Secret sharing device, assistance device, user device, secret sharing program, assistance program, and user device program
By integrating true random number generators and secure calculation units into secret sharing systems, the challenge of maintaining information theoretical security in communications is addressed, ensuring robust protection against quantum computer threats.
Patent Information
- Application Number
- PCT/JP2024/031093
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-08-29
- Publication Date
- 2025-05-08
AI Technical Summary
Existing secret sharing systems often rely on computational security for communication, which is weak and vulnerable to quantum computer analysis, even if the secret sharing method itself has information theoretical safety.
The development of secret sharing devices and programs that incorporate true random number generators and calculation units to achieve information theoretical security by securely distributing and managing random numbers throughout the system, including communication paths.
This approach ensures information theoretical safety as a whole system, including communications, by preventing information leakage even if quantum computers are used, and reduces the risk of secret information exposure.
Smart Images

Figure JP2024031093_08052025_PF_FP_ABST
Abstract
Description
Secret sharing device, support device, user device, secret sharing program, support program, and user device program
[0001] The technology disclosed herein relates to a secret sharing device, an assistance device, a user device, a sender device, a receiver device, a verification request device, a verifier device, a secret sharing program, an assistance program, a user device program, a sender program, a receiver program, a verification request program, and a verifier program.
[0002] The evaluation of security regarding information security technologies can be broadly divided into information-theoretic security and computational security. Information-theoretic security is security that cannot be solved even if an attacker has infinite computing power because there is not enough information, while computational security is security that can be solved if the attacker has more computing power than expected.
[0003] The (k, n) threshold secret sharing scheme is known as a type of scheme with information-theoretic security. The (k, n) threshold secret sharing scheme is a scheme in which one piece of secret information is distributed into n different values, and the original secret information can be restored by collecting k (k≦n) values out of the n distributed values, but no information about the secret information can be obtained from values less than k. The (k, n) threshold secret sharing scheme by Shamir (hereinafter referred to as the Shamir scheme) is well known as this type of secret sharing scheme. In the Shamir scheme, the party that distributes the secret information is called a dealer, and it consists of n servers or participants that store the distributed values (hereinafter referred to as the shared values), and a restorer that restores the secret information. In addition, x, which is called a server ID, i (i=1, 2, . . . , n) are public values that anyone can know.
[0004] The Shamir algorithm for secret information s is as follows. [Shamir algorithm] [Distribution] 1. The dealer selects an arbitrary prime number p where s<p and n<p. 2. The dealer selects n different xi (i=1, 2, ..., n) from Z / pZ and sets them as server IDs. 3. The dealer selects k-1 random numbers a from Z / pZ. l (l=1, 2, ..., k-1) is selected and the following equation (hereafter called the dispersion equation) is generated: W i= s + a 1 x i +a 2 x i 2 +...+a k-1 x i k-1 (mod p) (1) 4. The dealer calculates x in the above formula (1). i Substitute each server ID into and calculate the variance value W i Calculate and server x i To W i [Decoding] 1. The distribution value used for decoding is W i (i = 1, 2, ..., k). The server ID corresponding to the variance value is x i (i = 1, 2, ..., k). 2. The restorer obtains k variance values W i Collect and add x to the dispersion formula i and W i Substituting and solving k simultaneous equations, we obtain s. When restoring s, it is convenient to use the Lagrange interpolation formula.
[0005] The additive secret sharing scheme is also well known. Below, we will explain the case where n = k. [Additive Secret Sharing Scheme] [Sharing] 1. The dealer distributes k-1 random numbers S 1 ~S k-1 2. The dealer calculates the following for the secret information s:
[0006] S k = s - S 1 -...-S k-1 (2) 3 Dealer assigns identifier x to k servers. i (i=1, 2, ..., k) and select server x i to S i [Decoding] 1. The decoder distributes k S i Collect s = S 1 +...+S k and recover the secret information s.
[0007] When n=k+1, the dealer sends S i , S i+1 However, for convenience, k+1 S 1It is considered to be.
[0008] Additive secret sharing schemes also consist of a dealer, n servers, and a restorer. This structure is based on the principle that after the dealer distributes the secret information, the dealer retains nothing and retrieves it from the server when needed. Additive secret sharing also achieves information-theoretic security, since even if k-1 shares are leaked, the secret information cannot be determined due to insufficient information. However, in both secret sharing schemes, the distribution of shares from the dealer to the server and the collection of shares by the restorer are performed using a secure communication channel. However, since secret sharing schemes provide information-theoretic security, information-theoretic security is also required for communication. The Vernam cipher is known as a cryptosystem that achieves information-theoretic security, but the Vernam cipher requires a large number of truly random numbers as a key to be securely shared between the sender and receiver without anyone knowing. However, it is generally difficult for the sender and receiver to generate a large number of truly random numbers, making it difficult to share random numbers with information-theoretic security without meeting in person offline. For this reason, common key cryptography, which has computational security such as AES (Advanced Encryption Standard), which only requires the sharing of a short key, is generally used, but when considering a system that also includes communications, the secret sharing system results in computational security, which is weak security overall, and there is a possibility that secret information may be leaked through communications. Therefore, in a system using secret sharing, it is necessary to achieve information-theoretic security that also includes communications, such as by building a mechanism that can easily generate and share random numbers for the Vernam cipher.
[0009] Meanwhile, research into quantum computers has progressed in recent years, and it is said that once quantum computers are realized, cryptography that only has current computational security will be easily analyzed. Therefore, once quantum computers are realized, even if the secret sharing scheme itself has information-theoretic security, if the communication channel only achieves computational security, there is a possibility that information will leak from the communication channel and the secret sharing system described above will be broken. Incidentally, methods that have information-theoretic security cannot be solved even with infinite computing power, so they cannot be solved even with a quantum computer.
[0010] In view of the above-mentioned problems, the present invention aims to propose a secret sharing device, a support device, a user device, a sender device, a receiver device, a verification request device, a verifier device, a secret sharing program, a support program, a user device program, a sender program, a receiver program, a verification request program, and a verifier program that can achieve information-theoretic security for the entire system, including communications.
[0011] In order to achieve the above-mentioned object, a secret sharing device of a first aspect of the technology disclosed herein includes a true random number generation unit that generates true random numbers, and a calculation unit that secretly shares a value obtained by multiplying k (k > 1) true random numbers from the true random number generation unit, sets one of the k true random numbers as a first random number, calculates its inverse, and combines the inverse with one of the secretly shared shared values to calculate k sets of conversion random numbers.
[0012] The second aspect of the assistance device is an assistance device that assists each of a sender device and a receiver device that perform encrypted communication with each other, and includes a true random number generation unit that generates true random numbers, a memory unit that stores the true random number generated by the true random number generation unit and transmitted to and stored in the sender device as a first sender random number, and stores the true random number that is different from the first sender random number and transmitted to and stored in the receiver device as a first receiver random number, a secret calculation unit that secretly calculates a second random number, which is a true random number generated by the true random number generation unit and used for encrypted communication between the sender device and the receiver device, using the first sender random number, and secretly calculates the second random number using the first receiver random number, and a communication unit that transmits the second random number secretly calculated using the first sender random number to the sender device, and transmits the second random number secretly calculated using the first receiver random number to the receiver device.
[0013] In the third aspect of the support device, in the second aspect, the memory unit stores a first user random number stored by each of multiple user devices participating in a secret calculation based on secret sharing, and further includes a support value calculation unit that calculates a support value required by each of the user devices participating in the secret calculation, and a secret calculation unit that secretly calculates the calculated support value using the first user random number of each of the multiple user devices, and the communication unit transmits the secretly calculated support value to each of the multiple user devices.
[0014] The fourth aspect of the support device is the third aspect, and includes an identifier assignment unit that assigns an identifier to the first user random number of each of the multiple user devices so that the usage status of the first user random number of each of the multiple user devices can be determined, and the communication unit sends the information obtained as a result of the secret calculation and the identifier to each of the multiple user devices.
[0015] The user device of the fifth aspect includes a receiving unit that receives the information obtained as a result of the secret calculation and the identifier from the assistance device described in the fourth aspect, and a decryption unit that decrypts the information obtained as a result of the secret calculation using a first user random number to which the identifier is attached.
[0016] The sender device of the sixth aspect has a random number calculation unit that uses the required number of random numbers from the first sender random number or the second sender random number described in the second aspect as a first distribution value, and calculates a random number used as a coefficient of an order other than the constant term of the first distribution value from the first distribution value and secret information held by the sender device, a distribution value calculation unit that calculates a second distribution value using the secret information held by the sender device, the random number, and a random number of an order having the random number as a coefficient, and a communication unit that sends the second distribution value to the receiver device.
[0017] The receiver device of the seventh aspect is equipped with a restoration unit that restores the secret information from the second distribution value sent from the sender device described in the sixth aspect, a first distribution value which is the required number of random numbers from the first sender random number or the second sender random number sent from the support device described in claim 5, and an order whose coefficient is the random number used in the second distribution value.
[0018] The eighth aspect of the verification request device is a verification request device that requests verification that it is the identity of the authentication information registered in the verifier device, and is equipped with a transformation unit that transforms transmitted information, which is a combination of the authentication information registered in the verifier device and information that differs for each transmission, into secretly calculated information so that it can be verified by secret calculation, and a transmission unit that transmits the transformed transmitted information to the verifier device, and is characterized in that the transformed transmitted information is transformed so that the result of the secret subtraction becomes 0 only when the registered authentication information, the information that differs for each transmission, and the transformed transmitted information match through secret subtraction using secret sharing.
[0019] A verifier device of the ninth aspect is a verifier device that registers authentication information described in the eighth aspect, and includes a receiving unit that receives the transformed transmission information, and a verification unit that performs secret subtraction described in the eighth aspect on the registered authentication information in the received transmission information, information that differs for each transmission, and the transformed transmission information, and verifies whether the result of the secret subtraction is 0.
[0020] A tenth aspect of the secret sharing device comprises: a calculation unit that performs secret calculation on the secret information by multiplying the secret information by one true random number from a true random number generation unit; calculates a random number used as a coefficient of an order other than the constant term of the first distribution value from a first distribution value that is first registration information and a fourth random number from the true random number generation unit; calculates a second distribution value using the fourth random number and the calculated random number; multiplying a value obtained by dividing the fourth random number by the second registration information, third registration information obtained from the true random number generation unit, and the inverse of the one true random number to obtain a deletion random number for deleting the one true random number in the secret information; a calculation unit that performs secret calculation on the secret information without performing division using the first distribution value, the second distribution value, and the secret information that has been secretly calculated; and a communication unit that sends the value calculated by the calculation unit.
[0021] The eleventh to twentieth aspects are programs corresponding to the first to tenth aspects, respectively.
[0022] A secret sharing device of the 21st aspect comprises a true random number generation unit that generates true random numbers using a natural phenomenon that cannot be controlled by humans, and a secret sharing unit that directly obtains a plurality of true random numbers from the true random number generation unit, calculates n shares from one piece of secret information using one or more of the true random numbers, and calculates n shares that can restore the secret information by collecting k (n≧k>1) of the shares, but cannot restore the secret information with k−1 or fewer shares, and the true random number generation unit and the secret sharing unit are configured on a single semiconductor.
[0023] The technology of the present disclosure can achieve information-theoretic security for the entire system, including communications.
