Analytical instruments, analytical systems, analytical methods, and programs
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2023-12-05
- Publication Date
- 2026-07-23
AI Technical Summary
Existing data utilization services face challenges in analyzing vehicle data and business data while maintaining the confidentiality of personal and confidential information.
An analysis device and system that utilize homomorphic encryption to encrypt vehicle data and business data, allowing analysis to be performed on encrypted data without decrypting it, while ensuring that only authorized parties can access and decrypt the analysis results.
Enables secure analysis for data utilization services by keeping sensitive data confidential throughout the analysis process, ensuring that only encrypted data is shared and analyzed, and allowing only authorized parties to access the decrypted results.
Abstract
Description
Analysis device, analysis system, customer server, store server, analysis method, encryption method, and recording medium
[0001] The present disclosure relates to an analysis device, an analysis system, a customer server, a store server, an analysis method, an encryption method, and a recording medium.
[0002] There is a technology for providing information about nearby stores to customers in a vehicle. Patent Literature 1 discloses an information processing device that uses information indicating the safety level of visiting and leaving each of a plurality of stores belonging to a predetermined category by using a vehicle to extract at least one store from the plurality of stores in descending order of the safety level for the target vehicle, and provides information encouraging the user in the target vehicle to visit at least one store.
[0003] Japanese Patent Application Laid-Open No. 2020-060426
[0004] There are data utilization services that use vehicle data, but it is difficult to get confidential data such as personal information and confidential information to be provided as is to the computing platform of such data utilization services.
[0005] An example of a purpose of the present disclosure is to provide an analysis device or the like that is capable of analyzing confidential data for data utilization services while keeping the data confidential.
[0006] An analysis device according to one aspect of the present disclosure includes a first acquisition means for acquiring vehicle data, including location information of a vehicle in which a customer rides, from a customer server in a format encrypted using a homomorphic encryption method with an individual key held by the customer server; a second acquisition means for acquiring sales data relating to the business status of each store from a plurality of store servers, the sales data being encrypted using a homomorphic encryption method with a different key for each store server; an analysis means for performing an analysis of each store based on the encrypted vehicle data and the encrypted sales data of each store; a transmission means for transmitting the encrypted analysis results to the customer server and each of the plurality of store servers; a reception means for receiving data obtained by distributively decrypting the encrypted analysis results by the customer server and each of the plurality of store servers using a decryption key corresponding to the encryption key used for encryption; and an output means for outputting the decrypted analysis results.
[0007] An analysis system in one aspect of the present disclosure is an analysis system having the above-mentioned analysis device, a customer server, and multiple store servers, wherein the customer server comprises a data storage means for storing vehicle data, an encryption means for encrypting sales data using a homomorphic encryption method with an encryption key generated by the customer server, an input / output means for transmitting the sales data in encrypted form to the analysis device, and a decryption means for decrypting the encrypted analysis results received from the analysis device using a decryption key of the encryption key pair, and the store servers each comprise a data storage means for storing sales data related to their own store's business, an encryption means for encrypting the sales data using a homomorphic encryption method with an encryption key generated by each of the multiple store servers, an input / output means for transmitting the sales data in encrypted form to the analysis device, and a decryption means for decrypting the encrypted analysis results received from the analysis device using a decryption key of the encryption key pair.
[0008] In one aspect of the present disclosure, the customer server includes a data storage means for storing vehicle data including location information of the vehicle in which the customer rides, an encryption means for encrypting the vehicle data using a homomorphic encryption method with an individual encryption key held by the customer server, an input / output means for transmitting the vehicle data in encrypted form to an analysis device, and a decryption means for decrypting the analysis results in encrypted form received from the analysis device using a decryption key corresponding to the encryption key.
[0009] In one aspect of the present disclosure, a store server includes a data storage means for storing sales data related to the sales status of vehicles at its store, an encryption means for encrypting the sales data using a homomorphic encryption method with an individual encryption key held by the store server, an input / output means for transmitting the sales data in encrypted form to an analysis device, and a decryption means for decrypting the encrypted analysis results received from the analysis device using a decryption key corresponding to the encryption key.
[0010] In one aspect of the present disclosure, an analysis method involves a computer acquiring vehicle data, including location information of a vehicle in which a customer is riding, from a customer server in a format encrypted using homomorphic encryption with an individual key held by the customer server, acquiring business data of each store from multiple store servers, encrypted using homomorphic encryption with a different key for each store server, performing an analysis for each store based on the encrypted vehicle data and the encrypted business data of each store, transmitting the encrypted analysis results to the customer server and each of the multiple store servers, receiving data obtained by distributed decryption of the encrypted analysis results using decryption keys corresponding to the encryption keys used by the customer server and each of the multiple store servers for encryption, and outputting the decrypted analysis results.
[0011] In one aspect of the present disclosure, an encryption method involves a computer storing vehicle data including location information of a vehicle in which a customer is riding, encrypting the vehicle data using a homomorphic encryption method with an individual encryption key held by the computer, transmitting the vehicle data in encrypted form to an analysis device, and decrypting the analysis results in encrypted form received from the analysis device using a decryption key corresponding to the encryption key.
[0012] In one aspect of the encryption method of the present disclosure, a computer stores sales data regarding the sales status of vehicles at its own store, encrypts the sales data using a homomorphic encryption method with an individual encryption key that the computer holds, transmits the sales data in encrypted form to an analysis device, and decrypts the analysis results in encrypted form received from the analysis device using a decryption key that corresponds to the encryption key.
