CONFIDENTIAL INFORMATION PROCESSING SYSTEM, CONFIDENTIAL INFORMATION PROCESSING PROCESS AND CONFIDENTIAL INFORMATION PROCESSING PROGRAM

The quantum-homomorphic cryptographic technique addresses the vulnerability of conventional quantum homomorphic encryption to quantum computers by using security parameters to generate encryption keys and ciphertexts, ensuring secure operations on encrypted data.

DE112022007028B4Active Publication Date: 2026-04-02MITSUBISHI ELECTRIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-14
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Conventional quantum homomorphic encryption, which satisfies circuit confidentiality, relies on the Decisional Small Polynomial Ratio (DSPR) problem for security, making it vulnerable to quantum computers, as the DSPR problem can be easily solved using quantum computers, compromising the security of homomorphic encryption.

Method used

A quantum-homomorphic cryptographic technique that ensures strong circuit confidentiality by generating encryption keys and ciphertexts using security parameters, allowing operations on encrypted data with different encryption keys, ensuring security even for quantum computers.

Benefits of technology

Enables secure quantum-homomorphic operations between ciphertexts encrypted with different encryption keys, providing strong circuit confidentiality against quantum computers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Confidential Information Processing System (100) corresponding to a quantum homomorphic cryptographic technique that satisfies strong circuit confidentiality, wherein the Confidential Information Processing System (100) comprises an encryption device (400) comprising an encryption unit (404) for generating a first ciphertext by encrypting a first plaintext using a first public parameter and a first encryption key, and for generating a second ciphertext by encrypting a second plaintext using a second public parameter and a second encryption key, wherein Each of the first public parameters as well as the second public parameter is a parameter that is generated using a security parameter, The first encryption key is an encryption key generated using the first public parameter, and a first decryption key is a decryption key generated using the security parameter. the second encryption key is an encryption key that is generated using the second public parameter and a second decryption key that is a decryption key generated using the security parameter, the first decryption key consists of a first homomorphic decryption key and a first quantum homomorphic decryption key, the second decryption key consists of a second homomorphic decryption key and a second quantum-homomorphic decryption key, the first encryption key consists of a first homomorphic public key generated on the basis of the first homomorphic decryption key, and a first quantum homomorphic public key generated on the basis of the first quantum homomorphic decryption key, the second encryption key consists of a second homomorphic public key generated on the basis of the second homomorphic decryption key, and a second quantum-homomorphic public key generated on the basis of the second quantum-homomorphic decryption key, the first ciphertext is generated based on the first public parameter, a first one-time pad key, the first homomorphic public key, the first quantum-homomorphic public key, and a first random number, and The second ciphertext is generated based on the second public parameter, a second one-time pad key, the second homomorphic public key, the second quantum-homomorphic public key, and a second random number.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] This disclosure relates to a Confidential Information Processing System, a Confidential Information Processing Procedure, and a Confidential Information Processing Program. State of the art

[0002] Quantum homomorphic encryption is a cryptographic technique that allows quantum arithmetic operations to be performed while the data remains encrypted. Although cloud services are widely used, recent concerns about cracking, cloud reliability, and other factors have led to increased consideration of encrypting and storing data in the cloud. Quantum homomorphic encryption can perform arithmetic operations on encrypted data without decrypting it. Therefore, it is a technique that enables the use of cloud services with quantum computation without compromising security.

[0003] A cryptographic method for improving the security of quantum homomorphic encryption, wherein the cryptographic method that achieves the security that no information about the arithmetic processing of a result of a quantum arithmetic operation leaks while the data remains encrypted is a quantum homomorphic encryption that satisfies circuit confidentiality. Among the parts of the quantum homomorphic encryption that satisfy circuit confidentiality, in particular, the quantum homomorphic encryption that achieves the security that no information about the quantum arithmetic operation of a result of a quantum homomorphic arithmetic operation on a ciphertext not generated by an encryption algorithm leaks is a quantum homomorphic encryption that satisfies strong circuit confidentiality.Quantum homomorphic encryption, which satisfies strict circuit confidentiality, is implemented when an arithmetic operation is performed on encrypted data. This is achieved by performing the arithmetic operation while the data remains encrypted using quantum homomorphic encryption, which satisfies normal circuit confidentiality after the validity of the input has been verified. Specifically, the validity of the input consists of the fact that an encryption key, which is the input to the arithmetic operation, is generated by a key generation algorithm, and a ciphertext, which is the input to the arithmetic operation, is generated by an encryption algorithm.The quantum homomorphic encryption that satisfies normal circuit confidentiality is a quantum homomorphic encryption where the circuit confidentiality is only valid for a ciphertext generated by the encryption algorithm.

[0004] In non-patent literature 1, a configuration example for quantum homomorphic encryption is disclosed that satisfies the confidentiality of the memory circuits, as well as a configuration example for quantum homomorphic encryption that satisfies the confidentiality of the strong circuits and can perform a homomorphic arithmetic operation on ciphertexts encrypted with different encryption keys.

[0005] WO 2021 / 245 931 A1 discloses an encryption device that converts plaintext data x into encrypted data C as C = B * R+E+x *G generates a matrix B contained in a key PK, a random number matrix R, a random number matrix E and a tensor product G. Reference list Non-patented literature

[0006] Non-patent literature 1: Chardouvelis,O.et al., “Rate-1 Quantum Fully Homomorphic Encryption”, TCC 2021: Theory of Cryptography, pp.149-176, 2021. Summary of the invention: Technical problem

[0007] Conventional quantum homomorphic encryption, which satisfies the circuit confidentiality disclosed in Non-Patent Document 1, uses a specific computational problem, the Decisional Small Polynomial Ratio (DSPR) problem, as its basis for security. However, the DSPR problem is known to be easily solved using a quantum computer. In particular, with the quantum homomorphic cryptographic technique disclosed in Non-Patent Document 1, the security of the homomorphic encryption, which satisfies the circuit confidentiality used as a configuration component, depends on the difficulty of the DSPR problem. Therefore, quantum homomorphic encryption, which satisfies the strong circuit confidentiality disclosed in Non-Patent Document 1, is not secure even for a quantum computer.