[0024] 1 is a block diagram showing an example of the secret sharing apparatus 100 of the first embodiment. FIG. 2 is a diagram showing an example of a first modified example of the secret sharing apparatus 100 of the first embodiment. FIG. 3 is a diagram showing an example of a second modified example of the secret sharing apparatus 100 of the first embodiment. FIG. 4 is a block diagram showing an example of the configuration of the secret sharing unit 12. FIG. 5 is a block diagram showing an example of a secret sharing system when n = k = 2. FIG. 6 is a flowchart showing an example of the processing flow of the secret sharing program 24P1. FIG. 7 is a flowchart showing an example of the processing flow of the recovery program 24P2. FIG. 8 is a block diagram showing a secret sharing system of the prior art. FIG. 9 is a block diagram showing an example of a secret sharing system. FIG. 10 is a block diagram showing a secret sharing system having three servers of the prior art. FIG. 11 is a block diagram showing an example of a secret sharing system consisting of two servers of the second embodiment. FIG. 12 is a diagram showing an example of the processing of the secret sharing unit 12 and the secret computation unit of the CPU 12 of the secret sharing apparatus 100 of the second embodiment. FIG. 13 is a flowchart showing an example of the overall flow from secret sharing to the recovery of the secret computation / calculation result of the secret sharing apparatus 100 of the third embodiment. FIG. 14 is a diagram showing an example of the processing of the secret sharing unit 12 of the CPU 12 of the secret sharing apparatus 100 of the fourth embodiment. FIG. 15 is a block diagram showing an example of a secret sharing system of the fourth embodiment. FIG. 16 is a block diagram showing an example of a verification system of the sixth embodiment. Fig. 1 is a block diagram showing an example of a verification system according to a seventh embodiment. Fig. 2 is a diagram showing an example of a secret sharing apparatus 100 according to a modification of the first embodiment. Fig. 3 is a diagram showing an example of a secret sharing apparatus 100 according to a modification of the second embodiment. Fig. 4 is a diagram showing an example of a secret sharing apparatus 100 according to a modification of the fourth embodiment. Fig. 5 is a block diagram showing an example of a verification system according to a modification of the sixth embodiment. Fig. 6 is a block diagram showing an example of a verification system according to a modification of the seventh embodiment.
[0025] An example of an embodiment of the technology of the present disclosure will be described in detail below with reference to the drawings. <First Embodiment> Fig. 1A is a block diagram showing an example of a secret sharing apparatus 100 according to a first embodiment. As shown in Fig. 1A, the secret sharing apparatus 100 includes a true random number generation unit 10, a secret sharing unit 12, a memory unit 14, and a communication unit 16. The true random number generation unit 10, the secret sharing unit 12, the memory unit 14, and the communication unit 16 are communicatively connected via a bus. The secret sharing apparatus 100 is configured on a single semiconductor (one chip). Specifically, the true random number generation unit 10, the secret sharing unit 12, the memory unit 14, and the communication unit 16 are configured on a single semiconductor.
[0026] Although not shown in FIG. 1A, parameters, etc., described below, are input to the secret sharing unit 12 by the input unit 15, as in the first and second variants of the secret sharing apparatus 100 of the first embodiment described below.
[0027] The secret sharing apparatus 100 of this embodiment is provided in, for example, a SIM (Subscriber Identity Module) card or an SD card. The secret sharing apparatus 100 is operated by inserting the SIM card or SD card into a personal computer, smartphone, or the like equipped with a communication device (not shown). The communication unit 16 functions as a connection port for communication between the true random number generation unit 10, the secret sharing unit 12, and the storage unit 14 and the personal computer, smartphone, or the like.
[0028] As described above, the secret sharing apparatus 100 of the first embodiment is configured on one semiconductor (one chip), but the technology of the present disclosure is not limited to this.
[0029] 1B is a diagram illustrating an example of a first modified example of the secret sharing apparatus 100 of the first embodiment. As shown in FIG. 1B, the first modified example of the secret sharing apparatus 100 of the first embodiment includes a computer 20, a true random number generation unit 10, a communication device 160, a storage unit 14, and an input unit 15. The computer 20 includes a CPU 22, a ROM 24, a RAM 26, and an input / output (I / O) port 28. The CPU 22, the ROM 24, the RAM 26, and the input / output (I / O) port 28 are interconnected by a bus 30. The true random number generation unit 10, the communication device 160, the storage unit 14, and the input unit 15 are connected to the input / output (I / O) port 28. The ROM 24 stores various programs, which will be described later, including a secret sharing program 24P1 and a restoration program 24P2. The CPU 22 reads the secret sharing program 24P from the ROM 24 into the RAM 26 and executes the secret sharing program 24P, thereby functioning as the secret sharing unit 12.
[0030] 1C is a diagram showing an example of a second modified example of the secret sharing apparatus 100 of the first embodiment. As shown in FIG. 1C, the second modified example of the secret sharing apparatus 100 of the first embodiment is configured by interconnecting a ROM 24, a CPU 22, an input unit 15, a true random number generation unit 10, a RAM 26, a storage unit 14, and a communication device 160 via a bus 36. Note that the ROM 24 stores various programs, described below, including a secret sharing program 24P1 and a restoration program 24P2, as described above. The CPU 22 reads the secret sharing program 24P from the ROM 24 into the RAM 26 and executes the secret sharing program 24P, thereby functioning as the secret sharing unit 12.
[0031] On the other hand, as shown in Fig. 7, the secret sharing system of the first embodiment includes a secret sharing apparatus 100 and k-1 server apparatuses (hereinafter referred to as "servers") 110N1 to 110Nk-1. Note that, like the secret sharing apparatus 100 shown in Fig. 1C, the servers 110N1 to 110Nk-1 include a CPU, a storage unit, a communication unit, etc. Servers of other embodiments have similar configurations. The secret sharing apparatus 100 and the k-1 servers 110N1 to 110Nk-1 are connected to each other via a network 102 so that they can communicate with each other. However, the number of servers may be less than k-1, but the following description will be given assuming that there are k-1 servers.
[0032] For simplicity, the operation of the secret sharing system shown in Fig. 1A will be described assuming that n = k = 2. In this case, the secret sharing system has one server 110, as shown in Fig. 3. Note that Fig. 3 shows an example in which two secret sharing apparatuses 100 according to the first embodiment are provided.
[0033] First, the true random number generator 10 employs a method of measuring each alpha particle emitted during spontaneous decay of quantum phenomena to generate pulses and generating random numbers from the pulse intervals. This is because the system uses naturally decaying nuclei in which quantum phenomena occur within the nucleus, eliminating the need for any control to maintain the quantum phenomena. Alpha particles are spontaneously emitted during quantum phenomena and are emitted randomly, completely unaffected by external factors such as temperature, pressure, and electromagnetic fields. Therefore, since random spontaneous decay is not artificially created, the generated numbers are guaranteed to be truly random and unaffected by human influence. While other methods require various controls for temperature, pressure, and electromagnetic fields, making it difficult to implement a true random number generator within a semiconductor, this method allows the true random number generator 10 to be implemented within a single semiconductor, allowing it to coexist with the secret sharing unit 12, memory unit 14, and other components.
[0034] 2, the secret sharing unit 12 includes a setting control unit 12A and a calculation unit 12B. When secret sharing parameters (n, k, p) and the like are input from an input unit 15 (where p represents the number of bits of the random number), the setting control unit 12A receives the parameters and controls the entire system (specifically, the true random number generation unit 10, the storage unit 14, the communication unit 16, and the calculation unit 12B).
[0035] The setting control unit 12A also extracts random numbers from the true random number generation unit 10 and outputs them to the calculation unit 12B, etc. The setting control unit 12A also outputs the random numbers to the secret calculation unit 18 (described later) and the memory unit 14 (in the case of the Vernam cipher) in addition to the calculation unit 12B.
[0036] For example, when the Shamir algorithm is used (and n=k=2), the true random numbers input from the true random number generation unit 10 are cut out into p bits and a 1 For example, if p=3 and the true random number generator 10 outputs 1, 0, 1, 1, ... in this order, the setting controller 12A cuts out (i.e., extracts) three bits of the random number from the true random number generator 10 to obtain 101, and converts 101=5 (decimal number) into a 1 and sends it to the calculation unit 12B.
[0037] The setting control unit 12A is set in advance with the server IDs via the input unit 15, and these are also sent to the calculation unit 12B. In the example shown in FIG. 7, the server IDs of the servers 110N1 to 110Nk-1 are x 1 ~x k-1 In the example of FIG. 3 (where k=2), x is entered as the server ID of the server 110. 1 A p-bit prime number P is also set in advance in the setting control unit 12A via the input unit 15, and may be output to the calculation unit 12B in accordance with p.
[0038] Similarly, for example, when an additive secret sharing scheme is used, the setting control unit 12A cuts out (i.e., extracts) p bits of the true random number generated by the true random number generation unit 10 and outputs them as S1 to the calculation unit 12B, etc. For example, if p=3 and 0, 1, 0, 0 are output in order from the true random number generation unit 10, the setting control unit 12A cuts out (i.e., extracts) 3 bits of the random number from the true random number generation unit 10, obtains 010, and sends 010 or 2 (converted to a decimal number) as S1 to the calculation unit 12B. Unlike the above (when k=2), when k is 3 or greater, the setting control unit 12A cuts out k-1 true random numbers and outputs a i or S i(i=1, .., k-1), x i and sends it to the calculation unit 12B.
[0039] The calculation unit 12B uses the parameters sent from the setting control unit 12A and the secret information input via the input unit 15 to calculate Equation (1) in the case of the Shamir scheme and Equation (2) in the case of additive secret sharing. That is, the calculation unit 12B calculates the share value Wi from Equation (1) in the case of the Shamir scheme and calculates the share value Sk from Equation (2) in the case of additive secret sharing. When the calculation unit 12B supports multiple secret sharing schemes, such as the Shamir scheme and additive secret sharing, a parameter indicating which secret sharing scheme to select can also be input from outside to the setting control unit 12A via the input unit 15, thereby supporting multiple calculations. Alternatively, since the device of the technology disclosed herein can support various processes as described below, a program can be input from outside via the input unit 15 and set in the calculation unit 12B, and the calculation unit 12B can perform calculations according to the program.
[0040] Next, the calculation unit 12B of the secret sharing unit 12 sends n-k+1 (at least 1) of the calculated shares Wi or Si to the storage unit 14, and the storage unit 14 stores the n-k+1 (at least 1) shares. The calculation unit 12B sends the remaining k-1 shares to the communication unit 16.
[0041] The communication unit 16 sends the k-1 shared values to k-1 servers 110N1 to 110Nk-1 (see FIG. 7). For example, the communication unit 16 sends the first shared value of the k-1 shared values to server 110N1, the second shared value to server 110N2, ... and the k-1th shared value to server 110Nk-1. At this time, information-theoretic security is maintained even if the shared values are sent as is without encryption, but they may also be encrypted using a computationally secure cipher such as AES. This AES encryption is performed to increase the effort required by an attacker, and information-theoretic security is maintained even if it is broken.
[0042] An example of the processing flow of the secret sharing program 24P1 is shown in FIG.
[0043] In step 52, the setting control unit 12A sets the secret information input via the input unit 15 and variables such as (n, k, p) required for secret sharing.
[0044] In step 54, the setting control unit 12A extracts true random numbers from the true random number generation unit 10 and sets the parameters (n, k, p) in the calculation unit 12B.
[0045] In step 56, the calculation unit 12B calculates the variance value Wi or Si of equation (1) or equation (2) using the secret information, the true random number, and the parameter.
[0046] In step 58, the storage unit 14 stores the n-k+1 variance values.
[0047] In step 60, the communication unit 16 distributes (ie, transmits) the k-1 variance values to the external server 110 (see FIG. 3).
[0048] In the "distribution" mentioned in the background art, n distribution values are sent from the dealer 200 to n servers 202N1 to 202Nn, as shown in Figure 6. Therefore, if these are intercepted and decrypted by a quantum computer or the like, confidential information will be leaked, even if it is encrypted.
