Secret attribute selection system, secret attribute selection device, secret attribute selection method, and program
The secret attribute selection system efficiently computes the attribute with the best evaluation value by using a matrix-based approach, reducing the number of calculations required in secure computation for grouped data, thus enhancing computational efficiency.
Patent Information
- Application Number
- JP2024522761
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-24
- Publication Date
- 2025-10-01
- Estimated Expiration
- 2042-05-24
AI Technical Summary
Existing secure computation methods require a large amount of calculations to determine the attribute with the best evaluation value from K attributes randomly selected for each group in N pieces of data consisting of M attributes grouped into a predetermined number of groups.
A secret attribute selection system utilizing a matrix-based approach with three secret attribute selection devices that efficiently computes the attribute with the best evaluation value by calculating evaluation values for only K attributes, reducing the number of calculations required.
Enables efficient secure computation to select the attribute with the best evaluation value from K attributes randomly selected for each group, improving computational efficiency by minimizing the number of calculations needed.
Smart Images

Figure 0007747192000001 
Figure 0007747192000002 
Figure 0007747192000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a secure computation technique, and more particularly to a technique for securely computing attribute selection based on an evaluation value. [Background technology]
[0002] Secure computation is a method of obtaining the result of a specified computation without restoring the encrypted numerical value (see, for example, Non-Patent Document 1). In the method of Non-Patent Document 1, encryption is performed by distributing multiple pieces of information from which a numerical value can be restored to three secure computing devices, and the results of addition / subtraction, constant sum, multiplication, constant multiplication, logical operations (negation, logical product, logical sum, exclusive OR), and data format conversion (integer, binary number) can be stored in a distributed state, i.e., encrypted, among the three secure computing devices without restoring the numerical value. In general, the number of shares is not limited to 3 but can be W (W is a predetermined constant greater than or equal to 3), and a protocol that realizes secure computation through cooperative computation by W secure computing devices is called a multi-party protocol.
[0003] Consider a secure computation in which, for N pieces of data consisting of M attributes divided into a predetermined number of groups, the attribute with the best evaluation value is selected from K attributes randomly selected for each group. In this case, by calculating the evaluation values for all M attributes for each group, it is possible to select the attribute with the best evaluation value from the K attributes randomly selected for each group. [Prior art documents] [Non-patent literature]
[0004] [Non-Patent Document 1] Koji Senda, Hiroki Hamada, Dai Igarashi, and Katsumi Takahashi, “Rethinking Lightweight Verifiable Three-Party Secure Function Computation,” in CSS, 2010. Summary of the Invention [Problem to be solved by the invention]
[0005] However, the above-described method is not efficient because it requires a large amount of calculations to calculate evaluation values for all M attributes for each group.
[0006] Therefore, the present invention aims to provide a technology that efficiently performs secure computation to select the attribute with the best evaluation value from K attributes randomly selected for each group for N pieces of data consisting of M attributes that are grouped into a predetermined number of groups. [Means for solving the problem]
[0007] In one aspect of the present invention, N (N is an integer of 1 or more) is the number of data, M (M is an integer of 1 or more) is the number of attributes that make up the data, and X=( → x1, …, → x N ) t (however, → x i (i=1, …, N) is a row vector of length M representing the i-th data, and N data → x1, …, → x N are grouped into a predetermined number of groups, and data belonging to the same group are arranged adjacently) → x1, …, → x N An N-by-M matrix representing → g=(g1, …, g N ) t (However, g i (i=1, …, N) is the i-th data → x i is the first data in a group, it is 1, otherwise it is 0) → x1, …, → x N Let be a column vector of length N representing the group, and it consists of three or more secret attribute selection devices and has N data. → x1, …, → x N The matrix X represents the share [[X]] and N data→ x1, …, → x N A column vector representing the groups into which → g share[[ → g]], the i-th data → x i The number of the attribute with the best evaluation value among K randomly selected attributes (K is an integer between 1 and M) in the group to which z belongs is the i-th element z. i A column vector of length N → z=(z1, …, z N ) t Share of [[ → A secret attribute selection system for computing a share [[ → Using the N-row M-column matrix E=( → e1, …, → e N ) t (however, → e i (i=1, …, N) is the i-th data → x i is a row vector of length M representing