Encrypted data computation device, cryptographic system, encrypted data computation method, and encrypted data computation program
The encrypted data calculation device and method improve the efficiency of two-variable non-linear operations in integer-type homomorphic encryption by employing One-HotSlot and EvalSum operations, reducing computational complexity from O(√N) to O(log N) and enhancing processing speed.
Patent Information
- Application Number
- JP2023210521
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-13
- Publication Date
- 2025-06-25
AI Technical Summary
Existing integer-type homomorphic encryption methods face inefficiencies in performing two-variable non-linear operations due to high computational complexity, particularly when dealing with large ranges of variable values, as they require O(√N) number theoretic transforms using Lagrange interpolation polynomials.
An encrypted data calculation device and method that employs One-HotSlot operations, a lookup table matrix, and EvalSum operations to convert and process ciphertexts of variables into indicator vectors, reducing computational complexity to O(log N) by utilizing improved homomorphic linear transformations and look-up table matrix operations.
The proposed solution significantly reduces the number of number-theoretic transforms required, increasing processing speed by approximately 10 times compared to conventional methods, thereby enhancing the efficiency of two-variable non-linear operations.
Smart Images

Figure 2025094776000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an encrypted data calculation device, an encryption system, an encrypted data calculation method, and an encrypted data calculation program.
Background Art
[0002] As a technology that enables calculation without decrypting data on a computing server, a special encryption technology called homomorphic encryption is known. Among homomorphic encryption technologies, those that can perform addition and multiplication on integer plaintexts are called integer-type homomorphic encryption.
[0003] Two-variable computational processes such as division and comparison operations, which cannot be easily realized by addition and multiplication, are called two-variable non-linear operations, and are utilized in applications such as encrypted database operations (search processing) and anomaly detection in an encrypted state. Since two-variable non-linear operations cannot be easily realized by addition and multiplication, it is not easy to implement them with integer-type homomorphic encryption either. However, as a method of implementing two-variable non-linear operations with integer-type homomorphic encryption, a method using Lagrange interpolation polynomials is known (see Non-Patent Document 1).
Prior Art Documents
Non-Patent Documents
[0004]
Non-Patent Document 1
Non-Patent Document 2
Non-Patent Document 3
[0005] Note that each disclosure of the above prior art documents is incorporated herein by reference. The following analysis was made by the present inventors.
[0006] By the way, the calculation using the Lagrange interpolation polynomial requires a large computational complexity. Specifically, assuming that the range of values that the variables used in the two-variable non-linear operation can take is from 0 to N-1, the calculation using the Lagrange interpolation polynomial asymptotically requires O(√N) number theoretic transforms / inverse number theoretic transforms. That is, the larger the range of values that the variables used in the two-variable non-linear operation can take, the greater the computational complexity required for the calculation using the Lagrange interpolation polynomial. Therefore, there is a need to improve the efficiency of the calculation in the general two-variable non-linear operation using integer-based homomorphic encryption.
[0007] In view of the above-described problems, an object of the present invention is to provide an encrypted data calculation device, an encryption system, an encrypted data calculation method, and an encrypted data calculation program that contribute to improving the efficiency of calculation in a general-purpose two-variable non-linear operation using integer homomorphic encryption.
Means for Solving the Problems
[0008] In a first aspect of the present invention, there is provided an encrypted data calculation device that calculates a ciphertext of a result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values of integers from 0 to N-1, the encrypted data calculation device including: a first One-HotSlot operation unit that converts the ciphertext of the first variable into an N-dimensional first indicator vector ciphertext in which only the component of the value of the first variable is 1 and the other components are 0; a second One-HotSlot operation unit that converts the ciphertext of the second variable into an N-dimensional second indicator vector ciphertext in which only the component of the value of the second variable is 1 and the other components are 0; a look-up table matrix of N×N that holds a plaintext obtained by previously calculating the results of the two-variable non-linear operation for all possible combinations of the values of the first variable and the second variable; a LUT matrix operation unit that extracts the row of the value of the first variable in the look-up table matrix by operating the first indicator vector ciphertext on the look-up table matrix; a multiplication operation unit that multiplies the vector ciphertext obtained by extracting the row of the value of the first variable in the look-up table matrix and the second indicator vector ciphertext; and an EvalSum operation unit that performs a calculation such that each slot of the vector ciphertext of the result of the multiplication operation unit becomes the sum of the values of all the slots.
[0009] In a second aspect of the present invention, there is provided a key generation device that generates the above-described encrypted data calculation device, a decryption key for decrypting a ciphertext, an encryption key for calculating a ciphertext from a plaintext, and an operation key for performing addition and multiplication on a plaintext while keeping the ciphertext encrypted, and transmits the operation key to the encrypted data calculation device. An encryption device that calculates ciphertexts of a first variable and a second variable having values of integers from 0 to N-1 using the encryption key and transmits the ciphertexts of the first variable and the second variable to the encrypted data calculation device. An encryption system is provided that includes the above.
[0010] In a third aspect of the present invention, there is provided an encrypted data calculation method for calculating a ciphertext of a result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values of integers from 0 to N-1, the method including: a first One-HotSlot operation for converting the ciphertext of the first variable into an N-dimensional first indicator vector ciphertext in which only a component of the value of the first variable is 1 and other components are 0; a second One-HotSlot operation for converting the ciphertext of the second variable into an N-dimensional second indicator vector ciphertext in which only a component of the value of the second variable is 1 and other components are 0; holding, as an N×N lookup table matrix, a ciphertext obtained by pre-calculating results of the two-variable non-linear operation for all possible combinations of values of the first variable and the second variable; an LUT matrix operation for extracting a row of the value of the first variable in the lookup table matrix by applying the first indicator vector ciphertext to the lookup table matrix; a multiplication operation for multiplying a vector ciphertext obtained by extracting the row of the value of the first variable in the lookup table matrix and the second indicator vector ciphertext; and an EvalSum operation for performing a calculation such that each slot of the vector ciphertext of the result of the multiplication operation is the sum of the values of all slots.
