Information processing system, data providing device, data processing device, data receiving device, method and program

The system addresses inefficiencies and flexibility issues in data processing by using sanitized signatures and range certification data to ensure legitimate anonymized data utilization, enhancing processing efficiency and flexibility.

JP7718580B2Active Publication Date: 2025-08-05NEC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024510598
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-28
Publication Date
2025-08-05
Estimated Expiration
2042-03-28

AI Technical Summary

Technical Problem

Existing data processing technologies lack flexibility and efficiency, and may not guarantee the legitimacy of anonymized data, risking inappropriate data utilization and policy/service decisions.

Method used

An information processing system comprising a data providing device, processing device, and receiving device that utilize sanitized signatures and range certification data to enable arbitrary generalization processing, ensuring data legitimacy through digital signature verification and range proof verification.

Benefits of technology

Enables efficient and flexible data processing while ensuring that anonymized data remains legitimate, allowing appropriate data utilization and reducing computational load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007718580000005
    Figure 0007718580000005
  • Figure 0007718580000006
    Figure 0007718580000006
  • Figure 0007718580000007
    Figure 0007718580000007
Patent Text Reader

Abstract

Provided is a system that can perform a process efficiently while performing manipulation of data appropriately. This data provision device (100) acquires range certification data in a plurality, generates a digital signature for each of the range certification data, and transmits a dataset, a sanitizable signature, the range certification data, and the digital signatures to a data manipulation device. The data manipulation device (200) performs a process for subjecting data to be manipulated to a generalization manipulation, performs a process on the sanitizable signature, and selects range certification data corresponding to the range of a generalized attribute value. The data manipulation device (200) transmits, to a data reception device, a dataset which has been subjected to manipulation, the sanitizable signature which has been subjected to the process, the range certification data which has been selected, and the digital signature which corresponds to the range certification data. The data reception device (300) performs verification of the sanitizable signature, performs verification of the digital signature corresponding to the range certification data, and performs verification of the range certification data.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing system, a data providing device, a data processing device, a data receiving device, a method, and program Regarding. [Background technology]

[0002] In recent years, the use of anonymously processed information (anonymized data), which is premised on the appropriate protection of personal information, has been increasing. When researchers and others use anonymized data, ensuring that the data has not been improperly altered (data legitimacy) is important in order to guarantee the legitimacy of the results of data utilization. In other words, if fraudulent data is used, the knowledge gained from the data will also be fraudulent, and there is a risk that policies and services based on the data will be inappropriate. Digital signature technology is a technology that can verify that electronic data has not been altered. However, if a digital signature is simply applied to the data, the anonymization process will result in the data being altered, and there is a risk that legitimacy cannot be verified.

[0003] In relation to such technology, Patent Document 1 discloses an anonymization system that can verify the legitimacy of anonymization processing on data even after anonymization processing such as deletion or replacement has been performed. In Patent Document 1, an anonymized data providing server performs a patient data record extension process and stores the processing result in an extended patient data table. The anonymized data providing server then performs a signature generation process to generate a digital signature using data from the extended patient data table as input, and transmits the generated signature value, along with the original patient data name, to an anonymized data user terminal via web server registration. Upon receiving a request to obtain anonymized data, the anonymized data providing server performs a verifiable anonymization process using the patient data name and anonymization conditions as input, generates anonymized data, and transmits it to the anonymized data user terminal. The anonymized data user terminal then performs a signature verification process using the anonymized data and the signature value as input, verifying the legitimacy of the anonymized data.

[0004] Non-Patent Document 1 discloses a chameleon hash-based sanitizable signature. This technology allows a data processor to perform any processing on the target data while ensuring the authenticity of the data. Non-Patent Document 2 and Non-Patent Document 3 disclose examples of certification protocols related to this disclosure. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Publication No. 2020-077256 [Non-patent literature]

[0006] [Non-Patent Document 1] G. Ateniese, DH Chou, B. de Medeiros, and G. Tsudik, "Sanitizable signatures", In ESORICS, Vol. 3679 of Lecture Notes in Computer Science, pp. 159-177. Springer, 2005., URL: https: / / link.springer.com / content / pdf / 10.1007%2F11555827_10.pdf [Non-patent document 2] Yuval Ishai, Eyal Kushilevitz, Rafail Ostrovsky, and Amit Sahai, "Zero-Knowledge from Secure Multiparty Computation", INVITED AND ACCEPTED TO SIAM JOURNAL ON COMPUTING (SICOMP) SPECIAL ISSUE DEVOTED TO STOC-2007., URL: https: / / web.cs.ucla.edu / ~rafail / PUBLIC / 77.pdf [Non-patent document 3] Zhengjun Cao, "An Efficient Range-Bounded Commitment Scheme", IACR Cryptol. ePrint Arch. 2007 (2007): 376., URL: https: / / eprint.iacr.org / 2007 / 376.pdf Summary of the Invention [Problem to be solved by the invention]

[0007] The technology disclosed in Patent Document 1 may reduce the flexibility of data processors in processing data. Therefore, the technology disclosed in Patent Document 1 may not allow data to be processed appropriately. Furthermore, if an attempt is made to achieve processing flexibility in Patent Document 1, there is a risk that processing will not be efficient. Furthermore, the technology disclosed in Non-Patent Document 1, which allows data processors to perform arbitrary processing, may not be able to guarantee whether the original data has been appropriately generalized. Therefore, the above-mentioned technology may not allow data to be processed appropriately.

[0008] The purpose of the present disclosure is to solve such problems and to provide a system, device, method, and program that can process data appropriately while efficiently processing the data. [Means for solving the problem]

[0009] An information processing system according to the present disclosure includes a data providing device that provides a data set composed of a plurality of data relating to at least one attribute, a data processing device that processes at least a portion of the plurality of data, and a data receiving device that receives the data set with the portion of the data processed; The data providing device comprises: a sanitized signature generation means for generating a sanitized signature that enables arbitrary generalization of processing target data that is permitted to be processed; a range certification acquisition means for acquiring a plurality of range certification data for proving that an attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on an attribute value of the processing target data; a signature generation means for generating a digital signature for each of the range certification data; and a first transmission means for transmitting the data set, the sanitized signature, the range certification data, and the digital signature to the data processing device; the data processing device comprises: a processing means for performing processing to perform generalization processing on the processing target data; a sanitized signature processing means for performing processing on the sanitized signature using the processing target data before processing and the processing target data after processing; a range certification selection means for selecting, for each of the processing target data that has been generalized, range certification data from a plurality of range certification data that corresponds to a range of generalized attribute values; and a second transmission means for transmitting to the data receiving device a data set that has been processed on the processing target data, the processed sanitized signature, the range certification data selected for each of the processing target data, and the digital signature corresponding to the range certification data, The data receiving device has a sanitized signature verification means that verifies the data set that has been processed on the data to be processed and the sanitized signature that has been processed by the data processing device, a digital signature verification means that verifies the digital signature that corresponds to the range proof data selected by the data processing device, and a range proof verification means that verifies the range proof data selected by the data processing device.

[0010] In addition, the data providing device according to the present disclosure includes a sanitized signature generation means for generating a sanitized signature that enables arbitrary generalization of target data that is permitted to be processed among a dataset consisting of a plurality of data related to at least one attribute; a range certification acquisition means for acquiring a plurality of range certification data for proving that the attribute value before processing falls within the range of generalized attribute values when generalization processing is performed on the attribute value of the target data; a signature generation means for generating a digital signature for each of the plurality of range certification data; and a transmission means for transmitting the dataset, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least some of the plurality of data.

[0011] In addition, the data processing device according to the present disclosure includes: a processing means for performing processing to perform generalization processing on target data for which processing is permitted, which is provided by a data providing device that provides a dataset consisting of a plurality of data related to at least one attribute; a sanitized signature processing means for performing processing on a sanitized signature that is generated by the data providing device for the target data using the target data before processing and the target data after processing, and that enables arbitrary generalization processing; range certification selection means for selecting range certification data that corresponds to the range of generalized attribute values from a plurality of range certification data acquired by the data providing device, for proving that the attribute value before processing falls within a range of generalized attribute values for each of the target data for which generalization processing has been performed; and a transmission means for transmitting the dataset on which processing has been performed on the target data, the processed sanitized signature, the range certification data selected for each of the target data for which processing has been performed, and a digital signature generated by the data providing device and corresponding to the range certification data, to a data receiving device that receives the dataset in which some data has been processed.

[0012] In addition, the data receiving device according to the present disclosure includes: a data set obtained by a data processing device from data to be processed that is permitted to be processed and that is provided by a data providing device that provides a data set consisting of multiple data related to at least one attribute; a sanitized signature verification means that verifies a sanitized signature that is generated by the data providing device for the data to be processed and that enables arbitrary generalization processing and that is processed by the data processing device; range proof data that proves that the attribute values before processing for each of the data to be processed that has been generalized fall within a range of generalized attribute values, and a digital signature verification means that verifies a digital signature corresponding to the range proof data selected by the data processing device from among the multiple range proof data acquired by the data providing device; and a range proof verification means that verifies the range proof data selected by the data processing device.

[0013] Furthermore, an information processing method according to the present disclosure includes, by a data providing device that provides a data set consisting of a plurality of data related to at least one attribute, generating a sanitized signature that enables arbitrary generalization of processing target data that is permitted to be processed, obtaining a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data, generating a digital signature for each of the range certification data, and transmitting the data set, the sanitized signature, the range certification data, and the digital signature to a data processing device that processes at least a portion of the plurality of data; using the data processing device, performing processing to generalize the data to be processed, processing the sanitized signature using the data to be processed before processing and the data to be processed after processing, selecting, for each of the data to be processed that has been generalized, the range certification data corresponding to the range of the generalized attribute value from among the plurality of range certification data, and transmitting the data set that has been processed for the data to be processed, the sanitized signature that has been processed, the range certification data selected for each of the data to be processed, and the digital signature that corresponds to the range certification data to a data receiving device that receives the data set in which some of the data has been processed; The data receiving device verifies the data set processed on the data to be processed and the sanitized signature processed by the data processing device, verifies the digital signature corresponding to the range proof data selected by the data processing device, and verifies the range proof data selected by the data processing device.

[0014] In addition, the data providing method disclosed herein generates a sanitized signature that enables arbitrary generalization processing for data to be processed that is permitted to be processed among a dataset consisting of multiple data related to at least one attribute, obtains multiple range certification data to prove that when generalization processing is performed on the attribute values of the data to be processed, the attribute values before processing fall within a range of generalized attribute values, generates a digital signature for each of the multiple range certification data, and transmits the dataset, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least some of the multiple data.

[0015] In addition, the data processing method disclosed herein performs processing to perform generalization processing on target data for which processing is permitted from a dataset provided by a data providing device that provides a dataset consisting of multiple data related to at least one attribute, and uses the target data before processing and the target data after processing to process a sanitized signature generated by the data providing device for the target data for which processing is permitted, allowing arbitrary generalization processing, and for each of the target data for which generalization processing has been performed, selects range certification data for proving that the attribute value before processing falls within a range of generalized attribute values, from the multiple range certification data acquired by the data providing device, the range certification data corresponding to the range of generalized attribute values, and transmits the dataset processed for the target data for which processing has been performed, the processed sanitized signature, the range certification data selected for each of the target data for which processing has been performed, and a digital signature generated by the data providing device corresponding to the range certification data to a data receiving device that receives the dataset in which some data has been processed.

[0016] In addition, the data receiving method disclosed herein verifies a data set obtained by a data processing device from data to be processed that is permitted to be processed and that is provided by a data providing device that provides a data set consisting of multiple data related to at least one attribute, and a sanitized signature obtained by the data processing device from a sanitized signature generated by the data providing device for the data to be processed and that enables arbitrary generalization processing, and verifies the digital signature corresponding to the range certification data selected by the data processing device from among the multiple range certification data obtained by the data providing device, which is range certification data for proving that the attribute values before processing for each of the data to be processed that has been generalized fall within a range of generalized attribute values, and verifies the range certification data selected by the data processing device.

