Confidential Computation Conversion System, Confidential Computation Conversion Method, and Confidential Computation Conversion Program

The secure operation conversion system addresses the limitations of existing secure computation methods by encrypting and exchanging secret information to generate operand information for another operation B, ensuring information-theoretic security and protecting the confidentiality of secret data.

JP7699803B2Active Publication Date: 2025-06-30HIROSHIMA CITY UNIVERSITY
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021117720
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-07-16
Publication Date
2025-06-30
Estimated Expiration
2041-07-16

AI Technical Summary

Technical Problem

Existing secure computation methods, such as those using the Paillier cryptosystem and ElGamal cryptosystem, face challenges with computational security, particularly the risk of being broken by quantum computers, and they do not guarantee information-theoretic security.

Method used

A secure operation conversion system and method that encrypts and exchanges secret information between institutions to generate operand information for another operation B, ensuring that the result of operation A on secret data from each institution can be obtained securely, using a protocol that guarantees information-theoretic security.

Benefits of technology

The system enables the creation of negotiation secret information among multiple institutions with guaranteed information-theoretic security, ensuring that the confidentiality of secret data is protected and that the results of secure computations are reliable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007699803000001
    Figure 0007699803000001
  • Figure 0007699803000002
    Figure 0007699803000002
  • Figure 0007699803000003
    Figure 0007699803000003
Patent Text Reader

Abstract

To create negotiation secret information according to a protocol whose information theoretical security is guaranteed between a plurality of institutions.SOLUTION: A secret calculation conversion system 1 encrypts and exchanges secret information and public information of each institution between data processors 100 of each institution, and generates information to be calculated of another calculation B that can acquire the same result as a result obtained by executing a calculation A to the secret information of each institution. Each data processor 100 includes a storage part 130 for storing information, secret calculation conversion processing means 161 for executing first processing for exchanging a cryptogram of own secret information with a data processor of the opposite institution to generate cryptogram secret information obtained by mixing secret information of both institutions, and second processing for exchanging a cryptogram obtained by encrypting the own secret information with the cryptogram secret information with the data processor of the opposite institution to generate information to be calculated, and negotiation secret information acquisition processing means 162 for storing negotiation secret information obtained by associating the own secret data with the generated information to be calculated in the storage part.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a secure computation conversion system, a secure computation conversion method, and a secure computation conversion program that securely calculate multiple inputs for another operation B that can obtain the same result as the result when performing operation A with secret data held by multiple institutions as inputs, and return the result as a secret output to each institution.

Background Art

[0002] For example, there are often situations where online store P1 (hereinafter sometimes abbreviated as institution P1) and online store P2 (hereinafter sometimes abbreviated as institution P2) want to derive the correlation of customers' item purchases without violating the privacy consent contract with the customers. As a method to achieve this, first, institution P1 and institution P2 prepare two vectors, "vector X" and "vector Y", which record the usage amounts of customers with the same credit number at the same position. If the inner product value obtained by using the above vectors X and Y as inputs is greater than a certain threshold, it can be determined that there is a positive correlation in the purchase behavior of the customers of institution P1 and institution P2, and there is a high possibility that the customers' preferences are similar, and by jointly developing products, it may be possible to develop products that better meet the customers' needs. At this time, if institution P1 and institution P2 each create vectors X and Y composed of a large number of purchase information, and do not disclose the contents of vectors X and Y to each other, and each can only calculate the inner product value, it will not conflict with the privacy consent contract between the customers and the institutions.

[0003] The inventor of the present application has invented a secret operation conversion system and a secret operation conversion method that can perform secret calculations at low cost using negotiation secret information and secret data while completely protecting the confidentiality of secret data, based on the confidentiality of the obtained negotiation secret information. This is different from the basis of confidentiality in the conventional homomorphic public key cryptography used as a technology that allows the above-mentioned mechanisms P1 and P2 to calculate only the inner product values without revealing the contents of vector X and vector Y to each other. By converting one secret operation into another secret operation, both parties can fairly obtain meaningful secret information (hereinafter sometimes referred to as negotiation secret information) agreed upon. A patent application (Patent Document 1) has been filed for this invention.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Patent Document 1 discloses a method of using the Paillier cryptosystem and a method of using the ElGamal cryptosystem as methods for creating negotiation secret information. The Paillier cryptosystem is based on the difficulty of the discrete logarithm problem and the composite number remainder determination for its security. Also, the Paillier cryptosystem has a problem that it is difficult to associate with elliptic curve cryptography and difficult to speed up. On the other hand, the ElGamal cryptosystem requires high-load calculations such as calculating the logarithm of the operation result, and also has a problem that the value range is limited. In the first place, it is assumed that the solution of problems related to the discrete logarithm problem and the like in both of the above cryptosystems does not fit within polynomial time, and this assumption is called computational security and is used as the basis of security. However, in the future, there is a possibility that the computational security will be broken by calculations using a quantum computer.

[0006] The present invention has been made in view of such problems, and an object thereof is to provide a secret operation conversion system and a secret operation conversion method capable of creating negotiation secret information according to a protocol in which information-theoretic security is guaranteed among a plurality of institutions.

Means for Solving the Problems

[0007] According to one aspect of the present invention, there is provided a secret operation conversion system including a data processing device of a first institution and a data processing device of a second institution, which encrypts and exchanges secret information and public information of each institution between the data processing devices to generate operand information of another operation B that can obtain the same result as the result of performing operation A on the secret data of each institution. Each of the data processing devices includes a storage unit for storing information, a first process for exchanging ciphertexts of its own secret information with the data processing device of the other institution to generate encrypted secret information in which the secret information of both institutions is mixed, and a second process for exchanging ciphertexts obtained by encrypting its own secret information with the encrypted secret information with the data processing device of the other institution to generate the operand information, and negotiation secret information acquisition processing means for storing in the storage unit negotiation secret information associating its own secret data with the generated operand information.

[0008] According to another aspect of the present invention, there is provided a secret operation conversion method for encrypting and exchanging secret information and public information of each institution between a data processing device of a first institution and a data processing device of a second institution to generate operand information of another operation B that can obtain the same result as the result of performing operation A on the secret data of each institution. The method includes: a first step in which a data processing device of each institution exchanges ciphertexts of its own secret information with the data processing device of the other institution to generate encrypted secret information in which the secret information of both institutions is mixed; a second step in which a data processing device of each institution exchanges ciphertexts obtained by encrypting its own secret information with the encrypted secret information with the data processing device of the other institution to generate the operand information; and a third step in which a data processing device of each institution stores in a storage unit negotiation secret information associating its own secret data with the generated operand information.

[0009] According to still another aspect of the present invention, there is provided a secure operation conversion program that causes a computer to function as the data processing device in a system for encrypting and exchanging secret information and public information between a data processing device of a first institution and a data processing device of a second institution, and generating operand information of another operation B that can obtain the same result as the result of performing operation A on the secret data of each institution. The secure operation conversion program includes: a first process of exchanging a ciphertext of its own secret information with a data processing device of the other institution to generate ciphertext anonymized information in which the secret information of both institutions is mixed; and a second process of exchanging a ciphertext obtained by encrypting its own secret information with the ciphertext anonymized information with a data processing device of the other institution to generate the operand information. The secure operation conversion program is characterized in that the computer functions as negotiation secret information acquisition processing means for storing negotiation secret information associating its own secret data with the generated operand information in a storage unit.