[0008] The present disclosure aims to realize a quantum-homomorphic cryptographic technique that ensures strong circuit confidentiality secure for a quantum computer and enables homomorphic operation by quantum computation between ciphertexts encrypted with different encryption keys. Solution to the problem

[0009] A confidential information processing system according to the present disclosure, corresponding to a quantum homomorphic cryptographic technique that satisfies strong circuit confidentiality, wherein the confidential information processing system has an encryption device comprising an encryption unit to generate a first ciphertext by encrypting a first plaintext using a first public parameter and a first encryption key, and to generate a second ciphertext by encrypting a second plaintext using a second public parameter and a second encryption key, wherein Each of the first public parameters as well as the second public parameter is a parameter that is generated using a security parameter, the first encryption key is an encryption key that is generated using the first public parameter and a first decryption key, which is a decryption key generated using the security parameter, and The second encryption key is an encryption key that is generated using the second public parameter and a second decryption key that is a decryption key generated using the security parameter. Advantageous effects of the invention

[0010] According to the present disclosure, it is possible to realize a quantum-homomorphic cryptographic technique that ensures strong circuit confidentiality secure for a quantum computer and enables quantum-homomorphic operation by quantum computation between ciphertexts encrypted with different encryption keys. Brief description of the drawings Fig. Figure 1 is a representation showing a configuration example for a Confidential Information Processing System 100 according to embodiment 1. Fig. Figure 2 is a representation showing a configuration example for a public parameter generating device 200 according to embodiment 1. Fig. Figure 3 is a representation showing a configuration example for a key generation device 300 according to embodiment 1. Fig. Figure 4 is a representation showing a configuration example of an encryption device 400 according to embodiment 1. Fig. Figure 5 is a representation showing a configuration example of a homomorphic arithmetic operation device 500 according to embodiment 1. Fig. Figure 6 is a representation showing a configuration example for a decryption device 600 according to embodiment 1. Fig. Figure 7 is a representation showing an example of a hardware configuration of each facility according to embodiment 1. Fig. Figure 8 is a flowchart showing the operation of the Confidential Information Processing System 100 according to embodiment 1. Fig. Figure 9 is a flowchart showing the operation of the Confidential Information Processing System 100 according to embodiment 1. Fig. Figure 10 is a flowchart showing the operation of the Confidential Information Processing System 100 according to embodiment 1. Fig. Figure 11 is a representation showing an example of a hardware configuration for each facility according to a modification of embodiment 1. Description of embodiments

[0011] In the description and drawings of the embodiments, identical and corresponding elements are designated with the same reference numeral. The description of elements named with the same reference numeral may be omitted or simplified where appropriate. Arrows in the drawings primarily indicate the flow of data or the flow of processing. Furthermore, "unit" can also be interpreted as "setup," "circuit," "process," "sequence," "step," or "circuit." Design 1.

[0012] The present embodiment is described in detail below with reference to the drawings. *** Configuration Description ***

[0013] Fig. Figure 1 shows a system configuration example of a confidential information processing system 100 according to the present embodiment. The confidential information processing system 100 comprises a public parameter generation device 200, a key generation device 300, an encryption device 400, a homomorphic arithmetic operation device 500, and a decryption device 600, as shown in Figure 1. Fig. 1 shown

[0014] Internet 101 is a communication path that connects the Public Parameter Generation Facility 200, the Key Generation Facility 300, a variety of Encryption Facility 400, the Homomorphic Arithmetic Operation Facility 500, and the Decryption Facility 600. Internet 101 is a specific example of a network. Other types of networks can be used instead of Internet 101.

[0015] A specific example of a Public Parameter Generating Device 200 is a Personal Computer (PC). The Public Parameter Generating Device 200 generates a public parameter, which is used to generate an encryption key, a decryption key, and a ciphertext, and transmits data specifying the generated public parameter over the Internet 101 to each of the Key Generating Device 300, the Encryption Device 400, and the Homomorphic Arithmetic Operation Device 500. The data specifying the generated public parameter can be transmitted directly by mail or by similar means.

[0016] A specific example of a Key Generation Device 300 is a PC. The Key Generation Device 300 generates an encryption key, which is used for encryption, and a decryption key, transmits data specifying the generated encryption key over the Internet 101 to the Encryption Device 400 and the Homomorphic Arithmetic Operation Device 500, and transmits data specifying the generated decryption key to the Decryption Device 600. The data specifying each generated key can be transmitted directly by mail or by similar means.

[0017] Since the decryption key is secret information, it is stored in both the key generation unit 300 and the decryption unit 600 to prevent leakage.

[0018] A specific example of an Encryption Device 400 is a PC. The Encryption Device 400 generates ciphertext data by encrypting plaintext data received from a sensor or the like in a factory, using a stored public parameter and a stored encryption key, and transmits the generated ciphertext data over the Internet 101 to the Homomorphic Arithmetic Operation Device 500.

[0019] A specific example of the Homomorphic Arithmetic Operation Device 500 is a computer with a large-capacity storage medium. The Homomorphic Arithmetic Operation Device 500 is also referred to as the Circuit-Confidential Quantum Homomorphic Arithmetic Operation Device.

[0020] The homomorphic arithmetic operation device 500 also functions as a data storage device. This means that when the encryption device 400 receives a storage request for ciphertext data, the homomorphic arithmetic operation device 500 stores the ciphertext data corresponding to the storage request.

[0021] The Homomorphic Arithmetic Operation Facility 500 also functions as a facility that performs a homomorphic arithmetic operation on stored ciphertext data. That is, the Homomorphic Arithmetic Operation Facility 500 generates ciphertext data from a stored public parameter, a stored encryption key, and stored ciphertext data. This ciphertext data corresponds to the result of an arithmetic operation on plaintext data that corresponds to the stored ciphertext data, and it transmits the generated ciphertext data via Internet 101 to the Decryption Facility 600.

[0022] A specific example of a decryption device 600 is a PC. The decryption device 600 also acts as a storage device for the decryption key, receiving data specifying a decryption key transmitted by the key generation device 300 and storing the decryption key specified in the received data.

[0023] The decryption device 600 is also a PC that acts as a decryption device for ciphertext data, receiving ciphertext data transmitted by the homomorphic arithmetic operation device 500 and obtaining a result of the arithmetic operation by decrypting the received ciphertext data using a stored decryption key.

[0024] At least two of the Public Parameter Generation Device 200, the Key Generation Device 300, the Encryption Device 400, the Homomorphic Arithmetic Operation Device 500 and the Decryption Device 600 can be contained in the same PC at the same time.

[0025] One configuration of the present embodiment is described below. The number of elements generated by each device can be two or more.

[0026] Fig. Figure 2 is a block diagram showing a configuration example for the Shared Parameter Generating Unit 200. The Shared Parameter Generating Unit 200 comprises an Input Unit 201, a Shared Parameter Generating Unit 202, and a Transmission Unit 203, as shown in Figure 2. Fig. 2 shown. Although not shown, the Public Parameter Generating Unit 200 contains a storage medium that stores data used in each unit of the Public Parameter Generating Unit 200.

[0027] The input unit 201 receives data specifying a security parameter λ and transmits the received data specifying the security parameter λ to the public parameter generation unit 202.

[0028] The public parameter generation unit 202 takes the security parameter λ, specified in the data received by the input unit 201, as input and generates a public parameter, which is a parameter for generating an encryption key and a decryption key. The public parameter generation unit 202 then transmits data specifying the generated public parameter PP to the transmission unit 203.

[0029] The transmission unit 203 transmits to each of the key generation device 300, the encryption device 400 and the homomorphic arithmetic operation device 500 the data specifying the public parameter PP generated by the public parameter generation unit 202.

[0030] Fig. Figure 3 is a block diagram showing a configuration example for the key generation device 300. The key generation device 300 comprises an input unit 301, a public parameter storage unit 302, a decryption key generation unit 303, an encryption key generation unit 304, and a transmission unit 305, as shown in Figure 3. Fig. 3 shown. Although not shown, the key generation device 300 includes a storage medium that stores data used in each unit of the key generation device 300.