[0011] In a fourth aspect of the present invention, there is provided an encrypted data calculation program for causing a computer to execute a process of calculating an encrypted text of a result of a two-variable non-linear operation from encrypted texts of a first variable and a second variable having values as integers from 0 to N-1, the encrypted text of the first variable being converted into an N-dimensional first indicator vector encrypted text in which only the component of the value of the first variable is 1 and the other components are 0 by a first One-HotSlot operation process, the encrypted text of the second variable being converted into an N-dimensional second indicator vector encrypted text in which only the component of the value of the second variable is 1 and the other components are 0 by a second One-HotSlot operation process, an encrypted text obtained by previously calculating the results of the two-variable non-linear operation for all possible combinations of the values of the first variable and the second variable being held as an N×N lookup table matrix, an LUT matrix operation process of extracting a row of the value of the first variable in the lookup table matrix by causing the first indicator vector encrypted text to act on the lookup table matrix, a multiplication operation process of multiplying a vector encrypted text obtained by extracting the row of the value of the first variable in the lookup table matrix and the second indicator vector encrypted text, and an EvalSum operation process of performing a calculation in which each slot of the vector encrypted text as a result of the multiplication operation process becomes the sum of the values of all the slots. Note that this program can be recorded on a computer-readable storage medium. The storage medium can be a non-transient one such as a semiconductor memory, a hard disk, a magnetic recording medium, an optical recording medium, etc. The present invention can also be embodied as a computer program product.
Effect of the Invention
[0012] According to each aspect of the present invention, it is possible to provide an encrypted data calculation device, an encryption system, an encrypted data calculation method, and an encrypted data calculation program that contribute to improving the efficiency of calculation in a general-purpose two-variable non-linear operation using integer-type homomorphic encryption.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
[0014] Hereinafter, embodiments of the present invention will be described with reference to the drawings. However, the present invention is not limited to the embodiments described below. Also, in each drawing, the same or corresponding elements are appropriately given the same reference numerals. Furthermore, it should be noted that the drawings are schematic, and the dimensional relationships and ratios of the respective elements may be different from the actual ones. There may also be portions where the dimensional relationships and ratios are different between the drawings.
[0015] [Encrypted Data Calculation Device] FIG. 1 is a diagram showing a schematic configuration of an encrypted data calculation device according to an embodiment. The encrypted data calculation device according to the embodiment is a device that calculates an encrypted text of the result of a two-variable non-linear operation from encrypted texts of a first variable and a second variable having values as integers from 0 to N-1. As shown in FIG. 1, the encrypted data calculation device 120 includes a transmission / reception unit 121, an encrypted text storage unit 122, an operation key storage unit 123, a first One-HotSlot operation unit 124_1, a second One-HotSlot operation unit 124_2, a LUT matrix operation unit 125, a LUT matrix storage unit 126, a multiplication operation unit 127, and an EvalSum operation unit 128.
[0016] The transmission / reception unit 121 is an interface for transmitting and receiving data with an external device of the encrypted data calculation device 120. For example, the transmission / reception unit 121 is used to receive ciphertexts of the first variable and the second variable used for the two-variable non-linear operation, and transmit the ciphertext of the result of the two-variable non-linear operation. Further, the transmission / reception unit 121 is used for passing information necessary for executing the two-variable non-linear operation, such as an operation key used for the homomorphic operation of the ciphertext.
[0017] The ciphertext storage unit 122 is a storage device for storing ciphertexts. For example, the ciphertext storage unit 122 is used to store the ciphertexts of the first variable and the second variable used for the two-variable non-linear operation received by the transmission / reception unit 121, and the ciphertext of the result of the two-variable non-linear operation. Note that the ciphertexts of the first variable and the second variable are those obtained by encrypting, using a homomorphic cipher, the values obtained by packing the same values of the first variable and the second variable into all N slots and packing them into a polynomial ring with finite field coefficients.
[0018] The operation key storage unit 123 is a storage device for storing operation keys. The process of calculating the ciphertext of the result of the two-variable non-linear operation from the ciphertexts of the first variable and the second variable executes a combination of homomorphic operations that perform addition and multiplication on the plaintext while keeping the ciphertext encrypted, so an operation key for executing the homomorphic operation is required. The operation key storage unit 123 is used to store the operation key for executing this homomorphic operation.
[0019] The first One-HotSlot operation unit 124_1 performs a process of converting the ciphertext of the first variable into an N-dimensional first indicator vector ciphertext in which only the components of the value of the first variable are 1 and the other components are 0. The details of this process will be described later.
[0020] The second One-HotSlot operation unit 124_2 performs a process of converting the ciphertext of the second variable into an N-dimensional second indicator vector ciphertext in which only the components of the value of the second variable are 1 and the other components are 0. The details of this process will be described later.
[0021] The LUT matrix calculation unit 125 performs a process of extracting the row of the value of the first variable in the lookup table matrix by applying the first indicator vector ciphertext to the lookup table matrix. Here, the lookup table matrix is a plaintext in which the results of two-variable non-linear operations for all possible combinations of the values of the first variable and the second variable are pre-calculated and held in the LUT matrix storage unit 126 as an N×N matrix, and the LUT matrix calculation unit 125 performs processing with reference to the lookup table matrix held in the LUT matrix storage unit 126.