Effects of the Invention

[0010] According to the present invention, each institution encrypts its own secret information with ciphertext anonymized information in which the secret information of both institutions is mixed and exchanges it with the other institution, so that the receiving side does not know what the secret information of the transmitting side is, and of course, the transmitting side also does not know what ciphertext the receiving side has received. Thus, negotiation secret information can be created among a plurality of institutions. As a result, negotiation secret information can be created according to a protocol that guarantees information-theoretic security among a plurality of institutions.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Embodiments for Carrying Out the Invention

[0012] (Configuration of the Present Invention) The secure operation conversion system of the present invention can obtain the same result as when applying a certain operation A to the secret data X and secret data Y of institution P1 or institution P2 without the help of a third party. By secretly calculating the combination of inputs OutputX and OutputY for another operation B according to the fully secure operation conversion protocol with guaranteed information-theoretic security, it is an information exchange system for both institution P1 and institution P2 to fairly obtain meaningful secret information agreed upon. Hereinafter, the basic configuration of the secure operation conversion system will be described with reference to the drawings.

[0013] As shown in FIG. 1, the secure operation conversion system 1 of the present invention is composed of two data processing devices 100 installed in institution P1 and institution P2 respectively, and a communication line 200 connecting them. The two data processing devices 100 cooperate with each other by transmitting and receiving data through the communication line 200 to execute the secure operation conversion process.

[0014] The data processing device 100 is built, for example, in a PC server or a mainframe, and is composed of a control unit 110, a communication unit 120, a storage unit 130, an operation unit 140, an interface unit 150, and an arithmetic processing unit 160.

[0015] The control unit 110 is composed of a CPU (Central Processing Unit) etc., and controls and manages each part of the data processing device 100. That is, upon receiving the "confidential arithmetic conversion processing start signal" from the operation unit 140, it designates the arithmetic conversion method type (hereinafter, may be abbreviated as Type) defined corresponding to the arithmetic A and the arithmetic B, reads out the information necessary for the arithmetic processing pre-stored in the storage unit 130, causes the arithmetic processing unit 160 to execute the arithmetic processing, stores the arithmetic processing result in the arithmetic processing unit 160 in the storage unit 130 as needed, sends out the information necessary for the confidential arithmetic conversion to the counterpart device via the communication unit 120, and is responsible for functions such as displaying and outputting the arithmetic result in the arithmetic processing unit 160 via the I / F unit 150.

[0016] The communication unit 120 is composed of a LAN connector, a processor for transmission and reception processing, etc., and communicates with the data processing device 100 of the counterpart device through the communication line 200 under the control of the control unit 110.

[0017] The storage unit 130 is composed of a storage device such as a hard disk or a RAM (Random Access Memory), and stores in advance data such as its own secret data and arithmetic conversion processing method data necessary for the arithmetic processing in the arithmetic processing unit 160, and stores the arithmetic result etc. in the arithmetic processing unit 160 as negotiated secret information as needed.

[0018] Here, "confidential data" refers to non-public information such as "customer information" and "confidential vector". Also, "customer information" is the information of customers who use each institution, and "confidential vector" is information obtained by rearranging customer information according to an ID known to multiple institutions in such a way that for a certain institution, the information at each vector position of the confidential vector it holds is the same as the information at the same vector position of the confidential vector held by another institution that provides information to the same customer, and is information that has been aligned with a common understanding between the two institutions.

[0019] Here, "operation conversion processing method data" is data for determining various concealment operation processing methods executed by the operation processing unit 160, and includes information for specifying the operation conversion method type Type and information for specifying whether to use negotiation confidential information, etc.

[0020] Also, "negotiation confidential information" is confidential information obtained by performing operation processing in the operation processing unit 160 and created with the consent of both parties. When institutions P1 and P2 have confidential data X (Φ A ), confidential data Y (Φ B ) and output data OutputX (Ψ A ), OutputY (Ψ B ), the confidential data SecretX[Id] and SecretY[Id] that both institutions P1 and P2 store in the storage unit 130 with the same index Id attached are referred to. In "concealment operation conversion processing", there may be cases where operation conversion processing is performed using previously created negotiation confidential information stored in the storage unit 130, but the details are described in Patent Document 1, so please refer to that. In this specification, a method for newly creating negotiation confidential information completely secretly according to a protocol that guarantees information-theoretic security will be described.

[0021] The operation unit 140 is composed of various buttons and the like configured on the outer surface of the data processing device 100. When a predetermined button is pressed by the user, a "concealment operation conversion processing start notification" is sent to the control unit 110. The concealment operation conversion processing start notification is a signal that serves as a trigger for starting the concealment operation conversion processing.

[0022] The I / F unit 150 is composed of, for example, a USB (Universal Serial Bus) connector, a video output terminal, etc., and transmits the processing result to an external device (for example, a PC, a monitor, etc.).

[0023] As described above, the configuration of the secure operation conversion system 1 and the functions of each part have been explained. Next, with reference to FIG. 2, the outlines of the "secure operation conversion process" and the "negotiated secret information acquisition process" in the operation processing unit 160 will be explained. For the sake of simplicity, the control unit 110 is omitted in FIG. 2. However, it goes without saying that the exchange of information between each component and the transmission and reception between the institutions P1 and P2 are controlled and regulated by the control unit 110.

[0024] The "secure operation conversion process" in the operation processing unit 160 is started by the "secure operation conversion process start notification" from the operation unit 140. The secure operation conversion processing units 161 of the institutions P1 and P2 execute secure operation processing. Specifically, the secure operation conversion processing units 161 of the institutions P1 and P2 cooperate to calculate confidentially the input sets OutputX and OutputY (Ψ A , Ψ B ) of operation B such that the results obtained by applying operation A to their own secret data and the secret data of the other institution (Φ A , Φ B ) are the same. Institution P1 acquires only its own output data OutputX (Ψ A ), and institution P2 acquires only its own secret data output OutputY (Ψ B ).

[0025] The basic idea of the perfect secure operation conversion protocol according to the present invention is that institutions P1 and P2 use information that neither of them can create without cooperation and that is difficult for both of them to infer (hereinafter sometimes referred to as encrypted secure information) to exchange encrypted secret information with each other to generate negotiated secret information. The encrypted secure information is information in which a plurality of secret information of both institutions P1 and P2 are mixed.

[0026] The encrypted and anonymized information is generated in the process where institutions P1 and P2 exchange information obtained by performing a predetermined operation based on their own secret information on the public information of the other party, and then further exchange information obtained by performing a predetermined operation based on their own secret information on the exchanged information. When the encrypted and anonymized information is generated, institutions P1 and P2 encrypt their own secret information with the encrypted and anonymized information and exchange ciphertexts to generate negotiation secret information. Here, by encrypting the secret information with the encrypted and anonymized information, not only does the receiving side not know what the transmitting side's secret information is in general, but also the transmitting side does not know what kind of ciphertext the receiving side has received. This makes it impossible to specify the secret information by inverse calculation.

