of column X of the j-th record in table T is labeled TX. j .
[0038] Cross join: Also known as a "cross join", a cross join is a combination of all records from two input tables, TL and TR, to obtain the set of records from table TL. j And the records TL in table TR p The method for combining tables in the corresponding TLR is described. Here, j is an integer greater than or equal to 0, p is an integer greater than or equal to 0, j = 0,...,LRN-1, p = 0,...,RRN-1, LRN is a positive integer representing the number of records in table TL, and RRN is a positive integer representing the number of records in table TR. That is, the resulting TLR is a table formed by combining records from tables TL and TR (TL0,...,TL...). LRN-1 And TR0,...,TR RRN-1 The product of tables TL and TR. The number of records in table TLR, the result of the cross-combination of tables TL and TR, is LRN*RRN. Here, "*" is the multiplication operator. In practical applications, it is often necessary to select only records that meet certain conditions based on table TRL and then utilize them.
[0039] Equivalence join: Also known as equivalence join or inner join, it is a join of two input tables TL and TR, resulting in table TRL, where the join is performed on the attribute (key attribute TL.Key) selected from table TL. j ) and the attribute selected from table TR (key attribute TR.Key) p ), obtain only the equal sign (TL.Key) j =TR.Key p This refers to the table combination method of ETRL, which is obtained by combining records from two input tables, TL and TR. Additionally, the key attribute is an element of the selected column. That is, combination is performed on records from the two input tables, TL and TR, that satisfy TL.Key. j =TR.Key p A combination of all records, retrieves the records in table TL. j And the records TL in table TR p The corresponding tables are obtained by combining the tables in ETLR.
[0040] The following symbols are used in the marking of hidden information.
[0041] [a]: The hidden information of a is marked as [a]. For example, a∈Z n The share obtained by secretly distributing 'a' to enable secret computation can also be [a] (e.g., see reference 1, etc.), and the ciphertext obtained by encrypting 'a' to enable secret computation (the ciphertext of homomorphic encryption) can also be [a]. When 'a' is secretly distributed into N groups (N is an integer greater than 1), N shares [a] are obtained for 'a': 0, ..., [a]. N-1 And targeting shares [a]0,...[a] N-1 Each share performs secret computation. However, since the algorithms for these secret computations are public to all shares, [a]0,...[a] are omitted. N-1 The subscript is marked as [a].
[0042] Reference 1: Koji Chida, Hiroshi Hamada, Dai Igarashi, Katsumi Takahashi, "A Three-Party Secure Function Evaluation with LightweightVerifiability Revisited," In CSS, 2010.
[0043] Z n Z n Let n be a finite ring consisting of the set of integers from 0 to n-1 (where n is an integer greater than or equal to 1).
[0044] [T]: Marks hidden information in a table T as [T].
[0045] [TX]: Marks the hidden information of column TX as [TX]. The hidden values are stored in each record (i.e., each field) of [TX].
[0046] [T j ]: Record T j The hidden information is marked as [T] j ]. [T j The columns (i.e., fields) of the array contain hidden values.
[0047] [TX j ]: Calculate the value TX of column X of the j-th record in table T. j The hidden information is marked as [TX] j That is, each field of [T] stores hidden information about the values of each field in table T.
[0048] [First Implementation Method]
[0049] The first embodiment of the present invention will be described.
[0050] <Structure>
[0051] like Figure 1 As illustrated, the secret binding system 1 of this embodiment includes N secret binding devices 10-0, ..., 10-(N-1). The secret binding devices 10-0, ..., 10-(N-1) of this embodiment are communicatively connected via a network. Here, when performing secret computation based on secret distribution, N is an integer of 2 or more (e.g., N = 3), and when performing secret computation based on homomorphic encryption, N is an integer of 1 or more (e.g., N = 1).
[0052] like Figure 2 As illustrated, each secret combination device 10-n (where n = 0, ..., N-1) has an input unit 11-n, a storage unit 12-n, a subkey column addition unit 13-n (first subkey column addition unit), a subkey column addition unit 14-n (second subkey column addition unit), a secret combination unit 15-n, an output unit 16-n, a control unit 17-n, and a memory 18-n. Descriptions are omitted below, but each secret combination device 10-n executes each process based on the control unit 17-n, stores the input data and the data obtained from each process in the memory 18-n, and reads and uses them as needed.
[0053] <Preprocessing>
[0054] As preprocessing, the concealment tables (first concealment table) [TL] and the concealment table (second concealment table) [TR] of the secret binding objects are input to each secret binding device 10-n. Figure 2 The input section 11-n is used to store the data in the storage section 12-n.
[0055] Figure 4A An example of a hidden table [TL] is provided. The hidden table [TL] contains hidden information for table TL (first table, left table). Table TL contains multiple (LRN) keys: TL.Key0, ..., TL.Key0. LRN-1 The key column TL.Key (first key column) and the arbitrary element TL.V(v) (LRN elements) 0,...,TL.V(v) LRN-1 The arbitrary element sequence TL.V(v) of (the first arbitrary element). Where v = 0, ..., LVN-1, and LVN is a positive integer representing the number of arbitrary elements in the sequence. The j-th record of table TL... jIncludes key TL.Key j And LVN arbitrary elements TL.V(0) j ,...,TL.V(LVN-1) j The number of records in table TL is LRN, which in this embodiment is an integer greater than or equal to 2.
[0056] Specifically, the cloning table [TL] illustrated in this embodiment contains multiple (LRN) cloning keys [TL.Key0],...,[TL.Key0] LRN-1 The hidden key sequence [TL.Key] and the hidden arbitrary elements [TL.V(v)0],...,[TL.V(v)] with multiple (LRN) hidden elements. LRN-1 An arbitrary column of elements [TL.V(v)]. Hidden records [TL.V(v)]. j [Contains the stealth key [TL.Key]] j ] and LVN concealed arbitrary elements [TL.V(0)] j ],...,[T LV(LVN-1) j ]( Figure 4A ).
[0057] The obfuscation table [TL] in this embodiment is a table sorted based on the key column TL.Key of the obfuscation key column [TL.Key]. This sorting can be performed either before obfuscation or after obfuscation through secret computation. Sorting methods based on secret computation are well known, for example, and are disclosed in Reference 2, etc.
[0058] Reference 2: Dai Igarashi, Hiroshi Hamada, Ryo Kikuchi, and Koji Chida, "Ultra-fast secret calculation design and design: Secret calculation design and day," CSS, 2017.
