Client device, secret table management system, record registration request generation method, record registration method, processing request execution method, and program
The secret table management system efficiently handles composite attributes by dividing them into multiple attributes and using order-preserving conversions, reducing table size and computation costs for secure computation.
Patent Information
- Application Number
- JP2024534786
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-19
- Publication Date
- 2025-10-01
- Estimated Expiration
- 2042-07-19
AI Technical Summary
Existing secure computation methods for tables with composite attributes face inefficiencies due to large table sizes and high calculation costs when converting composite attribute values to numerical values one-to-one, making it difficult to perform secure computations efficiently.
A secret table management system divides composite attributes into multiple attributes, using one-to-one functions to convert attribute values to numbers while preserving order relations, and employs a multi-party protocol involving multiple secure computing devices for efficient secure computation.
This approach reduces the size of the table representation and lowers computational costs for secure computation on composite attributes, enabling efficient searches and processing requests.
Smart Images

Figure 0007747215000002 
Figure 0007747215000003 
Figure 0007747215000004
Abstract
Description
[Technical Field]
[0001] The present invention relates to a secure computation technology, and more particularly to a secure computation technology for a table including a composite attribute made up of a plurality of attributes. [Background technology]
[0002] Secure computation is a method of obtaining the result of a specified computation without restoring the encrypted numerical value (see, for example, Reference Non-Patent Document 1, Non-Patent Document 1, and Patent Document 1). In the method of Reference Non-Patent Document 1, encryption is performed by distributing multiple pieces of information from which a numerical value can be restored to three secure computing devices, and the results of addition / subtraction, constant sum, multiplication, constant multiplication, logical operations (negation, logical product, logical sum, exclusive OR), and data format conversion (integer, binary number) can be stored in a distributed state, i.e., encrypted, among the three secure computing devices without restoring the numerical value. In general, the number of shares is not limited to 3 and can be W (W is a predetermined constant greater than or equal to 3), and a protocol that realizes secure computation through cooperative computation by W secure computing devices is called a multi-party protocol.
[0003] (Reference Non-Patent Document 1: Koji Senda, Hiroki Hamada, Dai Igarashi, Katsumi Takahashi, “Rethinking Lightweight Verifiable Three-Party Secure Function Computation,” In CSS, 2010.) In secure computation for tables, the attribute values that make up the table are converted to numerical values before operations such as registering records and searching tables are performed. At this time, the attribute values and numerical values are converted so that there is a one-to-one correspondence.
[0004] Among the attributes that make up a table are those called composite attributes, which are made up of multiple attributes. For example, there is the composite attribute "Classification," which is made up of the attribute "Major Category," which can take values from 1 to 20, the attribute "Middle Category," which can take values from A to J, and the attribute "Minor Category," which can take values from 1 to 200, and the composite attribute "Year, Month, and Day," which is made up of the attribute "Year," which can take values from 1900 to 2100, the attribute "Month," which can take values from 1 to 12, and the attribute "Day," which can take values from 1 to 31. For these composite attributes as well, conversions were previously made so that the values of the composite attributes and numerical values simply corresponded one-to-one. [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] Koji Senda, Dai Igarashi, Hiroki Hamada, and Katsumi Takahashi, "Proposal and Implementation Evaluation of Lightweight Three-Party Secure Function Computation with Error Detection," Transactions of Information Processing Society of Japan, Vol. 52, No. 9, pp. 2674-2685, 2011. [Patent documents]
[0006] [Patent Document 1] WO2019 / 203262 Summary of the Invention [Problem to be solved by the invention]
[0007] As described above, if the values of composite attributes are converted so that they simply correspond one-to-one to the numerical values, for example, in the case of the composite attribute "classification," it would be necessary to manage the correspondence using a table containing (number of values of the attribute "major classification") x (number of values of the attribute "middle classification") x (number of values of the attribute "minor classification") = 20 x 10 x 200 = 40,000 records. In other words, there is a problem with composite attributes in that the table for managing the correspondence becomes large.
[0008] For example, when searching for records where the value of the attribute "intermediate category" is A for the composite attribute "category," the values of the composite attribute "category" (1, A, 1), (1, A, 2), ..., (20, A, 200) must each be converted to numeric values using the above table, and then the search must be performed using the 4,000 numeric values obtained by the conversion. In other words, there is a problem with composite attributes: the calculation cost for searches becomes large.
[0009] In other words, if a conversion is used in which the value of a composite attribute and a numerical value simply correspond one-to-one, it is not possible to efficiently perform secure computation on a table that includes composite attributes.
[0010] Therefore, an object of the present invention is to provide a table management technology that can efficiently perform secure computation on tables that include multiple attributes. [Means for solving the problem]
[0011] In one aspect of the present invention, A is divided into M attributes A1, ..., A M Let T be a composite attribute consisting of N attributes A, B1, …, B (N is an integer greater than or equal to 1) including composite attribute A. N-1 Let F be a table consisting of m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of attribute A to a number (except for attribute A) m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), and a secret table calculation system including a secret table management system consisting of W (W is an integer equal to or greater than 3) secret table management server devices that manage a table [T] obtained by concealing table T, and one or more client devices, and a client device in the secret table calculation system, M ) (where α m (m=1, …, M) is attribute A m ) to the attribute values of composite attribute A (F1(α1), …, F M (α M)) and the attribute value converter for generating the attribute values of composite attribute A (F1(α1), …, F M (α M )), attribute value β1 of attribute B1, …, attribute B N-1 Attribute value β of N-1 From the records containing the record, select the record (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 ]), and a record concealer that generates records (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 and a record registration request generating unit that generates a registration request to table [T] of the record registration request table [T].