[0049] In contrast, the secret sharing apparatus 100 of the technology disclosed herein is configured so that the dealer itself can participate in the secure computation, and transmits k-1 shares to k-1 servers 110N1 to 110Nk-1, as shown in Fig. 7. Therefore, even if all the k-1 shares are intercepted and decrypted, the secret information will not be leaked, and it can be seen that information-theoretic security is achieved.
[0050] 1A, the secret sharing unit 12, the true random number generation unit 10, and the storage unit 14 are configured on a single semiconductor. Therefore, it can be said that there is almost no possibility of information leakage in communication between the true random number generation unit 10, the secret sharing unit 12, and the storage unit 14, which are configured on a single semiconductor, and therefore the device can be said to achieve information-theoretic security. Also, as long as each component is managed securely, it can also be configured using a computer as shown in FIGS. 1B and 1C.
[0051] Next, the process corresponding to [Restore] will be described. The process flow of the restore program 24P2 is shown in FIG.
[0052] First, in step 62, parameters (n, k, p) required for the restoration process are input from the input unit 15 and set in the setting control unit 12A. Then, the communication unit 16 retrieves (i.e., receives) k-1 shares from the servers 110N1 to 110Nk-1 and sends them to the calculation unit 12B. These shares may be sent as is, or may be encrypted using AES or the like before being sent. As with shares, this encryption is performed to increase the effort required by an attacker. When encrypting and decrypting, the encryption key is held in the communication unit 16.
[0053] Next, in step 64, n-k+1 (minimum one) shared values (one or more shared values) are sent from the memory unit 14 to the calculation unit 12B. In step 66, the calculation unit 12B performs a restoration calculation. When the Shamir method is used, the restoration calculation performed by the calculation unit 12B executes Lagrange's interpolation formula or a solution to a simultaneous equation to restore the secret information. In the case of additive secret sharing, the secret information is restored by the sum of the shared values. In step 68, the restoration result is transmitted (output) via the communication unit 16 and obtained.
[0054] The "recovery" shown in the background art has the same structure as the "shared" shown in FIG. 6, and if k shared values among them are intercepted or decrypted, the secret information will be leaked.
[0055] In contrast, since the device of the technique of the present disclosure has the configuration shown in FIG. 7, secret information is not leaked from the k-1 distributed values, and information-theoretic security is achieved.
[0056] Generally, in secret sharing, after the secret sharing device (dealer) distributes the secret information, it does not keep anything in its possession, and when it wants to restore the secret information, it obtains k shares from the distributed servers and restores the secret information, as a rule, resulting in the [distribution] and [restoration] shown in the background art.
[0057] In contrast, in this embodiment, the secret sharing device (dealer) 100 is configured to keep one share locally (its own device) and manage it secretly (or to participate in secure computation), thereby realizing information-theoretic security.
[0058] As described above, this embodiment can achieve information-theoretic security for the entire system, including communications. Specifically, if the semiconductor shown in FIG. 1A , in which the true random number generation unit 10, secret sharing unit 12, and memory unit 14 are configured on a single semiconductor, is implemented as a SIM card or SD card and inserted into a server, PC 100A, or smartphone (hereinafter referred to as "smartphone") 100B as shown in FIG. 3 , information-theoretic security is maintained even if all information sent by the secret sharing apparatus (dealer) 100 to the server 110 is leaked. Alternatively, the PC 100A and smartphone 100B may be configured as computers, as shown in FIGS. 1B and 1C . Therefore, even if an attacker attacks communications and the server 110 to obtain information, the secret information will not be leaked, and information-theoretic security is achieved for the entire secret sharing system, including communications. However, there may be multiple servers 110 shown in FIG. 3 , and there may also be multiple PCs 100A or smartphones 100B each equipped with the secret sharing apparatus (dealer) 100. Note that a tablet device may be used instead of a smartphone. Second Embodiment In the first embodiment, a secret sharing apparatus that realizes information-theoretic security for the storage and restoration of secret information is shown. In the second embodiment, an apparatus that realizes information-theoretic security for processes including secure computation is shown.
[0059] When performing secure computation using secret sharing, the following two points (conditions) are important for achieving information-theoretic security as a system, including communications:
[0060] (1) First Condition The first condition is that the secure computation algorithm must be capable of secure computation with n = k. Many secure computation algorithms have been proposed to date, but most of them have not been able to achieve n = k. The reason for this is that in the case of the Shamir algorithm, the multiplication result of k-1 degree polynomials (shared values) held by k servers becomes a 2k-2 degree polynomial, and 2k-1 servers are required to restore it. Therefore, the number of servers is often n = 2k-1, and even if the minimum k = 2 is set, the number of servers required is n = 2k-1 = 3. In this case, the device configuration shown in FIG. 8 is used. For example, if server 204A acts as the dealer and distributes shares to servers 204B and 204C, if an attacker eavesdrops on each communication, the problem can be solved because k = 2, and confidential information will be leaked from the communication.
[0061] (2) Second Condition The second condition is that a TTP or the like is not used outside the system, or that information-theoretically secure communication is possible. A TTP (Trusted Third Party) is a trusted third-party organization that supports secure computation. The relationship between the TTP and the server is similar to that in FIG. 6, where the dealer 200 is replaced with a TTP. As in FIG. 6, if communication between the TTP 200 and the servers 202N1 to 202Nn is intercepted, confidential information will be leaked. Even if the configuration shown in FIG. 7 were to be adopted, it would not be possible because the secret sharing apparatus 100 is also a server from the TTP's perspective. Therefore, it is necessary to achieve information-theoretically secure communication without using a TTP. Alternatively, the Vernam cipher is known as a cipher that achieves information-theoretically secure communication, but as mentioned above, the Vernam cipher requires the sender and receiver to share a large amount of true random numbers in advance, which is time-consuming. Therefore, it is necessary to easily achieve information-theoretically secure communication using the Vernam cipher or the like.
[0062] No secure computation algorithm that satisfies the above two conditions has been known to date. Algorithms that satisfy condition 1 include the TUS method described in Non-Patent Document 1 and the SPDZ method described in Non-Patent Document 2.
[0063] (Non-Patent Document 1) Keiichi Iwamura and Ahmad Akmal Aminuddin Mohd Kamal, “Communication-Efficient Secure Computation of Encrypted Inputs Using (k, n) Threshold Secret Sharing”, IEEE Access, May 2023. (Non-patent Document 2) Damgard I. , Keller M. , Larraia E. , Pastro V. , Scholl P. , Smart N. P. : "Practical coveringly secure MPC for dishonorable majority - Or: Breaking the SPDZ Limits." In: Crampton J., Jajodia S., Mayes K. (eds) Computer Security (ESORICS 2013). LNCS, vol. 8134, pp. 1-18. Springer, Berlin, Heidelberg. (2013) The TUS method shown in Non-Patent Document 1 requires TTP.
[0064] The SPDZ method described in Non-Patent Document 2 does not require TTP, but does not achieve information-theoretic security.
[0065] Therefore, in this embodiment, a method that satisfies the above conditions 1 and 2 is shown.
[0066] As shown in FIG. 6, the TUS system comprises a dealer 200 (inputter), n servers 202N1-202Nn, and a restorer device (not shown). Note that a TTP (trusted password protocol) is also included outside this system (not shown). In the TUS system, communications between the servers 202N1-202Nn, between the dealer 200 (inputter) and each of the servers 202N1-202Nn, and between the restorer device and each of the servers 202N1-202Nn are assumed to be secure. To achieve information-theoretic security for the entire system, the Vernam cipher is required for each of the above communications. Therefore, in this embodiment, the TUS system is improved to achieve information-theoretic security, including communications, without using a TTP or a Vernam cipher.
[0067] First, we will show the conventional TUS system before the improvement.
[0068]
[0069] For simplicity, we will use a 1 a 2 +a 3 The following explanation will be given for the case where n = k = 3, taking the multiplication and accumulation operation of the formula above as an example. The form of the formula is determined by l and mi of the extended multiplication and accumulation operation, and the multiplication and accumulation operation is, for example, l = 2, m1 = 2, m2 = 1. Also, the variance value of a is [a] j (j=0,...,n-1). The Shamir algorithm is used for secret sharing. In the TUS method, the sum-of-products operation a 1 a 2 +a 3 is calculated as follows: 1 a 2 +a 3 = (a 1 +1) (a 2 +1)-(a 1 +1)-(a 2 +1) + (a 3 +1) (3) Confidential information a i If the secret information is 0, add 1 to the random number b i Directly concealed b i a i Even if we use the same random number (random numbers used in secure computation do not use 0), it will be 0. i = 0 is leaked, so add 1 to the secret information b i (a i +1) and calculate equation (3).
[0070] [Confidentiality of confidential information] 1. Inputter A i (i=1, 2, 3) is each secret information a i For k random numbers b i,0 , b i,1 , ..., b i,k-1 Generate and calculate the following: b i,j to server S j (j=0, . . . , n-1=k-1). There are three dealers 200 in FIG. 6, and as described above, i corresponds to three dealers 200, and the server S jcorresponds to the servers 202N1 to 202Nn in FIG.
[0071]
[0072] 2. Inputter A i (i = 1, 2, 3) is the secret information a i For b i (a i +1) = b i × (a i + 1) and send it to all servers (i = 1, 2, 3). [Generating random numbers for conversion] 1. TTP generates k random numbers e h,0 , e h,1 , ..., e h,k-1 Generate g sets of
[0073]
[0074] Calculate the following: e h (h=1,...,g) is secretly shared, and the g sets of [e h ] j (j=0, . . . , n-1) and each server S j (j=0, . . . , n-1).
[0075]
[0076] 2 Therefore, server S j has the following information before the secret computation: i (a i +1), b i,j , e h,j , [e h ] j (i = 1, ..., 3, h = 1, ..., g) [Random number calculation for deletion] 1 Server S j is a random number d j Generate the following and calculate the following: 0 ) and send it to d j Save.
[0077]
[0078] 2 Server S 0 multiplies the sent values to calculate the following and sends it to all servers.
[0079]
[0080] [Secret calculation] All servers S j computes the following:
[0081]
[0082] [Restoration] The restorer restores k servers S j (j=0,...,n-1) to [d(a 1 a 2 +a 3 )] j , d j Collect and d(a 1 a 2 +a 3 ) is restored, and the calculation result a is obtained as follows: 1 a 2 +a 3 We obtain
[0083]
[0084] In the TUS method, it is assumed that each server has a conversion random number set from the beginning, but since it is difficult for each server to have a conversion random number set calculated by a common calculation without using the TTP, in the above it is assumed that the conversion random number set is generated by the TTP. However, in the [conversion random number set generation] performed by the TTP, n conversion random number sets are generated by each server S j (j=0,...,n-1), so even if the information flowing through the communication channel is encrypted, if it can be decrypted using a quantum computer or the like, the TUS method will leak confidential information. i,j Distribution of [d(a 1 a 2 +a 3 )] j , d j is also collected from all servers Sj (j=0, . . . , n-1), so confidential information and calculation results are similarly leaked from the communication path.
[0085] From the above, it can be said that the problems with the TUS method are the distribution of random number sets for conversion from the TTP to each server, the distribution of random numbers that conceal secret information, and the collection of calculation results for restoration.
[0086] Therefore, in this embodiment, for simplicity, we first consider a case where one user performs secure computation using the TUS method. In this case, the secret sharing apparatus 100 shown in Fig. 1 conceals secret information and generates a set of random numbers for conversion as follows.
[0087] [Secret sharing unit 12: concealment of secret information (for one person)] 1. When variables (n, k, p) required for secret sharing are set in the setting control unit 12A from the input unit 15, the setting control unit 12A cuts out the true random numbers sent from the true random number generation unit 10 into p bits and creates the secret information a i (i = 1, 2, 3) for each i 2 The calculation unit 12B receives the b i Using b i (a i +1) (i=1, 2, 3).