K randomly selected attributes in the group to which → e i j-th element e of i,j a first matrix calculation means for calculating the share [[E]] of the jth attribute (where V is 1 if the jth attribute is the selected attribute and 0 otherwise); → v1, …, → v N ) t (however, → v i (i=1, …, N) is the i-th data → x i The attribute numbers are arranged in the order of the attribute numbers, and the row vector (1, 2, ..., M) of length M is set as an N-by-M matrix. Using the share [[E]], the N-by-K matrix Y = ( → y1, …, → y N ) t (however, → y i (i=1, …, N) is the i-th data→ x i The i-th data for K randomly selected attributes in the group to which → x i The share [[Y]] of the attribute is a row vector of length K in which the values of the attributes are arranged in numerical order. The share [[V]] is then converted into an N-by-K matrix U=( → u1, …, → u N ) t (however, → u i (i=1, …, N) is the i-th data → x i A second matrix calculation means calculates the share [[U]] of each of the attributes (which is a row vector of length K in which the numbers of K attributes randomly selected in the group to which each belongs are arranged in the order of the attribute numbers), and a matrix S=( → s1, …, → s N ) t (however, → s i (i=1, …, N) is the i-th data → x i a third matrix calculation means for calculating the share [[S]] of a group (which is a row vector of length K in which the evaluation values of the group for K randomly selected attributes in the group to which the group belongs are arranged in the order of the attribute numbers); and a third matrix calculation means for calculating the share [[Y]] from the share [[ → and a first vector calculation means for calculating z]]. [Effects of the Invention]
[0008] According to the present invention, for N pieces of data consisting of M attributes grouped into a predetermined number of groups, it is possible to efficiently perform secret computation to select the attribute with the best evaluation value from K attributes randomly selected for each group. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a block diagram showing the configuration of a secret attribute selection system 10. FIG. [Figure 2] FIG. 2 is a block diagram showing the configuration of a secret attribute selection device 100i. [Figure 3] 1 is a flowchart showing the operation of the secret attribute selection system 10. [Figure 4] FIG. 2 is a diagram illustrating an example of the functional configuration of a computer that realizes each device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present invention will be described in detail. Components having the same functions are given the same numbers, and duplicated explanations will be omitted.
[0011] Before describing each embodiment, the notation used in this specification will be explained.
[0012] ^ (caret) represents a superscript, e.g., x y^z Yes z is a superscript to x, and x y^z Yes z is a subscript to x. Also, _ (underscore) represents a subscript. For example, x y_z Yes z is a superscript to x, and x y_z Yes z is a subscript to x.
[0013] The superscripts "^" and "~" such as ^x and ~x for a certain letter x should be written directly above the "x", but due to restrictions on the notation in the specification, they are written as ^x and ~x. <Technical background> <<Secure calculation>> The secure computation in the present invention is constructed by combining existing secure computation operations. The operations required for this secure computation are encryption, addition, subtraction, multiplication, division, logical operations (negation, logical AND, logical OR, exclusive OR), comparison operations (=, <, >, ≦, ≧), secret-stable sorting, and group-wise sum. Below, we will explain some of the operations, including their notations. [Redacted] Let [[x]] be the value of x concealed by secret sharing (hereinafter referred to as a share of x). Any secret sharing method can be used. For example, 61 -1) Shamir secret sharing on Z2 and replication secret sharing on Z2 can be used.
[0014] Multiple secret sharing methods may be combined within a single algorithm. In this case, they will be converted into each other as appropriate.
[0015] Also, N-dimensional vector → x=(x1, …, x N ) for [[ → x]]=([[x1]], …, [[x N ]]). That is, [[ → x]] is → The nth element of x, x n Share [[x n ]] is a vector with n-th element. Similarly, M×N matrix A=(a m,n )(1≦m≦M, 1≦n≦N), [[A]] is the (m, n)th element of A, a m,n Share of [[a m,n Let ]] be the matrix whose element is (m, n).
[0016] Note that x is called the plaintext of [[x]].
[0017] Specific examples of a method for obtaining [[x]] from x (concealment) and a method for obtaining x from [[x]] (restoration) are described in Non-Patent Document 1 and Reference Non-Patent Document 1. (Reference Non-Patent Document 1: Shamir, A., "How to share a secret", Communications of the ACM, Vol. 22, No. 11, pp. 612-613, 1979.) [Addition, Subtraction, Multiplication, Division] Secure addition [[x]]+[[y]] takes inputs [[x]] and [[y]] and outputs [[x+y]]. Secure subtraction [[x]]-[[y]] takes inputs [[x]] and [[y]] and outputs [[xy]]. Secure multiplication [[x]]×[[y]] (sometimes expressed as mul([[x]], [[y]])) takes inputs [[x]] and [[y]] and outputs [[x×y]]. Secure division [[x]] / [[y]] (sometimes expressed as div([[x]], [[y]])) takes inputs [[x]] and [[y]] and outputs [[x / y]].