[0012] In one aspect of the present invention, A is divided into M attributes A1, ..., A M Let T be a composite attribute consisting of N attributes A, B1, …, B (N is an integer greater than or equal to 1) including composite attribute A. N-1 Let F be a table consisting of m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of attribute A to a number (except for attribute A) m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), a secret table management system in a secret table calculation system including W (W is an integer of 3 or more) secret table management server devices that manage a table [T] obtained by concealing table T, and one or more client devices, and M ), attribute value β1 of attribute B1, …, attribute B N-1 Attribute value β of N-1 The redacted records (([α1], …, [α M ]), [β1], …, [β N-1 ]) to table [T], records (([F1(α1)], …, [F M (α M)]), [β1], …, [β N-1 ]), and a record (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 ]) in table [T].
[0013] In one aspect of the present invention, A is divided into M attributes A1, ..., A M Let T be a composite attribute consisting of N attributes A, B1, …, B (N is an integer greater than or equal to 1) including composite attribute A. N-1 Let F be a table consisting of m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of attribute A to a number (except for attribute A) m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), G is a one-to-one function that converts a set of M' numbers (M' is an integer between 2 and M) into one number (where function G is a function that preserves the order relation), and a secret table management system in a secret table calculation system including W (W is an integer of 3 or more) secret table management server devices that manage a table [T] obtained by concealing table T, and one or more client devices, wherein [r] is a record obtained by concealing record r included in table T, m attribute A of record r m The processing request from the client device represents the attribute value of M' attributes A that make up the composite attribute A. i_1 , …, A i_M’ (i1, …, i M’ is 1≦i1<… M’ Attribute value α of i_1 , …, α i_M’ (However, α m (m=i1, …, i M’ ) is attribute A m If the search is for an attribute A, i_1 , …, A i_M’ Attribute value [Fi_1 (α i_1 )], …, [F i_M’ (α i_M’ )] for the value of function G([F i_1 (α i_1 )], …, [F i_M’ (α i_M’ )]) and attribute A of record [r] in table [T] i_1 , …, A i_M’ attribute value [r i_1 ], …, [r i_M’ ] the value of the function G for [r i_1 ], …, [r i_M’ ]) and executes a search, and a processing request from the client device is i_1 , …, A i_M’ (i1, …, i M’ is 1≦i1<… M’ ≦M), attribute A of record [r] in table [T] i_1 , …, A i_M’ attribute value [r i_1 ], …, [r i_M’ ] the value of the function G for [r i_1 ], …, [r i_M’ ]) and executes the secret sort. [Effects of the Invention]
[0014] According to the present invention, it is possible to efficiently perform secure computation on a table including composite attributes. [Brief explanation of the drawings]
[0015] [Figure 1] FIG. 1 is a block diagram showing the configuration of a secret table calculation system 10. [Figure 2] FIG. 1 is a block diagram showing the configuration of a client device 100v (1≦v≦V). [Figure 3] FIG. 10 is a block diagram showing the configuration of a secret table management server device 200w (1≦w≦W). [Figure 4] 10 is a flowchart showing the operation of a client device 100v (1≦v≦V) in record registration. [Figure 5] 10 is a flowchart showing the operation of the private table management system 20 in record registration. [Figure 6] 10 is a flowchart showing the operation of a client device 100v (1≦v≦V) in executing a processing request. [Figure 7] 10 is a flowchart showing the operation of the secret table management system 20 in executing a processing request. [Figure 8] FIG. 1 is a block diagram showing the configuration of a client device 100v (1≦v≦V). [Figure 9] FIG. 10 is a block diagram showing the configuration of a secret table management server device 200w (1≦w≦W). [Figure 10] 10 is a flowchart showing the operation of a client device 100v (1≦v≦V) in record registration. [Figure 11] 10 is a flowchart showing the operation of the private table management system 20 in record registration. [Figure 12] FIG. 2 is a diagram illustrating an example of the functional configuration of a computer that realizes each device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0016] Hereinafter, embodiments of the present invention will be described in detail. Components having the same functions are given the same numbers, and duplicated explanations will be omitted.
[0017] Before describing each embodiment, the notation used in this specification will be explained.
[0018] ^ (caret) represents a superscript, e.g., x y^z Yes z is a superscript to x, and x y^z Yes z is a subscript to x. Also, _ (underscore) represents a subscript. For example, xy_z Yes z is a superscript to x, and x y_z Yes z is a subscript to x.
[0019] For a character x → x, ^x, and ~x → ", "^" and "~" should be written directly above the "x", but due to limitations on the description in the specification, → These are written as x, ^x or ~x.
[0020] <Technical background> <<Secure calculation>> The secure computation in the present invention is constructed by combining existing secure computation operations. The operations required for this secure computation include, for example, concealment, addition, subtraction, multiplication, division, logical operations (negation, logical AND, logical OR, exclusive OR), comparison operations (=, <, >, ≦, ≧), and secure sorting. Below, we will explain some of the operations, including their notations.