[0017] In addition, a first program according to the present disclosure causes a computer to execute the following steps: generating a sanitized signature that enables arbitrary generalization of target data that is permitted to be processed among a dataset consisting of multiple data related to at least one attribute; obtaining multiple range certification data to prove that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the target data; generating a digital signature for each of the multiple range certification data; and transmitting the dataset, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least some of the multiple data.

[0018] In addition, a second program according to the present disclosure causes a computer to execute the following steps: performing processing to perform generalization processing on target data for which processing is permitted among a dataset provided by a data providing device that provides a dataset consisting of multiple data related to at least one attribute; using the target data before processing and the target data after processing, performing processing on a sanitized signature generated by the data providing device for the target data for which processing is permitted, which enables arbitrary generalization processing; selecting range certification data for each of the target data for which generalization processing has been performed, the range certification data being for proving that the attribute value before processing falls within a range of generalized attribute values, from among the multiple range certification data acquired by the data providing device, the range certification data corresponding to the range of generalized attribute values; and transmitting the dataset for which processing has been performed on the target data for which processing has been performed, the processed sanitized signature, the range certification data selected for each of the target data for which processing has been performed, and a digital signature generated by the data providing device and corresponding to the range certification data to a data receiving device that receives the dataset in which some data has been processed.

[0019] In addition, a third program according to the present disclosure causes a computer to execute the following steps: verifying a data set obtained by a data processing device from data to be processed that is permitted to be processed and that is provided by a data providing device that provides a data set consisting of multiple data related to at least one attribute; and a sanitized signature obtained by the data processing device from a sanitized signature generated by the data providing device for the data to be processed and that enables arbitrary generalization processing; verifying a digital signature corresponding to range certification data selected by the data processing device from among the multiple range certification data acquired by the data providing device, which is range certification data for proving that the attribute values before processing for each of the data to be processed that has been generalized fall within a range of generalized attribute values; and verifying the range certification data selected by the data processing device. [Effects of the Invention]

[0020] According to the present disclosure, it is possible to provide a system, an apparatus, a method, and a program that can process data appropriately and efficiently. [Brief explanation of the drawings]

[0021] [Figure 1] FIG. 10 is a diagram for explaining a comparative example. [Figure 2] 1 is a diagram illustrating a configuration of an information processing system according to a first embodiment. [Figure 3] FIG. 1 is a diagram illustrating a configuration of a data providing device according to a first embodiment. [Figure 4] FIG. 1 is a diagram illustrating a configuration of a data processing device according to a first embodiment. [Figure 5] FIG. 2 is a diagram illustrating a configuration of a data receiving device according to the first embodiment. [Figure 6] 10 is a flowchart illustrating an information processing method executed by the information processing system according to the second embodiment. [Figure 7]10 is a flowchart showing a data providing process executed by the data providing device according to the second embodiment; [Figure 8] FIG. 10 is a diagram illustrating a data set according to the second embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of a non-interactive zero-knowledge proof algorithm used for generating range proof data by the range proof acquisition unit according to the second embodiment. [Figure 10] 10 is a flowchart showing a data processing process executed by a data processing device according to a second embodiment. [Figure 11] 10 is a flowchart showing a data receiving process executed by the data receiving device according to the second embodiment. [Figure 12] FIG. 1 is a block diagram illustrating an example of the hardware configuration of a calculation processing device capable of realizing an apparatus and a system according to each embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0022] (Outline of this embodiment) Before describing the present embodiment, an outline of the present embodiment will be described. Note that, although the present embodiment will be described below, the following embodiment does not limit the invention according to the claims. Also, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention. Also, in the following description, the indexes (alphabetical letters) used are not necessarily common throughout this specification.

[0023] First, the basic data flow involved in signature verification with anonymization will be described. For example, original data (dataset; plaintext) consists of one or more records. A record is a unit of data collection. If the original data is medical data, a record contains one or more pieces of data related to a patient. For example, the original data consists of one or more attributes. An attribute indicates the type of data. Attributes include, for example, the name, address, age, and gender corresponding to each record. For example, the original data may be organized in a table format having rows and columns. In this case, each row corresponds to a record, and each column corresponds to an attribute. Each piece of data corresponding to each cell in the table format has an attribute value corresponding to the attribute. If the attribute is "address," the attribute value may indicate, for example, "Tokyo," "Kanagawa," and "Osaka." If the attribute is "age," the attribute value may indicate, for example, "25 years old," "34 years old," and "43 years old."

[0024] In addition, the data provider who provides the original data (data set) creates a signature (electronic signature; digital signature) for the original data using random numbers, and sends the original data and signature to the data processor. The data processor processes (anonymizes) the original data, and sends the processed data and signature to the data recipient. One example of processing (anonymization) is "generalization." "Generalization" is processing that generalizes (abstracts) attribute values. The data recipient (data verifier) verifies the signature using the processed data and signature, and verifies the legitimacy of the processed data. The data recipient can utilize the processed data, whose legitimacy has been verified.

[0025] Before describing this embodiment, a comparative example will be described. In the technology disclosed in Patent Document 1, in the patient data record extension process, each value of a group of abstraction patterns (such as a generalized hierarchical tree) that are replacement candidates must be added to the patient data. Thus, in Patent Document 1, the data provider must specify rules for abstraction (generalization), such as the group of abstraction patterns. Therefore, in Patent Document 1, the flexibility of data processing by the data processor may be reduced. Furthermore, if the data processor attempts to achieve flexibility in processing in Patent Document 1, the number of patterns in the group of abstraction patterns increases, which may increase the computational load. Therefore, the technology disclosed in Patent Document 1 may not be able to perform processing efficiently. Note that, in the technology disclosed in Patent Document 1, signature verification fails unless the data processor processes the data in accordance with the generalization rules. In contrast, in the technology disclosed in Non-Patent Document 1, a sanitized signature using a chameleon hash function allows the data processor to perform any generalization processing.

[0026] FIG. 1 is a diagram for explaining a comparative example. FIG. 1 is a diagram for explaining a case where a sanitized signature that allows arbitrary processing is performed. FIG. 1 shows an example of processing a dataset having columns of two attributes, the attribute "name" and the attribute "age". A dataset D1, which is original data, is provided from a data provider to a data processor. In the dataset D1 illustrated in FIG. 1, in the record of the name "AA" in the first row, the attribute value of the attribute "age" is "43". In addition, in the record of the name "BB" in the second row, the attribute value of the attribute "age" is "38". In addition, in the record of the name "CC" in the third row, the attribute value of the attribute "age" is "31".

[0027] In the first record, the data processor deletes (anonymizes) the attribute value "AA" from the attribute "Name" and generalizes (anonymizes) the attribute value "43" from the attribute "Age" to the attribute value "40s." In the second record, the data processor deletes (anonymizes) the attribute value "BB" from the attribute "Name" and generalizes (anonymizes) the attribute value "38" from the attribute "Age" to the attribute value "30s." In the third record, the data processor deletes (anonymizes) the attribute value "CC" from the attribute "Name" and generalizes (anonymizes) the attribute value "31" from the attribute "Age" to the attribute value "30s." In this way, the data processor generates anonymized data D2 and sends it to the data recipient.

[0028] In the example shown in Figure 1, the attribute value of the attribute "age" is generalized. If a sanitized signature that allows arbitrary generalization is applied, the data processor can generalize the attribute value as desired. Therefore, it may not be possible to guarantee that the attribute value before processing actually falls within the range of the generalized attribute value after processing. For example, in the record in the first row, the attribute value of the attribute "age" is generalized to "40s," but it may not be possible to guarantee that the attribute value before processing was actually between 40 and 49 years old. For example, if the attribute value before processing was "35" and the data processor changed the attribute value to "40s," the data recipient may not be able to confirm that the original attribute value was not "40s."

[0029] In contrast, as described below, the system according to this embodiment is configured so that a data provider acquires multiple range certification data for proving that pre-processing attribute values fall within a generalized attribute value range. The system according to this embodiment is also configured so that a data processor selects range certification data corresponding to the generalized attribute value range. The system is also configured so that a data recipient performs verification using the selected range certification data. Therefore, this embodiment enables efficient processing while appropriately processing data.

[0030] (Embodiment 1) Hereinafter, embodiments will be described with reference to the drawings. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. In addition, the same elements in each drawing are designated by the same reference numerals, and duplicate explanations have been omitted as necessary.

[0031] FIG. 2 is a diagram showing the configuration of an information processing system 10 according to the first embodiment. The information processing system 10 includes a data providing device 100, a data processing device 200, and a data receiving device 300. The data providing device 100, the data processing device 200, and the data receiving device 300 are physically separate, but may be integrated. The data providing device 100, the data processing device 200, and the data receiving device 300 are communicably connected to each other via wired or wireless communication. The data providing device 100 may be managed by the data provider described above. The data processing device 200 may be managed by the data processor described above. The data receiving device 300 may be managed by the data recipient described above.

[0032] The information processing system 10 generates a signature for data (data set) provided by the above-mentioned device, processes (anonymizes) at least a portion of the data, and verifies the signature for the data set with the processed portion of the data. Details will be described later. Note that the information processing system 10 can also function as a digital signature system (signature system or electronic signature system) for issuing a digital signature (electronic signature), a data processing system for processing data, or a signature verification system (verification system) for verifying a signature.

[0033] The data providing device 100 is configured to provide a data set consisting of a plurality of data relating to at least one attribute. The data processing device 200 is configured to process at least a portion of the plurality of data. The data receiving device 300 is configured to receive a data set in which a portion of the data has been processed. Details will be described later.

[0034] FIG. 3 is a diagram showing the configuration of the data providing device 100 according to the first embodiment. The data providing device 100 has, as its components, a sanitized signature generation unit 120, a range proof acquisition unit 130, a signature generation unit 140, and a transmission unit 150. The sanitized signature generation unit 120 functions as a sanitized signature generation means (first signature generation means). The range proof acquisition unit 130 functions as a range proof acquisition means. The signature generation unit 140 functions as a signature generation means (second signature generation means; range proof signature generation means). The transmission unit 150 functions as a transmission means (first transmission means).

[0035] The data providing device 100 receives a dataset composed of multiple data related to at least one attribute from a data provider. The data providing device 100 then provides the dataset. As described above, the dataset is composed of one or more records and one or more attributes. As described above, the dataset may be composed, for example, in a table format with rows and columns. Each row may correspond to a record, and each column may correspond to an attribute. The dataset may be, for example, medical data of multiple patients, but is not limited to this. The data providing device 100 also generates a sanitized signature, which is a digital signature that can be used to anonymize the provided data (dataset). The data providing device 100 can also function as a signature generation device (sanitized signature generation device) that generates a digital signature (electronic signature).

[0036] The data providing device 100 can be realized by an information processing device such as a computer. That is, the data providing device 100 has an arithmetic device such as a CPU (Central Processing Unit) and a storage device such as a memory or a disk. The data providing device 100 realizes each of the above components by, for example, having the arithmetic device execute a program stored in the storage device. This also applies to other embodiments described later.

[0037] The sanitizable signature generation unit 120 generates a sanitizable signature that allows arbitrary generalized processing of data that is permitted to be processed. Note that the sanitizable signature generation unit 120 may generate an unmodifiable signature for data that is not permitted to be processed. Note that the sanitizable signature is, for example, a sanitizable signature related to a digital signature to which a chameleon hash is applied, but is not limited to this. Specific processing by the sanitizable signature generation unit 120 will be described later.

[0038] The range proof acquisition unit 130 acquires multiple pieces of range proof data for proving that the attribute values before processing fall within the range of generalized attribute values when generalization processing is performed on the attribute values of the processing target data. The range proof acquisition unit 130 may generate multiple pieces of range proof data, but is not limited to this. The range proof acquisition unit 130 may acquire (receive) range proof data from another device, etc. Alternatively, the range proof acquisition unit 130 may acquire range proof data by inputting range proof data into the data providing device 100 through operation by a user (data provider). The range proof data is generated using, for example, a proof protocol based on zero-knowledge proof or a proof protocol based on non-interactive zero-knowledge proof, but is not limited to this. Specific processing by the range proof acquisition unit 130 will be described later.