[0059] Furthermore, the key column TL.Key (first key column) of table TL contains two or more but less than KL keys (first keys) with the same value. That is, the key column TL.Key contains multiple keys with repeated values, and the maximum number of repetitions (the maximum number of first keys with the same value contained in the first key column) is KL. KL is an integer greater than or equal to 2. The value of KL also corresponds to the hidden table [TL] and is stored in storage section 12-n.
[0060] Figure 4B An example of a hidden table [TR] is provided. A hidden table [TR] is the hidden information of table TR (the second table, the right table). Table TR contains multiple (RRN) keys TR.Key0,...,TR.Key RRN-1The key column TR.Key (second key column) and TR.V(w) (with multiple (RRN) arbitrary elements) 0,...,TR.V(w) RRN-1 The arbitrary element sequence TR.V(w) of (the second arbitrary element). Where w = 0, ..., RVN-1, and RVN is a positive integer representing the number of arbitrary elements in the sequence. The p-th record of table TR... p Contains key TR.Key p And RVN arbitrary elements TR.V(0) p ,...,TR.V(RVN-1) p The number of records in table TR is RRN, which in this embodiment is an integer greater than or equal to 2.
[0061] Specifically, the stealth table [TR] illustrated in this embodiment contains multiple (RRN) stealth keys [TR.Key0],...,[TR.Key0] RRN-1 The hidden key sequence [TR.Key] and the multiple (RRN) anonymized arbitrary elements [TR.V(w)0],...,[TR.V(w)] RRN-1 An arbitrary column of elements [TR.V(w)]. Hidden records [TR] p [Contains the stealth key [TR.Key]] p [TR.V(0)] and RVN concealed arbitrary elements p ],...,[TR.V(RVN-1) p ]( Figure 4B ).
[0062] The obfuscation table [TR] in this embodiment is a table sorted based on the key column TR.Key of the obfuscation key column [TR.Key]. This sorting can be performed either before obfuscation or after obfuscation through secret computation.
[0063] Furthermore, the key column TR.Key (second key column) of table TR contains two or more keys (second keys) with the same value but fewer than KR. That is, the key column TR.Key contains multiple keys with repeated values, and the maximum number of repetitions (the maximum number of second keys with the same value contained in the second key column) is KR. KR is an integer greater than or equal to 2. The value of KR also corresponds to the hidden table [TR] and is stored in storage section 12-n.
[0064] <Processing>
[0065] use Figure 3 The combination method of the secrets of this embodiment will be explained.
[0066] Processing of Subkey Column Appendage Section 13-n (Steps S13-n)
[0067] Various secret combination devices 10-n ( Figure 2 The subkey column appending section 13-n (first subkey column appending section) secretly calculates the hidden appending table [TLs] (first hidden appending table) read from the storage section 12-n using the hidden table (first hidden table) [TL] and outputs it. Figure 5A The hidden append table [TLs] is the hidden information of the append table TLs (first append table) obtained by appending the subkey column TLs.S (first subkey column) to the table TL (first table).
[0068] like Figure 5A As illustrated, appending the key column TLs.Key of table TLs is the table TL( Figure 4A The key column TL.Key (first key column) and the keys TLs.Key0,...,TLs.Key of the key column TLs.Key. LRN-1 It is TLs.Key0=TL.Key0,...,TLs.Key LRN-1 =TL.Key LRN-1 (First key). Appending any element column TLs.V(v) to table TLs is the table TL( Figure 4A Let TL.V(v) be an arbitrary list of elements of TL.V(v), and let TLs.V(v) be any elements of the arbitrary list TL.V(v), where 0,...,TLs.V(v) are any elements of TL.V(v). LRN-1 It is TLs.V(v)0=TL.V(v)0,...,TLs.V(v) LRN-1 =TL.V(v) LRN-11 (First arbitrary element).
[0069] like Figure 5A As illustrated, the subkey column TLs.S (the first subkey column) has multiple (LRN) subkeys TLs.S0,...,TLs.S LRN-1 (First subkey). Subkeys TLs.S0,...,TLs.S LRN-1 Any one of the keys TL.Key0,...,TL.Key LRN-1 The various correspondences of (first key). In Figure 5A In the example, subkeys TLs.S j Each with the key TL.Key j Specifically, the hidden subkeys [TLs.S] correspond to this. j ] respectively with the occultation bond [TL.Key j ]correspond.
[0070] As described above, the key column TL.Key (the first key column) contains two or more but fewer than KL keys (the first key) with the same value. Subkeys TLs.S have distinct values. j (First subkey) AND key TL.Key0,...,TL.Key LRN-1 Keys with the same value (first key) correspond to each other. Figure 5A In the example, TLs.S are subkeys with distinct values. j The hidden subkeys of the hidden information [TLs.S j [TL.Key0],...,[TL.Key LRN-1 The hidden keys that are identical to the recovery values (decryption values) in the [ ] correspond to each other.
[0071] For j = 0, ..., LRN-1, if the instance key TL.Key j and subkeys TLs.S j The relationship is as follows.
[0072] When (b-1)j = 0, TLs.S j =0
[0073] (b-2) If j > 0 and TL.Key j ≠TL.Key j-1 Then TLs.S j =0
[0074] (b-3) If j > 0 and TL.Key j =TL.Key j-1 Then TLs.S j =TLs.S j-1 +1
[0075] Here (b-1) refers to the subkey TLs.S j =0 corresponds to the initial key TL.Key0. (b-2) refers to the second and subsequent keys TL.Key. j With the preceding key TL.Key j-1 When the values are different, subkeys TLs.S j =0 and the key TL.Key j Corresponding. (b-3) refers to the second and subsequent keys TL.Key j With the preceding key TL.Key j-1 When the values are the same, subkeys TLs.S j =TLs.S j-1 +1 and the key TL.Key jCorrespondingly, since the hidden table [TL] is a table sorted based on the key column TL.Key of the hidden key column [TL.Key], the subkeys TLs.S with distinct values (such as 0, 1, 2, 3... incrementing by 1) are obtained through (b-1)(b-2)(b-3). j AND keys TL.Key0,...,TL.Key LRN-1 Keys with identical values correspond to each other. This is just one example and is not intended to limit the invention. The subkey column appending section 13-n, in order to perform (b-1)(b-2)(b-3) in the state of concealed values using secret computation via the concealed table [TL], needs to compute the concealed [TLs.S] using the concealed [TL.Key]. In this computation, the method used in the secure grouping computation of reference 3 can be used.
[0076] Reference 3: Hamada Hiroshi, Igarashi Dai, Chida Koji, "Integrated key central value calculation of secret calculations," In CSS, 2012.