[0021] Secure computation on a table can be realized by regarding the table as a matrix, the columns of attribute values of the table as column vectors, and the records of the table as row vectors.
[0022] [Redacted] Let [x] be the value of x concealed by secret sharing (hereinafter referred to as a share of x). Any secret sharing method can be used. For example, 61 -1) Shamir secret sharing on Z2 and replication secret sharing on Z2 can be used.
[0023] Multiple secret sharing methods may be combined within a single algorithm. In this case, they will be converted into each other as appropriate.
[0024] Also, N-dimensional vector → x=(x1, …, x N ) and [ → x]=([x1], …, [xN ]) in other words, [ → x] is → The nth element of x, x n Share of [x n ] is a vector with n-th element. Similarly, M×N matrix A=(a m,n )(1≦m≦M, 1≦n≦N), [A] is also the (m, n)th element of A, a m,n Share of [a m,n ] is the matrix whose element is (m, n).
[0025] Note that x is called the plaintext of [x].
[0026] Specific examples of a method for obtaining [x] from x (concealment) and a method for obtaining x from [x] (restoration) are described in Reference Non-Patent Document 1 and Reference Non-Patent Document 2.
[0027] (Reference Non-Patent Document 2: Shamir, A., "How to share a secret", Communications of the ACM, Vol. 22, No. 11, pp. 612-613, 1979.) [Addition, Subtraction, Multiplication, Division] Secure addition [x]+[y] takes [x] and [y] as input and outputs [x+y]. Secure subtraction [x]-[y] takes [x] and [y] as input and outputs [xy]. Secure multiplication [x]×[y] (sometimes expressed as mul([x], [y])) takes [x] and [y] as input and outputs [x×y]. Secure division [x] / [y] (sometimes expressed as div([x], [y])) takes [x] and [y] as input and outputs [x / y].
[0028] Specific methods for addition, subtraction, multiplication, and division include those described in Reference Non-Patent Documents 3 and 4.
[0029] (Reference Non-Patent Document 3: Ben-Or, M., Goldwasser, S. and Wigderson, A., “Completeness theorems for non-cryptographic fault-tolerant distributed computation”, Proceedings of the twentieth annual ACM symposium on Theory of computing, ACM, pp. 1-10, 1988.) (Reference Non-Patent Document 4: Gennaro, R., Rabin, MO and Rabin, T., “Simplified VSS and fast-track multiparty computations with applications to threshold cryptography”, Proceedings of the seventeenth annual ACM symposium on Principles of distributed computing, ACM, pp.101-111, 1998.) [Logical Operations] Secure negation not[x] takes [x] as input and outputs [not(x)]. Secure logical conjunction and([x], [y]) takes [x] and [y] as input and outputs [and(x, y)]. Secure logical sum or([x], [y]) takes [x] and [y] as input and outputs [or(x, y)]. Secure exclusive OR xor([x], [y]) takes [x] and [y] as input and outputs [xor(x, y)].
[0030] Note that logical operations can be easily configured by combining addition, subtraction, multiplication, and division.
[0031] [Comparison operation] Equality determination by secret calculation =([x], [y]) (sometimes denoted as equal([x], [y])) takes [x] and [y] as inputs and outputs [1] if x = y and [0] otherwise. Comparison by secret calculation <([x], [y]) takes [x] and [y] as inputs and outputs [1] if x < y and [0] otherwise. Comparison by secret calculation >([x], [y]) takes [x] and [y] as inputs and outputs [1] if x > y and [0] otherwise. Comparison by secret calculation ≦([x], [y]) takes [x] and [y] as inputs and outputs [1] if x ≦ y and [0] otherwise. Comparison by secret calculation ≧([x], [y]) takes [x] and [y] as inputs and outputs [1] if x ≧ y and [0] otherwise.
[0032] Note that the comparison operation can be easily constructed by combining logical operations.
[0033] [Secret Sort] Secret sort takes an N-dimensional vector → x=(x1, …, x N )'s shares → x] as inputs, and → the elements [x1], …, [x N of x] are sorted in ascending order to obtain a vector sort( → x]):=([x i_1 , …, [x i_N ) (where x [[ID=2K]] i_1 i_N is x i_1 ≦x i_2 ≦ … ≦x i_N is satisfied) as the output. Also, for a table [T] obtained by anonymizing table T, the table obtained by secretly sorting table [T] with the attribute A of table [T] as the key is a table in which the records are swapped for each record so that the values of the elements of attribute A are in ascending order from the first record.
[0034] As a specific method of secret sorting, there is a method described in Reference Non-Patent Document 5.
[0035] (Reference Non-Patent Document 5: Dai Igarashi, Hiroki Hamada, Ryo Kikuchi, and Koji Senda, “Design and Implementation of Ultra-High-Speed Secure Computation Sorting: The Day Secure Computation Stands on Par with Scripting Languages,” Computer Security Symposium (CSS), 2017.) [Secret combination] TL is a key attribute Key and attributes B1, …, B M (M is an integer greater than or equal to 1), TR is a table consisting of a key attribute Key and attributes C1, …, C N (N is an integer equal to or greater than 1). In this case, a table TC obtained by equijoining table TL and table TR with respect to the key attribute Key is a table consisting of the key attribute Key and attributes B1, ..., B M and key attribute Key and attributes C1, …, C N It is a table consisting of
[0036] Equijoins can be defined similarly for table [TL], which is a table TL anonymized, and table [TR], which is a table TR anonymized. That is, the key attribute Key and attributes B1, ..., B M The table TL is a table [TL] that is anonymized by adding the key attribute Key and the attributes C1, …, C N Table [TR] is a table that is anonymized from table TR, and table [TL] and table [TR] are secretly joined with respect to the key attribute Key to obtain table [TC], which is a table that has the key attribute Key and attributes B1, ..., B M and key attribute Key and attributes C1, …, C N It is a concealed version of the table TC, which is composed of the above.