[0018] Specific methods for addition, subtraction, multiplication, and division include those described in Reference Non-Patent Documents 2 and 3. (Reference Non-Patent Document 2: Ben-Or, M., Goldwasser, S. and Wigderson, A., “Completeness theorems for non-cryptographic fault-tolerant distributed computation”, Proceedings of the twentieth annual ACM symposium on Theory of computing, ACM, pp. 1-10, 1988.) (Reference Non-Patent Document 3: Gennaro, R., Rabin, MO and Rabin, T., “Simplified VSS and fast-track multiparty computations with applications to threshold cryptography”, Proceedings of the seventeenth annual ACM symposium on Principles of distributed computing, ACM, pp.101-111, 1998.) [Logical Operations] Secure negation not[[x]] takes [[x]] as input and outputs [[not(x)]]. Secure logical conjunction and([[x]], [[y]]) takes [[x]], [[y]] as input and outputs [[and(x, y)]]. Secure logical sum or([[x]], [[y]]) takes [[x]], [[y]] as input and outputs [[or(x, y)]]. Secure exclusive OR xor([[x]], [[y]]) takes [[x]], [[y]] as input and outputs [[xor(x, y)]].
[0019] Note that logical operations can be easily configured by combining addition, subtraction, multiplication, and division. [Comparison operation] Equality determination by secure computation =([[x]], [[y]]) (sometimes denoted as equal([[x]], [[y]])) takes [[x]] and [[y]] as inputs and outputs [[1]] if x = y, and [[0]] otherwise. Comparison <([[x]], [[y]]) by secure computation takes [[x]] and [[y]] as inputs and outputs [[1]] if x < y, and [[0]] otherwise. Comparison >([[x]], [[y]]) by secure computation takes [[x]] and [[y]] as inputs and outputs [[1]] if x > y, and [[0]] otherwise. Comparison ≤([[x]], [[y]]) by secure computation takes [[x]] and [[y]] as inputs and outputs [[1]] if x ≤ y, and [[0]] otherwise. Comparison ≥([[x]], [[y]]) by secure computation takes [[x]] and [[y]] as inputs and outputs [[1]] if x ≥ y, and [[0]] otherwise.
[0020] Note that the comparison operation can be easily constructed by combining logical operations. [Secure Stable Sort] Secure stable sort refers to stable sort in secure computation, which is for N-dimensional vectors → y=(y1, …, y N )'s shares → y]] being a vector obtained by securely stably sorting the shares → k=(k1, …, k N )'s → k]] of the N-dimensional vector → x=(x1, …, x N )'s → x]] with respect to → y]] means that → y]] becomes a vector obtained by securely stably sorting → x]] using a permutation σ of {1, …, N} that stably sorts
[0021] As a specific method of secure stable sort, there is a method described in Reference Non-Patent Document 4. (Reference non-patent document 4: Koji Chida, Koki Hamada, Dai Ikarashi, Ryo Kikuchi, Naoto Kiribuchi, and Benny Pinkas, “An Efficient Secure Three-Party Sorting Protocol with an Honest Majority,” IACR Cryptol. ePrint Arch., 2019.) [Group-wise sum operation] Group-wise sum operation is an N-dimensional vector → x=(x1, …, x N ) (where N elements x1, …, x N is grouped into a predetermined number of groups, with elements belonging to the same group adjacent to each other), an N-dimensional vector → g=(g1, …, g N ) (where g n (n=1, …, N) is the nth element x n is the first data in a group, it is 1, otherwise it is 0) → x]], [[ → g]] is the input, and → y=(y1, …, y N ) (where y n (n=1, …, N) is the nth element x n The share of [[ → y]] is output.
[0022] A specific method for group-wise sum calculation is the method described in Non-Patent Document 5. (Reference non-patent document 5: Koki Hamada, Dai Ikarashi, Ryo Kikuchi, and Koji Chida, “Efficient decision tree training with new data structure for secure multi-party computation,” arXiv:2112.12906 [cs.CR], 2021.) Note that the group-wise sum operation can also be defined for matrices by applying the group-wise sum operation to each row or column. First Embodiment The secret attribute selection system 10 will be described below with reference to Figs. 1 to 3. Fig. 1 is a block diagram showing the configuration of the secret attribute selection system 10. The secret attribute selection system 10 includes W (W is a predetermined integer equal to or greater than 3) secret attribute selection devices 1001, ..., 100 W Secret attribute selection devices 1001, ..., 100 W are connected to a network 800 and can communicate with each other. The network 800 may be, for example, a communication network such as the Internet or a broadcast communication path. i 3 is a block diagram showing the configuration of (1≦i≦W). FIG. 3 is a flowchart showing the operation of the secret attribute selection system 10.