[0039] The signature generation unit 140 generates a digital signature for each of the multiple range proof data. Specific processing by the signature generation unit 140 will be described later. The transmission unit 150 transmits the data set, the sanitized signature, the range proof data, and the digital signature corresponding to the range proof data to the data processing device 200. Specific processing by the transmission unit 150 will be described later. Note that the data providing device 100 may temporarily store the information to be transmitted before transmitting the information to the data processing device 200.

[0040] FIG. 4 is a diagram showing the configuration of the data processing device 200 according to the first embodiment. The data processing device 200 has, as its components, a processing unit 210, a sanitized signature processing unit 220, a range proof selection unit 230, and a transmission unit 240. The processing unit 210 functions as processing means. The sanitized signature processing unit 220 functions as sanitized signature processing means. The range proof selection unit 230 functions as range proof selection means. The transmission unit 240 functions as transmission means (second transmission means).

[0041] The data processing device 200 acquires (receives) information including a data set, a sanitized signature, range certification data, and a digital signature from the data providing device 100. Then, the data processing device 200 processes at least a portion of the data of the data set provided by the data providing device 100. Note that the data processing device 200 can also function as an anonymization device that anonymizes data (anonymization processing).

[0042] The data processing device 200 can be realized by, for example, an information processing device such as a computer. That is, the data processing device 200 has an arithmetic unit such as a CPU and a storage device such as a memory or a disk. The data processing device 200 realizes each of the above components by, for example, having the arithmetic unit execute a program stored in the storage device. This also applies to other embodiments described below.

[0043] The processing unit 210 performs processing to generalize (anonymize) the processing target data. Specific processing by the processing unit 210 will be described later. The sanitized signature processing unit 220 processes the sanitized signature generated for the processing target data by the data providing device 100, using the processing target data before processing and the processing target data after processing. Specific processing by the sanitized signature processing unit 220 will be described later.

[0044] The range proof selection unit 230 selects, for each piece of processing target data that has been generalized, range proof data that corresponds to the range of the generalized attribute value from among the plurality of range proof data. Specific processing by the range proof selection unit 230 will be described later. The transmission unit 240 transmits to the data receiving device 300 the data set that has been processed for the processing target data, the processed sanitized signature, the range proof data selected for each piece of processing target data, and the digital signature that corresponds to the range proof data. Specific processing by the transmission unit 240 will be described later. The data processing device 200 may temporarily store the information to be transmitted before transmitting the information to the data receiving device 300.

[0045] FIG. 5 is a diagram showing the configuration of the data receiving device 300 according to the first embodiment. The data receiving device 300 has, as its components, a sanitized signature verification unit 310, a digital signature verification unit 320, and a range proof verification unit 330. The sanitized signature verification unit 310 functions as a sanitized signature verification means (first verification means). The digital signature verification unit 320 functions as a digital signature verification means (second verification means; range proof signature verification means). The range proof verification unit 330 functions as a range proof verification means (third verification means).

[0046] The data receiving device 300 acquires (receives) the processed data set, the processed sanitized signature, the selected range proof data, and the digital signature corresponding to the range proof data from the data processing device 200. Then, the data receiving device 300 verifies the signature for the data set in which some of the data has been processed. Note that the data receiving device 300 can also function as a signature verification device (verification device) that verifies the signature.

[0047] The data receiving device 300 can be realized by an information processing device such as a computer. In other words, the data receiving device 300 has an arithmetic unit such as a CPU and a storage device such as a memory or a disk. The data receiving device 300 realizes each of the above components by, for example, having the arithmetic unit execute a program stored in the storage device. This also applies to the other embodiments described below.

[0048] The sanitized signature verification unit 310 verifies the data set obtained by processing the data to be processed and the sanitized signature processed by the data processing device 200. Specific processing by the sanitized signature verification unit 310 will be described later. The digital signature verification unit 320 verifies the digital signature corresponding to the range proof data selected by the data processing device 200 from the multiple range proof data acquired by the data providing device 100. Specific processing by the digital signature verification unit 320 will be described later. The range proof verification unit 330 verifies the range proof data selected by the data processing device 200. Specific processing by the range proof verification unit 330 will be described later.

[0049] As described above, in the information processing system 10 according to the first embodiment, the data providing device 100 is configured to acquire a plurality of range proof data for proving that the pre-processing attribute value falls within the range of generalized attribute values. Furthermore, the data processing device 200 is configured to select range proof data corresponding to the range of the generalized attribute value. This eliminates the need for the data provider to specify rules for abstraction (generalization), as in Patent Document 1. Furthermore, by performing a sanitized signature that allows arbitrary generalization processing, flexibility in data processing can be achieved. Furthermore, even when a sanitized signature is performed, the data receiving device 300 can verify whether the original data has been appropriately generalized. Therefore, in the first embodiment, data can be appropriately processed.

[0050] Furthermore, as described above, when attempting to achieve processing flexibility in Patent Document 1, the number of abstraction patterns increases. As a result, the number of hash value calculations increases according to the number of patterns, which may increase the calculation load. In contrast, in the first embodiment, the calculation load is prevented from increasing according to the number of generalization processing patterns. Therefore, in the first embodiment, it is possible to perform processing efficiently. Therefore, the information processing system 10 according to the first embodiment is able to perform processing efficiently while processing data appropriately.

[0051] The range certification acquisition unit 130 may generate range certification data for each of a plurality of candidates (range candidates) for the range that includes the attribute value of the data to be processed. In this case, the range certification selection unit 230 may select range certification data for the candidate (range candidate) that corresponds to the generalized range of the attribute value from the plurality of generated range certification data. Details will be described later.

[0052] Furthermore, the signature generation unit 140 may generate a digital signature for a first set (candidate / proof set), which is a set of the above-mentioned candidates (range candidates) and range proof data corresponding to the candidates. In this case, the transmission unit 150 may transmit the first set and a digital signature corresponding to the first set to the data processing device 200. Furthermore, the range proof selection unit 230 may select at least one first set corresponding to a generalized range of attribute values from among multiple first sets. Furthermore, the transmission unit 240 may transmit the selected first set and a digital signature corresponding to the selected first set to the data receiving device 300. Furthermore, the digital signature verification unit 320 may verify the first set and the digital signature corresponding to the selected first set. Then, the range proof verification unit 330 may verify the range proof data using the first set. This will be described in detail later. Furthermore, the first set may include identification information of the corresponding processing target data. This will be described in detail later.

[0053] If a first set having candidates whose range matches the generalized attribute value range exists, the range proof selection unit 230 may select the first set. On the other hand, if a first set having candidates whose range matches the generalized attribute value range does not exist, the range proof selection unit 230 may select a second set (range proof set) that is a combination of multiple first sets. That is, if the generalized attribute value range is expressed by a combination of multiple candidates, the range proof selection unit 230 may select a second set that is a combination of first sets corresponding to the multiple candidates. Furthermore, the transmission unit 240 may transmit the selected second set and a digital signature corresponding to the selected second set to the data receiving device. Furthermore, the digital signature verification unit 320 may verify the selected second set and the digital signature corresponding to the second set. Then, the range proof verification unit 330 may verify the range proof data using the selected second set. This will be described in detail later.

[0054] Furthermore, the range proof acquisition unit 130 may generate range proof data using a proof protocol based on zero-knowledge proof. In this case, the range proof verification unit 330 may verify the range proof data using the proof protocol based on zero-knowledge proof. Furthermore, the range proof acquisition unit 130 may generate range proof data using a proof protocol based on non-interactive zero-knowledge proof. In this case, the range proof verification unit 330 may verify the range proof data using the proof protocol based on non-interactive zero-knowledge proof. This will be described in more detail later.

[0055] (Embodiment 2) Next, a second embodiment will be described. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. Furthermore, in each drawing, the same elements are given the same reference numerals, and repeated explanations are omitted as necessary. Note that the system configuration according to the second embodiment is substantially the same as the system configuration according to the first embodiment, and therefore explanations thereof will be omitted. In other words, the information processing system 10 according to the second embodiment has a data providing device 100, a data processing device 200, and a data receiving device 300. The second embodiment corresponds to a more specific version of the configuration according to the first embodiment described above.

[0056] 6 is a flowchart showing an information processing method executed by the information processing system 10 according to the second embodiment. The information processing method executed by the information processing system 10 can also be realized as a digital signature method (signature method or electronic signature method), a data processing system, or a signature verification method (verification method).

[0057] The information processing system 10 performs a data providing process (step S100). Specifically, the data providing device 100 of the information processing system 10 provides a data set consisting of a plurality of data relating to at least one attribute. At this time, the data providing device 100 performs a signature generation process on the provided data (data set) as described above. The process of S100 will be described in detail later.

[0058] The information processing system 10 performs data processing (step S200). Specifically, the data processing device 200 of the information processing system 10 acquires information including a data set, a sanitized signature, and a digital signature (range certification signature) from the data providing device 100. Then, the data processing device 200 processes at least a portion of the multiple data in the data set. Details of the processing of S200 will be described later.

[0059] The information processing system 10 performs a data receiving process (step S300). Specifically, the data receiving device 300 of the information processing system 10 acquires a data set in which some of the data has been processed, a sanitized signature, and a digital signature (range proof signature) from the data processing device 200. Then, the data receiving device 300 performs a verification process. Details of the process of S300 will be described later.

[0060] <Signature generation process> Fig. 7 is a flowchart showing the data providing process (S100) executed by the data providing device 100 according to the second embodiment. The flowchart in Fig. 7 shows a data providing method, but it can also be said to show a digital signature method (signature method or electronic signature method).

[0061] In the data providing device 100, the sanitizable signature generation unit 120 generates a sanitizable signature (step S110). Specifically, the sanitizable signature generation unit 120 generates a sanitizable signature for a data set (plain text) that is the original data. More specifically, as described above, the sanitizable signature generation unit 120 may generate a sanitizable signature that allows arbitrary generalized processing for processing target data (cells) that are permitted to be processed. On the other hand, the sanitizable signature generation unit 120 may generate an unprocessable signature for data (cells) that are not permitted to be processed. In this case, the sanitizable signature generation unit 120 may generate a signature (sanitizable signature) using a hash value generated for the data and a private key using an RSA signature method, a DSA (Digital Signature Algorithm) signature method, or the like.

[0062] FIG. 8 is a diagram illustrating a data set Da1 according to the second embodiment. The data set Da1 illustrated in FIG. 8 is configured in a table format with M rows and N columns. Here, the column of attribute #1 is a column that is not to be processed. On the other hand, the column of attribute #2 is a column that is to be processed (generalized). In this case, the sanitizable signature generation unit 120 may generate an unprocessable signature for each data item of attribute #1 (attribute values #11 to #M1). On the other hand, the sanitizable signature generation unit 120 may generate a sanitizable signature for each data item of attribute #2 (attribute values #12 to #M2) that allows generalization. The sanitizable signature can be realized by any signature algorithm that allows generalization. For example, the sanitizable signature generation unit 120 may generate a sanitizable signature using a private key for normal signatures, a public key for sanitizable signatures, plaintext (data to be processed), and a random number.

[0063] Furthermore, for example, the sanitizable signature generation unit 120 may generate a sanitizable signature by applying a signature algorithm (chameleon hash-based sanitizable signature) that combines a chameleon hash and a digital signature, as disclosed in Non-Patent Document 1. For example, the sanitizable signature generation unit 120 may calculate a hash value (message digest) for each row using a general hash function (SHA256, etc.) for attribute values (e.g., attribute value #11, etc.) of columns (attributes) that are not to be processed. Furthermore, the sanitizable signature generation unit 120 may calculate a hash value for each row using a chameleon hash function and a public key for sanitizable signatures for attribute values (e.g., attribute value #12, etc.) of columns (attributes) that are to be processed.