[0037] A specific method for secret equal binding is the method described in Patent Document 1. The method described in Patent Document 1 is a method that allows duplicate values of the key attribute Key of the table TR.
[0038] (Reference Patent Document 1: WO2018 / 061800) First Embodiment Let A be a composite attribute composed of M (M is an integer greater than or equal to 2) attributes A1, …, A M and let T be a table composed of N (N is an integer greater than or equal to 1) attributes A, B1, …, B including the composite attribute A N-1 . Also, let F m (m = 1, …, M) be a one-to-one function that converts the attribute values of attribute A m into numerical values (however, when an order relation is defined on the set of attribute values of attribute A m , the function F m is a function that preserves the order relation). Here, that the function F m is a function that preserves the order relation means that for the attribute values a1, a2 of attribute A m satisfying a1 < a2, F m (a1) < F m (a2) holds. The function F m can be represented as a table composed of records including the attribute values of attribute A m and the numerical values corresponding to those attribute values.
[0039] The secret table calculation system 10 is a system that performs secret calculations on the table [T] obtained by anonymizing the table T.
[0040] Hereinafter, the secret table calculation system 10 will be described with reference to FIGS. 1 to 7. FIG. 1 is a block diagram showing the configuration of the secret table calculation system 10. The secret table calculation system 10 includes V (V is an integer greater than or equal to 1) client devices 1001, …, 100 V and a secret table management system 20. The secret table management system 20 includes W (W is an integer greater than or equal to 3) secret table management server devices 2001, …, 200 W . The client devices 1001, …, 100 V are connected to the network 800 and can communicate with the secret table management system 20. The secret table management server devices 2001, …, 200 Ware connected to a network 800 and can communicate with each other. The network 800 may be, for example, a communication network such as the Internet or a broadcast communication path. v 3 is a block diagram showing the configuration of the secret table management server device 200 (1≦v≦V). w FIG. 4 is a block diagram showing the configuration of the client device 100 in the record registration. v FIG. 5 is a flowchart showing the operation of the private table management system 20 in the record registration. FIG. 6 is a flowchart showing the operation of the client device 100 in the process request execution. v 7 is a flowchart showing the operation of (1≦v≦V) Fig. 7 is a flowchart showing the operation of the secret table management system 20 in executing a processing request.
[0041] As shown in FIG. v attribute value conversion unit 110 v and the record concealment unit 120 v and the record registration request generating unit 130 v and the processing request generation unit 140 v and the transmitting / receiving unit 180 v and recording unit 190 v Recording unit 190 v The client device 100 v The recording unit 190 is a component that records information necessary for the processing of the v For example, the function F m Record (m=1, …, M).
[0042] As shown in FIG. 3, the private table management server device 200 w The record registration unit 210 w and the processing request execution unit 220 w and the transmitting / receiving unit 280 w and recording unit 290 w Transmitter / receiver 280 w and Recording Section 290 w Secret table management server device 200 excluding wEach component of the storage unit 290 is configured to be able to execute operations required to realize the function of each component, such as encryption, addition, subtraction, multiplication, division, logical operation, comparison operation, and secret sorting, which are required for executing a processing request. In the present invention, the specific functional configuration for realizing each operation is sufficient if it is a configuration that can execute an existing algorithm, and since these are conventional configurations, detailed explanations will be omitted. w The secret table management server device 200 w The recording unit 290 is a component that records information necessary for the processing of the w For example, records table [T], which is table T anonymized.
[0043] W secret table management server devices 200 w By the collaborative computation of (1≦w≦W), the secret table management system 20 realizes secure computation for the execution of processing requests, which is a multi-party protocol. Therefore, the record registration means 210 (not shown) of the secret table management system 20 includes record registration units 2101, ..., 210 W The processing request execution means 220 (not shown) is configured as processing request execution units 2201, . . . , 220 W The transmitting / receiving means 280 (not shown) is composed of transmitting / receiving units 2801, . . . , 280 W It consists of:
[0044] [Record Registration] Here, the attribute values of composite attribute A (α1, …, α M ) (where α m (m=1, …, M) is attribute A m ), attribute value β1 of attribute B1, ..., attribute B N-1 Attribute value β of N-1 The following describes how the client device 100 registers the anonymized records obtained from the records containing the anonymized records in the table [T]. v The operation of the secret table management system 20 will be described.
[0045] S110 vIn this case, the attribute value conversion unit 110 v is the attribute value (α1, …, α M ) to find the attribute values of composite attribute A (F1(α1), …, F M (α M )).
[0046] S120 v In the record concealment unit 120 v is S110 v The attribute values of the composite attribute A generated in (F1(α1), …, F M (α M )), attribute value β1 of attribute B1, …, attribute B N-1 Attribute value β of N-1 From the records containing the record, select the record (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 ]).
