Secret Sharing Device, Secret Sharing Method, and Program

By employing a secret sharing device that stabilizes the sorting of explanatory variables within groups during the secret calculation of decision trees, the method effectively reduces the computational cost of further grouping, addressing the high calculation costs of existing methods.

JP7694684B2Active Publication Date: 2025-06-18NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023553887
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-10-15
Publication Date
2025-06-18
Estimated Expiration
2041-10-15

AI Technical Summary

Technical Problem

The existing methods for learning decision trees by secret calculation require sorting the elements of the vector x', which results in a high calculation cost.

Method used

A secret sharing device that groups teacher data by secret calculation, allowing samples in the same group to be consecutive, and performs stable sorting of the explanatory variables within each group, reducing the need for subsequent sorting during further grouping.

Benefits of technology

This approach reduces the calculation cost associated with further grouping data that has already been grouped by secret calculation, while maintaining the stability of the sorting process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007694684000011
    Figure 0007694684000011
  • Figure 0007694684000012
    Figure 0007694684000012
  • Figure 0007694684000013
    Figure 0007694684000013
Patent Text Reader

Abstract

In this secret partition device according to one preferred embodiment, teacher data configured from multiple samples having m explanatory variables is given as a hidden values comprising a target variable vector z having the values of the target variable of each sample as elements and an explanatory variable vector wj (j ∈ [1,m]) having the values of the jth explanatory variable of each sample as elements, the samples configuring the teacher data are partitioned into groups, and a grouping for reordering is executed with secret computation such that samples in the same group are consecutive, wherein the secret partition device is provided with: an input unit which inputs hidden values of a target variable vector y of the grouped teacher data, hidden values of a permutation σj for stably sorting, within the groups, the j^th explanatory variable vector of the grouped teacher data, hidden values of the explanatory variable vector vj obtained by stably sorting, within the groups, the j^th explanatory variable vector of the grouped teacher data, and hidden values of a partition result vector b representing the partition result when the teacher data has been partitioned into groups according to a prescribed condition; and a secret partition unit which calculates, with secret computation, hidden values of the target variable vector y' of the teacher data newly grouped in accordance with the partition result represented by the partition result vector, hidden values of the permutation σj' for stably sorting, within the groups, the j^th explanatory variable vector of the teacher data newly grouped in accordance with the partition result, and hidden values of the explanatory variable vector vj' obtained by stably sorting, within the groups, the j^th explanatory variable vector of the teacher data newly grouped in accordance with the partition result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a secret sharing device, a secret sharing method, and a program.

Background Art

[0002] As a method for obtaining a specific calculation result without restoring an encrypted numerical value, a method called secret calculation (or private calculation) is known (for example, Non-Patent Document 1). In the method described in Non-Patent Document 1, encryption is performed by dispersing fragments of a numerical value among three secret calculation devices, and by performing cooperative calculations among the three secret calculation devices, results such as addition, subtraction, constant addition, multiplication, constant multiplication, logical operations (negation, logical product, logical sum, exclusive logical sum), and data format conversion (integer and binary number) can be obtained in a state dispersed among the three secret calculation devices without restoring the numerical value.

[0003] Here, when performing learning of a decision tree by secret calculation, it is common to perform learning while recursively dividing given teacher data (that is, learning while recursively repeating further grouping of the grouped teacher data).

[0004] For example, assume that teacher data consisting of n samples with m attributes (m ≧ 1) of explanatory variables is given as a vector z of target variables with size n and m vectors w of explanatory variables with size n j (j ∈ [1, m]). Also, while maintaining the correspondence between the target variable and each explanatory variable so that the samples of the teacher data are grouped and the samples in the same group are consecutive, the elements of the vector z and each vector w j are rearranged and denoted as vectors y and x, respectively j . That is, there exists a permutation π of size n such that for all i ∈ [1, n], y[π(i)] = z[i], and for all j ∈ [1, m], x j [π(i)] = w j[i], and if the i-th sample and the j-th sample (where i < j) after rearrangement are in the same group, then for any k ∈ [i, j], the k-th sample is also in the same group. Note that y[i], z[i], x j [i], w j [i] are the i-th elements of vectors y, z, x j , w j respectively.

