Secret calculation system, user terminal, operation server, and program
By dividing participants into groups within a (k+1, k+1)-ThFHE configuration, the system enhances efficiency in ThFHE systems while maintaining security, addressing the inefficiency issues associated with increasing participant numbers.
Patent Information
- Application Number
- JP2023189460
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-06
- Publication Date
- 2025-05-19
AI Technical Summary
Threshold fully homomorphic encryption (ThFHE) systems experience decreased efficiency as the number of participants increases, due to longer key generation times, longer operation keys, and increased execution times for homomorphic operations.
The system divides participants into groups, using a (k+1, k+1)-ThFHE configuration where each group shares a secret key, and the operator holds its own secret key. This allows for efficient homomorphic operations by reducing the number of groups rather than total participants.
This approach improves efficiency without compromising security, as the confidentiality of ciphertexts is maintained by ensuring that k+1 participants, including the operator, do not collude.
Smart Images

Figure 2025077345000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a secure computing system based on fully homomorphic operations with data input from multiple users.
Background Art
[0002] The fully homomorphic encryption (FHE) is a public key encryption method that enables arbitrary calculations while keeping the data encrypted. For example, its configuration is shown in Non-Patent Documents 1 to 3 and the like. Also, the threshold fully homomorphic encryption (ThFHE) is an extended method of FHE having functions for use by multiple users. For example, its configuration is shown in Non-Patent Documents 4 and 5 and the like.
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Non-Patent Document 2
Non-Patent Document 3
Non-Patent Document 4
Non-Patent Document 5
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, since ThFHE needs to generate secret keys for N participants, the key generation time increases according to N, the operation key becomes longer depending on N, and the execution time of the homomorphic operation increases. That is, there is a problem that the efficiency decreases according to the number of participants N.
[0005] An object of the present invention is to provide a secret calculation system that can improve efficiency without impairing security.
Means for Solving the Problems
[0006] A first aspect of the secret computing system according to the present invention includes a plurality of user terminals distributed into two or more groups and an arithmetic server. The plurality of user terminals are in a fully homomorphic encryption scheme that can be decrypted only by integrating all the partial decryption texts obtained by partially decrypting the ciphertext encrypted with the public key using different secret keys in each group. It includes a terminal secret key holding unit that shares the secret key within the group, and an encryption unit that encrypts its own input data with the public key and transmits it to the arithmetic server. Among the plurality of user terminals, the representative terminal in each of the groups further includes a terminal partial decryption unit that, when receiving the ciphertext of the arithmetic result from the arithmetic server, decrypts it into a partial decryption text with the secret key and transmits it to any of the plurality of user terminals. Any one of the plurality of user terminals further includes an arithmetic result output unit that outputs the arithmetic result decrypted by integrating all the partial decryption texts when receiving all the partial decryption texts. The arithmetic server includes a homomorphic arithmetic unit that executes a predetermined arithmetic on the encrypted input data received from the plurality of user terminals in an encrypted state using an arithmetic key and transmits the ciphertext of the arithmetic result to at least the representative terminal among the plurality of user terminals.
[0007] The second aspect of the secret computing system according to the present invention includes a plurality of user terminals distributed into one or more groups and an arithmetic server. The plurality of user terminals are in a fully homomorphic encryption scheme that can be decrypted only by integrating ciphertext encrypted with a public key and all partial decryption texts obtained by partially decrypting the ciphertext with different secret keys in each of the groups and the arithmetic server, and includes a terminal secret key holding unit that shares the secret key within the group, and an encryption unit that encrypts its own input data with the public key and transmits it to the arithmetic server. Among the plurality of user terminals, a representative terminal in each of the groups further includes a terminal partial decryption unit that, when receiving the ciphertext of the arithmetic result from the arithmetic server, decrypts it into a partial decryption text with the secret key and transmits it to any of the plurality of user terminals. Any one of the plurality of user terminals further includes an arithmetic result output unit that outputs the arithmetic result decrypted by integrating all the partial decryption texts when receiving all the partial decryption texts. The arithmetic server includes an operator secret key holding unit that holds its own secret key, a homomorphic operation unit that executes a predetermined operation on the encrypted input data received from the plurality of user terminals in an encrypted state using an operation key and transmits the ciphertext of the arithmetic result to at least the representative terminal among the plurality of user terminals, and an operator partial decryption unit that decrypts the ciphertext of the arithmetic result into a partial decryption text with the own secret key and transmits it to any of the plurality of user terminals.