[0077] Secret grouping is a method that groups data by column [Key] values within a hidden table [T] and calculates the median of each group. Reference 3 describes how to group data with the same Key value within a secretly sorted table [T] based on the Key column. j The hidden value [Key] j The method of assigning hidden values with increments starting from 0 (calculation of step +). If the function performing this operation is expressed as groupby, then the subkey column appending part 13-n can be obtained from [TL.Key] as follows.
[0078] The groupby function:
[0079] [TLs.S] = groupby([TL.Key])
[0080] Input: [TL.Key]
[0081] Output: [TLs.S]
[0082] Processing of Subkey Column Appendage Section 14-n (Steps S14-n)
[0083] The subkey column appending unit 14-n (second subkey column appending unit) of each secret combination device 10-n obtains and outputs the concealment appending table [TRs] (second concealment appending table) by using the secret calculation of the concealment table (second concealment table) [TR] read from the storage unit 12-n. Figure 5B as well as Figure 6 The hidden append table [TRs] is the hidden information of the append table TRs (second append table) obtained by appending the subkey column TRs.S (second subkey column) to the table TRc (third table).
[0084] Table TRc (the third table) is an appendix to table TR (the second table) containing data from table TR (the second table). Figure 4B Each record TR p (Where p = 0, ..., RRN-1) A table obtained from multiple copy records acquired every K copies. Figure 5B Where K ≥ KL, preferably K = KL. In this embodiment, the value of KL is read from the storage unit 12-n and used. As described above, each record TR of table TR (second table) p Contains key TR.Key p (Second key) and any element TR.V(0) p ,...,TR.V(RVN-1) p (Second arbitrary element). For example... Figure 5B The example [TRc] adds [TR] to [TR] and adds the various [TR] values of [TR]. p [TR](where p = 0, ..., RRN-1) is a table obtained from multiple hidden copy records acquired every K copies. For example, [TR] contains each [TR] p [TR.Key] p [] and [TR.V(0)] p ],...,[TR.V(RVN-1) p ].
[0085] like Figure 5B As illustrated, the key column TRc.Key (third key column) of table TRc (third table) contains RRN*K keys: TRc.Key0 = TR.Key0, ..., TRc.Key0. K-1 =TR.Key0,TRc.Key K =TR.Key1,...,TRc.Key 2K-1 =TR.Key1,...,TRc.Key RRN*K-1 =TR.Key RRN-1 (Second key and multiple third keys containing copies of the second key). Any column TRc.V(v) (the third arbitrary column) of table TRc contains TRc.V(v)0 = TR.V(v)0,...,TRc.V(v) K-1 =TR.V(v)0,TRc.V(v) K=TR.V(v)1,...,TRc.V(v) 2K-1 =TR.V(v)1,...,TRc.V(v) RRN*K-1 =TR.V(v) RRN-1 (A second arbitrary element and multiple third arbitrary elements that include copies of the second arbitrary element).
[0086] like Figure 6 As illustrated, appending the key column TRs.Key of table TRs is the key column of table TRc( Figure 5B The key column TRc.Key (the third key column) contains RRN*K keys TRs.Key0 = TR.Key0, ..., TRs.Key K-1 =TR.Key0,TRs.Key K =TR.Key1,...,TRs.Key 2K-1 =TR.Key1,...,TRs.Key RRN*K-1 =TR.Key RRN-1 (Second key and multiple third keys containing copies of the second key). Appending any element column TRs.V(v) to table TRs is a table TRc( Figure 5B Let TRc.V(v) be an arbitrary list of elements (the third arbitrary list), containing TRs.V(v)0 = TR.V(v)0, ..., TRs.V(v). K-1 =TR.V(v)0,TRs.V(v) K = TR.V(v)1,...,TRs.V(v) 2K-1 = TR.V(v)1,...,TRs.V(v) RRN*K-1 =TR.V(v) RRN-1 (A second arbitrary element and multiple third arbitrary elements that include copies of the second arbitrary element).
[0087] The append table TRs (second append table) has a subkey column TRs.S (second subkey column) that has multiple (RRN*K) subkeys TRs.S0,...,TRs.S RRN*K-1 (Second subkey). Subkeys TRs.S0,...,TRs.S RRN*K-1 Any of the (second subkeys) is associated with the key TRs.Key0 of the appended table TRs = TR.Key0,...,TRs.Key K-1 =TR.Key0,TRs.Key K =TR.Key1,...,TRs.Key 2K-1 =TR.Key1,...,TRs.Key RRN*K-1 =TR.Key RRN-1The correspondences of (third key). In this embodiment, subkey TRs.S i (where i = 0, ..., RRN*K-1) and the key TRs.Key i Correspondence. For example, subkeys TRs.S with distinct values. i AND keys TRs.Key0,...,TRs.Key RRN*K-1 Keys with the same value correspond to each other. Figure 6 In the example, TRs.S are subkeys with distinct values. i The hidden subkeys of the hidden information [TRs.S i [TRs.Key0],...,[TRs.Key RRN*K-1 The hidden keys that are identical to each other in the [ ] are the same.
[0088] Furthermore, for example, in the append table TRs (second append table), the key column TRs.Key (third key column, TRc.Key) ( Figure 6 ) contains representations and append tables TLs( Figure 5A Any key in TLs.Key j (First key, TL.Key) j TRs.Key with the same value (common value) i (Third key, TR.Key) i In the case of ), and the key TLs.Key representing that public value. j (First key, TL.Key) j The subkeys TLs.S corresponding to ) j Subkeys TRs.S with the same value as the first subkey i (Second subkey) and TRs representing that common value. i (Third key, TR.Key) i It corresponds to at least a portion of the public value. For example, it corresponds to the key TLs.Key that represents the public value. j (First key, TL.Key) j The subkeys TLs.S corresponding to ) j Subkeys TRs.S with the same value as the first subkey i (Second subkey) hidden information [TRs.S i ], and TRs.Key as a representation of that public value. i (Third key, TR.Key) i The hidden information of [TRs.Key] i At least a portion of ] corresponds. Preferably, in the appended table TRs (second appended table) ( Figure 6The key column TRs.Key (third key column, TRc.Key) contains TRs.Key representing the public value. i (Third key, TR.Key) i In the case of ), the key TLs.Key represents the public value. j (First key, TL.Key) j ()( Figure 5A Any subkey TLs.S corresponding to ) j The value of (first subkey) is also related to TRs, which represent that public value. i (Third key, TR.Key) i The subkeys corresponding to TRs.S0,...,TRs.S RRN*K-1 Any of the (second subkeys) have the same value. For example, as [TLs.Key] j ]( Figure 5A Any hidden subkey corresponding to ) [TLs.S j The subkey TLs.S of the recovered value (decrypted value) j The value of (first subkey) is also used as [TRs.Key] i The corresponding hidden subkeys [TRs.S0],...,[TRs.S RRN*K-1 The subkeys TRs.S0,...,TRs.S of the recovered value (decrypted value) RRN*K-1 Any of the (second subkeys) have the same value, where [TLs.Key j ] is the key TLs.Key representing that public value. j (First key, TL.Key) j The hidden information of [TRs.Key] i ] represents TRs.Key, which represents the public value. i (Third key, TR.Key) i (hidden information)
[0089] The following examples illustrate the relationship between [TR], [TRc], and [TRs].
