Secret calculation device, secret calculation system, secret calculation method, and secret calculation program
The secure computing device and system address the limitations of existing homomorphic encryption methods by using multiple encryption methods and ciphertext conversion, enabling secure and confidential computations on encrypted data without decrypting intermediate results.
Patent Information
- Application Number
- JP2023197402
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-21
- Publication Date
- 2025-06-02
AI Technical Summary
Existing homomorphic encryption methods have limited types of secure operations, necessitating decryption of intermediate results for certain computational processes, which compromises data confidentiality.
A secure computing device and system that employs a first and second homomorphic encryption method, along with a ciphertext conversion method, to perform secure computations on encrypted data without decrypting intermediate results, thereby enhancing data confidentiality.
The proposed solution enables secure performance of complex computational processes on encrypted data, maintaining data confidentiality by avoiding the need for decryption of intermediate results.
Smart Images

Figure 2025083807000001_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to a secure computing device, a secure computing system, a secure computing method, and a secure computing program.
Background Art
[0002] In recent years, the utilization of data including confidential information such as personal information has been expanding in various fields. When utilizing data among multiple organizations, risks such as information leakage, unauthorized use, and theft are a concern. For this reason, technologies for analyzing confidential information while keeping it encrypted have attracted attention.
[0003] For example, a technique for performing encryption using a homomorphic encryption method based on Ring-LWE (Learning-with-errors) has been disclosed (see, for example, Patent Document 1 and Non-Patent Documents 1 to 3). However, in the prior art, since the types of secure operations that can be realized in many homomorphic encryption methods are limited, not all of a certain computational process can be securely computed, and it may be necessary to decrypt intermediate results and proceed with the computation in the plaintext state, which may reduce the confidentiality of the data.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Non-Patent Documents
[0005]
Non-Patent Document 1
[0006] The problem to be solved by the present invention is to provide a secure computing device, a secure computing system, a secure computing method, and a secure computing program capable of improving data confidentiality. [Means for Solving the Problems]
[0007] The secure computing device according to the embodiment includes a first secure computing processing unit, a ciphertext conversion processing unit, and a second secure computing processing unit. The first secure computing processing unit calculates a second ciphertext by performing first secure computing processing using a first homomorphic operation according to the first homomorphic encryption method on a first ciphertext obtained by encrypting input data using the first homomorphic encryption method. The ciphertext conversion processing unit converts the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption method using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method without decrypting the second ciphertext. The second secure computing processing unit calculates a fourth ciphertext by performing second secure computing processing using a second homomorphic operation according to the second homomorphic encryption method on the third ciphertext.
Brief Description of Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Best Mode for Carrying Out the Invention
[0009] With reference to the accompanying drawings below, a secure computing device, a secure computing system, a secure computing method, and a secure computing program will be described in detail. In the following embodiments and modifications, the same functional parts may be given the same reference numerals, and detailed descriptions may be omitted.
[0010] (First Embodiment) FIG. 1 is a schematic diagram of an example of the secure computing system 100 of this embodiment.
[0011] The secure computing system 100 includes a first terminal device 1 and a secure computing device 4. The first terminal device 1 and the secure computing device 4 are communicably connected via a network 5.
[0012] The secure computing system 100 may have a configuration including one or more first terminal devices 1, and is not limited to a configuration including one first terminal device 1. Also, the secure computing system 100 may have a configuration including one or more secure computing devices 4, and is not limited to a configuration including one secure computing device 4.
[0013] The first terminal device 1 and the secure computing device 4 are computers that execute various information processes. In this embodiment, the first terminal device 1 executes processes such as generation of an encryption key, encryption of input data, and decryption of the ciphertext generated by the secure computing device 4. The secure computing device 4 executes processes such as a first secure computing process and a second secure computing process on the received ciphertext without decrypting the ciphertext, and outputs the processed ciphertext to the first terminal device 1.
[0014] The network 5 is a wide area network such as the Internet, for example.
[0015] Input data refers to the data to be processed and includes information to be concealed such as confidential information. Confidential information includes, for example, but is not limited to, personal information, etc. Input data includes, for example, in the medical and health fields, health examination data, receipt data, genomic data, etc. held by medical institutions, research institutions, or enterprises.
[0016] The first confidential calculation process is a confidential calculation process using a first homomorphic operation by the first homomorphic encryption method on the ciphertext obtained by encrypting the input data using the first homomorphic encryption method. The first confidential calculation process includes an inner product or sum calculation process. For example, the first confidential calculation process is at least one inner product or sum calculation process for a vector.
[0017] The second confidential calculation process is a second confidential calculation process using a second homomorphic operation by the second homomorphic encryption method on the ciphertext. The second confidential calculation process includes addition, multiplication, or identity operation processing. For example, the second confidential calculation process is at least one addition or multiplication for a scalar value.
[0018] A homomorphic encryption method is an encryption technology used for confidential calculations. When two ciphertexts obtained by encrypting two plaintexts respectively are given, it is a calculation method that can calculate the ciphertext of the result of a binary operation on the plaintext without decrypting the ciphertext. Binary operations include, for example, addition, multiplication, etc. From a practical perspective, homomorphic encryption with homomorphic properties regarding a finite number of additions and multiplications may be used. As an example of such homomorphic encryption, for example, there is a homomorphic encryption method using Ring-LWE (Learning-with-errors). The homomorphic encryption method using Ring-LWE can encrypt polynomials and is a homomorphic encryption that can utilize homomorphic multiplication and homomorphic addition regarding polynomials. In addition, there are also Module-LWE, etc. in the homomorphic encryption method. Module-LWE is a homomorphic encryption method that generalizes the homomorphic encryption method using Ring-LWE.
[0019] The second homomorphic encryption method may be any homomorphic encryption method different from the first homomorphic encryption method. The second homomorphic operation may be any homomorphic operation different from the first homomorphic operation. The first homomorphic operation and the second homomorphic operation are operations including at least one multiplication and addition.
[0020] In this embodiment, as an example, a form will be described in which the first homomorphic encryption method is a homomorphic encryption method using Ring-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE.
[0021] Also, in this embodiment, as an example, a form will be described in which the input data includes two polynomials, and each coefficient of these polynomials is an element of a vector.
[0022] Also, in this embodiment, as an example, a form will be described in which the inner product of two vectors is calculated as the first secure calculation process, and the square calculation of the inner product result is calculated as the second secure calculation process.
[0023] Note that this embodiment is the most basic embodiment for explaining the basic concept in this application.
[0024] <Explanation of Secure Calculation Process Content> First, the content of each secure calculation process of the first secure calculation process and the second secure calculation process in this embodiment will be described.
[0025] In the secure calculation device 4 of this embodiment, as the first secure calculation process, the inner product of a first vector u = (u 0 , u 1 , …, u l-1 ) of length l and a second vector v = (v 0 , v 1 , …, v l-1 ) of length l is calculated, and a first scalar value s1 = <u, v> is output. Note that the symbol <u, v> is a symbol representing the inner product of u and v, and <u, v> = u 0 v 0 + u 1 v 1 + … + u l-1 v l-1That is. Also, in the secure computing device 4, as the second secure computing process, the square calculation of the first scalar value s1 is calculated, and the second scalar value s2 = s1 2 is output. In the secure computing device 4 of the present embodiment, for each of these first secure computing process and second secure computing process, the data input thereto is calculated in a state where it is encrypted, that is, in a state of being a ciphertext as it is.
[0026] Note that the first secure computing process and the second secure computing process are examples of convenient computing processes for explaining the concept of the present application, and more general computing processes can also be used for these secure computing processes.
[0027] Specifically, as the first secure computing process, a computing process that takes at least one vector as an input and outputs at least one scalar value may be used. Also, as the second secure computing process, a computing process that takes at least one scalar value, which is the output data of the first secure computing process, as an input and outputs at least one scalar value may be used.
[0028] <Explanation of the somewhat homomorphic encryption method and the ciphertext conversion method> In the secure computing device 4 of the present embodiment, in order to perform data input / output between the first secure computing process and the second secure computing process while keeping the data encrypted, the ciphertext is converted using a ciphertext conversion method defined between the first somewhat homomorphic encryption method and the second somewhat homomorphic encryption method.
[0029] In the secure computing device 4, a second ciphertext is calculated by the first secure computing process using the first somewhat homomorphic operation according to the first somewhat homomorphic encryption method on the first ciphertext obtained by encrypting the input data using the first somewhat homomorphic encryption method. Then, using the ciphertext conversion method defined between the first somewhat homomorphic encryption method and the second somewhat homomorphic encryption method, the second ciphertext is converted into a third ciphertext encrypted by the second somewhat homomorphic encryption method without decrypting the second ciphertext. Further, a fourth ciphertext is calculated by the second secure computing process using the second somewhat homomorphic operation according to the second somewhat homomorphic encryption method on the third ciphertext.
[0030] For example, the first homomorphic encryption method is a homomorphic encryption method using Ring-LWE or a homomorphic encryption method using Module-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE or LWE that does not depend on the ring dimension of the first homomorphic encryption method. In this case, the ciphertext conversion method is a ciphertext conversion method between a second ciphertext encrypted by the first homomorphic encryption method using Ring-LWE or Module-LWE and a third ciphertext encrypted by the second homomorphic encryption method using LWE or LWE that does not depend on the ring dimension of the first homomorphic encryption method.
[0031] In the ciphertext conversion using the ciphertext conversion method, by extracting a part of the numerical values constituting the second ciphertext of the polynomial, the second ciphertext is converted into a third ciphertext in which the plaintext represented by the scalar value of the constant term of the polynomial is encrypted without decrypting the second ciphertext.
[0032] In the ciphertext conversion using the ciphertext conversion method for converting to the second homomorphic encryption method using LWE that does not depend on the ring dimension of the first homomorphic encryption method, in addition to the process of extracting a part of the numerical values constituting the second ciphertext, by performing a calculation process using the encryption key and the conversion key, the second ciphertext is converted into a third ciphertext in which the plaintext represented by the scalar value of the constant term of the polynomial is encrypted without decrypting the second ciphertext.
[0033] As described above, in this embodiment, a form in which the first homomorphic encryption method is a homomorphic encryption method using Ring-LWE and the second homomorphic encryption method is a homomorphic encryption method using LWE will be described as an example. Therefore, in this embodiment, as an example of the ciphertext conversion method, a form will be described in which a ciphertext conversion method between a second ciphertext encrypted by the first homomorphic encryption method using Ring-LWE and a third ciphertext encrypted by the second homomorphic encryption method using LWE is used.
[0034] The homomorphic encryption method using Ring-LWE has a parameter n representing the dimension of the polynomial ring, and an (n - 1)-th degree polynomial m can be encrypted as a plaintext.
[0035] The secret key sk used for encryption RLWE is given by an (n - 1)-degree polynomial, and the public key pk RLWE is given by a pair of two (n - 1)-degree polynomials. Therefore, the ciphertext with the (n - 1)-degree polynomial m as the plaintext is given by a pair of two (n - 1)-degree polynomials (b, a), and m = a × sk RLWE has the relation of + b.
[0036] In the homomorphic encryption scheme using Ring-LWE, at least one homomorphic multiplication and homomorphic addition regarding polynomials can be utilized. By using the method described in Non-Patent Document 2, in the homomorphic encryption scheme using Ring-LWE, by converting a vector into a polynomial in a predetermined method and encrypting it, the homomorphic multiplication functions as a homomorphic inner product operation.
[0037] Specifically, the secure computing device 4 uses the first conversion function fw and the second conversion function bw to convert two vectors u = (u 0 , u 1 , …, u l-1 ) and v = (v 0 , v 1 , …, v l-1 ) of length l <= n into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 − v 1 x n―1 − v 2 x n―2 − … − v l―1 x n-(l―1) respectively. fw(u) is a polynomial that assigns the elements u 0 , u 1 , …, u l-1 of the vector in ascending order from the coefficient of degree 0. Also, bw(v) assigns the element v 0 of the vector to the coefficient of degree 0, and assigns the values obtained by inverting the signs of the elements v 1 , v 2 , …, v l―1 of the vector in descending order from the coefficient of degree n - 1.
[0038] If the above polynomial is encrypted, as shown in the following formula (1), the homomorphic multiplication EvalMult RLWE can be defined as a homomorphic inner product operation.
[0039] EvalMult RLWE (Enc RLWE (fw(u)), Enc RLWE (bw(v)))= Enc RLWE (<u, v> + r 1 x + r 2 x 2 +…+ x n-1 x n-1 ) ··· Formula (1)
[0040] The Enc described in Formula (1) RLWE is an encryption function used in a homomorphic encryption method using Ring-LWE, and r i is a scalar value.
[0041] In a homomorphic encryption method using LWE, a parameter d representing the vector dimension number is used, and a scalar value m can be encrypted as a plaintext.
[0042] The secret key sk LWE is given by a d-dimensional vector, and the public key pk LWE is given by a pair of a scalar and a d-dimensional vector. The ciphertext with the scalar value m as the plaintext is given by a pair (b, a) of a d-dimensional vector a and a scalar b, and has the relationship m = <a, sk LWE > + b.
[0043] In a homomorphic encryption method using LWE, at least one homomorphic multiplication and homomorphic addition for scalar values can be used. According to Non-Patent Document 3, the ciphertext of the (n - 1)-th degree polynomial m = m 0 + m 1 x + … + m n-1 x n-1 encrypted by a homomorphic encryption method using Ring-LWE can be converted into the ciphertext of the constant term m 0 encrypted by a homomorphic encryption method using LWE with the vector dimension number d = n without decrypting the ciphertext.
[0044] Let the ciphertext of the above polynomial \(m\) be \(Enc\) RLWE (m)=(b,a 0 ) where \(a\) 0 =a 0,0 +a 0,1 x+\cdots +a 0,n-1 x n-1 In this case, for the homomorphic encryption scheme using LWE with the vector dimension \(d = n\), the ciphertext of the constant term \(m\) 0 of the polynomial \(m\) encrypted by the homomorphic encryption scheme using LWE can be calculated by the ciphertext conversion \(Extract\) RLWEtoLWE described in the following formula (2).
[0045] Enc LWE (m 0 )=Extract RLWEtoLWE (Enc RLWE (m))=(b 0 ,a 0 ,-a n-1 ,-a n-2 \cdots,-a 1 ) \cdots Formula (2)
[0046] For the ciphertext encrypted by the homomorphic encryption scheme using LWE, when the secret key in Ring-LWE homomorphic encryption is \(sk\) RLWE =sk 0 +sk 1 x+\cdots +sk n-1 x n-1 and the secret key of LWE homomorphic encryption is \(sk\) LWE =(sk 0 ,sk 1 ,\cdots,sk n-1 ), the ciphertext described in formula (2) can be decrypted.
[0047] Note that these first-level homomorphic encryption methods and second-level homomorphic encryption methods are just examples. As the first-level homomorphic encryption method, a homomorphic encryption method that can encrypt the plaintext of a polynomial and define homomorphic operations related to polynomial multiplication and polynomial addition may be used. However, the polynomial is a polynomial whose coefficients are elements of a vector. Also, as the second-level homomorphic encryption method, a homomorphic encryption method that can encrypt scalar values, can utilize homomorphic multiplication and homomorphic multiplication, and furthermore, can define ciphertext conversion with the first-level homomorphic encryption method may be used.
[0048] <Explanation of the Secret Computation Method> In the secret computing device 4 according to this embodiment, the first secret computing process and the second secret computing process are secretly computed in the following procedure using the first-level homomorphic encryption method, the second-level homomorphic encryption method, and ciphertext conversion.
[0049] As preparation for the homomorphic encryption, in the first terminal device 1, the secret key sk RLWE and the public key pk RLWE of the first-level homomorphic encryption method are generated. Also, when the secret key used in the first-level homomorphic encryption method is sk RLWE =sk 0 +sk 1 x+…+sk n-1 x n-1 , the secret key of the second-level homomorphic encryption method is sk LWE =(sk 0 ,sk 1 ,…,sk n-1 ). At this time, sk LWE is a vector of length n whose elements are the coefficients of the (n - 1)-th degree polynomial of sk RLWE in order from the 0-th degree coefficient. The public key pk RLWE used in the first-level homomorphic encryption method is used as the first encryption key, and the secret key sk LWE used in the second-level homomorphic encryption method is used as the first decryption key. Note that the secret key sk RLWE used in the first-level homomorphic encryption method may also be used as the first encryption key.
[0050] In the first terminal device 1, using the first-level homomorphic encryption method, the first vector u of length l that is the input of the first secret computing process u=(u 0 ,u1 ,…,u l-1 ) and the second vector v = (v 0 , v 1 ,…,v l-1 ) are respectively converted by the first conversion function fw and the second conversion function bw into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 − v 1 x n―1 − v 2 x n―2 − … − v l―1 x n-(l―1) . Note that during the conversion, fw(v) and bw(u) may also be used. And in the first terminal device 1, the polynomials are respectively encrypted using the first encryption key pk RLWE to generate two first ciphertexts ct u , ct v . That is, the first ciphertext is a ciphertext obtained by encrypting a plaintext including a vector.
[0051] In the secure computing device 4, the first ciphertexts ct u , ct v encrypted by the first homomorphic encryption method are subjected to a first secure computing process using the homomorphic multiplication EvalMult RLWE to calculate a second ciphertext ct s1+ = EvalMult RLWE (ct u , ct v ) of a polynomial having the first scalar value s1 = <u, v> as a constant term. That is, the second ciphertext is a ciphertext obtained by encrypting a plaintext including a scalar value. The homomorphic multiplication EvalMult RLWE functions as a homomorphic inner product operation available in the first homomorphic encryption method. The second ciphertext is a ciphertext encrypted by the first homomorphic encryption method.
[0052] And in the secure computing device 4, without decrypting the second ciphertext ct s1+ which is the output data of the first secure computing process, using the ciphertext conversion Extract RLWEtoLWE , a third ciphertext ct s1 of the first scalar value s1 is obtained.=Extract RLWEtoLWE (ct s1+ ) is converted. That is, the third ciphertext is a ciphertext obtained by encrypting the plaintext of the scalar value. Specifically, the third ciphertext is a ciphertext encrypted using the second homomorphic encryption method.
[0053] Furthermore, in the confidentiality calculation device 4, the third ciphertext ct s1 encrypted using the second homomorphic encryption method is LWE subjected to the second confidentiality calculation process using the homomorphic multiplication EvalMult 2 to calculate the fourth ciphertext ct s2 =EvalMult LWE (ct s1 , ct s1 ). That is, the fourth ciphertext is a ciphertext obtained by encrypting the plaintext of the scalar value. In other words, the fourth ciphertext is a ciphertext encrypted using the second homomorphic encryption method. The homomorphic multiplication EvalMult LWE is a homomorphic multiplication available in the second homomorphic encryption method.
[0054] In the first terminal device 1, the fourth ciphertext ct s2 of the second scalar value s2 is LWE decrypted using the first decryption key sk
[0055] <Description of System Configuration and Functions> Next, the confidentiality calculation system 100 of this embodiment will be specifically described.
[0056] FIG. 2 is a functional block diagram of an example of the first terminal device 1 of this embodiment.
[0057] The first terminal device 1 includes a key generation processing unit 11, an encryption key storage unit 12, a decryption key storage unit 13, an input unit 21, a first data storage unit 22, an encryption processing unit 23, a second data storage unit 24, a transmission unit 25, a reception unit 31, a third data storage unit 32, a decryption processing unit 33, a fourth data storage unit 34, and an output unit 35.
[0058] The key generation processing unit 11, the input unit 21, the encryption processing unit 23, the transmission unit 25, the reception unit 31, the decryption processing unit 33, and the output unit 35 are realized by, for example, one or more processors. For example, each of the above units may be realized by causing a processor such as a CPU (Central Processing Unit) to execute a program, that is, by software. Each of the above units may be realized by a processor such as a dedicated IC, that is, by hardware. Each of the above units may be realized by using a combination of software and hardware. When using a plurality of processors, each processor may realize one of the units, or may realize two or more of the units.
[0059] Note that each of these units may be realized by, for example, one or more CPUs, microprocessors, GPUs (Graphics Processing Units), ASICs (Application Specific Integrated Circuits), FPGAs (Field-Programmable Gate Arrays), or other processing circuits, or an electronic circuit including these circuits.
[0060] The key generation processing unit 11 generates an encryption key of the first homomorphic encryption method and a decryption key of the second homomorphic encryption method. In the present embodiment, the key generation processing unit 11 generates a public key pk RLWE used in the first homomorphic encryption method as an encryption key (first encryption key), and generates a secret key sk RLWE as a decryption key.
[0061] When the secret key used in the first homomorphic encryption method is sk RLWE =sk 0 +sk 1 x+…+sk n-1 x n-1 and the secret key of the second homomorphic encryption method is sk LWE =(sk 0 ,sk 1 ,…,sk n-1 ). That is, in the present embodiment, the public key pk RLWE used in the first homomorphic encryption method is used as the first encryption key, and the secret key sk used in the second homomorphic encryption methodLWE is used as the first decryption key. Note that the secret key sk used in the first homomorphic encryption scheme RLWE may be used as the first encryption key.
[0062] The key generation processing unit 11 stores the generated first encryption key in the encryption key storage unit 12 and stores the first decryption key in the decryption key storage unit 13.
[0063] The input unit 21 acquires input data used for the first confidential calculation process from a computer or the like connected to the first terminal device 1. In this embodiment, the input unit 21 uses, as the input data, the first vector u = (u 0 , u 1 , …, u l-1 ) and the second vector v = (v 0 , v 1 , …, v l-1 ). The encryption key storage unit 12 stores the acquired first vector u and second vector v in the first data storage unit 22.
[0064] The encryption processing unit 23 calculates a first ciphertext obtained by encrypting the input data using the encryption key. Specifically, the encryption processing unit 23 uses the first conversion function fw and the second conversion function bw to convert the first vector u and the second vector v stored in the first data storage unit 22 into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 − v 1 x n―1 − v 2 x n―2 − … − v l―1 x n-(l―1) respectively. Then, the encryption processing unit 23 encrypts these polynomials using the first encryption key pk RLWE stored in the encryption key storage unit 12 and calculates the first ciphertext ct u , ct v encrypted by the first homomorphic encryption scheme. The encryption processing unit 23 stores the first ciphertext in the second data storage unit 24.
[0065] The transmission unit 25 transmits the first ciphertext ct u and ct v stored in the second data storage unit 24 to the secure computing device 4.
[0066] The receiving unit 31 receives the fourth ciphertext ct s2 of the second scalar value, which is the data output by the second secure computing process and encrypted using the second homomorphic encryption method, from the secure computing device 4. The receiving unit 31 stores the received fourth ciphertext in the third data storage unit 32.
[0067] The decryption processing unit 33 calculates the output data obtained by decrypting the fourth ciphertext stored in the third data storage unit 32 using the decryption key. Specifically, the decryption processing unit 33 decrypts the fourth ciphertext using the first decryption key sk LWE stored in the decryption key storage unit 13 and calculates the second scalar value s2. The decryption processing unit 33 stores the second scalar value s2 in the fourth data storage unit 34.
[0068] The output unit 35 outputs the second scalar value s2 stored in the fourth data storage unit 34 to an external device such as a computer connected to the first terminal device 1.
[0069] Note that the input unit 21 may obtain the above polynomials fw(u) and bw(v) from a computer or the like connected to the first terminal device 1 and store the polynomials in the first data storage unit 22. Further, the encryption processing unit 23 may encrypt the polynomials stored in the first data storage unit 22 using the first encryption key pk RLWE stored in the encryption key storage unit 12. Then, the encryption processing unit 23 may calculate the first ciphertext ct u and ct v encrypted by the first homomorphic encryption method by this encryption and store them in the second data storage unit 24.
[0070] FIG. 3 is a functional block diagram of an example of the secure computing device 4 of the present embodiment.
[0071] The confidential computing device 4 includes a receiving unit 41, a first data storage unit 42, a first confidential computing processing unit 43, a second data storage unit 44, a ciphertext conversion processing unit 45, a third data storage unit 46, a second confidential computing processing unit 47, a fourth data storage unit 48, and a transmitting unit 49.
[0072] The receiving unit 41, the first confidential computing processing unit 43, the ciphertext conversion processing unit 45, the second confidential computing processing unit 47, and the transmitting unit 49 are realized by, for example, one or more processors. For example, each of the above units may be realized by causing a processor such as a CPU to execute a program, that is, by software. Each of the above units may be realized by a processor such as a dedicated IC, that is, by hardware. Each of the above units may be realized by using a combination of software and hardware. When using a plurality of processors, each processor may realize one of the units or two or more of the units.
[0073] Note that each of these units may be realized by, for example, one or more CPUs, microprocessors, GPUs, ASIs, FPGs, or other processing circuits, or electronic circuits including these circuits.
[0074] The receiving unit 41 receives the first ciphertext ct u , ct v from the first terminal device 1 and stores it in the first data storage unit 42.
[0075] The first confidential computing processing unit 43 encrypts the input data using the first homomorphic encryption method to obtain the first ciphertext ct u , ct vA second ciphertext is calculated by means of a first secure calculation process using a first homomorphic operation according to a first homomorphic encryption method with respect to [[ID=]]. Specifically, the first secure calculation unit 43 calculates a second ciphertext obtained by encrypting a plaintext including a scalar value by means of the first secure calculation process with respect to a first ciphertext obtained by encrypting a plaintext including a vector. More specifically, the first secure calculation unit 43 performs a first secure calculation process using a first homomorphic operation which is a homomorphic inner product operation according to the first homomorphic encryption method with respect to two first ciphertexts each obtained by encrypting each of two polynomials whose coefficients are elements of a vector included in input data, and calculates a second ciphertext of a plaintext of a polynomial in which a scalar value of an inner product result is stored in a constant term.
[0076] In the present embodiment, the first secure calculation unit 43 performs a first secure calculation process on the first ciphertexts ct u , ct v using a homomorphic multiplication EvalMult RLWE . The first secure calculation unit 43 calculates a second ciphertext ct s1+ encrypted using the first homomorphic encryption method by means of this first secure calculation process. The second ciphertext ct s1+ is a ciphertext ct s1+ of a polynomial having the first scalar value s1 as a constant term. The first secure calculation unit 43 stores the second ciphertext s1+ in the second data storage unit 44.
[0077] The ciphertext conversion unit 45 converts the second ciphertext into a third ciphertext encrypted by a second homomorphic encryption method without decrypting the second ciphertext, using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method. Specifically, the ciphertext conversion unit 45 converts the second ciphertext into a third ciphertext obtained by encrypting a plaintext of a scalar value by means of the second homomorphic encryption method. More specifically, the ciphertext conversion unit 45 converts the second ciphertext into a third ciphertext obtained by encrypting a scalar value of a constant term of a polynomial encrypted by the second homomorphic encryption method without decrypting the second ciphertext.
[0078] Specifically, the ciphertext conversion processing unit 45 converts the second ciphertext ct stored in the second data storage unit 44 into a third ciphertext ct of the first scalar value s1 encrypted by the second homomorphic encryption method without decrypting it, using the ciphertext conversion Extract RLWEtoLWE . Then, the ciphertext conversion processing unit 45 stores the third ciphertext ct s1 in the third data storage unit 46. s1+ without decrypting it, using the ciphertext conversion Extract RLWEtoLWE into a third ciphertext ct of the first scalar value s1 encrypted by the second homomorphic encryption method s1 Then, the ciphertext conversion processing unit 45 stores the third ciphertext ct s1 in the third data storage unit 46.
[0079] The second secure calculation processing unit 47 calculates a fourth ciphertext by performing second secure calculation processing using a second homomorphic operation based on the second homomorphic encryption method on the third ciphertext. Specifically, the second secure calculation processing unit 47 calculates a fourth ciphertext in which the plaintext of the scalar value is encrypted by performing second secure calculation processing on the third ciphertext. More specifically, the second secure calculation processing unit 47 calculates the fourth ciphertext by performing second secure calculation processing using a second homomorphic operation including at least one homomorphic multiplication and homomorphic addition on the third ciphertext.
[0080] Specifically, the second secure calculation processing unit 47 performs second secure calculation processing using the homomorphic multiplication EvalMult LWE on the ciphertext ct s1 stored in the third data storage unit 46 to calculate the fourth ciphertext ct s2 . The fourth ciphertext ct s2 is a ciphertext obtained by performing second secure calculation processing using the second homomorphic encryption method and is a ciphertext of the second scalar value s2. s1 using the homomorphic multiplication EvalMult LWE to calculate the fourth ciphertext ct s2 The fourth ciphertext ct s2 is a ciphertext obtained by performing second secure calculation processing using the second homomorphic encryption method and is a ciphertext of the second scalar value s2.
[0081] The second secure calculation processing unit 47 stores the fourth ciphertext ct s2 in the fourth data storage unit 48.
[0082] The transmission unit 49 transmits the fourth ciphertext ct s2 stored in the fourth data storage unit 48 to the first terminal device 1. s2 to the first terminal device 1.
[0083] <Description of the flow> Next, an example of the flow of information processing executed by the first terminal device 1 and the secure calculation device 4 of the present embodiment will be described.
[0084] FIG. 4 is a flowchart showing an example of the flow of information processing executed by the first terminal device 1 and the confidential computing device 4 of the present embodiment.
[0085] The key generation processing unit 11 of the first terminal device 1 generates a public key pk RLWE used in the first homomorphic encryption method as the first encryption key. Further, the key generation processing unit 11 generates a secret key sk RLWE used in the first homomorphic encryption method, and generates a secret key sk RLWE used in the second homomorphic encryption method from the secret key sk LWE as the first decryption key (step S1).
[0086] As described above, the key generation processing unit 11 may use the secret key sk RLWE used in the first homomorphic encryption method as the first encryption key. The key generation processing unit 11 stores the first encryption key generated in step S1 in the encryption key storage unit 12, and stores the first decryption key in the decryption key storage unit 13.
[0087] The input unit 21 of the first terminal device 1 obtains input data including a first vector u = (u 0 , u 1 , …, u l-1 ) and a second vector v = (v 0 , v 1 , …, v l-1 ) from a computer or the like communicably connected to the first terminal device 1 (step S2). The input unit 21 stores the input data including the acquired first vector and second vector in the first data storage unit 22.