[0005] At this time, in the learning of decision trees by secret calculation, vectors y, vector v j , permutation σ j , vector b are used as inputs, and vectors y', vector v j ', permutation σ j ' are calculated repeatedly. Here, v j is the vector obtained by arranging the elements of x j in ascending order within the group, σ j is the permutation that arranges the elements of x j to make v j , and b is a vector representing the division result when each sample is divided into groups under a certain condition. Also, y' and x j ' are vectors obtained by rearranging the elements of z and w j while maintaining the correspondence between the target variable and each explanatory variable so that samples in the same group are adjacent after further dividing each group according to b, v j ' is the vector obtained by arranging the elements of x j ' in ascending order within the group, and σ j ' is the permutation that arranges the elements of x j ' to make v j '.

[0006] Also, when calculating vectors y', vector v j ', permutation σ j ', vector x j is calculated first, and the elements of vector y and the elements of vector x j are rearranged into new groups according to vector b to obtain vectors y' and x j ', and then vector x jFind a substitution that sorts the elements of 'σ' within each group j ' and let the substitution be σ j ' and rearrange the elements of the vector x j ' according to σ j ' to obtain the vector v

Prior Art Documents

Non-Patent Documents

[0007]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0008] However, in the above conventional method, when calculating the substitution σ j ', it is necessary to sort the elements of the vector x j ', so there is a problem that the calculation cost is large.

[0009] One embodiment of the present invention has been made in view of the above points, and an object thereof is to reduce the calculation cost when further grouping data grouped by secret calculation.

Means for Solving the Problems

[0010] To achieve the above object, a secret sharing device according to an embodiment is configured such that teacher data composed of a plurality of samples having m explanatory variables, a target variable vector z having the values of the target variables of each sample as elements, and an explanatory variable vector w having the values of the j-th explanatory variable of each sample as elements jA secret splitting device that is given as a secret value of (j ∈ [1, m]), divides samples constituting the teacher data into groups, and performs grouping by secret calculation so that samples in the same group are consecutive. The secret value of the target variable vector y of the grouped teacher data, and the substitution σ that stably sorts the j-th explanatory variable vector of the grouped teacher data within the group j The secret value of, and the explanatory variable vector v obtained by stably sorting the j-th explanatory variable vector of the grouped teacher data within the group j An input unit that inputs the secret value of, the secret value of the splitting result vector b representing the splitting result when the teacher data is divided into groups under a predetermined condition, the secret value of the target variable vector y' of the teacher data newly grouped according to the splitting result represented by the splitting result vector, and the substitution σ that stably sorts the j-th explanatory variable vector of the teacher data newly grouped according to the splitting result within the group j The secret value of ', and the secret value of the explanatory variable vector v obtained by stably sorting the j-th explanatory variable vector of the teacher data newly grouped according to the splitting result within the group j And a secret splitting unit that calculates by secret calculation the secret value of

Advantages of the Invention

[0011] It is possible to reduce the calculation cost when further grouping data grouped by secret calculation.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Modes for Carrying Out the Invention

[0013] Hereinafter, an embodiment of the present invention will be described. In this embodiment, a secret sharing device 10 that can reduce the calculation cost when further grouping data grouped by secret calculation will be described.

[0014] <Notation, Definitions, etc.> Hereinafter, notations, definitions, etc. used in this embodiment will be described.

[0015] A value obtained by anonymizing the value a by encryption, secret sharing, etc. is called the anonymized value of a and is denoted as [[a]]. When a is anonymized by secret sharing, [[a]] refers to the set of fragments of secret sharing held by each secret calculation device.

[0016] The i-th element of the vector v is referred to as v[i]. That is, when the vector v has a size of n, v = (v[1], v[2], ···, v[n]).