[0088] (a i The "1" in +1) is an example of a "constant determined from the range of secret information and calculation result" in the technology of the present disclosure. In the TUS method, the range of secret information is an integer equal to or greater than 0, so the constant is determined from the range in which the input value and calculation result do not become 0. In the above example, the constant is set to "1" for ease of calculation. Details will be described later.
[0089] b i is an example of the "second random number" of the technology of the present disclosure. i The calculation unit 12B calculates the reciprocal of b and sends it to the storage unit 14, which stores it. i (a i +1) to the external server, which stores it. [Secret sharing unit 12: Generation of random number sets for conversion (for one person)] 1. When variables (n, k, p) required for secret sharing are set in the setting control unit 12A from the input unit 15, the setting control unit 12A converts the true random numbers sent from the true random number generation unit 10 into k random numbers e for each p bits. h,0 , e h,1 , ..., e h,k-1 Cut out g sets of
[0090]
[0091] The result is sent to the calculation unit 12B.
[0092] k random numbers e h,0 , e h,1 , ..., e h,k-1 One of the numbers is an example of the “first random number” of the technique of the present disclosure. h,0 , e h,1 , ..., e h,k-1 Calculate equation (5) using e h (h=1,...,g) is secret shared, and [e h ] j (j=0,...,n-1).
[0093]
[0094] 3. The calculation unit 12B is e h,j The reciprocal of the k random number sets for conversion (1 / e h,j , [e h ] j ) (j=0,...,k-1) is obtained. h,q , [e h ] q ) (q=1, . . . , k−1) to the external server S via the communication unit 16. q (q=1, . . . , k−1), and the calculation unit 12B sends i (a i +1), 1 / b i , 1 / e h,0 , [e h ] j is sent to the storage unit 14.
[0095] Unlike the TUS method, the random numbers that conceal the secret information in the [Secret Computation Unit 18: Concealment of Secret Information (for one person)] are not distributed to other servers, and the problem is solved because the number of conversion random number sets that are not released to the outside is k-1 or more in the [Secret Sharing Unit 12: Generation of Conversion Random Number Sets (for one person)]. Furthermore, if the user's device performs [Recovery], the [d(a 1 a 2 +a 3 )] J , d jIn other words, secure computation can be performed with a configuration including two servers 210 and 220, as shown in Fig. 9, instead of Fig. 8.
[0096] Furthermore, in the TUS method, [Secure Confidential Information], [Generate Random Number Set for Conversion], and [Calculate Random Number for Deletion] are pre-calculated before the [Secure Computation], which requires high processing speed, so processing speed is not a major concern. However, the [Secure Computation Unit 18: Confidential Confidential Information (Single User)] is more efficient than the TUS method, with reduced computational effort, communication volume, and storage volume. In other words, the number of true random numbers extracted is reduced, and the calculation of equation (4) is eliminated. Furthermore, because division over a finite field is not integer division, it is necessary to prepare a reciprocal table or use the Extended Euclidean Algorithm in advance. When p is large (e.g., 128 bits), the reciprocal table becomes enormous, and calculation using the Extended Euclidean Algorithm is time-consuming. While division is performed in the [Secure Computation] of the TUS method, in the above example, this effort is not performed in the [Secure Computation], which requires high processing speed, but rather in the [Secure Confidential Information], which can be pre-processed, and the reciprocal is stored in the memory unit 14, thereby speeding up the [Secure Computation] process. Similarly, by storing the reciprocals of the random numbers included in the conversion random number set, division is eliminated, and the processing speed can be increased. In addition, the above processing reduces the amount of storage required in the storage unit 14 and the external server compared to the TUS method, and also reduces the amount of communication with the outside. i (a i +1) is sent to the external server, which realizes information-theoretic security. In other words, an attacker cannot obtain the secret information unless he has the information of the device of the technology disclosed herein and the information of the external server. i (a i +1), b i If the secret information is not known, it is impossible to obtain it, and information-theoretic security is maintained.
[0097] However, when one person performs secure computation using their own secret information, a more efficient method than the TUS method is shown below. The configuration of the technology disclosed in this case is shown in Figure 10. The difference from Figure 1 is the addition of a secure computation unit 18. However, the configuration of the secret sharing unit 12 is the same as that in Figure 2. In this device configuration, all components may also be connected by a bus, allowing programs to be input from outside.
[0098] 10 will be described below, but it is assumed that the confidentiality of the secret information is achieved by the above-mentioned [Secret sharing unit 12: confidentiality of secret information (for one person)], and the configurations and processes of the true random number generation unit 10, storage unit 14, and communication unit 16 are the same as those in the first embodiment, so their explanations will be omitted. It is assumed that the external server does not use the technology disclosed herein and is not secure.
[0099] In contrast, the processes corresponding to [pre-calculation], [secure calculation] and [restoration] in the TUS method are performed as follows. In this case too, the amount of calculation and communication traffic is significantly reduced compared to the TUS method. In particular, the time and effort for [generation of random number set for conversion] and [restoration] is eliminated, and the calculation result can be obtained directly. [Secure calculation unit 18: for one person] 1 The secure calculation unit 18 receives the data from the storage unit 14 and stores it in the form of a i The secure computation form is also determined from the form of the formula. i (a i +1) and calculate either of the following:
[0100]
[0101] However, the above-mentioned [secure computation unit 18: for one user] is limited to the case where there is one user, and is not used as generally as the TUS method. However, the TUS method only assumes that the communication path is secure, and does not take into account information-theoretic security in communication, but the device of the technology disclosed herein makes it possible to perform information-theoretically secure secure computation including communication. Also, while the TUS method performs division during secure computation, the above algorithm does not use b i Yae h,j Since the reciprocal of is calculated and stored before the secure computation, division is realized by direct multiplication of the reciprocal, which is efficient. General-purpose secure computation using the TUS method is shown in the third embodiment.
[0102] In addition, confidential information a i The range is an integer greater than or equal to 0, so if the value is greater than or equal to 0, including the calculation result, a i +1 never equals 0. However, when ai and the calculation result are in the range of u-1 to -u+1, let P be a prime number of P≧2u, and i +1 to a i +u, the calculation result, including the input, will never be 0. Therefore, when repeating a calculation, the intermediate results will never be 0, so for example, the restored result will be d(a 1 a 2 +a 3 +u), it is possible to perform repeated calculations using the restored result as is. i +u, and the restored result is d(a 1 a 2 +a 3 To perform secure computation so that the result is (u + u), the following is calculated instead of equation (3): 1 a 2 +a 3 +u=(a 1 +u) (a 2 +u)-u(a 1 +u)-u(a 2 +u) +u 2 + (a 3 +u) Also, a 1 and the calculation result is u 1 -1 to -u 2 +1, P≧u 1 +u 2 As a i +1 to ai+u 2 If so, the calculation result will never be 0. i If the range of the calculation result is unknown and a large P is set, u=P / 2 can be used. i If the calculation result is an integer equal to or greater than 1, u can be set to 0.
[0103] Furthermore, if the value to be added to the secret information is a random number instead of a constant, it can be done as follows.
[0104] a i and the calculation result is u1 -1 to -u 2 +1, P≧2(u 1 +u 2 ) as a i +r, where r is u 1 +2u 2 From U 2 It is a random number in the range of a. i +r is 2(u 1 +u 2 ) ranges from −1 to 1, and the calculation result will never be 0. These are examples of “constants or random numbers including 0 determined from the range of confidential information and calculation results” in the technology of the present disclosure.
[0105] Therefore, like the first embodiment, this embodiment is secure with respect to the storage and restoration of secret information, and can also achieve information-theoretic security for secure computation. Therefore, even if the technology of the present disclosure is implemented in a SIM card or an SD card and secure computation is performed in an environment such as that shown in FIG. 3 , it can be said that information-theoretic security can be achieved, including the communication channel. <Third Embodiment> The second embodiment illustrates a case in which one user performs secure computation using their own data stored in a secret sharing manner. This embodiment illustrates a case in which multiple users jointly perform secure computation using their own secret information. However, it is assumed that conversion random number pairs have been distributed in advance to participants in the secure computation, including the device of the technology of the present disclosure, using the fourth embodiment described below.
[0106] The following describes the process of [Secret sharing unit 12: concealment of secret information (for multiple users)] and [Secure computation unit 18: for multiple users] when multiple users perform the process. In the process of [Secret sharing unit 12: concealment of secret information (for multiple users)], for example, users A, B, and C each share secret information a 1 , a 2 , a 3 In this case, the processing is slightly different from that of the [secret sharing unit 12: concealment of secret information (for one person)]. Also, the processing of the [secret calculation unit 18: for multiple people] is different from the TUS method in that the random numbers that conceal the secret information are not decomposed, and therefore the amount of communication, calculation, and storage is reduced compared to the TUS method. In the following, when a user having the device of the technology disclosed herein shares secret information a 1 and other users have a 2 , a3 When each user has performed confidential information concealment processing, 1 This shows the process of concealing secret information of a user who has secret information of the above. Finally, the storage unit 14 and the external server have the following 5. (It is assumed that the conversion random number set has already been stored).
[0107] The overall flow from secret sharing to secure computation and recovery of computation results is shown in FIG.
[0108] In step 72, the secret sharing unit 12 sets variables and conceals the secret information as described later in [Secret sharing unit 12: concealment of secret information (for multiple users)].
[0109] In step 74, the communication unit 16 transmits the concealed secret information to an external server, and the communication unit 16 obtains a set of random numbers for conversion from the TTP and transmits it to the memory unit 14, and the memory unit 14 stores the concealed secret information and the transmitted set of random numbers for conversion.
[0110] In step 76, the secure computation unit 12 uses the stored secret information to perform secure computation as described later in [Secure computation unit 18: for multiple users]. Note that this is also performed separately on other servers.
[0111] In step 78, the communication unit 16 collects k calculation results (shared values), and the secure calculation unit 18 performs restoration as described later in [Secret sharing unit 12: restoration].
[0112] A detailed explanation will be given below. A simplified version of the [secret calculation unit 18: for multiple users] [secret sharing unit 12: restoration] in which the amount of calculation is reduced by setting n = k = 3 will be explained below. However, if there is a restorer, the data is sent in a secret form using the Vernam cipher according to the fourth embodiment (details will be described later). [Secret sharing unit 12: Secret information concealment (for multiple users)] 1. For secret information a1, a random number b from the true random number generation unit 10 is generated. 1 2 The calculation unit 12B extracts the b sent from the setting control unit 12A and sends it to the calculation unit 12B. 1 Using secret information a 1 For b 1 (a 1 +1). 3. The calculation unit 12B calculates b 1 Calculate the reciprocal of 1 / b 1 is sent to the storage unit 14, and b is sent via the communication unit 16.1 (a 1 +1) to the user who performs the secure computation. 4. The computation unit 12B makes the b i (a i +1) (i=2, 3) is received via the communication unit 16 and sent to the storage unit 14. 5 If g conversion random number sets are sent from the TTP according to the fourth embodiment, the device according to the technology of the present disclosure receives b i (a i +1), 1 / b 1 , ([e h ] j , 1 / e h,j ) (i = 1, 2, 3, h = 1, ..., g). Hereafter, 1 The device of the disclosed technique having 0 , a 2 , a 3 other user devices having S 1 , S 2 It is called.