[0022] The multiplication operation unit 127 multiplies the vector ciphertext obtained by extracting the row of the value of the first variable in the lookup table matrix and the second indicator vector ciphertext. By this process, an N-dimensional vector ciphertext is obtained in which only the components of the value of the second variable are the results of the two-variable non-linear operation and the other components are 0.
[0023] The EvalSum operation unit 128 performs a calculation such that each slot of the vector ciphertext that is the result of the multiplication operation unit 127 becomes the sum of the values of all the slots. Since the result of the multiplication operation unit 127 is an N-dimensional vector ciphertext in which only the components of the value of the second variable are the results of the two-variable non-linear operation and the other components are 0, the result of the processing of the EvalSum operation unit 128 is a vector ciphertext in which the value of each slot is the result of the two-variable non-linear operation. That is, when the vector ciphertext that is the result of the processing of the EvalSum operation unit 128 is decrypted, the result of the two-variable non-linear operation regarding the ciphertexts of the first variable and the second variable is obtained. However, since the encryption data calculation device 120 does not hold a decryption key for decrypting the ciphertext, in order to transmit it to an external device of the encryption data calculation device 120 that holds the decryption key, the vector ciphertext that is the result of the processing of the EvalSum operation unit 128 is stored in the ciphertext storage unit 122.
[0024] As will be described later, the computational complexity of the number-theoretic transform / inverse number-theoretic transform in the two-variable non-linear operation executed by the above-described encrypted data calculation device 120 is asymptotically O(log N) times. In the conventional calculation using the Lagrange interpolation polynomial, asymptotically O(√N) times of number-theoretic transform / inverse number-theoretic transform were required. Therefore, in the two-variable non-linear operation executed by the encrypted data calculation device 120, the number of times of number-theoretic transform / inverse number-theoretic transform can be asymptotically reduced.
[0025] For example, when N = 2 15 in the case of the conventional calculation using the Lagrange interpolation polynomial, approximately 181 times of number-theoretic transform / inverse number-theoretic transform are performed. However, the computational complexity of the number-theoretic transform / inverse number-theoretic transform in the two-variable non-linear operation executed by the encrypted data calculation device 120 is 15 times. Since the computational complexity of the number-theoretic transform / inverse number-theoretic transform can be reduced to 1 / 10, the processing speed is expected to be increased by about 10 times.
[0026] 〔Encrypted Data Calculation Method〕 FIG. 2 is a diagram showing a schematic procedure of the encrypted data calculation method according to the embodiment. The encrypted data calculation method according to the embodiment calculates the ciphertext of the result of the two-variable non-linear operation from the ciphertexts of the first variable and the second variable having values as integers from 0 to N - 1. As shown in FIG. 2, the encrypted data calculation method includes a first One-HotSlot operation S1, a second One-HotSlot operation S2, a LUT matrix operation S3, a multiplication operation S4, and an EvalSum operation S5.
[0027] As shown in FIG. 2, the encrypted data calculation method starts from obtaining the ciphertexts of the first variable and the second variable used for the two-variable non-linear operation. Note that the ciphertexts P1 and P2 of the first variable and the second variable are obtained by encrypting, using a homomorphic cipher, the result of packing the same values a and b of the first variable and the second variable into all N slots and packing them into a polynomial ring with finite field coefficients.
[0028] The first One - Hot Slot operation S1 performs a process of converting the ciphertext P1 of the first variable into an N - dimensional first indicator vector ciphertext P3 in which only the component of the value a of the first variable is 1 and the other components are 0. The details of this process will be described later.
[0029] The second One - Hot Slot operation S2 performs a process of converting the ciphertext P2 of the second variable into an N - dimensional second indicator vector ciphertext P4 in which only the component of the value b of the second variable is 1 and the other components are 0. The details of this process will be described later.
[0030] The LUT matrix operation S3 extracts the row P5 of the value a of the first variable in the lookup table matrix F by applying the first indicator vector ciphertext P3 to the lookup table matrix F. Here, the lookup table matrix F is an N×N matrix obtained by pre - calculating the plaintext of the results of a two - variable non - linear operation for all possible combinations of the values a and b of the first variable and the second variable. If the two - variable non - linear operation is f(a,b), the lookup table matrix F is a matrix as follows.
Number
[0031] The multiplication operation S4 multiplies the vector ciphertext P5 obtained by extracting the row of the value a of the first variable in the lookup table matrix F and the second indicator vector ciphertext P4. By this process, an N - dimensional vector ciphertext P6 is obtained in which only the component of the value b of the second variable is the result f(a,b) of the two - variable non - linear operation and the other components are 0.
[0032] The EvalSum operation S5 performs a calculation where each slot of the vector ciphertext P6, which is the result of the multiplication operation S4, becomes the sum of the values of all slots. Since the result of the multiplication operation S4 is an N - dimensional vector ciphertext P6 in which only the components of the value of the second variable are the result of the two - variable non - linear operation and the other components are 0, the result of the processing of the EvalSum operation S5 is a vector ciphertext P7 where the value of each slot is the result f(a, b) of the two - variable non - linear operation. That is, when decrypting the vector ciphertext P7 which is the result of the processing of the EvalSum operation S5, the result f(a, b) of the two - variable non - linear operation regarding the ciphertexts of the first variable and the second variable can be obtained.
[0033] Hereinafter, each process executed in the encryption data calculation method and the encryption data calculation device according to the embodiment will be described in more detail.
[0034] (Packing process) As described above, the encryption data calculation method and the encryption data calculation device according to the embodiment start the process by acquiring the ciphertexts of the first variable and the second variable used for the two - variable non - linear operation. The ciphertexts of the first variable and the second variable are obtained by encrypting, using a homomorphic cipher, the ones obtained by packing the same values of the first variable and the second variable into all N slots and packing them into a polynomial ring with finite - field coefficients.