[0017] A permutation of size n is a bijective mapping from {1, 2, ···, n} to {1, 2, ···, n}. When a permutation α of size n satisfies α(i) = b for each i ∈ [1, ···, n], i it is satisfied,

[0018]

Number

[0019] The operation of creating a vector v' by rearranging the elements of a vector v of size n according to a permutation α of size n such that v'[α(i)] = v[i] is called "application" and is denoted as v' = αv. Also, hereinafter, when there is no confusion, simply rearranging the elements of the vector v may be denoted as "rearranging the vector v", etc.

[0020] For permutations π, σ of size n and each i ∈ [1, n], a permutation ρ of size n that satisfies ρ(i) = π(σ(i)) is called the composition of the permutation π and the permutation σ,

[0021]

Number

[0022] The inverse mapping of the substitution π is called the inverse substitution and is denoted as π -1 It is expressed as.

[0023] <Hardware Configuration of Secret Sharing Device 10> The hardware configuration of the secret sharing device 10 according to this embodiment is shown in FIG. 1. As shown in FIG. 1, the secret sharing device 10 according to this embodiment is realized by the hardware configuration of a general computer or computer system, and includes an input device 101, a display device 102, an external I / F 103, a communication I / F 104, a processor 105, and a memory device 106. These pieces of hardware are communicably connected to each other via a bus 107.

[0024] The input device 101 is, for example, a keyboard, a mouse, a touch panel, a physical button, or the like. The display device 102 is, for example, a display, a display panel, or the like. Note that the secret sharing device 10 may not have at least one of the input device 101 and the display device 102, for example.

[0025] The external I / F 103 is an interface with an external device such as a recording medium 103a. The secret sharing device 10 can read and write to the recording medium 103a via the external I / F 103. Note that the recording medium 103a includes, for example, a CD (Compact Disc), a DVD (Digital Versatile Disk), an SD memory card (Secure Digital memory card), a USB (Universal Serial Bus) memory card, or the like.

[0026] The communication I / F 104 is an interface for connecting the secret sharing device 10 to a communication network. The processor 105 is various arithmetic units such as, for example, a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit). The memory device 106 is various storage devices such as, for example, an HDD (Hard Disk Drive), an SSD (Solid State Drive), a RAM (Random Access Memory), a ROM (Read Only Memory), or a flash memory.

[0027] The secret sharing device 10 according to the present embodiment can realize the secret sharing process described later by having the hardware configuration shown in FIG. 1. Note that the hardware configuration shown in FIG. 1 is an example, and the secret sharing device 10 may have other hardware configurations. For example, the secret sharing device 10 may have a plurality of processors 105 or may have a plurality of memory devices 106.

[0028] <Functional Configuration of Secret Sharing Device 10> The functional configuration of the secret sharing device 10 according to the present embodiment is shown in FIG. 2. As shown in FIG. 2, the secret sharing device 10 according to the present embodiment includes an input unit 201, a secret sharing unit 202, and an output unit 203. Each of these units is realized, for example, by a process in which one or more programs installed in the secret sharing device 10 cause the processor 105 to execute. Further, the secret sharing device 10 according to the present embodiment includes a storage unit 204. The storage unit 204 is realized, for example, by the memory device 106.

[0029] The input unit 201 inputs the secret value of the grouped data. The secret sharing unit 202 calculates the secret value of the data obtained by further grouping the secret value input by the input unit 201 by secret calculation. The output unit 203 outputs the secret value calculated by the secret sharing unit 202. The storage unit 204 stores data such as the secret value input by the input unit 201, the secret value output by the output unit 203, and the secret value of the calculation result (including intermediate calculation results) by the secret sharing unit 202.

[0030] <Example> Hereinafter, an example will be described. Hereinafter, it is assumed that all data including the input to the secret sharing device 10, the output, and the intermediate calculation results are secret values, but the description of "secret value" may be omitted. For example, the secret value [[π]] of the permutation π may be expressed as "permutation [[π]]".