[0031] The input unit 301 receives the data specifying the public parameter PP transmitted by the public parameter generating unit 200 and transmits the public parameter PP specified in the received data to the public parameter storage unit 302.

[0032] Furthermore, the input unit 301 receives the data specifying the security parameter λ and transmits the received data specifying the security parameter λ to the decryption key generation unit 303.

[0033] The public parameter storage unit 302 stores the public parameter PP specified in the data received from the input unit 301.

[0034] The decryption key generation unit 303 generates a decryption key SK using the security parameter λ specified in the data received by the input unit 301 and transmits data specifying the generated decryption key SK to the encryption key generation unit 304 and the transmission unit 305.

[0035] The encryption key generation unit 304 uses the public parameter PP, specified in the data received from the public parameter storage unit 302, and the decryption key SK, specified in the data received from the decryption key generation unit 303, as input to generate an encryption key PK, and transmits data specifying the generated encryption key PK to the transmission unit 305.

[0036] The encryption key generation unit 304 generates a first encryption key using a first public parameter and a first decryption key, and generates a second encryption key using a second public parameter and a second decryption key. Here, each of the first and second public parameters is a parameter generated using the security parameter λ. Each of the first and second decryption keys is a decryption key generated using the security parameter λ.

[0037] The transmission unit 305 transmits data to the decryption unit 600, specifying the decryption key SK generated by the decryption key generation unit 303.

[0038] Furthermore, the transmission unit 305 transmits the data specifying the encryption key PK generated by the encryption key generation unit 304 to each of the encryption device 400 and the homomorphic arithmetic operation device 500.

[0039] Fig. Figure 4 is a block diagram showing a configuration example for the encryption device 400. The encryption device 400 comprises an input unit 401, a public parameter storage unit 402, an encryption key storage unit 403, an encryption unit 404, and a transmission unit 405, as shown in Figure 4. Fig. Figure 4 is shown. Although not shown, the Encryption Device 400 includes a recording medium that stores data used in each unit of the Encryption Device 400.

[0040] The input unit 401 receives the data specifying the public parameter PP transmitted by the public parameter generating unit 200 and transmits the received data specifying the public parameter PP to the public parameter storage unit 402.

[0041] Furthermore, the input unit 401 receives the data specifying the encryption key PK transmitted by the key generation unit 300 and transmits the received data specifying the encryption key PK to the encryption key storage unit 403.

[0042] Furthermore, the input unit 401 receives plaintext data m and transmits the received plaintext data m to the encryption unit 404.

[0043] The public parameter storage unit 402 stores the public parameter PP specified in the data received from the input unit 401.

[0044] The encryption key storage unit 403 stores the encryption key PK, which is specified in the data received from the input unit 401.

[0045] The encryption unit 404 generates ciphertext data C_PK(m) using the public parameter PP received from the public parameter storage unit 402, the encryption key PK received from the encryption key storage unit 403, and the plaintext data m received from the input unit 401. This ciphertext data corresponds to the plaintext data m, and the unit transmits the generated ciphertext data C_PK(m) to the transmission unit 405. Hereinafter, ciphertext data obtained by encrypting the plaintext data m using the encryption key PK is referred to as ciphertext data C_PK(m).

[0046] The encryption unit 404 generates a first ciphertext by encrypting a first plaintext using the first public parameter and the first encryption key, and generates a second ciphertext by encrypting a second plaintext using the second public parameter and the second encryption key.

[0047] The transmission unit 405 receives the ciphertext data C_PK(m) from the encryption unit 404 and transmits the received ciphertext data C_PK(m) to the homomorphic arithmetic operation unit 500.

[0048] Fig. Figure 5 is a block diagram showing a configuration example for the Homomorphic Arithmetic Operation Facility 500. The Homomorphic Arithmetic Operation Facility 500 comprises an Input Unit 501, a Public Parameter Storage Unit 502, an Encryption Key Storage Unit 503, a Ciphertext Storage Unit 504, a Homomorphic Arithmetic Operation Unit 505, and a Transmission Unit 506, as shown in Figure 5. Fig. Figure 5 is shown. Although not shown, the Homomorphic Arithmetic Operation Unit 500 includes a recording medium that stores data used in each unit of the Homomorphic Arithmetic Operation Unit 500.

[0049] Input unit 501 receives data specifying public parameter PP1 and data specifying public parameter PP2, transmitted by public parameter generator 200, and transmits the received data specifying public parameter PP1 and the received data specifying public parameter PP2 to public parameter storage unit 502. Here, the number at the end of the symbol denoting each element is a notation used to distinguish between multiple existing elements of the same type. For public parameter PP1 and public parameter PP2, 1 or 2 is specified to distinguish two public parameters PP generated by public parameter generator 200. Furthermore, public parameter PP1 corresponds to the first public parameter, and public parameter PP2 corresponds to the second public parameter.

[0050] Furthermore, the input unit 501 receives data specifying an encryption key PK1 and data specifying an encryption key PK2, transmitted from the key generation unit 300, and transmits the received data specifying encryption key PK1 and the received data specifying encryption key PK2 to the encryption key storage unit 503. Encryption key PK1 corresponds to the first encryption key. Encryption key PK2 corresponds to the second encryption key. The first encryption key consists of a first homomorphic public key, generated based on a first homomorphic decryption key, and a first quantum homomorphic public key, generated based on a first quantum homomorphic decryption key.The second encryption key consists of a second homomorphic public key, generated on the basis of a second homomorphic decryption key, and a second quantum homomorphic public key, generated on the basis of a second quantum homomorphic decryption key.

[0051] Furthermore, the input unit 501 receives the ciphertext data C_PK(m1) and ciphertext data C_PK(m2) transmitted by the encryption unit 400 and transmits the received ciphertext data C_PK(m1) and the received ciphertext data C_PK(m2) to the ciphertext storage unit 504. Here, the plaintext data m1 corresponds to the first plaintext. The plaintext data m2 corresponds to the second plaintext. The ciphertext data C_PK(m1) corresponds to the first ciphertext. The ciphertext data C_PK(m2) corresponds to the second ciphertext. The first ciphertext is a ciphertext generated based on the first public parameter, a first one-time pad key, the first homomorphic public key, the first quantum homomorphic public key, and a first random number.The second ciphertext is a ciphertext generated on the basis of the second public parameter, a second one-time pad key, the second homomorphic public key, the second quantum homomorphic public key, and a second random number.

[0052] Furthermore, the input unit 501 receives data specifying an arithmetic operation circuit f and transmits the received data specifying the arithmetic operation circuit f to the homomorphic arithmetic operation unit 505. The arithmetic operation circuit f can consist of a plurality of arithmetic operation circuits.

[0053] The public parameter storage unit 502 stores the public parameter PP1 and public parameter PP2 specified in the data received from the input unit 501.

[0054] The encryption key storage unit 503 stores the encryption key PK1 and the encryption key PK2, specified in the data received from the input unit 501.

[0055] The ciphertext storage unit 504 stores the ciphertext data C_PK(m1) received from the input unit 501 and the ciphertext data C_PK(m2).