[0035] Here, packing is a method of associating a vector with a (plaintext) polynomial while maintaining the sum and product, and if we represent the association of the vector (a’0,..., a’ N-1 ) with a polynomial as Pack(a’0,..., a’ N-1 ), the following relationship holds.
Equation
[0036] Such an associative Pack can be constructed using a ring isomorphism based on the Chinese Remainder Theorem. In the following formula, ω is a primitive 2N-th root of unity.
Number
[0037] That is, the associative Pack can be constructed using the above ring isomorphism as follows.
Number
[0038] Here, since the plaintext spaces of the integer-type homomorphic cryptosystems BFV (Non-Patent Document 4) and BGV (Non-Patent Document 5) are polynomial rings (over finite fields), the Pack (a’0,..., a’ N-1 ) that associates the vector (a’0,..., a’ N-1 ) constructed as above with a polynomial can be encrypted. Representing the function for encryption using the integer-type homomorphic cryptosystems BFV and BGV as Enc(), the following relationship holds.
Number
[0039] Here, since the condition for packing is t ≡ 1 (mod 2N), t > 2N. That is, each slot of F t N in which the Pack function is defined is F t = {0, 1,... N - 1, N,..., t - 1}, but in the encryption data calculation method and the encryption data calculation device according to the embodiment, only the range of {0, 1,... N - 1} is used.
[0040] Furthermore, in the encrypted data calculation method and the encrypted data calculation device according to the embodiment, a packed plaintext in which all slots are filled with the same integer (the first variable and the second variable that are the targets of the two-variable non-linear operation) is used.
[0041] That is, the ciphertexts of the first variable and the second variable having values of integers from 0 to N-1 used in the encrypted data calculation method and the encrypted data calculation device according to the embodiment are obtained by encrypting, using a homomorphic cipher, a packing into a polynomial ring with finite field coefficients by assigning the same values of the first variable and the second variable to all N slots. That is, when the first variable is a and the second variable is b, it is Enc(Pack(a,...,a)) and Enc(Pack(b,...,b)) configured as described above.
[0042] (One-HotSlot operation) The encrypted data calculation method and the encrypted data calculation device according to the embodiment convert the ciphertext of the first variable into an N-dimensional first indicator vector ciphertext in which only the component of the value of the first variable is 1 and the other components are 0, and convert the ciphertext of the second variable into an N-dimensional second indicator vector ciphertext in which only the b component of the value of the second variable is 1 and the other components are 0. This process is a process of converting the plaintext into an indicator vector while keeping the ciphertexts of the first variable Enc(Pack(a,...,a)) and the second variable Enc(Pack(b,...,b)) in the encrypted state, and is the following conversion. [Equation] The above Pack(0,...,0,1,0,...,0) is a vector in which only the b component is 1 and the other components are 0.
[0043] The above conversion can be configured as follows. When the packed ciphertext Enc(Pack(b,...,b)) is input, the following homomorphic operation is performed.
[0044] 1: Enc(Pack(b, b - 1,..., 0,..., b - N + 1)) ← Enc(Pack(b,..., b)) - Pack(0, 1,..., N - 1) However, in the above Enc(Pack(b, b - 1,..., 0,..., b - N + 1)), only the b-th component is 0.
[0045] 2: Enc(Pack(1, 1,..., 1, 0, 1,..., 1)) ← Enc(Pack(b, b - 1,..., 0,..., b - N + 1)) t-1 The above uses Fermat's little theorem. Also, for the computational complexity of the number-theoretic transform / inverse number-theoretic transform in the above process, since t ≡ 1 (mod 2N) implies t = c·2N + 1 (c: constant), O(log(t)) = O(log(N)).
[0046] 3: Enc(Pack(0,..., 0, 1, 0,..., 0)) ← Pack(1, 1,..., 1) - Enc(Pack(1,..., 1, 0, 1,..., 1))
[0047] 4: Output Enc(Pack(0,..., 0, 1, 0,..., 0)). This is the N-dimensional second indicator vector ciphertext where only the b-th component of the value of the second variable is 1 and the other components are 0.
[0048] As described above, for the One-Hot Slot operation executed by the encryption data calculation method and the encryption data calculation device according to the embodiment, the asymptotic computational complexity of the number-theoretic transform / inverse number-theoretic transform is O(log(N)).
[0049] (LUT matrix operation) The encryption data calculation method and the encryption data calculation device according to the embodiment perform a process of extracting a row of values of a first variable in the lookup table matrix F by applying a first indicator vector ciphertext to the lookup table matrix F. For the process of applying a matrix to the packed ciphertext in this encrypted state, Homomorphic Linear Transformation described in Non-Patent Document 2 can be used.
[0050] In Homomorphic Linear Transformation, automorphisms of the order of the matrix to be applied (N in this embodiment) are required, and O(N) automorphisms are required for simple application. The Automorphism operation is a process that causes rotation for the slots of the packed ciphertext, and since O(1) number-theoretic transforms / inverse number-theoretic transforms are performed per time, the computational complexity is high. However, in Homomorphic Linear Transformation, there is a process that can be reused because the same operation on the ciphertext is repeated. On the other hand, Non-Patent Document 3 describes a technique called Improved Hoisted-Rotations that reuses the number-theoretic transform calculated once. By using this Improved Hoisted-Rotations, the asymptotic computational complexity of the number-theoretic transform / inverse number-theoretic transform in Homomorphic Linear Transformation can be reduced to O(1) times.