[0064] In this case, the sanitizable signature generation unit 120 may generate (h, r) using the function hash1(pk, m). Note that the function hash1() is a Chameleon hash function, pk is a public key for the Chameleon hash-based sanitizable signature, and m is plaintext (the data to be processed before processing). Also, h is a hash value, and r is a random number corresponding to h.

[0065] Furthermore, the sanitizable signature generation unit 120 may calculate a hash value for a data string that concatenates hash values for the attribute values of each attribute calculated for each row. That is, the sanitizable signature generation unit 120 may calculate a hash value for a data string that concatenates hash values for the attribute values of the attributes to be processed and hash values for the attribute values of the attributes not to be processed. Then, the sanitizable signature generation unit 120 may generate a sanitizable signature for the data set (data set signature) using the calculated hash value and a private key for signature generation.

[0066] The range certification acquisition unit 130 acquires range candidates (step S112). Specifically, the range certification acquisition unit 130 acquires multiple candidates (range candidates) for ranges that include the attribute values of the data to be processed. The range candidates may be generated by the range certification acquisition unit 130, or may be generated by another device and acquired (received) from that device. Alternatively, the range candidates may be arbitrarily determined by the user (data provider).

[0067] Assume that attribute value x in attribute a (corresponding to each column of data set Da1) of record r (corresponding to each row of data set Da1) is the target of generalization processing. Note that r and a correspond to the identification information of the data to be processed. In this case, the range proof acquisition unit 130 searches for range candidates R1,...,R that include attribute value x. n In other words, we obtain the candidate ranges R1, ,R n Each of the range proof obtaining units 130 includes the attribute value x. Then, the range proof obtaining unit 130 obtains range candidates for all attribute values of all attributes that are the targets of processing for generalization.

[0068] 8, for example, as a first specific example, the range proof acquisition unit 130 acquires candidates for a range that includes the attribute value #12. For example, if the attribute #2 is "age" and the attribute value #12 is "21" (x=21), the range proof acquisition unit 130 may acquire the following R1 to R4 for the attribute value #12. R1: 20≦x≦29 (for example, "in their 20s") R2: 20≦x≦40 (e.g., meaning "young people") R3: 20≦x≦100 (e.g., meaning "adult") R4: 19≦x≦22 (e.g., "university student")

[0069] Also, for example, as a second specific example, suppose that attribute #3 is the column to be processed, attribute #3 is "address", and attribute value #13 is "Tokyo" (x="Tokyo") In this case, range proof acquisition unit 130 may acquire the following R1 to R4 for attribute value #13. R1: "Kanto" R2: "South Kanto" R3: "East Japan" R4: "Japan"

[0070] The range proof acquisition unit 130 generates a range proof (step S120). Specifically, the range proof acquisition unit 130 generates a range proof by using the acquired multiple range candidates R1,...,R n Generate corresponding range proof data σ. Here, the range candidate R i The range proof data σ corresponding to i Even if the verifier does not know the attribute value x, the attribute value x is within the range candidate R i The range proof data σ i It is data (some value) that can be verified using

[0071] For example, the range proof acquisition unit 130 calculates a range candidate R for the attribute value x using the following formula (1): i Range proof data σ corresponding to (i=1, ,n) i Generate.

number

[0072] In formula (1), pp is a public parameter (a parameter that can be made public). Gen() is a parameter that is used when x is in R i Range proof data σ that proves that it is included in iThe function Gen() outputs pp, x, and R i With input, σ i Gen() is a function that outputs the following. Gen() may be a function in any certification protocol. Note that the function Gen() may be determined appropriately depending on the algorithm of the certification protocol to be applied.

[0073] For example, Gen() may be a function in a proof protocol based on any zero-knowledge proof. In this case, the range proof acquisition unit 130 generates the range proof data σ using the proof protocol based on the zero-knowledge proof. Furthermore, Gen() may be a function in a proof protocol based on any zero-knowledge interactive proof (ZKIP). In this case, the range proof acquisition unit 130 generates the range proof data σ using the proof protocol based on the zero-knowledge interactive proof. The proof protocol based on the zero-knowledge interactive proof may use an algorithm such as that disclosed in Non-Patent Document 2, for example.

[0074] Gen() may also be a function in a proof protocol based on any non-interactive zero-knowledge proof (NIZK). In this case, the range proof acquisition unit 130 generates the range proof data σ using a proof protocol based on non-interactive zero-knowledge proof. The proof protocol based on non-interactive zero-knowledge proof may use an algorithm such as a CFT proof or a Boudot proof as disclosed in Non-Patent Document 3, or a Bulletproof. Gen() may also be a function in any proof protocol other than zero-knowledge proof. In this case, the range proof acquisition unit 130 generates the range proof data σ using a proof protocol other than zero-knowledge proof. As the proof protocol other than zero-knowledge proof, for example, argument, which is a proof system based on computational soundness, may be used.

[0075] Fig. 9 is a diagram illustrating an algorithm of a non-interactive zero-knowledge proof used for generating range proof data by the range proof acquisition unit 130 according to the second embodiment. Note that Fig. 9 is merely an example, and the algorithm used for generating a range proof is not limited to the one illustrated in Fig. 9. Fig. 9 shows the algorithm of the CFT proof mentioned above. Fig. 9 shows the algorithm of the CFT proof when a certain value x is -2 t+l b≦x≦2 t+l Figure 9 shows a non-interactive zero-knowledge proof that x is within the range of b. t+l b≦x≦2 t+l This shows an algorithm that allows Bob to verify that x is within the range of b by simply sending the proof to Bob without letting Bob know x. Here, t, l, and s are security parameters, n is a large composite number (that is difficult to factorize), and H is a hash function that outputs 2t-bits. In Figure 9, the function Gen() corresponds to the algorithm by which Alice calculates (C, D1, D2) in steps 1 to 3. The calculated data (C, D1, D2) corresponds to the range proof data σ.

[0076] The signature generation unit 140 generates a signature for the range proof data (step S122). Specifically, the signature generation unit 140 generates a signature for the range candidate R i and its range candidate R i Range proof data for σ i A digital signature (range proof signature) is generated for a candidate / proof set (first set) that is a set of r, a, and the target data (r, a). More specifically, the signature generation unit 140 may generate a digital signature for a candidate / proof set that includes identification information of the target data. That is, the signature generation unit 140 generates a digital signature for a candidate / proof set that includes identification information of the target data (r, a) that is a range candidate R i and range proof data σ i The candidate / proof set (r, a, R i ,σ i ) for which the digital signature δ_(r,a,R i ,σ i ) is generated. This allows us to determine which attribute value of which record is in the range candidate R iProof that the range of the data σ i ) is generated by the data provider (data providing device 100).

[0077] The signature generation unit 140 may generate a digital signature (range proof signature) using a general signature algorithm other than the sanitized signature. For example, the signature generation unit 140 generates a candidate / proof set (r, a, R i ,σ i ) and the private key. That is, the signature generator 140 may generate a digital signature by using, for example, a hash value generated for a candidate / proof set (r, a, R i ,σ i ) Concatenated data (r||a||R i ||σ i ) may be calculated using a general hash function. Then, the signature generation unit 140 uses the private key to generate a digital signature δ_(r, a, R i ,σ i ) may be generated.

[0078] The signature generation unit 140 generates a digital signature δ_(r, a, R i ,σ i ) for attribute value #12 in the example of FIG. 8, the signature generation unit 140 generates δ_(1,2,R1,σ1), δ_(1,2,R2,σ2), . . . , δ_(1,2,R n ,σ n ) for attribute value #22. Similarly, the signature generation unit 140 generates δ_(2,2,R1,σ1), δ_(2,2,R2,σ2), . . . , δ_(2,2,R n ,σ n )

[0079] That is, the signature generating unit 140 generates a pair of a candidate / proof set and a corresponding digital signature for each cell (processing target data) of the processing target attribute, as shown in the following formula (2).

number

[0080] In equation (2), C j’ corresponds to the last column among the columns corresponding to the attributes to be processed for generalization. In the example of Figure 8, if attribute #N is the attribute to be processed, C j’ corresponds to attribute #N. Also, row max corresponds to the record in the last row of the dataset. In the example in Figure 8, max corresponds to row #M.

[0081] The signature generation unit 140 generates a digital signature δ_(r, a, R i ,σ i ) is generated. This is to enable the selection of a range proof set (second set), which is a combination of multiple candidate / proof sets, in the processing by the data processing device 200, which will be described later. That is, when generating a sanitizable signature, a hash value is calculated for a hash value calculated by a general hash function or a chameleon hash function and a hash value calculated for the candidate / proof set, and a signature is generated for the hash value. In this way, the data processing device 200 will not be able to select a range proof set (multiple range proof data). Therefore, the signature generation unit 140 generates a digital signature δ_(r,a,R i ,σ i )

[0082] The sending unit 150 sends information to the data processing device 200 (step S124). Specifically, the sending unit 150 sends the data set Da1, the sanitized signature (data set signature), the candidate / proof set, and the digital signature (range proof signature). At this time, the sending unit 150 sends a set of pairs of the candidate / proof set and the range proof signature {(r, a, R i ,σ i ),δ_(r,a,R i ,σ i )} to the data processing device 200. Before transmitting the information to the data processing device 200, the data providing device 100 may temporarily store the information to be transmitted.

[0083] <Data processing> Fig. 10 is a flowchart showing the data processing (S200) executed by the data processing device 200 according to the second embodiment. Fig. 10 shows a data processing method. In the data processing device 200, the processor 210 performs processing for generalizing (anonymizing) the data to be processed corresponding to the attribute to be processed (step S202). The processor 210 may perform generalizing processing on each attribute value in the column of the attribute to be generalized, according to an operation by a data processor.

[0084] As in the first specific example in the example of FIG. 8 above, suppose attribute #2 is "age" and attribute value #12 is "21." Then, suppose the data processor generalizes attribute value #12="21" to "20s (20-29 years old)." In this case, the processor 210 changes (processes) attribute value #12 to a value indicating "20s (20-29 years old)." Alternatively, for example, if the data processor generalizes attribute value #12="21" to "20-22 years old," the processor 210 changes (processes) attribute value #12 to a value indicating "20-22 years old."

[0085] Furthermore, as in the second specific example in the example of FIG. 8 above, suppose that attribute #3 is the column to be processed, attribute #3 is "address," and attribute value #13 is "Tokyo." Then, suppose that the data processor generalizes attribute value #13="Tokyo" to "Kanto." In this case, the processor 210 changes (processes) attribute value #13 to a value indicating "Kanto." Alternatively, for example, suppose that the data processor generalizes attribute value #13="Tokyo" to "Japan." In this case, the processor 210 changes (processes) attribute value #13 to a value indicating "Japan."

[0086] In this manner, the processor 210 changes (processes) the attribute value x of the attribute a of the record r to the attribute value x'. The range corresponding to this processed attribute value x' is defined as R'. In the above example, when the attribute value #12="21" is generalized to "20s (20-29 years old)", x=21 and x' is a value indicating "20s (20-29 years old)". The range R' corresponding to x' is "20≦x≦29". When the attribute value #12="21" is generalized to "20-22 years old", x=21 and x' is a value indicating "20-22 years old". The range R' corresponding to x' is "20≦x≦22".

[0087] The sanitizable signature processing unit 220 performs processing on the sanitizable signature (step S210). Specifically, as described above, the sanitizable signature processing unit 220 performs processing on the sanitizable signature using the processing target data before processing and the processing target data after processing. More specifically, the sanitizable signature processing unit 220 may process the sanitizable signature using the processing target data before processing, the processing target data after processing, the sanitizable signature generated by the data providing device 100, a public key for normal signatures, and a private key corresponding to the public key for sanitizable signatures. This makes it possible to maintain the validity of the signature even if the processing target data is processed. In other words, the sanitizable signature processing unit 220 processes the sanitizable signature so that verification is successful when the sanitizable signature is verified by the data recipient (data receiving device 300).