[0090] For i = 0, ..., RRN·K-1, let the quotient of i divided by K be idk (i.e., idk = I div K), and imk = i - idk * K. Table TR (Second Table) Figure 4B The k-th record of ) is TR idk Table T Rc (Third Table) Figure 5B The i-th record of ) is TRc i Additional table TRs (Second additional table) Figure 6 The i-th subkey (second subkey) of the subkey column TRs.S (second subkey column) is TRsS.i In this case, TRs i =TRc i =TR idk TRs.S i =imk.
[0091] Therefore, the subkey column append section 14-n can obtain the concealment append table [TRs] based on the concealment table [TR] as follows.
[0092] For i = 0, ..., RRN·K-1, let idk be the quotient obtained by dividing i by K, and let imk = i - idk*K, and perform the following processing.
[0093] (c-1)[TRs i ] = [TRc i ] = [TR idk ]
[0094] (c-2)[TRs.S i ]=[imk]
[0095] Here, (c-1) can hide the records [TR] in the hidden table [TR]. idk As [TRs] i This is achieved by copying [TRs.S]. (c-2) This can be achieved by cloaking imk (e.g., secret distribution) and setting it to [TRs.S]. i This is achieved by using [imk] = [imk].
[0096] Additionally, table TRc and the hidden table [TRc] are shown here for illustration purposes, but the subkey column appending section 14-n uses the hidden table [TR] ( Figure 4B Secret calculations are used to obtain the concealed append tables [TRs]( Figure 6 This is sufficient; it is not necessary to obtain the hidden table [TRc] obtained by hiding the table TRc. Figure 5B That is, the subkey column appending part 14-n can directly obtain [TR s] based on [TR], or obtain [TRc] based on [TR], and further obtain [TRs] based on [TRc].
[0097] Processing of the secret junction 15-n (steps S15-n)
[0098] The secret connection parts 15-n of each secret connection device 10-n are obtained by using the concealment appended forms [TLs] (first concealment appended forms) as described above. Figure 5A ) and the stealth append table [TRs] (second stealth append table) Figure 6The secret calculation of ) is used to obtain and output the concealed binding table [ETRL]. In this concealed binding table [ETRL], the TLs.Key of the table TLs is... j (First key) and subkeys TLs.S j (first subkey) group (TLs.Key) j ,TLs.S j (j = 0, ..., LRN-1) is set as the key attribute of the append table TLs (the first append table), and the key TRs.Key of the append table TRs is set as... i (Third key) and subkey TRs.S i (Second subkey) group (TRs.Key) i TRs.S i (i = 0, ..., RRN*K-1) is set as the key attribute of the append table TRs (second append table). This hidden combination table [ETRL] serves as the hidden information of the combination table ETRL obtained by equal combination of append tables TLs (first append table) and append tables TRs (second append table). As described above, the combination table TLR is selected from the table TRL resulting from the cross combination of append tables TLs and append tables TRs, only the equal sign (TLs.Key) is selected. j TLs.S j ) = (TRs.Key i TRs.S i A table obtained from the records established.
[0099] Here, subkeys TLs.S with distinct values j The keys of the append table TLs (the first append table) are TLs.Key0 = TL.Key0, ..., TLs.Key0. LRN-1 =TL.Key LRN-1 Keys with the same value correspond to each other. Therefore, as a group of key attributes appended to table TLs (TLs.Key j ,TLs.S j The value of ) uniquely determines each record TLs j In other words, append the groups (TLs.Key0, TLs.S0), ..., (TLs.Key0, TLs.S0) of table TLs. LRN-1 ,TLs.S LRN-1 There are no groups with the same value (groups with two repeated elements) in the table. On the other hand, there are groups that are the key properties of the append table TRs (the second append table) (TRs.Key). i TRs.S i The value of ) does not uniquely determine the TRs of each record. jIn other words, append the groups (TRs.Key0, TRs.S0), ..., (TRs.Key0, TRs.S0) of the table TRs. RRN*K-1 TRs.S RRN*K-1 There exist groups with the same values (groups where two elements are repeated). Patent Document 1 discloses a method for performing equal binding by secret computation when, in two tables of equal binding objects, one table has no duplicate key attributes, but only the other table has duplicate key attributes. Therefore, the secret equal binding part 15-n, for example, follows the method disclosed in Patent Document 1, obtaining and outputting the concealed binding table [ETRL] by secretly computing the concealed appended table [TLs] and the concealed appended table [TRs]. This process is described below.
[0100] function join:
[0101] [ETRL]=join(([TLs.Key],[TLs.S],[TLs.V(0)],...,[TLs.V(LVN-1)]),
[0102] ([TRs.Key],[TRs.S],[TRs.V(0)],...,[TRs.V(RVN-1)]),
[0103] ([TLs.Key],[TLs.S]),
[0104] ([TRs.Key],[TRs.S]))
[0105] Input: ([TLs.Key],[TLs.S],[TLs.V(0)],...,[TLs.V(LVN-1)]),([TRs.Key],[TRs.S],[TRs.V(0)],...,[TRs.V(RVN-1)])
[0106] Output: [ETRL]=([TLs.Key],[TLs.S],[TLs.V(0)],...,[TLs.V(LVN-1)],[TRs.Key],[TRs.S],[TRs.V(0)],...,[TRs.V(RVN-1)])
[0107] Here, `join` is a function that performs secret joins as follows.
[0108] [The table obtained by combining Table 1 and Table 2] = join([Table 1], [Table 2], [Key attributes of Table 1], [Key attributes of Table 2])
[0109] The obtained concealed combination table [ETRL] can be used in other processes (e.g., secret equal sign processing or decoding processing) in the secret equal sign device 10-n, or it can be output from the output unit 16-n and used in other processes.
[0110] <Example>
[0111] Next, specific examples will be used to illustrate this implementation method.