[0023] As shown in FIG. 2, the secret attribute selection device 100 i is the first matrix calculation unit 110 i and the second matrix calculation unit 120 i and the third matrix calculation unit 130 i and the first vector calculation unit 140 i and recording unit 190 i Recording unit 190 i Secret attribute selection device 100 excluding iEach component of the above is configured to be able to execute the operations required for secure computation, that is, at least among the operations required to realize the function of each component, such as encryption, addition, subtraction, multiplication, division, logical operations, comparison operations, securely stable sorting, and group-wise sum operations. In the present invention, the specific functional configuration for realizing each operation is sufficient if it is a configuration that can execute existing algorithms including the algorithms disclosed in Non-Patent Document 1 and Reference Non-Patent Documents 1 to 5, and since these are conventional configurations, detailed description thereof will be omitted. In addition, the recording unit 190 i is a secret attribute selection device 100 i This is a component that records information necessary for processing.
[0024] W secret attribute selection devices 100 i By the collaborative computation by the above, the secret attribute selection system 10 realizes secure computation of attribute selection, which is a multi-party protocol. Therefore, the first matrix computation means 110 (not shown) of the secret attribute selection system 10 includes first matrix computation units 1101, ..., 110 W The second matrix calculation means 120 (not shown) is composed of second matrix calculation units 1201, ..., 120 W The third matrix calculation means 130 (not shown) is composed of third matrix calculation units 1301, ..., 130 W The first vector calculation means 140 (not shown) is composed of first vector calculation units 1401, ..., 140 W It consists of:
[0025] The secret attribute selection system 10 is a system in which N (N is an integer of 1 or more) is the number of data, M (M is an integer of 1 or more) is the number of attributes that make up the data, and X=( → x1, …, → x N ) t (however, → x i (i=1, …, N) is a row vector of length M representing the i-th data, and N data → x1, …, → x Nare grouped into a predetermined number of groups, and data belonging to the same group are arranged adjacently) → x1, …, → x N An N-by-M matrix representing → g=(g1, …, g N ) t (However, g i (i=1, …, N) is the i-th data → x i is the first data in a group, it is 1, otherwise it is 0) → x1, …, → x N Let be a column vector of length N that represents the group, and → x1, …, → x N The matrix X represents the share [[X]] and N data → x1, …, → x N A column vector representing the groups into which → g share[[ → g]], the i-th data → x i The number of the attribute with the best evaluation value among K randomly selected attributes (K is an integer between 1 and M) in the group to which z belongs is the i-th element z. i A column vector of length N → z=(z1, …, z N ) t Share of [[ → z]]. Note that share [[X]] and share [[ → g]] is previously recorded in the recording unit 190 i You can also record it in, for example, → x1, …, → x N ) t The t on the right side of a vector or matrix, like the t in , indicates transposition.
[0026] The operation of the secret attribute selection system 10 will be described below with reference to FIG.
[0027] In S110, the first matrix calculation means 110 calculates the share [[ → Using the N-row M-column matrix E=( → e1, …, → e N ) t (however, → e i (i=1, …, N) is the i-th data → x i is a row vector of length M representing K randomly selected attributes in the group to which → e i j-th element e of i,j is 1 if the j-th attribute is the selected attribute, and is 0 otherwise). The first matrix calculation means 110 calculates the share [[E]] of the j-th attribute (which is 1 if the j-th attribute is the selected attribute, and is 0 otherwise). → d1, …, → d N ) t (however, → d i (i=1, …, N) is a row vector of length M in which K randomly selected elements out of M elements are 1 and the remaining MK elements are 0), and generate shares [[D]] of the share [[ → Using the share [[D]], we obtain the matrix D'=( → d'1, …, → d' N ) t (however, → d' i (i=1, …, N) is g i If =1, → d i , g i If =0, → 0 (However, → 0 is a row vector of length M with all elements 0)) and calculate the share [[D']] of → g]] is used to calculate the share [[E]] from the share [[D']]. When calculating the share [[E]] from the share [[D']], for example, a group-wise sum operation can be used.