[0047] S130 v In the record registration request generation unit 130 v is S120 v The records generated by (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 ]) to the table [T], and the sending and receiving unit 180 v The registration request is sent to the secret table management system 20 using the above.
[0048] In S210, the record registration means 210 uses the transmission / reception means 280 to v Records from (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 ]) to table [T], and receives a request to register records (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 ]) into table [T].
[0049] [Execute processing request] Here, the execution of a processing request from a client device will be described. v The operation of the secret table management system 20 will be described.
[0050] S140 v In the above, the processing request generation unit 140 v generates a processing request for the table [T] and sends it to the sending / receiving unit 180 v The processing request is sent to the secret table management system 20 using the above.
[0051] In S220, the processing request execution means 220 transmits the request to the client device 100 using the transmission / reception means 280. v and executes the processing request from the client device 100 using the transmission / reception means 280. v Send the processing results to .
[0052] [r] is the anonymized record of record r in table T, m attribute A of record r m For example, if a processing request is m In the case of searching for a record whose attribute value is a, the processing request execution means 220 executes the following for the record [r] included in the table [T]: m ], [F m (a)]) and calculate =([r m ], [F m (a)]) is [1], and generates a processing result including the record. m In the case of searching for a record whose attribute value is greater than or equal to a1 and less than or equal to a2, the processing request execution means 220 searches for a record [r] included in the table [T] using the condition ≧([r m ], [F m (a1)]) and ≦([r m ], [F m (a2)]) and calculate ≧([r m, [F m (a1)]) and ≤ ([r m , [F m Extract records where both (a2)]) are [1], and generate a processing result including the records.
[0053] Also, when the processing request is related to the composite attribute A, the processing request execution means 220 may use a one-to-one function G (where G is a function that preserves the order relationship) that converts a set of M' (where M' is an integer greater than or equal to 2 and less than or equal to M) numerical values into one numerical value to execute the processing request. Here, that the function G is a function that preserves the order relationship means that for a set of M' numerical values a1, a2 that satisfy a1 < a2, G(a1) < G(a2) holds. As the order relationship in the set of a set of M' numerical values, for example, the lexicographical order can be used. When the processing request is a search regarding the attribute values α i_1 , …, A i_M’ (i1, …, i M’ where 1 ≤ i1 < … < i M’ ≤ M) of A i_1 , …, α i_M’ (however, α m (m = i1, …, i M’ ) are the attribute values of the attribute A m ), the processing request execution means 220 calculates the value G([F i_1 , …, A[[ID=XXX]] i_M’ of the attribute values [F i_1 (α i_1 )], …, [F XXX i_M’ (α i_M’ )] of A i_1 (α i_1 )], …, [F<00S0246>(α i_M’ )]) and the value G([r i_1 , …, A i_M’ of the attribute values [r i_1 , …, [r i_M’ of the records [r] included in the table [T], and may execute the search. Here, G([F i_1 , …, [r i_M’ ) and calculates and executes the search. Here, G([F i_1 (α It seems there are some tags that might be incorrect or incomplete in the original text (e.g., "XXX" in the translated text). Please double-check the original text for accuracy.i_1 )], …, [F i_M’ (α i_M’ )])=[G(F i_1 (α i_1 ), …, F i_M’ (α i_M’ ))], G([r i_1 ], …, [r i_M’ ])=[G(r i_1 , …, r i_M’ )]. In addition, the processing request is a set of M' attributes A that make up the composite attribute A. i_1 , …, A i_M’ (i1, …, i M’ is 1≦i1<… M’ ≦M), the processing request execution means 220 executes the sorting for the attribute A of the record [r] included in the table [T]. i_1 , …, A i_M’ attribute value [r i_1 ], …, [r i_M’ ] the value of the function G for [r i_1 ], …, [r i_M’ ]) and perform a secret sort.
[0054] The function G can be, for example, the following function:
number
[0055] The cost of secure computation of formula (1) is small, and in general, attribute A i_1 , …, A i_M’ It is better to calculate the share of the value of function G for the attribute value of attribute A and then execute the processing request. i_1 , …, A i_M’ This results in a lower computational cost than executing a processing request using a share of the attribute value of the attribute.
[0056] <Modification> In the first embodiment, the client device 100 v However, the attribute value conversion may be performed by the secret table management system 20.
[0057] Hereinafter, the client device 100 in the modified example will be described with reference to FIGS. 8 to 11. v Next, the secret table management system 20 will be described. FIG. 8 shows the configuration of the client device 100. v 9 is a block diagram showing the configuration of the secret table management server device 200 (1≦v≦V). w FIG. 10 is a block diagram showing the configuration of the client device 100 in the record registration. v 11 is a flowchart showing the operation of (1≦v≦V) Fig. 11 is a flowchart showing the operation of the private table management system 20 in record registration.
[0058] As shown in FIG. v The record concealment unit 120 v and the record registration request generating unit 130 v and the processing request generation unit 140 v and the transmitting / receiving unit 180 v and recording unit 190 v Recording unit 190 v The client device 100 v The recording unit 190 is a component that records information necessary for the processing of the v For example, the function F m Record (m=1, …, M).