[0027] Hereinafter, a specific example of the perfectly secret arithmetic conversion protocol according to the present invention will be described with reference to FIGS. 3 to 6. FIGS. 3 and 4 are processing schematic diagrams for explaining the outline of the preprocessing (processing for generating encrypted and anonymized information) of the arithmetic conversion processing according to the perfectly secret arithmetic conversion protocol. FIGS. 5 and 6 are processing schematic diagrams for explaining the outline of the theoretical and actual arithmetic conversion processing (processing for generating negotiation secret information by exchanging ciphertexts of secret information using encrypted and anonymized information) according to the perfectly secret arithmetic conversion protocol. Hereinafter, with reference to these figures, the perfectly secret arithmetic conversion protocol according to the present invention, which guarantees information-theoretic security, will be described.

[0028] As a premise of the perfectly secret arithmetic conversion protocol, institution P1 stores values EA1, a1, a2, a3, γ as secret information in its storage unit 130. A , δ A , λ A , μ A , π A , Π A , μ A1 , μ A2 , ρ A , σ A , τ A , ν A And institution P2 stores values DB1, EB1, b1, b2, b3, γ as secret information in its storage unit 130. B , δ B , λB 、 μ B 、 χ B 、 α B 、 β B 、 π B 、 Π B 、 δ B1 、 δ B2 、 ρ B 、 σ B 、 τ B 、 ν B are each stored in its own memory unit 130. Some of these secret information are interdependent, but for those that can be determined independently, any value, i.e., a random number, is acceptable. Also, institution P1 discloses Q A1 = (a1) 1 / λA 、 Q A2 = (a2) 1 / δA 、 Q A3 = (a3) 1 / ρA to institution P2, and institution P2 discloses Q B1 = (b1) 1 / γB 、 Q B2 = (b2) 1 / μB 、 Q B3 = (b3) 1 / σB 、 DB2 to institution P1.

[0029] First, referring to Figure 3, the first preprocessing of the operation conversion process according to the perfectly confidential operation conversion protocol will be described. (Step1) The confidential operation conversion processing unit 161 of institution P1 calculates a value J B1 containing its own secret information δ A 、 γ A stored in the memory unit 130 as shown in (Equation 1) for the public information Q A of institution P2, and stores it in the memory unit 130. u is a primitive element. J A = Q B1 1 / δA u γA / δA (1) The confidential operation conversion processing unit 161 of institution P2 calculates a value J A1 containing its own secret information μ B 、 λ B stored in the memory unit 130 as shown in (Equation 2) for the public information QB Calculate it and store it in the storage unit 130. J B =Q A1 1 / μB u λB / μB (2) The confidential operation conversion processing unit 161 of the institution P1 transmits the calculated J A to the institution P2, and the confidential operation conversion processing unit 161 of the institution P2 transmits the calculated J B to the institution P1, and these values are exchanged between the institutions P1 and P2.

[0030] (Step2) The confidential operation conversion processing unit 161 of the institution P1 receives the J B from the institution P2, and calculates the value L A , μ A , δ A , Π A , μ A1 including the self-secret information λ A1 , L A2 stored in the storage unit 130 according to (Equation 3), and stores it in the storage unit 130. (L A1 , L A2 ) = (J B λA u μA , Q B2 1 / δA (J B / Π A ) λA / δA u μA1 / δA ) (3) Here, Π A = u πA = u λB1 / μB , J B / Π A = Q A1 1 / μB u (λB / μB)-πA = Q A1 1 / μB u λB2 / μB is set. That is, λ B1 = π A μ B , λ B2 = λ B - λ B1 is. The confidential operation conversion processing unit 161 of the institution P2 receives the J AReceive it, and the self-secret information γ stored in the storage unit 130 represented by (Equation 4) B , δ B , μ B , Π B , δ B1 The value L including B1 , L B2 is calculated and stored in the storage unit 130. (L B1 , L B2 ) = (J A γB u δB , Q A2 1 / μB (J A / Π B ) γB / μB u δB1 / μB ) (4) Here, Π B = u πB = u γA1 / δA , J A / Π B = Q B1 1 / δA u (γA / δA)-πB = Q B1 1 / δA u γA2 / δA is set. That is, γ A1 = π B δ A , γ A2 = γ A - γ A1 is. The confidential calculation conversion processing unit 161 of the institution P1 transmits the calculated (L A1 , L A2 ) to the institution P2, and the confidential calculation conversion processing unit 161 of the institution P2 transmits the calculated (L B1 , L B2 ) to the institution P1, and these values are exchanged between the institutions P1 and P2.

[0031] (Step3) The confidential calculation conversion processing unit 161 of the institution P1 receives L B1 from the institution P2, and calculates the value M B1 obtained by raising L A to the power of the self-secret information δ A1 stored in the storage unit 130, and stores it in the storage unit 130. M A1 can be expanded as in (Equation 5). M A1 = L B1 δA = Q B1 γB u γAγB u δAδB = b1R1(5) Here, Q B1 γB = b1, and let u^(γ A γ B + δ A δ B ) = R1. R1 is one of the encrypted confidential information. Note that the "^" in the formula represents the power operation. Also, the confidential operation conversion processing unit 161 of institution P1 receives L B2 from institution P2 and calculates the value M A , Π A , λ A , μ A2 including them and stores it in the storage unit 130, as shown in (Equation 6). A2 M A2 = L B2 δA Π A λA u μA2 (6) The confidential operation conversion processing unit 161 of institution P2 receives L A1 from institution P1 and calculates the value M A1 by raising L B to the power of its own secret information μ B1 stored in the storage unit 130 and stores it in the storage unit 130. M B1 can be expanded as shown in (Equation 7). M B1 = L A1 μB = Q A1 λA u λAλB u μAμB = a1R2(7) Here, Q A1 λA = a1, and let u^(λ A λ B + μ A μ B ) = R2. R2 is one of the encrypted confidential information. Also, the confidential arithmetic conversion processing unit 161 of institution P2 receives L from institution P1 A2 and calculates a value M including its own secret information μ, Π, γ, δ stored in the storage unit 130 as shown in (Equation 8) B 、Π B 、γ B 、δ B2 and stores it in the storage unit 130. B2 M B2 =L A2 μB Π B γB u δB2 (8) The confidential arithmetic conversion processing unit 161 of institution P1 transmits the calculated M to institution P2, and the confidential arithmetic conversion processing unit 161 of institution P2 transmits the calculated M to institution P1, and these values are exchanged between institutions P1 and P2. A2 B2

[0032] (Step4) The confidential arithmetic conversion processing unit 161 of institution P1 receives M from institution P2, raises M to the power of its own secret information δ stored in the storage unit 130, divides it by the secret information a1, calculates a value N, and stores it in the storage unit 130. N can be expanded as shown in (Equation 9). B2 B2 A A A N A =M B2 δA / a1 =Q B2 μB ((Q A1 λA u λAλB u μAμB ) / (a1Π A δAμB ))Π B δAγB u μA1μB u δAδB2 =(Q A1 λA Q B2 μB u λAλB2 u μA1μB u γA1γB u δAδB2 ) / a1​​​​​​​​ =b2R4(9) Here, Q A1 λA =a1, Q B2 μB =b2, and let u^(λ A λ B2 +μ A1 μ B +γ A1 γ B +δ A δ B2 ) = R4. R4 is one of the encrypted confidential information. The confidential operation conversion processing unit 161 of institution P2 receives M A2 from institution P1, and raises M A2 to the power of its own secret information μ B stored in the storage unit 130 and divides it by the secret information b1 to calculate the value N B and stores it in the storage unit 130. N B can be expanded as in (Equation 10). N B =M A2 μB / b1 =Q A2 δA ((Q B1 γB u γAγB u δAδB ) / (b1Π B δAγB ))Π A λAμB u μA2μB u δAδB1 =(Q B1 γB Q A2 δA u γA2γB u δAδB1 u λAλB1 u μA2μB ) / b1 =a2R3(10) Here, Q B1 γB =b1, Q A2 λA =a2, and u^(γ A2 γ B +δ A δ B1 +λ A λ B1 +μA2 μ B ) is set to R3. R3 is one of the encrypted secret information. The first preprocessing of the operation conversion process according to the complete secret operation conversion protocol is completed above.