[0031] Also, let the number of attributes of the explanatory variable be m ≧ 1 and j ∈ [1, m]. Furthermore, several processes are defined below.

[0032] [[π]] ← StableSort([[x]]) represents a process of calculating the secret value [[π]] of the permutation π that stably sorts the vector x from the secret value [[x]] of the vector x. Note that sorting means arranging in ascending order.

[0033] [[y]] ← Apply([[π]], [[x]]) represents a process of calculating the secret value [[y]] of the vector y = πx from the secret value [[x]] of the vector x and the secret value [[π]] of the permutation π.

[0034] [[σ]] ← [[π]] -1 represents a process of calculating the secret value [[σ]] of the permutation σ = π from the secret value [[π]] of the permutation π. -1

[0035]

Number

[0036]

Number

[0037] In this embodiment, teacher data consisting of n samples with explanatory variables of m attributes (m ≥ 1) is given to the secret sharing device 10 as a target variable vector z of size n and m explanatory variable vectors w j (j ∈ [1, m]). Also, while maintaining the correspondence between the target variable and each explanatory variable by grouping the samples of the teacher data so that the samples in the same group are consecutive, the elements of the vector z and each vector w j are rearranged to obtain vectors y and x j respectively. That is, there exists a permutation π of size n such that for all i ∈ [1, n], y[π(i)] = z[i], and for all j ∈ [1, m], x j [π(i)] = w j [i], and further, if the i-th sample and the j-th sample (where i < j) after rearrangement are in the same group, then for any k ∈ [i, j], the k-th sample is also in the same group

[0038] At this time, the secret sharing device 10 according to this embodiment takes the vector y, the vector v j and the permutation σ j and the vector b as inputs, and performs a secret sharing process of calculating (that is, calculating while keeping the values of each input and output and the intermediate calculation results secret) the vector y' and the vector v j ' and the permutation σ j ' by secret calculation, and outputs the calculation result. However, v j is a vector obtained by arranging the elements of x j in ascending order within the group, σ j is a permutation that rearranges the elements of x j to obtain v j , and b is a vector representing the division result when dividing each sample into groups under a certain predetermined condition. Also, y' and x j ' are vectors obtained by rearranging the elements of z and w j while maintaining the correspondence between the target variable and each explanatory variable so that the samples in the same group are adjacent after further dividing each group into groups according to b, v j ' is x jA vector obtained by arranging the elements of ' in ascending order within a group, σ j ' is x j A replacement that rearranges the elements of ' to v j is made.

[0039] That is, the input and output of the secret sharing process executed by the secret sharing device 10 according to this embodiment are as follows.

[0040] Input: Vector [[y]] of grouped target variables, replacement [[σ j that stably sorts the grouped explanatory variables within the group, vector [[v j of the grouped explanatory variables stably sorted within the group, vector [[b]] representing the division result Output: Vector [[y']] of newly grouped target variables according to the division result, replacement [[σ j ']] that stably sorts the newly grouped explanatory variables within the group according to the division result, vector [[v j ']] By repeatedly executing the secret sharing process with this input and output, a decision tree can be learned by secret calculation.

[0041] Hereinafter, the secret sharing process according to this embodiment will be described with reference to FIG. 3.

[0042] Step S101: The input unit 201 inputs the vector [[y]] of the grouped target variables, the replacement [[σ j that stably sorts the grouped explanatory variables within the group, the vector [[v j of the grouped explanatory variables stably sorted within the group, and the vector [[b]] representing the division result.

[0043] Step S102: The secret sharing unit 202 calculates a replacement [[π]] that stably sorts the vector [[b]] representing the division result by [[π]] ← StableSort([[b]]).

[0044] Step S103: The secret sharing unit 202 [[b j ← Apply([[σ j , [[b]]) is used to apply the permutation [[σ j that stably sorts the grouped explanatory variables within the group to the vector [[b]] and calculate a vector [[b j in the same order as the vector [[v j obtained by stably sorting the grouped explanatory variables within the group.