[0013] A recording medium in one aspect of the present disclosure stores a program that causes a computer to execute the following steps: obtain, from a customer server, vehicle data including location information of the vehicle in which the customer is riding, in a format encrypted using a homomorphic encryption method with an individual key held by the customer server; obtain, from multiple store servers, business data of each store encrypted using a homomorphic encryption method with a different key for each store server; perform an analysis of each store based on the encrypted vehicle data and the encrypted business data of each store; send the encrypted analysis results to each of the customer server and the multiple store servers; receive data that has been distributed-decrypted from the encrypted analysis results using a decryption key that corresponds to the encryption key used by the customer server and the multiple store servers; and output the decrypted analysis results.
[0014] According to one example of the effect of the present disclosure, it is possible to analyze confidential data for data utilization services while keeping the data confidential.
[0015] Fig. 1 is a block diagram showing the configuration of an analysis system according to the present disclosure. Fig. 2 is a diagram showing a hardware configuration in which the analysis system according to the present disclosure is realized by a computer device and its peripheral devices. Fig. 3 is a flowchart showing the analysis operation according to the present disclosure. Fig. 4 is an example of an analysis result output according to the present disclosure. Fig. 5 is a block diagram showing the configuration of the analysis system according to the present disclosure.
[0016] Hereinafter, with reference to the drawings, embodiments of an analysis device, an analysis system, a customer server, a store server, an analysis method, an encryption method, a program, and a non-transitory recording medium for recording a program according to the present disclosure will be described in detail. The present embodiments do not limit the disclosed technology.
[0017] 1 is a block diagram showing the configuration of an analysis system 10 according to the present disclosure. The analysis system 10 is a system that performs analysis for data utilization using vehicle data held by a customer server 200 and business data held by multiple store servers 300, each in encrypted form.
[0018] In this disclosure, analysis for data utilization refers to, for example, analysis conducted to solve store management issues or create new businesses. More specific examples of analysis include analysis of customers who are likely to visit a store, or analysis to propose stores, products, or services that match customer preferences. The results of the analysis in this disclosure are provided to, for example, local governments working to revitalize the area or corporations operating stores. The analysis device 100 is assumed to provide travelers in a specific area with information about recommended stores in that area, but this example is not necessarily limited to this. Furthermore, in this disclosure, stores are primarily assumed to be leisure facilities or commercial facilities such as restaurants, but are not limited thereto.
[0019] 1 , an analysis system 10 includes an analysis device 100, a customer server 200, and multiple store servers 300i (i = 1, ..., k). The analysis device 100 is owned, for example, by a data utilization service provider. The analysis device 100 performs analysis of the store using vehicle data acquired from the customer server 200 and sales data acquired from each of the multiple store servers in a format encrypted using homomorphic encryption. In the present disclosure, the analysis device 100 includes a first acquisition unit 101, a second acquisition unit 102, an analysis unit 103, a transmission unit 104, a reception unit 105, and an output unit 106.
[0020] The customer server 200 is, for example, a terminal owned by the customer or a car navigation system or a drive recorder installed in the vehicle. The vehicle data includes at least the vehicle's location information, and may also include information such as the vehicle's speed, departure point, or destination.
[0021] The store server 300 is a server owned by a person who manages the business data of each store. The business data may be any data that can grasp the business status of the store, such as the degree of congestion or sales data of the store. The degree of congestion may be, for example, the seat vacancy rate, waiting time to enter the store, or the number of customers.
[0022] 2 is a diagram showing an example of a hardware configuration in which the analysis device 100 according to the present disclosure is realized by a computer device 500 including a processor. As shown in FIG. 2, the analysis device 100 includes a central processing unit (CPU) 501, memories such as a read-only memory (ROM) 502 and a random access memory (RAM) 503, a storage device 505 such as a hard disk for storing a program 504, a communication interface (I / F) 508 for network connection, and an input / output interface 511 for inputting and outputting data. In the present disclosure, vehicle data received from the customer server 200 and sales data received from each store server 300 are input to the analysis device 100 via the communication I / F 508.
[0023] The CPU 501 runs an operating system to control the entire analysis apparatus 100 according to the present disclosure. The CPU 501 also reads programs and data into memory from a recording medium 506 attached to, for example, a drive device 507. The CPU 501 also functions as the first acquisition unit 101, the second acquisition unit 102, the analysis unit 103, the transmission unit 104, the reception unit 105, and the output unit 106 according to the present disclosure, or as part of these units, and executes processing or commands in the flowchart shown in FIG. 3, which will be described later, based on the program.
[0024] The recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. A part of the recording medium in the storage device is a non-volatile storage device, and the program is recorded therein. The program may also be downloaded from an external computer (not shown) connected to a communication network.
[0025] The input device 509 is realized by, for example, a mouse, a keyboard, built-in key buttons, etc., and is used for input operations. The input device 509 is not limited to a mouse, a keyboard, or built-in key buttons, and may be, for example, a touch panel. The output device 510 is realized by, for example, a display, and is used to check output.