[0008] The secret computing system includes one or more data providing terminals that do not hold the secret key and encrypt their own input data with the public key and transmit it to the arithmetic server, and the homomorphic operation unit may execute the predetermined operation on the encrypted input data received from the plurality of user terminals and the data providing terminals.
[0009] The user terminal according to the present invention is in a fully homomorphic encryption method that can be decrypted by integrating all the partial decryption texts obtained by partially decrypting the ciphertext encrypted with the public key using different secret keys for each group. The user terminal includes: a terminal secret key holding unit that shares the secret key within the group; an encryption unit that encrypts its own input data with the public key and transmits it to the arithmetic server; a terminal partial decryption unit that, when receiving the ciphertext of the arithmetic result obtained by executing a predetermined arithmetic operation on the encrypted input data received from a plurality of terminals by the arithmetic server using the arithmetic key in an encrypted state, decrypts it into a partial decryption text with the secret key; and an arithmetic result output unit that, when receiving all the partial decryption texts from each of the groups, outputs the arithmetic result decrypted by integrating all the partial decryption texts.
[0010] The first aspect of the arithmetic server according to the present invention is: when receiving the input data of each of the plurality of user terminals encrypted with the public key in a fully homomorphic encryption method that can be decrypted only by integrating all the partial decryption texts obtained by partially decrypting with different secret keys for each of the two or more groups, a homomorphic arithmetic unit that executes a predetermined arithmetic operation on the encrypted input data using the arithmetic key in an encrypted state, and transmits the ciphertext of the arithmetic result to at least a representative terminal among the user terminals of each group for partial decryption.
[0011] A second aspect of the computing server according to the present invention is in a fully homomorphic encryption scheme that can be decrypted only by integrating all the partial decryption texts partially decrypted by a plurality of different secret keys. It includes an operator secret key holding unit that holds one of the plurality of secret keys as its own secret key, and when receiving the input data of each of the plurality of user terminals encrypted by the public key in the fully homomorphic encryption scheme from a plurality of user terminals distributed to one or more groups that share any of the plurality of secret keys, it executes a predetermined operation on the encrypted input data in an encrypted state using an operation key, and transmits the ciphertext of the operation result to at least a representative terminal among the user terminals of each group to perform partial decryption, and an operator partial decryption unit that decrypts the ciphertext of the operation result into a partial decryption text using the own secret key and transmits it to any of the plurality of user terminals.
[0012] The program according to the present invention is for causing a computer to function as the user terminal.
[0013] Also, the program according to the present invention is for causing a computer to function as the computing server.
Advantages of the Invention
[0014] According to the present invention, a secure computing system with improved efficiency can be configured without sacrificing security.
Brief Description of the Drawings
[0015]
Figure 1
Figure 2
Figure 3
Embodiments for Carrying Out the Invention
[0016] Hereinafter, an example of an embodiment of the present invention will be described. For comparison with this embodiment, first, a conventional threshold fully homomorphic encryption method and a conventional secret calculation system using the same will be described, and then the system configuration and its functions of this embodiment will be described in detail.
[0017] [FHE] The fully homomorphic encryption method FHE = (FHE.Keygen, FHE.Enc, FHE.Dec, FHE.Eval) is defined as follows.