[0088] The encryption processing unit 23 of the first terminal device 1 converts the first vector u and the second vector v, which are the input data stored in the first data storage unit 22, into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 and bw(v) = v 0 − v 1 x n―1-v 2 x n―2 -…-v l―1 x n-(l―1) Convert it to. Then, the encryption processing unit 23 uses the first encryption key pk RLWE Stored in the encryption key storage unit 12 to encrypt these polynomials, and calculates the first ciphertext ct u , ct v (Step S3). The encryption processing unit 23 stores the calculated first ciphertext in the second data storage unit 24.
[0089] The transmission unit 25 of the first terminal device 1 transmits the first ciphertext ct u , ct v to the secure computing device 4 (Step S4).
[0090] The receiving unit 41 of the secure computing device 4 receives the first ciphertext ct u , ct v from the first terminal device 1 and stores the first ciphertext in the first data storage unit 42 (Step S5).
[0091] The first secure computing processing unit 43 of the secure computing device 4 performs secure computing on the first ciphertext ct u , ct v stored in the first data storage unit 42 by the first secure computing process using the homomorphic multiplication EvalMult RLWE and calculates the second ciphertext ct s1+ (Step S6). The first secure computing processing unit 43 stores the second ciphertext in the second data storage unit 44.
[0092] The ciphertext conversion processing unit 45 of the secure computing device 4 converts the second ciphertext ct s1+ stored in the second data storage unit 44 into the third ciphertext ct RLWEtoLWE of the first scalar value s1 without decrypting it using the ciphertext conversion Extract s1 (Step S7). The ciphertext conversion processing unit 45 stores the third ciphertext in the third data storage unit 46.
[0093] The second secure computing unit 47 of the secure computing device 4 takes the third ciphertext ct stored in the third data storage unit 46 s1 and performs secure computing through second secure computing processing using the homomorphic multiplication EvalMult LWE to calculate the fourth ciphertext ct of the second scalar value s2 s2 (step S8). The second secure computing unit 47 stores the fourth ciphertext in the fourth data storage unit.
[0094] The fourth data storage unit 48 of the secure computing device 4 transmits the fourth ciphertext ct stored in the fourth data storage unit 34 s2 to the first terminal device 1 (step S9).
[0095] The receiving unit 31 of the first terminal device 1 receives the fourth ciphertext ct s2 from the secure computing device 4 and stores it in the third data storage unit 32 (step S10).
[0096] The decryption processing unit 33 of the first terminal device 1 decrypts the fourth ciphertext stored in the third data storage unit 32 using the first decryption key sk LWE stored in the decryption key storage unit 13 to calculate the second scalar value s2 (step S11). The decryption processing unit 33 stores the second scalar value in the fourth data storage unit 34.
[0097] The output unit 35 of the first terminal device 1 outputs the second scalar value s2 stored in the fourth data storage unit 34 to a computer or the like connected to the first terminal device 1. Then, this routine ends.
[0098] As described above, the secret calculation device 4 of the present embodiment includes a first secret calculation processing unit 43, a ciphertext conversion processing unit 45, and a second secret calculation processing unit 47. The first secret calculation processing unit 43 calculates a second ciphertext by performing a first secret calculation process using a first homomorphic operation according to a first homomorphic encryption method on a first ciphertext obtained by encrypting input data using the first homomorphic encryption method. The ciphertext conversion processing unit 45 converts the second ciphertext into a third ciphertext encrypted by a second homomorphic encryption method using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method without decrypting the second ciphertext. The second secret calculation processing unit 47 calculates a fourth ciphertext by performing a second secret calculation process using a second homomorphic operation according to the second homomorphic encryption method on the third ciphertext.
[0099] Here, in the prior art, since the types of secret operations that can be realized in many homomorphic encryption methods are limited, not all of a certain calculation process can be performed as a secret calculation, and it may be necessary to decrypt intermediate results and proceed with the calculation in plaintext, which may reduce the secrecy of the data.
[0100] Specifically, as an example of the application destination of homomorphic encryption, genome-wide association study (GWAS), which is one of the statistical analysis methods for genomic data and the like, can be mentioned. Genomic data is utilized for disease risk prediction and drug discovery. GWAS is used to clarify the presence or absence of a relationship between SNP data and trait data by performing statistical analysis on single nucleotide polymorphism (SNP) data of multiple individuals and trait data representing the presence or absence of a certain disease, and to identify the genetic factors of the disease. If homomorphic encryption is applied to GWAS, SNP data and trait data can be analyzed while keeping them secret, and information leakage and the like can be prevented. For example, a method of applying a homomorphic encryption method using Ring-LWE to GWAS is described in Non-Patent Document 1.
[0101] In the genomic data analysis of GWAS described in Non-Patent Document 1, since the process of calculating the inner product for vectors is included, a homomorphic encryption method using Ring-LWE that enables homomorphic inner product operations is utilized. According to Non-Patent Document 2, in the homomorphic encryption method using Ring-LWE, by regarding a vector as a polynomial and encrypting it, homomorphic multiplication can be utilized as a homomorphic inner product operation. Specifically, from the ciphertexts encrypted after converting two vectors into polynomials in a predetermined method, a ciphertext of a polynomial having the inner product result of the vectors as the constant term can be calculated. However, although the homomorphic encryption method using Ring-LWE utilizing the method described in Non-Patent Document 2 can efficiently execute homomorphic inner product operations, the method of executing homomorphic multiplication for the elements of the vector has not been clarified. Therefore, for example, when calculating an inner product or the like in the first secure calculation process and calculating a multiplication or the like in the second secure calculation process, decryption of the ciphertext may be required when passing the ciphertext of the result of the first secure calculation process to the second secure calculation process.
[0102] Actually, in the genomic data analysis by GWAS described in Non-Patent Document 1, since calculation processes such as the first secure calculation process and the second secure calculation process are included, the ciphertext of the inner product result corresponding to the intermediate data of GWAS has been decrypted, and it is impossible to conceal the allele frequency table or the like which is the intermediate data of GWAS. Also, when decrypting the ciphertext of the result of homomorphic inner product calculation, information may leak from terms other than the constant term, so it is necessary to perform a masking process on the ciphertext as described in Patent Document 1, which is troublesome. The above is not limited to the homomorphic encryption method using Ring-LWE, and the same can be said for, for example, the homomorphic encryption method using Module-LWE in which the homomorphic encryption method using Ring-LWE is generalized.
[0103] As described above, in the prior art, decryption of the ciphertext may be required when passing the ciphertext of the result of the first secure calculation process to the second secure calculation process, and the confidentiality may be reduced.
[0104] On the one hand, in the privacy computing device 4 of the present embodiment, the ciphertext conversion processing unit 45 uses a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method to convert the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. The second privacy computing processing unit 47 calculates a fourth ciphertext by performing second privacy computing processing using a second homomorphic operation according to the second homomorphic encryption method on the third ciphertext.
[0105] Therefore, in the privacy computing device 4 of the present embodiment, privacy computing processing can be performed without decrypting the ciphertext, and the privacy can be improved.
[0106] Therefore, the privacy computing device 4 and the privacy computing system 100 of the present embodiment can improve the privacy of data.
[0107] Note that FIG. 2 shows, as an example, a configuration in which the first terminal device 1 includes a key generation processing unit 11, an encryption key storage unit 12, a decryption key storage unit 13, an input unit 21, a first data storage unit 22, an encryption processing unit 23, a second data storage unit 24, a transmission unit 25, a reception unit 31, a third data storage unit 32, a decryption processing unit 33, a fourth data storage unit 34, and an output unit 35. However, the first terminal device 1 may have a configuration including a part of these units. For example, the first terminal device 1 may have a configuration including at least one of the key generation processing unit 11, the encryption processing unit 23, and the decryption processing unit 33.
[0108] Specifically, the first terminal device 1 may be configured not to include the key generation processing unit 11. For example, an external terminal device different from the first terminal device 1 may include the key generation processing unit 11, and the external terminal device may generate a first encryption key used in the first homomorphic encryption method and a first decryption key used in the second homomorphic encryption method. In this case, the external terminal device may transmit the generated first encryption key and first decryption key to the first terminal device 1. When the first terminal device 1 is not configured to include the encryption processing unit 23, the external terminal device may not transmit the first encryption key to the first terminal device 1. When the first terminal device 1 is not configured to include the decryption processing unit 33, the external terminal device may not transmit the first decryption key to the first terminal device 1. When the receiving unit 31 of the first terminal device 1 receives the first encryption key or the first decryption key from the external terminal device, it may store the first encryption key and the first decryption key in the encryption key storage unit 12 and the decryption key storage unit 13, respectively.
[0109] Further, the first terminal device 1 may include a key generation processing unit 11, an encryption key storage unit 12, a decryption key storage unit 13, and a transmission unit 25, and may generate a first encryption key and a first decryption key used in a terminal device different from the first terminal device 1. In this case, the transmission unit 25 of the first terminal device 1 may transmit the first encryption key to, for example, an external terminal device including the encryption processing unit 23, and transmit the first decryption key to an external terminal device including the decryption processing unit 33. After these transmission processes, the first terminal device 1 may delete the first encryption key and the first decryption key.
[0110] Also, the first terminal device 1 may be configured not to include the input unit 21. For example, an external terminal device different from the first terminal device 1 may include the input unit 21 and the first data storage unit 22. In this case, the external terminal device transmits the input data received by the input unit 21 to the first terminal device 1. When the receiving unit 31 of the first terminal device 1 receives the input data from the external terminal device, it may store the input data in the first data storage unit 22 of the first terminal device 1.
[0111] Further, the first terminal device 1 may be configured not to include the first data storage unit 22 and the encryption processing unit 23. Also, a terminal device external to the first terminal device 1 may be configured to further include the encryption processing unit 23 and the second data storage unit 24. In this case, the first terminal device 1 may be configured not to include the encryption key storage unit 12. Also, in this case, the external terminal device transmits the first ciphertext stored in the second data storage unit 24 to the first terminal device 1. When the receiving unit 31 of the first terminal device 1 receives the first ciphertext from the external terminal device, the first ciphertext may be stored in the second data storage unit 24 of the first terminal device 1.
[0112] Further, the first terminal device 1 may be configured not to include the second data storage unit 24 and the transmission unit 25. For example, a terminal device external to the first terminal device 1 may include the transmission unit 25. Note that when the first terminal device 1 does not include the key generation processing unit 11 and, for example, receives the first decryption key from the external terminal device, the first terminal device 1 may include the receiving unit 31. Also, when the first terminal device 1 does not include the output unit 35 or the decryption processing unit 33 and transmits the ciphertext or the decryption result to the external terminal device, the first terminal device 1 may include the transmission unit 25.
[0113] Also, the first terminal device 1 may include the encryption key storage unit 12, the input unit 21, the first data storage unit 22, the encryption processing unit 23, the second data storage unit 24, the transmission unit 25, and the receiving unit 31. In this case, for example, the receiving unit 31 of the first terminal device 1 may receive the first encryption key from a terminal device including the key generation processing unit 11 and store the first encryption key in the encryption key storage unit 12.
[0114] Further, the first terminal device 1 may not include the output unit 35. For example, a terminal device different from the first terminal device 1 may include the fourth data storage unit 34 and the output unit 35, and the external terminal device may output the decryption result stored in the fourth data storage unit 34. In this case, the transmission unit 25 of the first terminal device 1 transmits the decryption result stored in the fourth data storage unit 34 of the first terminal device 1 to the external terminal device. When the external terminal device receives the decryption result from the first terminal device 1, it may store the decryption result in the fourth data storage unit 34 of the external terminal device.
[0115] Furthermore, the first terminal device 1 may not further include the decryption processing unit 33 and the fourth data storage unit 34. For example, the external terminal device may further include the third data storage unit 32 and the decryption processing unit 33, and decrypt the ciphertext stored in the third data storage unit 32. In this case, the first terminal device 1 may not further include the decryption key storage unit 13. Also, in this case, the transmission unit 25 of the first terminal device 1 transmits the fourth ciphertext stored in the third data storage unit 32 of the first terminal device 1 to the external terminal device. When the receiving unit 31 of the external terminal device receives the ciphertext from the first terminal device 1, it may store the ciphertext in the third data storage unit 32 of the external terminal device.
[0116] Moreover, the first terminal device 1 may not further include the receiving unit 31 and the third data storage unit 32. For example, the external terminal device may further include the receiving unit 31 and receive the ciphertext from the secret calculation device 4. When the first terminal device 1 does not include the key generation processing unit 11 and receives the first encryption key from the external terminal device, the first terminal device 1 may include the receiving unit 31. Also, when the first terminal device 1 does not include the input unit 21 or the encryption processing unit 23 and receives data or ciphertext from the external terminal device, the first terminal device 1 may include the receiving unit 31.
[0117] Further, the first terminal device 1 may include a decryption key storage unit 13, a reception unit 31, a third data storage unit 32, a decryption processing unit 33, a fourth data storage unit 34, and an output unit 35. In this case, the reception unit 31 of the first terminal device 1 may receive the first decryption key from an external terminal device including, for example, a key generation processing unit 11, and store the first decryption key in the decryption key storage unit 13.
[0118] <Hardware configuration example> Next, an example of the hardware configurations of the first terminal device 1 and the secure computing device 4 of the present embodiment will be described.
[0119] FIG. 5 is a schematic diagram of an example of the hardware configurations of the first terminal device 1 and the secure computing device 4 of the present embodiment.
[0120] The first terminal device 1 and the secure computing device 4 are computers or the like, and each has a processor 101, a memory 102, a storage device 103, a communication circuit 104, and an input / output device 105, and are each connected by a bus 106.
[0121] The processor 101 is configured using, for example, a CPU (Central Processing Unit). The processor 101 operates according to a program for controlling the secure computing system 100, such as the various processes described above, stored in the storage device 103. The processor 101 controls the memory 102, the storage device 103, the communication circuit 104, and the input / output device 105 according to the processing content of the program, and causes them to perform predetermined operations.
[0122] Programs and data generated during the operation of the program are temporarily held in the memory 102. The memory 102 is configured using, for example, a RAM (Random Access Memory) and a ROM (Read Only Memory). The RAM is, for example, a work memory used during the operation of the program, and the ROM stores and holds programs and the like in advance. Data and the like generated during the operation of the program and the like may be stored in the storage device 103. The storage device 103 is configured using, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive). Depending on the operation of the program controlled by the processor 101, data and the like may be stored in the storage device 103 via the input / output device 105, and data and the like stored in the storage device 103 may be output. Also, depending on the operation of the program, it may be transmitted to a network or the like connected via the communication circuit 104.
[0123] In the first terminal device 1 and the confidential computing device 4, the CPU reads out the program for executing the above processing from the ROM onto the RAM and executes it, whereby each of the above units is realized on a computer.
[0124] Note that the above program may be provided by being pre-incorporated in the ROM. Also, the above program may be stored in a computer-readable storage medium such as a CD-ROM, CD-R, memory card, DVD (Digital Versatile Disc), flexible disk (FD), etc. in an installable or executable file format and provided as a computer program product. Also, the above program may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network. Also, the above program may be provided or distributed via a network such as the Internet.
[0125] (Modification Example 1 of the First Embodiment) In this modified example, as an example, a form will be described in which the first homomorphic encryption method is a homomorphic encryption method using Module-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE.
[0126] Also, in this modified example, similar to the first embodiment, a form will be described as an example in which the input data includes two polynomials, and the coefficients of each of these polynomials are elements of a vector. Also, in this modified example, similar to the first embodiment, a form will be described as an example in which the inner product of two vectors is calculated as the first secure calculation process, and the square calculation of the inner product result is calculated as the second secure calculation process.
[0127] FIG. 1 is a schematic diagram of an example of the secure calculation system 100B of this modified example.
[0128] The secure calculation system 100B includes a first terminal device 1B and a secure calculation device 4B. The first terminal device 1B and the secure calculation device 4B are communicably connected via a network 5.
[0129] <Explanation of secure calculation processing content> First, the content of each secure calculation process of the first secure calculation process and the second secure calculation process in this modified example will be described.
[0130] In the secure calculation device 4B of this modified example, similar to the secure calculation device 4 of the first embodiment, as the first secure calculation process, the inner product of a first vector u = (u 0 , u 1 , …, u l-1 ) of length l and a second vector v = (v 0 , v 1 , …, v l-1 ) of length l is calculated, and a first scalar value s1 = <u, v> is output. Also, in the secure calculation device 4B, similar to the secure calculation device 4 of the first embodiment, as the second secure calculation process, the square calculation of the first scalar value s1 is calculated, and a second scalar value s2 = s1 2Outputs it. In the secure computing device 4B of this modified example, similar to the secure computing device 4 of the first embodiment, the data input to each of these first secure computing processes and second secure computing processes is calculated in a state where it is encrypted, that is, in a state of being a ciphertext.
[0131] <Explanation of the quasi - homomorphic encryption method and the ciphertext conversion method> In the secure computing device 4B of this modified example, in order to perform data input / output between the first secure computing process and the second secure computing process while keeping the data encrypted, the ciphertext is converted using a ciphertext conversion method defined between the first quasi - homomorphic encryption method and the second quasi - homomorphic encryption method.
[0132] In the secure computing device 4B of this modified example, as the first quasi - homomorphic encryption method, a quasi - homomorphic encryption method using Module - LWE is utilized. Module - LWE is a quasi - homomorphic encryption method that generalizes the quasi - homomorphic encryption method using Ring - LWE. Also, in the secure computing device 4B of this modified example, as the second quasi - homomorphic encryption method, a quasi - homomorphic encryption method using LWE is utilized. Further, in the secure computing device 4B of this modified example, as the ciphertext conversion method, the ciphertext conversion method between the second ciphertext encrypted by the first quasi - homomorphic encryption method using Module - LWE and the third ciphertext encrypted by the second quasi - homomorphic encryption method using LWE is utilized.
[0133] The quasi - homomorphic encryption method using Module - LWE has the dimension n of the polynomial ring and the dimension k of the vector, and when k = 1, it can be used as the quasi - homomorphic encryption method using Ring - LWE. Also, when n = 1, it can be used as the quasi - homomorphic encryption method using LWE. In this modified example, as the first quasi - homomorphic encryption method, a quasi - homomorphic encryption method using Module - LWE with n≠1 is utilized.
[0134] In the quasi - homomorphic encryption method using Module - LWE, an (n - 1) - degree polynomial m can be encrypted as a plaintext. The secret key sk MLWE is a set sk MLWE =(sk 0 , sk 1 ,…, sk k-1) is given by the public key pk MLWE is given by a set of k + 1 polynomials of degree n - 1. The ciphertext with the plaintext m is a set (b, a) consisting of one polynomial b of degree n - 1 and k polynomials a = (a 0 , a 1 , …, a k-1 ), and has the relationship m = <a, sk MLWE > + b.
[0135] In the homomorphic encryption scheme using Module-LWE, at least one homomorphic multiplication and homomorphic addition regarding polynomials of degree n - 1 can be utilized. For the homomorphic encryption scheme using Module-LWE when n ≠ 1, similar to the homomorphic encryption scheme using Ring-LWE, if the method described in Non-Patent Document 2 is used, the homomorphic multiplication can be utilized as a homomorphic inner product operation.
[0136] Expand the ciphertext conversion defined between the homomorphic encryption scheme using Ring-LWE described in Non-Patent Document 3 and the homomorphic encryption scheme using LWE. In this case, for the ciphertext (b, a 0 + m 1 x + … + m n-1 x n-1 ) of the polynomial m = m 0 , a 1 , …, a k-1 ) encrypted by the homomorphic encryption scheme using Module-LWE when n ≠ 1, without decrypting the ciphertext, it can be converted into the ciphertext of the constant term m 0 encrypted by the homomorphic encryption scheme using LWE with d = nk. However, a i = a i,0 + a i,1 x + … + a i,n-1 x n-1 . The ciphertext of the constant term m 0 encrypted by the homomorphic encryption scheme using LWE with the vector dimension d = nk can be calculated by the ciphertext conversion Extract MLWEtoLWE described in the following formula (3).
[0137] Enc LWE (m 0 ) = ExtractMLWEtoLWE =(b 0 , a 0,0 , -a 0,n-1 , …, -a 0,1 , a 1,0 , -a 1,n-1 , …, -a 1,1 , …, a k-1,0 , -a k-1,n-1 , …, -a k-1,1 ) ··· Equation (3)
[0138] Let the secret key used in the homomorphic encryption method using Module-LWE where n≠1 be sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). Then, the ciphertext described in the above Equation (3) can be decrypted. However, if sk i =sk i,0 +sk i,1 x+…+sk i,n-1 x n-1 ), then the secret key used in the homomorphic encryption method using LWE with the vector dimension d = nk is sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ). At this time, sk LWE is a vector of length nk with the coefficients of the n-1 degree polynomial sk MLWE , sk 0 , …, sk 1 , …, sk k-1 as elements in order from the coefficient of the 0th degree.
[0139] Note that these first homomorphic encryption methods and second homomorphic encryption methods are just examples. As the first homomorphic encryption method, a homomorphic encryption that can encrypt a polynomial plaintext and define homomorphic operations related to polynomial multiplication and polynomial addition may be used. However, the polynomial is a polynomial whose coefficients are elements of a vector. Also, as the second homomorphic encryption method, a homomorphic encryption that can encrypt a scalar value, can use homomorphic multiplication and homomorphic multiplication, and can further define ciphertext conversion with the first homomorphic encryption method may be used.
[0140] <Explanation of the Secret Calculation Method> In the secret calculation system according to this modification example, the first secret calculation process and the second secret calculation process are secretly calculated in the following procedure using a first homomorphic encryption method, a second homomorphic encryption method, and ciphertext conversion.
[0141] As preparation for the homomorphic encryption, in the first terminal device 1B, the secret key sk MLWE and the public key pk MLWE of the first homomorphic encryption method are generated. Also, in the first terminal device 1B, the secret key used in the first homomorphic encryption method is sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i =sk i,0 +sk i,1 x+…+sk i,n-1 x n-1 ), the secret key of the second homomorphic encryption method is sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ). In the first terminal device 1B, the public key pk MLWE used in the first homomorphic encryption method is used as the first encryption key, and the secret key sk LWE used in the second homomorphic encryption method is used as the first decryption key. Note that the secret key sk MLWEmay be used as the first encryption key.
[0142] In the first terminal device 1B, input data including a first vector u = (u 0 , u 1 , …, u l-1 ) and a second vector v = (v 0 , v 1 , …, v l-1 ) is respectively converted into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 − v 1 x n―1 − v 2 x n―2 − … − v l―1 x n-(l―1) by the first conversion function fw and the second conversion function bw. Note that fw(v) and bw(u) may also be used during the conversion. Then, in the first terminal device 1B, the polynomials are respectively encrypted using the first encryption key pk MLWE to generate two first ciphertexts ct u , ct v .
[0143] In the secure computing device 4B, a first secure computing process using the homomorphic multiplication EvalMult u , ct v is calculated for the first ciphertexts ct MLWE , and a second ciphertext ct s1+ = EvalMult MLWE (ct u , ct v ) of a polynomial with the first scalar value s1 = <u, v> encrypted by the first homomorphic encryption method as the constant term is calculated.
[0144] In the secure computing device 4B, without decrypting the second ciphertext ct s1+ , using the ciphertext conversion Extract MLWEtoLWE , a third ciphertext ct s1 = Extract MLWEtoLWE (ct s1+ ) of the first scalar value s1 encrypted by the second homomorphic encryption method is converted.
[0145] In the concealment calculation device 4B, the third ciphertext ct s1 is subjected to a second concealment calculation process using the homomorphic multiplication EvalMult LWE , and the second scalar value s2 = s1 encrypted using the second homomorphic encryption method 2 of the fourth ciphertext ct s2 = EvalMult LWE (ct s1 , ct s1 ) is calculated.
[0146] In the first terminal device 1B, the fourth ciphertext ct of the second scalar value s2 s2 is decrypted using the first decryption key sk LWE to calculate the second scalar value s2.
[0147] <Description of System Configuration and Functions> Next, the concealment calculation system 100B of this modification will be specifically described.
[0148] FIG. 2 is a functional block diagram of an example of the first terminal device 1B of this modification. The first terminal device 1B is the same as the first terminal device 1 of the first embodiment described above, except that it includes a key generation processing unit 11B instead of the key generation processing unit 11 and an encryption processing unit 23B instead of the encryption processing unit 23.
[0149] The key generation processing unit 11B generates a public key pk MLWE and a secret key sk MLWE used in the first homomorphic encryption method. Also, the key generation processing unit 11B sets the secret key used in the first homomorphic encryption method as sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i = sk i,0 + sk i,1 x + … + sk i,n-1 x n-1 , the secret key of the second homomorphic encryption method is sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 becomes as follows.
[0150] Also, the key generation processing unit 11B uses the public key pk MLWE used in the first homomorphic encryption method as the first encryption key, and uses the secret key sk LWE used in the second homomorphic encryption method as the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may be used as the first encryption key.
[0151] The key generation processing unit 11B stores the first encryption key in the encryption key storage unit 12 and stores the first decryption key in the decryption key storage unit 13.
[0152] The encryption processing unit 23B converts the first vector u and the second vector v included in the input data stored in the first data storage unit 22 into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 − v 1 x n―1 − v 2 x n―2 − … − v l―1 x n-(l―1) using the first transformation function fw and the second transformation function bw, respectively. After the conversion, the encryption processing unit 23B encrypts the polynomial using the first encryption key pk MLWE stored in the encryption key storage unit 12, and calculates the second ciphertext ct u , ct v encrypted by the first homomorphic encryption method. The encryption processing unit 23 stores the second ciphertext in the second data storage unit 24.
[0153] Note that the input unit 21 of the first terminal device 1B may acquire the polynomials fw(u) and bw(v) from a computer or the like connected to the first terminal device 1B and store the polynomials in the first data storage unit 22. Further, the encryption processing unit 23B encrypts the polynomial stored in the first data storage unit 22 using the first encryption key pk MLWE stored in the encryption key storage unit 12 to obtain a first ciphertext ct u , ct v and store the first ciphertext in the second data storage unit 24.
[0154] FIG. 3 is a functional block diagram of an example of the confidential computing device 4B of this modified example.
[0155] The confidential computing device 4B is the same as the confidential computing device 4 of the first embodiment except that it includes a first confidential computing processing unit 43B and a ciphertext conversion processing unit 45B instead of the first confidential computing processing unit 43 and the ciphertext conversion processing unit 45.
[0156] The first confidential computing processing unit 43B performs confidential computing on the first ciphertext ct u , ct v stored in the first data storage unit 42 by using the first confidential computing processing using the homomorphic multiplication EvalMult MLWE that functions as a homomorphic inner product operation of the first homomorphic encryption method, and calculates a second ciphertext ct s1+ of a polynomial having the first scalar value s1 as a constant term. The first confidential computing processing unit 43B stores the second ciphertext in the second data storage unit 44.
[0157] The ciphertext conversion processing unit 45B converts the second ciphertext ct s1+ stored in the second data storage unit 44 into a third ciphertext ct MLWEtoLWE of the first scalar value s1 using the ciphertext conversion Extract s1 without decrypting it, and stores the third ciphertext in the third data storage unit 46.
[0158] Note that the hardware configurations of the first terminal device 1B and the confidential computing device 4B are the same as those of the first terminal device 1 and the confidential computing device 4 of the first embodiment (see FIG. 5).
[0159] <Description of the Flow> Next, an example of the information processing flow executed by the first terminal device 1B and the secure computing device 4B in this modified example will be described.
[0160] FIG. 4 is a flowchart showing an example of the information processing flow executed by the first terminal device 1B and the secure computing device 4B in this modified example. In this modified example, the processes of steps S1 to S12 are executed in the same manner as the first terminal device 1 and the secure computing device 4 in the above first embodiment.
[0161] However, in this modified example, in step S1, the key generation processing unit 11B of the first terminal device 1B generates a public key pk MLWE and a secret key sk MLWE using the first homomorphic encryption method. Then, the key generation processing unit 11B calculates a secret key sk MLWE used in the second homomorphic encryption method from the secret key sk LWE used in the first homomorphic encryption method. The key generation processing unit 11B uses the public key pk MLWE used in the first homomorphic encryption method as the first encryption key and the secret key sk LWE used in the second homomorphic encryption method as the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may also be used as the first encryption key. The key generation processing unit 11B stores the first encryption key in the encryption key storage unit 12 and the first decryption key in the decryption key storage unit 13.
[0162] Also, in step S3, the encryption processing unit 23B of the first terminal device 1B converts the input data including the first vector u and the second vector v stored in the first data storage unit 22 into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 − v 1 x n―1 − v 2 x n―2 − … − v l―1 xn-(l―1) Convert it. Then, the encryption processing unit 23B encrypts the polynomial using the first encryption key pk MLWE stored in the encryption key storage unit 12, and calculates the first ciphertext ct u , ct v encrypted by the first homomorphic encryption method. The encryption processing unit 23B stores the first ciphertext in the second data storage unit 24.
[0163] Also, in step S6, the first secure calculation processing unit 43B of the secure calculation device 4B performs secure calculation on the first ciphertext ct u , ct v stored in the first data storage unit 42 by the first secure calculation process using the homomorphic multiplication EvalMult MLWE that functions as a homomorphic inner product operation available in the first homomorphic encryption method. Through this secure calculation, the first secure calculation processing unit 43B calculates the second ciphertext ct s1+ of the polynomial with the first scalar value s1 as the constant term encrypted using the first homomorphic encryption method. The first secure calculation processing unit 43B stores the second ciphertext in the second data storage unit 44.
[0164] Also, in step S7, the ciphertext conversion processing unit 45B of the secure calculation device 4B converts the second ciphertext ct s1+ stored in the second data storage unit 44 into the third ciphertext ct MLWEtoLWE of the first scalar value s1 encrypted by the second homomorphic encryption method using the ciphertext conversion Extract s1 without decrypting it. Then, the ciphertext conversion processing unit 45B stores the third ciphertext in the third data storage unit 46.
[0165] As described above, the ciphertext conversion processing unit 45B of the secure computing device 4B of this modification example, similar to the ciphertext conversion processing unit 45 of the above embodiment, uses a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method to convert the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, in the secure computing device 4B and the secure computing system 100B of this modification example, even when using Module-LWE as the first homomorphic encryption method and LWE as the second homomorphic encryption method, the secrecy can be improved in the same manner as in the first embodiment. In addition, the secure computing device 4B and the secure computing system 100B of this modification example can utilize a homomorphic encryption method using Module-LWE, which has higher security performance than the homomorphic encryption method using Ring-LWE as the first homomorphic encryption method.