[0028] In addition,→ e i (i=1, …, N) is a row vector in which K elements out of M elements are 1 and the other MK elements are 0. Also, the i-th data → x i and the jth data → x j If they belong to the same group, → e i = → e j This becomes:
[0029] In S120, the second matrix calculation means 120 calculates V=( → v1, …, → v N ) t (however, → v i (i=1, …, N) is the i-th data → x i The attribute numbers are arranged in the order of the attribute numbers, and the row vector (1, 2, ..., M) of length M is used as an N-row, M-column matrix. Using the share [[E]] calculated in S110, the N-row, K-column matrix Y = ( → y1, …, → y N ) t (however, → y i (i=1, …, N) is the i-th data → x i The i-th data for K randomly selected attributes in the group to which → x i The share [[Y]] of the attribute is a row vector of length K in which the values of the attributes are arranged in numerical order. The share [[V]] is then converted into an N-by-K matrix U=( → u1, …, → u N ) t (however, → u i (i=1, …, N) is the i-th data → x iThe second matrix calculation means 120 calculates the share [[U]] of each of the attributes (which is a row vector of length K in which the numbers of K attributes randomly selected in the group to which the attribute belongs are arranged in the order of the attribute numbers). → e i Share about → x i ]] is obtained by secretly stably sorting the vector obtained by sorting the M-K+1th to Mth elements of the vector, and the resulting row vector of length K is shared by [[ → y i ]] (i=1, …, N) to calculate the share [[Y]] and the share [[ → e i Share about → v i ]] is obtained by secretly stably sorting the vector obtained by sorting the M-K+1th to Mth elements of the vector, and the resulting row vector of length K is shared by [[ → u i ]] (i=1, ..., N) to calculate the share [[U]]. For secret-stable sorting, for example, the method described in Non-Patent Document 4 can be used. Note that the share [[ → e i ]] (i=1, …, N) is a vector obtained by secretly stably sorting such that the 1st to MKth elements are [[0]] and the M-K+1st to Mth elements are [[1]].
[0030] In S130, the third matrix calculation means 130 calculates a matrix S=( → s1, …, → s N ) t (however, → s i (i=1, …, N) is the i-th data → x iThe share [[S]] of the group to which the attribute belongs is calculated. The share [[S]] can be calculated using the attribute-wise test selection algorithm described in Non-Patent Document 5, for example.
[0031] In S140, the first vector calculation means 140 calculates the share [[Y]] from the share [[S]] calculated in S130 using the share [[Y]] and share [[U]] calculated in S120. → The first vector calculation means 140 calculates, for example, the share [[ → s i ]] to a row vector of length K → h i (however, → h i teeth → s i The element with the best evaluation value is 1, and the other elements are 0.) → h i ]] and calculate the share [[ → u i ]] and share [[ → h i ]]from → u i and → h i The dot product of → u i * → h i Share of [[ → u i * → h i ]] and calculate [[z i ]]=[[ → u i * → h i ]] (i=1, …, N), the share [[ → Calculate z].
[0032] The secret attribute selection system 10 can be used for machine learning based on, for example, random forests.
[0033] According to an embodiment of the present invention, for N pieces of data each consisting of M attributes divided into a predetermined number of groups, it is possible to efficiently perform secure computation to select the attribute with the best evaluation value from K attributes selected randomly for each group. Specifically, while the method described in the "Background Art" requires that evaluation values be calculated for all M attributes, according to an embodiment of the present invention, it is sufficient to calculate evaluation values for only K attributes, thereby reducing the number of times that evaluation values need to be calculated. <Additional Notes> The processing of each unit of each of the above-mentioned devices may be realized by a computer, in which case the processing content of the functions that each device should have is described by a program. Then, by loading this program into the recording unit 2020 of the computer 2000 shown in Fig. 4 and operating the arithmetic processing unit 2010, the input unit 2030, the output unit 2040, the auxiliary recording unit 2025, etc., the various processing functions of each of the above-mentioned devices are realized on the computer.
[0034] The device of the present invention may, for example, be a single hardware entity, having an input unit capable of inputting signals from outside the hardware entity, an output unit capable of outputting signals to outside the hardware entity, a communication unit to which a communication device (e.g., a communication cable) can be connected for communication with outside the hardware entity, a CPU (which may also include a central processing unit, cache memory, registers, etc.) as an arithmetic processing unit, RAM and ROM as memories, an external storage device such as a hard disk, and buses connecting these input unit, output unit, communication unit, CPU, RAM, ROM, and external storage device so as to enable data exchange. If necessary, the hardware entity may also be provided with a device (drive) capable of reading and writing to a recording medium such as a CD-ROM. An example of a physical entity equipped with such hardware resources is a general-purpose computer.