[0088] Furthermore, for example, when a sanitizable signature is generated using Chameleon hash-based sanitizable signature processing, the sanitizable signature processing unit 220 may process the sanitizable signature using a private key corresponding to the public key used to generate the sanitizable signature. By using this private key, the sanitizable signature processing unit 220 can obtain a collision between the processed target data (attribute value) and the hash value calculated for the target data (attribute value) before processing. This allows the data processing device 200 to process the target data while maintaining the validity of the signature.

[0089] In this case, the sanitizable signature processing unit 220 may generate a random number r' using the function adopt(sk, m, m', r). Here, sk is a private key corresponding to the public key pk used when generating a sanitizable signature using Chameleon hash-based sanitizable signature. Also, m' is the processed data (attribute value). Also, r' is a random number corresponding to m'. Here, h = hash2(pk, m, r) = hash2(pk, m', r'). hash2() will be described later.

[0090] The range proof selection unit 230 selects range proof data corresponding to the range of the generalized attribute value for each of the processing target data that has been generalized (step S220). Specifically, the range proof selection unit 230 first selects a set of pairs of candidate / proof sets and range proof signatures {(r, a, R i ,σ i ),δ_(r,a,R i ,σ i )}.

[0091] The range proof selector 230 selects a candidate / proof set (r, a, R i ,σ i ), the range R' (= R i’ ) with candidate / proof set (r, a, R i’ ,σ i’ Determine whether there exists a candidate / proof set (r, a, R) with a candidate range R that matches the range R'.i’ ,σ i’ ) exists, that is, R'=R i’ R i’ If there exists a candidate / proof set (r, a, R i’ ,σ i’ ) to obtain the range proof σ i’ Furthermore, the range proof selector 230 selects (extracts) a digital signature (range proof signature) corresponding to the selected candidate / proof set.

[0092] As in the first specific example described above, when attribute #2 is "age" and attribute value #12 is "21", it is assumed that R1: 20≦x≦29, R2: 20≦x≦40, R3: 20≦x≦100, and R4: 19≦x≦22 are obtained. Then, it is assumed that attribute value #12="21" is generalized to "20-29 years old". In this case, R' corresponding to attribute value x' after processing is "20≦x≦29". Therefore, for attribute value #12, R'=R1. Therefore, for attribute value #12, the range proof selection unit 230 selects a candidate / proof set (r, a, R) corresponding to range candidate R1 for attribute value #12. i’ ,σ i’ ) (=(1,2,R1,σ1)). Then, the range proof selector 230 selects (extracts) the range proof signature δ_(1,2,R1,σ1) corresponding to the selected candidate / proof set (1,2,R1,σ1).

[0093] On the other hand, the candidate / proof set (r, a, R) with a candidate range R that matches the range R' i’ ,σ i’ ), the range proof selector 230 determines whether the range R′ is expressed by a combination of multiple range candidates included in multiple candidate / proof sets. For example, the range proof selector 230 determines whether R′=R i ∩R j R such that i ,R j The set of {R i’} exists. In this case, R' is i ,R j It can be expressed by a combination of

[0094] When the range R' is expressed by a combination of multiple range candidates, the range proof selector 230 selects a combination of candidate / proof sets (second set; range proof set) corresponding to these multiple range candidates. That is, R' = R i ∩R j R such that i ,R j The set of {R i’} exists, the range proof selection unit 230 selects R i ,R j (r, a, R i’ ,σ i’ ) pair {(r,a,R i’ ,σ i’ )}={(r,a,R i ,σ i ),(r,a,R j ,σ j )}. This allows multiple range proofs σ i’ Furthermore, the range proof selection unit 230 selects (extracts) a digital signature (range proof signature) corresponding to the selected candidate / proof set. Note that the number of candidate / proof sets selected for a certain range R' is not limited to two, and may be three or more.

[0095] As in the first specific example described above, when attribute #2 is "age" and attribute value #12 is "21", it is assumed that R1: 20≦x≦29, R2: 20≦x≦40, R3: 20≦x≦100, and R4: 19≦x≦22 are obtained. Then, it is assumed that attribute value #12="21" is generalized to "20-22 years old". In this case, R' corresponding to attribute value x' after processing is "20≦x≦22". In this case, R' is expressed as, for example, R1∩R4. Therefore, for attribute value #12, the range proof selection unit 230 selects a pair of candidate / proof sets {(r, a, R i’ ,σ i’)}(={(1,2,R1,σ1),(1,2,R4,σ4)}. Then, the range proof selector 230 selects (extracts) range proof signatures δ_(1,2,R1,σ1), δ_(1,2,R4,σ4) corresponding to the selected candidate / proof sets (1,2,R1,σ1), (1,2,R4,σ4).

[0096] The sending unit 240 sends the information to the data receiving device 300 (step S222). Specifically, the sending unit 240 sends the data set obtained by processing the processing target data and the processed sanitized signature to the data receiving device 300. Furthermore, the sending unit 240 sends the candidate / proof set selected for each piece of processing target data and the digital signature (range proof signature) corresponding to the selected candidate / proof set. Note that the data processing device 200 may temporarily store the information to be sent before sending the information to the data receiving device 300.

[0097] At this time, the sending unit 240 generates a set of pairs of candidate / proof sets and range proof signatures {(r, a, R i ,σ i ),δ_(r,a,R i ,σ i )} may be transmitted to the data processing device 200 for each data (r, a) to be processed. i ,σ i ),δ_(r,a,R i ,σ i )} corresponds to the range proof set. Then, the sending unit 240 may send to the data processing device 200 a set of pairs of candidate / proof sets and range proof signatures for each processing target data (r, a) as shown in the following formula (3).

number

[0098] In this embodiment, the range proof selection unit 230 selects a range candidate R corresponding to the range R′. i and the corresponding range proof σ iand the range proof signature δ. In contrast, the technology disclosed in Patent Document 1 adds candidate replacement values to the target data in advance, and then replaces the candidate replacement values with hash values through hashing, an intermediate process in the signature generation process. In other words, Patent Document 1 generates a new hash value from a hash value. In this technology, when processing data, it is necessary to calculate hash values according to the number of candidate replacements, i.e., the number of abstraction patterns. Therefore, as the number of abstraction patterns increases, the amount of hash value calculation also increases, which may increase the processing load. In particular, since increasing the number of abstraction patterns is necessary to increase the flexibility of processing, an attempt to increase the processing load may increase. Therefore, the technology disclosed in Patent Document 1 may not be able to perform processing efficiently when attempting to achieve flexibility in processing.

[0099] On the other hand, in this embodiment, the data provider is configured to obtain multiple range certification data for proving that the attribute value before processing falls within the range of the generalized attribute value. The system according to this embodiment is configured so that the data processor selects range certification data corresponding to the range of the generalized attribute value. Therefore, in this embodiment, when processing data, a range candidate R corresponding to the range R' is selected. i and the corresponding range proof σ i and the range certification signature δ, the processing load does not increase even if the number of range candidates increases. Therefore, in this embodiment, it is possible to perform processing efficiently while realizing flexibility in processing.

[0100] <Verification process> Fig. 11 is a flowchart showing the data receiving process (S300) executed by the data receiving device 300 according to the second embodiment. The flowchart in Fig. 11 shows a data receiving method, but it can also be said to show a verification method (signature verification method).

[0101] In the data receiving device 300, the sanitizable signature verification unit 310 verifies the sanitizable signature (step S310). Specifically, the sanitizable signature verification unit 310 may verify the sanitizable signature using the sanitizable signature, a public key corresponding to the private key for normal signatures, a public key for sanitizable signatures, and the processed data set (data to be processed). For example, the sanitizable signature verification unit 310 may verify the sanitizable signature using a hash value generated for the processed data.

[0102] Furthermore, for example, when a sanitizable signature is generated using a Chameleon hash-based sanitizable signature, the sanitizable signature verification unit 310 may calculate a hash value (message digest) for each row using a general hash function (such as SHA256) for the attribute values (e.g., attribute value #11) of the columns (attributes) that are not to be processed. Furthermore, the sanitizable signature generation unit 120 may calculate a hash value for each row using a Chameleon hash function and a public key for the sanitizable signature for the attribute values (e.g., attribute value #12) of the columns (attributes) that are to be processed.

[0103] In this case, the sanitizable signature verification unit 310 may generate h' using the function hash2(pk, m', r'). Note that the function hash2() is a Chameleon hash function, pk is a public key for the Chameleon hash-based sanitizable signature, and m' is the processed data. Also, r' is a random number corresponding to m'. h' is a hash value corresponding to m'.

[0104] Furthermore, the sanitized signature verification unit 310 may calculate a hash value for a data string that concatenates hash values for the attribute values of each attribute calculated for each row. That is, the sanitized signature verification unit 310 may calculate a hash value for a data string that concatenates hash values for the attribute values after processing of the attribute to be processed and hash values for the attribute values of the attributes not to be processed. Then, the sanitized signature verification unit 310 may verify the signature from the calculated hash value and the sanitized signature transmitted from the data processing device 200, using a public key corresponding to the private key used for signature generation.

[0105] If the verification is successful, it is determined that the data processor has not illicitly altered the data set, and that the data passed from the data processor is based on the data of the data provider. On the other hand, if the verification is unsuccessful, it is determined that the data set has been illicitly altered by the data processor, or that the data set may contain false data other than that based on the data of the data provider. Note that if the data receiving device 300 fails to verify the sanitized signature in the processing of S310, it may not be necessary to perform the processing subsequent to S300 (S320, S330). In other words, the data receiving device 300 may perform the processing of S320 and S330 if the verification of the sanitized signature in the processing of S310 is successful.

[0106] The digital signature verification unit 320 verifies the digital signature (range proof signature) (step S320). Specifically, for each attribute a of the record r, the digital signature verification unit 320 verifies the digital signature (range proof signature) for each candidate / proof set selected by the data processing device 200 and transmitted to the data receiving device 300. More specifically, the digital signature verification unit 320 may verify the digital signature (range proof signature) using a verification algorithm such as the above-mentioned RSA or DSA. For example, the digital signature verification unit 320 verifies the digital signature (range proof signature) for each candidate / proof set (r, a, R i ,σ i ) hash value generated for the public key (verification key), and digital signature δ_(r,a,R i ,σ i ) to verify the signature. As a result, the digital signature verification unit 320 can verify whether the original attribute value x of the attribute a of the record r is within the range candidate R i Proof that it fits within (range proof data σ i ) is indeed generated by the data provider (data providing device 100).

[0107] For example, in the first specific example shown in FIG. 8, suppose that the attribute value #12="21" is generalized to "20s (20-29 years old)" in the data processing device 200. In this case, the digital signature verification unit 320 performs verification using the candidate / proof set (1, 2, R1, σ1) and the corresponding digital signature δ_(1, 2, R1, σ1). That is, the digital signature verification unit 320 performs verification on the first set (candidate / proof set) and the digital signature corresponding to the first set.

[0108] Also, for example, in the first specific example, suppose that the attribute value #12="21" is generalized to "20-22 years old" in the data processing device 200. In this case, the digital signature verification unit 320 performs verification using the candidate / proof set pairs (1,2,R1,σ1), (1,2,R4,σ4) and the corresponding digital signatures δ_(1,2,R1,σ1), δ_(1,2,R4,σ4). In other words, the digital signature verification unit 320 performs verification on the second pair (range proof set) and the digital signature corresponding to the second pair.

[0109] If the verification is successful, it is determined that the data processor has not tampered with the candidate / proof set (range proof data), and that the candidate / proof set (range proof data) passed by the data processor was provided by the data provider. On the other hand, if the verification fails, it is determined that the data processor may have tampered with the candidate / proof set (range proof data), or that the candidate / proof set (range proof data) may not have been provided by the data provider. Note that if the verification of the range proof signature fails, the data receiving device 300 does not need to perform the process of S330.