[0018] · FHE.Keygen(1 λ ) → (pk, evk, sk): A key generation algorithm that outputs a public key pk, a public operation key evk, and a secret key sk. · FHE.Enc(pk, m ∈ {0, 1}) → ct: An encryption algorithm similar to ordinary public key encryption that takes a public key pk and a plaintext m ∈ {0, 1} as inputs and outputs a ciphertext ct. · FHE.Dec(sk, ct) → m: A decryption algorithm similar to ordinary public key encryption that takes a secret key sk and a ciphertext ct as inputs and outputs a plaintext m. · FHE.Eval(evk, f, ct 1 , …, ct l ) → ct f : An operation key evk, a binary circuit f: {0, 1} l → {0, 1}, m 1 , …, m l The l ciphertexts ct 1 , …, ct l encrypted with, and inputs f(m 1 , …, m l ) and outputs the ciphertext ct f of f(m
[0019] [ThFHE] The set of participants (users) is P = {P 1 , …, P NLet it be so, and let S be a class of access structures for decryption with respect to P. For example, "t-out-of-N" indicates an access structure with a threshold t that can be decrypted if t out of N people gather. For the class S, the threshold fully homomorphic encryption scheme ThFHE = (ThFHE.KeyGen, ThFHE.Enc, ThFHE.Eval, ThFHE.PartDec, ThFHE.FinDec) is defined as follows.
[0020] ·ThFHE.KeyGen(1 λ , A) → (evk, jpk, sk 1 , …, sk N ): A key generation algorithm that generates a common public key jpk, a public operation key evk, and distributed secret keys sk 1 , …, sk N for the input security parameter λ and the access structure A belonging to the class S. ThFHE.Enc(jpk, m) → ct: An encryption algorithm that outputs a ciphertext ct for the input public key jpk and plaintext m ∈ {0, 1}. ·ThFHE.Eval(evk, f, ct 1 , …, ct l ) → ct f : A homomorphic operation algorithm that takes the operation key evk, a binary circuit f: {0, 1} l → {0, 1}, ciphertexts ct 1 , …, ct l as input and outputs ct 1 , …, m l ) which is the ciphertext of f(m f . ·ThFHE.PartDec(ct, sk i ) → p i : A partial composite algorithm that each participant P i executes, takes the ciphertext ct and the distributed secret key sk i as input, and outputs a partial decryption text p i . ·ThFHE.FinDec({p i} i∈Q ) → m^: A set Q ⊆ {P 1 , …, P N} of participants corresponds to a set {p i} i∈Q of partial decryption texts. When Q satisfies the access structure A, the decryption algorithm outputs the plaintext m ∈ {0, 1}, and when it does not satisfy, it outputs ⊥ (not outputting the correct plaintext).
[0021] Thus, in ThFHE, a public key jpk and a corresponding distributed secret key (sk 1 , …, sk N ) are used. Each participant (number i) holds the distributed secret key sk i respectively, and the common public key jpk is used for encryption. In the case of a (t, N)-threshold fully homomorphic encryption scheme where the access structure is t-out-of-N, among N participants, t or more participants perform partial decryption using the distributed secret key sk i respectively, and the overall decryption is completed by collecting these partial decryption texts.
[0022] Figure 3 is a diagram showing the configuration of a conventional secret computing system using ThFHE. In the case of a multi-user secret computing system using (t, N)-ThFHE, N participants (P 1 , …, P N ) each hold a distributed secret key (sk 1 , …, sk N ), and further hold a Joint public key jpk := (pk i + … + pk i ) that is common to all participants, calculated from the public key pk 1 corresponding to sk N . Decryption is completed by t participants among N performing partial decryption (PartDec) using the distributed secret key sk i and then collecting the t partial decryption texts p i and performing FinDec.
[0023] [System Configuration] The secure computing system of this embodiment is configured by dividing N participants into k < N groups and using (k + 1, k + 1)-ThFHE.
[0024] Figure 1 is a diagram showing the configuration of the secure computing system 1 in this embodiment. Participant P 1 ,…,P N are divided into k < N groups G 1 ,…,G k . Separately from the k groups, an operator E who performs homomorphic operations is provided.
[0025] Here, the participants belonging to each group G 1 ,…,G k share the secret keys sk G1 ,…,sk Gk respectively, and the operator E holds its own secret key sk E . Also, jpk is the Joint public key corresponding to k + 1 secret keys sk E ,sk G1 ,…,sk Gk , and the decryption access structure is (k + 1)-out-of-(k + 1). That is, for decryption, partial decryption using all k + 1 secret keys is required.