[0026] As described above, the analysis device 100 shown in FIG. 1 is realized by the computer hardware shown in FIG. 2. However, the means for realizing each unit of the analysis device 100 in FIG. 1 are not limited to the configuration described above. Furthermore, the analysis device 100 may be realized by a single physically coupled device, or by two or more physically separate devices connected by wire or wirelessly. For example, the input device 509 and the output device 510 may be connected to the computer device 500 via a network. Furthermore, the analysis device 100, customer server 200, and store server 300 shown in FIG. 1 may be configured using cloud computing or the like.
[0027] <Analysis Device 100> First, the analysis device 100 of the present disclosure will be described. The first acquisition unit 101 is a means for acquiring vehicle data, including location information of a vehicle in which a customer rides, from the customer server 200 in a format encrypted by homomorphic encryption using an individual key held by the customer server 200.
[0028] The second acquisition unit 102 is a means for acquiring, from a plurality of store servers 300, business data relating to the business status of each store, encrypted by homomorphic encryption using a key that differs for each store server.
[0029] Homomorphic encryption is a public key encryption method that has homomorphic properties, and operations performed on the ciphertext are maintained even after decryption. In the present disclosure, by encrypting vehicle data and sales data using homomorphic encryption, analysis operations are performed in the encrypted format by the analysis device 100, and analysis results are obtained in encrypted format. This allows the vehicle data provided by customers and the sales data provided by stores to be analyzed while remaining confidential from other data providers and analysts.
[0030] The first acquisition unit 101 and the second acquisition unit 102 each receive vehicle data and business data in a format encrypted by homomorphic encryption via a network, for example, triggered by an operation to perform analysis, and output each data to the analysis unit 103. The first acquisition unit 101 may further acquire, as vehicle data, the distance traveled by the vehicle from a predetermined time ago. Then, the first acquisition unit 101 outputs the vehicle data to the analysis unit 103 when the distance traveled by the vehicle is less than a predetermined distance. In this case, the analysis unit 103 performs analysis only when the distance traveled by the vehicle is less than the predetermined distance and the customer is caught in traffic, for example.
[0031] The analysis unit 103 is a means for performing an analysis of each store based on the encrypted vehicle data, customer information, and encrypted business data of each store. For example, the analysis unit 103 performs an analysis of a store to recommend to a customer from among multiple stores based on the encrypted vehicle data and the encrypted business data of each store. For example, the analysis unit 103 extracts stores that the customer can easily drop by or that the customer wants to visit, based on the location of the customer's vehicle and the store's congestion level. Specifically, the analysis unit 103 extracts, for example, stores within a predetermined range from the vehicle's driving position that have a congestion level or current sales below a predetermined value. Furthermore, the analysis unit 103 may extract stores that can be reached from the vehicle's driving position within a predetermined time and have a congestion level or current sales below a predetermined value.
[0032] The analysis unit 103 may perform the analysis using an analytical model used to perform analysis on each store. The analysis unit 103 may analyze the vehicle data and the sales data in encrypted form by, for example, inputting the encrypted vehicle data and the encrypted sales data of each store into an analytical model that has been machine-learned in advance. The analytical model is stored in, for example, the storage device 505. The analytical model may also be used in a form encrypted using homomorphic encryption.
[0033] The analysis unit 103 may also perform analysis using multiple analytical models. In this case, the analysis unit 103 may integrate (ensemble) the results calculated by each analytical model. The method for integrating the results calculated by each analytical model is not particularly limited, and may be, for example, averaging or majority voting. The analysis unit 103 may also integrate parameters of multiple analytical models using homomorphic encryption. A known method can be used as the parameter integration method. For example, when integrating, the weight of the parameters corresponding to each model may be changed depending on the characteristics of each model.
[0034] The transmission unit 104 is a means for transmitting the encrypted analysis results to the customer server 200 and each of the multiple store servers 300. In the present disclosure, the customer server 200 and each store server 300 possess a decryption key for decrypting the analysis results that they themselves encrypted. When the customer server 200 and each store server 300 receive the encrypted analysis results, they perform distributed decryption of the encrypted analysis results using their own decryption key, and transmit the distributed decrypted analysis results to the analysis device 100 or the server device that requested the analysis. With this method, the analysis device 100 or the server device that requested the analysis can obtain the analysis results, but they do not know the contents of the vehicle data or the sales data of each store.
[0035] The transmitting unit 104 may transmit the analysis results only to the customer server 200 and the store server 300 that have accepted the distributed decryption. In this case, for example, the transmitting unit 104 transmits a message to each of the customer server 200 and the multiple store servers 300 to request distributed decryption before sending the analysis results. This message includes, for example, a button for transmitting a response indicating whether or not to accept the distributed decryption. Then, the transmitting unit 104 transmits the analysis results to the customer server 200 and the multiple store servers 300 that have received a response indicating that they accept the distributed decryption.
[0036] The receiving unit 105 decodes the analysis result by combining the results of the distributed decoding performed by the customer server 200 and each store server 300. The specific operation of the receiving unit 105 will be described later.
[0037] The output unit 106 is a means for displaying the decoded analysis results on a display device such as a display etc. The output unit 106 may output store information recommended to the customer based on the analysis results.
[0038] (Customer server 200) Customer server 200 includes a data storage unit 201 that stores vehicle data including location information of the vehicle in which the customer rides, an encryption unit 202 that encrypts the vehicle data stored in data storage unit 201 using a homomorphic encryption method, an input / output unit 203 that transmits the vehicle data in encrypted form to analysis device 100, a key generation unit 204 that generates an encryption key and a decryption key, an encryption key storage unit 205 that stores the encryption key generated by key generation unit 204, a decryption key storage unit 206 that stores the decryption key generated by key generation unit 204, and a decryption unit 207 that decrypts the analysis results in encrypted form received from analysis device 100 using the decryption key.