[0110] The range proof verification unit 330 verifies the range proof data (step S330). Specifically, for each attribute a of the record r, the range proof verification unit 330 verifies the range proof data σ for each candidate / proof set selected by the data processing device 200 and transmitted to the data receiving device 300. In other words, the range proof verification unit 330 uses the range proof data σ to verify that the original attribute value x corresponding to the attribute a of the record r is included in the range candidate R.

[0111] For example, the range proof verification unit 330 verifies that the original attribute value x is included in the range candidate R using the following formula (4).

number

[0112] In equation (4), Verify() is a function for verifying that the original attribute value x is included in the range candidate R using the range proof data σ. The function Verify() is a function that takes as input the public parameter pp, the range proof data σ, and the range candidate R corresponding to σ, and outputs "1" indicating that the verification was successful or "0" indicating that the verification was unsuccessful. Note that Verify() corresponds to the function Gen() in equation (1) above. In other words, Verify() is a function used on the verifier side in the proof protocol to which Gen() used to generate the range proof data σ is applied. The function Verify() can be determined appropriately depending on the algorithm of the proof protocol to be applied.

[0113] For example, suppose that range proof data σ is generated by function Gen() in a proof protocol based on zero-knowledge proof. In this case, range proof verification unit 330 may verify range proof data σ using function Verify() corresponding to Gen() in the proof protocol based on zero-knowledge proof. Also, suppose that range proof data σ is generated by function Gen() in a proof protocol based on zero-knowledge interactive proof (ZKIP). In this case, range proof verification unit 330 may verify range proof data σ using function Verify() corresponding to Gen() in the proof protocol based on zero-knowledge interactive proof.

[0114] Also, suppose that the range proof data σ is generated by the function Gen() in a proof protocol based on a non-interactive zero-knowledge proof (NIZK). In this case, the range proof verification unit 330 may verify the range proof data σ using the function Verify() corresponding to Gen() in the proof protocol based on the non-interactive zero-knowledge proof. Also, suppose that the range proof data σ is generated by the function Gen() in a proof protocol other than a zero-knowledge proof. In this case, the range proof verification unit 330 may verify the range proof data σ using the function Verify() corresponding to Gen() in the proof protocol other than a zero-knowledge proof.

[0115] For example, suppose that the range proof data σ is generated by the non-interactive zero-knowledge proof algorithm (CFT proof) illustrated in Figure 9. In this case, Verify() is executed in step 4 when Bob verifies that x is -2 using (C, D1, D2) corresponding to the range proof data σ. t+l b≦x≦2 t+l corresponds to an algorithm that verifies that the value falls within the range of b.

[0116] If the verification is successful, it is proven that the attribute value x falls within the range candidate R. Therefore, in conjunction with the verification in S320, it is verified that there is no fraud in the generalization processing. On the other hand, if the verification fails, it is not proven that the attribute value x falls within the range candidate R, and there is a possibility that the attribute value x does not fall within the range candidate R. Therefore, there is a possibility that there is fraud in the generalization processing.

[0117] For example, in the first specific example shown in FIG. 8 above, if the attribute value #12="21" is generalized to "20s (20-29 years old)" in the data processing device 200, the range proof verification unit 330 performs verification using the candidate / proof set (1, 2, R1, σ1). In other words, the range proof verification unit 330 verifies the range proof data using the first set. That is, the range proof verification unit 330 verifies that the original attribute value #12=x is within the range of the range candidate R1 by inputting the range proof data σ1 and the range candidate R1 into the function Verify().

[0118] Also, for example, in the first specific example, if the attribute value #12="21" is generalized to "20-22 years old" in the data processing device 200, the range proof verification unit 330 performs verification using the candidate / proof sets (1, 2, R1, σ1) and (1, 2, R4, σ4). In other words, the range proof verification unit 330 performs verification using the second set (range proof set). That is, the range proof verification unit 330 verifies that the original attribute value #12=x falls within the range of the range candidate R1 by inputting the range proof data σ1 and the range candidate R1 into the function Verify(). Also, the range proof verification unit 330 verifies that the original attribute value #12=x falls within the range of the range candidate R4 by inputting the range proof data σ4 and the range candidate R4 into the function Verify(). This allows the range proof verification unit 330 to verify that the attribute value #12=x is within both the range of the range candidate R1 and the range of the range candidate R4. In other words, the range proof verification unit 330 can verify that the generalized attribute value x' is within the range expressed by R1∩R4.

[0119] As described above, in the information processing system 10 according to this embodiment, the data providing device 100 is configured to acquire multiple pieces of range certification data for proving that the pre-processing attribute value falls within a generalized attribute value range. Furthermore, the data processing device 200 is configured to select range certification data corresponding to the generalized attribute value range. As a result, even when a sanitized signature is performed, as described above, the data receiving device 300 can verify whether the original data has been appropriately generalized. Therefore, the information processing system 10 according to this embodiment can appropriately process data.

[0120] Furthermore, in this embodiment, the digital signature verification unit 320 verifies the range proof signature using the range candidates selected by the data processing device 200 and the corresponding range proofs and range proof signatures. In contrast, the technology disclosed in Patent Document 1 generates a new hash value from a hash value corresponding to the processed data during verification. This technology requires calculation of hash values according to the number of replacement candidates, i.e., the number of abstraction patterns, during verification. Therefore, as the number of abstraction patterns increases, the amount of hash value calculation also increases, potentially increasing the processing load. In particular, since increasing the number of abstraction patterns is necessary to increase the flexibility of processing, increasing the processing load may increase the processing load. Therefore, the technology disclosed in Patent Document 1 may not be able to perform efficient processing when attempting to achieve flexibility in processing.

[0121] On the other hand, in this embodiment, the data provider is configured to obtain multiple range certification data for proving that the attribute value before processing falls within the range of generalized attribute values. The system according to this embodiment is configured so that the data processor selects range certification data corresponding to the range of the generalized attribute value. Furthermore, in the system according to this embodiment, the data recipient is configured to perform verification using the range certification data selected by the data processor. Therefore, in this embodiment, during verification, the range candidate R selected by the data processor isi and the corresponding range proof σ i and the range certification signature δ, the processing load is suppressed even if the number of range candidates increases. Therefore, in this embodiment, it is possible to perform processing efficiently while realizing flexibility in processing.

[0122] (Example of hardware configuration) An example of the configuration of hardware resources for implementing the devices and systems according to the above-described embodiments using one calculation processing device (information processing device, computer) will be described. However, the devices according to the embodiments (data providing device, data processing device, and data receiving device) may be physically or functionally implemented using at least two calculation processing devices. Furthermore, the devices according to the embodiments may be implemented as dedicated devices or general-purpose information processing devices.

[0123] FIG. 12 is a block diagram showing an example of the hardware configuration of a calculation processing device capable of realizing the device and system according to each embodiment. The calculation processing device 1000 has a CPU 1001, a volatile storage device 1002, a disk 1003, a non-volatile recording medium 1004, and a communication IF (Interface) 1007. Therefore, it can be said that the device according to each embodiment has the CPU 1001, the volatile storage device 1002, the disk 1003, the non-volatile recording medium 1004, and the communication IF 1007. The calculation processing device 1000 may be connectable to an input device 1005 and an output device 1006. The calculation processing device 1000 may also include the input device 1005 and the output device 1006. Furthermore, the calculation processing device 1000 can send and receive information to and from other calculation processing devices and communication devices via the communication IF 1007.

[0124] The nonvolatile recording medium 1004 is a computer-readable medium, such as a compact disc or a digital versatile disc. The nonvolatile recording medium 1004 may also be a USB (Universal Serial Bus) memory, a solid state drive, or the like. The nonvolatile recording medium 1004 stores the program and allows portability without requiring a power supply. The nonvolatile recording medium 1004 is not limited to the above-mentioned medium. The program may also be supplied via the communication IF 1007 and a communication network instead of the nonvolatile recording medium 1004.

[0125] The volatile storage device 1002 is computer-readable and can temporarily store data. The volatile storage device 1002 is a memory such as a dynamic random access memory (DRAM) or a static random access memory (SRAM).

[0126] That is, when executing a software program (computer program: hereinafter simply referred to as "program") stored on disk 1003, CPU 1001 copies the program to volatile storage device 1002 and executes arithmetic processing. CPU 1001 reads data required to execute the program from volatile storage device 1002. When display is required, CPU 1001 displays the output result on output device 1006. When a program is input from the outside, CPU 1001 obtains the program from input device 1005. CPU 1001 interprets and executes a program corresponding to the function (process) of each component shown in FIGS. 3 to 5 described above. CPU 1001 executes the process described in each of the above-mentioned embodiments. In other words, the function of each component shown in FIGS. 3 to 5 described above can be realized by CPU 1001 executing a program stored on disk 1003 or volatile storage device 1002.

[0127] That is, each of the embodiments can be realized by the above-described program. Furthermore, each of the embodiments can be realized by a computer-readable non-volatile recording medium on which the above-described program is recorded.

[0128] (Variation) The present invention is not limited to the above-described embodiment, and can be modified as appropriate without departing from the spirit of the present invention. For example, in the above-described flowchart, the order of each process (step) can be modified as appropriate. Furthermore, one or more of the multiple processes (steps) may be omitted. For example, in the flowchart of FIG. 10, the order of the process of S210 and the process of S220 is arbitrary. Furthermore, in the flowchart of FIG. 11, the order of the process of S330 and the process of S330 is arbitrary.

[0129] In the above examples, the program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technology, CD-ROM, digital versatile disk (DVD), Blu-ray® disk or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.

[0130] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the invention.