[0112] In this specific example, the following is shown: Figures 7A to 7C The example of the concealment table is combined with secrets to obtain... Figure 7D The example shown is a hidden combination of tables. Figure 7A The hidden table is a table of beverage product names where "ID" is set as the key column and "Beverage Product Name" is set as an arbitrary element column (hereinafter, "Hidden Beverage Product Name Table"). The key column of the beverage product name table has ID = "1000", "4050", "3210" as elements, and the arbitrary element column has beverage product name = "Pure Water A", "Black Coffee B", "Orange Juice C" as elements. Figure 7B The hidden table is a capacity table where "ID" is set as the key column and "Capacity" is set as any element column (hereinafter, "Hidden Capacity Table"). The key column of the capacity table has ID = "1000", "1000", "1000", "4050", "3210" as elements, and the arbitrary element column has capacity = "200", "500", "1000", "200", "500" as elements. Figure 7C The hidden table is the hidden information of the container type table (hereinafter, "Hidden Container Type Table"), where ID is set as the key column and "Container" is set as any element column. The key column of the container type table has ID = "1000", "1000", "4050", "4050", "3210" as elements, and the arbitrary element column has container = "Plastic Bottle", "Aluminum Can", "Plastic Bottle", "Aluminum Can", "Aluminum Can" as elements.
[0113] Here, with Figure 7A The key column of the hidden beverage product name table does not contain elements (keys) with the same value. On the other hand, with Figure 7B The hidden capacity table has a key column containing elements with the same value "1000", and... Figure 7C The table of hidden container types has key columns containing elements with the same values: "1000" and "4050". Therefore, as... Figure 8 As illustrated, (1) firstly, the method of this embodiment is used to perform... Figure 7B The concealment capacity table and Figure 7CThe secret of the concealment container type table is combined to obtain the concealment combination table, and then (2) the concealment combination table is combined with the secret of the concealment container type table. Figure 7A By combining the secrets of the concealed beverage product name table, etc., to obtain Figure 7D The final obfuscation combination table is shown in the example. Here, the obfuscation capacity table is set to [TL], with LRN=5, LVN=1, [TL.Key]=[ID], [TL.Key0]=
[1000] , [TL.Key1]=
[1000] , [TL.Key2]=
[1000] , [TL.Key3]=
[4050] , [TL.Key4]=
[3210] , [TL.V(0)0]=
[200] , [TL.V(0)1]=
[500] , [TL.V(0)2]=
[1000] , [TL.V(0)3]=
[200] , [TL.V(0)4]=
[500] . In addition, the concealed container type table is set to [TR], RRN=5, RVN=1, [TR.Key]=[ID], [TR.Key0]=
[1000] , [TR.Key1]=
[1000] , [TR.Key2]=
[4050] , [TR.Key3]=
[4050] , [TR.Key4]=
[3210] , [TR.V(0)0]=[Plastic Bottle], [TR.V(0)1]=[Aluminum Can], [TR.V(0)2]=[Plastic Bottle], [TR.V(0)3]=[Aluminum Can], [TR.V(0)4]=[Aluminum Can].
[0114] If step S13-n is performed on the concealment capacity table [TL], then for example, the following can be obtained: Figure 9A The example shown is a hidden appended table (the hidden "capacity + sequence number" table) [TLs]. In this hidden appended table [TLs], LRN=5, LVN=1, [TLs.Key]=[ID], [TLs.Key0]=
[1000] , [TLs.Key1]=
[1000] , [TLs.Key2]=
[1000] , [TLs.Key3]=
[4050] , [TLs.Key4]=
[3210] , [TLs.S]=[SeqNo], [TLs.Key4]=
[3210] , [TLs.S]=[SeqNo], [TLs.Key5]=
[4050] , [TLs.Key6]=
[4050] , [TLs.Key7]=
[4050] , [TLs.Key8]=
[4050] , [TLs.Key9]=
[4050] , [TLs.Key1 ... s.S0]=[0], [TLs.S1]=[1], [TLs.S2]=[2], [TLs.S3]=[0], [TLs.S4]=[0], [TLs.V(0)0]=[2 00], [TLs.V(0)1]=
[500] , [TLs.V(0)2]=
[1000] , [TLs.V(0)3]=
[200] , [TLs.V(0)4]=
[500] .
[0115] If step S14-n is performed on the stealth container type table [TR], then for example, the following can be obtained: Figure 9B The example shown is a hidden appended table (the hidden "capacity type + serial number" table) [TRs]. In this hidden appended table [TRs], K=5, RRN=5, RVN=1, [TRs.Key]=[ID], [TRs.Key0]=
[1000] , [TRs.Key1]=
[1000] , [TRs.Key2]=
[1000] , [TRs.Key3]=
[1000] , [TRs.Key4]=
[1000] , [TRs.Key5]=
[1000] , [TRs.Key6]=
[4050] , [TRs.Key7]=
[4050] , [TRs.Key8]=
[4050] , [TRs.Key9]=
[4050] , [TRs.Key... 10 ] =
[4050] , [T Rs.Key 11 ] =
[4050] , [TRs.Key 12 ] =
[3210] , [TRs.Key 13 ] =
[3210] , [TRs.Key 14 ]=
[3210] , [TRs.S]=[SeqNo], [TRs.S0]=[0], [TRs.S1]=[1], [TRs.S2]=[2], [TRs.S3]=[0], [TR s.S4]=[1], [TRs.S5]=[2], [TRs.S6]=[0], [TRs.S7]=[1], [TRs.S8]=[2], [TRs.S9]=[0], [TRs.S 10 ] = [1], [TRs.S 11 ]=[2],[TRs.S 12 ] = [0], [TRs.S 13 ]=[1],[T Rs.S 14 [TRs.V(0)0] = [2], [TRs.V(0)1] = [Plastic Bottle], [TRs.V(0)2] = [Plastic Bottle], [TRs.V(0)3] = [Aluminum Can], [TRs.V(0)4] = [Aluminum Can], [TRs.V(0)5] = [Aluminum Can], [TRs.V(0)6] = [Plastic Bottle], [TRs.V(0)7] = [Plastic Bottle], [TRs.V(0)8] = [Plastic Bottle], [TRs.V(0)8] = [Aluminum Can], [TRs.V(0)9] = [Aluminum Can], [TRs.V(0)] = [Aluminum Can], [TRs.V(0)] = [2], [TRs.V(0)0] = [Plastic Bottle], [TRs.V(0)1] = [Plastic Bottle], [TRs.V(0)2] = [Plastic Bottle], [TRs.V(0)9] = [Aluminum Can], [TRs.V(0)] = [2], [TRs.V(0)0] = [Plastic Bottle ...Aluminum Can], [TRs.V(0)0] = [Plastic Bottle], [TRs.V(0)0] = [Plastic Bottle], [TRs.V(0)0] = [Plastic Bottle], [TRs.V(0)0] = [Plastic Bottle], [TRs.V(0)0] = [Plastic Bottle], [TR 10 ] = [aluminum can], [TRs.V(0)] 11 ] = [aluminum can], [TRs.V(0)]12 ] = [aluminum can], [TRs.V(0)] 13 ] = [aluminum can], [TRs.V(0)] 14 ] = [aluminum can].