[0039] (Store Server 300) Each store server 300 includes a data storage unit 301i (i = 1, ..., k) that stores sales data for each store, an encryption unit 302i (i = 1, ..., k) that encrypts the sales data stored in the data storage unit 301i using a homomorphic encryption method, an input / output unit 303i (i = 1, ..., k) that transmits the sales data in encrypted form to the analysis device 100, a key generation unit 304i (i = 1, ..., k) that generates an encryption key and a decryption key, an encryption key storage unit 305i (i = 1, ..., k) that stores the encryption key generated by the key generation unit 304, a decryption key storage unit 306i (i = 1, ..., k) that stores the decryption key generated by the key generation unit 304, and a decryption unit 307i (i = 1, ..., k) that decrypts the encrypted analysis results received from the analysis device 100 using the decryption key. The number of store servers 300 provided is equal to the number (k) of stores that provide business data.
[0040] The key generation unit 204 generates a key pair of an encryption key and a decryption key of a homomorphic public key cryptosystem. The key generation unit 204 generates the key pair of an encryption key and a decryption key using various known techniques and stores them in the encryption key storage unit 205 and the decryption key storage unit 206, respectively (multi-key homomorphic encryption).
[0041] Similarly, the key generation unit 304 generates a key pair of an encryption key and a decryption key using a homomorphic public key cryptosystem, and stores them in the encryption key memory unit 305 and the decryption key memory unit 306 of each store server 300, respectively (multi-key homomorphic encryption).
[0042] Alternatively, the store server 300 may generate a composite key by combining the encryption keys generated by the key generation unit 304 (threshold homomorphic encryption). In this case, each key generation unit 304 transmits the generated encryption key to the key generation unit 304 of one of the store servers 300. The key generation unit 304 that receives the encryption key from another store server 300 generates a composite key of the encryption keys using a known method. The store server 300 that generates the composite key may be predetermined or selected randomly.
[0043] The decryption units 207, 307 use the decryption key to perform distributed decryption of the encrypted analysis results received from the analysis device 100. The input / output units 203, 303 then transmit the distributed decryption results to a device that wishes to obtain the decrypted analysis results. In this embodiment, a case will be described in which the device that wishes to obtain the decrypted analysis results is the analysis device 100, but the device may also be a server device owned by a party that requests analysis other than the analysis device 100.
[0044] In the customer server 200 and each store server 300, the decryption units 207, 307 communicate with each other and perform distributed decryption of the analysis results using a decryption key corresponding to the encryption key used to encrypt the data they provided. In this disclosure, distributed decryption does not mean dividing a ciphertext corresponding to a single piece of data into multiple parts, but rather means that each store server 300 calculates a distributed decryption result in the sense of an "incomplete decryption result." The analysis device 100 or the server device of the analysis requester combines the distributed decryption results, which are incomplete decryption results, to obtain a completely decrypted analysis result.
[0045] Here, an example of a shared decryption method in multi-key homomorphic encryption or threshold homomorphic encryption in the customer server 200 and each store server 300 will be described. The shared decryption method described below employs the method described in Chen et al., "Efficient Multi-Key Homomorphic Encryption with Packed Ciphertexts with Application to Oblivious Neural Network Inference," CCS'19. However, this shared coding method is only an example, and a different method may also be used. The customer server 200 and each store server 300i (i = 1, ..., k) each use a decryption key s k+1、 Decryption key s i In addition, the ciphertext ct has integer coefficients as shown in the following formula (1), and (X n +1) is the polynomial ring.
[0046] In addition, in formula (1), when q is an integer, it is expressed as Rq = R / (q·R), and the coefficient has a value on mod q, and (X n +1). For simplicity, in this disclosure, it is assumed that k+1 (devices each having k+1 decryption keys) are involved in the calculation, and ct is the ciphertext of the calculation result.
[0047] The first acquisition unit 101 acquires the ciphertext from the customer server 200, and the second acquisition unit 102 acquires the ciphertext from each store server 300i (i=1, . . . , k). The analysis unit 103 analyzes the ciphertext while it is still encrypted, and converts the ciphertext of the analysis result into ct=(c 0 , c 1 , ..., c k , c k+1 ) c k+1 indicates the ciphertext from the customer server 200. Then, the transmission unit 104 transmits the ciphertext to the customer server 200 and the store server 300i (i=1, . . . , k). i (i=1, . . . , k, k+1) are transmitted to the client server 200. Then, the decryption unit 207 of the client server 200 transmits the decryption key s k+1 The decryption unit 307 of each store server 300 decrypts the decryption key s iSpecifically, the customer server 200 and each store server 300 perform distributed decryption using the distributed decryption result μ i is calculated by the formula (2). In the formula (2), e i is noise sampled from the noise distribution φ. Each decoding unit 307 transmits the results of these distributed decoding operations to the analysis device 110.
[0048]
[0049] Next, the receiving unit 105 of the analysis device 100 combines and decodes the distributed decoded results received from the customer server 200 and each store server 3000. Specifically, the receiving unit 105 receives μ i is obtained from the customer server 200 and each store server 300, and the plaintext m is calculated using equation (3).