[0045] Step S104: The secret sharing unit 202 [[ρ j ← StableSort([[b j ) is used to calculate a permutation [[ρ j that stably sorts the vector [[b j .

[0046] Step S105: The secret sharing unit 202 [[v j ']] ← Apply([[ρ j , [[v j ) is used to apply the permutation [[ρ j to the vector [[v j and calculate a vector [[v j ']] of the explanatory variables stably sorted within the divided group.

[0047] Step S106: The secret sharing unit 202

[0048]

Number

[0049] Step S107: The secret splitting unit 202 calculates the vector [[y']] of the grouped target variables after splitting (that is, the vector of the target variables obtained by further grouping the grouped target variables) by applying the permutation [[π]] to the vector [[y]] according to [[y']]←Apply([[π]],[[y]]).

[0050] Step S108: The output unit 203 stably sorts the vector [[y']] of the newly grouped target variables according to the splitting result, the permutation [[σ j ']] for stably sorting the newly grouped explanatory variables within the group according to the splitting result, and the vector [[v j ']] of the stably sorted newly grouped explanatory variables within the group according to the splitting result, and outputs them to a predetermined output destination (for example, the storage unit 204, etc.).

[0051] As described above, the explanatory variables grouped by secret calculation can be further grouped. Moreover, at this time, in this embodiment, x j is not sorted, and the secret values of y', v j ', and σ j ' can be calculated. This utilizes the property that when the new grouping by splitting is performed by stable sorting by splitting, the group configuration does not change even if the order is rearranged within each group. That is, by rearranging the explanatory variables sorted within the group before splitting by stable sorting by splitting, it is guaranteed that they will still be sorted within the new groups after splitting due to the stability of the sorting. Therefore, in this embodiment, when further grouping the explanatory variables grouped by secret calculation, the calculation cost can be reduced compared to the conventional method.

[0052] ·Specific Example Hereinafter, a specific splitting example will be described. In the following, the vertical bar "|" in each mathematical formula represents the boundary between groups.

[0053] Assuming m = 2 and n = 8, the vectors z and w j (j = 1, 2) are as follows.

[0054]

Number

[0055]

Number

[0056]

Number

[0057] Let the vector b representing the division result when each sample is divided into groups under a certain predetermined condition be as follows.

[0058]

Number

[0059] The vector x with its elements rearranged in the same order as the vector y' is j the vector x j '. Then, in the above secret sharing process,

[0060]

Number

[0061] <Effect> When learning a decision tree by secure computation, it is necessary to divide the grouped training data and create new grouped and sorted training data. For this purpose, in the conventional method, it is necessary to sort the explanatory variables in ascending order within each new group. On the other hand, according to the present embodiment, it is not necessary to sort the explanatory variables in ascending order within each new group. Instead, it is sufficient to perform sorting of the division results, application of substitution, composition of substitution, and calculation of inverse substitution. As a result, the computational cost is reduced.

[0062] Note that in the present embodiment, it is assumed that a decision tree is learned by secure computation, and the secret sharing process of further grouping the data grouped by secure computation has been described. However, the secret sharing device 10 according to the present embodiment may execute the process of learning the decision tree by repeating the above secret sharing process. Further, the secret sharing device 10 according to the present embodiment may execute processes such as various data analyses, data classifications, and device controls based on those analysis or classification results (for example, control such as stopping a device based on an anomaly detection result).

[0063] The present invention is not limited to the specifically disclosed above embodiments, and various modifications, changes, combinations with known techniques, etc. are possible without departing from the description of the claims.