[0116] If step S15-n is performed on such concealment append tables [TLs] and concealment append tables [TRs], then, for example, the following can be obtained: Figure 10 The example of the concealed binding table [ETRL] = ([TLs.Key], [TLs.S], [TLs.V(0)], ..., [TLs.V(LVN-1)], [TRs.Key], [TRs.S], [TRs.V(0)], ..., [TRs.V(R VN-1)]) = ([ID], [SeqNo], [Capacity], [ID], [SeqNo], [Container]).
[0117] <Features of this embodiment>
[0118] As described above, in this embodiment, the subkey column appending unit 13-n obtains the obfuscated appending table [TLs] (first obfuscated appending table) by secretly calculating the obfuscated table (first obfuscated table) [TL] (step S13-n). This obfuscated appending table [TLs] is the obfuscated information of the appended table TLs (first appending table) obtained by appending the subkey column TLs.S (first subkey column) to the table TL (first table). Furthermore, the subkey column appending unit 14-n obtains the obfuscated appending table [TRs] (second obfuscated appending table) by secretly calculating the obfuscated table (second obfuscated table) [TR] (step S14-n). This obfuscated appending table [TRs] is the obfuscated information of the appended table TRs (second appending table) obtained by appending the subkey column TRs.S (second subkey column) to the table TRc (third table) obtained by copying the record of TR. Then, the secret binding part 15-n obtains and outputs the concealment binding table [ETRL] by using the secret calculation of the concealment append table [TLs] (first concealment append table) and the concealment append table [TRs] (second concealment append table) (step S15-n). In this concealment binding table [ETRL], the TLs.Key of the table TLs is... j (First key) and subkeys TLs.S j (first subkey) group (TLs.Key) j ,TLs.S j (j = 0, ..., LRN-1) is set as the key attribute of the append table TLs (the first append table), and the key TRs.Key of the append table TRs is set as... i (Third key) and subkey TRs.Si (Second subkey) group (TRs.Key) i TRs.S i (i = 0, ..., RRN*K-1) is set as the key attribute of the append table TRs (second append table). This hidden join table [ETRL] is the hidden information of the join table ETRL obtained by equally joining the append table TLs (first append table) and the append table TRs (second append table). Here, the subkeys TLs.S with different values are... j The keys of the append table TLs (the first append table) are TLs.Key0 = TL.Key0, ..., TLs.Key0. LRN-1 =TL.Key LRN-1 Correspondingly. Therefore, as the group of key attributes appended to table TLs (TLs.Key0, TLs.S0), ..., (TLs.Key LRN-1 ,TLs.S LRN-1 There are no groups with the same values (groups with repeated elements) in the table. For example, according to the method disclosed in Patent Document 1, the secret combination table [ETRL] can be obtained by using secret calculations of the concealed appended tables [TLs] and the concealed appended tables [TRs]. In this case, since the processing of splitting the table before secret combination and combining the table after secret combination is no longer needed, the two tables can be quickly combined while the information of the concealed tables is still present.
[0119] In particular, Table TRc (Third Table) Figure 5B This is appending data to table TR (the second table). Figure 4B Each record TR p (Where p = 0, ..., RRN-1) A table obtained from multiple copies of records obtained every K copies, but it can be processed most quickly when K = KL.
[0120] Furthermore, when the maximum value KR of the number of keys (second keys) with identical values in the key column TR.Key (second key column) of table TR (second table, right table) is less than the maximum value KL of the number of keys with identical values in the key column TL.Key (first key column) of table TL (first table, left table) (KR≤KL), processing can be performed more quickly. Therefore, it is preferable that the hidden table (first hidden table) [TL] and the hidden table (second hidden table) [TR] are stored in storage unit 12-n such that KR≤KL.
[0121] In addition, in this embodiment, KL and KR are stored in storage unit 12-n, but if at least one of them is known, the known value may not be stored in storage unit 12-n.
[0122] [Second Implementation]
[0123] As described above, by storing the obfuscation table (first obfuscation table) [TL] and the obfuscation table (second obfuscation table) [TR] in the storage unit 12-n to ensure KR≤KL, processing can be performed more quickly. In environments where this is not guaranteed, the obfuscation table can also be replaced to ensure KR≤KL. Hereinafter, the description will focus on the differences from the first embodiment, and the same reference numerals will be used for the matters already described, and the description will be simplified.
[0124] <Structure>
[0125] like Figure 1 As illustrated, the secret binding system 2 of this embodiment includes N secret binding devices 20-0, ..., 20-(N-1). The secret binding devices 20-0, ..., 20-(N-1) of this embodiment are communicatively connected via a network.
[0126] like Figure 2 As illustrated, each secret combination device 20-n (where n = 0, ..., N-1) has a table reset unit 221-n, an input unit 11-n, a storage unit 12-n, a subkey column appending unit 13-n (first subkey column appending unit), a subkey column appending unit 14-n (second subkey column appending unit), a secret combination unit 15-n, an output unit 16-n, a control unit 17-n, and a memory 18-n. Descriptions are omitted below, but each secret combination device 20-n executes each process based on the control unit 17-n, stores the input data and the data obtained from each process in the memory 18-n, and reads and uses them as needed.
[0127] <Preprocessing>
[0128] Same as the first implementation method.
[0129] <Processing>
[0130] use Figure 3 The combination method of the secrets of this embodiment will be explained.