[0050] however,
[0051] Note that equation (4) indicates the value of x rounded off to the nearest whole number, and when t is an integer in equation (3), the plaintext m∈R t is.
[0052] The operation of the analysis system 11 configured as above will be described with reference to the flowchart of FIG.
[0053] 3 is a flowchart showing an outline of the operation of the analysis system 10 according to the present disclosure. The processing according to this flowchart may be executed based on program control by the processor described above. Furthermore, the flow (S101) for generating a key pair by the key generation unit 204 and the flow (S102) for encrypting vehicle data by the encryption unit 202 do not need to be executed consecutively. Similarly, the flow (S104) for generating a key pair by the key generation unit 304 and the flow (S105) for encrypting business data by the encryption unit 302 do not need to be executed consecutively.
[0054] 3 , in the customer server 200, the key generation unit 204 generates a key pair of an encryption key and a decryption key, and stores the key pair in the encryption key storage unit 205 and the decryption key storage unit 206, respectively (step S101). Next, the encryption unit 202 encrypts the vehicle data stored in the data storage unit 201 using the encryption key by homomorphic encryption (step S102). Next, the input / output unit 203 transmits the vehicle data in encrypted form to the analysis device 100 (step S103).
[0055] Then, in each of the store servers 300, the key generation unit 304 generates a key pair of an encryption key and a decryption key, and stores the key pair in the encryption key storage unit 305 and the decryption key storage unit 306 (step S104). Next, the encryption unit 302 encrypts the sales data stored in the data storage unit 301 using the encryption key by homomorphic encryption (step S105). Next, the input / output unit 303 transmits the encrypted sales data to the analysis device 100 (step S106).
[0056] In the analysis device 100, the first acquisition unit 101 acquires vehicle data in encrypted format from the customer server 200 (step S107). The second acquisition unit 102 acquires business data related to business conditions in encrypted format from the multiple store servers 300 (step S108). Next, the analysis unit 103 performs analysis for each store based on the encrypted vehicle data and the encrypted business data for each store (step S109). Next, the transmission unit 104 transmits the encrypted analysis results to the customer server and the multiple store servers (step S110).
[0057] Again, in the customer server 200, the input / output unit 203 receives the analysis result in encrypted form (step S111). Next, the decryption unit 207 performs shared decryption of the encrypted analysis result using the decryption key stored in the decryption key storage unit 206 (step S112). Next, the input / output unit 203 transmits the shared decrypted analysis result to the analysis device 100 (step S113).
[0058] In each of the store servers 300, the input / output unit 303 receives the encrypted analysis result (step S114). Next, the decryption unit 307 performs shared decryption of the encrypted analysis result using the decryption key stored in the decryption key storage unit 306 (step S115). Next, the input / output unit 303 transmits the shared decrypted analysis result to the analysis device 100 (step S116).
[0059] Furthermore, in the analysis device 100, the receiving unit 105 combines the results of the distributed decoding of the analysis results performed by the customer server 200 and each store server 300 to decode the analysis results (step S117). Finally, the output unit 106 outputs the decoded analysis results (step S118). This completes the analysis operation of the analysis system 10.
[0060] In the analysis device 100, the analysis unit 103 performs an analysis of each store based on the vehicle data encrypted using the homomorphic encryption method and the sales data of each store encrypted using the homomorphic encryption method. This makes it possible to perform an analysis aimed at a data utilization service while keeping sensitive vehicle data and sales data confidential.
[0061] Furthermore, in the analysis device 100, in the customer server 200, each key generation unit 204 generates a key pair of an encryption key and a decryption key, and the encryption unit 202 encrypts the vehicle data using the individual encryption key generated by the customer server 200. Similarly, in the multiple store servers 300, each key generation unit 304 generates a key pair of an encryption key and a decryption key, and the encryption unit 302 encrypts the business data using the individual encryption key generated by the each store server 300. In this case, the vehicle data and business data cannot be decrypted unless the decryption key paired with the encryption key is used, thereby improving confidentiality.
[0062] [Variation 1 of the First Embodiment] Next, a variation of the first embodiment will be described. In this variation, the first acquisition unit 101 further acquires customer information related to the customer in a format encrypted by homomorphic encryption using an individual key held by the customer server 200. The customer information is, for example, information that influences the customer's attributes such as gender and age, and the customer's preferences for food, entertainment, etc.
[0063] The second acquisition unit 102 further acquires store information relating to the products or services offered by each store from the multiple store servers 300. In the case of a restaurant, the store information is publicly available information such as the store's menu. The second acquisition unit 102 receives the store information in plain text from the multiple store servers 300 without encrypting it. In this case, the second acquisition unit 102 receives both encrypted business data and store information in plain text.
[0064] In this modification, the analysis unit 103 performs an analysis of whether a customer matches each store based on the encrypted vehicle data and customer information, the encrypted business data of each store, and the unencrypted store information. In this modification, the analysis of whether a customer matches each store is performed based on the customer information and store information in addition to the vehicle data and business data. In other words, the analysis also analyzes whether a customer's preferences match with the services offered by the store.
[0065] FIG. 4 is an example of an analysis result that is output in the present disclosure. The example of the analysis result in FIG. 4 shows the degree of match between customer X and multiple stores A to C. In the example of FIG. 4, customer X has the highest degree of match with store A, so the output unit 106 outputs a message recommending store A to the customer. However, the analysis result in FIG. 4 is an example, and the analysis result that is output is not limited to this.