[0059] As shown in FIG. 9, the private table management server device 200 w attribute value conversion unit 205 w and the record registration unit 210 w and the processing request execution unit 220 w and the transmitting / receiving unit 280 w and recording unit 290 w Transmitter / receiver 280 w and Recording Section 290 w Secret table management server device 200 excluding wEach component of the memory 290 is configured to be able to execute operations required to realize the function of each component, such as encryption, addition, subtraction, multiplication, division, logical operation, comparison operation, secret sorting, and secret combination, among the operations required to execute a processing request. In the present invention, the specific functional configuration for realizing each operation is sufficient if it is a configuration that can execute existing algorithms, and since these are conventional configurations, detailed explanations will be omitted. w The secret table management server device 200 w The recording unit 290 is a component that records information necessary for the processing of the w For example, table [T] is a table T that has been anonymized, and function F m Record (m=1, …, M).
[0060] W secret table management server devices 200 w By the collaborative computation of (1≦w≦W), the secret table management system 20 realizes secure computation for the execution of processing requests, which is a multi-party protocol. Therefore, the attribute value conversion means 205 (not shown) of the secret table management system 20 includes attribute value conversion units 2051, ..., 205 W The record registration means 210 (not shown) is composed of record registration units 2101, . . . , 210 W The processing request execution means 220 (not shown) is configured as processing request execution units 2201, . . . , 220 W The transmitting / receiving means 280 (not shown) is composed of transmitting / receiving units 2801, . . . , 280 W It consists of:
[0061] [Record Registration] Here, the attribute values of composite attribute A (α1, …, α M ) (where α m (m=1, …, M) is attribute A m ), attribute value β1 of attribute B1, ..., attribute B N-1 Attribute value β of N-1 The following describes how the client device 100 registers the anonymized records obtained from the records containing the anonymized records in the table [T].v The operation of the secret table management system 20 will be described.
[0062] S120 v In the record concealment unit 120 v is the attribute value (α1, …, α M ), attribute value β1 of attribute B1, …, attribute B N-1 Attribute value β of N-1 From the records containing the record, select the record ([α1], …, [α M ]), [β1], …, [β N-1 ]).
[0063] S130 v In the record registration request generation unit 130 v is S120 v The records (([α1], …, [α M ]), [β1], …, [β N-1 ]) to the table [T], and the sending and receiving unit 180 v The registration request is sent to the secret table management system 20 using the above.
[0064] In S205, the attribute value conversion means 205 transmits the attribute value to the client device 100 using the transmission / reception means 280. v Records from (([α1], …, [α M ]), [β1], …, [β N-1 ]) to table [T], and receives a request to register records (([α1], …, [α M ]), [β1], …, [β N-1 ]) to record (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 The attribute value conversion means 205 generates, for example, a record (([α1], ..., [α M ]), [β1], …, [β N-1 ]) and a function F mBy applying a secret equijoin to the anonymized table, the table representing the records (([F1(α1)], …, [F M (α M )]), [β1], …, [β N-1 ]) can be generated.
[0065] In S210, the record registration means 210 registers the records ([F1(α1)], ..., [F M (α M )]), [β1], …, [β N-1 ]) into table [T].
[0066] According to an embodiment of the present invention, it is possible to efficiently perform secure computation on a table including a composite attribute. By using a conversion that ensures a one-to-one correspondence between the values of each attribute constituting the composite attribute and a numerical value, it is possible to reduce the size of the table representing the function. For example, for the composite attribute "classification," it is sufficient to manage three tables: one containing 20 records, one containing 10 records, and one containing 200 records. It is also possible to reduce the computational cost of searches related to composite attributes. For example, when performing a search for the composite attribute "classification" to extract records in which the attribute "middle classification" has a value of A, it is sufficient to convert the value A of the attribute "middle classification" to a numerical value and then perform a search using the single numerical value obtained by the conversion.
[0067] <Additional Notes> The processing of each unit of each of the above-mentioned devices may be realized by a computer, in which case the processing content of the functions that each device should have is described by a program. Then, by loading this program into the recording unit 2020 of the computer 2000 shown in Fig. 12 and operating the arithmetic processing unit 2010, the input unit 2030, the output unit 2040, the auxiliary recording unit 2025, etc., various processing functions of each of the above-mentioned devices are realized on the computer.
[0068] The device of the present invention may, for example, be a single hardware entity, having an input unit capable of inputting signals from outside the hardware entity, an output unit capable of outputting signals to outside the hardware entity, a communication unit to which a communication device (e.g., a communication cable) can be connected for communication with outside the hardware entity, a CPU (which may also include a central processing unit, cache memory, registers, etc.) as an arithmetic processing unit, RAM and ROM as memories, an external storage device such as a hard disk, and buses connecting these input unit, output unit, communication unit, CPU, RAM, ROM, and external storage device so as to enable data exchange. If necessary, the hardware entity may also be provided with a device (drive) capable of reading and writing to a recording medium such as a CD-ROM. An example of a physical entity equipped with such hardware resources is a general-purpose computer.
[0069] The external storage device of the hardware entity stores the programs required to realize the above-mentioned functions and the data required for processing these programs (the programs may be stored in a ROM, which is a read-only storage device, for example, instead of an external storage device). Data obtained by processing these programs is stored in RAM, the external storage device, etc. as appropriate.
[0070] In the hardware entity, each program stored in an external storage device (or ROM, etc.) and data required for processing each program are loaded into memory as needed, and interpreted, executed, and processed by the CPU as appropriate. As a result, the CPU realizes predetermined functions (each component represented as the above, "... unit," "... means," etc.). In other words, each component in the embodiments of the present invention may be configured by a processing circuitry.