[0131] Processing of Table Reset Section 221-n (Steps S221-n)
[0132] The table reset unit 221-n reads the values of KR (the maximum number of second keys in the second key column with identical values) and KL (the maximum number of first keys in the first key column with identical values) from the storage unit 12-n. If KR is greater than KL, the concealment table [TL] (first concealment table) and concealment table [TR] (second concealment table) stored in the storage unit 12-n are replaced and stored in the storage unit 12-n. Thus, a table containing multiple (LRN) keys TL.Key0,...,TL.Key0 is created. LRN-1 The key column TL.Key (first key column) and the arbitrary element TL.V(v) (LRN elements) 0,...,TL.V(v) LRN-1 The arbitrary element column TL.V(v) of (the first arbitrary element) is a table TL(first table, left table) and contains multiple (RRN) keys TR.Key0,...,TR.Key RRN-1 The key column TR.Key (second key column) and TR.V(w) (with multiple (RRN) arbitrary elements) 0,...,TR.V(w) RRN-1 The table TR(second table, right table) of any element column TR.V(w) of (the second arbitrary element) is reset to contain multiple (RRN) keys TR.Key0,...,TR.Key RRN-1 The key column TR.Key (second key column) and TR.V(w) (with multiple (RRN) arbitrary elements) 0,...,TR.V(w) RRN-1 The arbitrary element column TR.V(w) of (the second arbitrary element) is a table TR (second table, right table) and contains multiple (LRN) keys TL.Key0,...,TL.Key LRN-1 The key column TL.Key (first key column) and the arbitrary element TL.V(v) (LRN elements) 0,...,TL.V(v) LRN-1 The table TL (first table, left table) is a column of arbitrary elements TL.V(v) of (first arbitrary element). The hidden table [TL] (first hidden table) and the hidden table [TR] (second hidden table) that are reset in this way satisfy the relationship KR≤KL. On the other hand, if KR and KL satisfy the relationship KR≤KL, the table reset part 221-n does not replace the hidden table [TL] and [TR].
[0133] After step S221-n, the processes described in steps S13-n, S14-n, and S15-n in the first embodiment are performed.
[0134] <Features of this embodiment> This embodiment achieves the same effects as the first embodiment. Furthermore, even if [TL] and [TR] satisfying the KR≤KL relationship are not stored in the storage unit 12-n, they can be reset to satisfy the KR≤KL relationship by replacing them. As a result, secret combinations can be performed more quickly.
[0135] [Hardware Structure]
[0136] The secret combination devices 10-n and 20-n in each embodiment are, for example, devices constructed by performing predetermined processing using a general-purpose or special-purpose computer equipped with a processor (hardware, processor) such as a CPU (central processing unit) or a memory such as RAM (random-access memory) or ROM (read-only memory). That is, the secret combination devices 10-n and 20-n in each embodiment, for example, have processing circuitry configured to implement their respective components. The computer may have one processor or memory, or multiple processors or memories. The program may be installed on the computer or pre-stored in ROM, etc. Furthermore, instead of a CPU-like circuitry that implements its functional structure by loading a program, some or all of the processing units may be constructed using separate circuitry that implements the processing function. Furthermore, the circuitry constituting a device may include multiple CPUs.
[0137] Figure 11 This is a block diagram illustrating the hardware structure of the secret connection devices 10-n and 20-n in various embodiments. For example... Figure 11As illustrated, the combination devices 10-n and 20-n in this example include a CPU (Central Processing Unit) 10a, an input unit 10b, an output unit 10c, a RAM (Random Access Memory) 10d, a ROM (Read Only Memory) 10e, an auxiliary storage device 10f, and a bus 10g. The CPU 10a in this example has a control unit 10aa, an arithmetic unit 10ab, and a register 10ac, and performs various arithmetic operations according to various programs read into the register 10ac. Furthermore, the input unit 10b includes input terminals for data input, such as a keyboard, mouse, and touchscreen. Furthermore, the output unit 10c includes output terminals for data output, such as a display, and a LAN card controlled by the CPU 10a which has a specified program loaded into it. Furthermore, RAM 10d is an SRAM (Static Random Access Memory), DRAM (Dynamic Random Access Memory), etc., and has a program area 10da for storing a specified program and a data area 10db for storing various data. Similarly, auxiliary storage device 10f is a hard disk, MO (Magneto-Optical Disc), semiconductor memory, etc., and has a program area 10fa for storing a specified program and a data area 10fb for storing various data. Furthermore, bus 10g connects CPU 10a, input unit 10b, RAM 10d, ROM 10e, and auxiliary storage device 10f to enable information exchange. CPU 10a writes the program stored in program area 10fa of auxiliary storage device 10f to program area 10da of RAM 10d according to the read OS (Operating System) program. Likewise, CPU 10a writes various data stored in data area 10fb of auxiliary storage device 10f to data area 10db of RAM 10d. Furthermore, the address on RAM 10d where the program or data is written is stored in register 10ac of CPU 10a. The control unit 10aa of CPU 10a sequentially reads these addresses stored in register 10ac, reads the program or data from the area on RAM 10d represented by the read address, and causes the arithmetic unit 10ab to sequentially execute the operations represented by these programs, storing the results in register 10ac. Through this structure, the functional structure of the secret combination devices 10-n and 20-n is realized.
[0138] The above program can be stored in a computer-readable recording medium. Examples of computer-readable recording media are non-transitory recording media. Examples of such recording media include magnetic recording devices, optical discs, optical-magnetic recording media, and semiconductor memories.
[0139] The program can be distributed, for example, through the sale, transfer, or lending of portable recording media such as DVDs and CD-ROMs containing the program. Alternatively, it can be configured to store the program in the storage device of a server computer and distribute it by transmitting the program from the server computer to other computers via a network. As described above, a computer executing such a program may first temporarily store the program stored on the portable recording medium or the data transmitted from the server computer in its own storage device. Then, during execution, the computer reads the program stored in its own storage device and executes the processing according to the read program. Furthermore, as another method of executing the program, it can be configured to have the computer directly read the program from the portable recording medium and execute the processing according to the program. Further, it can be configured to execute the processing according to the received program sequentially whenever a program is transmitted from the server computer to the computer. Additionally, it can be configured to perform the above processing by not transmitting the program from the server computer to the computer, but by only obtaining its execution instructions and results—a so-called ASP (Application Service Provider) type service. Furthermore, the program in this embodiment is assumed to include information equivalent to the program for computer-based processing (data, etc., which are not direct instructions to the computer but have the nature of specifying the computer's processing).
[0140] In various embodiments, the apparatus is configured to be constructed by executing a prescribed program on a computer, but at least a portion of these processing contents may also be implemented by hardware.
[0141] It should be noted that the present invention is not limited to the embodiments described above. For example, the secret connection devices 10-0, ..., 10-(N-1) (or 20-0, ..., 20-(N-1)) may also exchange data via a portable recording medium instead of a network. Furthermore, in the above embodiments, a sequence number such as 0, 1, 2, 3... incrementing by 1 is exemplified as a subkey, but other numbers or symbols may also be used as subkeys.
[0142] Furthermore, the various processes described above can be executed not only in a time sequence as described, but also in parallel or individually, depending on the processing capacity of the device performing the processing or as needed. Additionally, it is obvious that appropriate modifications can be made without departing from the spirit of the invention.
[0143] Explanation of reference numerals in the attached figures
[0144] 1, 2, and other secret systems
[0145] 10-n, 20-n secret combination devices
[0146] 13-n, 14-n subbond additions
[0147] 15-n secret junctions, etc.