[0066] In this modification, the analysis unit 103 performs an analysis of a match between a customer and each store based on the encrypted vehicle data and customer information, and the encrypted business data and store information of each store. This allows the use of more data provided by the customer or store, thereby improving the accuracy of the analysis. In this modification, the analysis unit 103 performs the analysis based on both the customer information and the store information, but the analysis may also be performed based on only at least one of the customer information and the store information.
[0067] [Second Embodiment] Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings. Below, descriptions of content that overlaps with the above description will be omitted to the extent that the description of this embodiment is not unclear. As with the computer device shown in FIG. 2, the functions of each component in each embodiment of the present disclosure can be realized not only by hardware but also by a computer device or software based on program control.
[0068] Fig. 5 is a block diagram showing the configuration of an analysis system 11 including an analysis device 110 according to the present disclosure. The analysis system 11 will be described with reference to Fig. 5, focusing on the differences from the analysis system 10. As shown in Fig. 5, the analysis system 11 differs from the analysis system 10 in that it includes multiple customer servers 210i (i = 1, ..., n). There are as many customer servers 210 as there are vehicles (n) within a predetermined range, such as a specific region.
[0069] In the analysis device 110, the first acquisition unit 111 acquires multiple vehicle data sets from multiple customer servers 210 in a format encrypted using homomorphic encryption. The second acquisition unit 112 acquires multiple sales data sets from multiple store servers 310 in a format encrypted using homomorphic encryption. The analysis unit 113 then performs analysis of store operations based on the encrypted vehicle data sets and the encrypted sales data sets. The components of the analysis device 110 other than those described above are the same as those of the analysis device 100, and therefore will not be described here.
[0070] Analysis of store operations is, for example, an analysis of visits to the store based on the location of vehicles or the number of vehicles, and the analysis results are used by the store for marketing analysis to improve the number of visitors and sales. For example, the store can use the analysis results based on vehicle data such as the number of vehicles around the store and business data such as sales to analyze whether there are no vehicles driving around the store, or whether there are vehicles driving around the store but they are not visiting the store.
[0071] The above-described analysis example is merely an example, and the analysis performed by the analysis unit 113 may be an analysis other than an analysis of store visits. For example, the first acquisition unit 111 further acquires customer information from multiple customer servers 210, and the second acquisition unit 112 further acquires store information from multiple store servers 310. The analysis unit 113 may then perform an analysis regarding the matching of multiple customers with each store based on the encrypted vehicle data and customer information of the multiple customers and the encrypted business data and store information of each store.
[0072] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.
[0073] For example, although multiple operations are described in a sequential order in the form of a flowchart, the order of description does not limit the order in which the multiple operations are performed. Therefore, when implementing each embodiment, the order of the multiple operations can be changed within the scope that does not affect the content.
[0074] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes.
[0075] (Supplementary Note 1) An analysis device comprising: a first acquisition means for acquiring, from a customer server, vehicle data including location information of a vehicle in which a customer rides, in a format encrypted by homomorphic encryption using an individual key held by the customer server; a second acquisition means for acquiring, from a plurality of store servers, sales data relating to the business status of each store, encrypted by homomorphic encryption using a key different for each store server; an analysis means for performing analysis for each store based on the encrypted vehicle data and the encrypted sales data of each store; a transmission means for transmitting the encrypted analysis results to the customer server and each of the plurality of store servers; a reception means for receiving data obtained by distributively decrypting the encrypted analysis results by the customer server and each of the plurality of store servers using a decryption key corresponding to the encryption key used for encryption; and an output means for outputting the decrypted analysis results.
[0076] (Supplementary Note 2) The analysis device described in Supplementary Note 1, wherein the analysis means performs an analysis of a store to recommend to the customer from among a plurality of stores based on encrypted vehicle data and encrypted business data of each store, and the output means outputs information on the store to recommend to the customer based on the analysis results.
[0077] (Supplementary Note 3) The analysis device according to Supplementary Note 1 or Supplementary Note 2, wherein the first acquisition means further acquires a travel distance of the vehicle from a predetermined time ago as the vehicle data, and the analysis means performs the analysis when the travel distance is less than a predetermined distance.
[0078] (Appendix 4) The analysis device described in any of Appendices 1 to 3, wherein the first acquisition means further acquires customer information about the customer in a format encrypted by homomorphic encryption using an individual key held by the customer server, and the analysis means performs analysis regarding matches between customers and each store based on the encrypted vehicle data and customer information and the encrypted business data of each store.
[0079] (Appendix 5) The second acquisition means further acquires store information regarding the products or services offered by each store from a plurality of store servers, and the analysis means performs an analysis regarding matching between customers and stores based on the encrypted vehicle data, the encrypted business data of each store, and the unencrypted store information of each store, in the analysis device described in any one of Appendices 1 to 4.
[0080] (Supplementary Note 6) The analysis device according to Supplementary Note 4 or Supplementary Note 5, wherein the output unit outputs information about a store recommended to the customer based on a degree of match between the customer and the store.
[0081] (Appendix 7) The analysis device described in Appendix 1, wherein the first acquisition means acquires multiple vehicle data of vehicles in which each customer rides from multiple customer servers, and the analysis means performs analysis of store operations based on the encrypted vehicle data of each vehicle and the encrypted business data of each store.