[0051] More specifically, in Homomorphic Linear Transformation, the internal processing that occurs separately from the automorphism operation differs depending on whether each component of the matrix to be applied is a plaintext or a ciphertext. When each component of the matrix to be applied is a plaintext, the multiplication of the ciphertext and the plaintext occurs N times. When each component of the matrix to be applied is a ciphertext, the multiplication of the ciphertexts occurs N times. And since each component of the lookup table matrix F used in the Homomorphic Linear Transformation of this embodiment is information that does not need to be concealed, it is stored as a plaintext, and the multiplication of the ciphertext and the plaintext occurs N times. When the multiplication of the ciphertexts occurs N times, the number-theoretic transform is performed O(N) times. However, even when the multiplication of the ciphertext and the plaintext occurs N times, the asymptotic computational complexity is O(1) times. Therefore, the asymptotic computational complexity of the number-theoretic transform / inverse number-theoretic transform in the Homomorphic Linear Transformation of this embodiment is O(1) times.
[0052] Note that Homomorphic Linear Transformation is a process proposed as a subroutine of the Bootstrapping process. The Bootstrapping process was proposed to reduce the noise (a factor that reduces the decoding probability) accumulated in the ciphertext by a quasi-homomorphic operation without decoding it. By performing this process, a Somewhat quasi-homomorphic cipher can be converted into a fully homomorphic cipher.
[0053] For the convenience of such an object, the packing process used in Homomorphic Linear Transformation utilizes a mapping that decomposes the polynomial ring R t into a vector F t d N / d of an extension body. On the other hand, the encrypted data calculation method and the encrypted data calculation device according to the embodiment decompose the polynomial ring R t into a vector F t NSince it uses a mapping that decomposes into, it has more slots than the packing process used in Homomorphic Linear Transformation. Therefore, in the encryption data calculation method and the encryption data calculation device according to the embodiment, the algorithm of Homomorphic Linear Transformation is adjusted in order to apply it to the packing process that uses the maximum number of slots.
[0054] (EvalSum operation) The encryption data calculation method and the encryption data calculation device according to the embodiment perform a calculation in which each slot of the vector ciphertext of the result of the multiplication operation is the sum of the values of all slots. As a result, a vector ciphertext in which the value of each slot is the result f(a, b) of the two-variable non-linear operation can be obtained.
[0055] The EvalSum operation is an operation expressed as follows.
Equation
[0056] The encryption data calculation method and the encryption data calculation device according to the embodiment obtain Enc(Pack(f(a, b),..., f(a, b))) by executing the EvalSum operation on Enc(Pack(0,..., 0, f(a, b), 0,..., 0)).
[0057] In the above EvalSum operation, a process called the automorphism operation is performed log(N) times inside. Inside, the automorphism operation σ i is a process that causes a rotation for the slots of the packed ciphertext and is expressed as follows.
Equation
[0058] The automorphism operation performs the number-theoretic transform / inverse number-theoretic transform O(1) times per iteration. Therefore, since the EvalSum operation internally performs the process called the automorphism operation log(N) times, it will perform the number-theoretic transform / inverse number-theoretic transform O(log(N)) times.
[0059] FIG. 3 is a diagram showing the computational complexity of the number-theoretic transform / inverse number-theoretic transform in each process of the encrypted data calculation method according to the embodiment. Note that FIG. 3 is obtained by adding the computational complexity of the number-theoretic transform / inverse number-theoretic transform to each process of the encrypted data calculation method shown in FIG. 2.
[0060] As shown in FIG. 3, the asymptotic computational complexity of the number-theoretic transform / inverse number-theoretic transform in the first One-HotSlot operation S1 and the second One-HotSlot operation S2 is O(log(N)), the asymptotic computational complexity of the number-theoretic transform / inverse number-theoretic transform in the LUT matrix operation S3 is O(1), the asymptotic computational complexity of the number-theoretic transform / inverse number-theoretic transform in the multiplication operation S4 is O(1), and the asymptotic computational complexity of the number-theoretic transform / inverse number-theoretic transform in the EvalSum operation S5 is O(log(N)).
[0061] Therefore, the asymptotic computational complexity of the number-theoretic transform / inverse number-theoretic transform in each process of the encrypted data calculation method according to the embodiment is O(log(N)). In the conventional calculation using the Lagrange interpolation polynomial, asymptotically O(√N) number-theoretic transforms / inverse number-theoretic transforms were required. Therefore, it was shown that the number of number-theoretic transforms / inverse number-theoretic transforms can be asymptotically reduced in the two-variable non-linear operation executed by the encrypted data calculation method according to the embodiment.
[0062] [Encryption System] FIG. 4 is a diagram showing the schematic configuration of the encryption system according to the embodiment. The encryption system according to the embodiment is a system that calculates the ciphertext of the result of the two-variable non-linear operation from the ciphertexts of the first variable and the second variable having values of integers from 0 to N-1. As shown in FIG. 4, it includes an encrypted data calculation device 120, a key generation device 100, an encryption device 110, and a decryption device 130.
[0063] The encrypted data calculation device 120 is a device that calculates the ciphertext of the result of a two-variable non-linear operation from the ciphertexts of a first variable and a second variable having values that are integers from 0 to N-1, and includes a transmission / reception unit 121, a ciphertext storage unit 122, an operation key storage unit 123, a first One-HotSlot operation unit 124_1, a second One-HotSlot operation unit 124_2, a LUT matrix operation unit 125, a LUT matrix storage unit 126, a multiplication operation unit 127, and an EvalSum operation unit 128. Since the configuration and functions of the encrypted data calculation device 120 have already been described, the description is omitted here.