[0166] Note that FIG. 2 shows, as an example, a configuration in which the first terminal device 1 includes a key generation processing unit 11, an encryption key storage unit 12, a decryption key storage unit 13, an input unit 21, a first data storage unit 22, an encryption processing unit 23, a second data storage unit 24, a transmission unit 25, a reception unit 31, a third data storage unit 32, a decryption processing unit 33, a fourth data storage unit 34, and an output unit 35. However, the first terminal device 1 may have a configuration including a part of these units. For example, the first terminal device 1 may have a configuration including at least one of the key generation processing unit 11, the encryption processing unit 23, and the decryption processing unit 33.
[0167] (Modification Example 2 of the First Embodiment) In this modification example, an example will be described in which the first homomorphic encryption method is a homomorphic encryption method using Ring-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE that does not depend on the ring dimension of Ring-LWE.
[0168] Also, in this modified example, similar to the first embodiment, an example will be described in a form where the input data includes two polynomials and the coefficients of each of these polynomials are elements of a vector. Also, in this modified example, similar to the first embodiment, an example will be described in a form where the inner product of two vectors is calculated as the first secret calculation process and the square calculation of the inner product result is calculated as the second secret calculation process. Also, in this modified example, as the ciphertext conversion method, a ciphertext conversion method between a second ciphertext encrypted by a first homomorphic encryption method using Ring-LWE and a third ciphertext encrypted by a second homomorphic encryption method using LWE that does not depend on the ring dimension number of the first homomorphic encryption method is used.
[0169] FIG. 1 is a schematic diagram of an example of the secret calculation system 100C of this modified example.
[0170] The secret calculation system 100C includes a first terminal device 1C and a secret calculation device 4C. The first terminal device 1C and the secret calculation device 4C are communicably connected via a network 5.
[0171] <Explanation of the content of the secret calculation process> First, the content of each of the first secret calculation process and the second secret calculation process in this modified example will be described.
[0172] In the secret calculation device 4C of this modified example, similar to the secret calculation device 4 of the first embodiment, as the first secret calculation process, the inner product of a first vector u = (u 0 , u 1 , …, u l-1 ) of length l and a second vector v = (v 0 , v 1 , …, v l-1 ) of length l is calculated, and a first scalar value s1 = <u, v> is output. Also, in the secret calculation device 4C, similar to the secret calculation device 4 of the first embodiment, as the second secret calculation process, the square calculation of the first scalar value s1 is calculated, and a second scalar value s2 = s1 2Output. In the secret calculation device 4C of this modified example, similar to the secret calculation device 4 of the first embodiment, the data input to each of these first secret calculation process and second secret calculation process is calculated in a state where it is encrypted, that is, in a state of remaining as ciphertext.
[0173] <Explanation of quasi - homomorphic encryption method and ciphertext conversion method> In the secret calculation device 4C of this modified example, in order to perform data input / output between the first secret calculation process and the second secret calculation process while keeping the data encrypted, the ciphertext is converted using a ciphertext conversion method defined between the first quasi - homomorphic encryption method and the second quasi - homomorphic encryption method.
[0174] In the secret calculation device 4C of this modified example, as the first quasi - homomorphic encryption method, a quasi - homomorphic encryption method using Ring - LWE with a ring dimension number n is utilized. Also, in the secret calculation device 4C, as the second quasi - homomorphic encryption method, a quasi - homomorphic encryption method using LWE with a vector dimension number d'≠n is utilized. Further, in the secret calculation device 4C, a ciphertext conversion method between the quasi - homomorphic encryption method using Ring - LWE with a ring dimension number n and the quasi - homomorphic encryption method using LWE with a vector dimension number d' is utilized.
[0175] The ciphertext conversion method used in this modified example is a combination of the ciphertext conversion Extract between the quasi - homomorphic encryption method using Ring - LWE with a ring dimension number n and the quasi - homomorphic encryption method using LWE with a vector dimension number n RLWEtoLWE and the ciphertext conversion method between the quasi - homomorphic encryption method using LWE with a vector dimension number d and the quasi - homomorphic encryption method using LWE with a vector dimension number d'. Hereinafter, the ciphertext conversion method between the quasi - homomorphic encryption method using LWE with a vector dimension number d and the quasi - homomorphic encryption method using LWE with a vector dimension number d' will be described.
[0176] Let the secret key used in the quasi - homomorphic encryption method using LWE with a vector dimension number d be sk LWE and the secret key used in the quasi - homomorphic encryption method using LWE with a vector dimension number d' be sk LWE’ and the public key be pk LWE’Let it be so. Also, as the conversion key used for ciphertext conversion, use the secret key sk used in the homomorphic encryption method using LWE of vector dimension d'. LWE’ Using sk used in the homomorphic encryption method using LWE of vector dimension d, LWE encrypt it to obtain the ciphertext ksk LWEtoLWE’ =Enc LWE’ (sk LWE ) as the conversion key. Note that since the conversion key is a ciphertext, it may be made public.
[0177] The ciphertext of the scalar value m encrypted by the homomorphic encryption method using LWE of vector dimension d 0 can be converted into the ciphertext of the scalar value m 0 encrypted by the homomorphic encryption method using LWE of vector dimension d' without decrypting the ciphertext. Specifically, for the ciphertext of the above scalar value m 0 let Enc LWE (m 0 )=(b,a). Here, a=(a 0 ,a 1 ,…,a d-1 ). In this case, the ciphertext of the scalar value m 0 encrypted by the homomorphic encryption method using LWE of vector dimension d' can be calculated by the ciphertext conversion Convert LWEtoLWE’ described in Equation (4).
[0178] Enc LWE’ (m 0 )=Convert LWEtoLWE’ (Enc LWE (m 0 ))=Enc LWE’ (b)+<a,ksk LWEtoLWE’ > ··· Equation (4)
[0179] Note that Enc LWE (b) described in Equation (4) may be the trivial ciphertext Enc LWE (b)=(b,0,0,…,0). Also, although the description is omitted in this embodiment, a conversion method using Gadget Decomposition may be used.
[0180] Enc described in Formula (4) LWE’ (b) is the ciphertext of b encrypted using the public key pk used in the homomorphic encryption method using LWE of vector dimension d'. LWE’ It is the ciphertext of b encrypted using
[0181] The ciphertext of the polynomial m encrypted by the homomorphic encryption method using Ring-LWE of ring dimension n is Enc RLWE (m) = (b, a 0 ) is set. However, a 0 = a 0,0 + a 0,1 x + … + a 0,n-1 x n-1 In this case, the ciphertext of the constant term m 0 of the polynomial m encrypted by the homomorphic encryption method using LWE with vector dimension d' can be calculated by the ciphertext conversion described in Formula (5).
[0182] Enc LWE (m 0 ) = Convert LWEtoLWE’ (Extract RLWEtoLWE (Enc RLWE (m))) ·· Formula (5)
[0183] <Explanation of the confidential calculation method> In the confidential calculation system according to this modification example, the first homomorphic encryption method, the second homomorphic encryption method, and the ciphertext conversion are used to perform the first confidential calculation process and the second confidential calculation process in the following procedure.
[0184] As preparation for the homomorphic encryption, the first terminal device 1C generates the secret key sk RLWE and the public key pk RLWE of the first homomorphic encryption method. Also, the first terminal device 1C generates the secret key sk LWE’ and the public key pk LWE’ of the second homomorphic encryption method. Also, when the secret key used in the first homomorphic encryption method is sk RLWE = sk 0 + sk 1 x + … + sk n-1 x n-1 , the conversion key ksk LWEtoLWE’is sk encrypted using the second homomorphic encryption method LWE =(sk 0 , sk 1 , …, sk n-1 ) ciphertext ksk LWEtoLWE’ = Enc LWE’ (sk LWE ). Let the public key pk RLWE used in the first homomorphic encryption method be the first encryption key, and the secret key sk LWE’ used in the second homomorphic encryption method be the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may also be used as the first encryption key. Also, let the public key pk LWE’ used in the second homomorphic encryption method be the second encryption key.
[0185] The first terminal device 1C converts the input data including the first vector u = (u 0 , u 1 , …, u l-1 ) and the second vector v = (v 0 , v 1 , …, v l-1 ) using the first conversion function fw and the second conversion function bw into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 ― v 1 x n―1 ― v 2 x n―2 ― … ― v l―1 x n-(l―1) . Note that fw(v) and bw(u) may also be used during the conversion. Then, the first terminal device 1C encrypts the above polynomials using the first encryption key pk RLWE and calculates two first ciphertexts ct u , ct v .
[0186] The secure computing device 4C performs the first secure computing process on the first ciphertexts ct u , ct v using the homomorphic multiplication EvalMult RLWE and obtains the second ciphertext ct of the polynomial with the first scalar value s1 = <u, v> as the constant terms1+ =EvalMult RLWE (ct u ,ct v ) is calculated.
[0187] The secure computing device 4C, without decrypting the second ciphertext ct s1+ , uses the ciphertext conversion Extract RLWEtoLWE and Convert LWEtoLWE’ , the conversion key ksk LWEtoLWE’ , and the second encryption key pk LWE’ to convert the third ciphertext ct of the first scalar value s1 s1 =Convert LWEtoLWE’ (Extract LWEtoLWE (ct s1+ ).
[0188] The secure computing device 4C performs a second secure computing process on the third ciphertext ct s1 using the homomorphic multiplication EvalMult LWE’ to calculate the fourth ciphertext ct of the second scalar value s2 = s1 2 =EvalMult s2 (ct LWE’ ,ct s1 ,ct s1 ). The homomorphic multiplication EvalMult LWE’ is a homomorphic multiplication available in the second homomorphic encryption scheme.
[0189] The first terminal device 1C decrypts the fourth ciphertext ct of the second scalar value s2 s2 using the first decryption key sk LWE’ to calculate the second scalar value s2.
[0190] <Description of System Configuration and Functions> Next, the secure computing system 100C of this modified example will be specifically described.
[0191] FIG. 6 is a functional block diagram of an example of the first terminal device 1C of this modification. The first terminal device 1C is the same as the first terminal device 1 of the first embodiment described above, except that it includes a key generation processing unit 11C, a transmission unit 25C, and a decryption processing unit 33C, and further includes a conversion key storage unit 14, instead of the key generation processing unit 11, the transmission unit 25, and the decryption processing unit 33.
[0192] The key generation processing unit 11C generates a public key pk RLWE and a secret key sk RLWE used in the first homomorphic encryption method. Further, the key generation processing unit 11C generates a public key pk LWE’ and a secret key sk LWE’ used in the second homomorphic encryption method. When the secret key used in the first homomorphic encryption method is sk RLWE = sk 0 + sk 1 x + … + sk n-1 x n-1 the conversion key ksk LWEtoLWE’ is the ciphertext ksk LWE =(sk 0 , sk 1 , …, sk n-1 ) encrypted using the second homomorphic encryption method, i.e., ksk LWEtoLWE’ = Enc LWE’ (sk LWE ). The key generation processing unit 11C uses the public key pk RLWE as the first encryption key and the secret key sk LWE’ as the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may also be used as the first encryption key. Further, the key generation processing unit 11C uses the public key pk LWE’ used in the second homomorphic encryption method as the second encryption key.
[0193] The key generation processing unit 11C stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14.
[0194] The transmission unit 25C uses the second encryption key pk LWE’ stored in the second data storage unit 24 and the conversion key ksk LWEtoLWE’It is transmitted to the secure computing device 4.
[0195] The decryption processing unit 33C decrypts the fourth ciphertext stored in the third data storage unit 32 using the first decryption key sk stored in the decryption key storage unit 13, and calculates the second scalar value s2. The decryption processing unit 33C stores the second scalar value in the fourth data storage unit 34. LWE’ It decrypts the fourth ciphertext stored in the third data storage unit 32 using the first decryption key sk stored in the decryption key storage unit 13, and calculates the second scalar value s2. The decryption processing unit 33C stores the second scalar value in the fourth data storage unit 34.
[0196] FIG. 7 is a functional block diagram of an example of the secure computing device 4C of this modified example.
[0197] The secure computing device 4C is the same as the secure computing device 4 of the first embodiment except that it includes a receiving unit 41C, a first secure computing processing unit 43C, a ciphertext conversion processing unit 45C, and a second secure computing processing unit 47C instead of the receiving unit 41, the first secure computing processing unit 43, the ciphertext conversion processing unit 45, and the second secure computing processing unit 47, and further includes an encryption key storage unit 51 and a conversion key storage unit 52.
[0198] The receiving unit 41C receives the second encryption key pk LWE’ and the conversion key ksk LWEtoLWE’ from the first terminal device 1C, stores the second encryption key in the encryption key storage unit 51, and stores the conversion key in the conversion key storage unit 52.
[0199] The ciphertext conversion processing unit 45C converts the second ciphertext ct s1+ stored in the second data storage unit 44 into the third ciphertext ct RLWEtoLWE of the first scalar value s1 encrypted by the second homomorphic encryption method using Ciphertext conversion Extract LWEtoLWE’ without decrypting it. The ciphertext conversion processing unit 45C uses the second encryption key pk s1 stored in the encryption key storage unit 51 and the conversion key ksk LWE’ stored in the conversion key storage unit 52 LWEtoLWE’ Using this, ciphertext conversion is performed. That is, the ciphertext conversion processing unit 45C converts the second ciphertext into a third ciphertext using the encryption key based on the second homomorphic encryption method and the conversion key used for ciphertext conversion without decrypting the second ciphertext. The ciphertext conversion processing unit 45C stores the third ciphertext in the third data storage unit 46.
[0200] The second secure calculation processing unit 47C securely calculates the third ciphertext ct stored in the third data storage unit 46 s1 by performing a second secure calculation process using the homomorphic multiplication EvalMult LWE’ to calculate the fourth ciphertext ct of the second scalar value s2. The second secure calculation processing unit 47C stores the fourth ciphertext in the fourth data storage unit 48. s2
[0201] Note that the hardware configurations of the first terminal device 1C and the secure calculation device 4C are the same as those of the first terminal device 1 and the secure calculation device 4 in the above first embodiment (see FIG. 5).
[0202] <Explanation of the flow> Next, an example of the flow of information processing executed by the first terminal device 1C and the secure calculation device 4C of this modification will be described.
[0203] FIG. 8 is a flowchart showing an example of the flow of information processing executed by the first terminal device 1C and the secure calculation device 4C of this modification. In this modification, the processes of steps S1 to S12 are executed in the same manner as the first terminal device 1 and the secure calculation device 4 in the above first embodiment. Further, the information processing executed by the first terminal device 1C and the secure calculation device 4C of this modification further includes step S13 between step S1 and step S2, and further includes step S14 between step S2 and step S3.
[0204] Specifically, in this modification, in step S1, the key generation processing unit 11C of the first terminal device 1C generates the public key pk RLWE and the secret key sk RLWE used in the first homomorphic encryption method. Also, the key generation processing unit 11C generates the public key pk used in the second homomorphic encryption methodLWE’ and the private key sk LWE’ is generated. The private key used in the first homomorphic encryption method is sk RLWE = sk 0 + sk 1 x + … + sk n-1 x n-1 When it is set as such, the conversion key ksk LWEtoLWE’ is the ciphertext of sk LWE =(sk 0 , sk 1 , …, sk n-1 ) encrypted using the second homomorphic encryption method, ksk LWEtoLWE’ = Enc LWE’ (sk LWE ). Also, the public key pk RLWE used in the first homomorphic encryption method is used as the first encryption key, and the private key sk LWE’ used in the second homomorphic encryption method is used as the first decryption key. Note that the private key sk MLWE used in the first homomorphic encryption method in the first terminal device 1C may be used as the first encryption key. Also, the public key pk LWE’ used in the second homomorphic encryption method in the secure computing device 4C is used as the second encryption key. The key generation processing unit 11C stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14.
[0205] Next, the transmission unit 25C of the first terminal device 1C transmits the second encryption key pk LWE’ stored in the encryption key storage unit 12 and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 14 to the secure computing device 4C (step S13).
[0206] The reception unit 41C of the secure computing device 4C receives the second encryption key pk LWE’ and the conversion key ksk LWEtoLWE’ from the first terminal device 1C, stores the second encryption key in the encryption key storage unit 51, and stores the conversion key in the conversion key storage unit 52 (step S14).
[0207] Then, in the same manner as in the first embodiment, the processes of steps S3 to S12 are executed.
[0208] However, in step 7, the ciphertext conversion processing unit 45C of the secure computing device 4C, without decrypting the second ciphertext ct stored in the second data storage unit 44, uses the ciphertext conversion Extract s1+ , Convert RLWEtoLWE to convert the third ciphertext ct of the first scalar value s1 and stores the third ciphertext in the third data storage unit 46. When calculating the ciphertext conversion, the ciphertext conversion processing unit 45C uses the second encryption key pk LWEtoLWE’ stored in the encryption key storage unit 51 and the conversion key ksk s1 stored in the conversion key storage unit 52. LWE’ and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 52.
[0209] Also, in step S8, the second secure computing processing unit 47C of the secure computing device 4C securely computes the third ciphertext ct stored in the third data storage unit 46 through second secure computing processing using the homomorphic multiplication EvalMult s1 , and calculates the fourth ciphertext ct of the second scalar value s2 LWE’ . The second secure computing processing unit 47C stores the fourth ciphertext in the fourth data storage unit 48. s2 . The second secure computing processing unit 47C stores the fourth ciphertext in the fourth data storage unit 48.
[0210] Also, in step S11, the decryption processing unit 33C of the first terminal device 1C decrypts the fourth ciphertext stored in the third data storage unit 32 using the first decryption key sk LWE’ stored in the decryption key storage unit 13 and calculates the second scalar value s2. The decryption processing unit 33C stores the second scalar value in the fourth data storage unit 34.
[0211] As described above, similar to the ciphertext conversion processing unit 45 in the above embodiment, the ciphertext conversion processing unit 45C of the concealment calculation device 4C in this modification example uses a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method to convert the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, in the concealment calculation device 4C and the concealment calculation system 100C of this modification example, even when Ring-LWE is used as the first homomorphic encryption method and LWE independent of the ring dimension number of Ring-LWE is used as the second homomorphic encryption method, the concealment can be improved in the same manner as in the first embodiment.
[0212] Further, since the concealment calculation device 4C and the concealment calculation system 100C of this modification example can utilize a homomorphic encryption method using LWE independent of the ring dimension number n, which is used in the homomorphic encryption method using Ring-LWE, there is a possibility that the processing performance of the homomorphic operation can be further improved by customizing the parameters. However, since the ciphertext conversion becomes more complicated in the concealment calculation system 100C of this modification example than in the concealment calculation system 100 of the first embodiment, the processing performance of the ciphertext conversion may decrease. Therefore, in the concealment calculation system 100C of this modification example, it is considered preferable to selectively use the ciphertext conversion according to the content of the second concealment calculation process.
[0213] Note that the first terminal device 1C in this modification example may have a configuration including a part of each unit shown in FIG. 6. For example, a plurality of external terminal devices different from the first terminal device 1C may include each unit not provided in the first terminal device 1C.
[0214] Specifically, the first terminal device 1C may have a configuration including at least one of a key generation processing unit 11, an encryption processing unit 23, and a decryption processing unit 33. Hereinafter, only the differences from the first embodiment will be described.
[0215] Specifically, the first terminal device 1C may not include a key generation processing unit 11. Then, an external terminal device different from the first terminal device 1C may include a key generation processing unit 11 and generate a first encryption key used in the first homomorphic encryption method, a second encryption key and a first decryption key used in the second homomorphic encryption method. In this case, the external terminal device transmits the first encryption key stored in the encryption key storage unit and the first decryption key stored in the decryption key storage unit to the first terminal device 1C, and transmits the second encryption key stored in the conversion key storage unit to the secure computing device 4C. When the first terminal device 1C does not include an encryption processing unit 23, the external terminal device may not transmit the first encryption key to the first terminal device 1C. When the first terminal device 1C does not include a decryption processing unit 33, the external terminal device may not transmit the first decryption key to the first terminal device 1C. When the receiving unit 31 of the first terminal device 1C receives the first encryption key or the first decryption key from the external terminal device, it stores the first encryption key and the first decryption key in the encryption key storage unit 12 and the decryption key storage unit 13, respectively. Also, when the secure computing device 4C receives the second encryption key from the external terminal device, it stores the second encryption key in the conversion key storage unit 52.
[0216] Further, the first terminal device 1 may include a key generation processing unit 11, an encryption key storage unit 12, a decryption key storage unit 13, a conversion key storage unit 14, and a transmission unit 25. Then, the first terminal device 1C may generate a first encryption key used in the first homomorphic encryption method, a first decryption key used in the second homomorphic encryption method, and a conversion key, which are used by an external terminal device different from the first terminal device 1C. In this case, the transmission unit 25 of the first terminal device 1C transmits, for example, the first encryption key stored in the encryption key storage unit 12 to an external terminal device including an encryption processing unit 23. Also, the transmission unit 25 of the first terminal device 1C transmits, for example, the first decryption key stored in the decryption key storage unit 13 to an external terminal device including a decryption processing unit 33. Further, the first terminal device 1C transmits the conversion key stored in the conversion key storage unit 14 to the secure computing device 4. After transmission, the first terminal device 1C may delete the first encryption key, the first decryption key, and the conversion key.
[0217] (Modification Example 3 of the First Embodiment) In this modified example, as an example, a form will be described in which the first homomorphic encryption method is a homomorphic encryption method using Module-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE that does not depend on the ring dimension number of Module-LWE.
[0218] Also, in this modified example, as in the first embodiment, a form will be described as an example in which the input data includes two polynomials, and the coefficients of each of these polynomials are elements of a vector. Also, in this modified example, as in the first embodiment, a form will be described as an example in which the inner product of two vectors is calculated as the first secure calculation process, and the square calculation of the inner product result is calculated as the second secure calculation process. Also, in this modified example, as an encryption text conversion method, an encryption text conversion method between a second encryption text encrypted by a first homomorphic encryption method using Module-LWE and a third encryption text encrypted by a second homomorphic encryption method using LWE that does not depend on the ring dimension number of the first homomorphic encryption method is used.
[0219] FIG. 1 is a schematic diagram of an example of the secure calculation system 100D of this modified example.
[0220] The secure calculation system 100D includes a first terminal device 1D and a secure calculation device 4D. The first terminal device 1D and the secure calculation device 4D are communicably connected via a network 5.
[0221] <Explanation of secure calculation processing content> First, the content of each secure calculation process of the first secure calculation process and the second secure calculation process in this modified example will be described.
[0222] In the secure calculation device 4D of this modified example, as in the secure calculation device 4 of the first embodiment, as the first secure calculation process, a first vector u = (u 0 , u 1 , …, u l-1 ) of length l and a second vector v = (v 0 , v 1 , …, v l-1) Calculate the inner product of and, and output the first scalar value s1 = <u, v>. Also, in the secure computing device 4C, similar to the secure computing device 4 in the first embodiment, as the second secure computing process, calculate the square of the first scalar value s1, and the second scalar value s2 = s1 2 is output. In the secure computing device 4C of this modified example, similar to the secure computing device 4 in the first embodiment, for each of these first secure computing process and second secure computing process, calculate in a state where the input data is encrypted, that is, in the state of ciphertext.
[0223] <Explanation of Homomorphic Encryption Scheme and Ciphertext Conversion Scheme> In the secure computing device 4D of this modified example, in order to perform data input / output between the first secure computing process and the second secure computing process while keeping the data encrypted, the ciphertext is converted using a ciphertext conversion method defined between the first homomorphic encryption scheme and the second homomorphic encryption scheme.
[0224] In the secure computing device 4D of this modified example, as the first homomorphic encryption scheme, a homomorphic encryption scheme using Module-LWE with ring dimension n≠1 and vector dimension k is utilized. Also, in the secure computing device 4D of this modified example, as the second homomorphic encryption scheme, a homomorphic encryption scheme using LWE with vector dimension d' is utilized. Also, in the secure computing device 4D, ciphertext conversion between the homomorphic encryption scheme using Module-LWE with ring dimension n and the homomorphic encryption scheme using LWE with vector dimension d' is utilized. Hereinafter, the secret key used in the homomorphic encryption scheme using Module-LWE with ring dimension n≠1 and vector dimension k is sk MLWE , and the public key is pk MLWE is denoted. Also, the secret key used in the homomorphic encryption scheme using LWE with vector dimension d' is sk LWE’ , and the public key is pk LWE’ is used.
[0225] <Explanation of Secure Computing Method> The secure computing system 100D of this modified example uses the first homomorphic encryption scheme, the second homomorphic encryption scheme, and the ciphertext conversion to perform the first secure computing process and the second secure computing process in the following procedure in a secure manner.
[0226] The first terminal device 1D prepares the homomorphic encryption by storing a secret key sk of the first homomorphic encryption method. MLWE and the public key pk MLWE The first terminal device 1D also generates a secret key sk of the second homomorphic encryption method. LWE’ The secret key used in the first homomorphic encryption method is generated as sk MLWE =(sk 0 ,sk 1 ,…,sk k-1 ) where sk i =sk i,0 +sk i,1 x+…+sk i,n-1 x n-1 Then, the conversion key ksk LWEtoLWE’ is the encrypted sk using the second homomorphic encryption method. LWE =(sk 0,0 ,sk 0,1 ,…,sk 0,n-1 ,sk 1,0 ,sk 1,1 ,…,sk 1,n-1 ,…,sk k-1,0 ,sk k-1,1 ,…,sk k-1,n-1 ) and the ciphertext ksk LWEtoLWE’ =Enc LWE’ (sk LWE ).
[0227] The first terminal device 1D receives a public key pk used in the first homomorphic encryption method. MLWE is the first encryption key, and the secret key sk used in the second homomorphic encryption method is LWE’ The first decryption key is the public key sk used in the first homomorphic encryption method. MLWE The first terminal device 1D may use a public key pk used in the second homomorphic encryption method as the first encryption key. LWE’ is the second encryption key.
[0228] In the first terminal device 1D, a first vector u=(u 0 ,u 1 ,…,u l-1 ) and a second vector v=(v 0 ,v 1 ,…,vl-1 ) and the input data including [it] are respectively converted by the first conversion function fw and the second conversion function bw into the polynomials fw(u)=u 0 +u 1 x+…+u l-1 x l-1 , bw(v)=v 0 ―v 1 x n―1 ―v 2 x n―2 ―…―v l―1 x n-(l―1) . Note that fw(v) and bw(u) may also be used during the conversion. Then, the first terminal device 1D encrypts the above polynomials respectively using the first encryption key pk MLWE and calculates two first ciphertexts ct u , ct v .
[0229] In the secure computing device 4D, the first ciphertexts ct u , ct v are subjected to first secure computing processing using the homomorphic multiplication EvalMult MLWE that functions as a homomorphic inner product operation of the first homomorphic encryption method, and a second ciphertext ct s1+ = EvalMult MLWE (ct u , ct v ) of a polynomial having the first scalar value s1 = <u, v> encrypted by the first homomorphic encryption method as a constant term is calculated.
[0230] The secure computing device 4D, without decrypting the second ciphertext ct s1+ , using the ciphertext conversion Extract MLWEtoLWE and Convert LWEtoLWE’ , the conversion key ksk LWEtoLWE’ , and the second encryption key pk LWE’ , converts it into a third ciphertext ct s1 = Convert LWEtoLWE’ (Extract LWEtoLWE (ct s1+ )) of the first scalar value s1.
[0231] The secure computing device 4D subjects the third ciphertext ct s1 to homomorphic multiplication EvalMult LWE’Use it to perform the second secret calculation process, and the second scalar value s2 = s1 2 of the fourth ciphertext ct s2 =EvalMult LWE’ (ct s1 , ct s1 ) is calculated.
[0232] The first terminal device 1D decrypts the fourth ciphertext ct of the second scalar value s2 s2 using the first decryption key sk LWE’ to calculate the second scalar value s2.
[0233] <Description of System Configuration and Functions> Next, the secret calculation system 100D of this modified example will be specifically described.
[0234] Figure 6 is a functional block diagram of an example of the first terminal device 1D of this modified example. The first terminal device 1D includes a key generation processing unit 11D, an encryption processing unit 23D, a transmission unit 25D, and a decryption processing unit 33D instead of the key generation processing unit 11, the encryption processing unit 23, the transmission unit 25, and the decryption processing unit 33, and is the same as the first terminal device 1 of the first embodiment except that it further includes a conversion key storage unit 14. Although not shown in Figure 6, in this embodiment, an arrow indicating the data exchange from the encryption key storage unit 12 to the transmission unit 25D is additionally required.
[0235] The key generation processing unit 11D generates the public key pk MLWE and the secret key sk MLWE used in the first homomorphic encryption method. Also, the key generation processing unit 11D generates the public key pk LWE’ and the secret key sk LWE’ used in the second homomorphic encryption method. Let the secret key used in the first homomorphic encryption method be sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i =sk i,0 +sk i,1 x+…+sk i,n-1 x n-1 and the conversion key ksk LWEtoLWE’is the encrypted sk using the second homomorphic encryption method LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 )'s ciphertext ksk LWEtoLWE’ = Enc LWE’ (sk LWE ).
[0236] The key generation processing unit 11D uses the public key pk MLWE used in the first homomorphic encryption method as the first encryption key, and the secret key sk LWE’ used in the second homomorphic encryption method as the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may also be used as the first encryption key. Also, the public key pk LWE’ used in the second homomorphic encryption method and utilized in the secure computing device 4D is used as the second encryption key. The key generation processing unit 11D stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14.
[0237] The transmission unit 25D transmits the second encryption key pk LWE’ stored in the encryption key storage unit 12 and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 14 to the secure computing device 4D.
[0238] The encryption processing unit 23D converts the first vector u and the second vector v stored in the first data storage unit 22 into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 − v 1 x n―1 − v 2 x n―2 − … − v l―1 x n-(l―1)Convert it. Then, the encryption processing unit 23D encrypts the above polynomial using the first encryption key pk stored in the encryption key storage unit 12, and calculates the first ciphertext ct encrypted by the first homomorphic encryption method, ct MLWE u v . The encryption processing unit 23D stores the first ciphertext in the second data storage unit 24.