[0035] The external storage device of the hardware entity stores the programs required to realize the above-mentioned functions and the data required for processing these programs (the programs may be stored in a ROM, which is a read-only storage device, for example, instead of an external storage device). Data obtained by processing these programs is stored in RAM, the external storage device, etc. as appropriate.
[0036] In the hardware entity, each program stored in an external storage device (or ROM, etc.) and data required for processing each program are loaded into memory as needed, and interpreted, executed, and processed by the CPU as appropriate. As a result, the CPU realizes predetermined functions (each component represented as the above, "... unit," "... means," etc.). In other words, each component in the embodiments of the present invention may be configured by a processing circuitry.
[0037] As described above, when the processing functions of the hardware entities (apparatuses of the present invention) described in the above embodiments are realized by a computer, the processing contents of the functions that the hardware entities should have are described by a program. Then, by executing this program on a computer, the processing functions of the hardware entities are realized on the computer.
[0038] The program describing the processing contents can be recorded on a computer-readable recording medium, such as a non-transitory recording medium, specifically a magnetic recording device, an optical disk, or the like.
[0039] The program may be distributed, for example, by selling, transferring, lending, etc. a portable recording medium such as a DVD or CD-ROM on which the program is recorded. Furthermore, the program may be stored in a storage device of a server computer, and then transferred from the server computer to another computer via a network, thereby distributing the program.
[0040] A computer that executes such a program, for example, first stores the program recorded on a portable recording medium or transferred from a server computer in its own non-transitory storage device, the auxiliary storage unit 2025. Then, when executing a process, the computer loads the program stored in its own non-transitory storage device, the auxiliary storage unit 2025, into the storage unit 2020 and executes processing in accordance with the loaded program. Alternatively, as another execution mode of this program, the computer may load the program directly from a portable recording medium into the storage unit 2020 and execute processing in accordance with the program. Furthermore, each time a program is transferred from a server computer to this computer, the computer may execute processing in accordance with the received program. Alternatively, the server computer may not transfer the program to this computer, but may instead execute the processing function by issuing an execution instruction and obtaining the results, thereby executing the above-described processing through a so-called ASP (Application Service Provider) type service. Note that the program in this embodiment includes information used for processing by a computer that is equivalent to a program (such as data that is not a direct instruction to a computer but has properties that define computer processing).
[0041] Furthermore, in this embodiment, the device is configured by executing a predetermined program on a computer, but at least a part of the processing contents may be realized by hardware.
[0042] The present invention is not limited to the above-described embodiment, and various modifications can be made without departing from the spirit of the present invention.
Claims
1. N (N is an integer greater than or equal to 1) is the number of data, M (M is an integer greater than or equal to 1) is the number of attributes that make up the data, X=( → x 1 , …, → x N ) t (however, → x i (i=1, …, N) is a row vector of length M representing the i-th data, and N data → x 1 , …, → x N are grouped into a predetermined number of groups, and data belonging to the same group are arranged adjacently) → x 1 , …, → x N An N-by-M matrix representing → g=(g 1 , …, g N ) t (However, g i (i=1, …, N) is the i-th data → x i If it is the first data in a group, it is 1; otherwise, it is 0. → x 1 , …, → x N Let be a column vector of length N representing the group, It consists of three or more secret attribute selection devices and N data → x 1 , …, → x N The matrix X represents the share [[X]] and N data → x 1 , …, → x N A column vector representing the groups into which → g share[[ → g]], the i-th data → x i The number of the attribute with the best evaluation value among K randomly selected attributes (K is an integer between 1 and M) in the group to which z belongs is the i-th element z. i A column vector of length N → z=(z 1 , …, z N ) t Share of [[ → 1. A secret attribute selection system for computing z]], share[[ → Using the N-row M-column matrix E=( → e 1 , …, → e N ) t (however, → e i (i=1, …, N) is the i-th data → x