Explanation of Signs

[0064] 10 Secret sharing device 101 Input device 102 Display device 103 External I / F 103a Recording medium 104 Communication I / F 105 Processor 106 Memory device 107 Bus 201 Input section 202 Secret sharing section 203 Output section 204 Storage section

Claims

1. Teacher data composed of a plurality of samples having m explanatory variables is given as a secret value of an explanatory variable vector w having as elements the values of the j-th explanatory variable of each sample and an objective variable vector z having as elements the values of the objective variables of each sample j (j ∈ [1, m]), and a secret splitting device that performs grouping by secret calculation to divide the samples constituting the teacher data into groups and rearranges them so that the samples in the same group are consecutive, The secret value of the objective variable vector y of the grouped teacher data, the substitution σ that stably sorts the j-th explanatory variable vector of the grouped teacher data within the group j The secret value of, and the explanatory variable vector v obtained by stably sorting the j-th explanatory variable vector of the grouped teacher data within the group j An input unit that inputs the secret value of, and the secret value of a split result vector b representing the split result when the teacher data is divided into groups under a predetermined condition, The secret value of the objective variable vector y' of the teacher data newly grouped according to the split result represented by the split result vector, the substitution σ that stably sorts the j-th explanatory variable vector of the teacher data newly grouped according to the split result within the group j The secret value of ', and the explanatory variable vector v obtained by stably sorting the j-th explanatory variable vector of the teacher data newly grouped according to the split result within the group j A secret splitting unit that calculates the secret value by secret calculation, A secret splitting device having.

2. The secret splitting unit Calculates the secret value of the substitution π that stably sorts the elements of the split result vector b, The split result vector b obtained by rearranging the elements of the split result vector b with the substitution σ j Calculates the secret value of, j Calculates the secret value of the substitution ρ that stably sorts the elements of the split result vector b The split result vector b j Calculates the secret value of, j Calculates the secret value of, The explanatory variable vector v j By rearranging the elements with the substitution ρ j The secret value of the explanatory variable vector v j ' is calculated, and The substitution ρ j And the substitution σ j And the inverse substitution of the substitution π are combined to calculate the secret value of the substitution σ j ', and By rearranging the elements of the target variable vector y with the substitution π, the secret value of the target variable vector y' is calculated. The secret sharing device according to claim 1.

3. The teacher data is data for learning a decision tree, The secret sharing device By repeating the input by the input unit and the calculation by the secret sharing unit, the decision tree is learned. The secret sharing device according to claim 1 or 2.

4. Teacher data composed of a plurality of samples having m explanatory variables is given as the secret value of the target variable vector z having the value of the target variable of each sample as an element and the explanatory variable vector w having the value of the j-th explanatory variable of each sample as an element j (j ∈ [1, m]), and the samples constituting the teacher data are grouped and rearranged so that the samples in the same group are consecutive. A secret sharing device that executes grouping by secret calculation The secret value of the target variable vector y of the grouped teacher data, the substitution σ that stably sorts the j-th explanatory variable vector of the grouped teacher data within the group j The secret value of, the explanatory variable vector v obtained by stably sorting the j-th explanatory variable vector of the grouped teacher data within the group j The input procedure for inputting the secret value of, and the secret value of the division result vector b representing the division result when the teacher data is divided into groups under a predetermined condition The secret value of the target variable vector y' of the teacher data newly grouped according to the segmentation result represented by the segmentation result vector, and the permutation σ for stably sorting the j-th explanatory variable vector of the teacher data newly grouped according to the segmentation result within the group j The secret value of ', and the explanatory variable vector v obtained by stably sorting the j-th explanatory variable vector of the teacher data newly grouped according to the segmentation result within the group j A secret splitting procedure for calculating by secret calculation the secret value of'and the j-th explanatory variable vector of the teacher data newly grouped according to the segmentation result, and A secret splitting method for executing.

5. A program for causing a computer to function as the secret splitting device according to any one of Claims 1 to 3.

Citation Information

Patent Citations

  • Secret aggregate function calculation system, secret calculation device, secret aggregate function calculation method, and program

    WO2019225401A1

  • Encoded data analysis device, encoded data analysis method, and program

    WO2021144840A1