[0239] The decryption processing unit 33D decrypts the fourth ciphertext stored in the third data storage unit 32 using the first decryption key sk stored in the decryption key storage unit 13, and calculates the second scalar value s2. The decryption processing unit 33D stores the second scalar value in the fourth data storage unit 34. LWE’
[0240] Note that the input unit 21 may obtain the above polynomials fw(u) and bw(v) from a computer or the like connected to the first terminal device 1D and store them in the first data storage unit 22. Further, the encryption processing unit 23D may encrypt the above polynomial stored in the first data storage unit 22 using the first encryption key pk stored in the encryption key storage unit 12 to calculate the first ciphertext ct MLWE u v . Then, the encryption processing unit 23D may store the first ciphertext in the second data storage unit 24.
[0241] FIG. 7 is a functional block diagram of an example of the secure computing device 4D of this modified example.
[0242] The secure computing device 4D is the same as the secure computing device 4 of the first embodiment except that it includes a receiving unit 41D, a first secure computing processing unit 43D, a ciphertext conversion processing unit 45D, and a second secure computing processing unit 47D instead of the receiving unit 41, the first secure computing processing unit 43, the ciphertext conversion processing unit 45, and the second secure computing processing unit 47, and further includes an encryption key storage unit 51 and a conversion key storage unit 52.
[0243] The receiving unit 41D receives the second encryption key pk LWE’ and the conversion key ksk LWEtoLWE’ Receives it, stores the second encryption key in the encryption key storage unit 51, and stores the conversion key in the conversion key storage unit 52.
[0244] The first secure calculation processing unit 43D performs secure calculation on the first ciphertext ct stored in the first data storage unit 42 u , ct v using the secure multiplication EvalMult that functions as a homomorphic inner product operation of the first homomorphic encryption method MLWE to calculate the second ciphertext ct of a polynomial with the first scalar value s1 as a constant term. The first secure calculation processing unit 43 stores the second ciphertext in the second data storage unit 44. s1+ The first secure calculation processing unit 43 stores the second ciphertext in the second data storage unit 44.
[0245] The ciphertext conversion processing unit 45D converts the second ciphertext ct stored in the second data storage unit 44 s1+ without decrypting it, using the ciphertext conversion Extract MLWEtoLWE , Convert LWEtoLWE’ to convert it to the third ciphertext ct of the first scalar value s1. The ciphertext conversion processing unit 45D stores the third ciphertext in the third data storage unit 46. When performing ciphertext conversion, the ciphertext conversion processing unit 45D uses the second encryption key pk s1 stored in the encryption key storage unit 51 and the conversion key ksk LWE’ stored in the conversion key storage unit 52. LWEtoLWE’ to utilize.
[0246] The second secure calculation processing unit 47D performs secure calculation on the third ciphertext ct stored in the third data storage unit 46 s1 using the secure multiplication EvalMult LWE’ to calculate the fourth ciphertext ct of the second scalar value s2. The second secure calculation processing unit 47 stores the fourth ciphertext in the fourth data storage unit. s2 The second secure calculation processing unit 47 stores the fourth ciphertext in the fourth data storage unit.
[0247] Note that the hardware configurations of the first terminal device 1D and the secure calculation device 4D are the same as those of the first terminal device 1 and the secure calculation device 4 in the above first embodiment (see FIG. 5).
[0248] <Explanation of the flow> Next, an example of the information processing flow executed by the first terminal device 1D and the confidential computing device 4D in this modification example will be described.
[0249] FIG. 8 is a flowchart showing an example of the information processing flow executed by the first terminal device 1D and the confidential computing device 4D in this modification example. In this modification example, in the same manner as the first terminal device 1 and the confidential computing device 4 in the above first embodiment, the processes of steps S1 to S12 are executed. Further, the information processing executed by the first terminal device 1D and the confidential computing device 4D in this modification example further includes step S13 between step S1 and step S2, and further includes step S14 between step S2 and step S3.
[0250] Specifically, in this modification example, in step S1, the key generation processing unit 11D of the first terminal device 1D generates a public key pk MLWE and a secret key sk MLWE for use in the first homomorphic encryption method. Further, the key generation processing unit 11D generates a public key pk LWE’ and a secret key sk LWE’ for use in the second homomorphic encryption method. Let the secret key used in the first homomorphic encryption method be sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i =sk i,0 +sk i,1 x+…+sk i,n-1 x n-1 , the conversion key ksk LWEtoLWE’ is the ciphertext ksk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ) of sk LWEtoLWE’ =Enc LWE’ (sk LWE ).
[0251] Also, the key generation processing unit 11D uses the public key pk used in the first homomorphic encryption method to be used in the first terminal device 1D as the first encryption key, and the secret key sk used in the second homomorphic encryption method as the first decryption key. Note that the secret key sk used in the first homomorphic encryption method may also be used as the first encryption key. Further, the public key pk used in the second homomorphic encryption method to be used in the secure computing device 4D is used as the second encryption key. MLWE The key generation processing unit 11D stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14. LWE’ In step S13, the transmission unit 25D of the first terminal device 1 transmits the second encryption key pk stored in the encryption key storage unit 12 and the conversion key ksk stored in the conversion key storage unit 14 to the secure computing device 4D. MLWE In step S14, the reception unit 41D of the secure computing device 4D receives the second encryption key pk and the conversion key ksk from the first terminal device 1D, stores the second encryption key in the encryption key storage unit 51, and stores the conversion key in the conversion key storage unit 52. LWE’ In step S3, the encryption processing unit 23D of the first terminal device 1D converts the input data including the first vector u and the second vector v stored in the first data storage unit 22 into polynomials fw(u)=u
[0252] +u
[0253] x+…+u LWE’ x LWEtoLWE’ using the first conversion function fw and the second conversion function bw, respectively.
[0254] bw(v)=v LWE’ -v LWEtoLWE’ x
[0255] -v 0 x 1 -…-v l-1 x l-1 -…-v 0 x 1 -…-v n―1 x 2 -…-v n―2 x l―1 -…-v n-(l―1)Convert it. Then, the encryption processing unit 23D encrypts the above polynomial using the first encryption key pk stored in the encryption key storage unit 12, and calculates the first ciphertext ct u , ct v . The encryption processing unit 23D stores the first ciphertext in the second data storage unit 24. MLWE using the first encryption key pk stored in the encryption key storage unit 12, encrypt the above polynomial, and calculate the first ciphertext ct u , ct v . u , ct v to calculate. The encryption processing unit 23D stores the first ciphertext in the second data storage unit 24.
[0256] Then, in the same manner as in the first embodiment, the processes of steps S3 to S12 are executed.
[0257] However, in step S6, the first secret calculation processing unit 43D of the secret calculation device 4D performs the first secret calculation processing on the first ciphertext ct u , ct v stored in the first data storage unit 42 using the homomorphic multiplication EvalMult MLWE , and calculates the second ciphertext ct s1+ of the polynomial having the first scalar value s1 as the constant term. The first secret calculation processing unit 43D stores the second ciphertext in the second data storage unit 44. u , ct v using the homomorphic multiplication EvalMult MLWE to perform the first secret calculation processing, and calculate the second ciphertext ct s1+ of the polynomial having the first scalar value s1 as the constant term. MLWE to calculate the second ciphertext ct s1+ of the polynomial having the first scalar value s1 as the constant term. The first secret calculation processing unit 43D stores the second ciphertext in the second data storage unit 44. s1+ to calculate. The first secret calculation processing unit 43D stores the second ciphertext in the second data storage unit 44.
[0258] Also, in step S7, the ciphertext conversion processing unit 45D of the secret calculation device 4D converts the second ciphertext ct s1+ stored in the second data storage unit 44 into the third ciphertext ct s1 of the first scalar value s1 without decrypting it, using the ciphertext conversion Extract MLWEtoLWE , Convert LWEtoLWE’ . Then, the ciphertext conversion processing unit 45D stores the third ciphertext in the third data storage unit 46. When calculating the ciphertext conversion, the ciphertext conversion processing unit 45D uses the second encryption key pk LWE’ stored in the encryption key storage unit 51 and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 52. s1+ without decrypting it, using the ciphertext conversion Extract MLWEtoLWE , Convert LWEtoLWE’ to convert it into the third ciphertext ct s1 of the first scalar value s1. MLWEtoLWE , Convert LWEtoLWE’ using to convert it into the third ciphertext ct s1 of the first scalar value s1. s1 to convert. Then, the ciphertext conversion processing unit 45D stores the third ciphertext in the third data storage unit 46. When calculating the ciphertext conversion, the ciphertext conversion processing unit 45D uses the second encryption key pk LWE’ stored in the encryption key storage unit 51 and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 52. LWE’ and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 52. LWEtoLWE’ to use.
[0259] Also, in step S8, the second secret calculation processing unit 47D of the secret calculation device 4D performs the second secret calculation processing on the third ciphertext ct s1 stored in the third data storage unit 46 using the homomorphic multiplication EvalMult LWE’ , and calculates the fourth ciphertext ct of the second scalar value s2 s1 using the homomorphic multiplication EvalMult LWE’ to perform the second secret calculation processing, and calculate the fourth ciphertext ct of the second scalar value s2 LWE’ using to perform the second secret calculation processing, and calculate the fourth ciphertext ct of the second scalar value s2s2 Calculate it. The second secure calculation processing unit 47D stores the fourth ciphertext in the fourth data storage unit.
[0260] Also, in step S11, the decryption processing unit 33D of the first terminal device 1D decrypts the fourth ciphertext stored in the third data storage unit 32 using the first decryption key sk stored in the decryption key storage unit 13, and calculates the second scalar value s2. The decryption processing unit 33D stores the second scalar value in the fourth data storage unit 34. LWE’ Calculate it. The decryption processing unit 33D of the first terminal device 1D decrypts the fourth ciphertext stored in the third data storage unit 32 using the first decryption key sk stored in the decryption key storage unit 13, and calculates the second scalar value s2. The decryption processing unit 33D stores the second scalar value in the fourth data storage unit 34.
[0261] As described above, the ciphertext conversion processing unit 45D of the secure calculation device 4D in this modification uses the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method, similar to the ciphertext conversion processing unit 45 in the above embodiment, to convert the second ciphertext into the third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, in the secure calculation device 4D and the secure calculation system 100D of this modification, even when Module-LWE is used as the first homomorphic encryption method and LWE independent of the ring dimension number of Module-LWE is used as the second homomorphic encryption method, the secrecy can be improved in the same manner as in the first embodiment.
[0262] Also, the secure calculation device 4D and the secure calculation system 100D of this modification can utilize the homomorphic encryption method using Module-LWE, which has higher security performance than the homomorphic encryption method using Ring-LWE.
[0263] In this modification, as shown in FIG. 6, the first terminal device 1D is described as an example having a configuration including a key generation processing unit 11D, an encryption key storage unit 12, a decryption key storage unit 13, a conversion key storage unit 14, an input unit 21, a first data storage unit 22, an encryption processing unit 23D, a second data storage unit 24, a transmission unit 25D, a reception unit 31, a third data storage unit 32, a decryption processing unit 33D, a fourth data storage unit 34, and an output unit 35. However, similar to the first terminal device 1 according to the first embodiment, the first terminal device 1D may have a configuration including some of these units.
[0264] (Second Embodiment) In this embodiment, as an example, a form will be described in which the first homomorphic encryption method is a homomorphic encryption method using Ring-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE.
[0265] Also, in this embodiment, as an example, a form will be described in which the input data includes two polynomials, and each coefficient of these polynomials is an element of a vector.
[0266] Also, in this embodiment, as an example, a form will be described in which the inner product of two vectors is calculated as the first secure calculation process, and the identity operation is calculated as the second secure calculation process.
[0267] The identity operation is an operation in which the original value and the operation result are the same value. That is, in this embodiment, as an example, a form will be described in which nothing is calculated for the original data as the second secure calculation process.
[0268] FIG. 1 is a schematic diagram of an example of the secure calculation system 100E of this embodiment.
[0269] The secure calculation system 100E includes a first terminal device 1E and a secure calculation device 4E. The first terminal device 1E and the secure calculation device 4E are communicably connected via a network 5.
[0270] <Explanation of Secure Calculation Processing Content> First, the content of each secure calculation process of the first secure calculation process and the second secure calculation process in this embodiment will be described.
[0271] In the secure calculation device 4E of this embodiment, similar to the secure calculation device 4 of the first embodiment, as the first secure calculation process, a first vector u = (u 0 , u 1 , …, u l-1 ) of length l and a second vector v = (v 0 , v 1 , …, v l-1) Calculate the inner product of them and output the first scalar value s1 = <u, v>. Also, in the secure computing device 4E, as the second secure computing process, calculate the second scalar value s2 = s1 without changing the value of the first scalar value s1 of the inner product result. In the secure computing device 4E of the present embodiment, similar to the secure computing device 4 of the first embodiment, calculate in a state where the data input to each of these first secure computing process and second secure computing process is encrypted, that is, in a state of remaining ciphertext.
[0272] <Explanation of the homomorphic encryption method and the ciphertext conversion method> In the secure computing device 4E of the present embodiment, in order to perform data input / output between the first secure computing process and the second secure computing process while keeping the data encrypted, the ciphertext is converted using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method.
[0273] In the secure computing device 4E of the present embodiment, as the first homomorphic encryption method, a homomorphic encryption method using Ring-LWE is utilized. In the secure computing device 4E, as the first homomorphic encryption method, a homomorphic encryption method using Ring-LWE with a ring dimension number n is utilized. Also, in the secure computing device 4E, as the second homomorphic encryption method, a homomorphic encryption method using LWE with a vector dimension number d = n is utilized. Also, in the secure computing device 4E, the ciphertext conversion used in the homomorphic encryption method using Ring-LWE with a ring dimension number n and the homomorphic encryption method using LWE with a vector dimension number d = n is utilized.
[0274] <Explanation of the secure computing method> In the secure computing system 100E according to the present embodiment, using the first homomorphic encryption method, the second homomorphic encryption method, and the ciphertext conversion, the first secure computing process and the second secure computing process are securely computed in the following procedure.
[0275] As preparation for homomorphic encryption, the first terminal device 1E generates a secret key sk RLWE and a public key pk RLWE of the first homomorphic encryption method. Also, the first terminal device 1E sets the secret key used in the first homomorphic encryption method as sk RLWE = sk 0+sk 1 x + … + sk n-1 x n-1 When set as such, the secret key of the second homomorphic encryption method is sk LWE =(sk 0 , sk 1 , …, sk n-1 ). The first terminal device 1E uses the public key pk RLWE used in the first homomorphic encryption method as the first encryption key and the secret key sk LWE used in the second homomorphic encryption method as the first decryption key. Note that the secret key sk RLWE used in the first homomorphic encryption method may also be used as the first encryption key.
[0276] The secure computing device 4E uses the first homomorphic encryption method to transform the input data including the first vector u = (u 0 , u 1 , …, u l-1 ) of length l and the second vector v = (v 0 , v 1 , …, v l-1 ) respectively into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 – v 1 x n―1 – v 2 x n―2 – … – v l―1 x n-(l―1) . Note that fw(v) and bw(u) may also be used during the transformation. Then, the secure computing device 4E encrypts the above polynomials using the first encryption key pk RLWE and calculates two first ciphertexts ct u , ct v .
[0277] The secure computing device 4E performs the first secure computing process on the first ciphertexts ct u , ct v using the homomorphic multiplication EvalMult RLWE and calculates the second ciphertext ct s1+ = EvalMult RLWE(ct u , ct v ) is calculated.
[0278] The secure computing device 4E converts the first ciphertext ct s1+ without decrypting it, using the ciphertext conversion Extract RLWEtoLWE to convert the third ciphertext ct s1 of the first scalar value s1 into ct RLWEtoLWE = Extract s1+ (ct s1
[0279] s2 For the third ciphertext ct s1 The secure computing device 4E does nothing as the second secure computing process, and calculates the fourth ciphertext ct s2 of the second scalar s2 = s1 as ct
[0280] The first terminal device 1E decrypts the fourth ciphertext ct LWE of the second scalar value s2 using the first decryption key sk s1 to calculate the second scalar value s2.
[0281] <Description of System Configuration and Functions> Next, the secure computing system 100E of this embodiment will be specifically described.
[0282] FIG. 2 is a functional block diagram of an example of the first terminal device 1E of this embodiment. The functional configuration of the first terminal device 1E is the same as that of the first terminal device 1 of the above first embodiment.
[0283] FIG. 3 is a functional block diagram of an example of the secure computing device 4E of this embodiment.
[0284] The secure computing device 4E is the same as the secure computing device 4 of the above first embodiment, except that it includes a second secure computing processing unit 47E instead of the second secure computing processing unit 47.
[0285] The second secure computing processing unit 47E is the third ciphertext ct stored in the third data storage unit 46 s1Instead of performing any calculations as the second secret calculation process, the third ciphertext ct s1 is calculated as the fourth ciphertext ct of the second scalar value s2 = s1 s2 = ct s1 The second secret calculation processing unit 47F stores the fourth ciphertext in the fourth data storage unit.
[0286] Note that the hardware configurations of the first terminal device 1E and the secret calculation device 4E are the same as those of the first terminal device 1 and the secret calculation device 4 in the above first embodiment (see FIG. 5).
[0287] <Description of the flow> Next, an example of the flow of information processing executed by the first terminal device 1E and the secret calculation device 4E in the present embodiment will be described.
[0288] FIG. 4 is a flowchart showing an example of the flow of information processing executed by the first terminal device 1E and the secret calculation device 4E in the present embodiment. In the present embodiment, the processes of steps S1 to S12 are executed in the same manner as the first terminal device 1 and the secret calculation device 4 in the above first embodiment.
[0289] However, in the present embodiment, in step S8, the second secret calculation processing unit 47E of the secret calculation device 4E does not perform any calculations on the third ciphertext ct stored in the third data storage unit 46 s1 and directly calculates it as the fourth ciphertext ct of the second scalar value s2 = s1 s2 = ct s1 The second secret calculation processing unit 47E stores the fourth ciphertext in the fourth data storage unit.
[0290] As described above, similar to the ciphertext conversion processing unit 45 in the above embodiment, the ciphertext conversion processing unit 45E of the confidential computing device 4E in the present embodiment uses a ciphertext conversion method defined between the first quasi-homomorphic encryption method and the second quasi-homomorphic encryption method to convert the second ciphertext into a third ciphertext encrypted by the second quasi-homomorphic encryption method without decrypting the second ciphertext. Therefore, in the confidential computing device 4E and the confidential computing system 100E in the present embodiment, even when Ring-LWE is used as the first quasi-homomorphic encryption method and LWE is used as the second quasi-homomorphic encryption method, confidentiality can be improved in the same manner as in the first embodiment.
[0291] In addition, the confidential computing device 4E and the confidential computing system 100E in the present embodiment calculate the inner product of two vectors as the first confidential computing process and calculate the identity operation as the second confidential computing process.
[0292] Here, when decrypting the ciphertext obtained by the first confidential computing process, there is a possibility that information may leak from terms other than the constant term. Therefore, it is necessary to perform a masking process on the ciphertext as described in Patent Document 1. On the other hand, in the confidential computing system 100E according to the present embodiment, since the ciphertext in which terms other than the constant term are deleted by the ciphertext conversion other than the constant term is decrypted, the masking process for the ciphertext is unnecessary. Therefore, in the confidential computing system 100E of the present embodiment, in addition to the above effects, the masking process for the ciphertext of the result of the quasi-homomorphic inner product operation can be made unnecessary.
[0293] (Modification Example 1 of the Second Embodiment) In this modification example, a form will be described as an example in which the first quasi-homomorphic encryption method is a quasi-homomorphic encryption method using Module-LWE and the second quasi-homomorphic encryption method is a quasi-homomorphic encryption method using LWE.
[0294] Also, in this modified example, similar to the first embodiment, an example will be described in which the input data includes two polynomials and the coefficients of each of these polynomials are elements of a vector. Also, in this modified example, similar to the second embodiment, an example will be described in which the inner product of two vectors is calculated as the first secure calculation process and the identity operation is calculated as the second secure calculation process.
[0295] FIG. 1 is a schematic diagram of an example of the secure calculation system 100F of this modified example.
[0296] The secure calculation system 100F includes a first terminal device 1F and a secure calculation device 4F. The first terminal device 1F and the secure calculation device 4F are communicably connected via a network 5.
[0297] <Explanation of Secure Calculation Processing Content> First, the content of each of the first secure calculation process and the second secure calculation process in this modified example will be described.
[0298] In the secure calculation device 4F of this modified example, similar to the secure calculation device 4 of the first embodiment, as the first secure calculation process, the inner product of a first vector u = (u 0 , u 1 , …, u l-1 ) of length l and a second vector v = (v 0 , v 1 , …, v l-1 ) of length l is calculated, and a first scalar value s1 = <u, v> is output. Also, in the secure calculation device 4F, as the second secure calculation process, the scalar value s1 of the inner product result is calculated as the second scalar value s2 = s1 without changing the value. In the secure calculation device 4F of this modified example, similar to the secure calculation device 4 of the first embodiment, the data input to each of these first secure calculation process and second secure calculation process is calculated in a state where it is encrypted, that is, in the state of ciphertext.
[0299] <Explanation of Homomorphic Encryption Method and Ciphertext Conversion Method> In the secret calculation device 4F of this modification example, in order to perform data input / output between the first secret calculation process and the second secret calculation process while keeping the data encrypted, the ciphertext is converted using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method.
[0300] In the secret calculation device 4F of this modification example, a homomorphic encryption method using Module-LWE is used as the first homomorphic encryption method. Also, in the secret calculation device 4F, a homomorphic encryption method using LWE is used as the second homomorphic encryption method. Further, in the secret calculation device 4F, the ciphertext conversion used in the homomorphic encryption method using Module-LWE and the homomorphic encryption method using LWE is utilized.
[0301] <Explanation of the secret calculation method> In the secret calculation system according to this modification example, the first secret calculation process and the second secret calculation process are secretly calculated in the following procedure using the first homomorphic encryption method, the second homomorphic encryption method, and ciphertext conversion.
[0302] In the first terminal device 1F, as preparation for homomorphic encryption, the secret key sk MLWE and the public key pk MLWE of the first homomorphic encryption method are generated. Also, the first terminal device 1D sets the secret key used in the first homomorphic encryption method as sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i =sk i,0 +sk i,1 x+…+sk i,n-1 x n-1 , the secret key of the second homomorphic encryption method is sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ).
[0303] The first terminal device 1F uses the public key pk used in the first homomorphic encryption method MLWE as the first encryption key and the secret key sk used in the second homomorphic encryption method LWE as the first decryption key. Note that the secret key sk used in the first homomorphic encryption method MLWE may also be used as the first encryption key.
[0304] The secure computing device 4F uses the first homomorphic encryption method to process the input data including the first vector u = (u 0 , u 1 , …, u l-1 ) of length l and the second vector v = (v 0 , v 1 , …, v l-1 ) through the first transformation function fw and the second transformation function bw into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 − v 1 x n―1 − v 2 x n―2 − … − v l―1 x n-(l―1) . Note that fw(v) and bw(u) may also be used during the transformation. Then, the secure computing device 4F encrypts the above polynomials using the first encryption key pk MLWE and calculates two first ciphertexts ct u , ct v .
[0305] The secure computing device 4F performs the first secure computing process on the first ciphertexts ct u , ct v using the homomorphic multiplication EvalMult MLWE of the first homomorphic encryption method and calculates the second ciphertext ct s1+ = EvalMult MLWE (ct u , ct v ) of the polynomial with the first scalar value s1 = <u, v> as the constant term.
[0306] The secure computing device 4F processes the second ciphertext ct s1+Convert the ciphertext transformation Extract without decrypting MLWEtoLWE Using MLWEtoLWE , convert the third ciphertext ct of the first scalar value s1 s1 = Extract MLWEtoLWE (ct s1+ ) into.
[0307] The anonymization calculation device 4F does nothing as the second anonymization calculation process for the third ciphertext ct s1 and calculates it as the fourth ciphertext ct of the second scalar s2 = s1 s2 = ct s1 .
[0308] The first terminal device 1F decrypts the fourth ciphertext ct of the second scalar value s2 s2 using the first decryption key sk LWE and calculates the second scalar value s2.
[0309] <Description of System Configuration and Functions> Next, the anonymization calculation system 100B of this modification example will be specifically described.
[0310] FIG. 2 is a functional block diagram of an example of the first terminal device 1F of this modification example. The functional configuration of the first terminal device 1F is the same as that of the first terminal device 1 of the above first embodiment.
[0311] FIG. 3 is a functional block diagram of an example of the anonymization calculation device 4F of this modification example.
[0312] The anonymization calculation device 4F is the same as the anonymization calculation device 4 of the above first embodiment except that it includes a second anonymization calculation processing unit 47F instead of the second anonymization calculation processing unit 47.
[0313] The second anonymization calculation processing unit 47F does not perform any calculation as the second anonymization calculation process on the third ciphertext ct s1 stored in the third data storage unit 46, and calculates the third ciphertext ct s1 as the fourth ciphertext ct of the second scalar value s2 = s1 s2 = ct s1 . The second anonymization calculation processing unit 47F stores the fourth ciphertext in the fourth data storage unit.
[0314] Note that the hardware configurations of the first terminal device 1F and the secure computing device 4F are the same as those of the first terminal device 1 and the secure computing device 4 in the above first embodiment (see Fig. 5).
[0315] <Description of the flow> Next, an example of the information processing flow executed by the first terminal device 1F and the secure computing device 4F in this modified example will be described.
[0316] Fig. 4 is a flowchart showing an example of the information processing flow executed by the first terminal device 1F and the secure computing device 4F in this modified example. In this modified example, the processes of steps S1 to S12 are executed in the same manner as the first terminal device 1 and the secure computing device 4 in the above first embodiment.
[0317] However, in this modified example, in step S8, the second secure computing processing unit 47F of the secure computing device 4F does not perform any calculation as the second secure computing process on the third ciphertext ct stored in the third data storage unit 46, and directly calculates the fourth ciphertext ct s1 where the second scalar value s2 = s1 as ct s2 = ct s1 The second secure computing processing unit 47F stores the fourth ciphertext in the fourth data storage unit.
[0318] As described above, the ciphertext conversion processing unit 45F of the secure computing device 4F in this modified example uses the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method, similar to the ciphertext conversion processing unit 45 in the above embodiment, to convert the second ciphertext into the third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, in the secure computing device 4F and the secure computing system 100F of this modified example, even when using Module-LWE as the first homomorphic encryption method and LWE as the second homomorphic encryption method, the secrecy can be improved in the same manner as in the above first embodiment.
[0319] In addition, in the secure computing device 4F and the secure computing system 100F of this modification example, as the first homomorphic encryption method, it is possible to use a homomorphic encryption method using Module-LWE, which has higher security performance than Ring-LWE.
[0320] In addition, the secure computing device 4F and the secure computing system 100F of this modification example calculate the inner product of two vectors as the first secure computing process, and calculate the identity operation as the second secure computing process.
[0321] Therefore, in the secure computing system 100F of this modification example, in addition to the above effects, it is possible to eliminate the need for masking processing on the ciphertext of the result of the homomorphic inner product operation.
[0322] (Modification Example 2 of the Second Embodiment) In this modification example, as an example, a form will be described in which the first homomorphic encryption method is a homomorphic encryption method using Ring-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE that does not depend on the ring dimension number of Ring-LWE.
[0323] In addition, in this modification example, as in the first embodiment, a form will be described as an example in which the input data includes two polynomials, and the coefficients of each of these polynomials are elements of a vector. In addition, in this modification example, as in the second embodiment, a form will be described as an example in which the inner product of two vectors is calculated as the first secure computing process, and the identity operation is calculated as the second secure computing process.
[0324] FIG. 1 is a schematic diagram of an example of the secure computing system 100G of this modification example.
[0325] The secure computing system 100G includes a first terminal device 1G and a secure computing device 4G. The first terminal device 1G and the secure computing device 4G are communicably connected via a network 5.
[0326] <Explanation of Secure Computing Process Content> First, the content of each confidential calculation process of the first confidential calculation process and the second confidential calculation process in this modified example will be described.
[0327] In the confidential calculation device 4G of this modified example, similar to the confidential calculation device 4 of the first embodiment, as the first confidential calculation process, for the first vector u = (u 0 , u 1 , …, u l-1 ) of length l and the second vector v = (v 0 , v 1 , …, v l-1 ) of length l, the inner product is calculated, and the first scalar value s1 = <u, v> is output. Also, in the confidential calculation device 4G, as the second confidential calculation process, the scalar value s1 of the inner product result is calculated as the second scalar value s2 = s1 without changing the value. In the confidential calculation device 4G of this modified example, similar to the confidential calculation device 4 of the first embodiment, the data input to each of these first confidential calculation processes and second confidential calculation processes is calculated in a state where it is encrypted, that is, in the state of being a ciphertext.
[0328] <Explanation of the homomorphic encryption method and the ciphertext conversion method> In the confidential calculation device 4G of this modified example, in order to perform data input / output between the first confidential calculation process and the second confidential calculation process while keeping the data encrypted, the ciphertext is converted using the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method.
[0329] In the confidential calculation device 4G of this modified example, as the first homomorphic encryption method, a homomorphic encryption method using Ring-LWE with a ring dimension number n is used. Also, in the confidential calculation device 4G, as the second homomorphic encryption method, a homomorphic encryption method using LWE with a vector dimension number d’ ≠ n is used. Also, in the confidential calculation device 4G, the ciphertext conversion method between the homomorphic encryption method using Ring-LWE with a ring dimension number n and the homomorphic encryption method using LWE with a vector dimension number d’ is used.
[0330] <Explanation of the confidential calculation method> In the secure computing system 100G according to this modification example, the first homomorphic encryption method, the second homomorphic encryption method, and ciphertext conversion are used to perform the first secure computing process and the second secure computing process in the following procedure in a secure manner.