[0113] The formula form described below is, for example, a 1 a 2 +a 3 If the formula is in the form of a calculation formula, then (a i +1) is determined. However, the actual expansion formula is composed of b i The secret b i (a i +1), so if we calculate equation (3) as is, we get the following: 1 (a 1 +1) b 2 (a 2 +1)-b 1 (a 1 +1)-b 2 (a 2+ 1) + b 3 (a 3 +1) Therefore, the first term of the above formula is used as a random number for deletion, and 1 / (b 1 b 2 ), 1 / b in the second term 1 , 1 / b in the third term 2 , 1 / b in the fourth term 3 It is necessary to generate and multiply by 1 / b 1 If you directly multiply the secret information,1 Therefore, the random number d j and 1 / e of the conversion random number set h,j And b i This random number product with bi kept secret is called a deletion random number piece, and the product of these is called a deletion random number. However, 1 / e h,j multiplied by 1 / e h is deleted by multiplying it by the share value included in the conversion random number set. Therefore, the formula for secure computation is as shown in formula (7). [Secure computation unit 18: for multiple users] 1. The secure computation unit 18 receives b from the storage unit 14. i (a i +1), 1 / b 1 , (1 / e h,j , [e h ] j ) (i=1, 2, 3, h=1, ..., g) is obtained. From the form of the formula, the following deletion random number fragment and the form of secure computation shown in formula (7) are also determined. 2 User device S j (j=0, . . . , k−1) is the random number d j , and calculate the following deletion random number fragments to be used by the user device S 0 However, the reciprocal of the random number that conceals the secret information is sent to i and the reciprocal 1 / e of the random number included in the conversion random number set h,j is stored in the storage unit 14, the following calculation is performed by multiplication only.
[0114]
[0115] The reciprocal of the random number included in the conversion random number set is 1 / e h,j is an example of the "reciprocal of the first random number" in the technology of the present disclosure. This reciprocal 1 / e h,j may be given from the outside via the input unit 15. The reciprocal of the random number that conceals the secret information is 1 / b i is an example of the "inverse of the second random number" of the technique of the present disclosure. j is an example of the "third random number" of the technique of the present disclosure. 0 sends the value sent via the communication unit 16 to the secure calculation unit 18, which calculates the following deletion random number, and q(q = 1, ..., k-1).
[0116]
[0117] 4. User device S j The secure computation unit 18 (j=0, . . . , k−1) calculates the following [d(a 1 a 2 +a 3 )] j is secretly calculated.
[0118]
[0119] The secure computation unit 18 is an example of a "secure computation unit that performs secure computation."
[0120] [Secret sharing unit 12: restoration] k-1 user devices S q is [d(a 1 a 2 +a 3 )] j and d j S 0 Send to S 0 The calculation unit 12B receives them via the communication unit 16 and calculates d(a 1 a 2 +a 3 ) is restored, and the following is calculated to obtain the result a 1 a 2 +a 3 and sends the calculation result to the storage unit 14 or the communication unit 16 as necessary.
[0121]
[0122] From the above, it can be seen that information-theoretic security, including communication, can be achieved even when multiple people perform secure computation using their own secret information. It is clear that extensions other than n = k = 3 are possible. Furthermore, the TUS method also shows calculations when operations are repeated, but the addition of a constant 1 in the [Secret Sharing Unit 12: for Multiple Users] is replaced with the addition of a random number, and the processing in the [Secret Sharing Unit 12: Concealment of Secret Information (for Multiple Users)] and the [Secret Computation Unit 18: for Multiple Users] performs similar processing using the added random number as secret information, so it is clear that repetition can also be performed in the same way. Furthermore, if the range of the secret information and the calculation result is known, it is possible to repeat the process by simply setting u or r shown in the second embodiment and adding. Furthermore, in the TUS method, when the number of participants in the secure computation changes, the b that conceals the secret information i,j In this embodiment, i,j Since the TUS method does not distribute the secret key, it is not necessary to perform reciprocal calculations. In addition, while the TUS method requires reciprocal calculations during secure calculations, the above algorithm can be efficiently performed by multiplication.
[0123] However, two or more legitimate users are required as participants, including the restorer. For example, in the second embodiment, the restorer is the same as the server performing the secure computation, which is secure. Even if the restorer is an attacker attempting to individually obtain the secret information of the inputters, even if one inputter cooperates, unless the remaining two inputters are attackers, the legitimate inputter's secret information cannot be decomposed into individual values, ensuring security. Therefore, it can be said that the system as a whole achieves information-theoretically secure secure computation. <Fourth Embodiment> As described below, the fourth embodiment provides information-theoretically secure secure computing for the entire system, including communications, and also demonstrates a mechanism for easily sharing random numbers for the Vernam cipher with the second condition described in the second embodiment. Specifically, as shown in FIG. 13, true random numbers are distributed to the sender device 302 and the receiver device 304 via the TTP 300. The advantage of this system is that it eliminates the need for the sender device 302 and receiver device 304 to individually generate and exchange true random numbers, and allows for easy encrypted communication using the Vernam cipher with anyone as long as the true random numbers are shared only with the TTP 300. However, users who wish to receive true random numbers become users of the system operated by the TTP 300 and enter into a contract for periodic distribution of true random numbers (one-time distribution is also acceptable).
[0124] The TTP 300, the sender device 302, and the receiver device 304 each include a secret sharing unit, a storage unit, a communication unit, etc., similar to the secret sharing device 100 shown in Fig. 1A. The configurations shown in Fig. 1B and 1C may also be used. Servers in other embodiments have a similar configuration.
[0125] The TTP 300 includes the true random number generation unit 10, communication unit 16, storage unit 14, conversion random number set generation unit, management unit, and encryption unit of the first embodiment (see FIG. 1) (or FIG. 10). The sender device 302 and the receiver device 304 each include the storage unit 14, communication unit 16, encryption unit, and decryption unit.
[0126] The TTP 300 is an example of the "support device" of the technology of the present disclosure.
[0127] The numbers in FIG. 13 correspond to the following procedures.
[0128] [Registration process] [1] The sender device 302 and receiver device 304 who wish to use the Vernam cipher become users of the system operated by the TTP 300 and determine the interval and number of true random number distributions. [2] The TTP 300 sends a set number of true random numbers (called first random numbers) from a true random number generator to the registered users (i.e., the sender device 302 and receiver device 304) by mail or the like, storing them on a storage medium such as a SIM card, SD card, USB, or CD-ROM. The first random number sent to the sender device 302 is different from the first random number sent to the receiver device 304.
[0129] The first random number sent to the sender device 302 is an example of a "first sender random number" in the techniques of the present disclosure. The first random number sent to the receiver device 304 is an example of a "first receiver random number" in the techniques of the present disclosure.
[0130] The sender device 302 stores the first random number sent from the TTP 300 in the memory unit 14 of the sender device 302, and the receiver device 304 stores the first random number sent from the TTP 300 in the memory unit 14 of the receiver device 304 (for example, the sent storage medium may contain a program that automatically transfers the first random number to the sender device 302 and the receiver device 304 when the sent storage medium and the secret sharing apparatus of the first embodiment are inserted into the sender device 302 and the receiver device 304). [3] The TTP 300 periodically sends true random numbers to the user as described above in accordance with the method described in [2] above. [4] The management unit of the TTP 300 records and manages the first random numbers sent for each user (i.e., the sender device 302 and the receiver device 304) in the memory unit 14 of the TTP 300. Specifically, the management unit assigns a number to the first random number so that it is possible to know how many numbers have been used for each user. Alphabetical characters may also be used. The number is also sent to the user (i.e., the sender device 302 and the receiver device 304) together with the first random number described in [2] and [3] above.
[0131] Numbers and alphabets are examples of "identifiers" in the technology of the present disclosure.
[0132] In this way, the memory unit 14 of the TTP 300 stores the first random number sent to the sender device 302 and the first random number sent to the receiver device 304, the memory unit 14 of the sender device 302 stores the first random number sent from the TTP 300, and the memory unit 14 of the receiver device 304 stores the first random number sent from the TTP 300. In other words, the first random number sent from the TTP 300 to the sender device 302 is shared between the TTP 300 and the sender device 302. The first random number sent from the TTP 300 to the receiver device 304 is shared between the TTP 300 and the receiver device 304. [Encrypted communication processing] [5] The communication unit 16 of the sender device 302 notifies the receiver device 304 that encrypted communication using the Vernam cipher will be performed. [6] The communication unit 16 of the sender device 302 requests the required number of true random numbers (referred to as second random numbers) for the Vernam cipher from the TTP 300. [7] The concealment unit of the TTP 300 conceals (Vernam ciphers) the requested number of second random numbers from the true random number generation unit using the first random numbers of the sender device 302, and the communication unit 16 sends to the sender device 302 the second random numbers concealed (Vernam ciphered) using the first random numbers and information on which first random number the second random numbers were encrypted with. [8] The enciphering unit of the TTP 300 enciphers (Vernam ciphers) the second random number (unenciphered) sent to the sender device 302 using the first random number of the receiver device 304, and the communication unit 16 sends to the receiver device 304 the second random number enciphered (Vernam ciphered) using the first random number of the receiver device 304 and information on which first random number was used for encryption. [9] After the TTP 300 transmits the second random number to the sender device 302 and the receiver device 304 (i.e., [7] and [8]), it immediately deletes the second random number.
[10] After receiving the information [7] (i.e., the number indicating which first random number was used to encrypt the second random number), the deciphering unit of the sender device 302 deciphers the first random number shared with the TTP 300 from the specified number, and automatically extracts the second random number.
[11] After receiving the information [8], the decryption unit of the receiver device 304 also decrypts the first random number shared with the TTP 300 from the specified number and automatically extracts the second random number.
[12] The encryption unit of the sender device 302 automatically encrypts (Vernam cipher) the communication content instructed by the sender device 302 using the second random number extracted in
[10] , and the communication unit 16 sends it to the receiver device 304.
[13] The decryption unit of the receiver device 304 automatically decrypts the communication content using the second random number extracted in
[11] and displays it on a display unit not shown.
[0133] The TTP 300 is a device different from the secret sharing device 100 of the first embodiment, but includes the components of the secret sharing device 100 .
[0134] The processes [1] to [3] above include user correspondence, mailing of storage media, etc. The TTP 300 is configured for each user (i.e., each of the sender device 302 and the receiver device 304) in [1]. The first random numbers in [2] and [3] are generated by the true random number generation unit 10 of the device of the technology of the present disclosure shown in FIG. 1 or FIG. 10, and output to a SIM card, SD card, USB, CD-ROM, etc. via the communication unit 16. Furthermore, the management of the first random numbers for each user by numbering in [4] may be performed by the setting control unit 12A, etc. Furthermore, if the number of first random numbers is enormous, the first random numbers may be managed for each user on a large-capacity external server isolated from the outside, and each time a second random number is requested by a user in [6], the TTP 300 is called, and the TTP 300 obtains the required first random number and conceals the second random number. After that, the TTP 300 disconnects the external server again and distributes the second random number to the user in [6]. In addition, the processes [7] to [9] may also be performed automatically in accordance with the request [6]. That is, the true random number generation unit 10 generates a second random number, conceals the second random number using the stored first random number, and transmits it via the communication unit 16.
[0135] The processing of the sender device 302 and the receiver device 304 can also be realized by the secret sharing device 100 shown in Figure 1 or Figure 10. However, since the true random number generation unit 10 is unnecessary, as shown in Figure 12, the true random number generation unit 10 may be eliminated, the first random number sent via the communication unit 16 may be sent to the memory unit 14, and the secret sharing unit 12 may have a simple configuration specialized for the processing of
[10] to
[13] . Furthermore, communication with the receiver device 304 does not have to be performed directly by the TTP 300; instead, a second random number concealed by the first random number of the receiver device 304 may be sent to the sender device 302, and the sender device 302 may send it. Furthermore, tens or hundreds of bits at specified positions in the information sent in [7] and [8] may be encrypted as information indicating who is communicating with whom, information indicating the date and time of transmission, etc., as information indicating the legitimacy of the transmitted information, so that the sender device 302 and the receiver device 304 can verify it.