[0033] Next, referring to FIG. 4, the second preprocessing of the operation conversion process according to the complete secret operation conversion protocol will be described. (Step1) The secret operation conversion processing unit 161 of institution P1 calculates the value S including its own secret information τ, σ stored in the storage unit 130, which is represented by (Equation 11), for the public information Q of institution P2, and stores it in the storage unit 130. B3 for the public information Q of institution P2, the value S including its own secret information τ, σ stored in the storage unit 130, which is represented by (Equation 11), A , σ A including the value S A and stores it in the storage unit 130. S A =Q B3 1 / τA u σA / τA (11) The secret operation conversion processing unit 161 of institution P2 calculates the value S including its own secret information ν, ρ stored in the storage unit 130, which is represented by (Equation 12), for the public information Q of institution P1, and stores it in the storage unit 130. A3 for the public information Q of institution P1, the value S including its own secret information ν, ρ stored in the storage unit 130, which is represented by (Equation 12), B , ρ B including the value S B and stores it in the storage unit 130. S B =Q A3 1 / νB u ρB / νB (12) The secret operation conversion processing unit 161 of institution P1 transmits the calculated S to institution P2, and the secret operation conversion processing unit 161 of institution P2 transmits the calculated S to institution P1, and these values are exchanged between institutions P1 and P2. A The secret operation conversion processing unit 161 of institution P1 transmits the calculated S to institution P2, and the secret operation conversion processing unit 161 of institution P2 transmits the calculated S to institution P1, and these values are exchanged between institutions P1 and P2. B and these values are exchanged between institutions P1 and P2.

[0034] (Step2) The secret operation conversion processing unit 161 of institution P1 receives S from institution P2, and calculates the value T including its own secret information ρ, ν stored in the storage unit 130, which is represented by (Equation 13), and stores it in the storage unit 130. B The secret operation conversion processing unit 161 of institution P1 receives S from institution P2, and for the public information Q of institution P2, the value S including its own secret information ρ, ν stored in the storage unit 130, which is represented by (Equation 13), A , ν A including the value T A and stores it in the storage unit 130. T A =SB ρA u νA (13) The secret operation conversion processing unit 161 of institution P2 receives S from institution P1 A and calculates a value T including its own secret information σ B , τ B stored in the storage unit 130 as shown in (Equation 14), and stores it in the storage unit 130. B T B = S A σB u τB (14) The secret operation conversion processing unit 161 of institution P1 sends the calculated T A to institution P2, and the secret operation conversion processing unit 161 of institution P2 sends the calculated T B to institution P1, and these values are exchanged between institutions P1 and P2.

[0035] (Step 3) The secret operation conversion processing unit 161 of institution P1 receives T from institution P2 B and calculates a value U obtained by raising T B to the power of its own secret information τ A stored in the storage unit 130, and stores it in the storage unit 130. U A can be expanded as shown in (Equation 15). A U A = T B τA = Q B3 σB u σAσB u τAτB = b3R5(15) Here, Q B3 σB = b3, and let u σAσB u τAτB = R5. R5 is one of the ciphertext concealment information. The secret operation conversion processing unit 161 of institution P2 receives T from institution P1 A and calculates a value U obtained by raising T A to the power of its own secret information ν B stored in the storage unit 130, and stores it in the storage unit 130. U B B ​​​It can be expanded as in (Equation 16). U B =T A νB =Q A3 ρA u ρAρB u νAμB =a3R6(16) Here, Q A3 ρA =a3, and u ρAρB u νAμB =R6. R6 is one of the cryptographic concealment information.

[0036] By the above first preprocessing and second preprocessing, a predetermined operation (these operations are high-load operations mainly involving exponential calculations) based on its own secret information is repeatedly performed on the values received from the other party between institutions P1 and P2 to generate new values and return them to the other party. As a result, the cryptographic concealment information R1, R2, R3, R4, R5, R6 that cannot be created without the cooperation of both institutions P1 and P2 and that is difficult for both parties to speculate on is generated. Strictly speaking, these cryptographic concealment information R1, R2, R3, R4, R5, R6 are parameters appropriately defined in the mathematical expressions during the protocol, and the values of these parameters are not directly calculated individually. That is, although R1, R4, R5 are generated in institution P1, institution P1 cannot know these values. Because what is calculated in institution P1 is a value obtained by multiplying the secret information b1, b2, b3 of institution P2 such as b1R1, b2R4, b3R5, and institution P2 has no way of knowing b1, b2, b3, so R1, R4, R5 cannot be identified. Similarly, although R2, R3, R6 are generated in institution P2, institution P2 cannot know these values. Because what is calculated in institution P2 is a value obtained by multiplying the secret information a1, a2, a3 of institution P1 such as a1R2, a2R3, a3R6, and institution P2 has no way of knowing a1, a2, a3, so R2, R3, R6 cannot be identified. As will be described later, even if the discrete logarithm problem can be solved by institutions P1 and P2, R1, R2, R3, R4, R5, R6 can only be identified probabilistically. In this regard, the perfect concealment operation conversion protocol according to the present invention guarantees information-theoretic security.

[0037] Next, with reference to FIGS. 5 and 6, a process of exchanging ciphertexts of secret information using the encrypted and anonymized information R3, R4, R5, R6 between the institutions P1 and P2 to generate negotiated secret information will be described. (Step0) As a preliminary preparation, the anonymization operation conversion processing unit 161 of the institution P2 acquires the encrypted and anonymized information R5 / R6 and stores it in the storage unit 130. Here, the secret information DB1 and the public information DB2 of the institution P2 can be expanded as shown in (Equation 17) and (Equation 18), respectively. DB1 = 1 / (χ B α B )(17) DB2 = (α B (R5 / R6) - β B ) / (χ B α B )(R5 / R6)(18) That is, the secret information DB1 is a value that can be represented using the secret information χ B , α B of the institution P2, and the public information DB2 is a value that can be represented using the secret information χ B , α B of the institution P2 and the encrypted and anonymized information R5 / R6. Theoretically, the anonymization operation conversion processing unit 161 of the institution P2 determines the secret information χ B , α B , β B in advance, calculates the secret information DB1 based on (Equation 17) from those values, and further acquires the encrypted and anonymized information R5 / R6 and calculates the public information DB2 based on (Equation 18). However, in practice, the secret information DB1 and the public information DB2 are determined in advance to appropriate values and stored in the storage unit 130, and the anonymization operation conversion processing unit 161 of the institution P2 obtains χ B , α B , β B from the predetermined DB1, DB2, and the acquired R5 / R6 and stores them in the storage unit 130.