[0331] As preparation for homomorphic encryption, the first terminal device 1G generates a secret key sk RLWE and a public key pk RLWE of the first homomorphic encryption method. Also, the first terminal device 1G generates a secret key sk LWE’ and a public key pk LWE’ of the second homomorphic encryption method. Further, the first terminal device 1G sets the secret key used in the first homomorphic encryption method as sk RLWE =sk 0 +sk 1 x+…+sk n-1 x n-1 And the conversion key ksk LWEtoLWE’ is the ciphertext of sk LWE =(sk 0 ,sk 1 ,…,sk n-1 ) encrypted using the second homomorphic encryption method, ksk LWEtoLWE’ =Enc LWE’ (sk LWE ).
[0332] The first terminal device 1G uses the public key pk RLWE used in the first homomorphic encryption method as the first encryption key, and the secret key sk LWE’ used in the second homomorphic encryption method as the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may also be used as the first encryption key. Also, the first terminal device 1G uses the public key pk LWE’ used in the second homomorphic encryption method as the second encryption key.
[0333] The first terminal device 1G uses the first homomorphic encryption method to generate a first vector u of length l, u=(u 0 ,u 1 ,…,u l-1 ) and a second vector v=(v 0 ,v 1 ,…,v l-1Input data including 0 +u 1 x+…+u l-1 x l-1 is converted by the first conversion function fw and the second conversion function bw into polynomials fw(u)=u 0 ―v 1 x n―1 ―v 2 x n―2 ―…―v l―1 x n-(l―1) respectively. Note that fw(v) and bw(u) may also be used during the conversion. Then, the first terminal device 1G encrypts the above polynomials using the first encryption key pk RLWE and calculates two first ciphertexts ct u , ct v .
[0334] The secure computing device 4G performs first secure computing processing on the first ciphertexts ct u , ct v using the homomorphic multiplication EvalMult RLWE and calculates a second ciphertext ct s1+ =EvalMult RLWE (ct u , ct v ) of a polynomial with the first scalar value s1 = <u, v> as the constant term.
[0335] The secure computing device 4G, without decrypting the second ciphertext ct s1+ , uses the ciphertext conversion Extract RLWEtoLWE , Convert LWEtoLWE’ , the conversion key ksk LWEtoLWE’ , and the second encryption key pk LWE’ to convert it into a third ciphertext ct s1 =Convert LWEtoLWE’ (Extract LWEtoLWE (ct s1+ )) of the first scalar value s1.
[0336] The secure computing device 4G does nothing in the second secure computing process and calculates the third ciphertext as the fourth ciphertext ct s2 =ct s1 of the second scalar s2 = s1.
[0337] The first terminal device 1G decrypts the fourth ciphertext ct of the second scalar value s2 s2 using the first decryption key sk LWE’ to calculate the second scalar value s2.
[0338] <Description of System Configuration and Functions> Next, the secure calculation system 100G of this modification example will be specifically described.
[0339] FIG. 6 is a functional block diagram of an example of the first terminal device 1G of this modification example. The functional configuration of the first terminal device 1G is the same as that of the first terminal device 1C in Modification Example 2 of the above first embodiment.
[0340] FIG. 7 is a functional block diagram of an example of the secure calculation device 4G of this modification example.
[0341] The secure calculation device 4G is the same as the secure calculation device 4C in Modification Example 2 of the above first embodiment, except that it includes a second secure calculation processing unit 47G instead of the second secure calculation processing unit 47C.
[0342] The second secure calculation processing unit 47G does not perform any calculation as the second secure calculation processing on the third ciphertext ct stored in the third data storage unit 46, and uses the third ciphertext ct s1 as the fourth ciphertext ct of the second scalar value s2 = s1 s1 = ct s2 = ct s1 to calculate. The second secure calculation processing unit 47G stores the fourth ciphertext in the fourth data storage unit.
[0343] Note that the hardware configurations of the first terminal device 1G and the secure calculation device 4G are the same as those of the first terminal device 1 and the secure calculation device 4 in the above first embodiment (see FIG. 5).
[0344] <Description of Flow> Next, an example of the information processing flow executed by the first terminal device 1G and the secure calculation device 4G of this modification example will be described.
[0345] FIG. 8 is a flowchart showing an example of the flow of information processing executed by the first terminal device 1G and the secure calculation device 4G of this modified example. In this modified example, the processing of steps S1 to S12 is executed in the same manner as the first terminal device 1 and the secure calculation device 4 of the first embodiment. Further, the information processing executed by the first terminal device 1G and the secure calculation device 4G of this modified example further includes step S13 between step S1 and step S2, and further includes step S14 between step S2 and step S3. The processing of step S13, step S2, step S14, and step S3 is the same as that of the first terminal device 1C and the secure calculation device 4C of the modified example 2 of the first embodiment described above.
[0346] However, in this modified example, in step S8, the second secure calculation processing unit 47G of the secure calculation device 4F does not perform any calculation on the third ciphertext ct stored in the third data storage unit 46, and directly uses the second scalar value s2 = s1 as the fourth ciphertext ct s1 = ct s2 and calculates it. The second secure calculation processing unit 47G stores the fourth ciphertext in the fourth data storage unit. s1 As described above, the ciphertext conversion processing unit 45G of the secure calculation device 4G of this modified example uses the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method, similar to the ciphertext conversion processing unit 45 of the above embodiment, to convert the second ciphertext into the third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, in the secure calculation device 4G and the secure calculation system 100G of this modified example, even when Ring-LWE is used as the first homomorphic encryption method and LWE independent of the ring dimension of Ring-LWE is used as the second homomorphic encryption method, the secrecy can be improved in the same manner as in the first embodiment.
[0347]
[0348] Further, the secure calculation device 4G and the secure calculation system 100G of this modified example calculate the inner product of two vectors as the first secure calculation process and calculate the identity operation as the second secure calculation process.
[0349] Therefore, in the secret calculation system 100G of this modified example, in addition to the above effects, it is possible to eliminate the need for masking processing on the ciphertext of the result of the homomorphic inner product operation.
[0350] (Modified Example 3 of the Second Embodiment) In this modified example, as an example, a form will be described in which the first homomorphic encryption method is a homomorphic encryption method using Module-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE that does not depend on the ring dimension number of Module-LWE.
[0351] Also, in this modified example, similar to the first embodiment above, a form will be described as an example in which the input data includes two polynomials, and the coefficients of each of these polynomials are elements of a vector. Also, in this modified example, similar to the first embodiment above, a form will be described as an example in which the inner product of two vectors is calculated as the first secret calculation process. Also, in this modified example, similar to the second embodiment above, a form will be described as an example in which the inner product of two vectors is calculated as the first secret calculation process, and the identity operation is calculated as the second secret calculation process.
[0352] FIG. 1 is a schematic diagram of an example of the secret calculation system 100H of this modified example.
[0353] The secret calculation system 100H includes a first terminal device 1H and a secret calculation device 4H. The first terminal device 1H and the secret calculation device 4H are communicably connected via a network 5.
[0354] <Explanation of Secret Calculation Processing Content> First, the content of each secret calculation process of the first secret calculation process and the second secret calculation process in this modified example will be described.
[0355] In the secret calculation device 4H of this modified example, similar to the secret calculation device 4 of the first embodiment above, as the first secret calculation process, a first vector u = (u 0 , u 1 , …, u l-1) and the inner product with the second vector v of length l, v = (v 0 , v 1 , …, v l-1 ) is calculated, and the first scalar value s1 = <u, v> is output. Also, in the secret calculation device 4H, as the second secret calculation process, the scalar value s1 of the inner product result is calculated as the second scalar value s2 = s1 without changing the value. In the secret calculation device 4H of this modification example, similar to the secret calculation device 4 of the first embodiment, the data input to each of these first secret calculation process and second secret calculation process is calculated in a state where it is encrypted, that is, in the state of ciphertext.
[0356] <Explanation of the homomorphic encryption method and the ciphertext conversion method> In the secret calculation device 4H of this modification example, in order to perform data input / output between the first secret calculation process and the second secret calculation process while keeping the data encrypted, the ciphertext is converted using the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method.
[0357] In the secret calculation device 4H of this modification example, as the first homomorphic encryption method, a homomorphic encryption method using Module-LWE with a ring dimension number n ≠ 1 and a vector dimension number k is used. Also, in the secret calculation device 4D of this modification example, as the second homomorphic encryption method, a homomorphic encryption method using LWE with a vector dimension number d' is used. Further, in the secret calculation device 4H, ciphertext conversion between the homomorphic encryption method using Module-LWE with a ring dimension number n and the homomorphic encryption method using LWE with a vector dimension number d' is utilized.
[0358] <Explanation of the secret calculation method> The secret calculation system 100H of this modification example performs the first secret calculation process and the second secret calculation process in the following procedure using the first homomorphic encryption method, the second homomorphic encryption method, and the ciphertext conversion.
[0359] As preparation for the homomorphic encryption, the first terminal device 1H generates the secret key sk MLWE and the public key pk MLWE of the first homomorphic encryption method. Also, the first terminal device 1 generates the secret key sk of the second homomorphic encryption method.LWE’ Generate it. Also, the first terminal device 1 uses the secret key sk used in the first homomorphic encryption method MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i = sk i,0 + sk i,1 x + … + sk i,n-1 x n-1 , the conversion key ksk LWEtoLWE’ is the ciphertext of sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ) encrypted using the second homomorphic encryption method, ksk LWEtoLWE’ = Enc LWE’ (sk LWE ).
[0360] The first terminal device 1H uses the public key pk used in the first homomorphic encryption method MLWE as the first encryption key and the secret key sk used in the second homomorphic encryption method LWE’ as the first decryption key. In addition, the public key sk MLWE used in the first homomorphic encryption method may be used as the first encryption key. Also, the first terminal device 1 uses the public key pk LWE’ used in the second homomorphic encryption method as the second encryption key.
[0361] The first terminal device 1H uses the first homomorphic encryption method to process the input data including the first vector u = (u 0 , u 1 , …, u l-1 ) of length l and the second vector v = (v 0 , v 1 , …, v l-1 ) through the first transformation function fw and the second transformation function bw to obtain the polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v0 -v 1 x n―1 -v 2 x n―2 -…-v l―1 x n-(l―1) Convert them. Note that fw(v) and bw(u) may be used during the conversion.
[0362] Then, the first terminal device 1H encrypts each of the above polynomials using the first encryption key pk MLWE and calculates two first ciphertexts ct u , ct v .
[0363] The secure computing device 4H performs first secure computing processing on the first ciphertexts ct u , ct v using the homomorphic multiplication EvalMult MLWE that functions as a homomorphic inner product operation of the first homomorphic encryption method, and calculates the second ciphertext ct s1+ =EvalMult MLWE (ct u , ct v ) of the polynomial with the first scalar value s1 = <u, v> as the constant term.
[0364] The secure computing device 4H, without decrypting the second ciphertext ct s1+ , uses the ciphertext conversion Extract MLWEtoLWE and Convert LWEtoLWE’ , the conversion key ksk LWEtoLWE’ , and the second encryption key pk LWE’ to convert it into the third ciphertext ct s1 =Convert LWEtoLWE’ (Extract MLWEtoLWE (ct s1+ )) of the first scalar value s1.
[0365] In the second secure computing process, the secure computing device 4H does nothing and calculates the third ciphertext as the ciphertext ct s2 =ct s1 of the second scalar s2 = s1 encrypted by the second homomorphic encryption method.
[0366] The first terminal device 1H decrypts the fourth ciphertext ct of the second scalar value s2 s2 using the first decryption key sk LWE’ to calculate the second scalar value s2.
[0367] <Description of System Configuration and Functions> Next, the secret calculation system 100H of this modified example will be specifically described.
[0368] FIG. 6 is a functional block diagram of an example of the first terminal device 1H of this modified example. The functional configuration of the first terminal device 1H is the same as that of the first terminal device 1C in the second modification of the first embodiment.
[0369] FIG. 7 is a functional block diagram of an example of the secret calculation device 4H of this modified example.
[0370] The secret calculation device 4H is the same as the secret calculation device 4C in the second modification of the second embodiment, except that it includes a second secret calculation processing unit 47H instead of the second secret calculation processing unit 47C.
[0371] The second secret calculation processing unit 47H does not perform any calculation as the second secret calculation processing on the third ciphertext ct s1 stored in the third data storage unit 46, and calculates the third ciphertext ct s1 as the fourth ciphertext ct of the second scalar value s2 = s1 s2 = ct s1 The second secret calculation processing unit 47H stores the fourth ciphertext in the fourth data storage unit.
[0372] Note that the hardware configurations of the first terminal device 1H and the secret calculation device 4H are the same as those of the first terminal device 1 and the secret calculation device 4 in the first embodiment (see FIG. 5).
[0373] <Description of Flow> Next, an example of the information processing flow executed by the first terminal device 1H and the secret calculation device 4H of this modified example will be described.
[0374] FIG. 8 is a flowchart showing an example of the flow of information processing executed by the first terminal device 1H and the secure calculation device 4H of this modified example. In this modified example, the processes of steps S1 to S12 are executed in the same manner as the first terminal device 1 and the secure calculation device 4 of the above-described first embodiment. Further, the information processing executed by the first terminal device 1H and the secure calculation device 4H of this modified example further includes step S13 between step S1 and step S2, and further includes step S14 between step S2 and step S3. The processes of step S13, step S2, step S14, and step S3 are the same as those of the first terminal device 1C and the secure calculation device 4C of the modified example 2 of the first embodiment described above.
[0375] However, in this modified example, in step S8, the second secure calculation processing unit 47H of the secure calculation device 4H does not perform any calculation as the second secure calculation processing on the third ciphertext ct stored in the third data storage unit 46, and directly uses the fourth ciphertext ct with the second scalar value s2 = s1 s1 to calculate as ct s2 = ct s1 The second secure calculation processing unit 47H stores the fourth ciphertext in the fourth data storage unit.
[0376] As described above, the ciphertext conversion processing unit 45H of the secure calculation device 4H of this modified example, similar to the ciphertext conversion processing unit 45 of the above embodiment, uses the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method to convert the second ciphertext into the third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, in the secure calculation device 4H and the secure calculation system 100H of this modified example, even when Module-LWE is used as the first homomorphic encryption method and LWE independent of the ring dimension number of Module-LWE is used as the second homomorphic encryption method, the secrecy can be improved in the same manner as in the first embodiment.
[0377] In addition, the secure calculation device 4H and the secure calculation system 100H of this modified example can utilize a homomorphic encryption method using Module-LWE, which has higher security performance than the homomorphic encryption method using Ring-LWE.
[0378] Also, the secret computing device 4H and the secret computing system 100H of this modified example calculate the inner product of two vectors as the first secret computing process and calculate the identity operation as the second secret computing process.
[0379] Therefore, in the secret computing system 100H of this modified example, in addition to the above effects, it is possible to eliminate the need for masking processing on the ciphertext of the result of the homomorphic inner product operation.
[0380] (Third Embodiment) In this embodiment, as a more specific calculation process, a form in which a secret computing system is applied to genome-wide association study (GWAS), which is one of the methods for analyzing genomic data, will be described.
[0381] GWAS is one of the genomic analysis processes. GWAS is a calculation process that uses, as input data, single nucleotide polymorphism (SNP) data of multiple people and trait data representing the presence or absence of a certain disease, etc., and outputs a statistic representing the degree of association between SNPs and traits. GWAS has a step of calculating an allele frequency table and a step of testing the allele frequency table. The allele frequency table is an example of a cross-tabulation table.
[0382] By using the GWAS calculation method described in Non-Patent Document 1, GWAS can be calculated by a first secret computing process that takes two vectors as input and outputs three scalar values, and a second secret computing process that takes the data obtained by the first secret computing process as input and outputs at least one scalar value.
[0383] FIG. 9 is a schematic diagram of an example of the secret computing system 100I of this embodiment.
[0384] The confidential computing system 100I includes a first terminal device 1I, a second terminal device 6I, and a confidential computing device 4I. The first terminal device 1I, the second terminal device 6I, and the confidential computing device 4I are communicably connected via a network 5. The confidential computing system 100I includes the first terminal device 1I and the second terminal device 6I instead of the first terminal device 1 in the first embodiment. Further, the confidential computing system 100I includes a confidential computing device 4I instead of the confidential computing device 4 in the first embodiment. Details of each device will be described later.
[0385] The confidential computing system 100I may have a configuration including one or more first terminal devices 1I and one or more second terminal devices 6I, and is not limited to a configuration including one first terminal device 1I and one second terminal device 6I. Further, the confidential computing system 100I may have a configuration including one or more confidential computing devices 4I, and is not limited to a configuration including one confidential computing device 4I.
[0386] <Explanation of GWAS calculation content> In the GWAS calculated by the confidential computing system 100I according to the present embodiment, the input data is single nucleotide polymorphism (SNP) data and trait data representing the presence or absence of a certain disease, for example.
[0387] When each of X and Y is a symbol representing any one of the base types A, G, C, and T, the SNP data per person is given as either XX, XY, or YY. Further, the SNP data per person can be represented as 2, 1, or 0 according to the count of the number of Xs. At this time, the SNP data of one person can be represented as a first vector u = (u 0 , u 1 , …, u l-1 ) of length l.
[0388] Also, the trait data per person representing the presence or absence of a certain disease can be represented as 1 if having the disease and 0 if not having the disease. At this time, the trait data of l people can be represented as a second vector v = (v 0 , v 1 , …, v l-1) can be represented as
[0389] In the step of calculating the allele frequency table, the first vector u and the second vector v are used as input data, and a scalar value a representing the total number of base types X of all individuals with the disease, a scalar value b representing the total number of base types Y of all individuals with the disease, a scalar value c representing the total number of base types X of all individuals without the disease, and a scalar value d representing the total number of base types Y of all individuals without the disease are output.
[0390] Also, a scalar value n1 of the addition result of the scalar value a and the scalar value c, a scalar value n2 of the addition result of the scalar value a and the scalar value b, a scalar value n3 of the addition result of the scalar value c and the scalar value d, and a scalar value n4 of the addition result of the scalar value b and the scalar value d may be calculated. Further, a scalar value n of the addition result of the scalar value a, the scalar value b, the scalar value c, and the scalar value d may be calculated. Note that the scalar value n has a relationship of being twice the vector length l of the input data. Thereby, the allele frequency table described in Table 1 is obtained.
[0391]
Table 1
[0392] Using the calculation method of GWAS described in Non-Patent Document 1, the scalar value a, the scalar value b, the scalar value c, the scalar value d, the scalar value n1, the scalar value n2, the scalar value n3, and the scalar value n4 can be calculated by the following formula (6).
[0393] a = <u, v> n1 = <u, 1> n2_ = <v, 1> n2 = 2 × n2_ n3 = n - n2 n4 = n - n1 b = n2 - a c = n1 - a d = n3 - c n = n1 + n4 ··· Equation (6)
[0394] In the step of testing the allergy frequency table, a chi-square test is calculated with the scalar values a, b, c, d, n1, n2, n3, n4, and n representing the allergy frequency table as inputs, and a scalar value Xsq representing the statistic is output. The scalar value Xsq can be calculated by the following equation (7).
[0395] Xsq = (a + b + c + d) × (a × d - b × c) 2 / ((a + b) × (a + c) × (b + d) × (c + d)) = n × (a × d - b × c) 2 / (n1 × n2 × n3 × n4) ··· Equation (7)
[0396] The above equation (7) corresponds to equation (A) of the present application and is an equation representing a chi-square test.
[0397] Hereinafter, let the scalar value representing the numerator of the scalar value Xsq be Xsq1, and the scalar value representing the denominator of the scalar value Xsq be Xsq2.
[0398] In the first secure calculation process of the secure calculation system 100I of the present embodiment, a second ciphertext is calculated in which the plaintext of the scalar value representing the element of the allergy frequency table (cross-tabulation table) aggregated by the first secure calculation process for the first ciphertext obtained by encrypting the plaintext including the vector is encrypted. Specifically, in the first secure calculation process, a first vector u = (u 0 , u 1 , …, u l-1 ) of length l representing SNP data and a second vector v = (v 0 , v 1 , …, v l-1Taking the vector length l and [the vector] as input data, a scalar value a, a scalar value n1, and a scalar value n2_ representing half of the scalar value n2 are output as the second ciphertext. In the case of the allergy frequency table shown in Table 1, in the first privacy calculation process, a second ciphertext in which the plaintext of the scalar value representing the element of the 2x2 allergy frequency table (cross-tabulation table) aggregated by the first privacy calculation process for the first ciphertext obtained by encrypting the plaintext including the vector is calculated.
[0399] Also, in the ciphertext conversion process of the privacy calculation system of the present embodiment, the second ciphertext is converted into a third ciphertext in which the plaintext of the scalar value representing the element of the allergy frequency table (cross-tabulation table) encrypted by the second homomorphic encryption method is encrypted. In the case of the allergy frequency table shown in Table 1, in the ciphertext conversion process, the second ciphertext is converted into a third ciphertext in which the plaintext of the scalar value representing the element of the 2x2 allergy frequency table (cross-tabulation table) encrypted by the second homomorphic encryption method is encrypted.
[0400] Also, in the second privacy calculation process of the privacy calculation system 100I of the present embodiment, a fourth ciphertext in which the plaintext of the scalar value representing the test result of the allergy frequency table (cross-tabulation table) is encrypted is calculated by the second privacy calculation process for the third ciphertext. In the case of the allergy frequency table shown in Table 1, in the second privacy calculation process, a fourth ciphertext in which the plaintext of the scalar value representing the chi-square test result of the 2x2 allergy frequency table (cross-tabulation table) is encrypted is calculated by the second privacy calculation process for the third ciphertext. Specifically, in the second privacy calculation process, the scalar value a, which is the output of the first privacy calculation process, the scalar value n1, the scalar value n2_, and a scalar value n representing twice the vector length l are input, and a scalar value Xsq1 and a scalar value Xsq2 are output.
[0401] In the present embodiment, calculations are performed while keeping the data input to each of the first privacy calculation process and the second privacy calculation process confidential. Hereinafter, the scalar value a is the first scalar value, the scalar value n1 is the second scalar value, the scalar value n2_ is the third scalar value, the scalar value Xsq1 is the fourth scalar value, and the scalar value Xsq2 is the fifth scalar value.
[0402] In this embodiment, the fourth scalar value Xsq1 and the fifth scalar value Xsq2 are calculated, but the scalar value Xsq = Xsq1 / Xsq2 may also be calculated. By calculating a comparison operation or the like with the fourth scalar value Xsq1 and the fifth scalar value Xsq2 as inputs, a binary value indicating the presence or absence of the correlation between the SNP data and the trait data may be output. Also, in this embodiment, by disclosing the vector length l, a scalar value n representing twice the vector length l is disclosed and calculated, but this may be calculated in a concealed manner. In this embodiment, a chi-square test is calculated as an example, but as other tests, for example, a Fisher's exact test may be calculated.
[0403] <Explanation of the homomorphic encryption method and the ciphertext conversion method> In the concealed calculation device of this embodiment, in order to perform data input / output between the first concealed calculation process and the second concealed calculation process while keeping the data concealed, the ciphertext is converted using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method.
[0404] In the concealed calculation device 4I of this embodiment, as the first homomorphic encryption method, a homomorphic encryption method using Ring-LWE is utilized. Also, in the concealed calculation device 4I, as the second homomorphic encryption method, a homomorphic encryption method using LWE is utilized. Also, in the concealed calculation device 4I, the ciphertext conversion used in the homomorphic encryption method using LWE using Ring-LWE is utilized.
[0405] Note that the first homomorphic encryption method and the second homomorphic encryption method are examples. The concealed calculation device 4I may utilize a homomorphic encryption that can encrypt the plaintext of a polynomial and can define homomorphic operations regarding polynomial multiplication and polynomial addition as the first homomorphic encryption method. However, the polynomial is a polynomial whose coefficients are elements of a vector. Also, the concealed calculation device 4I may utilize a homomorphic encryption that can encrypt a scalar value, can utilize homomorphic multiplication and homomorphic multiplication, and furthermore, a ciphertext conversion can be defined between the first homomorphic encryption method as the second homomorphic encryption method.
[0406] <Explanation of the concealed calculation method for GWAS> The secret computing system 100I according to this embodiment uses a first homomorphic encryption method, a second homomorphic encryption method, and ciphertext conversion to perform first secret computing processing and second secret computing processing in the following procedures in a secret manner.
[0407] As preparation for homomorphic encryption, the first terminal device 1I generates a secret key sk RLWE and a public key pk RLWE of the first homomorphic encryption method. Also, when the secret key used in the first homomorphic encryption method is sk RLWE =sk 0 +sk 1 x+…+sk n-1 x n-1 the secret key of the second homomorphic encryption method is sk LWE =(sk 0 ,sk 1 ,…,sk n-1 ). The public key pk RLWE used in the first homomorphic encryption method is used as the first encryption key, and the secret key sk LWE used in the second homomorphic encryption method is used as the first decryption key.
[0408] The first terminal device 1I and the second terminal device 6I use the first homomorphic encryption method to transform the input data of each of the first vector u=(u 0 ,u 1 ,…,u l-1 ) of length l and the second vector v=(v 0 ,v 1 ,…,v l-1 ) into polynomials fw(u)=u 0 +u 1 x+…+u l-1 x l-1 , bw(v)=v 0 ―v 1 x n―1 ―v 2 x n―2 ―…―v l―1 x n-(l―1) using the first transformation function fw and the second transformation function bw. Note that fw(v) and bw(u) may also be used during the transformation. Then, the first terminal device 1I and the second terminal device 6I encrypt the above polynomials using the first encryption key pk RLWE respectively, and obtain two first ciphertexts ctu , ct v is calculated.
[0409] The secure computing device 4I uses the first ciphertext ct u , ct v and performs the first secure computing process according to the following formula (8) using the homomorphic multiplication EvalMult RLWE . Through this process, the secure computing device 4I obtains the second ciphertext ct a+ of a polynomial with the first scalar value a encrypted by the first homomorphic encryption method as the constant term, the second ciphertext ct n1+ of a polynomial with the second scalar value n1 as the constant term, and the second ciphertext ct n2_+ of a polynomial with the third scalar value n2_ as the constant term.
[0410] ct a+ = EvalMult RLWE (ct u , ct v ) ct n1+ = EvalMult RLWE (ct u , bw(1)) ct n2_+ = EvalMult RLWE (fw(1), ct v ) ····· Formula (8)
[0411] Note that bw(1) and fw(1) described in Formula (8) are obtained by converting the all-1 vector (1, 1,..., 1) of length l into polynomials fw(1) = 1 + 1x +... + 1x l-1 , bw(1) = 1 - x n―1 - x n―2 - … - x n-(l―1) using two conversion functions fw and bw.
[0412] The secure computing device 4I performs ciphertext conversion Extract a+ , ct n1+ , ct n2_+ on the second ciphertext ct RLWEtoLWEUsing the formula (9), the third ciphertext ct of the first scalar value a encrypted using the second homomorphic encryption method a and the third ciphertext ct of the second scalar value n1 n1 and the third ciphertext ct of the third scalar value n2_ n2_ are each transformed.
[0413] ct a = Extract RLWEtoLWE (ct a+ ) ct n1 = Extract RLWEtoLWE (ct n1+ ) ct n2_ = Extract RLWEtoLWE (ct n2_+ ) ···Formula (9)
[0414] The secure computing device 4I performs a second secure computing process on three third ciphertexts encrypted using the second homomorphic encryption method and a scalar value n representing twice the vector length l, using the homomorphic multiplication EvalMult LWE , the homomorphic addition EvalAdd LWE , and the homomorphic subtraction EvalSub LWE . The homomorphic subtraction EvalSub LWE can be defined from the homomorphic addition EvalAdd LWE . Then, the secure computing device 4I calculates the fourth ciphertext ct of the fourth scalar value Xsq1 and the fourth ciphertext ct of the fifth scalar value Xsq1 encrypted using the second homomorphic encryption method. Xsq1 , and the fourth ciphertext ct of the fifth scalar value Xsq1 Xsq2 .
[0415] ct n2 =EvalAdd LWE (ct n2_ ,ct n2_ ) ct n3 =EvalSub LWE (n,ct n2 ) ct n4 =EvalSub LWE (n,ct n1 ) ct b =EvalSub LWE (ct n2 ,ct a ) ct c =EvalSub LWE (ct n1 ,ct a ) ct d =EvalSub LWE (ct n3 ,ct c ) ct tmp1 =EvalMult LWE (ct a ,ct d ) ct tmp2 =EvalMult LWE (ct c ,ct b ) ct tmp3 =EvalSub LWE (ct tmp1 ,ct tmp2 ) ct tmp4 =EvalMult LWE (ct tmp3 ,ct tmp3 ) ct Xsq1 =EvalMult LWE (n,ct tmp4 ) ct tmp5 =EvalMult LWE (ct n1 ,ct n2 ) ct tmp6 =EvalMult LWE (ct n3 ,ct n4 ) ct Xsq2 =EvalMult LWE (ct tmp5 ,ct tmp6 ) ···· Equation (10)
[0416] The first terminal device 1I is the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1and the fourth ciphertext ct of the fifth scalar value Xsq1 are decrypted using the first decryption key sk LWE to calculate the fourth scalar value Xsq1 and the fifth scalar value Xsq2.
[0417] When homomorphic division can be defined in the second homomorphic encryption method, the secure computing device 4I may output the fourth ciphertext of the sixth scalar value Xsq = Xsq1 / Xsq2 as the output data of the second secure computing process. Also, when homomorphic comparison operations can be defined in the second homomorphic encryption method, the secure computing device 4I may output a binary fourth ciphertext indicating the presence or absence of the relevance between the SNP data and the trait data as the output data of the second secure computing process.
[0418] <Description of System Configuration and Functions> Next, the secure computing system 100I of the present embodiment will be specifically described.
[0419] FIG. 2 is a functional block diagram of an example of the first terminal device 1I of the present embodiment. The first terminal device 1I is the same as the first terminal device 1 of the first embodiment described above, except that it includes a key generation processing unit 11I, an input unit 21I, an encryption processing unit 23I, a transmission unit 25I, a reception unit 31I, a decryption processing unit 33I, and an output unit 35I instead of the key generation processing unit 11, the input unit 21, the encryption processing unit 23, the transmission unit 25, the reception unit 31, the decryption processing unit 33, and the output unit 35.