[0136] Furthermore, when multiple people perform secure computation, the distribution of conversion random number sets can be performed as follows (the registration process is similar). However, it is assumed that the users performing secure computation are users of the system operated by the TTP 300.
[0137] As described above, this embodiment can achieve information-theoretic security for the entire system, including communications.
[0138] [Conversion Random Number Distribution Process]
[21] A representative user device among multiple secure computations notifies the communication units 16 of the other user devices performing the secure computation that it will perform the secure computation.
[22] The communication unit 16 of the representative user device notifies the TTP 300 of parameters such as (n, k, p), the number of conversion random number sets required, and the users participating in the secure computation, and requests the generation and distribution of conversion random number sets.
[23] The true random number generation unit 10 of the TTP 300 generates k random numbers for each of the requested number of conversion random number sets, and the conversion random number set generation unit multiplies the k random numbers and performs secret sharing to combine the reciprocals of the k random numbers with the k distribution values one by one to form k conversion random number sets.
[0139] The k conversion random number sets are an example of the "support value" of the technology of the present disclosure.
[24] The concealment unit of the TTP 300 conceals (Vernam ciphers) the conversion random number sets using the first random numbers of each user device participating in the secure computation, and the communication unit 16 sends the concealed conversion random number sets and information on the first random number used for encryption to each user device participating in the secure computation.
[25] After transmitting the conversion random number sets to each user device, the TTP 300 promptly deletes them.
[26] The secure computation unit of each user device extracts the conversion random number sets using the first random numbers shared with the TTP 300 starting from the specified number.
[27] The secure computation unit of each user device performs secure computation using the extracted conversion random number sets.
[0140] It is clear that this TTP 300 can also be realized by the secret sharing apparatus of the first embodiment. Also, if each user device has the secret sharing apparatus of the third embodiment, it can perform the secret computation by multiple people shown in the third embodiment after receiving the conversion random number set from the TTP 300. In this embodiment, the information communicated is Vernam-encrypted using true random numbers, so information-theoretic security is realized.
[0141] This mechanism is not limited to the distribution of conversion random number sets in the TUS method, but can also be used for the distribution of shares of random numbers called Multiplication Triple in the SPDZ method shown in Non-Patent Document 2. In this case, the term "conversion random number set" in the above procedure can be changed to "Multiplication Triple", and
[23] can be changed to "TTP 300 generates two random numbers a and b for each requested number of Multiplication Triples, calculates their product c = ab, and performs secret sharing of a, b, and c to generate a set of shares."
[0142]
[0143] In this case, the TTP 300 includes a secret sharing unit that, after the first user random numbers stored in each of the plurality of user devices are stored in the storage unit, calculates multiplication values by multiplying the two true random numbers acquired from the true random number generation unit and calculates k shared values from each of the two true random numbers and the multiplication values, a configuration unit that configures a Multiplication Triple by combining three sets of the k shared values, one for each set, and a concealment unit that conceals the Multiplication Triple with the first user random number of each of the plurality of user devices, and the communication unit sends information obtained as a result of the concealment to each of the plurality of user devices.
[0144] In this embodiment, k conversion random number sets are calculated as an example of support values, but the technology of the present disclosure is not limited to this. For example, there are the Multiplication Triple shown in Non-Patent Document 2 and the first variance value shown in the fifth embodiment (the second variance value is calculated on the assumption that it is calculated using the same mechanism as the first variance value).
[0145] In addition, it is clear that the TTP of this embodiment can also be applied to cases where data generated by a common mechanism is distributed individually and securely. <Fifth Embodiment> In public key cryptography, there is a mechanism called PKI (Public Key Infrastructure) in which a TTP called a CA (Certificate Authority) guarantees the legitimacy of a public key (information such as the key owner, key value, and the CA that guarantees it) using a public key certificate. In PKI, the CA guarantees the legitimacy of a user's public key by attaching a digital signature to the public key certificate. However, this is premised on the user trusting the CA.
[0146] Consider configuring a similar mechanism using secret sharing. In the fifth embodiment, a TTP 300 that realizes the Vernam cipher shown in the fourth embodiment is provided (user devices participating in this mechanism perform the [registration process] shown in the fourth embodiment).
[0147] In the fifth embodiment, the sender device 302 shown in Fig. 13 corresponds to user device A, and the receiver device 304 corresponds to user device B. User device A has the same configuration as the sender device 302, and user device B has the same configuration as the receiver device 304.
[0148] If the public key certificate for the public key of user device A is K, the TTP 300 issues a certificate as follows: Since n = k = 2 below, the problem can be solved by collecting two shares, S1 (the share obtained by directly using a random number as a share is called the first share) and S2 (the share calculated as follows is called the second share).
[0149] [Certificate Issuance Process]
[31] When user device A wants to send K to user device B, the following process is performed in the confidentiality unit, and the communication unit 16 encrypts the two random numbers (S1, x 1 (1) The secret part of the user device A notifies the TTP 300 of the number S1=K+a, which corresponds to the first shared value. 1 x 0 (S1, K, x 0 is fixed) so a 1 (2) The secret part of the user device A calculates the second shared value S2 = K + a 1 x 1 (3) The secret part of TTP 300 is calculated by user device A (S1, x 1 ) is concealed by the first random number of user device B and sent together with the information of user device A.
[32] User device B recovers K from S1 and S2.
[0150] The reason for using secret sharing in the above is that standard information such as a public key certificate makes it easy to infer the contents of K (such as the name of user device A, its public key, and the name of the CA). If K is sent using the Vernam cipher, the ciphertext will be K+S1 (in this case, S1 is not a shared value but is simply used as a random number), and if an attacker can infer the value and position of K in the ciphertext, they can add a differential value to that position (for example, if K is written in ASCII code, they can add the ASCII code difference to the value of K), allowing them to tamper as intended.
[0151] On the other hand, in the case of secret sharing, even if a similar tampering is performed on K, which is the constant term of S2, S1, x 1 Since the attacker does not know the value, the restored value by S1 and S2 will not be the value intended by the attacker and will not be restored correctly. Therefore, if user device B trusts TTP 300, if there is nothing strange about the restored K, the sent information is the information from user device A indicated by TTP 300, and the information has not been tampered with, and user authentication and message authentication can be achieved at the same time, and a role similar to that of an electronic signature can be played.
[0152] The above is not limited to public key certificates, and can be used when user device A wants to prove that information sent to user device B is legitimate.
[0153] Furthermore, if the user device A and the user device B share the second random number as in the fourth embodiment, the TTP 300 will 1 ), user device A can send the number of the second random number used by user device A (in this case, the second random number is also assumed to be a number) to user device B, and if there is nothing strange about the information restored by user device B using that random number, the information received by user device B is information from user device A, which shares the second random number via TTP 300, and has not been tampered with, and user authentication and message authentication can be achieved simultaneously at any time.
[0154] However, a of
[31] (1) 1 Haa 1 = (S1 - K) / x 0 So x 0 = 1, or 1 / x 0 If the above formula is sent to the calculation unit 12B, division is eliminated and processing can be made more efficient.
[0155] However, the first random number or the second random number can only be used once, as in the case of the Vernam cipher. This is because if K is made public, S2 can 1 can be calculated, and then S1, i.e., the value of the random number used, can be known. If S1 is used multiple times, an attacker can also use that S1 to tamper with it as intended. Therefore, if S1 is not used multiple times, K can be made public.
[0156] Also, the order of the first distributed value can be increased to complicate the structure of the transmitted second distributed value and make it more difficult to tamper with.
[0157] The user device A (i.e., the sender device 302) includes a random number calculation unit that sets a required number of random numbers from the first sender random numbers as first distribution values, and calculates random numbers used as coefficients of orders other than the constant term of the first distribution value from the first distribution values and secret information held by the sender device, and a distribution value calculation unit that calculates second distribution values using the secret information held by the sender device, the random numbers, and random numbers of orders having the random numbers as coefficients. The communication unit 16 sends the second distribution values to the user device B (i.e., the receiver device 304).
[0158] Specifically, in the above [Certificate Issuance Process], n=k=2, but if n=k=3, for example, the random number calculation unit uses k-1 (in this case, 2) random numbers from the first random number (first sender random number) and sets them as S1 and S2 below. 1 , a 2 Calculate (S1, S2, K, x 0 , x 1 is determined). The variance calculation unit calculates a 1 , a 2 (In this case, S3 is the second variance value. However, x 1 is a constant, and x 2 is determined from the first random number and shared with user device B). S1 = K + a 1 x 0 +a 2 x 0 2 S2 = K + a 1 x 1 +a 2 x 1 2 S3 = K + a 1 x 2 +a 2 x 2 2 In this case, since n = k = 3, even if K is made public, 1 , a 2Since the random numbers used are not leaked and the values are unknown, security is improved. In this case, S1 and S2 are called first distributed values.
[0159] Alternatively, the following may be used: User device A takes less than k-1 random numbers (1 in this case) from the first random number as S1, and generates a new random number different from the sent random number, a 1 From S1 to a 2 (S1, K, a 1 , x 0 is determined), and S2 and S3 are calculated using the results and sent to user device B.
[0160] User device B (i.e., receiver device 304) includes a restoration unit that restores the secret information from the second shared value sent from user device A (i.e., sender device 302), the first shared value sent from TTP 300 (i.e., trusted third party device), and the order whose coefficient is the random number used in the second shared value. Specifically, the restoration unit of user device B calculates K from S1 obtained from TTP 300 and S2 and S3 sent from user device A. This makes it possible to complicate the structure of the shared values and reduce the number of random numbers used and sent from TTP 300. In this case, S2 and S3 are called second shared values. <Sixth Embodiment> The second embodiment showed an application example of the TUS method when the number of users is limited to one. The sixth and seventh embodiments show application examples of the TUS method when the number of users is limited to two. Therefore, this embodiment does not use TTP or Vernam cipher, and instead includes a prover device 402 and a verifier device 404, as shown in Fig. 14. The prover device 402 and the verifier device 404 include a secret sharing unit, a storage unit, a communication unit, etc., similar to the secret sharing device 100 shown in Fig. 1A. The servers of the other embodiments have a similar configuration.
[0161] The prover device 402 is an example of the "verification request device" of the technology of the present disclosure.
[0162] In this embodiment, secret sharing is used to realize identity authentication in which the prover device 402 can prove that it is the person who registered authentication information such as a password in the verifier device 404 by secretly sending information indicating that it is the person who knows the authentication information to the verifier device 404, which is the registration destination, and the verifier device 404 can authenticate the person while keeping the information secret.
[0163] For simplicity, the prover device 402 and the verifier device 404 are configured in the same manner as the secret sharing device 100 of the third embodiment. In the case of personal authentication, n=k=2, and a key corresponding to a password and x corresponding to a server ID are used. 0 The following explanation will be given assuming that the (random number) is determined in advance between prover device 402 and verifier device 404 and set in setting control unit 12A. Also, i represents the number of times, and is initially registered as i=1. The processing for the i-th time is shown below.
[0164] [Personal authentication procedure]
[41] The prover device 402 receives a set of random numbers for conversion (1 / e i,0 , [e i ] 0 ), (1 / e i,1 , [e i ] 1 The prover device 402 generates a set of random numbers for conversion (1 / e i,0 , [e i ] 0 ) to the verifier device 404 via the communication unit 16.
[0165] The verifier device 404 stores (1 / e i,0 , [e i ] 0 ) is memorized.
[0166] The prover device 402 uses its own conversion random number set (1 / e i,1 , [e i ] 1 ) is stored in the storage unit 14 of the prover device 402.
[42] The setting control unit 12A of the prover device 402 stores the random number b i is extracted and calculated by the calculation unit 12B. i (Key+i), [e i ] 1 (Key+i) is calculated and sent to the verifier device 404 via the communication unit 16, and 1 / b iis calculated and stored in the storage unit 14.