[0082] (Supplementary Note 8) The analysis device according to Supplementary Note 7, wherein the analysis means performs an analysis on customers visiting a store based on the location of the vehicle or the number of vehicles.
[0083] (Supplementary Note 9) The analysis device according to any one of Supplementary Notes 1 to 8, wherein the transmission means transmits the analysis results to each of the customer server and a plurality of store servers that have agreed to the distributed decryption.
[0084] (Supplementary Note 10) The analysis device according to Supplementary Notes 1 to 9, wherein the analysis means performs the analysis using an analytical model used for the analysis.
[0085] (Supplementary Note 11) The analysis device according to Supplementary Note 10, wherein the analysis means performs the analysis using an analytical model in encrypted form.
[0086] (Supplementary Note 12) The analysis device according to Supplementary Note 10 or Supplementary Note 11, wherein the analysis means integrates analysis results obtained by using each of a plurality of analysis models.
[0087] (Supplementary Note 13) An analysis system having the analysis device according to any one of Supplements 1 to 12, a customer server, and a plurality of store servers, wherein the customer server comprises: a data storage means for storing the vehicle data; an encryption means for encrypting the sales data by homomorphic encryption using an encryption key generated by the customer server itself; an input / output means for transmitting the sales data in encrypted form to the analysis device; and a decryption means for decrypting the encrypted analysis results received from the analysis device by a decryption key that is a pair of the encryption keys; and the store servers each comprise: a data storage means for storing sales data relating to the business status of its own store; an encryption means for encrypting the sales data by homomorphic encryption using an encryption key generated by each of the plurality of store servers; an input / output means for transmitting the sales data to the analysis device in encrypted form; and a decryption means for decrypting the encrypted analysis results received from the analysis device by a decryption key that is a pair of the encryption keys.
[0088] (Supplementary Note 14) The analysis system described in Supplementary Note 13, wherein the encryption means in the store server encrypts the sales data using a homomorphic encryption method using a composite key of encryption keys generated by each of the multiple store servers, and the decryption means decrypts the calculated analysis results using a decryption key generated by each of the multiple store servers.
[0089] (Supplementary Note 15) A customer server comprising: a data storage means for storing vehicle data including location information of a vehicle in which a customer rides; an encryption means for encrypting the vehicle data by a homomorphic encryption method using an individual encryption key held by the customer server; an input / output means for transmitting the vehicle data in encrypted form to an analysis device; and a decryption means for decrypting the analysis results in encrypted form received from the analysis device by a decryption key corresponding to the encryption key.
[0090] (Supplementary Note 16) A store server comprising: a data storage means for storing sales data relating to the sales status of vehicles at its own store; an encryption means for encrypting the sales data using a homomorphic encryption method with an individual encryption key held by the store server; an input / output means for transmitting the sales data in encrypted form to an analysis device; and a decryption means for decrypting the analysis results in encrypted form received from the analysis device with a decryption key corresponding to the encryption key.
[0091] (Supplementary Note 17) An analysis method in which a computer: acquires, from a customer server, vehicle data including location information of a vehicle in which a customer rides, in a format encrypted by homomorphic encryption using an individual key held by the customer server; acquires, from multiple store servers, sales data relating to the business status of each store, encrypted by homomorphic encryption using a key different for each store server; performs analysis for each store based on the encrypted vehicle data and the encrypted sales data of each store; sends the encrypted analysis results to the customer server and each of the multiple store servers; receives data obtained by distributively decrypting the encrypted analysis results, each of which is obtained by the customer server and the multiple store servers using a decryption key corresponding to the encryption key used for encryption; and outputs the decrypted analysis results.
[0092] (Supplementary Note 18) An encryption method in which a computer stores vehicle data including location information of a vehicle in which a customer rides, encrypts the vehicle data using a homomorphic encryption method with an individual encryption key held by the computer, transmits the vehicle data in encrypted form to an analysis device, and decrypts the analysis results in encrypted form received from the analysis device using a decryption key corresponding to the encryption key.
[0093] (Supplementary Note 19) An encryption method in which a computer stores sales data relating to the sales status of vehicles at its own store, encrypts the sales data using a homomorphic encryption method with an individual encryption key held by the computer, transmits the sales data in encrypted form to an analysis device, and decrypts the analysis results in encrypted form received from the analysis device using a decryption key corresponding to the encryption key.
[0094] (Supplementary Note 20) A recording medium storing a program that causes a computer to execute the following steps: obtain from a customer server vehicle data including location information of the vehicle in which the customer is riding, in a format encrypted by homomorphic encryption using an individual key held by the customer server; obtain from multiple store servers business data of each store encrypted by homomorphic encryption using a key that differs for each store server; perform analysis of each store based on the encrypted vehicle data and encrypted business data regarding the business status of each store; send the encrypted analysis results to the customer server and each of the multiple store servers; receive data obtained by distributively decrypting the encrypted analysis results, each by the customer server and each of the multiple store servers using a decryption key corresponding to the encryption key used for encryption; and output the decrypted analysis results.
[0095] Some or all of the configurations described in Supplements 2 to 12 that are dependent on Supplement 1 above may also be dependent on Supplement 17 and Supplement 20 in the same dependency relationship as Supplements 2 to 12. Not limited to Supplements 1, 17, and 20, some or all of the configurations described as Supplements may be made dependent on various hardware, software, various recording devices for recording software, or systems, within the scope of each of the above-mentioned embodiments.