[0071] As described above, when the processing functions of the hardware entities (apparatuses of the present invention) described in the above embodiments are realized by a computer, the processing contents of the functions that the hardware entities should have are described by a program. Then, by executing this program on a computer, the processing functions of the hardware entities are realized on the computer.
[0072] The program describing the processing contents can be recorded on a computer-readable recording medium, such as a non-transitory recording medium, specifically a magnetic recording device, an optical disk, or the like.
[0073] The program may be distributed, for example, by selling, transferring, lending, etc. a portable recording medium such as a DVD or CD-ROM on which the program is recorded. Furthermore, the program may be stored in a storage device of a server computer, and then transferred from the server computer to another computer via a network, thereby distributing the program.
[0074] A computer that executes such a program, for example, first stores the program recorded on a portable recording medium or transferred from a server computer in its own non-transitory storage device, the auxiliary storage unit 2025. Then, when executing a process, the computer loads the program stored in its own non-transitory storage device, the auxiliary storage unit 2025, into the storage unit 2020 and executes processing in accordance with the loaded program. Alternatively, as another execution mode of this program, the computer may load the program directly from a portable recording medium into the storage unit 2020 and execute processing in accordance with the program. Furthermore, each time a program is transferred from a server computer to this computer, the computer may execute processing in accordance with the received program. Alternatively, the server computer may not transfer the program to this computer, but may instead execute the processing function by issuing an execution instruction and obtaining the results, thereby executing the above-described processing through a so-called ASP (Application Service Provider) type service. Note that the program in this embodiment includes information used for processing by a computer that is equivalent to a program (such as data that is not a direct instruction to a computer but has properties that define computer processing).
[0075] Furthermore, in this embodiment, the device is configured by executing a predetermined program on a computer, but at least a part of the processing contents may be realized by hardware.
[0076] The present invention is not limited to the above-described embodiment, and various modifications can be made without departing from the spirit of the present invention.
Claims
1. Attribute A of M A (M is an integer greater than or equal to 2) 1 , …, A M Let T be a composite attribute consisting of N attributes A, B (N is an integer greater than or equal to 1) including composite attribute A. 1 , …, B N-1 Let the table consist of F m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), A client device in a secret table calculation system including a secret table management system consisting of W (W is an integer equal to or greater than 3) secret table management server devices that manage a table [T] obtained by concealing a table T, and one or more client devices, Attribute value of composite attribute A (α 1 , …, α M ) (where α m (m=1, …, M) is attribute A m ) to the attribute value of composite attribute A (F 1 (α 1 ), …, F M (α M )) and an attribute value conversion unit that generates Attribute value of composite attribute A (F 1 (α 1 ), …, F M (α M )), attribute B 1 Attribute value β of 1 ,..., attribute B N-1 Attribute value β of N-1 From the records containing 1 (α 1 )], …, [F M (α M )]), [β 1 ], …, [β N-1 ]), and Record (([F 1 (α 1 )], …, [F M (α M )]), [β 1 ], …, [β N-1 a record registration request generation unit that generates a registration request to table [T] of a client device including:
2. Attribute A of M A (M is an integer greater than or equal to 2) 1 , …, A M Let T be a composite attribute consisting of N attributes A, B (N is an integer greater than or equal to 1) including composite attribute A. 1 , …, B N-1 Let the table consist of F m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), A secret table management system in a secret table calculation system including W (W is an integer of 3 or more) secret table management server devices that manage a table [T] obtained by concealing a table T, and one or more client devices, The attribute value (α 1 , …, α M ), attribute B 1 Attribute value β of 1 ,..., attribute B N-1 Attribute value β of N-1 A record containing a redacted record ([α 1 ], …, [α M ]), [β 1 ], …, [β N-1 ]) to table [T], record (([F 1 (α 1 )], …, [F M (α M )]), [β 1 ], …, [β N-1 ]), and Record (([F 1 (α 1 )], …, [F M (α M )]), [β 1 ], …, [β N-1 ]) to table [T]; Secret table management system including
3. Attribute A of M A's (M is an integer greater than or equal to 2) 1 , …, A M Let T be a composite attribute consisting of N attributes A, B (N is an integer greater than or equal to 1) including composite attribute A. 1 , …, B N-1 Let the table consist of F m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), Let G be a one-to-one function that converts a set of M' numbers (M' is an integer between 2 and M) into a single number (where G is a function that preserves the order relationship), A secret table management system in a secret table calculation system including W (W is an integer of 3 or more) secret table management server devices that manage a table [T] obtained by concealing a table T, and one or more client devices, [r] is the anonymized record of record r in table T, m attribute A of record r m Let 'represent the attribute value of A processing request from a client device is made up of M' attributes A that make up a composite attribute A. i_1 , …, A i_M’ (i 1 , …, i M’ is 1≦i 1 <… M’ ≦M) i_1 , …, α i_M’ (However, α m (m=i 1 , …, i M’ ) is attribute A m If the search is for an attribute A, i_1 , …, A i_M’ Attribute value [F i_1 (α i_1 )], …, [F i_M’ (α i_M’ )] for the value of function G([F i_1 (α i_1 )], …, [F i_M’ (α i_M’ )]) and attribute A of record [r] in table [T] i_1 , …, A i_M’ attribute value [r i_1 ], …, [r i_M’ ] the value of the function G for [r i_1 ], …, [r i_M’ ]) and perform the search, A processing request from a client device is made up of M' attributes A that make up a composite attribute A. i_1 , …, A i_M’ (i 1 , …, i M’ is 1≦i 1 <… M’ ≦M), attribute A of record [r] in table [T] i_1 , …, A i_M’ attribute value [r i_1 ], …, [r i_M’ ] the value of the function G for [r i_1 ], …, [r i_M’ ]) and executes secret sorting; Secret table management system including