[0167] (Key+i) is an example of "information that combines authentication information and information that differs for each transmission" in the technology of the present disclosure.
[0168] The bi(Key+i) is an example of the “transformed transmission information” of the technique of the present disclosure.
[43] The setting control unit 12A of the prover device 402 generates the random number d i is extracted and the secure computation unit 18 calculates d i / b i , d i / e i,1 and sends it to the verifier device 404 via the communication unit 16.
[0169] Also, the prover device 402 updates i to i+1.
[44] The secure computing unit 18 of the verifier device 404 receives d i / b i = 0, d i / e i,1 If ≠0, the verifier does not authenticate the conversion random number set (1 / f i,1 , [f i ] 1 ), (1 / f i,0 , [f i ] 0 ) and stores it in the storage unit 14.
[46] The verifier device 404 generates a random number c i is extracted and the following is calculated by the secure computation unit 18: i d i ) / (f i b i ) = c i / f i ×d i / b i , (c i d i ) / e i = c i / e i,0 ×d i / e i,1
[47] The verifier device 404 sends the registration information Key,i stored in the setting control unit 12A to the secure computing unit 18, i d i [A] 0The latter half of Key+i is generated, and the following is calculated by the secure computation unit 18: i d i [A] 0 = b i (Key + i) × (c i d i ) / (b i f i ) × [f i ] 0 -(Key+i)×(c i d i ) / e i × [e i ] 0 c i d i [A] 1 = b i (Key + i) × (c i d i ) / (b i f i ) × [f i ] 1 - [e i ] 1 (Key + i) × (c i d i ) / e i The above calculation (subtraction) performed by the secure computation unit 18 is an example of the "secret subtraction" of the technique of the present disclosure.
[48] The secure computation unit 18 of the verifier device 404 calculates d[A] 0 , d[A] 1 is restored and if it is 0, the prover device 402 is authenticated, and if it is not 0, it is rejected.
[0170] The secure computing unit 18 of the verifier device 404 is an example of the "verification unit" of the technology of the present disclosure.
[49] If the authentication is successful, the setting control unit 12A of the verifier device 404 updates i to i+1.
[0171] This is the b sent by the prover device 402. i This is a process in which the verifier device 404 looks up (Key+i) by the registered correct value to confirm whether the prover device 402 knows the correct value.
[0172] c in
[47] i d i [A] 0Since the latter half of (Key+i) is created using the registration information, if it is different from the first half that was sent, it will not be 0.
[0173] Furthermore, if
[41] to
[43] are sent together, only one communication is required.
[0174] Furthermore, although the Key is a password, it may also be biometric information such as fingerprint information or image information.
[0175] However, since there is a possibility that different Key' and i' may coincidentally result in Key+i = Key'+i', if two different passwords, i.e., Key and Key0, are set and the same process is performed, Key+i and Key0+i will not become 0 at the same time.
[0176] Furthermore, if the verifier device 404 returns a signal indicating successful authentication to the prover device in
[49] , the update i=i+1 of the prover device 402 performed in
[43] may be performed after receiving that signal.
[0177] [Proof of Security] Assume that the prover device 402 and the verifier device 404 do not commit any fraud and manage registered information securely. In this case, an attacker attempts to learn registered information, including the key, from the information flowing through the communication path between the prover device 402 and the verifier device 404, and if he obtains this information, the attack is deemed successful. Therefore, the attacker obtains the following in the i-th communication. Ai = {(1 / e i,0 , [e i ] 0 ), b i (Key+i), [e i ] 1 (Key + i), d i / b i , d i / e i,1} Variables other than Key and i are truly random numbers and are different each time, and the combination of variables cannot be decomposed into individual values. However, b i (Key+i), [e i ] 1 (Key+i) is the same value used twice. The ratio is b i / [e i ] 1 is obtained, and d i / b iHowever, it cannot be decomposed into individual values. Also, since i is updated at i = i + 1, replay attacks are not possible. i ] 1 ) (Key + i) is known, but the next value is chosen independently, e.g., b i+1 Since (Key+i+1) is calculated, spoofing is not possible. Therefore, the attacker cannot obtain information from Ai, and the following holds:
[0178]
[0179] Therefore, it can be said that information-theoretic security is achieved by this embodiment.
[0180] If the verifier device 404 does not want to know the key, the prover device 402 can send the key to the verifier device 404 instead of the key.
[0181]
[0182] In this case, in
[43] , d 1 / b i , d 1 / e i,1 In addition to the above, the following is calculated and sent to the verifier device 404:
[0183]
[0184] Also,
[47] becomes as follows:
[0185] The verifier device 404 uses the registration information [Key] stored in the setting control unit 12A. 1 d 1,i is sent to the secure computing unit 18, and c i d i [A] 1 The second half of [Key] 1 d i,i is generated from the registration information, and the following is calculated by the secure computation unit 18.
[0186]
[0187] In the above
[0188]
[0189] are sent as individual pieces of information and cannot be broken down.
[0190]
[0191] of,
[0192]
[0193] Dividing by [e i ] 1 Obtained e i was leaked, ([Key] 0 ×e i + i × [e i ] 0 ) to [Key] 0 is obtained.
[0194] However, [Key] 1 d 1 Since the key is not leaked, the above formula (8) holds true, and information-theoretic security is maintained. To improve security, the initial i and the 1 to be added are used as random numbers, or the server ID x 0 Not only x 1 Alternatively, the secret number may be a secret random number. <Seventh Embodiment> This embodiment is also an application example of the TUS method when the number of users is limited to two. Therefore, this embodiment does not use TTP or Vernam cipher, and includes a first user device 502 of user A and a second device 504 of user B, as shown in FIG. 15. This embodiment illustrates a case where the first user device 502 and the second device 504 use secret sharing to communicate secret information of the first user device 502 to the second device 504 with theoretical security. However, the first user device 502 and the second device 504 have the same configuration as the secret sharing device of the third embodiment. The first user device 502 and the second device 504 have a secret sharing unit, a storage unit, a communication unit, etc., similar to the secret sharing device 100 shown in FIG. 1A. The servers of the other embodiments have similar configurations.
[0195] As mentioned above, the Vernam cipher is known as a cipher with information-theoretic security, but the Vernam cipher requires a large amount of truly random numbers to be shared in advance between the sender device and the receiver device, which is time-consuming.
[0196] In contrast, in this embodiment, secret information can be shared with information-theoretic security by sharing a relatively small amount of information. However, n = k = 2, and in the following, the second device 504 generates three random numbers ([e 1 ] 1 , e 1,1 , d 1 ) and is shared with the first device 502.
[0197] [e 1 ] 1 , is an example of "first registration information" in the technology of the present disclosure.
[0198] d 1 is an example of the "second registration information" of the technology of the present disclosure.
[0199] e 1,1 is an example of the "third registration information" of the technology of the present disclosure.
[0200] The state of the i-th communication is shown below.
[0201] [Secret sharing unit 12: concealment of secret information (for secret communication)]
[51] The first user device 502 receives secret information a i The true random number generator 10 generates a random number b i
[52] The calculation unit 12B of the first user device 502 extracts the transmitted b i Using secret information a i For b i (a i
[53] The calculation unit 12B of the first user device 502 calculates b i Calculate the reciprocal of 1 / b i is sent to the storage unit 14, and b is sent via the communication unit 16. i (a i +1) to the second device 504.
[0202] [Secret calculation unit 12B: secret communication]
[61] The first user device 502 receives a random number e i Generate and given [e1] 1 From the following i Calculate [e i ] 0 = e i +r i x0 and sends it to the second device 504. 1 ] 1 = e i +r i x 1
[62] The first user device 502 is connected to the shared 1 , e 1,1 From d 1 / b i e i,0 = (d 1 ×e 1,1 ) / (b i ×e i ) and sends it to the second device 504.
[63] The second device 504 calculates the random number c i is extracted from the true random number generation unit 10, and the secure computation unit 18 extracts c i / e 1,1 Calculate the following deletion random numbers:
[0203]
[0204]
[64] The secure computing unit 18 of the second device 504 is i d 1 (a i +1) 0 , [c i d 1 (a i +1) 1 Calculate .
[0205]
[0206] b i (a i +1) and (c i d i ) / (b i e i ) and [e i ] 0 , [e 1 ] 1 The calculation using is an example of "the secure calculation according to claim 4 in claim 14" of the technology of the present disclosure.
[0207] [Reconstruction] The calculation unit 12B of the second device 504 is i d i (a i +1) is restored, and the secret information a of the first user device 502 is obtained from the following:i get.
[0208]
[0209] b sent in
[53] i (a i +1) is a i If is a positive integer, it is not 0, so b i a i In this case, subtraction of 1 in [Restore] becomes unnecessary. [Proof of Security] In the above, it is assumed that the first user device 502 and the second user device 504 are not tampered with and their internal analysis is not performed. In this case, the attacker attempts to obtain secret information from the information flowing through the communication path, and if the secret information is obtained, the attack is deemed successful. The attacker obtains the following in the i-th communication. Bi={b i (a i +1), [e i ] 0 , d 1 / b i e i,0} In Bi, b i , a i is determined arbitrarily. Also, the conversion random number set ([e 1 ] 1 , 1 / e 1,1 ) is fixed, and e i are truly random numbers that are different each time, and from these, another set of random numbers for conversion ([e i ] 0 , 1 / e i,0 ) is calculated. In this case, [e 1 ] 1 If we set t to t, we get the following: t=e 1 +r 1 x 1 , [e 1 ] 0 = e 1 +r 1 x 0 (9) t = e 2 +r 2 x 1 , [e 2 ] 0 = e 2 +r 2 x 0 (10) t = e 3 +r 3 x 1, [e 3 ] 0 = e 3 +r 3 x 0 (11) From equation (9), e 1 =t-r 1 x 1 Therefore, [e 1 ] 0 = t + r 1 (x 0 -x 1 ), (10) from the equation 2 =t-r 2 x 1 Therefore, [e 2 ] 0 = t + r 2 (x 0 -x 1 ), (11) From the equation 3 =t-r 3 x 1 Therefore, [e 3 ] 0 = t + r 3 (x 0 -x 1 ), therefore, [e 1 ] 0 -r 1 (x 0 -x 1 ) = [e 2 ] 0 -r 2 (x 0 -x 1 ) = [e 3 ] 0 -r 3 (x 0 -x 1 )...
[0210] [e 1 ] 0 , [e 2 ] 0 , [e 3 ] 0 , (x 0 -x 1 ) is known, so one r i , i.e., one e i If leaked, all e iis leaked. i is confidential information a i If i If the information is made public, all confidential information will be leaked. i is a value that is combined with other random numbers and deleted during the restoration process, and is not leaked from Bi. i , a i Even if you know the next b i+1 , a i+1 is determined independently of them, so it is secure against known plaintext attacks, and b i Even if it is known, 1 / b i e i,0 From e i does not leak. Therefore, e i To know the value, the first user device 502 generates an i or [e 1 ] 1 However, even if the Vernam cipher is used, if the random number set in the device is known, the secret information will be leaked. Therefore, 1 ] 1 , e 1,1 , d 1 ) is not leaked, it can be said to be information-theoretically secure. 1 is also fixed, but c i , b i , e i,0 Since d changes every time 1 Therefore, ([e 1 ] 1 , e 1,1 , d 1 ) is not known, the following can be said. i can be said to be communicated with information-theoretic security. 1 ] 1 , e 1,1 [e 1 ]0, e 1,0 The inverse operation may be performed as follows.
[0211]
[0212] Furthermore, it is shared ([e 1 ] 1 , e 1,1 , d 1 ) an attacker cannot send the intended secret information. 0 or x 0 , x 1 is also a random number ([e 1 ] 1 , e 1,1 , d 1 ) may be shared first as well.