[0038] Theoretically, institution P2 only needs to obtain the encrypted confidential information R5 / R6. However, as described above, since the values of the encrypted confidential information R5 and R6 cannot be calculated individually, R5 / R6 cannot be directly calculated. In practice, however, R5 / R6 can be indirectly calculated based on U A which is the value including R5 shown in (Equation 15) B and U B which is the value including R6 shown in (Equation 16). Here, since U A is a value calculated by institution P2, institution P2 can calculate R5 / R6 by obtaining the value including U A from institution P1. Specifically, as shown in (Equation 19), the confidential operation conversion processing unit 161 of institution P2 obtains U A multiplied by the secret information a3 of institution P1, which is U A a3, and divides that value by U B and its own secret information b3 stored in the storage unit 130 to calculate R5 / R6. (U A a3) / (U B b3)=(b3R5a3) / (a3R6b3)=R5 / R6(19)

[0039] (Step 1) The confidential operation conversion processing unit 161 of institution P1 receives, from institution P2, the ciphertext DB1' obtained by encrypting the secret information DB1 of institution P2 with the encrypted confidential information R3 / R5 and the public information DB2 of institution P2. Theoretically, the ciphertext DB1' only needs to be generated by multiplying the secret information DB1 of institution P2 by the encrypted confidential information R3 / R5. However, as described above, since the values of the encrypted confidential information R3 and R5 cannot be calculated individually, R3 / R5 cannot be directly calculated. However, R3 / R5 can be indirectly calculated based on N B which is the value including R3 shown in (Equation 10) A and U A which is the value including R5 shown in (Equation 15). Therefore, in practice, as shown in (Equation 20), the ciphertext DB1' is the temporary ciphertext DB1 (b3N B multiplied by b3) obtained by the confidential operation conversion processing unit 161 of institution P2 multiplying the secret information DB1 of institution P2 stored in the storage unit 130 by N B) is sent to institution P1, and the confidential operation conversion processing unit 161 of institution P1 receives the encrypted text DB1(b3N B ) sent from institution P2, and divides DB1(b3N B ) by the secret information U of institution P1 stored in the storage unit 130 A and a2 for calculation. DB1′ = DB1(b3N B ) / (a2U A ) = DB1(b3a2R3) / (a2b3R5) = DB1(R3 / R5) = (1 / (χ B α B ))(R3 / R5) (20) By encrypting the secret information DB1 of institution P2 with the encrypted confidential information R3 / R5 in this way, institution P1 does not know what the secret information DB1 of institution P2 is, and institution P2 does not know what the encrypted text DB1′ received by institution P1 is. Note that DB1′ received by institution P1 is a value uniquely determined by multiplying the secret information DB1 of institution P2 by the encrypted confidential information R3 / R5, and since DB2 is the public information of institution P2, institution P2 has no degree of freedom to change these values received by institution P1. Therefore, institution P1 only needs to receive these values unidirectionally from institution P2.

[0040] The confidential operation conversion processing unit 161 of institution P1 uses the encrypted text DB1′ received from institution P2 and the public information DB2 of institution P2 to calculate the secret information EA1 of the value obtained by subtracting 1 from DB1′ and adding DB2, and stores it in the storage unit 130. From (Equation 17), (Equation 18), and (Equation 20), EA1 can be expanded as in (Equation 21). EA1 = (DB1′ - 1) + DB2 =(1 / (χ B α B )(R3 / R5) - 1) + 1 / (χ B α B )(α B (R5 / R6) - β B )(R6 / R5) =(R3 - χ B α B R5 + α B R5 - βB R6)(1 / (χ B α B R5)) =(R3-(χ B -1)α B R5-β B R6)(1 / (χ B α B R5)) (21) Thus, EA1 can be easily calculated in institution P1 by performing arithmetic operations on the given DB1' and DB2. However, its essence is a value that can be represented using the secret information χ B , α B , β B of institution P2 that institution P1 cannot know, and the encrypted secret information R3, R5, and R6.

[0041] The secret operation conversion processing unit 161 of institution P2 calculates the secret information EB1 shown in (Equation 22) using the encrypted secret information R5 / R6 stored in the storage unit 130, its own secret information DB1, and the public information DB2, and stores it in the storage unit 130. EB1=(1-DB2(R5 / R6))DB1 -1 =((χ B -1)α B R5 / R6+β B ) (22) Thus, EB1 can be easily calculated in institution P2 by performing arithmetic operations on DB1 and DB2 that it owns and the acquired R5 / R6.

[0042] (Step2) The secret operation conversion processing unit 161 of institution P1 receives, from institution P2, the ciphertext EB1' obtained by encrypting the secret information EB1 of institution P2 with the encrypted secret information R6R4. Theoretically, the ciphertext EB1' may be generated by multiplying the secret information EB1 of institution P2 by the encrypted secret information R6R4. However, as described above, since the values of the encrypted secret information R6 and R4 cannot be calculated individually, R6R4 cannot be directly calculated. However, R6R4 is the value U B including R6 shown in (Equation 16) and the value N A including R4 shown in (Equation 9).It can be calculated indirectly based on this. Therefore, in reality, as shown in (Equation 23), the ciphertext EB1′ is the secret information EB1 of institution P2 stored in the storage unit 130 by the secret operation conversion processing unit 161 of institution P2, multiplied by U B and divided by b2 to obtain the temporary ciphertext EB1(U B / b2), which is sent to institution P1. The secret operation conversion processing unit 161 of institution P1 receives the temporary ciphertext EB1(U B / b2) sent from institution P2, and EB1(U B / b2) is multiplied by the secret information N A of institution P1 stored in the storage unit 130 and divided by a3 for calculation. EB1′ = EB1(N A / a3) / (U B / b2) = EB1(b2R4 / a3) / (a3R6 / b2) = EB1(R6R4) = ((χ B -1)α B (R5 / R6)+β B )(R6R4) (23) By encrypting the secret information EB1 of institution P2 with the ciphertext concealment information R6R4 in this way, institution P1 does not know what the secret information EB1 of institution P2 is, and institution P2 does not know what the ciphertext EB1′ received by institution P1 is.

[0043] The secret operation conversion processing unit 161 of institution P1 directly stores the ciphertext EB1′ obtained by encrypting the secret information EB1 of institution P2 with the ciphertext concealment information R6R4 in the storage unit 130 as the output data FA1. From (Equation 22) and (Equation 23), FA1 can be expanded as in (Equation 24). FA1 = EB1′ = ((χ B -1)α B R5+β B R6)R4(24) In this way, FA1 is the given EB1′ itself and can be obtained by institution P1 without any calculation. However, its entity is a value that can be expressed using the secret information χ B , α B , β B of institution P2 that institution P1 cannot know, and the ciphertext concealment information R4 and R5.