[0096] 10, 11 Analysis system 100, 110 Analysis device 101, 111 First acquisition unit 102, 112 Second acquisition unit 103, 113 Analysis unit 104, 114 Transmission unit 105, 115 Reception unit 106, 116 Output unit 200, 210 Customer server 201, 211 Data storage unit 202, 212 Encryption unit 203, 213 Input / output unit 204, 214 Key generation unit 205, 215 Encryption key storage unit 206, 216 Decryption key storage unit 207, 217 Decryption unit 300, 310 Store server 301, 311 Data storage unit 302, 312 Encryption unit 303, 313 Input / output unit 304, 314 Key generation unit 305, 315 Encryption key storage unit 306, 316 Decryption key storage unit 307, 317 Decryption unit 500 Computer device 501 CPU 502 ROM 503 RAM 504 Program 505 Storage device 506 Recording medium 507 Drive device 508 Communication interface 511 Input / output interface 512 Bus
Claims
1. A first acquisition means that acquires vehicle data, including location information of the vehicle the customer is riding in, from the customer server in a form encrypted using a homomorphic encryption scheme with an individual key held by the customer server, A second acquisition method involves obtaining business data regarding the operating status of each store from multiple store servers, encrypted using homomorphic encryption with a different key for each store server. An analytical means that performs analysis on each store based on encrypted vehicle data and encrypted sales data for each store. A transmission means for transmitting the encrypted analysis results to the customer server and the multiple store servers, A receiving means that receives data obtained by distributively decrypting the encryption format analysis results using decryption keys corresponding to the encryption keys used by the customer server and multiple store servers, respectively. An analytical apparatus comprising an output means for outputting decoded analysis results.
2. The analysis means performs an analysis of which store to recommend to the customer from among multiple stores, based on encrypted vehicle data and encrypted sales data for each store. The analysis apparatus according to claim 1, wherein the output means outputs information on stores recommended to the customer based on the analysis results.
3. The first acquisition means further acquires the vehicle's travel distance from a predetermined time prior as vehicle data, The analytical apparatus according to claim 1 or 2, wherein the analytical means performs the analysis when the travel distance is less than a predetermined distance.
4. The first acquisition means further acquires customer information relating to the customer in a form encrypted using a homomorphic encryption scheme with individual keys held by the customer server, The analysis apparatus according to claim 1 or 2, wherein the analysis means performs an analysis on the matching of customers with each store based on encrypted vehicle data and customer information and encrypted business data of each store.
5. The second acquisition means further acquires store information regarding the products or services offered by each store from multiple store servers, The analysis apparatus according to claim 1 or 2, wherein the analysis means performs an analysis on the matching of customers and stores based on encrypted vehicle data, encrypted business data for each store, and unencrypted store information for each store.
6. The analysis apparatus according to claim 4, wherein the output means outputs information on stores recommended to the customer based on the degree of match between the customer and the store.
7. An analysis system comprising the analysis device described in Claim 1 or Claim 2, a customer server, and a plurality of store servers, The customer server includes a data storage means for storing the vehicle data, An encryption means that encrypts the aforementioned sales data using a homomorphic encryption scheme with an encryption key generated by itself, Input / output means for transmitting the aforementioned sales data to the analysis device in an encrypted format, The device comprises a decryption means that decrypts the encrypted analysis results received from the analysis device using the decryption key of the encryption key pair, Each of the aforementioned store servers includes a data storage means for storing business data related to the operating status of its own store, An encryption means that encrypts the business data using a homomorphic encryption scheme with encryption keys generated on each of the aforementioned multiple store servers, Input / output means for transmitting the aforementioned sales data to the analysis device in an encrypted format, An analysis system comprising: a decryption means for decrypting an encrypted analysis result received from the analysis device using the decryption key of the encryption key pair.
8. The encryption means in the store server encrypts the business data using a homomorphic encryption scheme with a composite key of encryption keys generated in each of the multiple store servers. The analysis system according to claim 7, wherein the decryption means decrypts the calculated analysis results using a decryption key generated in each of the plurality of store servers.
9. Computers Vehicle data, including location information of the vehicle the customer is riding in, is obtained from the customer server in a form encrypted using homomorphic encryption with an individual key held by the customer server. From multiple store servers, business data regarding the operating status of each store is obtained, encrypted using homomorphic encryption with a different key for each store server. Based on encrypted vehicle data and encrypted sales data for each store, we perform analysis on each store. The analysis results in encrypted format are transmitted to the customer server and the multiple store servers, The customer server and multiple store servers each receive the data after distributively decrypting the encryption format analysis results using the decryption keys corresponding to the encryption keys used for encryption. An analysis method that outputs decoded analysis results.
10. Vehicle data, including location information of the vehicle the customer is riding in, is obtained from the customer server in a form encrypted using homomorphic encryption with an individual key held by the customer server. From multiple store servers, we obtain business data for each store, encrypted using homomorphic encryption with a different key for each store server. Based on encrypted vehicle data and encrypted sales data regarding the operating status of each store, we perform analysis on each store. The analysis results in encrypted format are transmitted to the customer server and the multiple store servers, The customer server and multiple store servers each receive the data after distributively decrypting the encryption format analysis results using the decryption keys corresponding to the encryption keys used for encryption. A program that instructs a computer to output the decoded analysis results.