[0064] The key generation device 100 includes a transmission unit 101, a decryption key generation unit 102, an encryption key generation unit 103, and an operation key generation unit 104. The decryption key generation unit 102 generates a decryption key for decrypting the ciphertext encrypted by the homomorphic encryption. The encryption key generation unit 103 generates an encryption key for encrypting the plaintext by the homomorphic encryption. The operation key generation unit 104 generates an operation key for performing a homomorphic operation on the ciphertext encrypted by the homomorphic encryption. These decryption key, encryption key, and operation key are paired. A ciphertext encrypted with a certain encryption key cannot be decrypted unless it is with the decryption key paired with that encryption key, and cannot be subjected to a homomorphic operation unless it is with the paired operation key. The transmission unit 101 transmits the decryption key to the decryption device 130, transmits the encryption key to the encryption device 110, and transmits the operation key to the encrypted data calculation device 120.
[0065] The encryption device 110 includes a transmission / reception unit 111, an encryption key storage unit 112, and an encryption calculation unit 113. The encryption key storage unit 112 stores the encryption key received from the key generation device 100. The encryption calculation unit 113 calculates the ciphertexts of the first variable and the second variable from the first variable and the second variable having values that are integers from 0 to N-1, using the encryption key stored in the encryption key storage unit 112. The transmission / reception unit 111 receives the encryption key from the key generation device 100 and transmits the ciphertexts of the first variable and the second variable calculated by the encryption calculation unit 113 to the encrypted data calculation device 120.
[0066] More specifically, the encryption calculation unit 113 encrypts, using a cryptographic key, a packed value obtained by assigning the same values of the first variable and the second variable to all N slots and packing them into a polynomial ring with finite field coefficients, by means of a homomorphic encryption.
[0067] The decryption device 130 includes a receiving unit 131, a ciphertext storage unit 132, a decryption key storage unit 133, and a decryption calculation unit 134. The receiving unit 131 receives a decryption key from the key generation device 100 and receives a ciphertext of the result of the two-variable non-linear operation from the encrypted data calculation device 120. The ciphertext storage unit 132 stores the ciphertext of the result of the two-variable non-linear operation received from the encrypted data calculation device 120. The decryption key storage unit 133 stores the decryption key received from the key generation device 100. The decryption calculation unit 134 decrypts the ciphertext of the result of the two-variable non-linear operation stored in the ciphertext storage unit 132, using the decryption key stored in the decryption key storage unit 133.
[0068] The encryption system with the above configuration can calculate a ciphertext of the result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values of integers from 0 to N-1. However, the encryption system described above is an example of the configuration of a system that can calculate a ciphertext of the result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values of integers from 0 to N-1, and it can be used with appropriate modifications. For example, in the above description, the encryption device 110 and the decryption device 130 are described as separate devices, but it is also possible to configure the encryption device 110 and the decryption device 130 as the same device. Also, in the above description, the decryption key, the encryption key, and the operation key are described as separate keys, but depending on the homomorphic encryption method used, the encryption key and the operation key may be the same. Even if these changes are made to the encryption system, the encryption system can still calculate a ciphertext of the result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values of integers from 0 to N-1, and there is no change in the effect that the number of number-theoretic transform / inverse number-theoretic transform can be asymptotically reduced in the two-variable non-linear operation executed by the encryption system.
[0069] 〔Hardware Configuration Example〕 FIG. 5 is a diagram showing a hardware configuration example of an encrypted data calculation device, a key generation device, an encryption device, and a decryption device. That is, the encrypted data calculation device 120, the key generation device 100, the encryption device 110, and the decryption device 130 are implemented by an information processing device (computer) 10 adopting the hardware configuration shown in FIG. 5. By executing the encrypted data calculation method described above as a program, each function in the encrypted data calculation device 120, the key generation device 100, the encryption device 110, and the decryption device 130 can be realized. However, the hardware configuration example shown in FIG. 5 is an example of the hardware configuration for realizing each function of the encrypted data calculation device 120, the key generation device 100, the encryption device 110, and the decryption device 130, and is not intended to limit the hardware configuration of the encrypted data calculation device 120, the key generation device 100, the encryption device 110, and the decryption device 130. The encrypted data calculation device 120, the key generation device 100, the encryption device 110, and the decryption device 130 can include hardware not shown in FIG. 5.
[0070] As shown in FIG. 5, the hardware configuration that the encrypted data calculation device 120, the key generation device 100, the encryption device 110, and the decryption device 130 can adopt includes, for example, a CPU (Central Processing Unit) 11, a main memory device 12, an auxiliary storage device 13, and an IF (Interface) unit 14 that are interconnected by an internal bus.
[0071] The CPU 11 executes each instruction included in the encrypted data calculation program executed by the information processing device (computer) 10. The main memory device 12 is, for example, a RAM (Random Access Memory), and temporarily stores various programs such as the encrypted data calculation program executed by the information processing device (computer) 10 for the CPU 11 to process.
[0072] The auxiliary storage device 13 is, for example, an HDD (Hard Disk Drive), and can store various programs such as an encryption data calculation program executed by the information processing device (computer) 10 in the medium to long term. Various programs such as the encryption data calculation program can be provided as a program product recorded on a non-transitory computer-readable storage medium.
[0073] The IF unit 14 provides, for example, an interface related to the input / output of the encryption data calculation device 120, the key generation device 100, the encryption device 110, and the decryption device 130.
[0074] By executing the above-described encryption data calculation method as a program, the information processing device (computer) 10 adopting the above hardware configuration realizes the functions of the encryption data calculation device 120, the key generation device 100, the encryption device 110, and the decryption device 130.