[0420] The key generation processing unit 11I generates a public key pk RLWE and a secret key sk RLWE used in the first homomorphic encryption method. Then, the key generation processing unit 11I calculates a secret key sk RLWE used in the second homomorphic encryption method from the secret key sk LWE used in the first homomorphic encryption method. In the key generation processing unit 11I, the public key pk RLWE used in the first homomorphic encryption method is used as the first encryption key, and the secret key sk LWE used in the second homomorphic encryption method is used as the first decryption key. The key generation processing unit 11I stores the first encryption key in the encryption key storage unit 12 and stores the first decryption key in the decryption key storage unit 13.
[0421] In addition to the process of transmitting the same information as the transmission unit 25, the transmission unit 25I transmits the encryption key pk stored in the encryption key storage unit 12 RLWE to the second terminal device 6I.
[0422] The input unit 21I obtains, from a computer or the like connected to the first terminal device 1I, a first vector u = (u 0 , u 1 , …, u l-1 ) of length l representing SNP data, which is the input data of the first secure calculation process, and stores the first vector in the first data storage unit 22.
[0423] The encryption processing unit 23I converts the first vector u stored in the first data storage unit 22 into a polynomial fw(u) = u 0 + u 1 x + … + u l-1 x l-1 using the first conversion function fw. Then, the encryption processing unit 23I encrypts the above polynomial using the first encryption key pk RLWE stored in the encryption key storage unit 12, and calculates a first ciphertext ct u encrypted by the first homomorphic encryption method. The encryption processing unit 23I stores the first ciphertext in the second data storage unit 24.
[0424] The transmission unit 25I transmits the first ciphertext ct u stored in the second data storage unit 24 and the vector length l to the secure calculation device 4I.
[0425] The reception unit 31I receives a fourth ciphertext ct Xsq1 of a fourth scalar value Xsq1 encrypted by the second homomorphic encryption method and a fourth ciphertext ct Xsq2 of a fifth scalar value Xsq2 from the secure calculation device 4I, and stores them in the third data storage unit 32.
[0426] The decryption processing unit 33I uses the first decryption key sk LWE stored in the decryption key storage unit 13 to decrypt the fourth ciphertext ct Xsq1 stored in the third data storage unit 32, ctXsq2 Decrypt it to calculate a fourth scalar value Xsq1 and a fifth scalar value Xsq2. The decryption processing unit 33I stores the fourth scalar value and the fifth scalar value in the fourth data storage unit 34.
[0427] The output unit 35I outputs the fourth scalar value Xsq1 and the fifth scalar value Xsq2 to a computer or the like connected to the first terminal device 1I.
[0428] Note that the input unit 21I may obtain the above polynomial fw(u) from a computer or the like connected to the first terminal device 1I and store the polynomial in the first data storage unit 22. Further, the encryption processing unit 23I encrypts the polynomial stored in the first data storage unit 22 using the first encryption key pk RLWE stored in the encryption key storage unit 12 to calculate a first ciphertext ct u and store it in the second data storage unit 24.
[0429] FIG. 10 is a functional block diagram of an example of the second terminal device 6I of the present embodiment. The second terminal device 6I includes an input unit 21I, a first data storage unit 22, an encryption processing unit 23I, a second data storage unit 24, a transmission unit 25I, a reception unit 31I, and an encryption key storage unit 12.
[0430] The reception unit 31I receives the first encryption key pk RLWE from the first terminal device 1I and stores it in the encryption key storage unit 12.
[0431] The input unit 21I obtains a second vector v = (v 0 , v 1 , …, v l-1 ) representing trait data of length l, which is input data of the first secure calculation process, from a computer or the like connected to the second terminal device 6I and stores it in the first data storage unit 22.
[0432] The encryption processing unit 23I uses the second conversion function bw to convert the second vector v stored in the first data storage unit 22 into a polynomial bw(v) = v 0 ―v 1 x n―1 ―v2 x n―2 ―…―v l―1 x n-(l―1) is converted. Then, the encryption processing unit 23I encrypts the polynomial using the first encryption key pk RLWE stored in the encryption key storage unit 72, and calculates the first ciphertext ct v encrypted by the first homomorphic encryption method. The encryption processing unit 23I stores the first ciphertext in the second data storage unit 24.
[0433] The transmission unit 25I transmits the first ciphertext ct v stored in the second data storage unit 24 and the vector length l to the secure computing device 4I.
[0434] Note that the input unit 21I may acquire the polynomial bw(v) from a computer or the like connected to the first terminal device 1I and store it in the first data storage unit 22. Further, the encryption processing unit 23I may encrypt the polynomial stored in the first data storage unit 22 using the first encryption key pk RLWE stored in the encryption key storage unit 12 to calculate the first ciphertext ct v and store it in the second data storage unit 24.
[0435] FIG. 3 is a functional block diagram of an example of the secure computing device 4I of the present embodiment.
[0436] The secure computing device 4I is the same as the secure computing device 4 of the first embodiment except that it includes a receiving unit 41I, a first secure computing processing unit 43I, a ciphertext conversion processing unit 45I, a second secure computing processing unit 47I, and a transmitting unit 49I instead of the receiving unit 41, the first secure computing processing unit 43, the ciphertext conversion processing unit 45, the second secure computing processing unit 47, and the transmitting unit 49.
[0437] The receiving unit 41I regards the first ciphertext ct u which is the first vector u representing SNP data that is the input data of the first secure computing process encrypted by the first homomorphic encryption method as a polynomial, and the first ciphertext ct vfrom the first terminal device 1I and the second terminal device 6I, respectively. The receiving unit 41I stores these first ciphertexts in the first data storage unit .
[0438] The first secret calculation processing unit 43I converts the first ciphertext ct u , ct v homomorphic multiplication EvalMult RLWE By this calculation process, the first secret calculation unit 43I performs the first secret calculation process by using the second ciphertext ct a+ , the second ciphertext ct of a polynomial with the second scalar value n1 as a constant term n1+ , and the second ciphertext ct of a polynomial with the third scalar value n2_ as a constant term n2_+ Calculate.
[0439] The first secret computation unit 43I stores the second ciphertext in the second data storage unit .
[0440] The ciphertext conversion processing unit 45I converts the second ciphertext ct a+ , ct n1+ , ct n2_+ About the ciphertext transformation Extract RLWEtoLWE , the third ciphertext ct of the first scalar value a can be obtained without decrypting the second ciphertext. a and the third ciphertext ct of the second scalar value n1 n1 and the third ciphertext ct of the third scalar value n2_ n2_ Then, ciphertext conversion processing unit 45I stores these third ciphertexts in third data storage unit .
[0441] The second secret calculation processing unit 47I converts the third ciphertext ct a , ct n1 , ct n2_ and a scalar value n representing twice the vector length l as input, and homomorphic multiplication EvalMult LWE and homomorphic addition EvalAdd LWE and homomorphic subtraction EvalSub LWEand use it to perform the second secure calculation process. Through this calculation process, the second secure calculation unit 47I calculates the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 and the fourth ciphertext ct of the fifth scalar value Xsq2 Xsq2 and stores these fourth ciphertexts in the fourth data storage unit.
[0442] The transmission unit 49I transmits the fourth ciphertext ct Xsq1 and ct Xsq2 stored in the fourth data storage unit 48 to the first terminal device 1I.
[0443] Note that the hardware configurations of the first terminal device 1I, the second terminal device 6I, and the secure calculation device 4I are the same as those of the first terminal device 1 and the secure calculation device 4 in the above first embodiment (see FIG. 5).
[0444] <Description of the flow> Next, an example of the information processing flow executed by the first terminal device 1I, the second terminal device 6I, and the secure calculation device 4I in this embodiment will be described.
[0445] FIG. 11 is a flowchart showing an example of the information processing flow executed by the first terminal device 1I, the second terminal device 6I, and the secure calculation device 4I in this embodiment.
[0446] In step S15, the key generation processing unit 11I of the first terminal device 1I generates the public key pk RLWE and the secret key sk RLWE used in the first homomorphic encryption method. Then, the key generation processing unit 11I calculates the secret key sk RLWE used in the second homomorphic encryption method from the secret key sk LWE used in the first homomorphic encryption method. Using the public key pk RLWE used in the first homomorphic encryption method as the first encryption key and the secret key sk LWE used in the second homomorphic encryption method as the first decryption key. The key generation processing unit 11I stores the first encryption key in the encryption key storage unit 12 and stores the first decryption key in the decryption key storage unit 13.
[0447] In step S16, the transmission unit 25I of the first terminal device 1 transmits the first encryption key pk stored in the encryption key storage unit 12 RLWE to the second terminal device 6I.
[0448] In step S17, the reception unit 31I of the second terminal device 6I receives the first encryption key pk from the first terminal device 1I RLWE and stores the encryption key in the encryption key storage unit 12.
[0449] In step S18, the input unit 21I of the first terminal device 1I obtains, from a computer or the like connected to the first terminal device 1I, a first vector u = (u 0 , u 1 , …, u l-1 ) of length l representing SNP data, which is the input data of the first confidential calculation process, and stores it in the first data storage unit 22.
[0450] In step S19, the encryption processing unit 23I of the first terminal device 1I converts the first vector u stored in the first data storage unit 22 into a polynomial fw(u) = u 0 + u 1 x + … + u l-1 x l-1 using the first conversion function fw. Then, the encryption processing unit 23I encrypts the above polynomial using the first encryption key pk RLWE and calculates the first ciphertext ct u . The encryption processing unit 23I stores the first ciphertext in the second data storage unit 24.
[0451] In step S20, the transmission unit 25I of the first terminal device 1I transmits the first ciphertext ct stored in the second data storage unit 24 u and the vector length l to the confidential calculation device 4I.
[0452] In step S21, the input unit 21I of the second terminal device 6I obtains, from a computer or the like connected to the second terminal device 6I, a second vector v = (v 0 , v 1 , …, v l-1) is acquired and stored in the first data storage unit 22.
[0453] In step S22, the encryption processing unit 23I of the second terminal device 6I converts the second vector v stored in the first data storage unit 22 into a polynomial bw(v)=v 0 ―v 1 x n―1 ―v 2 x n―2 ―…―v l―1 x n-(l―1) using the second conversion function bw. Then, the encryption processing unit 23I encrypts the polynomial using the first encryption key pk RLWE and calculates the first ciphertext ct v . The encryption processing unit 23I stores the first ciphertext in the second data storage unit 24.
[0454] In step S23, the transmission unit 25I of the second terminal device 6I transmits the first ciphertext ct v and the vector length l to the secure computing device 4I.
[0455] In step S24, the receiving unit 41I of the secure computing device 4I receives the first ciphertext ct u regarded as a polynomial representing the SNP data and the first ciphertext ct v regarded as a polynomial representing the trait data from the first terminal device 1I and the second terminal device 6I, respectively, and stores them in the first data storage unit 42.
[0456] In step S25, the first secure computing processing unit 43I of the secure computing device 4I performs the first secure computing process on the first ciphertext ct u , ct v using the homomorphic multiplication EvalMult RLWE to calculate the second ciphertext ct a+ of a polynomial with the first scalar value a as the constant term, the second ciphertext ct n1+ of a polynomial with the second scalar value n1 as the constant term, and the second ciphertext ct n2_+ of a polynomial with the third scalar value n2_ as the constant term. The first secure computing processing unit 43I stores the second ciphertext in the second data storage unit 44.
[0457] In step S26, the ciphertext conversion unit 45I of the secure computing device 4I uses the ciphertext conversion Extract a+ , ct n1+ , ct n2_+ to convert the second ciphertext ct RLWEtoLWE into the third ciphertext ct a of the first scalar value a, the third ciphertext ct n1 of the second scalar value n1, and the third ciphertext ct n2_ of the third scalar value n2_ without decrypting the second ciphertext. Then, the ciphertext conversion unit 45I stores the third ciphertext in the third data storage unit 46.
[0458] In step S27, the second secure computing unit 47I of the secure computing device 4I performs a second secure calculation using the third ciphertext ct a , ct n1 , ct n2_ and a scalar value n representing twice the vector length l, along with the homomorphic multiplication EvalMult LWE , the homomorphic addition EvalAdd LWE , and the homomorphic subtraction EvalSub LWE . Through this calculation process, the second secure computing unit 47I calculates the fourth ciphertext ct Xsq1 of the fourth scalar value Xsq1 and the fourth ciphertext ct Xsq2 of the fifth scalar value Xsq2 encrypted using the second homomorphic encryption method. The second secure computing unit 47I stores the fourth ciphertext in the fourth data storage unit.
[0459] In step S28, the transmission unit 48I of the secure computing device 4I transmits the fourth ciphertext ct Xsq1 , ct Xsq2 to the first terminal device 1I.
[0460] In step S29, the reception unit 31I of the first terminal device 1I receives the fourth ciphertext ct Xsq1 of the fourth scalar value Xsq1 and the fourth ciphertext ct Xsq2 of the fifth scalar value Xsq2 from the secure computing device 4I and stores them in the third data storage unit 32.
[0461] In step S30, the decoding unit 33I of the first terminal device 1I uses the first decoding key sk LWE to decode the fourth ciphertext ct Xsq1 , ct Xsq2 and calculates the fourth scalar value Xsq1 and the fifth scalar value Xsq2. The decoding unit 33I stores the fourth scalar value and the fifth scalar value in the fourth data storage unit.
[0462] In step S31, the output unit 35I of the first terminal device 1I outputs the fourth scalar value Xsq1 and the fifth scalar value Xsq2 to a computer or the like connected to the first terminal device 1I.
[0463] As described above, the ciphertext conversion unit 45I of the secure computing device 4I of the present embodiment uses the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method, similar to the ciphertext conversion unit 45 of the above embodiment, to convert the second ciphertext into the third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, in the secure computing device 4I and the secure computing system 100I of the present embodiment, similar to the first embodiment, the confidentiality can be improved.
[0464] Further, the secure computing device 4I and the secure computing system 100I of the present embodiment utilize the ciphertext conversion between the first homomorphic encryption method and the second homomorphic encryption method to perform calculations without decrypting the ciphertexts of the first scalar value a, the second scalar value n1, and the third scalar value n2_, which are the output data of the first secure computing process in GWAS. At least a cross-tabulation table such as an allele frequency table can be straightforwardly calculated from the first scalar value a, the second scalar value n1, and the third scalar value n2_, and since these values are kept secret, it is considered that they can contribute to the anonymization of the cross-tabulation table.
[0465] Note that, as an example, the first terminal device 1I in this embodiment includes, as shown in FIG. 2, a key generation processing unit 11I, an encryption key storage unit 12, a decryption key storage unit 13, an input unit 21I, a first data storage unit 22, an encryption processing unit 23I, a second data storage unit 24, a transmission unit 25I, a reception unit 31I, a third data storage unit 32, a decryption processing unit 33I, a fourth data storage unit 34, and an output unit 35I. However, similar to the first terminal device 1 in the first embodiment, a configuration including a part of each of these units may also be used. Further, a plurality of external terminal devices different from the first terminal device 1I may include units that the first terminal device 1I does not include. Further, the first terminal device 1I may include at least one of the key generation processing unit 11I, the encryption processing unit 23I, and the decryption processing unit 33I.
[0466] (Modification Example 1 of the Third Embodiment) In this modification example, in the above-described third embodiment, a form in which the first homomorphic encryption method is a homomorphic encryption method using Module-LWE and the second homomorphic encryption method is a homomorphic encryption method using LWE will be described as an example.
[0467] FIG. 9 is a schematic diagram of an example of the secure calculation system 100J of this modification example.
[0468] The secure calculation system 100J includes a first terminal device 1J, a second terminal device 6J, and a secure calculation device 4J. The first terminal device 1J, the second terminal device 6J, and the secure calculation device 4J are communicably connected via a network 5.
[0469] <Explanation of Secure Calculation Processing Content> First, the content of each secure calculation process of the first secure calculation process and the second secure calculation process in this modification example will be described.
[0470] In the secure calculation device 4J of this modification example, similar to the secure calculation device 4I of the third embodiment described above, as the first secure calculation process, a first vector u = (u 0 , u 1 , …, u l-1) and a second vector v of length l representing trait data indicating the presence or absence of a certain disease, v = (v 0 , v 1 , …, v l-1 ), are used as input data, and a first scalar value a, a second scalar value n1, and a third scalar value n2_ are output. Also, in the secure computing device 4J, as the second secure computing process, the first scalar value a, the second scalar value n1, and the third scalar value n2_ are input, and a fourth scalar value Xsq1 representing the chi-square statistic indicating the degree of association between the SNP data and the trait data, and a fifth scalar value Xsq2 are output. Also, in the secure computing device 4J, the data input to each of the first secure computing process and the second secure computing process is calculated in a state where it is encrypted, that is, in the state of being ciphertext.
[0471] <Explanation of the homomorphic encryption method and the ciphertext conversion method> In the secure computing device 4J of this modification example, in order to perform data input / output between the first secure computing process and the second secure computing process while keeping the data encrypted, the ciphertext is converted using the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method.
[0472] In the secure computing device 4J of this modification example, a homomorphic encryption method using Module-LWE is used as the first homomorphic encryption method. Also, in the secure computing device 4J, a homomorphic encryption method using LWE is used as the second homomorphic encryption method. Also, in the secure computing device 4J, the ciphertext conversion used in the homomorphic encryption method using Module-LWE and the homomorphic encryption method using LWE is utilized.
[0473] <Explanation of the secure computing method> In the secure computing system according to this modification example, the first secure computing process and the second secure computing process are securely computed in the following procedure using the first homomorphic encryption method, the second homomorphic encryption method, and the ciphertext conversion.
[0474] In the first terminal device 1J, as preparation for homomorphic encryption, a secret key sk MLWE and a public key pk MLWE of the first homomorphic encryption method are generated. Also, the secret key used in the first homomorphic encryption method is skMLWE =(sk 0 , sk 1 , …, sk k-1 ) is defined as such. However, when sk i = sk i,0 + sk i,1 x + … + sk i,n-1 x n-1 , the secret key of the second homomorphic encryption method is sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ).
[0475] The first terminal device 1J uses the public key pk MLWE used in the first homomorphic encryption method as the first encryption key, and the secret key sk LWE used in the second homomorphic encryption method as the first decryption key. Note that the first terminal device 1J may also use the secret key sk MLWE used in the first homomorphic encryption method as the first encryption key.
[0476] In the first terminal device 1J and the second terminal device 6J, the first vector u = (u 0 , u 1 , …, u l-1 ) of length l and the second vector v = (v 0 , v 1 , …, v l-1 ) are respectively converted into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 ― v 1 x n―1 ― v 2 x n―2 ― … ― v l―1 x n-(l―1) by the first transformation function fw and the second transformation function bw. Note that during the transformation, fw(v) and bw(u) may also be used. And in the first terminal device 1J and the second terminal device 6J, the first encryption key pk MLWEUse it to encrypt each polynomial, and calculate two first ciphertexts ct u and ct v respectively.
[0477] In the secure computing device 4J, the first ciphertexts ct u and ct v are used for the first secure computing process according to Equation (8) by using the homomorphic multiplication EvalMult MLWE of the first homomorphic encryption method. Then, the secure computing device 4J calculates, through each computing process, the second ciphertext ct a+ of the polynomial with the first scalar value a as the constant term, the second ciphertext ct n1+ of the polynomial with the second scalar value n1 as the constant term, and the second ciphertext ct n2_+ of the polynomial with the third scalar value n2_ as the constant term.
[0478] In the secure computing device 4J, without decrypting the second ciphertexts ct a+ , ct n1+ , and ct n2_+ , use the ciphertext conversion Extract MLWEtoLWE to convert them into the third ciphertext ct a of the first scalar value a, the third ciphertext ct n1 of the second scalar value n1, and the third ciphertext ct n2_ of the third scalar value n2_ respectively according to Equation (9).
[0479] The secure computing device 4J performs the second secure computing process according to Equation (10) by using three third ciphertexts, the scalar value n representing twice the vector length l, the homomorphic multiplication EvalMult LWE , the homomorphic addition EvalAdd LWE , and the homomorphic subtraction EvalSub LWE . Through this computing process, the secure computing device 4J calculates the fourth ciphertext ct Xsq1 of the fourth scalar value Xsq1 and the fourth ciphertext ct Xsq2 of the fifth scalar value Xsq1.
[0480] The first terminal device 1J has the fourth ciphertext ct Xsq1 of the fourth scalar value Xsq1 and the fourth ciphertext ct Xsq1 of the fifth scalar value.using the first decryption key sk LWE to decrypt and calculate the fourth scalar value Xsq1 and the fifth scalar value Xsq2.
[0481] Note that when homomorphic division can be defined in the second homomorphic encryption method, the secret computing device 4J may output the fourth ciphertext of the sixth scalar value Xsq = Xsq1 / Xsq2 as the output data of the second secret computing process. Also, when homomorphic comparison operations can be defined in the second homomorphic encryption method, the secret computing device 4J may output a binary fourth ciphertext indicating the presence or absence of the relevance between the SNP data and the trait data as the output data of the second secret computing process.
[0482] <Description of System Configuration and Functions> Next, the secret computing system 100J of this modified example will be specifically described.
[0483] FIG. 2 is a functional block diagram of an example of the first terminal device 1J of the present embodiment. The first terminal device 1J is the same as the first terminal device 1I of the third embodiment described above, except that it includes a key generation processing unit 11J, an encryption processing unit 23J, and a transmission unit 25J instead of the key generation processing unit 11I, the encryption processing unit 23I, and the transmission unit 25I.
[0484] The key generation processing unit 11J generates a public key pk MLWE and a secret key sk MLWE used in the first homomorphic encryption method. Also, the key generation processing unit 11J sets the secret key used in the first homomorphic encryption method as sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i = sk i,0 + sk i,1 x + … + sk i,n-1 x n-1 the secret key of the second homomorphic encryption method is set as sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, skk-1,0 , sk k-1,1 , …, sk k-1,n-1 ) is as follows.
[0485] In the key generation processing unit 11J, the public key pk MLWE used in the first homomorphic encryption method is used as the first encryption key, and the secret key sk LWE used in the second homomorphic encryption method is used as the decryption key. Note that the key generation processing unit 11J may use the secret key sk MLWE used in the first homomorphic encryption method as the first encryption key. The key generation processing unit 11J stores the first encryption key in the encryption key storage unit 12 and stores the first decryption key in the decryption key storage unit 13.
[0486] The transmission unit 25J transmits the first encryption key pk MLWE stored in the encryption key storage unit 12 to the second terminal device 6J.
[0487] The encryption processing unit 23J converts the first vector u stored in the first data storage unit 22 into a polynomial fw(u) = u 0 + u 1 x + … + u l-1 x l-1 using the first conversion function fw. Then, the encryption processing unit 23J encrypts the above polynomial using the first encryption key pk MLWE and calculates the first ciphertext ct u encrypted by the first homomorphic encryption method. The encryption processing unit 23J stores the first ciphertext in the second data storage unit 24.
[0488] Note that the input unit 21I may obtain the above polynomial fw(u) from a computer or the like connected to the first terminal device 1I and store the above polynomial in the first data storage unit 22. Also, the encryption processing unit 23J may calculate the first ciphertext ct RLWE by encrypting the polynomial stored in the first data storage unit 22 using the first encryption key pk u stored in the encryption key storage unit 12 and store it in the second data storage unit 24.
[0489] FIG. 10 is a functional block diagram of an example of the second terminal device 6J of this modified example. The second terminal device 6J is the same as the second terminal device 6I of the third embodiment except that it includes an encryption processing unit 23J and a reception unit 31J instead of the encryption processing unit 23I and the reception unit 31I.
[0490] The reception unit 31J receives the first encryption key pk MLWE from the first terminal device 1J and stores it in the encryption key storage unit 12.
[0491] The encryption processing unit 23J converts the second vector v stored in the first data storage unit 22 by the second conversion function bw into a polynomial bw(v)=v 0 −v 1 x n―1 −v 2 x n―2 −…−v l―1 x n-(l―1) Then, the encryption processing unit 23J encrypts the above polynomial using the first encryption key pk MLWE to obtain the first ciphertext ct v The encryption processing unit 23J stores the first ciphertext in the second data storage unit 24.
[0492] Note that the input unit 21I may obtain the above polynomial bw(v) from a computer or the like connected to the second terminal device 6I and store it in the first data storage unit 22. Further, the encryption processing unit 23J may encrypt the above polynomial stored in the first data storage unit 22 using the first encryption key pk MLWE stored in the encryption key storage unit 12 to calculate the first ciphertext ct v Then, the encryption processing unit 23J may store the first ciphertext in the second data storage unit 24.
[0493] FIG. 3 is a functional block diagram of an example of the secure computing device 4J of this modified example.
[0494] The secure computing device 4J is the same as the secure computing device 4I of the third embodiment except that it includes a first secure computing processing unit 43J and a ciphertext conversion processing unit 45J instead of the first secure computing processing unit 43I and the ciphertext conversion processing unit 45I.
[0495] The first secure calculation processing unit 43J performs first secure calculation on the first ciphertext ct u , ct v stored in the first data storage unit 42, using the homomorphic multiplication EvalMult MLWE that functions as a homomorphic inner product operation of the first homomorphic encryption method. Then, the first secure calculation processing unit 43J calculates the second ciphertext ct a+ of a polynomial with the first scalar value a as a constant term, the second ciphertext ct n1+ of a polynomial with the second scalar value n1 as a constant term, and the second ciphertext ct n2_+ of a polynomial with the third scalar value n2_ as a constant term, which are encrypted by the calculation processing. The first secure calculation processing unit 43J stores the second ciphertext in the second data storage unit 44.
[0496] The ciphertext conversion processing unit 45J converts the second ciphertext ct a+ , ct n1+ , ct n2_+ into the third ciphertext ct MLWEtoLWE of the first scalar value a, the third ciphertext ct a of the second scalar value n1, and the third ciphertext ct n1 of the third scalar value n2_, respectively, using the ciphertext conversion Extract n2_ without decrypting the second ciphertext. Then, the ciphertext conversion processing unit 45J stores these ciphertexts in the third data storage unit 46.
[0497] Note that the hardware configurations of the first terminal device 1J, the second terminal device 6J, and the secure calculation device 4J are the same as those of the first terminal device 1 and the secure calculation device 4 in the above first embodiment (see FIG. 5).
[0498] <Description of the Flow> Next, an example of the information processing flow executed by the first terminal device 1J, the second terminal device 6J, and the secure calculation device 4J in this modification will be described.
[0499] FIG. 11 is a flowchart showing an example of the flow of information processing executed by the first terminal device 1J, the second terminal device 6J, and the anonymizing calculation device 4J in this modified example. In this modified example, the processes of steps S15 to S31 are executed in the same manner as the first terminal device 1I, the second terminal device 6I, and the anonymizing calculation device 4I in the third embodiment described above.
[0500] However, in this modified example, in step S15, the key generation processing unit 11J of the first terminal device 1J generates a public key pk MLWE and a secret key sk MLWE to be used in the first homomorphic encryption method. Further, the key generation processing unit 11J sets the secret key to be used in the first homomorphic encryption method as sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i =sk i,0 +sk i,1 x+…+sk i,n-1 x n-1 , the secret key of the second homomorphic encryption method is set as sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ). Further, the public key pk MLWE to be used in the first homomorphic encryption method is used as the first encryption key, and the secret key sk LWE to be used in the second homomorphic encryption method is used as the decryption key. Note that the secret key sk MLWE to be used in the first homomorphic encryption method may be used as the first encryption key. The key generation processing unit 11J stores the first encryption key in the encryption key storage unit 12 and stores the first decryption key in the decryption key storage unit 13.
[0501] Also, in step S16, the transmission unit 25J of the first terminal device 1J transmits the first encryption key pk MLWE stored in the encryption key storage unit 12 to the second terminal device 6J.
[0502] Also, in step S17, the receiving unit 31J of the second terminal device 6J receives the first encryption key pk MLWE from the first terminal device 1J and stores it in the encryption key storage unit 12.
[0503] Also, in step S19, the encryption processing unit 23J of the first terminal device 1J uses the first conversion function fw to convert the first vector u stored in the first data storage unit 22 into a polynomial fw(u)=u 0 +u 1 x+…+u l-1 x l-1 to. Then, the encryption processing unit 23J encrypts the polynomial using the first encryption key pk MLWE and calculates the first ciphertext ct u . The encryption processing unit 23J stores the first ciphertext in the second data storage unit 24.
[0504] Also, in step S22, the encryption processing unit 23J of the second terminal device 6J uses the second conversion function bw to convert the second vector v stored in the first data storage unit 22 into a polynomial bw(v)=v 0 ―v 1 x n―1 ―v 2 x n―2 ―…―v l―1 x n-(l―1) to. Then, the encryption processing unit 23J encrypts the polynomial using the first encryption key pk MLWE and calculates the first ciphertext ct v . The encryption processing unit 23J stores the first ciphertext in the second data storage unit 24.
[0505] Also, in step S25, the first secure calculation processing unit 43J of the secure calculation device 4J performs the first secure calculation processing on the first ciphertexts ct u , ct v using the homomorphic multiplication EvalMult MLWE to obtain the second ciphertext ct a+ of the polynomial with the first scalar value a as the constant term, the second ciphertext ct n1+ of the polynomial with the second scalar value n1 as the constant term, and the second ciphertext ct n2_+The first secret calculation processor 43J stores the second ciphertext in the second data storage unit 44.
[0506] In step S26, the ciphertext conversion processing unit 45J of the secret computing device 4J converts the second ciphertext ct a+ , ct n1+ , ct n2_+ About the ciphertext transformation Extract MLWEtoLWE , the third ciphertext ct of the first scalar value a can be obtained without decrypting the second ciphertext. a and the third ciphertext ct of the second scalar value n1 n1 and the third ciphertext ct of the third scalar value n2_ n2_ Then, ciphertext conversion processing unit 45J stores the third ciphertext in third data storage unit .
[0507] As described above, the ciphertext conversion processing unit 45J of the secure computing device 4J of this modification, like the ciphertext conversion processing unit 45 of the above embodiment, converts the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption scheme without decrypting the second ciphertext, using a ciphertext conversion scheme defined between the first homomorphic encryption scheme and the second homomorphic encryption scheme. Therefore, the secure computing device 4J and the secure computing system 100J of this modification can improve confidentiality, like the first embodiment.