i is a row vector of length M representing K randomly selected attributes in the group to which → e i j-th element e of i,j a first matrix calculation means for calculating a share [[E]] of the j-th attribute (where E is 1 if the j-th attribute is the selected attribute and 0 otherwise); V=( → v 1 , …, → v N ) t (however, → v i (i=1, …, N) is the i-th data → x i Let (1, 2, …, M) be a row vector of length M in which the attribute numbers of Using the share [[E]], we can get the matrix Y = ( → y 1 , …, → y N ) t (however, → y i (i=1, …, N) is the i-th data → x i The i-th data for K randomly selected attributes in the group to which → x i The share [[Y]] of the attribute is a row vector of length K in which the values of the attributes are arranged in numerical order. The share [[V]] is then converted into an N-by-K matrix U=( → u 1 , …, → u N ) t (however, → u i (i=1, …, N) is the i-th data → x i The share of (a row vector of length K that lists the numbers of K randomly selected attributes in the group to which ) belongs, sorted in attribute number order. second matrix calculation means for calculating [[U]] respectively; From the share [[Y]], we get the N-row K-column matrix S=( → s 1 , …, → s N ) t (however, → s i (i=1, …, N) is the i-th data → x i a third matrix calculation means for calculating a share [[S]] of a group to which the attribute belongs, the group being a row vector of length K in which the group's evaluation values for K randomly selected attributes are arranged in the order of the attribute numbers; Using share [[Y]] and share [[U]], share [[S]] is converted to share [[ → a first vector calculation means for calculating z]]; A secret attribute selection system including:
2. 2. The secret attribute selection system of claim 1, The first matrix calculation means N row M column matrix D=( → d 1 , …, → d N ) t (however, → d i (i=1, …, N) is a row vector of length M in which K randomly selected elements out of M elements are 1 and the remaining M elements are 0), share[[ → Using the share [[D]], we obtain the matrix D'=( → d' 1 , …, → d' N ) t (however, → d' i (i=1, …, N) is g i If =1, → d i , g i If =0, → 0 (However, → Calculate the share [[D']] of (where 0 is a row vector of length M with all elements 0), share[[ → Calculate share [[E]] from share [[D']] using [[g]] A secret attribute selection system comprising:
3. 2. The secret attribute selection system of claim 1, The second matrix calculation means share[[ → e i Share about → x i ]] is obtained by secretly stably sorting the vector obtained by sorting the M-K+1th to Mth elements of the vector, and the resulting row vector of length K is shared by [[ → y i ]] (i=1, …, N) to calculate the share [[Y]], share[[ → e i Share about → v i ]] is obtained by secretly stably sorting the vector obtained by sorting the M-K+1th to Mth elements of the vector, and the resulting row vector of length K is shared by [[ → u i ]](i=1, …, N) to calculate the share [[U]] A secret attribute selection system comprising:
4. 2. The secret attribute selection system of claim 1, The first vector calculation means share[[ → s i ]] to a row vector of length K → h i (however, → h i teeth → s i The element with the best evaluation value is 1, and the other elements are 0.) → h i ]] and calculate the share [[ → u i ]] and share [[ → h i ]]from → u i and → h i The dot product of → u i * → h i Share of [[ → u i * → h i ]] and calculate [[z i ]]=[[ → u i * → h i ]] (i=1, …, N), the share [[ → Calculate z] A secret attribute selection system comprising:
5. N (N is an integer greater than or equal to 1) is the number of data, M (M is an integer greater than or equal to 1) is the number of attributes that make up the data, X=( → x 1 , …, → x N ) t (however, → x i (i=1, …, N) is a row vector of length M representing the i-th data, and N data → x 1 , …, → x N are grouped into a predetermined number of groups, and data belonging to the same group are arranged adjacently) → x 1 , …, → x N An N-by-M matrix representing → g=(g 1 , …, g N ) t (However, g i (i=1, …, N) is the i-th data → x i If it is the first data in a group, it is 1; otherwise, it is 0. → x 1 , …, → x N Let be a column vector of length N representing the group, N pieces of data → x 1 , …, → x N The matrix X represents the share [[X]] and N data → x 1 , …, → x N A column vector representing the groups into which → g share[[ → g]], the i-th data → x i The number of the attribute with the best evaluation value among K randomly selected attributes (K is an integer between 1 and M) in the group to which z belongs is the i-th element z. i A column vector of length N → z=(z 1 , …, z N ) t Share of [[ → A secret attribute selection device in a secret attribute selection system consisting of three or more secret attribute selection devices that calculates share[[ → Using the N-row M-column matrix E=( → e 1 , …, → e N ) t (however, → e i (i=1, …, N) is the i-th data → x i is a row vector of length M representing K randomly selected attributes in the group to which → e i j-th element e of i,j a