[0075] Some or all of the above embodiments may be described as follows in the following supplementary notes, but are not limited thereto. [Supplementary Note 1] An encryption data calculation device that calculates an encrypted text of the result of a two-variable non-linear operation from encrypted texts of a first variable and a second variable having values as integers from 0 to N - 1, a first One-HotSlot operation unit that converts the encrypted text of the first variable into an N-dimensional first indicator vector encrypted text in which only the component of the value of the first variable is 1 and the other components are 0, a second One-HotSlot operation unit that converts the encrypted text of the second variable into an N-dimensional second indicator vector encrypted text in which only the component of the value of the second variable is 1 and the other components are 0, A plaintext obtained by pre-computing the results of the two-variable non-linear operation for all possible combinations of the values of the first variable and the second variable is held as an N×N look-up table matrix, and an LUT matrix operation unit that extracts the row of the value of the first variable in the look-up table matrix by applying the first indicator vector ciphertext to the look-up table matrix, a multiplication operation unit that multiplies the vector ciphertext obtained by extracting the row of the value of the first variable in the look-up table matrix and the second indicator vector ciphertext, an EvalSum operation unit that performs a calculation such that each slot of the vector ciphertext that is the result of the multiplication operation unit becomes the sum of the values of all the slots, and an encrypted data calculation device comprising the same. [Appendix 2] The encrypted data calculation device according to Appendix 1, wherein the ciphertexts of the first variable and the second variable are those obtained by encrypting, using a homomorphic cipher, a packing in a polynomial ring with finite field coefficients by assigning the same values of the first variable and the second variable to all N slots. [Appendix 3] The encrypted data calculation device according to Appendix 1 or Appendix 2, which holds an operation key for performing addition and multiplication on a plaintext while keeping the ciphertext encrypted, and performs the process up to calculating the ciphertext of the result of the two-variable non-linear operation from the ciphertexts of the first variable and the second variable while keeping the ciphertext encrypted using the operation key. [Appendix 4] The encrypted data calculation device according to Appendix 1, a key generation device that generates a decryption key for decrypting the ciphertext, an encryption key for calculating the ciphertext from the plaintext, and an operation key for performing addition and multiplication on the plaintext while keeping the ciphertext encrypted, and transmits the operation key to the encrypted data calculation device, an encryption device that calculates the ciphertexts of the first variable and the second variable using the encryption key from the first variable and the second variable having values of integers from 0 to N - 1, and transmits the ciphertexts of the first variable and the second variable to the encrypted data calculation device, and an encryption system comprising the same. [Appendix 5] The encryption device encrypts, using the encryption key, by a homomorphic encryption, a polynomial ring with finite field coefficients obtained by assigning the same values of the first variable and the second variable to all of the N slots, according to the encryption system described in Supplementary Note 4. [Supplementary Note 6] The encryption system described in Supplementary Note 4, further comprising a decryption device that decrypts, using the decryption key, the ciphertext of the result of the two-variable non-linear operation received from the encrypted data calculation device. [Supplementary Note 7] An encrypted data calculation method for calculating a ciphertext of the result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values of integers from 0 to N-1, comprising: a first One-HotSlot operation that converts the ciphertext of the first variable into a ciphertext of an N-dimensional first indicator vector in which only the component of the value of the first variable is 1 and the other components are 0; a second One-HotSlot operation that converts the ciphertext of the second variable into a ciphertext of an N-dimensional second indicator vector in which only the component of the value of the second variable is 1 and the other components are 0; a LUT matrix operation that holds, as an N×N lookup table matrix, a plaintext obtained by pre-calculating the results of the two-variable non-linear operation for all possible combinations of the values of the first variable and the second variable, and extracts the row of the value of the first variable in the lookup table matrix by applying the first indicator vector ciphertext to the lookup table matrix; a multiplication operation that multiplies the vector ciphertext obtained by extracting the row of the value of the first variable in the lookup table matrix and the second indicator vector ciphertext; an EvalSum operation that performs a calculation such that each slot of the vector ciphertext of the result of the multiplication operation is the sum of the values of all slots; An encrypted data calculation method including the above. [Supplementary Note 8] An encrypted data calculation program for causing a computer to execute a process of calculating a ciphertext of the result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values of integers from 0 to N-1, A first One-HotSlot operation process that converts the ciphertext of the first variable into an N-dimensional first indicator vector ciphertext in which only the components of the value of the first variable are 1 and the other components are 0, A second One-HotSlot operation process that converts the ciphertext of the second variable into an N-dimensional second indicator vector ciphertext in which only the components of the value of the second variable are 1 and the other components are 0, A LUT matrix operation process that holds a plaintext obtained by pre-computing the results of the two-variable non-linear operation for all possible combinations of the values of the first variable and the second variable as an N×N lookup table matrix, and extracts the row of the value of the first variable in the lookup table matrix by applying the first indicator vector ciphertext to the lookup table matrix, A multiplication operation process that multiplies the vector ciphertext obtained by extracting the row of the value of the first variable in the lookup table matrix and the second indicator vector ciphertext, An EvalSum operation process that performs a calculation in which each slot of the vector ciphertext that is the result of the multiplication operation process becomes the sum of the values of all slots, An encrypted data calculation program including the above.
[0076] Note that the disclosures of each of the cited non-patent documents and the like shall be incorporated herein by reference. Within the scope of the entire disclosure of the present invention (including the claims), modifications and adjustments of the embodiments or examples can be made based on the basic technical idea. Also, within the scope of the entire disclosure of the present invention, various combinations or selections (including partial deletion) of various disclosure elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible. That is, the present invention naturally includes all the disclosures including the claims, and various modifications and corrections that could be made by those skilled in the art according to the technical idea. In particular, regarding the numerical ranges described in this document, any numerical value or small range included within the range should be construed as being specifically described even in the absence of separate description. Furthermore, each disclosure item of the above-cited documents may, as necessary and in accordance with the spirit of the present invention, be used in combination with the description items of this document, either in part or in whole, as part of the disclosure of the present invention, and is considered to be included in the disclosure items of this application.