[0056] The homomorphic arithmetic operation unit 505 calculates ciphertext data C_PK(M) using the arithmetic operation circuit f specified in the data received from the input unit 501, the public parameter PP1 and public parameter PP2 received from the public parameter storage unit 502, the encryption key PK1 and encryption key PK2 received from the encryption key storage unit 503, and the ciphertext data C_PK(m1) and C_PK(m2) received from the ciphertext storage unit 504, and transmits the calculated ciphertext data C_PK(M) to the transmission unit 506.Here are the ciphertext data C_PK(M) data that specify a ciphertext corresponding to the arithmetic operation result data M(=f(m1, m2)), which are data that specify an arithmetic operation result obtained by applying an arithmetic operation specified by the arithmetic operation circuit f to the plaintext data m1 and the plaintext data m2. Furthermore, f(m1, m2) represents the result of executing the arithmetic operation specified by the arithmetic operation circuit f, with the plaintext data m1 and the plaintext data m2, which are two parts of plaintext data, as input. In the following, homomorphically arithmetically operated ciphertext data of the arithmetic operation result data M with respect to a set {PK1, PK2}, consisting of the encryption key PK1 and the encryption key PK2, are represented as C_PK(M). C_PK(M) is also referred to as homomorphically arithmetically operated ciphertext data.Here, the plaintext data m1 corresponds to the first plaintext. The plaintext data m2 corresponds to the second plaintext. C_PK(M) corresponds to a third ciphertext. The arithmetic operation result data M can be decrypted using a decryption key SK1 and a decryption key SK2 for the ciphertext data C_PK(M). The decryption key SK1 corresponds to the first decryption key. The decryption key SK2 corresponds to the second decryption key. The first decryption key consists of the first homomorphic decryption key and the first quantum-homomorphic decryption key. The second decryption key consists of the second homomorphic decryption key and the second quantum-homomorphic decryption key.

[0057] The homomorphic arithmetic operation unit 505 generates the third ciphertext by performing a quantum calculation using the first public parameter, the second public parameter, the first ciphertext, the second ciphertext, the first encryption key, and the second encryption key. Here, the third ciphertext is a ciphertext generated by encrypting an arithmetic operation result obtained by applying an arithmetic operation specified by the arithmetic operation circuit f to the first plaintext and the second plaintext. The arithmetic operation circuit f can each contain a part for calculating a first decryption random number and a part for calculating a second decryption random number.The first decryption random number is a random number calculated based on the security parameter, the first one-time pad key, the first one-time pad key ciphertext data, the first quantum homomorphic public key, and the first random number, and is a random number used to decrypt the third ciphertext. The second decryption random number is a random number calculated based on the security parameter, the second one-time pad key, the second one-time pad key ciphertext data, the second quantum homomorphic public key, and the second random number, and is a random number used to decrypt the third ciphertext.If at least one of the first encryption key, the second encryption key, the first ciphertext and the second ciphertext has not been generated, the homomorphic arithmetic operation unit 505 generates random quantum data as the third ciphertext.

[0058] The Homomorphic Arithmetic Operation Unit 505 determines whether the first encryption key has been generated by the encryption device, depending on whether the first decryption random number has been generated, and determines whether the second encryption key has been generated by the encryption device, depending on whether the second decryption random number has been generated. The Homomorphic Arithmetic Operation Unit 505 also determines whether the first ciphertext has been generated by the encryption device, depending on whether the first decryption random number has been generated, and determines whether the second ciphertext has been generated by the encryption device, depending on whether the second decryption random number has been generated.

[0059] The transmission unit 506 transmits the arithmetically operated ciphertext data C_PK(M) received by the homomorphic arithmetic operation unit 505 to the decryption device 600.

[0060] Fig. Figure 1 is a block diagram showing a configuration example of the decryption device 600. The decryption device 600 comprises an input unit 601, a decryption key storage unit 602, a decryption processing unit 603, and a decryption result storage unit 604, as shown in Figure 2. Fig. Figure 6 is shown. Although not shown, the Decryption Device 600 includes a recording medium that stores data used in each unit of the Decryption Device 600.

[0061] The input unit 601 receives data specifying the decryption key SK1 and data specifying the decryption key SK2 transmitted by the key generation unit 300, and transmits the received data specifying the decryption key SK1 and the received data specifying the decryption key SK2 to the decryption key storage unit 602.

[0062] Furthermore, the input unit 601 receives the arithmetically operated ciphertext data C_PK(M) of the arithmetic operation result data M with respect to the set PK={PK1, PK2} of the encryption key transmitted by the homomorphic arithmetic operation device 500 and transmits the received arithmetically operated ciphertext data C_PK(M) to the decryption processing unit 603.

[0063] The decryption key storage unit 602 stores the decryption key SK1 and the decryption key SK2, specified in the data received from the input unit 601.

[0064] The decryption processing unit 603 receives the arithmetically operated ciphertext data C_PK(M) from the input unit 601, receives the decryption key SK1 and the decryption key SK2 from the decryption key storage unit 602, decrypts the arithmetic operation result data M, which is encrypted using the decryption key SK1 and the decryption key SK2 received for the received arithmetically operated ciphertext data C_PK(M), and transfers the decrypted arithmetic operation result data M to the decryption result storage unit 604.

[0065] The decryption result storage unit 604 receives the arithmetic operation result data M from the decryption processing unit 603 and stores the received arithmetic operation result data M.

[0066] Fig. Figure 7 is a diagram showing an example of the hardware resources of each device according to the present embodiment. Each device is a general-purpose computer comprising a processor 11 (central processing unit) as shown in Figure 7. Fig. 7 shown.

[0067] A specific example of the processor 11 is a central processing unit (CPU), a digital signal processor (DSP), or a graphics processing unit (GPU). The processor 11 is connected via a bus 12 to and controls hardware devices such as a read-only memory (ROM) 13, random access memory (RAM) 14, a communication board 15, a display 31 (display device), a keyboard 32, a mouse 33, a drive 34, and a magnetic disk device 20. The drive 34 is a device that reads from and writes to a storage medium such as a flexible disk drive (FD), a compact disc (CD), and a digital versatile disc (DVD).

[0068] The ROM 13, the RAM 14, the magnetic disk device 20 and the drive 34 are examples of storage devices.

[0069] The keyboard 32, the mouse 33 and the communication board 15 are examples of input devices.

[0070] The display 31 and the communication board 15 are examples of output devices.

[0071] The communication board 15 is connected either wired or wirelessly to a communication network such as a local area network (LAN), the Internet or a telephone line.

[0072] The magnetic disk device 20 stores an operating system (OS) 21, a program group 22 and a file group 23.

[0073] Program group 22 comprises programs that perform functions described in the present embodiment as each “unit”. The programs are read and executed by processor 11. That is, the programs cause a computer to operate as each “unit” and cause the computer to execute a sequence or procedure of each “unit”.

[0074] The file group 23 contains various data pieces (input, output, determination results, calculation results and processing results, etc.) that are used in each "unit" described in the present embodiment.

[0075] Processes of the present embodiment, which are described by means of flowcharts or the like, are carried out using hardware such as the processor 11, a storage device, an input device and an output device.