[0026] The algorithm (protocol) of the encryption method implemented in the secure computing system 1 is executed in the following procedure.
[0027] Key generation: The representatives P 1 ,…,G k of each group G * G1 ,…,P * Gk , and k + 1 people including the operator E execute the KeyGen of (k + 1, k + 1)-ThFHE to generate (jpk, evk, sk E ,sk G1 ,…,sk Gk ). The operator E holds its own secret key sk Eholds. Also, the representative P of each group * G1 ,…,P * Gk holds the secret key sk G1 ,…,sk Gk respectively, and shares them with the participants within their own group using a secure communication channel.
[0028] Encryption: Participants P 1 ,…,P N encrypt their respective plaintext inputs m 1 ,…,m N using jpk (ThFHE.Enc) to generate ciphertexts ct 1 ,…,ct N and send them to the operator E.
[0029] Homomorphic operation: The operator E uses the operation key evk to perform a homomorphic operation (ThFHE.Eval) of the function f on the ciphertexts to generate ciphertext ct. Furthermore, the operator E uses its own secret key sk E to perform partial decryption (ThFHE.PartDec) on ct to generate a partially decrypted text p E . After that, ct and p E are sent to each participant P 1 ,…,P N .
[0030] Decryption: One by one from each group G 1 ,…,G k performs partial decryption using the secret key sk of its own group Gi to generate a partially decrypted text p Gi , and sends it to all participants P 1 ,…,P N , or only to the participants who desire to perform decryption. p E ,p G1 ,…,p Gk The participants who obtain these complete the decryption using ThFHE.FinDec.
[0031] Figure 2 is a diagram showing the functional units of each device constituting the secret calculation system 1 in the present embodiment. Each of the plurality of user terminals 10 assigned to one or more groups and the calculation server 20 as a calculator is an information processing device (computer) having various input / output and communication interfaces in addition to a control unit and a storage unit. The control unit realizes the processing of each functional unit by reading and executing the software stored in the storage unit.
[0032] The control unit of the user terminal 10 includes a terminal secret key holding unit 11, an encryption unit 12, a terminal partial decryption unit 13, and a calculation result output unit 14. Note that the terminal partial decryption unit 13 only needs to be provided in at least one representative terminal in each group among the plurality of user terminals 10. Also, the calculation result output unit 14 only needs to be provided in any one of the plurality of user terminals 10, that is, the participant who desires the calculation result.
[0033] The terminal secret key holding unit 11 shares the secret key sk in the aforementioned (k + 1, k + 1)-ThFHE Gi among each group G i internally.
[0034] The encryption unit 12 encrypts its own input data (plaintext m) with the Joint public key jpk and transmits it to the calculation server 20.
[0035] When the terminal partial decryption unit 13 receives the ciphertext ct of the calculation result from the calculation server 20, it decrypts the ciphertext into a partial decryption text p Gi using the secret key sk Gi shared within its own group, and transmits it to the terminal of the participant who desires the calculation result, that is, any one of the plurality of user terminals.
[0036] When the calculation result output unit 14 receives all the partial decryption texts from all the groups, it outputs the decrypted calculation result by integrating all these partial decryption texts.
[0037] The control unit of the computing server 20 includes a computing operator's secret key holding unit 21, a homomorphic computing unit 22, and a computing operator's partial decryption unit 23.
[0038] The computing operator's secret key holding unit 21 holds the secret key sk of the computing server 20 itself, which is different from the plurality of user terminals 10. E to hold.
[0039] The homomorphic computing unit 22 performs a predetermined operation on the encrypted input data received from the plurality of user terminals 10 in an encrypted state using the computing key evk, and transmits the ciphertext of the operation result to at least the representative terminal among the plurality of user terminals.
[0040] The computing operator's partial decryption unit 23 decrypts the ciphertext of the operation result into a partial decryption text p E using its own secret key sk, E and transmits the operation result to the terminal of the participant who desires it, that is, any one of the plurality of user terminals 10.
[0041] In this way, the secret computing system 1 generates (jpk, evk, sk E , sk G1 , …, sk Gk ) by KeyGen of (k + 1, k + 1)-ThFHE, and shares sk G1 , …, sk Gk among the participants in the group G 1 , …, G k .