[0131] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes. (Appendix 1) a data providing device that provides a dataset consisting of a plurality of data relating to at least one attribute; a data processing device that processes at least a portion of the plurality of data; a data receiving device that receives the data set in which some of the data has been processed; and The data providing device is a sanitizable signature generating means for generating a sanitizable signature that enables arbitrary generalization of processing of processing target data that is permitted to be processed; a range certification acquisition means for acquiring a plurality of range certification data for proving that the attribute value before processing falls within the range of the generalized attribute value when generalization processing is performed on the attribute value of the processing target data; a signature generating means for generating a digital signature for each of the range proof data; a first transmitting means for transmitting the data set, the sanitized signature, the range certification data, and the digital signature to the data processing device; and The data processing device is a processing means for performing a process for generalizing the processing object data; a sanitized signature processing means for processing the sanitized signature using the processing target data before processing and the processing target data after processing; a range certification selection means for selecting, for each of the processing target data that has been generalized, from among the plurality of range certification data, the range certification data that corresponds to the range of the generalized attribute value; a second transmission means for transmitting to the data receiving device a data set obtained by processing the data to be processed, the sanitized signature obtained by processing, the range certification data selected for each of the data to be processed, and the digital signature corresponding to the range certification data; and The data receiving device a sanitized signature verification means for verifying a data set obtained by processing the data to be processed and the sanitized signature processed by the data processing device; a digital signature verification means for verifying the digital signature corresponding to the range proof data selected by the data processing device; a range proof verification means for verifying the range proof data selected by the data processing device; having Information processing system. (Appendix 2) the range certification acquisition means generates a plurality of the range certification data; 10. The information processing system of claim 1. (Appendix 3) the range certification acquisition means generates the range certification data for each of a plurality of candidates for a range that includes the attribute value of the processing target data; the range proof selection means selects the range proof data for the candidate corresponding to a generalized range of attribute values; 10. The information processing system of claim 2. (Appendix 4) the signature generation means generates the digital signature for each first pair, which is a pair of the candidate and the range proof data corresponding to the candidate; the first transmission means transmits a plurality of the first sets and the digital signatures corresponding to the first sets to the data processing device; the range proof selection means selects at least one first set from the plurality of first sets that corresponds to a generalized range of attribute values; the second transmitting means transmits the selected first set and the digital signature corresponding to the selected first set to the data receiving device; the digital signature verification means verifies the first set and the digital signature corresponding to the first set; the range proof verification means verifies the range proof data using the first set; 10. The information processing system of claim 3. (Appendix 5) the range proof selection means selects the first set if there is a first set having the candidates whose range matches the generalized attribute value range; 5. The information processing system of claim 4. (Appendix 6) the range proof selection means, when there is no first set having the candidate whose range matches the generalized attribute value range but the generalized attribute value range is expressed by a combination of a plurality of the candidates, selects a second set which is a combination of the first sets corresponding to the plurality of candidates; the second transmitting means transmits the selected second set and the digital signature corresponding to the selected second set to the data receiving device; the digital signature verification means performs verification on the selected second set and the digital signature corresponding to the second set; the range proof verification means verifies the range proof data using the selected second set; 6. The information processing system according to claim 5. (Appendix 7) The first set includes identification information of the corresponding processing target data. 7. An information processing system according to any one of appendixes 4 to 6. (Appendix 8) the range proof acquisition means generates the range proof data using a proof protocol based on non-interactive zero-knowledge proof; the range proof verification means verifies the range proof data using the non-interactive zero-knowledge proof proof protocol; 8. An information processing system according to any one of appendices 2 to 7. (Appendix 9) a sanitized signature generating means for generating a sanitized signature that enables arbitrary generalization of processing of processing target data that is permitted to be processed among a data set that is composed of a plurality of data related to at least one attribute; a range certification acquisition means for acquiring a plurality of range certification data for proving that the attribute value before processing falls within the range of the generalized attribute value when generalization processing is performed on the attribute value of the processing target data; a signature generating means for generating a digital signature for each of the plurality of range proof data; a transmitting means for transmitting the data set, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least a portion of the plurality of data; A data providing device having the following. (Appendix 10) the range certification acquisition means generates a plurality of the range certification data; 10. The data providing device according to claim 9. (Appendix 11) the range certification acquisition means generates the range certification data for each of a plurality of candidates for a range that includes the attribute value of the data to be processed; 11. The data providing device according to claim 10. (Appendix 12) the signature generation means generates the digital signature for a first pair, which is a pair of the candidate and the range proof data corresponding to the candidate; the transmitting means transmits the first set and the digital signature corresponding to the first set to the data processing device; 12. The data providing device according to claim 11. (Appendix 13) The first set includes identification information of the corresponding processing target data. 13. The data providing device according to claim 12. (Appendix 14) the range proof acquisition means generates the range proof data using a proof protocol based on non-interactive zero-knowledge proof; 14. A data providing device according to any one of appendices 10 to 13. (Appendix 15) a processing means for performing processing to generalize processing on processing target data that is permitted to be processed, among a data set provided by a data providing device that provides the data set consisting of a plurality of data related to at least one attribute; a sanitized signature processing means for processing a sanitized signature that is generated for the processing target data by the data providing device and that enables arbitrary generalization processing, using the processing target data before processing and the processing target data after processing; range certification data for proving that the attribute value before processing falls within a range of generalized attribute values for each of the processing target data that has been generalized, wherein range certification selection means selects the range certification data corresponding to the range of generalized attribute values from among a plurality of range certification data acquired by the data providing device; a transmitting means for transmitting a data set in which the processing has been performed on the processing target data, the processed sanitized signature, the range certification data selected for each of the processing target data, and a digital signature generated by the data providing device and corresponding to the range certification data to a data receiving device that receives the data set in which some of the data has been processed; A data processing device having the above configuration. (Appendix 16) the range certification selection means selects the range certification data relating to the candidate corresponding to the generalized range of attribute values from among the plurality of range certification data generated for each of a plurality of candidates of a range including the attribute value of the data to be processed. 16. The data processing device according to claim 15. (Appendix 17) the range proof selection means selects at least one first pair corresponding to a generalized range of attribute values from a plurality of first pairs each of which is a pair of the candidate and the range proof data corresponding to the candidate; the transmitting means transmits the selected first set and the digital signature generated for the selected first set to the data receiving device; 17. The data processing device according to claim 16. (Appendix 18) the range proof selection means selects the first set if there is a first set having the candidates whose range matches the generalized attribute value range; 18. The data processing device according to claim 17. (Appendix 19) the range proof selection means, when there is no first set having the candidate whose range matches the generalized attribute value range but the generalized attribute value range is expressed by a combination of a plurality of the candidates, selects a second set which is a combination of the first sets corresponding to the plurality of candidates; the transmitting means transmits the selected second set and the digital signature corresponding to the selected second set to the data receiving device; 19. The data processing device according to claim 18. (Appendix 20) The first set includes identification information of the corresponding processing target data. 20. A data processing device according to any one of appendices 17 to 19. (Appendix 21) a data set obtained by processing target data, which is permitted to be processed and provided by a data providing device that provides a data set consisting of a plurality of data relating to at least one attribute, by a data processing device, and a sanitized signature verification means that verifies the sanitized signature obtained by processing the sanitized signature generated by the data providing device for the target data and allowing arbitrary generalization of the data by the data processing device; a digital signature verification means for verifying a digital signature corresponding to range certification data selected by the data processing device from among a plurality of range certification data acquired by the data providing device, the range certification data being used to verify that the attribute values before processing for each of the processing target data that has been generalized fall within the range of generalized attribute values; a range proof verification means for verifying the range proof data selected by the data processing device; A data receiving device having: (Appendix 22) the digital signature verification means verifies a first set, which is a set of a candidate range in which the attribute value of the processing target data is included and the range certification data corresponding to the candidate range, and which is selected by the data processing device, and the digital signature generated for the first set; the range proof verification means verifies the range proof data using the first set; 22. The data receiving device of claim 21. (Appendix 23) the digital signature verification means performs verification on a second set which is a combination of the first sets corresponding to a plurality of the candidates and which is selected by the data processing device, and the digital signature corresponding to the second set; the range proof verification means verifies the range proof data using the selected second set; 23. The data receiving device of claim 22. (Appendix 24) The first set includes identification information of the corresponding processing target data. 24. The data receiving device according to claim 22 or 23. (Appendix 25) the range proof verification means verifies the range proof data using a proof protocol based on non-interactive zero-knowledge proof; 25. A data receiving device according to any one of appendices 21 to 24. (Appendix 26) A data providing device provides a dataset consisting of a plurality of data relating to at least one attribute, A sanitized signature is generated that allows arbitrary generalization of the data to be processed, and acquiring a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data; generating a digital signature for each of the range proof data; transmitting the data set, the sanitized signature, the range certification data, and the digital signature to a data processing device that processes at least some of the data among the plurality of data; The data processing device performing a process for generalizing the processing target data; performing processing on the sanitized signature using the processing target data before processing and the processing target data after processing; For each of the processing target data that has been generalized, select the range certification data corresponding to the range of the generalized attribute value from among the plurality of range certification data; Transmitting a data set in which processing has been performed on the processing target data, the processed sanitized signature, the range certification data selected for each of the processing target data, and the digital signature corresponding to the range certification data to a data receiving device that receives the data set in which some data has been processed; By the data receiving device, verifying a data set obtained by processing the data to be processed and the sanitized signature processed by the data processing device; verifying the digital signature corresponding to the range proof data selected by the data processing device; performing verification on the range proof data selected by the data processing device; Information processing methods. (Appendix 27) generating a sanitized signature that enables arbitrary generalization of data to be processed that is permitted to be processed among a data set that includes a plurality of data related to at least one attribute; acquiring a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data; generating a digital signature for each of the plurality of range proof data; transmitting the data set, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least a portion of the plurality of data; How data is provided. (Appendix 28) performing a process for generalizing processing of processing target data that is permitted to be processed, among the data set provided by a data providing device that provides a data set consisting of a plurality of data related to at least one attribute; Using the processing target data before processing and the processing target data after processing, processing is performed on a sanitized signature that is generated for the processing target data by the data providing device and that enables arbitrary generalization processing; For each of the processing target data that has been generalized, range certification data is used to certify that the attribute value before processing falls within a range of generalized attribute values, and the range certification data corresponding to the range of generalized attribute values is selected from among a plurality of range certification data acquired by the data providing device; a data set in which the processing has been performed on the data to be processed, the processed sanitized signature, the range certification data selected for each of the data to be processed, and a digital signature generated by the data providing device and corresponding to the range certification data, to a data receiving device that receives the data set in which some of the data has been processed; Data processing methods. (Appendix 29) a data set obtained by processing target data, which is permitted to be processed and provided by a data providing device that provides a data set consisting of a plurality of data relating to at least one attribute, by a data processing device, and a sanitized signature obtained by processing a sanitized signature generated by the data providing device for the target data and enabling arbitrary generalization processing by the data processing device; range certification data for proving that the attribute value before processing for each of the processing target data that has been generalized falls within the range of the generalized attribute value, wherein verification is performed on a digital signature corresponding to the range certification data selected by the data processing device from among the plurality of range certification data acquired by the data providing device; performing verification on the range proof data selected by the data processing device; How we receive your data. (Appendix 30) A step of generating a sanitized signature that enables arbitrary generalization of processing of processing target data that is permitted to be processed among a data set consisting of a plurality of data related to at least one attribute; acquiring a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data; generating a digital signature for each of the plurality of range proof data; transmitting the data set, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least a portion of the plurality of data; A non-transitory computer-readable medium storing a program that causes a computer to execute the program. (Appendix 31) a step of performing a process for generalizing processing on processing target data that is permitted to be processed, among a data set provided by a data providing device that provides a data set consisting of a plurality of data related to at least one attribute; a step of performing processing on a sanitized signature that is generated for the processing target data by the data providing device and that enables arbitrary generalization processing, using the processing target data before processing and the processing target data after processing; a step of selecting, for each of the processing target data that has been generalized, range certification data for proving that the attribute value before processing falls within a range of generalized attribute values, the range certification data corresponding to the range of generalized attribute values from among a plurality of range certification data acquired by the data providing device; a step of transmitting a data set in which the processing has been performed on the processing target data, the processed sanitized signature, the range certification data selected for each of the processing target data, and a digital signature generated by the data providing device and corresponding to the range certification data to a data receiving device that receives the data set in which some of the data has been processed; A non-transitory computer-readable medium storing a program that causes a computer to execute the program. (Appendix 32) a step of verifying a data set obtained by processing target data, which is permitted to be processed and provided by a data providing device that provides a data set consisting of a plurality of data relating to at least one attribute, by a data processing device, and a sanitized signature obtained by processing a sanitized signature generated by the data providing device for the target data and enabling arbitrary generalization processing by the data processing device; a step of verifying a digital signature corresponding to range certification data selected by the data processing device from among a plurality of range certification data acquired by the data providing device, the range certification data being used to prove that the attribute values before processing for each of the processing target data that has been generalized fall within a range of generalized attribute values; performing verification on the range proof data selected by the data processing device; A non-transitory computer-readable medium storing a program that causes a computer to execute the program. [Explanation of symbols]

[0132] 10 Information Processing Systems 100 Data providing device 120 Redacted signature generation section 130 Range Proof Acquisition Unit 140 Signature generation section 150 Transmitter 200 Data Processing Device 210 Processing section 220 Sanitizable Signature Processing Unit 230 Range Proof Selection Unit 240 Transmitter 300 Data receiving device 310 Sanitizable Signature Verification Unit 320 Digital Signature Verification Unit 330 Range Proof Verification Unit

Claims

1. a data providing device that provides a data set consisting of a plurality of data relating to at least one attribute; a data processing device that processes at least a portion of the plurality of data; a data receiving device that receives the data set in which some of the data has been processed; and The data providing device is a sanitizable signature generating means for generating a sanitizable signature that enables arbitrary generalization of processing of processing target data that is permitted to be processed; a range certification acquisition means for acquiring a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data; a signature generating means for generating a digital signature for each of the range proof data; a first transmitting means for transmitting the data set, the sanitized signature, the range certification data, and the digital signature to the data processing device; and The data processing device is a processing means for performing a process for generalizing the processing object data; a sanitized signature processing means for processing the sanitized signature using the processing target data before processing and the processing target data after processing; a range certification selection means for selecting, for each of the processing target data that has been generalized, from among the plurality of range certification data, the range certification data that corresponds to the range of the generalized attribute value; a second transmission means for transmitting to the data receiving device a data set obtained by processing the data to be processed, the sanitized signature obtained by processing, the range certification data selected for each of the data to be processed, and the digital signature corresponding to the range certification data; and The data receiving device a sanitized signature verification means for verifying a data set obtained by processing the data to be processed and the sanitized signature processed by the data processing device; a digital signature verification means for verifying the digital signature corresponding to the range proof data selected by the data processing device; a range proof verification means for verifying the range proof data selected by the data processing device; having Information processing system.