[0076] What is described as each "unit" can be implemented through firmware, software, hardware, or a combination thereof.

[0077] Any program described in this specification may be recorded on a computer-readable, non-volatile recording medium. A concrete example of such a medium is an optical disc or flash memory. Any program described in this specification may be provided as a program product. *** Description of a business ***

[0078] An operational process of Confidential Information Processing System 100 corresponds to a Confidential Information Processing Procedure. The Confidential Information Processing Procedure is also a general term for procedures that correspond to the operational processes of the individual units that comprise Confidential Information Processing System 100. Furthermore, a program that implements the operation of Confidential Information Processing System 100 is synonymous with a Confidential Information Processing Program. The Confidential Information Processing Program is also a general term for programs that implement the operations of the individual units that comprise Confidential Information Processing System 100.

[0079] Fig. Figure 8 is a flowchart that shows an example of the creation and storage of a public parameter in the Confidential Information Processing System 100. The processes of creating and storing the public parameter are illustrated by… Fig. 8 described.

[0080] Steps S701 to S703 are processes performed by the Public Parameter Generation Device 200, steps S704 to S705 are processes performed by the Key Generation Device 300, steps S706 to S707 are processes performed by the Encryption Device 400, and steps S708 to S709 are processes performed by the Homomorphic Arithmetic Operation Device 500. (Step S701)

[0081] The input unit 201 receives the security parameter λ. (Step S702)

[0082] The public parameter generation unit 202 takes the security parameter λ received from the input unit 201 in step S701 as input and generates the public parameter PP. (Step S703)

[0083] The transmission unit 203 receives the public parameter PP generated by the public parameter generation unit 202 in step S702 and transmits data specifying the received public parameter PP to each of the key generation device 300, the encryption device 400 and the homomorphic arithmetic operation device 500. (Step S704)

[0084] In step S703, the input unit 301 receives the data received from the transmission unit 203, which specifies the public parameter PP. (Step S705)

[0085] The public parameter storage unit 302 stores the public parameter PP specified in the data received from the input unit 301 in step S704. (Step S706)

[0086] In step S703, the input unit 401 receives the data transmitted by the transmission unit 203, which specifies the public parameter PP. (Step S707)

[0087] The public parameter storage unit 402 stores the public parameter PP specified in the data received from the input unit 401 in step S706. (Step S708)

[0088] In step S703, the input unit 501 receives the data transmitted by the transmission unit 203, which specifies the public parameter PP. (Step S709)

[0089] The public parameter storage unit 502 stores the public parameter PP specified in the data received by the input unit 501 in step S708.

[0090] Fig. Figure 9 is a flowchart that shows an example of a process for generating and storing an encryption key and a decryption key in the Confidential Information Processing System 100. The processes of generating and storing the encryption key and the decryption key are illustrated by Fig. 9 described.

[0091] Steps S801 to S804 are processes performed by the key generation device 300, steps S805 to S806 are processes performed by the encryption device 400, steps S807 to S808 are processes performed by the homomorphic arithmetic operation device 500, and steps S809 to S810 are processes performed by the decryption device 600. (Step S801)

[0092] The input unit 301 receives the data specifying the security parameter λ. (Step S802)

[0093] The decryption key generation unit 303 takes the security parameter λ, which is specified in the data received by the input unit 301 in step S801, as input and generates a decryption key SK, which is expressed in a format such as [Formula 1]. SK=(sk,qsk)

[0094] Here, a homomorphic decryption key sk is generated using a homomorphic key generation algorithm described in [Reference 1] with the security parameter λ as input. Furthermore, a quantum-homomorphic decryption key qsk is generated using a quantum-homomorphic key generation algorithm described in [Reference 2] with the security parameter λ and a random number r as input. [Reference 1]

[0095] Ostrovsky, R. et al., “Maliciously Circuit-private FHE.”, CRYPTO 2014: Advances in Cryptology-CRYPTO 2014, pp. 536-553, 2014. [Reference 2]

[0096] Agarwal, A. et al., “Post-Quantum Multi-Party Computation”, EUROCRYPT 2021: Advances in Cryptology - EUROCRYPT 2021, pp. 435-464, 2021. (Step S803)

[0097] The encryption key generation unit 304 takes the decryption key SK generated by the decryption key generation unit 303 in step S802 and the public parameter PP stored in the public parameter storage unit 302 as input and generates the encryption key PK in a format such as [Formula 2]. PK=(pk,qpk,[r])

[0098] Here, a homomorphic public key pk is generated using the homomorphic key generation algorithm described in [Reference 1] and the homomorphic decryption key sk as input. A quantum-homomorphic public key qpk is generated using the quantum-homomorphic key generation algorithm described in [Reference 2], where the public parameter PP, the quantum-homomorphic decryption key qsk, and the random number r serve as input. Furthermore, a random number ciphertext [r] is generated using a homomorphic encryption algorithm described in [Reference 1], where the random number r and the homomorphic public key pk serve as input. (Step S804)

[0099] The transmission unit 305 receives the data specifying the decryption key SK generated by the decryption key generation unit 303 in step S802 and the data specifying the encryption key PK generated by the key generation unit 304 in step S803, transmits the received data specifying the encryption key PK to each of the encryption devices 400 and the homomorphic arithmetic operation device 500, and transmits the received data specifying the decryption key SK to the decryption device 600. (Step S805)

[0100] In step S804, the input unit 401 receives the data transmitted by the transmission unit 305, which specifies the public parameter PP. (Step S806)

[0101] The encryption key storage unit 403 stores the encryption key PK, which is specified in the data received from the input unit 401, in step S805. (Step S807)

[0102] In step S804, the input unit 501 receives the data transmitted by the transmission unit 305, which specifies the encryption key PK. (Step S808)

[0103] The encryption key storage unit 503 stores the encryption key PK, which is specified in the data received from the input unit 501, in step S807. (Step S809)

[0104] In step S804, the input unit 601 receives the data transmitted by the transmission unit 305, which specifies the decryption key SK. (Step S810)

[0105] The decryption key storage unit 602 stores the decryption key SK, which is specified in the data received from the input unit 601, in step S809.

[0106] Since the decryption key SK is secret information, the decryption key storage unit 602 must strictly store the decryption key SK to prevent it from leaking.

[0107] Fig. Figure 10 is a flowchart that shows an example of the homomorphic arithmetic operation in Confidential Information Processing System 100. The homomorphic arithmetic operation is described with reference to Fig. 10 described.