[0148] Table 221-n Reset Section.
Claims
1. A secret coupling device, comprising: Storage section; first subkey column append section; second subkey column append section; and secret and other connecting sections, The storage unit stores a first concealment table and a second concealment table. The first hidden table serves as the hidden information of a first table containing a first key column with multiple first keys and a first arbitrary element column with multiple first arbitrary elements. The second hidden table serves as the hidden information of a second table containing a second key column with multiple second keys and a second arbitrary element column with multiple second arbitrary elements. The first subkey column appending section obtains a first hidden appending table, which is a first appending table containing hidden information of the first appending table obtained by appending the first subkey column to the first table, through secret calculation of the first hidden table. The first subkey column has multiple first subkeys. Each of the first subkeys corresponds to each of the first keys. The maximum number of first keys whose values are identical to each other in the first key column is KL, where KL is an integer greater than or equal to 2. The first subkeys with distinct values correspond to the first keys with identical values. The second subkey column appending section obtains a second hidden appending table, which is a second appending table containing hidden information as a result of appending the second subkey column to the third table, by using the secret calculation of the second hidden table. Each record in the second table contains each of the second keys and each of the second arbitrary elements. The third table is obtained by appending multiple copied records to the second table, where K ≥ KL. The third table contains a third key column and a third arbitrary element column, wherein, The third key column has multiple third keys including the second key and copies of the second key, and the third arbitrary element column has multiple third arbitrary elements including the second arbitrary element and copies of the second arbitrary element. The second subkey column has multiple second subkeys. Each of the second sub-keys corresponds to one of the third keys. In the case where the third key column contains a third key representing a common value identical to any of the first keys, the second subkey that has the same first subkey value as the first key representing the common value corresponds to at least a portion of the third key representing the common value. The secret combination part obtains a hidden combination table by using secret calculations of the first hidden append table and the second hidden append table. In this hidden combination table, the combination of the first key and the first subkey is set as the key attribute of the first append table, and the combination of the third key and the second subkey is set as the key attribute of the second append table. This hidden combination table serves as the hidden information of the combination table obtained by combining the first append table and the second append table.
2. The secret coupling device according to claim 1, wherein, When the third key column contains the third key representing the common value, the value of any of the first subkeys corresponding to the first key representing the common value is also the same as the value of any of the second subkeys corresponding to the third key representing the common value.
3. The secret coupling device according to claim 1 or 2, wherein, K=KL.
4. The secret coupling device according to claim 1 or 2, wherein, The maximum number of second keys in the second key column whose values are identical to each other is below the maximum number of first keys in the first key column whose values are identical to each other.
5. The secret coupling device according to claim 1 or 2, wherein, It also includes a table resetting unit, which replaces the first hiding table and the second hiding table when the maximum number of second keys with identical values in the second key column is greater than the maximum number of first keys with identical values in the first key column. The table reset unit will reset a first table containing a first key column having the first key and a first arbitrary element column having the first arbitrary element, and a second table containing a second key column having the second key and a second arbitrary element column having the second arbitrary element, into a second table containing a second key column having the second key and a second arbitrary element column having the second arbitrary element, and a first table containing a first key column having the first key and a first arbitrary element column having the first arbitrary element, respectively.
6. The secret coupling device according to claim 1 or 2, wherein, The first table has a record count of LRN, and the second table has a record count of RRN, where LRN and RRN are integers greater than or equal to 2. j=0,…,LRN-1, The j-th first key in the first key column is TL.Key j , The j-th first subkey in the first subkey column is TLs.S j , When j=0, TLs.S j =0, If j > 0 and TL.Key j ≠TL.Key j-1 Then TLs.S j =0, If j > 0 and TL.Key j =TL.Key j-1 Then TLs.S j =TLs.S j-1 +1, i=0,…,RRN*K-1, The quotient obtained by dividing i by K is idk. imk = i - idk * K, The idk-th record in the second table is TR. idk , The i-th record in the third table is TRc. i , TRc i =TR idk , The i-th second subkey in the second subkey column is TRs.S i , TRs.S i =take.
7. A secret binding method for a secret binding device, comprising: The steps include: storage steps; appending the first subkey column; appending the second subkey column; and combining steps such as the secret key. The storage step involves storing the first and second concealment tables in the storage unit. The first hidden table serves as the hidden information of a first table containing a first key column with multiple first keys and a first arbitrary element column with multiple first arbitrary elements, and The second hidden table serves as the hidden information of a second table containing a second key column with multiple second keys and a second arbitrary element column with multiple second arbitrary elements. The first subkey column appending step is a step in which the first subkey column appending part obtains a first hidden appending table, which is the hidden information of the first appending table obtained by appending the first subkey column to the first table, through secret calculation of the first hidden table. The first subkey column has multiple first subkeys. Each of the first subkeys corresponds to each of the first keys. The maximum number of first keys whose values are identical to each other in the first key column is KL, where KL is an integer greater than or equal to 2. The first subkeys with distinct values correspond to the first keys with identical values. The second subkey column appending step is a step in which the second subkey column appending part obtains a second hidden appending table, which is a second appending table obtained by appending the second subkey column to the third table, through secret calculation of the second hidden table. Each record in the second table contains each of the second keys and each of the second arbitrary elements. The third table is obtained by appending multiple copied records to the second table, where K ≥ KL. The third table contains a third key column and a third arbitrary element column, wherein, The third key column has multiple third keys including the second key and copies of the second key, and the third arbitrary element column has multiple third arbitrary elements including the second arbitrary element and copies of the second arbitrary element. The second subkey column has multiple second subkeys. Each of the second sub-keys corresponds to one of the third keys. In the case where the third key column contains a third key representing a common value identical to any of the first keys, the second subkey that has the same first subkey value as the first key representing the common value corresponds to at least a portion of the third key representing the common value. The secret binding step is a step in which the secret binding part obtains a hidden binding table by using secret calculations of the first hidden append table and the second hidden append table. In this hidden binding table, the combination of the first key and the first subkey is set as the key attribute of the first append table, and the combination of the third key and the second subkey is set as the key attribute of the second append table. This hidden binding table serves as the hidden information of the binding table obtained by binding the first append table and the second append table.
8. A computer-readable recording medium storing a program for enabling a computer to function as a secret or other combination device as claimed in any one of claims 1 to 6.
Citation Information
Patent Citations
Secret equi-join system, secret equi-join device, secret equi-join method, and program
WO2018061800A1
Secret equi-join system, secret equi-join device, secret equi-join method, and program
CN109791741A
Secure equijoin system, secure equijoin device, secure equijoin method, and program
US20190228010A1