[0042] Here, the number k of groups satisfies k ≥ 1, and a secret key sk E is also assigned to the computing server to ensure a plurality of secret keys, but the system configuration is not limited to this. That is, a configuration based on (k, k)-ThFHE may be adopted in which the secret key sk E is not distributed to the computing operator E, and only other participants hold the secret keys sk G1 , …, sk Gk . However, in this configuration, the number of groups is limited to the case where k > 2.
[0043] In addition, the participants in the secret computing system 1 may include a data provider terminal that does not have a secret key but only has a public key jpk, that is, a configuration in which only encrypted data is provided to the computing server 20 and the terminal does not participate in decryption. In this case, the computing server 20 similarly executes a predetermined operation on the encrypted input data received from the plurality of user terminals 10 and the data providing terminal. The added data providing terminal can provide data to the computing server 20 in exchange for, for example, a reward, but cannot decrypt the ciphertext, and thus cannot obtain the operation result.
[0044] According to this embodiment, the secret computing system 1 improves efficiency and security as follows compared with the prior art. (Efficiency) In the prior art, the efficiency decreased according to the total number of participants N. However, in this embodiment, since the efficiency is determined according to the number of groups k (<N), it is more efficient than the prior art. (Security) In the prior art, the confidentiality of the ciphertext was maintained as long as t out of N participants did not collude. In contrast, in this embodiment, the confidentiality of the ciphertext is maintained as long as k + 1 participants, one participant from each group and the operator E, do not collude. Therefore, by appropriately setting the number of groups k (k ≧ t - 1), security equal to or higher than that of the prior art can be maintained. Furthermore, since it is necessary to select a representative for each group, an improvement in security can be expected compared with the prior art.
[0045] Thus, according to this embodiment, it is possible to configure a secret computing system 1 that is more efficient than the prior art without sacrificing security. In addition, the secret computing system 1 may also obtain user data from a data providing terminal that does not hold a secret key and cannot decrypt the operation result, thereby making it applicable to statistical analysis of large-scale data and the like. Furthermore, by adopting a configuration in which the computing server 20 participates in partial decryption, the number of groups for distributing participants can be generalized to 1 or more.
[0046] Note that according to this embodiment, for example, since a secure computing system having practical efficiency and safety can be configured, it is possible to contribute to Goal 9 of the Sustainable Development Goals (SDGs) led by the United Nations, "Build resilient infrastructure, promote sustainable industrialization, and foster innovation."
[0047] As described above, the embodiments of the present invention have been described. However, the present invention is not limited to the above-described embodiments. Also, the effects described in the above-described embodiments are merely an enumeration of the most suitable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0048] The secure computing method by the secure computing system 1 is realized by software or a hardware circuit. When realized by software, the program constituting this software is installed in an information processing apparatus (computer). Further, these programs may be recorded on a removable medium such as a CD-ROM and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a web service via a network without being downloaded.
Description of Reference Numerals
[0049] 1 Secure computing system 10 User terminal 11 Terminal secret key holding unit 12 Encryption unit 13 Terminal partial decryption unit 14 Computation result output unit 20 Computation server 21 Operator secret key holding unit 22 Homomorphic computation unit 23 Operator partial decryption unit
Claims
1. A system including a plurality of user terminals divided into two or more groups and a processing server, The plurality of user terminals include A fully homomorphic encryption method in which a ciphertext encrypted with a public key can be decrypted only by combining all partially decrypted texts obtained by partially decrypting the ciphertext with different private keys in the group, the method comprising: a terminal private key holding unit that shares the private key within the group; an encryption unit that encrypts its own input data with the public key and transmits the encrypted data to the processing server; Among the plurality of user terminals, a representative terminal in each of the groups is A terminal partial decryption unit that, upon receiving a ciphertext of a calculation result from the calculation server, decrypts the ciphertext into a partially decrypted text using the private key and transmits the partially decrypted text to any one of the plurality of user terminals, Any one of the plurality of user terminals, a computation result output unit that outputs a computation result obtained by integrating all the partially decrypted texts when all the partially decrypted texts are received; The computing server includes: A secure computing system comprising a homomorphic computing unit that performs a predetermined computation in an encrypted state on encrypted input data received from the plurality of user terminals using a computation key, and transmits the resulting ciphertext to at least the representative terminal among the plurality of user terminals.