[0108] Steps S901 to S903 are processes performed by the encryption device 400, steps S904 to S908 are processes performed by the homomorphic arithmetic operation device 500, and steps S909 to S911 are processes performed by the decryption device 600. (Step S901)

[0109] The input unit 401 receives the plaintext data m1 and the plaintext data m2, which are collected, for example, by a sensor, and transmits the received plaintext data m1 and the received plaintext data m2 to the encryption unit 404. (Step S902)

[0110] The encryption unit 404 generates the ciphertext data C_PK(m1) and C_PK(m2) from the plaintext data m1 and m2 received by the input unit 401 in step S901, the public parameters PP1 and PP2 stored in the public parameter storage unit 402, and the encryption keys PK1 and PK2 stored in the encryption key storage unit 403. The ciphertext data is expressed in a format such as [Formula 3]. The notation in a formula may differ from the notation in the present text, depending on the character format that can be expressed. CPK(m1)=(c1,[[otk1]]1,[otk1,s1]1) CPK(m2)=(c2,[[otk2]]2,[otk2,s2]2)

[0111] Here, quantum ciphertext data c1 and quantum ciphertext data c2 are generated using a quantum one-time pad encryption algorithm described in [Reference 2], each with a one-time pad key otk1 and a one-time pad key otk2 as input. The one-time pad key otk1 corresponds to the first one-time pad key. The one-time pad key otk2 corresponds to the second one-time pad key. Both [[otk1]]_1 and [[otk2]]_2, which are one-time pad key ciphertext data, are generated using a multi-key quantum homomorphic encryption algorithm described in [Reference 2] with the one-time pad key otk1 or the one-time pad key otk2, a quantum homomorphic public key qpk1 or a quantum homomorphic public key qpk2 and a random number s1 or a random number s2 as input.The quantum homomorphic public key qpk1 corresponds to the first quantum homomorphic public key. The quantum homomorphic public key qpk2 corresponds to the second quantum homomorphic public key. Both the public parameter PP1 and the public parameter PP2 are used as input for the multi-key quantum homomorphic encryption algorithm. Furthermore, [otk1, s1]_1 and [otk2, s2]_2, which are one-time pad keys and random number ciphertext data, are each generated using the homomorphic encryption algorithm described in [Reference 1] with the one-time pad key otk1 or the one-time pad key otk2, a homomorphic public key pk1 or a homomorphic public key pk2, and the random number s1 or the random number s2 as input. The homomorphic public key pk1 corresponds to the first homomorphic public key.The homomorphic public key pk2 corresponds to the second homomorphic public key. The random number s1 corresponds to the first random number. The random number s2 corresponds to the second random number. The encryption unit 404 transmits the ciphertext data C_PK(m1) and the ciphertext data C_PK(m2) respectively to the transmission unit 405 of the encryption device 400. (Step S903)

[0112] The transmission unit 405 receives the ciphertext data C_PK(m1) and the ciphertext data C_PK(m2) transmitted by the encryption unit 404 in step S902, and transmits the received ciphertext data C_PK(m1) and the received ciphertext data C_PK(m2) to the homomorphic arithmetic operation unit 500. (Step S904)

[0113] The input unit 501 receives the ciphertext data C_PK(m1) and ciphertext data C_PK(m2) transmitted by the transmission unit 405 and transmits the received ciphertext data C_PK(m1) and the received ciphertext data C_PK(m2) to the ciphertext storage unit 504. (Step S905)

[0114] The ciphertext storage unit 504 receives the ciphertext data C_PK(m1) and the ciphertext data C_PK(m2) transmitted by the input unit 501 in step S904, and stores the received ciphertext data C_PK(m1) and the received ciphertext data C_PK(m2). (Step S906)

[0115] The input unit 501 receives the arithmetic operation circuit f, which is entered via a keyboard, mouse, memory device or similar, and transmits the received arithmetic operation circuit f to the homomorphic arithmetic operation device 505. (Step S907)

[0116] The homomorphic arithmetic operation unit 505, using the arithmetic operation circuit f received from the input unit 501, generates the arithmetically operated ciphertext data C_PK(M), which corresponds to the arithmetic operation result data M(=f(m1, m2)), which corresponds to the set of encryption keys {PK1, PK2} in the format of [Formula 4], the public parameters PP1 and PP2 stored in the public parameter storage unit 502, the encryption keys PK1 and PK2 stored in the encryption key storage unit 503, and the ciphertext data C_PK(m1) and C_PK(m2) stored in the ciphertext storage unit 504 as input, and transmits the generated arithmetically operated ciphertext data C_PK(M) to the transmission unit 506. CPK(M)=(c',(c1',c2))

[0117] Here, quantum homomorphic arithmetic ciphertext data c' is generated according to a procedure described in [Formula 5]. The quantum homomorphic arithmetic partial ciphertext data c1' and c2' are each generated using a homomorphic arithmetic algorithm described in [Reference 1] with an arithmetic operation circuit described in [Formula 7] or [Formula 8], the homomorphic public key pk1 or the homomorphic public key pk2, random number ciphertext data [r1]_1 or random number ciphertext data [r2]_2 and [otk1, s1]_1 or [otk2, s2]_2, which are one-time pad keys and random number ciphertext data, as input. c'=QOTP.Enc(otk',c")

[0118] An algorithm QOTP.Enc is the quantum one-time pad encryption algorithm described in [Reference 2], and the one-time pad key otk' is a randomly selected bit sequence. Furthermore, c'' is generated using a quantum homomorphic arithmetic algorithm described in [Reference 2] with a quantum circuit G, expressed by [Formula 6], the quantum homomorphic public key qpk1 and the quantum homomorphic public key qpk2, and [[otk1]]_1 and [[otk2]]_2, which are one-time pad key ciphertext data, as input. Both the public parameter PP1 and the public parameter PP2 are used as input for the quantum homomorphic arithmetic algorithm. Gc1,c2(otk1,otk2)=f(QOTP.Dec(otk1,c1),QOTP.Dec(otk2,c2))

[0119] The algorithm QOTP.Dec is a quantum one-time pad decryption algorithm described in [Reference 2]. Tqpk1.[[otk1]]1,ρ1(r1,otk1,s1)={ρ1wenn(⋅,qpk1)=MKQFHE.Gen(1λ,r1)0und[[otk1]]1=MKQFHE.Enc(qpk1,otk1,s1)andernfalls Tqpk1.[[otk1]]2,ρ2(r2,otk2,s2)={ρ2wenn(⋅,qpk2)=MKQFHE.Gen(1λ,r2)0und[[otk1]]1=MKQFHE.Enc(qpk2,otk2,s2)andernfalls1

[0120] The algorithms MKQFHE.Gen and MKQFHE.Enc are, respectively, the quantum homomorphic key generation algorithm and the quantum homomorphic encryption algorithm, as described in [Reference 2]. Furthermore, a random number ρ1 and a random number ρ2 are used for decrypting ciphertext data and satisfy the relationship of [Formula 9] with respect to the one-time pad key otk'. Here, [Formula 7] corresponds to the part that calculates the first decryption random number. [Formula 8] corresponds to the part that calculates the second decryption random number. The random number ρ1 corresponds to the first decryption random number. The random number ρ2 corresponds to the second decryption random number.