[0044] The secret operation conversion processing unit 161 of institution P2 receives, from institution P1, the ciphertext EA1' obtained by encrypting the secret information EA1 of institution P2 with the ciphertext concealment information R5R4. Theoretically, the ciphertext EA1' may be generated by multiplying the secret information EA1 of institution P1 by the ciphertext concealment information R5R4. However, as described above, since the values of the ciphertext concealment information R5 and R4 cannot be calculated individually, R5R4 cannot be directly calculated. However, R5R4 can be indirectly calculated based on U A which is the value including R5 shown in (Equation 15) A and N A which is the value including R4 shown in (Equation 9). A Therefore, in practice, as shown in (Equation 25), the ciphertext EA1' is the temporary ciphertext EA1(N A U A ) obtained by multiplying the secret information EA1 of institution P1 stored in the storage unit 130 of the secret operation conversion processing unit 161 of institution P1 by N A U A and sent to institution P2. The secret operation conversion processing unit 161 of institution P2 receives the temporary ciphertext EA1(N A U A ) sent from institution P1, and EA1(N EA1' = EA1(N A U A ) / (b2b3) = EA1(b2R4b3R5) / (b2b3) = EA1(R5R4) = (R3 - (χ B - 1)α B R5 - β B R6)(R5R4) / (χ B α B R5) (25) By encrypting the secret information EA1 of institution P1 with the ciphertext concealment information R5R4 in this way, institution P2 does not know what the secret information EA1 of institution P1 is, and institution P1 does not know what the ciphertext EA1' received by institution P2 is.

[0045] The confidential operation conversion processing unit 161 of institution P2 uses the ciphertext EA1' received from institution P1 and its own secret information DB1 stored in the storage unit 130 to multiply DB1 by EA1' -1 to calculate the output data FB1 and store it in the storage unit 130. From (Equation 17) and (Equation 25), FB1 can be expanded as in (Equation 26). FB1 = EA1'DB1 -1 = (R3 - (χ B - 1)α B R5 - β B R6)R4 (26) In this way, FB1 can be easily calculated in institution P2 by performing arithmetic operations on the given EA1' and the DB1 held by itself.

[0046] Next, the relationship between FA1 and FB1 finally generated in institutions P1 and P2 in the above procedure and M A1 , M B1 generated in the pre - processing will be described. Regarding the value of M A1 calculated by institution P1 divided by the secret information a1 of institution P1, M A1 / a1, and the value of M B1 calculated by institution P2 divided by the secret information b1 of institution P2, M B1 / b1, from (Equation 5) and (Equation 7), (Equation 27) holds. (M A1 / a1)(M B1 / b1) = (b1R1 / a1)(a1R2 / b1) = R1R2 (27) Also, in (Equation 5), (Equation 7), (Equation 10), and (Equation 9) R1 = u^(γ A γ B + δ A δ B ) R2 = u^(λ A λ B + μ A μ B ) R3 = u^(γ A2 γ B + δ A δ B1 + λ A λ B1 + μA2 μ B ) R4 = u^(λ A λ B2 + μ A1 μ B + γ A1 γ B + δ A δ B2 ) Since it is set as such, (Equation 28) holds. R1R2 = u^(γ A γ B + δ A δ B )u^(λ A λ B + μ A μ B ) = u^((γ A1 + γ A2 )γ B )u^(δ A (δ B1 + δ B2 ))u^(λ A (λ B1 + λ B2 ))u^((μ A1 + μ A2 )μ B ) = u^(γ A2 γ B + δ A δ B1 + λ A λ B1 + μ A2 μ B )u^(λ A λ B2 + μ A1 μ B + γ A1 γ B + δ A δ B2 ) = R3R4 (28) Here, γ A = γ A1 + γ A2 、δ B = δ B1 + δ B2 、λ B = λ B1 + λ B2 、μ A = μ A1 + μA2 Let it be so. Furthermore, regarding the sum FA1 + FB1 of FA1 and FB1, (Equation 29) holds from (Equation 24) and (Equation 26). FA1 + FB1 = ((χ B - 1)α B R5 + β B R6)R4 + (R3 - (χ B - 1)α B R5 - β B R6)R4 = R3R4 (29) Therefore, (Equation 30) holds from (Equation 27), (Equation 28), and (Equation 29). (M A1 / a1)(M B1 / b1) = R1R2 = R3R4 = FA1 + FB1 (30) Here, the information M A1 / a1 and FA1 that only institution P1 can know are respectively the secret data Φ A and the output data Ψ A of institution P1, and the information M B1 / b1 and FB1 that only institution P2 can know are respectively the secret data Φ B and the output data Ψ B of institution P2. Then, (Equation 31) holds from (Equation 30). Φ A Φ B = Ψ A + Ψ B (31) The information represented by this (Equation 31) is the negotiation secret information to be obtained. What this (Equation 31) means is that the product Φ A of the secret data Φ B of institution P1 and the secret data Φ A of institution P2 can be converted into the sum Ψ B of the output data Ψ A of institution P1 and the output data Ψ B of institution P2, that is, Ψ A + Ψ B .

[0047] The negotiation secret information acquisition processing unit 162 of institution P1 and institution P2 executes the negotiation secret information acquisition process. Specifically, the negotiation secret information acquisition processing unit 162 of institution P1 uses the output data Ψ obtained by the confidentiality operation conversion processing unit 161A , and the secret data Φ A , the information specifying the arithmetic conversion method type Type (information indicating the conversion from multiplication to addition in the above procedure) is grouped as ObjectX. Similarly, the negotiation secret information acquisition processing unit 162 of the institution P2 also outputs the data Ψ B , and the secret data Φ B , and groups the arithmetic conversion method type Type as ObjectY. Further, the institutions P1 and P2 cooperate to determine the same index Id for ObjectX and ObjectY at both institutions, and store them as negotiation secret information SecretX[Id] and SecretY[Id] in their respective storage units 130.

[0048] When the negotiation secret information created in complete secrecy is stored in the respective storage units 130 of the institutions P1 and P2 in this way, thereafter, by using the negotiation secret information, a new secret operation conversion process based on new secret information can be extremely safely performed between the institutions P1 and P2 by an operation with a small computational load of only four arithmetic operations such as the "multiplication-addition conversion process with negotiation secret information" or the "addition-multiplication conversion process with negotiation secret information" disclosed in Patent Document 1. Furthermore, new negotiation secret information can be obtained by the new secret operation conversion process. The negotiation secret information acquisition processing units 162 of the institutions P1 and P2 store the new negotiation secret information in the storage unit 130 and update the negotiation secret information stored until then. Thereafter, in the same manner as above, by using the new negotiation secret information, a new secret operation conversion process based on new secret information can be extremely safely performed between the institutions P1 and P2 by an operation with a small computational load of only four arithmetic operations such as the "multiplication-addition conversion process with negotiation secret information" or the "addition-multiplication conversion process with negotiation secret information".

[0049] Next, it will be explained that the complete secrecy operation conversion protocol according to the present invention guarantees information-theoretic security. For the sake of explanation, assume that the discrete logarithm problem is solved in the institution P1 in the preprocessing of the operation conversion process according to the complete secrecy operation protocol.