2. the range certification acquisition means generates a plurality of the range certification data; The information processing system according to claim 1 .

3. the range certification acquisition means generates the range certification data for each of a plurality of candidates for a range that includes the attribute value of the processing target data; the range proof selection means selects the range proof data for the candidate corresponding to a generalized range of attribute values; The information processing system according to claim 2 .

4. the signature generation means generates the digital signature for each first pair, which is a pair of the candidate and the range proof data corresponding to the candidate; the first transmission means transmits a plurality of the first sets and the digital signatures corresponding to the first sets to the data processing device; the range proof selection means selects at least one first set from the plurality of first sets that corresponds to a generalized range of attribute values; the second transmitting means transmits the selected first set and the digital signature corresponding to the selected first set to the data receiving device; the digital signature verification means verifies the first set and the digital signature corresponding to the first set; the range proof verification means verifies the range proof data using the first set; The information processing system according to claim 3 .

5. the range proof selection means selects the first set if there is a first set having the candidates whose range matches the generalized attribute value range; The information processing system according to claim 4 .

6. the range proof selection means, when there is no first set having the candidate whose range matches the generalized attribute value range but the generalized attribute value range is expressed by a combination of a plurality of the candidates, selects a second set which is a combination of the first sets corresponding to the plurality of candidates; the second transmitting means transmits the selected second set and the digital signature corresponding to the selected second set to the data receiving device; the digital signature verification means performs verification on the selected second set and the digital signature corresponding to the second set; the range proof verification means verifies the range proof data using the selected second set; The information processing system according to claim 5 .

7. The first set includes identification information of the corresponding processing target data. The information processing system according to any one of claims 4 to 6.

8. the range proof acquisition means generates the range proof data using a proof protocol based on non-interactive zero-knowledge proof; the range proof verification means verifies the range proof data using the non-interactive zero-knowledge proof proof protocol; The information processing system according to any one of claims 2 to 7.

9. a sanitized signature generating means for generating a sanitized signature that enables arbitrary generalization of processing of processing target data that is permitted to be processed among a data set that is composed of a plurality of data related to at least one attribute; a range certification acquisition means for acquiring a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data; a signature generating means for generating a digital signature for each of the plurality of range proof data; a transmitting means for transmitting the data set, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least a portion of the plurality of data; A data providing device having the following.

10. the range certification acquisition means generates a plurality of the range certification data; The data providing device according to claim 9.

11. the range certification acquisition means generates the range certification data for each of a plurality of candidates for a range that includes the attribute value of the data to be processed. The data providing device according to claim 10.

12. the signature generation means generates the digital signature for a first pair, which is a pair of the candidate and the range proof data corresponding to the candidate; the transmitting means transmits the first set and the digital signature corresponding to the first set to the data processing device; The data providing device according to claim 11.

13. The first set includes identification information of the corresponding processing target data. The data providing device according to claim 12.

14. the range proof acquisition means generates the range proof data using a proof protocol based on non-interactive zero-knowledge proof; The data providing device according to any one of claims 10 to 13.

15. a processing means for performing a process for generalizing processing on processing target data that is permitted to be processed, among a data set provided by a data providing device that provides the data set including a plurality of data relating to at least one attribute; a sanitized signature processing means for processing a sanitized signature that is generated for the processing target data by the data providing device and that enables arbitrary generalization processing, using the processing target data before processing and the processing target data after processing; range certification data for proving that the attribute value before processing falls within a range of generalized attribute values for each of the processing target data that has been generalized, wherein range certification selection means selects the range certification data corresponding to the range of generalized attribute values from among a plurality of range certification data acquired by the data providing device; a transmitting means for transmitting a data set in which the processing has been performed on the processing target data, the processed sanitized signature, the range certification data selected for each of the processing target data, and a digital signature generated by the data providing device and corresponding to the range certification data to a data receiving device that receives the data set in which some of the data has been processed; A data processing device having the above configuration.

16. the range certification selection means selects the range certification data relating to the candidate corresponding to the generalized range of attribute values from among the plurality of range certification data generated for each of a plurality of candidates of a range including the attribute value of the data to be processed.

16. The data processing device according to claim 15.

17. the range proof selection means selects at least one first pair corresponding to a generalized range of attribute values from a plurality of first pairs each of which is a pair of the candidate and the range proof data corresponding to the candidate; the transmitting means transmits the selected first set and the digital signature generated for the selected first set to the data receiving device; 17. The data processing device according to claim 16.

18. the range proof selection means selects the first set if there is a first set having the candidates whose range matches the generalized attribute value range; 18. The data processing device according to claim 17.

19. the range proof selection means, when there is no first set having the candidate whose range matches the generalized attribute value range but the generalized attribute value range is expressed by a combination of a plurality of the candidates, selects a second set which is a combination of the first sets corresponding to the plurality of candidates; the transmitting means transmits the selected second set and the digital signature corresponding to the selected second set to the data receiving device; 19. The data processing device according to claim 18.

20. The first set includes identification information of the corresponding processing target data.

20. The data processing device according to any one of claims 17 to 19.

21. a data set obtained by processing target data, which is permitted to be processed and provided by a data providing device that provides a data set consisting of a plurality of data relating to at least one attribute, by a data processing device, and a sanitized signature verification means that verifies the sanitized signature obtained by processing the sanitized signature generated by the data providing device for the target data and allowing arbitrary generalization of the data by the data processing device; a digital signature verification means for verifying a digital signature corresponding to range certification data selected by the data processing device from among a plurality of range certification data acquired by the data providing device, the range certification data being used to verify that the attribute values before processing for each of the processing target data that has been generalized fall within the range of generalized attribute values; a range proof verification means for verifying the range proof data selected by the data processing device; A data receiving device having:

22. the digital signature verification means verifies a first set, which is a set of a candidate range in which the attribute value of the processing target data is included and the range certification data corresponding to the candidate range, the first set being selected by the data processing device, and the digital signature generated for the first set; the range proof verification means verifies the range proof data using the first set; 22. The data receiving device according to claim 21.

23. the digital signature verification means performs verification on a second set, which is a combination of the first sets corresponding to a plurality of the candidates and is selected by the data processing device, and the digital signature corresponding to the second set; the range proof verification means verifies the range proof data using the selected second set; 23. The data receiving device according to claim 22.

24. The first set includes identification information of the corresponding processing target data.

24. The data receiving device according to claim 22 or 23.

25. the range proof verification means verifies the range proof data using a proof protocol based on non-interactive zero-knowledge proof; 25. A data receiving device according to any one of claims 21 to 24.

26. A data providing device that provides a dataset consisting of a plurality of data relating to at least one attribute, A sanitized signature is generated that allows arbitrary generalization of the data to be processed, and acquiring a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data; generating a digital signature for each of the range proof data; transmitting the data set, the sanitized signature, the range certification data, and the digital signature to a data processing device that processes at least some of the data among the plurality of data; The data processing device performing a process for generalizing the processing target data; performing processing on the sanitized signature using the processing target data before processing and the processing target data after processing; For each of the processing target data that has been generalized, select the range certification data corresponding to the range of the generalized attribute value from among the plurality of range certification data; Transmitting a data set in which processing has been performed on the processing target data, the processed sanitized signature, the range certification data selected for each of the processing target data, and the digital signature corresponding to the range certification data to a data receiving device that receives the data set in which some data has been processed; By the data receiving device, verifying a data set obtained by processing the data to be processed and the sanitized signature processed by the data processing device; verifying the digital signature corresponding to the range proof data selected by the data processing device; performing verification on the range proof data selected by the data processing device; Information processing methods.

27. generating a sanitized signature that enables arbitrary generalization of data to be processed that is permitted to be processed among a data set that is composed of a plurality of data related to at least one attribute; acquiring a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data; generating a digital signature for each of the plurality of range proof data; transmitting the data set, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least a portion of the plurality of data; How data is provided.

28. performing a process for generalizing processing of processing target data that is permitted to be processed, among the data set provided by a data providing device that provides a data set consisting of a plurality of data related to at least one attribute; Using the processing target data before processing and the processing target data after processing, processing is performed on a sanitized signature that is generated for the processing target data by the data providing device and that enables arbitrary generalization processing; For each of the processing target data that has been generalized, range certification data is used to certify that the attribute value before processing falls within a range of generalized attribute values, and the range certification data corresponding to the range of generalized attribute values is selected from among a plurality of range certification data acquired by the data providing device; a data set in which the processing has been performed on the data to be processed, the processed sanitized signature, the range certification data selected for each of the data to be processed, and a digital signature generated by the data providing device and corresponding to the range certification data, to a data receiving device that receives the data set in which some of the data has been processed; Data processing methods.

29. a data set obtained by processing target data, which is permitted to be processed and provided by a data providing device that provides a data set consisting of a plurality of data relating to at least one attribute, by a data processing device, and a sanitized signature obtained by processing a sanitized signature generated by the data providing device for the target data and enabling arbitrary generalization processing by the data processing device; range certification data for proving that the attribute value before processing for each of the processing target data that has been generalized falls within the range of the generalized attribute value, wherein verification is performed on a digital signature corresponding to the range certification data selected by the data processing device from among the plurality of range certification data acquired by the data providing device; performing verification on the range proof data selected by the data processing device; How we receive your data.

30. generating a sanitized signature that enables arbitrary generalization of processing of data to be processed that is permitted to be processed among a data set that includes a plurality of data related to at least one attribute; acquiring a plurality of range certification data for proving that the attribute value before processing falls within a range of generalized attribute values when generalization processing is performed on the attribute value of the processing target data; generating a digital signature for each of the plurality of range proof data; transmitting the data set, the sanitized signature, the range certification data, and the digital signature corresponding to the range certification data to a data processing device that processes at least a portion of the plurality of data; A program that causes a computer to execute the following.

31. a step of performing processing for generalizing target data that is permitted to be processed, among a data set provided by a data providing device that provides a data set consisting of a plurality of data related to at least one attribute; a step of performing processing on a sanitized signature that is generated for the processing target data by the data providing device and that enables arbitrary generalization processing, using the processing target data before processing and the processing target data after processing; a step of selecting, for each of the processing target data that has been generalized, range certification data for proving that the attribute value before processing falls within a range of generalized attribute values, the range certification data corresponding to the range of generalized attribute values from among a plurality of range certification data acquired by the data providing device; a step of transmitting a data set in which the processing has been performed on the processing target data, the processed sanitized signature, the range certification data selected for each of the processing target data, and a digital signature generated by the data providing device and corresponding to the range certification data to a data receiving device that receives the data set in which some of the data has been processed; A program that causes a computer to execute the following.

32. a step of verifying a data set obtained by processing target data, which is permitted to be processed and provided by a data providing device that provides a data set consisting of a plurality of data relating to at least one attribute, by a data processing device, and a sanitized signature obtained by processing a sanitized signature generated by the data providing device for the target data and enabling arbitrary generalization processing by the data processing device; a step of verifying a digital signature corresponding to range certification data selected by the data processing device from among a plurality of range certification data acquired by the data providing device, the range certification data being used to prove that the attribute values before processing for each of the processing target data that has been generalized fall within a range of generalized attribute values; performing verification on the range proof data selected by the data processing device; A program that causes a computer to execute the following.

Citation Information

Patent Citations

  • Anonymization system and anonymization method

    JP2020077256A

  • System and method for recommending public data generalization level guaranteeing data anonymity and useful to data analysis

    KR1020180104473A

  • Signature validation system, signature validation method, and program

    WO2021245806A1