Explanation of Signs
[0077] 10 Information processing device 11 CPU 12 Main memory device 13 Auxiliary storage device 14 IF section 100 Key generation device 101 Transmission section 102 Decryption key generation section 103 Encryption key generation section 104 Arithmetic key generation section 110 Encryption device 111 Transmission / reception section 112 Encryption key storage section 113 Encryption calculation section 120 Encrypted data calculation device 121 Transmission / reception section 122 Ciphertext storage section 123 Arithmetic key storage section 124_1 First One-HotSlot calculation section 124_2 Second One-HotSlot calculation section 125 LUT matrix calculation section 126 LUT matrix storage unit 127 Multiplication operation unit 128 EvalSum operation unit 130 Decryption device 131 Receiver 132 Ciphertext storage unit 133 Decryption key storage unit 134 Decryption calculation unit
Claims
1. An encrypted data calculation device that calculates an encrypted text of the result of a two-variable non-linear operation from encrypted texts of a first variable and a second variable having values as integers from 0 to N-1, a first One-HotSlot operation unit that converts the encrypted text of the first variable into an N-dimensional first indicator vector encrypted text in which only the component of the value of the first variable is 1 and the other components are 0, a second One-HotSlot operation unit that converts the encrypted text of the second variable into an N-dimensional second indicator vector encrypted text in which only the component of the value of the second variable is 1 and the other components are 0, holds a plain text obtained by pre-calculating the results of the two-variable non-linear operation for all possible combinations of the values of the first variable and the second variable as an N×N look-up table matrix, and extracts the row of the value of the first variable in the look-up table matrix by operating the first indicator vector encrypted text on the look-up table matrix, an LUT matrix operation unit, a multiplication operation unit that multiplies the vector encrypted text obtained by extracting the row of the value of the first variable in the look-up table matrix and the second indicator vector encrypted text, an EvalSum operation unit that performs a calculation in which each slot of the vector encrypted text of the result of the multiplication operation unit becomes the sum of the values of all slots, An encrypted data calculation device comprising:
2. The encrypted data calculation device according to claim 1, wherein the encrypted texts of the first variable and the second variable are obtained by encrypting, using a homomorphic encryption, a packing in a polynomial ring with finite field coefficients by assigning the same values of the first variable and the second variable to all N slots.
3. Holds an operation key for performing addition and multiplication on a plain text while keeping the encrypted text encrypted, and performs the process until calculating the encrypted text of the result of the two-variable non-linear operation from the encrypted texts of the first variable and the second variable while keeping the encrypted text encrypted using the operation key. The encrypted data calculation device according to claim 1 or claim 2.
4. The encrypted data calculation device according to claim 1, a decryption key for decrypting the encrypted text, an encryption key for calculating the encrypted text from the plain text, and an operation key for performing addition and multiplication on the plain text while keeping the encrypted text encrypted are generated, and a key generation device that transmits the operation key to the encrypted data calculation device, An encryption device that calculates ciphertexts of the first variable and the second variable using the encryption key from a first variable and a second variable having values that are integers from 0 to N-1, and transmits the ciphertexts of the first variable and the second variable to the encrypted data calculation device, An encryption system comprising the same. **Claim 5** The encryption system according to claim 4, wherein the encryption device encrypts, using the encryption key, by homomorphic encryption, a packed polynomial ring with finite field coefficients obtained by assigning the same values of the first variable and the second variable to all N slots. **Claim 6** The encryption system according to claim 4, further comprising a decryption device that decrypts the ciphertext of the result of the two-variable non-linear operation received from the encrypted data calculation device using the decryption key. **Claim 7** An encrypted data calculation method for calculating a ciphertext of the result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values that are integers from 0 to N-1, a first One-HotSlot operation that converts the ciphertext of the first variable into a ciphertext of a first N-dimensional indicator vector in which only the component of the value of the first variable is 1 and the other components are 0, a second One-HotSlot operation that converts the ciphertext of the second variable into a ciphertext of a second N-dimensional indicator vector in which only the component of the value of the second variable is 1 and the other components are 0, a LUT matrix operation that holds, as an N×N lookup table matrix, a plaintext obtained by pre-calculating the results of the two-variable non-linear operation for all possible combinations of the values of the first variable and the second variable, and extracts the row of the value of the first variable in the lookup table matrix by applying the first indicator vector ciphertext to the lookup table matrix, a multiplication operation that multiplies the vector ciphertext obtained by extracting the row of the value of the first variable in the lookup table matrix and the second indicator vector ciphertext, an EvalSum operation that performs a calculation in which each slot of the vector ciphertext of the result of the multiplication operation becomes the sum of the values of all slots, An encrypted data calculation method including the above. **Claim 8** An encrypted data calculation program that causes a computer to execute a process of calculating a ciphertext of the result of a two-variable non-linear operation from ciphertexts of a first variable and a second variable having values that are integers from 0 to N-1, A first One-HotSlot operation process for converting the ciphertext of the first variable into an N-dimensional first indicator vector ciphertext in which only the components of the value of the first variable are 1 and the other components are 0; A second One-HotSlot operation process for converting the ciphertext of the second variable into an N-dimensional second indicator vector ciphertext in which only the components of the value of the second variable are 1 and the other components are 0; A LUT matrix operation process that holds, as an N×N lookup table matrix, a plaintext in which the results of the two-variable non-linear operation for all possible combinations of the values of the first variable and the second variable are pre-calculated, and extracts the row of the value of the first variable in the lookup table matrix by applying the first indicator vector ciphertext to the lookup table matrix; A multiplication operation process for multiplying the vector ciphertext obtained by extracting the row of the value of the first variable in the lookup table matrix and the second indicator vector ciphertext; An EvalSum operation process for performing a calculation such that each slot of the vector ciphertext that is the result of the multiplication operation process becomes the sum of the values of all slots; An encrypted data calculation program including the above.