[0050] FIG. 7 is a processing schematic diagram for explaining an overview of secret information analysis of institution P2 when the discrete logarithm problem is solved in institution P1 in the first preprocessing of the arithmetic conversion process shown in FIG. 3. Assuming that the discrete logarithm problem is solved in institution P1, as shown in FIG. 7, when institution P1 receives Q B1 at (Step1), q B1 ′ is obtained. When institution P1 receives J B at (Step2), j B ′ is obtained. When institution P1 receives L B1 , L B2 at (Step3), l B1 ′, l B2 ′ are obtained. When institution P1 receives M B2 at (Step4), m B2 ′ is obtained. From the information thus obtained, the relationships shown in (Equation 32) and (Equation 33) are found. j B ′=(q A1 +λ B ) / μ B → μ B =(q A1 +λ B ) / j B ′ (32) l B ′=j A γ B +δ B → δ B =l B ′-j A γ B (33) Here, for institution P1, γ B , δ B , λ B , μ B are unknown, and the other values are known. Also, δ B can be expressed as a function of γ B , and μ B can be expressed as a function of λ B . From this, R1 and R2 are expressed as in (Equation 34) and (Equation 35). R1=u^(γ A γ B +δ A (l B1 ′-j Aγ B )) (34) R2 = u ^ (λ A λ B + μ A (q A1 + λ B ) / j B ′) (35) (In equations (34) and (35), γ B , λ B The probability of accurately predicting is the same for all candidates, and for candidates of γ B , λ B There are candidates for R1 and R2 respectively. Therefore, R1 and R2 cannot be uniquely identified and can only be identified probabilistically.

[0051] Also, from the information that the discrete logarithm problem can be solved and obtained, the relationships shown in equations (36), (37), and (38) are found. l B2 ′ = (q A2 +(j A - π B )γ B + δ B1 ) / μ B → δ B1 = μ B l B2 ′ - q A2 -(j A - π B )γ B (36) m B2 ′ = l A2 μ B + π B γ B + δ B2 → δ B2 = m B2 ′ - l A2 μ B - π B γ B (37) δ B = δ B1 + δ B2 → δ B = μ B l B2 ′ + m B2 ′ - q A2 - j A γ B - lA2 μ B (38) Here, as described above, δ B is a function of γ B and can be expressed as a function of μ B respectively. Also, l B can be substituted with (Equation 39). A2 l A2 =(q B2 ′+(j B ′-π A )λ A +μ A1 ) / δ A (39) From this, R4 and R3 are expressed as in (Equation 40) and (Equation 41). For the sake of convenience, the intermediate process of formula expansion is omitted. R4 = u^(-q B2 ((λ B +q A1 ) / j B ′-λ A q A1 +δ A m B2 ′)) (40) R3 = u^(γ A γ B +μ A μ B +δ A δ B +λ A λ B +q B2 ′((λ B +q A1 ) / j B ′)+λ A q A1 -δ A m B2 ′) (41) Thus, R3 is expressed as a function of γ B and λ B , and R4 is expressed as a function of λ B . In (Equation 40) and (Equation 41), the probability of accurately predicting γ B and λ B is the same for all candidates, and γ B and λ B ​For the candidates of R3 and R4, there are corresponding candidates respectively. Therefore, R3 and R4 cannot be uniquely identified either and can only be identified probabilistically.

[0052] Figure 8 is a processing schematic diagram for explaining the outline of the secret information analysis of institution P2 when the discrete logarithm problem is solved in institution P1 in the second preprocessing of the arithmetic conversion process shown in Figure 4. Assuming that the discrete logarithm problem is solved in institution P1, as shown in Figure 8, when institution P1 receives Q in (Step1), q' is obtained. When institution P1 receives S in (Step2), s' is obtained. When institution P1 receives T in (Step3), t' is obtained. From the information thus obtained, the relationships shown in (Equation 42) and (Equation 43) are found. B3 When receiving q B3 ′ is obtained when institution P1 receives S B When receiving s B ′ is obtained. When institution P1 receives T in (Step3), t B When receiving t B ′ is obtained. From the information that can be obtained in this way, the relationships shown in (Equation 42) and (Equation 43) are found. s B ′=(q A3 +ρ B ) / ν B → ν B =(q A3 +ρ B ) / s B ′ (42) t B ′=((q B3 ′ / τ A )+(σ A / τ A ))σ B +τ B → τ B =t B ′-((q B3 ′ / τ A )+(σ A / τ A ))σ B (43) Here, for institution P1, ν B , ρ B , σ B , τ B are unknown, and the other values are known. Also, ν B is a function of ρ B , and τ B is a function of σ Bcan be expressed as functions respectively. From this, R5 and R6 are expressed as in (Equation 44) and (Equation 45). R5 = u^(σ A σ B + τ A (t B ′ - ((q B3 ′ / τ A ) + (σ A / τ A )σ B ) (44) R2 = u^(ρ A ρ B + ν A (q A3 + ρ B ) / s B ′) (45) In (Equation 44) and (Equation 45), the probability of accurately predicting ρ B , σ B is the same for all candidates, and for candidates of ρ B , σ B , there are candidates for R5 and R6 respectively. Therefore, R5 and R6 cannot be uniquely identified either and can only be identified probabilistically.

[0053] Next, from (Equation 34), (Equation 35), (Equation 40), and (Equation 41), R1 / R2, R3 / R4, R3 / R1, R3 / R2, R4 / R1, and R4 / R2 are expressed as in (Equation 46), (Equation 47), (Equation 48), (Equation 49), (Equation 50), and (Equation 51) respectively. For the sake of convenience, the intermediate process of formula expansion is omitted. R1 / R2 = u^(γ A γ B + δ A (l B1 ′ - j A γ B ) - λ A λ B - μ A (q A1 + λ B ) / j B ) (46) R3 / R4 = u^(γ A γ B + μ A μ B + δ A δ B + λA λ B +2q B2 ′(λ B +q A1 ) / j B ′+2λ A q A1 -2δ A m B2 ′) (47) R3 / R1 = u^(λ A λ B +(μ A +q B2 ′)(λ B +q A1 ) / j B ′+λ A q A1 -δ A m B2 ′) (48) R3 / R2 = u^(γ A γ B +δ A (l B1 ′-j A γ B )+q B2 ′(λ B +q A1 ) / j B ′+λ A q A1 -δ A m B2 ′) (49) R4 / R1 = u^(-q B2 (λ B +q A1 ) / j B ′-λ A q A1 +δ A m B2 ′-γ A γ B -δ A (l B1 ′-j A γ B )) (50) R4 / R2 = u^(-(q B2 +j B ′λ A +μ A )(q A1 +λ B ) / j B ′+δ A m B2 ′) (51)

[0054] Here, it is difficult for only institution P1 to estimate the ratios of each of R1 and R2 to each of R3 and R4, and γ B , λ B For each candidate of, there are corresponding candidates for the values of R1 / R2, R3 / R4, R3 / R1, R3 / R2, R4 / R1, and R4 / R2. Therefore, without using specific candidate values of γ B , λ B , it is difficult for institution P1 to obtain the ratios between Φ A , Φ B , Ψ A , Ψ B . Also, for each candidate combination (γ B , λ B ) of the variable combination (γ B ′, λ B ′), there are corresponding candidates R1′, R2′, R3′, and R4′ for each of R1, R2, R3, and R4, and in any combination R1′R2′ = R3′R4′ holds. Even when using Ψ A = FA1 obtained by institution P1 through the perfect secrecy operation conversion protocol of the present invention, FA1 = R4′((χ B ′ - 1)α B ′R5′ + β B ′) can only be estimated. Here, χ B ′, α B ′, β B ′, R5′, and R6′ are the estimated values of each variable. The estimated value FB1′ of information FB1 is FB1′ = R3′R4′ - R4′((χ B ′ - 1)α B ′R5′ + β B ′) By satisfying this, institution P1 can only estimate the estimated value of information FB1 held by institution P2 as FB1′ = R3′R4′ - FA1 . At this time, R1′R2′ = FA1 + FB1′ and no contradiction occurs. Therefore, for all (γ B , λB ) for each candidate combination (γ B ′, λ B ′), there must exist a candidate FB1′ of the information FB1.