[0121] The homomorphic arithmetic operation unit 505 verifies that each of the encryption keys PK and each part of the ciphertext data C_PK(m) are correctly generated by performing the arithmetic operation specified by the arithmetic operation circuit f described in [Formula 7] and [Formula 8] while the data remains encrypted. If an encryption key not generated by the key generation unit 300 is used in the homomorphic arithmetic operation unit 505, the random numbers ρ1 and ρ2 cannot be obtained in the decryption unit 600 due to the configuration of the arithmetic operation circuit f described in [Formula 7] and [Formula 8].Even if ciphertext data not generated by the encryption device 400 is used in the homomorphic arithmetic operation unit 505, the random number ρ1 and the random number ρ2 cannot be obtained in a similar way in the decryption device 600. otk'=XOR(ρ1,ρ2)

[0122] Here is an arithmetic operation circuit XOR, a circuit that calculates a bitwise XOR of ρ1 and ρ2 that are input into the circuit. (Step S908)

[0123] In step S907, the transmission unit 506 transmits the arithmetically operated ciphertext data C_PK(M) received from the homomorphic arithmetic operation unit 505 to the decryption device 600. (Step S909)

[0124] The input unit 601 receives the arithmetically operated ciphertext data C_PK(M) transmitted by the transmission unit 506 in step S908 and transmits the received arithmetically operated ciphertext data C_PK(M) to the decryption processing unit 603. (Step S910)

[0125] The decryption processing unit 603 obtains a decryption result M by performing a decryption process using the arithmetically operated ciphertext data C_PK(M) transferred by the input unit 601 in step S909 and the decryption keys SK1 and SK2, which are stored in the decryption key storage unit 602. Here, the decryption processing unit 603 can decrypt the decryption result M(=f(m1, m2)) for the encryption key set {PK1, PK2}, which corresponds to the arithmetically operated ciphertext data C_PK(M), only if the encryption key PK1 was generated in the encryption key generation unit 304 with the decryption key SK1 as input and the encryption key PK2 was generated in the encryption key generation unit 304 with the decryption key SK2 as input.

[0126] The decryption processing unit 603 transfers the decryption result M to the decryption result storage unit 604. (Step S911)

[0127] The decryption result storage unit 604 stores the decryption result M transferred by the decryption processing unit 603 in step S910.

[0128] A ciphertext to be received by the decryption device 600 is a ciphertext to which the homomorphic arithmetic operation has been applied. Therefore, if the ciphertext is to be decrypted before the homomorphic arithmetic operation is applied, the plaintext data corresponding to the ciphertext before the homomorphic arithmetic operation is applied can be decrypted by requesting the homomorphic arithmetic operation device 500 to perform the homomorphic arithmetic operation, which outputs the same value as the input itself, and by decrypting a ciphertext to which the homomorphic arithmetic operation has been applied, obtained by performing the homomorphic arithmetic operation, in the same way as in step S910.

[0129] Step S911 terminates the homomorphic arithmetic processing of the Confidential Information Processing System 100. *** Description of the effects of embodiment 1 ***

[0130] As described above, the present embodiment uses internal homomorphic encryption that satisfies the circuit confidentiality requirement for a quantum computer. Each of the cryptographic techniques described in [Reference 1] and [Reference 2] provides security for the quantum computer. Therefore, a quantum homomorphic encryption method that satisfies the strong circuit confidentiality requirement of the present embodiment also provides security for the quantum computer. Conversely, since internal homomorphic encryption that satisfies circuit confidentiality is not secure for the quantum computer, the conventional technique does not provide security for the quantum computer.

[0131] Since the present embodiment offers security against the quantum computer, it is also possible to adjust a parameter more efficiently and implement an encryption method. However, since conventional techniques do not provide security for the quantum computer, a ciphertext must be calculated whose size is large enough to guarantee security for the quantum computer.

[0132] Accordingly, according to the present embodiment, it is not necessary to generate a ciphertext that is secure for a quantum computer and whose size is sufficiently large. *** Other configurations ***<Modifikation 1>

[0133] Fig. Figure 11 shows an example of the hardware configuration of each facility according to the present modification.

[0134] Each device contains a processing circuit 18 in place of the processor 11, the processor 11 and the ROM 13, the processor 11 and the RAM 14, or the processor 11, the ROM 13 and the RAM 14.

[0135] The processing circuit 18 is hardware that implements at least part of each unit contained in each facility.

[0136] The processing circuit 18 can be dedicated hardware or a processor that executes a program stored in RAM 14.

[0137] If the processing circuit 18 is dedicated hardware, a specific example of the processing circuit 18 is a single circuit, a composite circuit, a programmed processor, a parallel-programmed processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a combination thereof.

[0138] Each system can include a variety of processing circuits as an alternative to processing circuit 18. These multiple processing circuits share the role of processing circuit 18.

[0139] In any given facility, some functions may be implemented through dedicated hardware, while the remaining functions may be implemented through software or firmware.

[0140] In a specific example, the processing circuit 18 is implemented by hardware, software, firmware or a combination thereof.

[0141] The processor 11, the ROM 13, the RAM 14, and the processing circuit 18 are collectively referred to as the "processing circuit." This means that the functions of the individual functional components of each device are implemented by the processing circuit. *** Other versions ***

[0142] While embodiment 1 has been described, a multitude of parts of the present embodiment can be implemented in combination. Alternatively, the present embodiment can also be implemented in parts. Furthermore, the present embodiment can be modified in various ways as required and can be implemented wholly or partially in any combination.

[0143] The embodiments described above are essentially preferred examples and are not intended to limit the present disclosure, its possible applications, or the scope of its uses. The methods described in the flowcharts and the like may be modified appropriately. Reference symbol list

[0144] 11: Processor; 12: Bus; 13: ROM; 14: RAM; 15: Communication board; 18: Processing circuit; 20: Magnetic disk device; 21: OS; 22: Program group; 23: File group; 31: Display; 32: Keyboard; 33: Mouse; 34: Drive; 100: Confidential information processing system; 101: Internet; 200: Public parameter generation device; 201: Input device; 202: Public parameter generation device; 203: Transmission device; 300: Key generation device; 301: Input device; 302: Public parameter storage device; 303: Decryption key generation device; 304: Encryption key generation device; 305: Transmission device; 400: Encryption device; 401: Input Unit; 402: Public Parameter Storage Unit; 403: Encryption Key Storage Unit; 404: Encryption Unit; 405: Transmission Unit; 500: Homomorphic Arithmetic Operation Unit; 501: Input Unit; 502: Public Parameter Storage Unit;503: Encryption key storage unit; 504: Ciphertext storage unit; 505: Homomorphic arithmetic operation unit; 506: Transmission unit; 600: Decryption unit; 601: Input unit; 602: Decryption key storage unit; 603: Decryption processing unit; 604: Decryption result storage unit.