2. A system including a plurality of user terminals divided into one or more groups and a processing server, The plurality of user terminals include A fully homomorphic encryption method in which a ciphertext encrypted with a public key can be decrypted only by integrating all of the partially decrypted texts obtained by partially decrypting the ciphertext with different private keys in each of the groups and the processing server, the method comprising: a terminal private key holding unit that shares the private key within the group; an encryption unit that encrypts its own input data with the public key and transmits the encrypted data to the processing server; Among the plurality of user terminals, a representative terminal in each of the groups is A terminal partial decryption unit that, upon receiving a ciphertext of a calculation result from the calculation server, decrypts the ciphertext into a partially decrypted text using the private key and transmits the partially decrypted text to any one of the plurality of user terminals, Any one of the plurality of user terminals, a computation result output unit that outputs a computation result obtained by integrating all the partially decrypted texts when all the partially decrypted texts are received; The computing server includes: A private key storage unit for storing a private key of the operator; a homomorphic arithmetic unit that performs a predetermined arithmetic operation on the encrypted input data received from the plurality of user terminals using an arithmetic key in an encrypted state, and transmits a ciphertext of the arithmetic operation result to at least the representative terminal of the plurality of user terminals; a partial decryption unit that decrypts the ciphertext of the computation result into a partially decrypted text using its own private key and transmits the partially decrypted text to one of the multiple user terminals.
3. one or more data providing terminals that do not hold the private key and encrypt their own input data with the public key and transmit the encrypted data to the computing server; 3. The secure computing system according to claim 1, wherein the homomorphic computing unit executes the predetermined computation on encrypted input data received from the plurality of user terminals and the data providing terminal.
4. In a fully homomorphic encryption method in which a ciphertext encrypted with a public key can be decrypted by integrating all of the partially decrypted texts obtained by partially decrypting the ciphertext with different private keys in each group, the method comprising: a terminal private key holding unit that shares the private key within the group; an encryption unit that encrypts its own input data with the public key and transmits the encrypted data to a processing server; a terminal partial decryption unit that, when receiving a ciphertext from the operation server, decrypts the ciphertext, which is a result of a predetermined operation performed in an encrypted state on encrypted input data received from a plurality of terminals by the operation server using an operation key, into a partially decrypted text using the private key; a calculation result output unit that, when receiving all the partially decrypted texts from each of the groups, outputs a calculation result obtained by integrating all the partially decrypted texts.
5. A computation server having a homomorphic computation unit that, when it receives input data from a plurality of user terminals assigned to two or more groups, the input data being encrypted using a public key in a fully homomorphic encryption method that can only be decrypted by combining all of the partial decrypted texts that have been partially decrypted using different private keys in each of the groups, performs a predetermined computation on the encrypted input data in an encrypted state using a computation key, and transmits the resulting ciphertext to at least a representative terminal of each of the user terminals in the group for partial decryption.
6. a fully homomorphic encryption method in which a partially decrypted text can be decrypted only by integrating all of the partially decrypted texts obtained by partially decrypting the texts using a plurality of mutually different private keys; a homomorphic arithmetic unit that, when receiving input data for each of the multiple user terminals encrypted with a public key in the fully homomorphic encryption scheme from a multiple user terminals assigned to one or more groups sharing any of the multiple private keys, executes a predetermined operation on the encrypted input data in an encrypted state using an operation key, and transmits a ciphertext resulting from the operation to at least a representative terminal of each of the user terminals in the group for partial decryption; a partial decryption unit that decrypts the ciphertext of the computation result into a partially decrypted text using its own private key and transmits the partially decrypted text to any one of the plurality of user terminals.
7. A program for causing a computer to function as the user terminal according to claim 4.
8. A program for causing a computer to function as the processing server according to claim 5 or 6.