[0055] The information of the mechanism P1 as seen from the mechanism P2 is also difficult to infer the ratios of R1 and R2 to R3 and R4 respectively only from the mechanism P2 in the same way as the above discussion. For the candidates of γ A , λ A , there exist candidates for the values of R1 / R2, R3 / R4, R3 / R1, R3 / R2, R4 / R1, and R4 / R2 respectively. Therefore, without using the specific candidate values of γ A , λ A , it is difficult to obtain the mutual ratios among Φ A , Φ B , Ψ A , Ψ B of the mechanism P1. Also, for each candidate combination (γ A , λ A ) for the combination of variables (γ A ′, λ A ′), there exist candidates R1′, R2′, R3′, and R4′ for each of R1, R2, R3, and R4, and in any combination R1′R2′ = R3′R4′ holds. Using Ψ AB = FB1 obtained by the mechanism P2 through the perfect secrecy operation conversion protocol according to the present invention FB1 = R3′R4′ - R4′((χ B - 1)α B R5′ + β B R6′) = R3′R4′ - R4′((χ B - 1)α B R5′ + β B (R6 / R5)R5′) can be inferred. Here, R5′ and R6′ are the inferred values of each variable. The inferred value FA1′ of the information FA1 is FA1′ = R4′((χ B - 1)α B R5′ + β B R6′) Since it satisfies, the mechanism P2 uses it as the inferred value of the information FA1 possessed by the mechanism P1 FA1′ = R3′R4′ - FB1 can only be speculated as such. At this time, R1′R2′ = FA1′ + FB1 and no contradiction occurs. Therefore, for each candidate combination (γ A , λ A ) for all (γ A ′, λ A ′), there must exist a candidate FA1′ for the information FA1.

[0056] As described above, according to this embodiment, each of the institutions P1 and P2 encrypts its own secret information with the encrypted secret information in which the secret information of both institutions is mixed and exchanges with the other institution. Thus, not only does the receiving side not know what the secret information of the transmitting side is, but also the transmitting side does not know what ciphertext the receiving side has received, so that the negotiation secret information can be created among multiple institutions. As a result, the negotiation secret information can be created according to a protocol that guarantees information-theoretic security among multiple institutions.

Explanation of Symbols

[0057] 1 Confidential operation conversion system, 100 Data processing device, 110 Control unit, 120 Communication unit, 130 Storage unit, 140 Operation unit, 150 Interface unit, 160 Arithmetic processing unit, 161 Confidential operation conversion processing unit, 162 Negotiation secret information acquisition processing unit, 200 Communication line

Claims

1. A secret operation conversion system comprising a data processing device of a first institution and a data processing device of a second institution, which encrypt and exchange secret information and public information between the data processing devices to generate operand information for another operation B that can obtain the same result as the result of performing operation A on the secret data of each institution, wherein each of the data processing devices has a storage unit for storing information, a secret operation conversion processing means for performing a first process of exchanging ciphertexts of its own secret information with the data processing device of the other institution to generate encrypted secret information in which the secret information of both institutions is mixed, and a second process of exchanging ciphertexts obtained by encrypting its own secret information with the encrypted secret information with the data processing device of the other institution to generate the operand information, and a negotiation secret information acquisition processing means for storing in the storage unit negotiation secret information associating its own secret data having the encrypted secret information as a factor with the generated operand information. A secret operation conversion system characterized by the above.

2. The secret operation conversion system according to claim 1, wherein operation A is multiplication and operation B is addition.

3. The secret operation conversion system according to claim 1 or 2, wherein the first process is a process including exponentiation calculation, and the second process consists of only arithmetic operations.

4. The secret operation conversion processing means executes the second process on its own new secret data to generate new operand information, and the negotiation secret information acquisition processing means stores in the storage unit new negotiation secret information associating the new secret data with the generated new operand information, and updates the negotiation secret information stored until then. The secret operation conversion system according to any one of claims 1 to 3.

5. A secret operation conversion method for encrypting and exchanging secret information and public information between a data processing device of a first institution and a data processing device of a second institution to generate operand information for another operation B that can obtain the same result as the result of performing operation A on the secret data of each institution, wherein the data processing device of each institution performs a first step of exchanging ciphertexts of its own secret information with the data processing device of the other institution to generate encrypted secret information in which the secret information of both institutions is mixed, and a second step in which the data processing device of each institution exchanges ciphertexts obtained by encrypting its own secret information with the encrypted secret information with the data processing device of the other institution to generate the operand information. A third step in which the data processing device of each institution stores in a storage unit negotiation secret information associating its own secret data having the encrypted secret information as a factor and the generated information to be calculated, A secret calculation conversion method characterized by the above.

6. The secret calculation conversion method according to claim 5, wherein the calculation A is multiplication and the calculation B is addition.

7. The secret calculation conversion method according to claim 5 or 6, wherein the first step is a process including exponentiation calculation and the second step is a process consisting only of arithmetic operations.

8. A fourth step in which the data processing device of each institution executes the second step for its own new secret data to generate new information to be calculated, A fifth step in which the data processing device of each institution stores in the storage unit new negotiation secret information associating the new secret data and the newly generated information to be calculated, and updates the negotiation secret information stored until then. The secret calculation conversion method according to any one of claims 5 to 7.

9. A secret calculation conversion program that functions a computer as the data processing device in a system that encrypts and exchanges secret information and public information between the data processing device of the first institution and the data processing device of the second institution, and generates information to be calculated for another calculation B that can obtain the same result as the result of performing calculation A on the secret data of each institution, A first process of exchanging an encrypted text of its own secret information with the data processing device of the other institution to generate encrypted secret information in which the secret information of both institutions is mixed, and a second process of exchanging an encrypted text obtained by encrypting its own secret information with the encrypted secret information with the data processing device of the other institution to generate the information to be calculated. Secret calculation conversion processing means for executing, Functioning a computer as negotiation secret information acquisition processing means for storing in a storage unit negotiation secret information associating its own secret data having the encrypted secret information as a factor and the generated information to be calculated, A secret calculation conversion program characterized by the above.

10. The secret calculation conversion program according to claim 9, wherein the calculation A is multiplication and the calculation B is addition.

11. The secret calculation conversion program according to claim 9 or 10, wherein the first process is a process including exponentiation calculation and the second process is a process consisting only of arithmetic operations.

12. The secret arithmetic conversion processing means executes the second process on its own new secret data to generate new data to be computed, The negotiation secret information acquisition processing means stores new negotiation secret information associating the new secret data with the generated new data to be computed in the storage unit, and updates the negotiation secret information stored until then. The secret arithmetic conversion program according to any one of claims 9 to 11.

Citation Information

Patent Citations

  • Secret calculation information exchange system, data processing device, secret calculation information exchange method, secret calculation information exchange program, and recording medium

    JP2016109891A

  • Secret calculation information exchanging system, data processor, secret calculation information exchanging method, secret calculation information exchanging program and recording medium

    JP2017129644A

  • Security calculation conversion system, security calculation conversion method, and security calculation conversion program

    JP2020016739A