Claims

[1] Confidential Information Processing System (100) corresponding to a quantum homomorphic cryptographic technique that satisfies strong circuit confidentiality, wherein the Confidential Information Processing System (100) comprises an encryption device (400) comprising an encryption unit (404) for generating a first ciphertext by encrypting a first plaintext using a first public parameter and a first encryption key, and for generating a second ciphertext by encrypting a second plaintext using a second public parameter and a second encryption key, wherein Each of the first public parameters as well as the second public parameter is a parameter that is generated using a security parameter, The first encryption key is an encryption key generated using the first public parameter, and a first decryption key is a decryption key generated using the security parameter. the second encryption key is an encryption key that is generated using the second public parameter and a second decryption key that is a decryption key generated using the security parameter, the first decryption key consists of a first homomorphic decryption key and a first quantum homomorphic decryption key, the second decryption key consists of a second homomorphic decryption key and a second quantum-homomorphic decryption key, the first encryption key consists of a first homomorphic public key generated on the basis of the first homomorphic decryption key, and a first quantum homomorphic public key generated on the basis of the first quantum homomorphic decryption key, the second encryption key consists of a second homomorphic public key generated on the basis of the second homomorphic decryption key, and a second quantum-homomorphic public key generated on the basis of the second quantum-homomorphic decryption key, the first ciphertext is generated based on the first public parameter, a first one-time pad key, the first homomorphic public key, the first quantum-homomorphic public key, and a first random number, and The second ciphertext is generated based on the second public parameter, a second one-time pad key, the second homomorphic public key, the second quantum-homomorphic public key, and a second random number. [2] Confidential information processing system (100) according to claim 1, further comprising a key generation device (300) comprising an encryption key generation unit (304) to generate the first encryption key using the first public parameter and the first decryption key, and to generate the second encryption key using the second public parameter and the second decryption key. [3] Confidential information processing system (100) according to claim 1 or 2, further comprising a homomorphic arithmetic operation device (500) comprising a homomorphic arithmetic operation unit (505) for generating a third ciphertext, which is a ciphertext generated by encrypting an arithmetic operation result obtained by applying an arithmetic operation specified by an arithmetic operation circuit to the first plaintext and the second plaintext, by performing quantum calculation using the arithmetic operation circuit, the first public parameter, the second public parameter, the first ciphertext, the second ciphertext, the first encryption key and the second encryption key. [4] Confidential Information Processing System (100) according to claim 3, wherein if at least one of the first encryption key, the second encryption key, the first ciphertext and the second ciphertext has not been generated, the homomorphic arithmetic operation unit (505) generates random quantum data as the third ciphertext. [5] Confidential information processing system (100) according to claim 3 or 4, wherein the arithmetic operation circuit each has a part that calculates a first decryption random number, which is a random number for decrypting the third ciphertext based on the security parameter, the first one-time pad key, the first one-time pad key ciphertext data, the first quantum homomorphic public key, and the first random number, and a part that calculates a second decryption random number, which is a random number for decrypting the third ciphertext based on the security parameter, the second one-time pad key, the second one-time pad key ciphertext data, the second quantum homomorphic public key, and the second random number. The first one-time pad key ciphertext data are ciphertext data generated based on the first one-time pad key, the first quantum homomorphic public key, and the first random number. the second one-time pad key ciphertext data are ciphertext data generated on the basis of the second one-time pad key, the second quantum homomorphic public key, and the second random number, and The homomorphic arithmetic operation unit (505) determines whether the first encryption key has been generated by the encryption device (400) or not, depending on whether the first decryption random number has been generated or not, and determines whether the second encryption key has been generated by the encryption device (400) or not, depending on whether the second decryption random number has been generated or not. [6] Confidential information processing system (100) according to claim 3 or 4, wherein the arithmetic operation circuit each has a part that calculates a first decryption random number, which is a random number for decrypting the third ciphertext based on the security parameter, the first one-time pad key, the first one-time pad key ciphertext data, the first quantum homomorphic public key, and the first random number, and a part that calculates a second decryption random number, which is a random number for decrypting the third ciphertext based on the security parameter, the second one-time pad key, the second one-time pad key ciphertext data, the second quantum homomorphic public key, and the second random number. The first one-time pad key ciphertext data are ciphertext data generated based on the first one-time pad key, the first quantum homomorphic public key, and the first random number. the second one-time pad key ciphertext data are ciphertext data generated on the basis of the second one-time pad key, the second quantum homomorphic public key, and the second random number, and The homomorphic arithmetic operation unit (505) determines whether the first ciphertext has been generated by the encryption device (400) or not, depending on whether the first decryption random number has been generated or not, and determines whether the second ciphertext has been generated by the encryption device (400) or not, depending on whether the second decryption random number has been generated or not. [7] Confidential information processing method corresponding to a quantum homomorphic cryptographic technique that satisfies strong circuit confidentiality, wherein the confidential information processing method includes by a computer, generating a first ciphertext by encrypting a first plaintext using a first public parameter and a first encryption key, and generating a second ciphertext by encrypting a second plaintext using a second public parameter and a second encryption key, wherein Each of the first public parameters as well as the second public parameter is a parameter that is generated using a security parameter, The first encryption key is an encryption key generated using the first public parameter, and a first decryption key is a decryption key generated using the security parameter. the second encryption key is an encryption key that is generated using the second public parameter and a second decryption key that is a decryption key generated using the security parameter, the first decryption key consists of a first homomorphic decryption key and a first quantum homomorphic decryption key, the second decryption key consists of a second homomorphic decryption key and a second quantum-homomorphic decryption key, the first encryption key consists of a first homomorphic public key generated on the basis of the first homomorphic decryption key, and a first quantum homomorphic public key generated on the basis of the first quantum homomorphic decryption key, the second encryption key consists of a second homomorphic public key generated on the basis of the second homomorphic decryption key, and a second quantum-homomorphic public key generated on the basis of the second quantum-homomorphic decryption key, the first ciphertext is generated based on the first public parameter, a first one-time pad key, the first homomorphic public key, the first quantum-homomorphic public key, and a first random number, and The second ciphertext is generated based on the second public parameter, a second one-time pad key, the second homomorphic public key, the second quantum-homomorphic public key, and a second random number. [8] Confidential information processing program conforming to a quantum homomorphic cryptographic technique that satisfies strong circuit confidentiality, wherein the confidential information processing program causes an encryption device (400), which is a computer, to execute an encryption process to generate a first ciphertext by encrypting a first plaintext using a first public parameter and a first encryption key, and to generate a second ciphertext by encrypting a second plaintext using a second public parameter and a second encryption key, wherein Each of the first public parameters as well as the second public parameter is a parameter that is generated using a security parameter, The first encryption key is an encryption key generated using the first public parameter, and a first decryption key is a decryption key generated using the security parameter. the second encryption key is an encryption key that is generated using the second public parameter and a second decryption key that is a decryption key generated using the security parameter, the first decryption key consists of a first homomorphic decryption key and a first quantum homomorphic decryption key, the second decryption key consists of a second homomorphic decryption key and a second quantum-homomorphic decryption key, the first encryption key consists of a first homomorphic public key generated on the basis of the first homomorphic decryption key, and a first quantum homomorphic public key generated on the basis of the first quantum homomorphic decryption key, the second encryption key consists of a second homomorphic public key generated on the basis of the second homomorphic decryption key, and a second quantum-homomorphic public key generated on the basis of the second quantum-homomorphic decryption key, the first ciphertext is generated based on the first public parameter, a first one-time pad key, the first homomorphic public key, the first quantum-homomorphic public key, and a first random number, and The second ciphertext is generated based on the second public parameter, a second one-time pad key, the second homomorphic public key, the second quantum-homomorphic public key, and a second random number.

Citation Information

Patent Citations

  • Concealed information processing device, encryption device, encryption method, and encryption program

    WO2021245931A1