[0508] In addition, in the secure computation device 4J and the secure computation system 100J of this modification, computation can be performed without decrypting the ciphertexts of the first scalar value a, the second scalar value n1, and the third scalar value n2_, which are the outputs of the first secure computation process in the GWAS. In addition, in the secure computation device 4J and the secure computation system 100J of this modification, it is possible to use a homomorphic encryption scheme using Module-LWE, which has higher security performance than Ring-LWE, as the first homomorphic encryption scheme.
[0509] (Modification 2 of the third embodiment) In this modified example, in the above-described third embodiment, an example will be described in which the first homomorphic encryption method is a homomorphic encryption method using Ring-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE that does not depend on the ring dimension number of Ring-LWE.
[0510] FIG. 9 is a schematic diagram of an example of the privacy calculation system 100K of this modified example.
[0511] The privacy calculation system 100K includes a first terminal device 1K, a second terminal device 6K, and a privacy calculation device 4K. The first terminal device 1K, the second terminal device 6K, and the privacy calculation device 4K are communicably connected via a network 5.
[0512] <Explanation of Privacy Calculation Processing Content> First, the content of each privacy calculation process of the first privacy calculation process and the second privacy calculation process in this modified example will be described.
[0513] Similar to the privacy calculation device 4I of the above-described third embodiment, the privacy calculation device 4K of this modified example uses, as the first privacy calculation process, a first vector u = (u 0 , u 1 , …, u l-1 ) of length l representing SNP data and a second vector v = (v 0 , v 1 , …, v l-1 ) of length l representing trait data indicating the presence or absence of a certain disease as input data, and outputs a first scalar value a, a second scalar value n1, and a third scalar value n2_. Further, in the privacy calculation device 4K, as the second privacy calculation process, the first scalar value a, the second scalar value n1, and the third scalar value n2_ are input, and a fourth scalar value Xsq1 representing a chi-square statistic indicating the degree of association between the SNP data and the trait data and a fifth scalar value Xsq2 are output. Further, in the privacy calculation device 4K, the data input to each of the first privacy calculation process and the second privacy calculation process is calculated in a state where it is encrypted, that is, in a state of being a ciphertext.
[0514] <Explanation of Homomorphic Encryption Method and Ciphertext Conversion Method> In the secure computing device 4K of this modification example, in order to perform data input / output between the first secure computing process and the second secure computing process while keeping the data encrypted, the ciphertext is converted using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method.
[0515] In the secure computing device 4K of this modification example, as the first homomorphic encryption method, a homomorphic encryption method using Ring-LWE with a ring dimension number n is utilized. Also, in the secure computing device 4K, as the second homomorphic encryption method, a homomorphic encryption method using LWE with a vector dimension number d’≠n is utilized. Further, in the secure computing device 4K, the ciphertext conversion method between the homomorphic encryption method using Ring-LWE with a ring dimension number n and the homomorphic encryption method using LWE with a vector dimension number d’ is utilized.
[0516] <Explanation of the secure computing method> In the secure computing system 100K according to this modification example, the first secure computing process and the second secure computing process are securely computed in the following procedure using the first homomorphic encryption method, the second homomorphic encryption method, and ciphertext conversion.
[0517] As preparation for the homomorphic encryption, the first terminal device 1K generates the secret key sk RLWE and the public key pk RLWE of the first homomorphic encryption method. Also, the first terminal device 1K generates the secret key sk LWE’ and the public key pk LWE’ of the second homomorphic encryption method. Also, when the secret key used in the first homomorphic encryption method is set as sk RLWE =sk 0 +sk 1 x+…+sk n-1 x n-1 , the conversion key ksk LWEtoLWE’ is the ciphertext ksk LWE =(sk 0 ,sk 1 ,…,sk n-1 ) encrypted using the second homomorphic encryption method, that is, ksk LWEtoLWE’ =Enc LWE’ (sk LWE ).
[0518] The first terminal device 1K uses the public key pk used in the first homomorphic encryption method RLWE as the first encryption key and the secret key sk used in the second homomorphic encryption method LWE’ as the first decryption key. Note that the secret key sk used in the first homomorphic encryption method RLWE may be used as the first encryption key. Also, the first terminal device 1K uses the public key pk used in the second homomorphic encryption method LWE’ as the second encryption key.
[0519] The first terminal device 1K and the second terminal device 6K use the first homomorphic encryption method to perform the first vector u = (u 0 , u 1 , …, u l-1 ) of length l and the second vector v = (v 0 , v 1 , …, v l-1 ) which are the inputs of the first secure calculation process, and convert them into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 ―v 1 x n―1 ―v 2 x n―2 ―…―v l―1 x n-(l―1) respectively by the first conversion function fw and the second conversion function bw. Note that fw(v) and bw(u) may be used during the conversion. Then, the first terminal device 1K and the second terminal device 6K encrypt the above polynomials using the encryption key pk RLWE of the first homomorphic encryption method, and calculate two first ciphertexts ct u , ct v .
[0520] The secure calculation device 4K performs the first secure calculation process on the first ciphertexts ct u , ct v using the homomorphic multiplication EvalMult RLWE according to Equation (8), and obtains the second ciphertext ct a+ of the polynomial with the first scalar value a as the constant term and the second ciphertext ct n1+And a second ciphertext ct of a polynomial having a third scalar value n2_ as a constant term n2_+ is calculated.
[0521] The secure computing device 4K, without decrypting the second ciphertext ct a+ , ct n1+ , ct n2_+ , uses the ciphertext conversion Extract RLWEtoLWE and Convert LWEtoLWE’ and the conversion key ksk LWEtoLWE’ and the second encryption key pk LWE’ to convert, according to Equation (9), the third ciphertext ct of the first scalar value a a , the third ciphertext ct of the second scalar value n1 n1 , and the third ciphertext ct of the third scalar value n2_ n2_ respectively.
[0522] The secure computing device 4K performs a second secure computing process on three third ciphertexts and a scalar value n representing twice the vector length l using the homomorphic multiplication EvalMult LWE , the homomorphic addition EvalAdd LWE , and the homomorphic subtraction EvalSub LWE according to the method described in Equation (10). Through this computing process, the secure computing device 4K calculates the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 , and the fourth ciphertext ct of the fifth scalar value Xsq1 Xsq2 .
[0523] The first terminal device 1K decrypts the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 and the fourth ciphertext ct of the fifth scalar value using the first decryption key sk Xsq1 to calculate the fourth scalar value Xsq1 and the fifth scalar value Xsq2. LWE
[0524] Note that when homomorphic division can be defined in the second homomorphic encryption method, the secret computing device 4K may output the fourth ciphertext of the sixth scalar value Xsq = Xsq1 / Xsq2 as the output of the second secret computing process. Also, when homomorphic comparison operations can be defined in the second homomorphic encryption method, the secret computing device 4K may output a binary fourth ciphertext indicating the presence or absence of the relevance between the SNP data and the trait data as the output of the second secret computing process.
[0525] <Description of System Configuration and Functions> Next, the secret computing system 100K of this modified example will be specifically described.
[0526] FIG. 6 is a functional block diagram of an example of the first terminal device 1K of this modified example. The first terminal device 1K includes a key generation processing unit 11K, a transmission unit 25K, and a decryption processing unit 33K instead of the key generation processing unit 11, the transmission unit 25, and the decryption processing unit 33, and further includes a conversion key storage unit 14, and is the same as the first terminal device 1I of the third embodiment except for this. Also, the conversion key storage unit 14 is the same as the first terminal device 1C of the modified example 2 of the first embodiment.
[0527] The key generation processing unit 11K generates a public key pk RLWE and a secret key sk RLWE used in the first homomorphic encryption method. Also, the key generation processing unit 11K generates a public key pk LWE’ and a secret key sk LWE’ used in the second homomorphic encryption method. When the secret key used in the first homomorphic encryption method is sk RLWE = sk 0 + sk 1 x + … + sk n-1 x n-1 and the conversion key ksk LWEtoLWE’ is the ciphertext ksk LWE =(sk 0 , sk 1 , …, sk n-1 ) encrypted using the second homomorphic encryption method, that is, ksk LWEtoLWE’ = Enc LWE’ (sk LWE ).
[0528] In the key generation processing unit 11K, the public key pk used in the first homomorphic encryption method used in the first terminal device 1K is used as the first encryption key, and the secret key sk used in the second homomorphic encryption method is used as the first decryption key. Note that the secret key sk used in the first homomorphic encryption method may be used as the first encryption key. Also, the public key pk used in the second homomorphic encryption method used in the secure computing device 4K is used as the second encryption key. The key generation processing unit 11K stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14. RLWE as the first encryption key, and the secret key sk LWE’ used in the second homomorphic encryption method is used as the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may be used as the first encryption key. Also, the public key pk LWE’ used in the second homomorphic encryption method used in the secure computing device 4K is used as the second encryption key. The key generation processing unit 11K stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14.
[0529] The transmission unit 25K transmits the second encryption key pk stored in the encryption key storage unit 12 and the conversion key ksk stored in the conversion key storage unit 14 to the secure computing device 4K. LWE’ and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 14 to the secure computing device 4K.
[0530] The decryption processing unit 33K uses the first decryption key sk stored in the decryption key storage unit 13 to decrypt the fourth ciphertext ct stored in the third data storage unit 32, ct LWE’ and calculates the fourth scalar value Xsq1 and the fifth scalar value Xsq2. The decryption processing unit 33K stores the fourth scalar value and the fifth scalar value in the fourth data storage unit. Xsq1 , ct Xsq2 and calculates the fourth scalar value Xsq1 and the fifth scalar value Xsq2. The decryption processing unit 33K stores the fourth scalar value and the fifth scalar value in the fourth data storage unit.
[0531] FIG. 10 is a functional block diagram of an example of the second terminal device 6K of this modification. The functional configuration of the second terminal device 6K is the same as that of the second terminal device 6I of the third embodiment.
[0532] FIG. 7 is a functional block diagram of an example of the secure computing device 4K of this modification.
[0533] The confidential computing device 4K is the same as the confidential computing device 4I of the third embodiment, except that the receiving unit 41I, the first confidential computing processing unit 43I, the ciphertext conversion processing unit 45I, and the second confidential computing processing unit 47I are replaced with a receiving unit 41K, a first confidential computing processing unit 43K, a ciphertext conversion processing unit 45K, and a second confidential computing processing unit 47K, and further includes an encryption key storage unit 51 and a conversion key storage unit 52. The encryption key storage unit 51 and the conversion key storage unit 52 are the same as those of the confidential computing device 4C in the modification 2 of the first embodiment.
[0534] The receiving unit 41K receives the second encryption key pk LWE’ and the conversion key ksk LWEtoLWE’ from the first terminal device 1K, stores the second encryption key in the encryption key storage unit 51, and stores the conversion key in the conversion key storage unit 52.
[0535] The ciphertext conversion processing unit 45K uses the ciphertext conversion Extract a+ 、ct n1+ 、ct n2_+ to convert the first ciphertext ct RLWEtoLWE 、Convert LWEtoLWE’ without decrypting the first ciphertext into the second ciphertext ct a of the first scalar value a, the second ciphertext ct n1 of the second scalar value n1, and the second ciphertext ct n2_ of the third scalar value n2_. Then, the ciphertext conversion processing unit 45K stores these second ciphertexts in the third data storage unit 46.
[0536] When calculating the ciphertext conversion, the ciphertext conversion processing unit 45K uses the second encryption key pk LWE’ stored in the encryption key storage unit 51 and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 52.
[0537] The second confidential computing processing unit 47K uses the third ciphertext ct a 、ct n1 、ct n2_ stored in the third data storage unit 46 and the scalar value n representing twice the vector length l for homomorphic multiplication EvalMult LWE’and homomorphic addition EvalAdd LWE’ and homomorphic subtraction EvalSub LWE’ are used to perform the second secure calculation process. Homomorphic subtraction EvalSub LWE’ can be defined from homomorphic addition EvalAdd LWE’ .
[0538] Then, the second secure calculation processing unit 47K, through this calculation process, obtains the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 and the fourth ciphertext ct of the fifth scalar value Xsq2 Xsq2 and calculates them. The second secure calculation processing unit 47 stores the fourth ciphertext in the fourth data storage unit.
[0539] Note that the hardware configurations of the first terminal device 1K, the second terminal device 6K, and the secure calculation device 4K are the same as those of the first terminal device 1 and the secure calculation device 4 in the above first embodiment (see Fig. 5).
[0540] <Description of the flow> Next, an example of the information processing flow executed by the first terminal device 1K, the second terminal device 6K, and the secure calculation device 4K in this modification will be described.
[0541] Fig. 12 is a flowchart showing an example of the information processing flow executed by the first terminal device 1K, the second terminal device 6K, and the secure calculation device 4K in this modification. In this modification, in the same manner as the first terminal device 1I, the second terminal device 6I, and the secure calculation device 4I in the above third embodiment, the processes of steps S15 to S31 are executed. However, in this modification, between steps S15 and S16, the processes of steps S32 and S33 are executed.
[0542] However, in this modification, in step S15, the key generation processing unit 11K of the first terminal device 1K generates the public key pk RLWE and the secret key sk RLWE used in the first homomorphic encryption method. Also, the key generation processing unit 11K generates the public key pk LWE’ and the secret key sk LWE’Generate. The secret key used in the first homomorphic encryption method is sk RLWE =sk 0 +sk 1 x+…+sk n-1 x n-1 When it is set as, the conversion key ksk LWEtoLWE’ is sk encrypted using the second homomorphic encryption method LWE =(sk 0 ,sk 1 ,…,sk n-1 )'s ciphertext ksk LWEtoLWE’ =Enc LWE’ (sk LWE ).
[0543] The key generation processing unit 11K uses the public key pk used in the first homomorphic encryption method used in the first terminal device 1K RLWE as the first encryption key, and the secret key sk used in the second homomorphic encryption method LWE’ as the first decryption key. Note that the secret key sk used in the first homomorphic encryption method RLWE may be used as the first encryption key. Also, the public key pk used in the second homomorphic encryption method used in the secure computing device 4K LWE’ is used as the second encryption key. The key generation processing unit 11K stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14.
[0544] In step S32, the transmission unit 25K of the first terminal device 1K uses the second encryption key pk stored in the encryption key storage unit 12 LWE’ and the conversion key ksk stored in the conversion key storage unit 14 LWEtoLWE’ to send to the secure computing device 4K.
[0545] In step S33, the receiving unit 41K of the secure computing device 4K receives the second encryption key pk from the first terminal device 1K LWE’ and the conversion key ksk LWEtoLWE’ . The receiving unit 41K stores the second encryption key in the encryption key storage unit 51 and stores the conversion key in the conversion key storage unit 52.
[0546] In step S26, the ciphertext conversion processing unit 45K of the secure computing device 4K uses the ciphertext conversion Extract a+ , ct n1+ , ct n2_+ to convert the second ciphertexts ct RLWEtoLWE , Convert LWEtoLWE’ into the third ciphertext ct a of the first scalar value a, the third ciphertext ct n1 of the second scalar value n1, and the third ciphertext ct n2_ of the third scalar value n2_, respectively, without decrypting the second ciphertext. The ciphertext conversion processing unit 45K stores the third ciphertexts in the third data storage unit 46. When calculating the ciphertext conversion, the ciphertext conversion processing unit 45K uses the second encryption key pk LWE’ stored in the encryption key storage unit 51 and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 52.
[0547] In step S27, the second secure computing processing unit 47K of the secure computing device 4K performs second secure computing processing on the third ciphertexts ct a , ct n1 , ct n2_ using the homomorphic multiplication EvalMult LWE’ , the homomorphic addition EvalAdd LWE’ , and the homomorphic subtraction EvalSub LWE’ . Through this computing process, the second secure computing processing unit 47K obtains the fourth ciphertext ct Xsq1 of the fourth scalar value Xsq1 and the fourth ciphertext ct Xsq2 of the fifth scalar value Xsq2. The second secure computing processing unit 47 stores the fourth ciphertexts in the fourth data storage unit.
[0548] In step S30, the decryption processing unit 33K of the first terminal device 1K uses the first decryption key sk LWE’ stored in the decryption key storage unit 13 to decrypt the fourth ciphertexts ct Xsq1 , ct Xsq2 and calculates the fourth scalar value Xsq1 and the fifth scalar value Xsq2. The decryption processing unit 33K stores the fourth scalar value and the fifth scalar value in the fourth data storage unit.
[0549] As described above, the ciphertext conversion processing unit 45K of the anonymized computing device 4K in this modification example, similar to the ciphertext conversion processing unit 45 in the above embodiment, uses a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method to convert the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, the anonymized computing device 4K and the anonymized computing system 100K in this modification example can improve the anonymity, similar to the first embodiment.
[0550] Also, in the anonymized computing device 4K and the anonymized computing system 100K of this modification example, calculations can be performed without decrypting the ciphertexts of the first scalar value a, the second scalar value n1, and the third scalar value n2_, which are the outputs of the first anonymized computing process in GWAS. Although a cross-tabulation table such as an allele frequency table can be straightforwardly calculated from at least the first scalar value a, the second scalar value n1, and the third scalar value n2_, these values are anonymized, so it is considered that they can contribute to the anonymization of the cross-tabulation table.
[0551] Also, in the anonymized computing device 4K and the anonymized computing system 100K of this modification example, a homomorphic encryption method using LWE that does not depend on the ring dimension number n used in the homomorphic encryption method using Ring-LWE is available.
[0552] (Modification Example 3 of the Third Embodiment) In this modification example, in the above third embodiment, an example will be described in which the first homomorphic encryption method is a homomorphic encryption method using Module-LWE, and the second homomorphic encryption method is a homomorphic encryption method using LWE that does not depend on the ring dimension number of Module-LWE.
[0553] FIG. 9 is a schematic diagram of an example of the anonymized computing system 100L in this modification example.
[0554] The anonymized computing system 100L includes a first terminal device 1L, a second terminal device 6L, and an anonymized computing device 4L. The first terminal device 1L, the second terminal device 6L, and the anonymized computing device 4L are communicably connected via a network 5.
[0555] <Explanation of the content of the confidential calculation process> First, the content of each confidential calculation process of the first confidential calculation process and the second confidential calculation process in this modified example will be described.
[0556] In the confidential calculation system 100L of this modified example, similar to the third embodiment, a first vector u = (u 0 , u 1 , …, u l-1 ) of length l representing SNP data and a second vector v = (v 0 , v 1 , …, v l-1 ) of length l representing trait data indicating the presence or absence of a certain disease are used as input data. Then, in the confidential calculation device 4L, similar to the confidential calculation device 4I of the third embodiment, as the first confidential calculation process, a first scalar value a, a second scalar value n1, and a third scalar value n2_ are output from the input data. Also, in the confidential calculation device 4L, as the second confidential calculation process, the first scalar value a, the second scalar value n1, and the third scalar value n2_ are input, and a fourth scalar value Xsq1 representing the chi-square statistic indicating the degree of association between the SNP data and the trait data and a fifth scalar value Xsq2 are output. In the confidential calculation device 4L of this modified example, the data input to each of the first confidential calculation process and the second confidential calculation process is calculated in a state where it is encrypted, that is, in the state of ciphertext.
[0557] Note that in this modified example, the fourth scalar value Xsq1 and the fifth scalar value Xsq2 are calculated, but the scalar value Xsq = Xsq1 / Xsq2 may also be calculated. Also, in this modified example, a binary value indicating the presence or absence of the correlation between the SNP data and the trait data may be output by calculating a comparison operation or the like with the fourth scalar value Xsq1 and the fifth scalar value Xsq2 as input. Also, in this modified example, although the scalar value n representing twice the vector length l is disclosed and calculated, it may also be calculated confidentially. In this modified example, the chi-square test is calculated as an example, but as other tests, for example, the Fisher's exact test may also be calculated.
[0558] <Explanation of the homomorphic encryption method and the ciphertext conversion method> In the anonymized computing device 4L of this modification example, in order to perform data input / output between the first anonymized computing process and the second anonymized computing process while keeping the data anonymized, the ciphertext is converted using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method.
[0559] In the anonymized computing device 4L of this modification example, as the first homomorphic encryption method, a homomorphic encryption method using Module-LWE with a ring dimension number n≠1 and a vector dimension number k is utilized. Also, in the anonymized computing device 4L of this modification example, as the second homomorphic encryption method, a homomorphic encryption method using LWE with a vector dimension number d’ is utilized. Further, the anonymized computing device 4L utilizes ciphertext conversion between the homomorphic encryption method using Module-LWE with a ring dimension number n and the homomorphic encryption method using LWE with a vector dimension number d’.
[0560] <Explanation of the anonymized computing method> The anonymized computing system 100L of this modification example performs the first anonymized computing process and the second anonymized computing process in the following procedure using the first homomorphic encryption method, the second homomorphic encryption method, and the ciphertext conversion.
[0561] The first terminal device 1L generates a secret key sk MLWE and a public key pk MLWE of the first homomorphic encryption method. Also, the first terminal device 1L generates a secret key sk LWE’ of the second homomorphic encryption method. Also, let the secret key used in the first homomorphic encryption method be sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i =sk i,0 +sk i,1 x+…+sk i,n-1 x n-1 , the conversion key ksk LWEtoLWE’ is sk LWE encrypted using the second homomorphic encryption method=(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ), and the ciphertext ksk LWEtoLWE’ = Enc LWE’ (sk LWE ) is.
[0562] The first terminal device 1L uses the public key pk MLWE used in the first homomorphic encryption method as the first encryption key, and the secret key sk LWE’ used in the second homomorphic encryption method as the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may also be used as the first encryption key. Also, the first terminal device 1L uses the public key pk LWE’ used in the second homomorphic encryption method as the second encryption key.
[0563] The first terminal device 1L and the second terminal device 6L use the first homomorphic encryption method to process the first vector u = (u 0 , u 1 , …, u l-1 ) of length l and the second vector v = (v 0 , v 1 , …, v l-1 ) respectively into polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 ― v 1 x n―1 ― v 2 x n―2 ― … ― v l―1 x n-(l―1) . Note that during the conversion, fw(v) and bw(u) may also be used. Then, the first terminal device 1L and the second terminal device 6L encrypt the polynomials using the first encryption key pk MLWE respectively, and calculate two first ciphertexts ct u , ct v .
[0564] The secure computing device 4L uses the first ciphertext ct u , ct v for homomorphic multiplication EvalMultMLWE Using MLWE , perform the first secure calculation process according to Equation (8) to obtain a second ciphertext ct of a polynomial with the first scalar value a as the constant term a+ and a second ciphertext ct of a polynomial with the second scalar value n1 as the constant term n1+ and a second ciphertext ct of a polynomial with the third scalar value n2_ as the constant term n2_+ Calculate them
[0565] Without decrypting the second ciphertext ct a+ , ct n1+ , ct n2_+ , use the ciphertext conversion Extract MLWEtoLWE and Convert LWEtoLWE’ and the conversion key ksk LWEtoLWE’ and the second encryption key pk LWE’ to convert them into the third ciphertext ct of the first scalar value a a , the third ciphertext ct of the second scalar value n1 n1 and the third ciphertext ct of the third scalar value n2_ n2_ respectively according to Equation (9)
[0566] The secure calculation device 4L performs the second secure calculation process on three third ciphertexts and a scalar value n representing twice the vector length l using the homomorphic multiplication EvalMult LWE’ and the homomorphic addition EvalAdd LWE’ and the homomorphic subtraction EvalSub LWE’ according to Equation (10). Through this calculation process, the secure calculation device 4L calculates the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 and the fourth ciphertext ct of the fifth scalar value Xsq1 Xsq2 Calculate them
[0567] The first terminal device 1L decrypts the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 and the fourth ciphertext ct of the fifth scalar value using the first decryption key sk Xsq1 to calculate the fourth scalar value Xsq1 and the fifth scalar value Xsq2 LWE’ Calculate them
[0568] In addition, when homomorphic division can be defined in the second homomorphic encryption method, the secret computing device 4L may output a ciphertext of the sixth scalar value Xsq = Xsq1 / Xsq2 as the output of the second secret computing process. Further, when a homomorphic comparison operation can be defined in the second homomorphic encryption method, the secret computing device 4L may output, as the output of the second secret computing process, a fourth ciphertext of two values indicating the presence or absence of the relevance between the SNP data and the trait data.
[0569] <Description of System Configuration and Functions> Next, the secret computing system 100L of this modified example will be specifically described.
[0570] FIG. 6 is a functional block diagram of an example of the first terminal device 1L of this modified example. The first terminal device 1L is the same as the first terminal device 1I of the third embodiment described above, except that it includes a key generation processing unit 11L, a transmission unit 25L, and a decryption processing unit 33L, and further includes a conversion key storage unit 14. The conversion key storage unit 14 is the same as the first terminal device 1C in the modified example 2 of the first embodiment described above.
[0571] The key generation processing unit 11L generates a public key pk MLWE and a secret key sk MLWE used in the first homomorphic encryption method. Further, the key generation processing unit 11L generates a public key pk LWE’ and a secret key sk LWE’ used in the second homomorphic encryption method. Let the secret key used in the first homomorphic encryption method be sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i = sk i,0 + sk i,1 x + … + sk i,n-1 x n-1 , the conversion key ksk LWEtoLWE’ is the encrypted sk LWE =(sk 0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 ) ciphertext ksk LWEtoLWE’ = Enc LWE’ (sk LWE ) is.
[0572] The key generation processing unit 11L uses the public key pk used in the first homomorphic encryption method used in the first terminal device 1 MLWE as the first encryption key and the secret key sk used in the second homomorphic encryption method LWE’ as the first decryption key. Note that the secret key sk used in the first homomorphic encryption method MLWE may be used as the first encryption key. Also, the public key pk used in the second homomorphic encryption method, which is used in the privacy calculation device 4L LWE’ is used as the second encryption key. The key generation processing unit 11L stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14.
[0573] The transmission unit 25L transmits the second encryption key pk stored in the encryption key storage unit 12 LWE’ and the conversion key ksk stored in the conversion key storage unit 14 LWEtoLWE’ to the privacy calculation device 4L.
[0574] The transmission unit 25L transmits the first encryption key pk stored in the encryption key storage unit 12 MLWE to the second terminal device 6L.
[0575] The encryption processing unit 23L uses the first vector u and the second vector v stored in the first data storage unit 22 with the first conversion function fw and the second conversion function bw to obtain polynomials fw(u) = u 0 + u 1 x + … + u l-1 x l-1 , bw(v) = v 0 - v 1 x n―1 - v 2 x n―2 - … - v l―1 x n-(l―1)Convert it. Then, the encryption processing unit 23L encrypts the above polynomial using the first encryption key pk stored in the encryption key storage unit 12 MLWE and calculates the first ciphertext ct encrypted by the first homomorphic encryption method u , ct v . The encryption processing unit 23L stores the ciphertext in the second data storage unit 24
[0576] The decryption processing unit 33L decrypts the fourth ciphertext ct stored in the third data storage unit 32 using the first decryption key sk stored in the decryption key storage unit 13 LWE’ and calculates the fourth scalar value Xsq1 and the fifth scalar value Xsq2. The decryption processing unit 33L stores the fourth scalar value and the fifth scalar value in the fourth data storage unit Xsq1 , ct Xsq2
[0577] Note that the input unit 21 may obtain the above polynomial fw(u) from a computer or the like connected to the first terminal device 1L and store the polynomial in the first data storage unit 22. Further, the encryption processing unit 23L may encrypt the polynomial stored in the first data storage unit 22 using the first encryption key pk MLWE stored in the encryption key storage unit 12. Then, the encryption processing unit 23L may calculate the first ciphertext ct by the encryption and store it in the second data storage unit 24 u
[0578] FIG. 10 is a functional block diagram of an example of the second terminal device 6L of this modification. The second terminal device 6L is the same as the second terminal device 6I of the third embodiment except that it includes a receiving unit 31L and an encryption processing unit 23L instead of the receiving unit 31I and the encryption processing unit 23I
[0579] The receiving unit 31L receives the encryption key pk from the first terminal device 1L MLWE and stores it in the encryption key storage unit 12
[0580] The encryption processing unit 23L converts the second vector v stored in the first data storage unit 22 into a polynomial bw(v)=v by the second conversion function bw 0 -v 1 x n―1 -v 2 x n―2 -…-v l―1 x n-(l―1) is converted. Then, the encryption processing unit 23L encrypts the polynomial using the encryption key pk MLWE stored in the encryption key storage unit 72, and calculates the first ciphertext ct v . The encryption processing unit 23L stores the first ciphertext in the second data storage unit 24.
[0581] Note that the input unit 21I may obtain the above polynomial bw(v) from a computer or the like connected to the first terminal device 1L, and store the polynomial in the first data storage unit 22. Further, the encryption processing unit 23L may encrypt the polynomial stored in the first data storage unit 22 using the first encryption key pk MLWE stored in the encryption key storage unit 12 to calculate the first ciphertext ct v , and store it in the second data storage unit 24.
[0582] FIG. 7 is a functional block diagram of an example of the secret calculation device 4L of this modified example.
[0583] The secret calculation device 4L includes a receiving unit 41L, a first secret calculation processing unit 43L, a ciphertext conversion processing unit 45L, and a second secret calculation processing unit 47L instead of the receiving unit 41I, the first secret calculation processing unit 43I, the ciphertext conversion processing unit 45I, and the second secret calculation processing unit 47I, and further includes an encryption key storage unit 51 and a conversion key storage unit 52, and is the same as the secret calculation device 4I of the third embodiment except for this. The encryption key storage unit 51 and the conversion key storage unit 52 are the same as those of the secret calculation device 4C of the modified example 2 of the first embodiment.
[0584] The receiving unit 41L receives the second encryption key pk LWE’ and the conversion key ksk LWEtoLWE’ from the first terminal device 1L. The receiving unit 41L stores the second encryption key in the encryption key storage unit 51 and stores the conversion key in the conversion key storage unit 52.