4. Attribute A of M A's (M is an integer greater than or equal to 2) 1 , …, A M Let T be a composite attribute consisting of N attributes A, B (N is an integer greater than or equal to 1) including composite attribute A. 1 , …, B N-1 Let the table consist of F m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), A secret table calculation system including a secret table management system configured by W (W is an integer equal to or greater than 3) secret table management server devices that manage a table [T] obtained by concealing a table T, and one or more client devices, Attribute value of composite attribute A (α 1 , …, α M ) (where α m (m=1, …, M) is attribute A m ) to the attribute value of composite attribute A (F 1 (α 1 ), …, F M (α M )) and an attribute value transformation step to generate The client device determines the attribute value (F 1 (α 1 ), …, F M (α M )), attribute B 1 Attribute value β of 1 ,..., attribute B N-1 Attribute value β of N-1 From the records containing 1 (α 1 )], …, [F M (α M )]), [β 1 ], …, [β N-1 ]); and The client device 1 (α 1 )], …, [F M (α M )]), [β 1 ], …, [β N-1 a record registration request generation step for generating a registration request to table [T] of A method for generating a record registration request, including:
5. Attribute A of M A (M is an integer greater than or equal to 2) 1 , …, A M Let T be a composite attribute consisting of N attributes A, B (N is an integer greater than or equal to 1) including composite attribute A. 1 , …, B N-1 Let the table consist of F m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), A secret table management system in a secret table calculation system including W (W is an integer equal to or greater than 3) secret table management server devices that manage a table [T] obtained by concealing a table T, and one or more client devices, The attribute value (α 1 , …, α M ), attribute B 1 Attribute value β of 1 ,..., attribute B N-1 Attribute value β of N-1 A record containing a redacted record ([α 1 ], …, [α M ]), [β 1 ], …, [β N-1 ]) to table [T], record (([F 1 (α 1 )], …, [F M (α M )]), [β 1 ], …, [β N-1 ]), and The secret table management system stores the record (([F 1 (α 1 )], …, [F M (α M )]), [β 1 ], …, [β N-1 ]) to table [T], Record registration methods including.
6. Attribute A of M A's (M is an integer greater than or equal to 2) 1 , …, A M Let T be a composite attribute consisting of N attributes A, B (N is an integer greater than or equal to 1) including composite attribute A. 1 , …, B N-1 Let the table consist of F m (m=1, …, M) is attribute A m A one-to-one function that converts the attribute value of m If an ordering relation is defined for the set of attribute values of m is a function that preserves the order relation), Let G be a one-to-one function that converts a set of M' numbers (M' is an integer between 2 and M) into a single number (where G is a function that preserves the order relationship), A secret table management system in a secret table calculation system including W (W is an integer equal to or greater than 3) secret table management server devices that manage a table [T] obtained by concealing a table T, and one or more client devices, [r] is the anonymized record of record r in table T, m attribute A of record r m Let 'represent the attribute value of A processing request from a client device is made up of M' attributes A that make up a composite attribute A. i_1 , …, A i_M’ (i 1 , …, i M’ is 1≦i 1 <… M’ ≦M) i_1 , …, α i_M’ (However, α m (m=i 1 , …, i M’ ) is attribute A m If the search is for an attribute A, i_1 , …, A i_M’ Attribute value [F i_1 (α i_1 )], …, [F i_M’ (α i_M’ )] for the value of function G([F i_1 (α i_1 )], …, [F i_M’ (α i_M’ )]) and attribute A of record [r] in table [T] i_1 , …, A i_M’ attribute value [r i_1 ], …, [r i_M’ ] the value of the function G for [r i_1 ], …, [r i_M’ ]) and perform the search, A processing request from a client device is made up of M' attributes A that make up a composite attribute A. i_1 , …, A i_M’ (i 1 , …, i M’ is 1≦i 1 <… M’ ≦M), attribute A of record [r] in table [T] i_1 , …, A i_M’ attribute value [r i_1 ], …, [r i_M’ ] the value of the function G for [r i_1 ], …, [r i_M’ ]) and perform a secret sort; A processing request execution method including:
7. A program for causing a computer to function as the client device according to claim 1.
8. 4. A program for causing a computer to function as a secret table management server device constituting the secret table management system according to claim 2.
Citation Information
Patent Citations
Anonymous data providing system, anonymous data device, and method performed thereby
JP2013156719A
Anonymous data providing system, anonymous data device, and method performed thereby
JP2013156720A
Computer-assisted name identification system, device, method, and program
JP2017075994A
Confidential information retrieval system, confidential information retrieval program and confidential information retrieval method
JP2020109447A
Secret aggregation rank system, secure computing device, secret aggregation rank method, and program
WO2019203262A1