first matrix calculation unit that calculates the share [[E]] of the j-th attribute (where E is 1 if the j-th attribute is the selected attribute and 0 otherwise); V=( → v 1 , …, → v N ) t (however, → v i (i=1, …, N) is the i-th data → x i Let (1, 2, …, M) be a row vector of length M in which the attribute numbers of Using the share [[E]], we can get the matrix Y = ( → y 1 , …, → y N ) t (however, → y i (i=1, …, N) is the i-th data → x i The i-th data for K randomly selected attributes in the group to which → x i The share [[Y]] of the attribute is a row vector of length K in which the values of the attributes are arranged in numerical order. The share [[V]] is then converted into an N-by-K matrix U=( → u 1 , …, → u N ) t (however, → u i (i=1, …, N) is the i-th data → x i The share of (a row vector of length K that lists the numbers of K randomly selected attributes in the group to which ) belongs, sorted in attribute number order. a second matrix calculation unit for calculating [[U]], From the share [[Y]], we get the N-row K-column matrix S=( → s 1 , …, → s N ) t (however, → s i (i=1, …, N) is the i-th data → x i a third matrix calculation unit that calculates the share [[S]] of the group to which the attribute belongs, where the attribute is a row vector of length K in which the attribute is a randomly selected attribute and the attribute is arranged in the order of the attribute numbers; Using share [[Y]] and share [[U]], share [[S]] is converted to share [[ → a first vector calculation unit that calculates A secret attribute selection device including:
6. N (N is an integer greater than or equal to 1) is the number of data, M (M is an integer greater than or equal to 1) is the number of attributes that make up the data, X=( → x 1 , …, → x N ) t (however, → x i (i=1, …, N) is a row vector of length M representing the i-th data, and N data → x 1 , …, → x N are grouped into a predetermined number of groups, and data belonging to the same group are arranged adjacently) → x 1 , …, → x N An N-by-M matrix representing → g=(g 1 , …, g N ) t (However, g i (i=1, …, N) is the i-th data → x i If it is the first data in a group, it is 1; otherwise, it is 0. → x 1 , …, → x N Let be a column vector of length N representing the group, A secret attribute selection system consisting of three or more secret attribute selection devices selects N data → x 1 , …, → x N The matrix X represents the share [[X]] and N data → x 1 , …, → x N A column vector representing the groups into which → g share[[ → g]], the i-th data → x i The number of the attribute with the best evaluation value among K randomly selected attributes (K is an integer between 1 and M) in the group to which z belongs is the i-th element z. i A column vector of length N → z=(z 1 , …, z N ) t Share of [[ → 2. A secret attribute selection method for computing z]], comprising: The secret attribute selection system is → Using the N-row M-column matrix E=( → e 1 , …, → e N ) t (however, → e i (i=1, …, N) is the i-th data → x i is a row vector of length M representing K randomly selected attributes in the group to which → e i j-th element e of i,j a first matrix calculation step that calculates the share [[E]] of the jth attribute (where E is 1 if the jth attribute is the selected attribute and 0 otherwise); V=( → v 1 , …, → v N ) t (however, → v i (i=1, …, N) is the i-th data → x i Let (1, 2, …, M) be a row vector of length M in which the attribute numbers of The secret attribute selection system uses the share [[E]] to generate an N-row, K-column matrix Y=( → y 1 , …, → y N ) t (however, → y i (i=1, …, N) is the i-th data → x i The i-th data for K randomly selected attributes in the group to which → x i The share [[Y]] of the attribute is a row vector of length K in which the values of the attributes are arranged in numerical order. The share [[V]] is then converted into an N-by-K matrix U=( → u 1 , …, → u N ) t (however, → u i (i=1, …, N) is the i-th data → x i The share of (a row vector of length K that lists the numbers of K randomly selected attributes in the group to which ) belongs, sorted in attribute number order. a second matrix calculation step for calculating [[U]] respectively; The secret attribute selection system generates an N-by-K matrix S=( → s 1 , …, → s N ) t (however, → s i (i=1, …, N) is the i-th data → x i a third matrix calculation step of calculating the share [[S]] of the group to which the attribute belongs (the group's evaluation values for K randomly selected attributes are arranged in the order of the attribute numbers); The secret attribute selection system selects a share [[Y]] from a share [[S]] using a share [[Y]] and a share [[U]]. → a first vector calculation step of calculating z]]; A secret attribute selection method including:
7. A program for causing a computer to function as the secret attribute selection device according to claim 5.
Citation Information
Patent Citations
Hidden decision tree test device, hidden decision tree test system, hidden decision tree test method, and program
WO2022079911A1