[0585] The first secret calculation processing unit 43L is the first ciphertext ctu , ct v is subjected to first confidential calculation processing using the homomorphic multiplication EvalMult of the first homomorphic encryption method MLWE . Through this calculation processing, the first confidential calculation processing unit 43L generates a second ciphertext ct of a polynomial having the first scalar value a as a constant term a+ and a second ciphertext ct of a polynomial having the second scalar value n1 as a constant term n1+ and a second ciphertext ct of a polynomial having the third scalar value n2_ as a constant term n2_+ . The first confidential calculation processing unit 43L stores the second ciphertext in the second data storage unit 44
[0586] The ciphertext conversion processing unit 45L, without decrypting the second ciphertexts ct a+ , ct n1+ , ct n2_+ , uses the ciphertext conversion Extract MLWEtoLWE , Convert LWEtoLWE’ to convert them into a third ciphertext ct of the first scalar value a a and a third ciphertext ct of the second scalar value n1 n1 and a third ciphertext ct of the third scalar value n2_ n2_ , respectively. The ciphertext conversion processing unit 45L stores the third ciphertext in the third data storage unit 46. When calculating the ciphertext conversion, the ciphertext conversion processing unit 45L uses the second encryption key pk LWE’ stored in the encryption key storage unit 51 and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 52
[0587] The second confidential calculation processing unit 47L performs second confidential calculation processing on the third ciphertexts ct a , ct n1 , ct n2_ and a scalar value n representing twice the vector length l using the homomorphic multiplication EvalMult LWE’ , the homomorphic addition EvalAdd LWE’ and the homomorphic subtraction EvalSub LWE’ . The second confidential calculation processing unit 47L generates a fourth ciphertext ct of the fourth scalar value Xsq1 obtained through this calculation processing Xsq1 and a fourth ciphertext ct of the fifth scalar value Xsq2 Xsq2Obtain it. The second secure calculation processing unit 47L stores the fourth ciphertext in the fourth data storage unit 48.
[0588] Note that the hardware configurations of the first terminal device 1L, the second terminal device 6L, and the secure calculation device 4L are the same as those of the first terminal device 1 and the secure calculation device 4 in the above first embodiment (see FIG. 5).
[0589] <Description of the flow> Next, an example of the flow of information processing executed by the first terminal device 1L, the second terminal device 6L, and the secure calculation device 4L in this modification will be described.
[0590] FIG. 12 is a flowchart showing an example of the flow of information processing executed by the first terminal device 1L, the second terminal device 6L, and the secure calculation device 4L in this modification. In this modification, in the same manner as the first terminal device 1I, the second terminal device 6I, and the secure calculation device 4I in the above third embodiment, the processing from step S15 to step S31 is executed. However, in this modification, the processing of step S32 and step S33 is executed between step S15 and step S16. Step S32 and step S33 are the same as the second modification of the above third embodiment.
[0591] However, in this modification, in step S15, the first terminal device 1L generates the public key pk MLWE and the secret key sk MLWE used in the first homomorphic encryption method. Also, the first terminal device 1L generates the public key pk LWE’ and the secret key sk LWE’ used in the second homomorphic encryption method. Let the secret key used in the first homomorphic encryption method be sk MLWE =(sk 0 , sk 1 , …, sk k-1 ). However, when sk i =sk i,0 +sk i,1 x + … + sk i,n-1 x n-1 , the conversion key ksk LWEtoLWE’ is the encrypted sk LWE =(sk0,0 , sk 0,1 , …, sk 0,n-1 , sk 1,0 , sk 1,1 , …, sk 1,n-1 , …, sk k-1,0 , sk k-1,1 , …, sk k-1,n-1 )'s ciphertext ksk LWEtoLWE’ = Enc LWE’ (sk LWE ) is.
[0592] The key generation processing unit 11L of the first terminal device 1L uses the public key pk MLWE as the first encryption key and the secret key sk LWE’ used in the second homomorphic encryption method as the first decryption key. Note that the secret key sk MLWE used in the first homomorphic encryption method may also be used as the first encryption key. Also, the key generation processing unit 11L uses the public key pk LWE’ used in the second homomorphic encryption method, which is used in the secure computing device 4L, as the second encryption key. The key generation processing unit 11L stores the first encryption key and the second encryption key in the encryption key storage unit 12, stores the first decryption key in the decryption key storage unit 13, and stores the conversion key in the conversion key storage unit 14.
[0593] In step S32, the transmission unit 25L of the first terminal device 1L transmits the first encryption key pk MLWE stored in the encryption key storage unit 12 to the second terminal device 6L.
[0594] In step S33, the reception unit 41L of the secure computing device 4L receives the second encryption key pk LWE’ and the conversion key ksk LWEtoLWE’ from the first terminal device 1L. The reception unit 41L stores the second encryption key in the encryption key storage unit 51 and stores the conversion key in the conversion key storage unit 52.
[0595] In step S16, the transmission unit 25L of the first terminal device 1L transmits the first encryption key pk MLWE stored in the encryption key storage unit 12 to the second terminal device 6L.
[0596] In step S17, the receiving unit 31L of the second terminal device 6L receives the encryption key pk from the first terminal device 1L MLWE and stores the encryption key in the encryption key storage unit 12.
[0597] In step S19, the encryption processing unit 23L of the first terminal device 1L converts the first vector u stored in the first data storage unit 22 into a polynomial fw(u)=u 0 +u 1 x+…+u l-1 x l-1 using the first conversion function fw. Then, the encryption processing unit 23L of the first terminal device 1L encrypts the polynomial using the first encryption key pk MLWE stored in the encryption key storage unit 12 and calculates the first ciphertext ct u encrypted by the first homomorphic encryption method. The encryption processing unit 23L stores the first ciphertext in the second data storage unit 24.
[0598] In step S22, the encryption processing unit 23L of the second terminal device 6L converts the second vector v stored in the first data storage unit 22 into a polynomial bw(v)=v 0 ―v 1 x n―1 ―v 2 x n―2 ―…―v l―1 x n-(l―1) using the second conversion function bw. Then, the encryption processing unit 23L of the second terminal device 6L encrypts the polynomial using the encryption key pk MLWE stored in the encryption key storage unit 72 and obtains the first ciphertext ct v encrypted by the first homomorphic encryption method. The encryption processing unit 23L of the second terminal device 6L stores the first ciphertext in the second data storage unit 24.
[0599] In step S25, the first secure calculation processing unit 43L of the secure calculation device 4L performs first secure calculation processing on the first ciphertext ct u , ct v stored in the first data storage unit 42 using the homomorphic multiplication EvalMult MLWE of the first homomorphic encryption method and obtains the second ciphertext ct of the polynomial with the first scalar value a as the constant term.a+ and a second ciphertext ct of a polynomial having a second scalar value n1 as a constant term n1+ and a second ciphertext ct of a polynomial having a third scalar value n2_ as a constant term n2_+ are calculated. The first secure calculation processing unit 43L stores the second ciphertext in the second data storage unit 44.
[0600] In step S26, the ciphertext conversion processing unit 45L of the secure calculation device 4L uses the ciphertext conversion Extract a+ ct n1+ ct n2_+ ct MLWEtoLWE Convert LWEtoLWE’ without decrypting them, and converts them into a third ciphertext ct of the first scalar value a a and a third ciphertext ct of the second scalar value n1 n1 and a third ciphertext ct of the third scalar value n2_ n2_ respectively. Then, the ciphertext conversion processing unit 45L stores the third ciphertext in the third data storage unit 46. When calculating the ciphertext conversion, the ciphertext conversion processing unit 45L uses the second encryption key pk LWE’ stored in the encryption key storage unit 51 and the conversion key ksk LWEtoLWE’ stored in the conversion key storage unit 52.
[0601] In step S27, the second secure calculation processing unit 47L of the secure calculation device 4L performs a second secure calculation on the third ciphertext ct a ct n1 ct n2_ stored in the third data storage unit 46, using the homomorphic multiplication EvalMult LWE’ and the homomorphic addition EvalAdd LWE’ and the homomorphic subtraction EvalSub LWE’ . The second secure calculation processing unit 47L obtains a fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 and a fourth ciphertext ct of the fifth scalar value Xsq2 Xsq2 by this calculation processing. The second secure calculation processing unit 47L stores the fourth ciphertext in the fourth data storage unit.
[0602] In step S30, the decryption processing unit 33L of the first terminal device 1L uses the first decryption key sk stored in the decryption key storage unit 13 LWE’ to decrypt the fourth ciphertext ct Xsq1 , ct Xsq2 and obtain the fourth scalar value Xsq1 and the fifth scalar value Xsq2. The decryption processing unit 33L stores the fourth scalar value and the fifth scalar value in the fourth data storage unit 48.
[0603] As described above, the ciphertext conversion processing unit 45L of the secure computing device 4L of this modification uses the ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method, similar to the ciphertext conversion processing unit 45 of the above embodiment, to convert the second ciphertext into the third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext. Therefore, the secure computing device 4K and the secure computing system 100K of this modification can improve the confidentiality as in the first embodiment.
[0604] Also, in the secure computing device 4L and the secure computing system 100L of this modification, calculations can be performed without decrypting the ciphertexts of the first scalar value a, the second scalar value n1, and the third scalar value n2_, which are the outputs of the first secure computing process in GWAS.
[0605] Also, in the secure computing device 4L and the secure computing system 100L of this modification, a homomorphic encryption method using Module-LWE with high security performance is available, and a homomorphic encryption method using LWE that does not depend on the ring dimension number n of Module-LWE is available.
[0606] (Fourth Embodiment) In this embodiment, a secure computing system that performs secure computing of GWAS with fewer calculation times than the secure computing system 100I of the third embodiment will be described. Hereinafter, mainly the differences from the secure computing system 100I according to the third embodiment will be described.
[0607] FIG. 9 is a schematic diagram of an example of the secure computing system 100M of this embodiment.
[0608] The confidential computing system 100M includes a first terminal device 1M, a second terminal device 6M, and a confidential computing device 4M. The first terminal device 1M, the second terminal device 6M, and the confidential computing device 4M are communicably connected via a network 5. Details of each device will be described later.
[0609] <Explanation of GWAS calculation content> In the step of testing the allele frequency table in the GWAS calculated by the confidential computing system 100M according to the present embodiment, using the scalar values a, b, c, d, n1, n2, n3, n4, and n representing the allele frequency table shown in Table 1, a chi-square test is calculated, and a scalar value Xsq representing a statistic is output.
[0610] The scalar value Xsq can be calculated by Equation (11).
[0611] Xsq = (a + b + c + d) × ((a + b + c + d) × a - (a + b) × (a + c)) 2 / ((a + b) × (a + c) × (b + d) × (c + d)) = n × (n × a - n1 × n2) 2 / (n1 × n2 × n3 × n4) ··· Equation (11)
[0612] Equation (11) corresponds to Equation (B) of the present application.
[0613] Note that when using Equation (11), the same scalar value as the scalar value Xsq that can be calculated by Equation (7) used in the confidential computing system 100I according to the third embodiment can be calculated.
[0614] Compared with the method used in the secure computing system 100I according to the third embodiment, in this embodiment, at least three subtractions and one multiplication can be reduced. When a scalar value n representing twice the vector length l is disclosed, one more multiplication can be replaced with a constant multiplication. Hereinafter, let the scalar value representing the numerator of the scalar value Xsq be Xsq1, and the scalar value representing the denominator of the scalar value Xsq be Xsq2.
[0615] In the secure computing system 100M according to this embodiment, a first vector u = (u 0 , u 1 , …, u l-1 ) of length l representing SNP data, a second vector v = (v 0 , v 1 , …, v l-1 ) of length l representing trait data indicating the presence or absence of a certain disease, and a scalar value n representing twice the vector length l are used as input data. Then, in the secure computing system 100M, as the first secure computing process, a scalar value a, a scalar value n1, and a scalar value n2_ representing half of the value of the scalar value n2 are output. Also, in the secure computing system 100M, as the second secure computing process, the scalar value a, the scalar value n1, the scalar value n2_, and the scalar value n are input, and the scalar value Xsq1 and the scalar value Xsq2 are output. In the secure computing system 100M, the data input to each of the first secure computing process and the second secure computing process is calculated while keeping it secret. Hereinafter, let the scalar value a be the first scalar value, the scalar value n1 be the second scalar value, the scalar value n2_ be the third scalar value, the scalar value Xsq1 be the fourth scalar value, and the scalar value Xsq2 be the fifth scalar value.
[0616] <Explanation of Homomorphic Encryption and Ciphertext Conversion> The secure computing system 100M according to this embodiment, similar to the secure computing system 100I according to the third embodiment, uses a first homomorphic encryption method, a second homomorphic encryption method, and ciphertext conversion between the first homomorphic encryption method and the second homomorphic encryption method to encrypt and calculate the input data of the first secure computing process and the second secure computing process. As the first homomorphic encryption method, a homomorphic encryption method using Ring-LWE is utilized, and as the second homomorphic encryption method, a homomorphic encryption method using LWE is utilized. Also, ciphertext conversion used in the homomorphic encryption method using Ring-LWE and the homomorphic encryption method using LWE is employed.
[0617] <Explanation of the secure computing method for GWAS> The secure computing system 100M according to this embodiment uses the first homomorphic encryption method, the second homomorphic encryption method, and ciphertext conversion to perform secure computing on the first secure computing process and the second secure computing process in the following procedure.
[0618] In the secure computing system 100M of this embodiment, as preparation for homomorphic encryption, the first terminal device 1M generates a secret key sk RLWE and a public key pk RLWE of the first homomorphic encryption method. Also, when the secret key used in the first homomorphic encryption method is set as sk RLWE =sk 0 +sk 1 x+…+sk n-1 x n-1 , the secret key of the second homomorphic encryption method is set as sk LWE =(sk 0 ,sk 1 ,…,sk n-1 ). The public key pk RLWE used in the first homomorphic encryption method is taken as the first encryption key, and the secret key sk LWE used in the second homomorphic encryption method is taken as the first decryption key.
[0619] The first terminal device 1M and the second terminal device 6M have a first vector u of length l = (u 0 ,u 1 ,…,u l-1 ) and a second vector v = (v 0 ,v 1 ,…,vl-1 ) is transformed by the first transformation function fw and the second transformation function bw into polynomials fw(u)=u 0 +u 1 x+…+u l-1 x l-1 , bw(v)=v 0 ―v 1 x n―1 ―v 2 x n―2 ―…―v l―1 x n-(l―1) respectively. Note that during the transformation, fw(v) and bw(u) may also be used. Then, the first terminal device 1M and the second terminal device 6M encrypt the above polynomials using the first encryption key pk RLWE respectively, and calculate two first ciphertexts ct u , ct v .
[0620] The secure computing device 4M performs the first secure computing process on the first ciphertexts ct u , ct v encrypted by the first homomorphic encryption method using the homomorphic multiplication EvalMult RLWE according to Equation (8). The secure computing device 4M calculates, through this computing process, the second ciphertext ct a+ of a polynomial with the first scalar value a as the constant term, the second ciphertext ct n1+ of a polynomial with the second scalar value n1 as the constant term, and the second ciphertext ct n2_+ of a polynomial with the third scalar value n2_ as the constant term.
[0621] The secure computing device 4M, without decrypting the second ciphertexts ct a+ , ct n1+ , ct n2_+ , uses the ciphertext transformation Extract RLWEtoLWE to transform them into the third ciphertext ct a of the first scalar value a, the third ciphertext ct n1 of the second scalar value n1, and the third ciphertext ct n2_ of the third scalar value n2_ respectively according to Equation (9).
[0622] The secure computing device 4M performs a second secure computing process on three third ciphertexts and a scalar value n representing twice the vector length l using the homomorphic multiplication EvalMult LWE and the homomorphic addition EvalAdd LWE and the homomorphic subtraction EvalSub LWE in accordance with Equation (12). Through this computing process, the secure computing device 4M obtains the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 and the fourth ciphertext ct of the fifth scalar value Xsq1 Xsq2 .
[0623] ct n2 =EvalAdd LWE (ct n2_ ,ct n2_ ) ct n3 =EvalSub LWE (n,ct n2 ) ct n4 =EvalSub LWE (n,ct n1 ) ct tmp1 =EvalMult LWE (ct n1 ,ct n2 ) ct tmp2 =EvalMult LWE (n,ct a ) ct tmp3 =EvalSub LWE (ct tmp2 ,ct tmp1 ) ct tmp4 =EvalMult LWE (ct tmp3 ,ct tmp3 ) ct Xsq1 =EvalMult LWE (n,ct tmp4 ) ct tmp5 =EvalMult LWE (ct n3 ,ct n4 ) ct Xsq2 =EvalMult LWE (cttmp1 , ct tmp5 ) ··· Equation (12)
[0624] The first terminal device 1M decrypts the fourth ciphertext ct of the fourth scalar value Xsq1 Xsq1 and the fourth ciphertext ct of the fifth scalar value Xsq1 using the first decryption key sk LWE to calculate the fourth scalar value Xsq1 and the fifth scalar value Xsq2.
[0625] Note that when homomorphic division can be defined in the second homomorphic encryption method, the secret calculation device 4M may output the fourth ciphertext of the sixth scalar value Xsq = Xsq1 / Xsq2 as the output of the second secret calculation process. Also, when homomorphic comparison operations can be defined in the second homomorphic encryption method, the secret calculation device 4M may output a binary fourth ciphertext indicating the presence or absence of the relevance between the SNP data and the trait data as the output of the second secret calculation process.
[0626] In the secret calculation system 100M of the present embodiment, compared with the method used in the secret calculation system 100I according to the third embodiment, in the secret calculation of the second secret calculation process, at least three homomorphic subtractions EvalSub LWE and one homomorphic multiplication EvalMult LWE can be reduced. Also, in the secret calculation system 100M of the present embodiment, when a scalar value n representing twice the vector length l is disclosed, one of the input data in one homomorphic multiplication EvalMult LWE can be a plaintext instead of a ciphertext.
[0627] <Description of System Configuration and Functions> Next, the secret calculation system 100M of the present embodiment will be specifically described.
[0628] FIG. 2 is a functional block diagram of an example of the first terminal device 1M of the present embodiment. The functional configuration of the first terminal device 1M is the same as that of the first terminal device 1I of the third embodiment.
[0629] FIG. 10 is a functional block diagram of an example of the second terminal device 6M of the present embodiment. The functional configuration of the second terminal device 6M is the same as that of the second terminal device 6I of the third embodiment.
[0630] FIG. 3 is a functional block diagram of an example of the secure computing device 4M of the present embodiment.
[0631] The secure computing device 4M is the same as the secure computing device 4I of the third embodiment described above, except that it includes a second secure computing processing unit 47M instead of the second secure computing processing unit 47I.
[0632] The second secure computing processing unit 47M performs second secure computing processing on the third ciphertext ct a , ct n1 , ct n2_ stored in the third data storage unit 46 and a scalar value n representing twice the vector length l, using the homomorphic multiplication EvalMult LWE and the homomorphic addition EvalAdd LWE and the homomorphic subtraction EvalSub LWE . Through this calculation process, the second secure computing processing unit 47M obtains the fourth ciphertext ct Xsq1 of the fourth scalar value Xsq1 and the fourth ciphertext ct Xsq2 of the fifth scalar value Xsq2. The second secure computing processing unit 47M stores the fourth ciphertext in the fourth data storage unit 48. When performing this second secure computing processing, the second secure computing processing unit 47M executes the secure computing processing using the above formula (12).
[0633] Note that the hardware configurations of the first terminal device 1M, the second terminal device 6M, and the secure computing device 4M are the same as those of the first terminal device 1 and the secure computing device 4 of the first embodiment described above (see FIG. 5).
[0634] <Description of the flow> Next, an example of the information processing flow executed by the first terminal device 1M, the second terminal device 6M, and the secure computing device 4M of the present embodiment will be described.
[0635] FIG. 11 is a flowchart showing an example of the flow of information processing executed by the first terminal device 1M, the second terminal device 6M, and the secure computing device 4M of the present embodiment. The first terminal device 1M, the second terminal device 6M, and the secure computing device 4M of the present embodiment execute the processing of steps S15 to S31 in the same manner as in the third embodiment.
[0636] However, in step S27, the second secure computing processing unit 47M of the secure computing device 4M performs a second secure computing process on the third ciphertext ct a , ct n1 , ct n2_ stored in the third data storage unit 46 and a scalar value n representing twice the vector length l, using the homomorphic multiplication EvalMult LWE and the homomorphic addition EvalAdd LWE , and the homomorphic subtraction EvalSub LWE . By this calculation process, the second secure computing processing unit 47M calculates the fourth ciphertext ct Xsq1 of the fourth scalar value Xsq1 and the fourth ciphertext ct Xsq2 of the fifth scalar value Xsq2. The second secure computing processing unit 47M stores the fourth ciphertext in the fourth data storage unit 48. The second secure computing processing unit 47M executes the secure computing process using the above formula (12) during this second secure computing process.
[0637] As described above, the secure computing device 4M of the present embodiment, like the above embodiment, use...
Claims
1. A first secure calculation processing unit that calculates a second ciphertext by performing a first secure calculation process using a first homomorphic operation according to the first homomorphic encryption method on a first ciphertext obtained by encrypting input data using the first homomorphic encryption method; A ciphertext conversion processing unit that converts the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption method using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method without decrypting the second ciphertext; A second secure calculation processing unit that calculates a fourth ciphertext by performing a second secure calculation process using a second homomorphic operation according to the second homomorphic encryption method on the third ciphertext; A secure calculation device comprising the above.
2. The first homomorphic operation and the second homomorphic operation include multiplication and addition. The secure calculation device according to Claim 1.
3. The first secure calculation process includes a calculation process of an inner product or a sum. The second secure calculation process includes an addition, multiplication, or identity operation process. The secure calculation device according to Claim 1.
4. The first secure calculation processing unit calculates a second ciphertext in which a plaintext including a scalar value is encrypted by performing the first secure calculation process on the first ciphertext in which a plaintext including a vector is encrypted; The ciphertext conversion processing unit converts the second ciphertext into a third ciphertext in which a plaintext of a scalar value is encrypted by the second homomorphic encryption method; The second secure calculation processing unit calculates a fourth ciphertext in which a plaintext of a scalar value is encrypted by performing the second secure calculation process on the third ciphertext. The secure calculation device according to Claim 1.
5. The first secure calculation processing unit calculates a second ciphertext in which a plaintext of a scalar value representing an element of a cross-tabulation table aggregated by performing the first secure calculation process on the first ciphertext in which a plaintext including a vector is encrypted is encrypted; The ciphertext conversion processing unit converts the second ciphertext into a third ciphertext in which a plaintext of a scalar value representing an element of the cross-tabulation table encrypted by the second homomorphic encryption method is encrypted; The second secure calculation processing unit calculates a fourth ciphertext in which a plaintext of a scalar value representing a test result of the cross-tabulation table is encrypted by performing the second secure calculation process on the third ciphertext. The secure calculation device according to Claim 4, characterized by the above.
6. The first secure calculation processing unit Calculate the second ciphertext obtained by encrypting the plaintext of the scalar value representing the element of the 2×2 cross-tabulation table aggregated by the first secure calculation process for the first ciphertext obtained by encrypting the plaintext including the vector, The ciphertext conversion processing unit, Convert the second ciphertext into a third ciphertext obtained by encrypting the plaintext of the scalar value representing the element of the 2×2 cross-tabulation table encrypted by the second homomorphic encryption method, The second secure calculation processing unit, Calculate a fourth ciphertext obtained by encrypting the plaintext of the scalar value representing the chi-square test result of the 2×2 cross-tabulation table by the second secure calculation process for the third ciphertext, The chi-square test is represented by formula (A) or formula (B), The secure calculation device according to claim 5. Xsq = (a + b + c + d) × (a × d - b × c) 2 / ((a + b) × (a + c) × (b + d) × (c + d))... Equation (A) Xsq = (a + b + c + d) × ((a + b + c + d) × a - (a + b) × (a + c)) 2 / ((a + b) × (a + c) × (b + d) × (c + d))... Equation (B) [In formulas (A) and (B), a, b, c, and d represent scalar values representing elements of the cross-tabulation table.]
7. The first secure calculation process is at least one calculation process of inner product or sum for a vector, The second secure calculation process is at least one addition or multiplication for a scalar value, The secure calculation device according to claim 6.
8. The input data includes two polynomials whose coefficients are elements of a vector, The first secure calculation processing unit, By the first secure calculation process using the first homomorphic operation which is a homomorphic inner product operation according to the first homomorphic encryption method for the two first ciphertexts obtained by encrypting each of the two polynomials included in the input data, calculate the second ciphertext of the plaintext of the polynomial in which the scalar value of the inner product result is stored in the constant term, The ciphertext conversion processing unit, Without decrypting the second ciphertext, convert the second ciphertext into a third ciphertext obtained by encrypting the plaintext of the scalar value of the constant term of the polynomial encrypted by the second homomorphic encryption method, The second secure calculation processing unit, Calculate a fourth ciphertext by the second secure calculation process using the second homomorphic operation including at least one homomorphic multiplication and homomorphic addition for the third ciphertext, The secure calculation device according to claim 1.
9. The first homomorphic encryption method is A homomorphic encryption method using Ring-LWE or a homomorphic encryption method using Module-LWE, The second homomorphic encryption method is LWE or a homomorphic encryption method using LWE independent of the ring dimension number of the first homomorphic encryption method, The ciphertext conversion method is A ciphertext conversion method between the second ciphertext encrypted by the first homomorphic encryption method using Ring-LWE or Module-LWE, and the third ciphertext encrypted by the second homomorphic encryption method using LWE or LWE independent of the ring dimension of the first homomorphic encryption method, The ciphertext conversion processing unit, By performing a process of extracting a part of the numerical values constituting the second ciphertext of the polynomial or, in addition to the process, performing a calculation process using an encryption key and a conversion key, the second ciphertext is converted into the third ciphertext in which the plaintext of the scalar value of the constant term of the polynomial is encrypted without decrypting the second ciphertext, The secret calculation device according to claim 8.
10. The first homomorphic encryption method is, A homomorphic encryption method using Ring-LWE, The second homomorphic encryption method is, A homomorphic encryption method using LWE, The ciphertext conversion method is, A ciphertext conversion method between the second ciphertext encrypted by the first homomorphic encryption method using Ring-LWE and the third ciphertext encrypted by the second homomorphic encryption method using LWE, The secret calculation device according to claim 9.
11. The first homomorphic encryption method is, A homomorphic encryption method using Module-LWE, The second homomorphic encryption method is, A homomorphic encryption method using LWE, The ciphertext conversion method is, A ciphertext conversion method between the second ciphertext encrypted by the first homomorphic encryption method using Module-LWE and the third ciphertext encrypted by the second homomorphic encryption method using LWE, The secret calculation device according to claim 9.
12. The first homomorphic encryption method is, A homomorphic encryption method using Ring-LWE, The second homomorphic encryption method is, A homomorphic encryption method using LWE independent of the ring dimension of the first homomorphic encryption method, The ciphertext conversion method is, A ciphertext conversion method between the second ciphertext encrypted by the first homomorphic encryption method using Ring-LWE and the third ciphertext encrypted by the second homomorphic encryption method using LWE independent of the ring dimension of the first homomorphic encryption method, The secret calculation device according to claim 9.
13. The first homomorphic encryption method is, A homomorphic encryption method using Module-LWE, The second homomorphic encryption method is, A homomorphic encryption method using LWE that is independent of the ring dimension of the first homomorphic encryption method. The ciphertext conversion method is A ciphertext conversion method between the second ciphertext encrypted by the first homomorphic encryption method using Module-LWE and the third ciphertext encrypted by the second homomorphic encryption method using LWE that is independent of the ring dimension of the first homomorphic encryption method. The secure computing device according to claim 9.
14. The ciphertext conversion method is A ciphertext conversion method between the second ciphertext encrypted by the first homomorphic encryption method using Ring-LWE or Module-LWE and the third ciphertext encrypted by the second homomorphic encryption method using LWE that is independent of the ring dimension of the first homomorphic encryption method. The ciphertext conversion processing unit Converts the second ciphertext into the third ciphertext using the encryption key of the second homomorphic encryption method and the conversion key used for ciphertext conversion without decrypting the second ciphertext. The secure computing device according to claim 9.
15. A secure computing system comprising the secure computing device according to claim 1 and a first terminal device communicating with the secure computing device, The first terminal device A key generation processing unit that generates an encryption key of the first homomorphic encryption method and a decryption key of the second homomorphic encryption method, An encryption processing unit that calculates the first ciphertext obtained by encrypting the input data using the encryption key, A decryption processing unit that calculates output data obtained by decrypting the fourth ciphertext received from the secure computing device using the decryption key, A secure computing system comprising at least one of the above.
16. The key generation processing unit Further generates a conversion key used for ciphertext conversion. The secure computing system according to claim 15.
17. A secure computing system comprising the secure computing device according to claim 1, a first terminal device communicating with the secure computing device, and a second terminal device communicating with the secure computing device and the first terminal device, The first terminal device A key generation processing unit that generates an encryption key of the first homomorphic encryption method and a decryption key of the second homomorphic encryption method, A first input unit that acquires input data, An encryption processing unit that calculates the first ciphertext obtained by encrypting the input data using the encryption key, A second transmission unit that transmits the first ciphertext to the secure computing device. A decryption processing unit that calculates output data obtained by decrypting the fourth ciphertext received from the anonymized computing device using the decryption key; An output unit that outputs the output data; Comprising: The second terminal device A third transmission unit that transmits the first ciphertext obtained by encrypting the input data using the encryption key to the anonymized computing device; Comprising: An anonymized computing system.
18. An anonymized computing method executed by an anonymized computing device, comprising: Calculating a second ciphertext by a first anonymized computing process using a first homomorphic operation according to the first homomorphic encryption method on a first ciphertext obtained by encrypting input data using the first homomorphic encryption method; Converting the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext, using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method; Calculating a fourth ciphertext by a second anonymized computing process using a second homomorphic operation according to the second homomorphic encryption method on the third ciphertext; An anonymized computing method including the above steps.
19. A computer Calculating a second ciphertext by a first anonymized computing process using a first homomorphic operation according to the first homomorphic encryption method on a first ciphertext obtained by encrypting input data using the first homomorphic encryption method; Converting the second ciphertext into a third ciphertext encrypted by the second homomorphic encryption method without decrypting the second ciphertext, using a ciphertext conversion method defined between the first homomorphic encryption method and the second homomorphic encryption method; Calculating a fourth ciphertext by a second anonymized computing process using a second homomorphic operation according to the second homomorphic encryption method on the third ciphertext; An anonymized computing program for causing the above steps to be executed.
Citation Information
Patent Citations
Computation on LWE-encrypted values
WO2022248396A1
Similarity calculation system, similarity calculation device, similarity calculation method, and similarity calculation program
WO2022201277A1