[0213] Also, the three a sent i to a new ([e 1 ] 1 , e 1,1 , d 1 ) before being updated. 1 ] 1 , e 1,1 , d 1 ) confidential information will not be leaked from the information before the update.
[0214] In addition, in the [secret calculation unit 12B: secret communication], [e 1 ] 1 are the plurality of first dispersion values in the fifth embodiment, and [e i ] 0 can be the plurality of second variance values in the fifth embodiment.
[0215] Furthermore, this embodiment can be said to be suitable for cryptographic communication with IoT devices. For example, when performing cryptographic communication using the Vernam cipher, the IoT device needs to have a large amount of true random numbers in advance, and once the random numbers are used up, cryptographic communication becomes impossible. In contrast, in this embodiment, if the first user device 502 is an IoT device and the second device 504 is a receiving device that receives information from the IoT device, (d 1 , [e 1 ] 1 , e 1,1 ) is initially set and shared with the IoT device, then in [Confidentiality of Confidential Information], the information in 3. is sent, and in [Secure Computation] 1, 2., [e 1 ] 0 and d0 / (b 1 e 1,0 ), it is possible to realize information-theoretically secure encrypted communication thereafter without using the Vernam cipher. However, if the first user device 502, which is an IoT device, is analyzed, the secret information will be leaked, and this is also the case with the Vernam cipher. In addition, as mentioned above, it is not possible for an attacker to send the secret information he intended, and 1 ] 1 , e 1,1 , d 1 ) is not known, updating the value will not leak previous secret information, just as in the case of the Vernam cipher. <Other Embodiments> In the above embodiments, it is assumed that only authorized users can input to the setting control unit 12A and calculate and communicate the distributed values. This may be handled by the smartphone or PC into which the device of the technology disclosed herein is inserted. It is also assumed that the input secret information is safely managed by the second embodiment or the like until it is input into the device of the technology disclosed herein. When input from outside, it is assumed that the secret information is sent using the Vernam cipher according to the fourth embodiment.
[0216] Furthermore, in the above embodiment, for the sake of simplicity, n=k=2 or the like is fixed, but it is clear that the present invention can be expanded to other values.
[0217] Furthermore, if the external server is tampered with or the device of the disclosed technology is lost, confidential information will be lost, so the external server and the device of the disclosed technology need to be backed up periodically.
[0218] In addition, to detect tampering with external servers, 1 (a 1 +1) is secretly shared with n=k=2, for example, 1 (a 1 +1)] 1 A b 1 (a 1 +1) to the external server, along with [b 1 (a 1 +1)]0 is stored in the device of the disclosed technology, and when the data is used, it is restored and if it matches, it can be confirmed that it has not been tampered with.
[0219] Furthermore, although the above embodiment has been described using the Shamir algorithm, it is clear that the invention can also be realized using an additive secret sharing algorithm.
[0220] Specific application examples (modifications) of the device of the technology of the present disclosure are shown in FIGS. 16 to 19. FIG.
[0221] 16 shows a case where the secret sharing apparatus 100 shown in the first embodiment is inserted into a smartphone, and personal information such as blood pressure and blood glucose levels is secretly managed by the individual. A server managed by an individual or a hospital is used as the server 110. This allows personal information to be easily managed with information-theoretic security. It is clear that the apparatus of the technology disclosed herein can also be used to manage money and other daily information with information-theoretic security, in addition to managing information about blood pressure and blood glucose levels.
[0222] FIG. 17 shows a case where a doctor DC inserts the secret sharing apparatus 100 shown in the second embodiment into a PC and performs statistical processing on the data of many patients for whom he is responsible. The doctor inputs the patient data, and the processing shown in the [Secret sharing unit 12: Concealment of secret information (single-person use)] of the second embodiment is performed and the data is securely stored. Statistical processing can be performed without restoring the concealed stored data using the TUS method. However, when statistical processing is performed by one person using the device of the technology disclosed herein, calculations can also be performed using the [Secure computation unit 18: Single-person use]. However, when using data from other doctors, the secure computation for multiple people shown in the third embodiment can be performed. When calculations are repeated, the calculations can be performed by repeatedly performing calculations without restoring the obtained calculation results. Furthermore, it is clear that the present invention can be used not only for medical data, but also for internal data in companies, etc.
[0223] 18 shows a case where the organizations 600A to 600D share conversion random number sets using the fourth embodiment and perform data comparisons and statistical calculations among themselves without disclosing their internal data using the third embodiment. Each organization 600A to 600D inserts the secret sharing apparatus 100 into a PC that communicates with the other organizations, and shares the conversion random number sets shown in the fourth embodiment. After that, the third embodiment is executed, and the shares of the calculation results obtained are exchanged via the communication unit 16. When these shares are restored by each organization 600A to 600D, the same results are shared. Furthermore, communication between each organization 600A to 600D can be performed securely using the Vernam cipher shown in the fourth embodiment.
[0224] 19 shows a case where personal authentication is performed using the sixth embodiment. It can be seen that this embodiment allows personal authentication to be realized with information-theoretic security without using TTP.
[0225] 20 shows a case where data is collected from an IoT device using the seventh embodiment. This can also be achieved with information-theoretic security without using TTP.
[0226] Furthermore, the fifth embodiment allows user authentication and message authentication to be simultaneously realized with information-theoretic security, although this requires TTP.
[0227] <Modifications> (Modification of the Third Embodiment) As described above, the third embodiment shows a case where multiple users jointly perform secure computation using their respective secret information, but conversion random number sets are distributed in advance to participants in the secure computation, including the device of the technology of the present disclosure, using the fourth embodiment described below. The present invention is not limited to this. Conversion random number sets may also be distributed in advance to participants in the secure computation, including the device of the technology of the present disclosure, using the seventh embodiment or a modification of the seventh embodiment described below.
[0228] As described above, in the third embodiment, in the simplified version of [secret computation unit 18: for multiple users] [secret sharing unit 12: restoration] in which the amount of calculation is reduced by setting n = k = 3 in step 78, if there is a restorer, the data is sent secretly using the Vernam cipher according to the fourth embodiment (described in detail later). The present invention is not limited to this. If there is a restorer, the data may be sent secretly using the Vernam cipher according to the seventh embodiment or a modified version of the seventh embodiment (described in detail later).
[0229] As described above, in the third embodiment, in [Secret sharing unit 12: Concealment of secret information (for multiple users)] 5, g conversion random number sets are sent from the TTP in the fourth embodiment. The present invention is not limited to this. The g conversion random number sets may be sent from the TTP in the seventh embodiment or a modified example of the seventh embodiment described later.
[0230] As described above, in the third embodiment, in the [secret computation unit 18: for multiple users] 2, the deletion random number piece is calculated and stored in the user device S 0 The present invention is not limited to this. From now on, it is the user device S that sends the deletion random number pieces. 0 The values may be exchanged.
[0231] (Variation of the Sixth Embodiment) As described above, in the sixth embodiment, the prover device 402 and the verifier device 404 are provided with a secret sharing unit, a storage unit, a communication unit, etc., similar to the secret sharing apparatus 100 shown in Fig. 1A. The present invention is not limited to this. The prover device 402 and the verifier device 404 may be provided with a secret sharing unit, a storage unit, a secret calculation unit, a communication unit, etc., similar to the secret sharing apparatus 100 shown in Fig. 10.
[0232] As described above, in the sixth embodiment, in
[48] of the [personal authentication procedure], the secure computing unit 18 of the verifier device 404 calculates d[A] 0 , d[A] 1 is restored and if it is 0, the prover device 402 is authenticated, and if it is not 0, it is rejected. 0 is a value indicating a match. Here, 0 is a value indicating a match.
[0233] As described above, in the sixth embodiment, c in
[47] of [Personal Authentication Procedure]i d i [A] The second half of 0 (Key + i) is created using registration information, so if it is different from the first half that was sent, it will not be 0. If it is different from the first half that was sent in this way, it will not be 0 and will not match.
[0234] As described above, in the sixth embodiment, Key is a password, but it can also be biometric information such as fingerprint information or image information. However, since there is a possibility that different Key' and i' may coincidentally result in Key+i=Key'+i', if two different passwords, i.e., Key and Key0, are set and the same process is performed, Key+i and Key0+i will not simultaneously become 0. In this case, Key and i may also be concatenated to form Key|i (| represents concatenation), and the process of preventing coincidence is not limited to this. In addition, the verifier device may generate a conversion random number set (1 / f i,1 , [f i ] 1 ), (1 / f i,0 , [f i ] 0 ) and c i generated, but f i,1 = f i,1 = c i = 1, and the processing related to these may be omitted.
[0235] As described above, in the sixth embodiment, a process is defined for when the verifier device 404 does not want to know the key. The present invention is not limited to this. In this case,
[42] to
[47] may be as follows.
[42] The setting control unit 12A of the prover device 402 sets the random number b i is extracted and calculated by the calculation unit 12B. i (Key+i) is calculated and sent to the verifier device 404 via the communication unit 16, and 1 / b i is calculated and stored in the storage unit 14.
[0236] (Key+i) is an example of "information that combines authentication information and information that differs for each transmission" in the technology of the present disclosure.
[0237] bi(Key+i) is an example of the "transformed transmission information" of the technique of the present disclosure.
[43] The setting control unit 12A of the prover device 402 generates the random number d'i Cut out and put d i = d' i +d1, the secure computation unit 18 computes the following and sends it to the verifier device 404 via the communication unit 16. The prover device 402 also updates i to i+1. d i / b i , [Key] 1 d i ',d i ([Key] 0 + i × 1 / e i × [e i ] 0 ), (d i / e i × [e i ] 1 )
[44] The secure computing unit 18 of the verifier device 404 is [Key] 1 d i If all the values sent except for ' are 0, it is considered as fraud and is not authenticated (0 is not used as the random number used in secure computation).
[45] The verifier device 404 sends the registration information [Key]1d1,i stored in the setting control unit 12A to the secure computation unit 18, which then calculates the following: d i [A] 0 = b i (Key + i) × d i / b i -d i ([Key] 0 + i × 1 / e i × [e i ] 0 ) d i [A] 1 = b i (Key + i) × d i / b i - ([Key] 1 d 1 + [Key] 1 d i ') + i × (d i / e i × [e i ] 1 The above calculation (subtraction) performed by the secure calculation unit 18 is an example of the "secret subtraction" of the technique of the present disclosure.
[0238]
[46]
[47] are omitted.
[0239] In the above, d i ([Key] 0 + i × 1 / e i × [e i ] 0 ), (d i / e i × [e i ] 1 ) are sent as individual pieces of information and cannot be decomposed. Therefore, the above formula (8) holds, and information-theoretic security is maintained. To improve security, the initial i and the 1 to be added are used as random numbers, or the server ID x 0 Not only x 1 may also be a secret random number.
[0240] (Variation of the Seventh Embodiment) As described above, in the seventh embodiment, the first user device 502 and the second device 504 are provided with a secret sharing unit, a storage unit, a communication unit, etc., similar to the secret sharing apparatus 100 shown in Fig. 1A. The present invention is not limited to this. The first user device 502 and the second device 504 are provided with a secret sharing unit, a storage unit, a secret calculation unit, a communication unit, etc., similar to the secret sharing apparatus 100 shown in Fig. 10, and the servers of the other embodiments may also have a similar configuration.
[0241] As mentioned above, the Vernam cipher is known as a cipher with information-theoretic security, but the Vernam cipher requires a large number of truly random numbers to be shared in advance between the sender device and the receiver device, which is time-consuming. In contrast, the seventh embodiment makes it possible to share secret information with information-theoretic security by sharing only a small amount of information.
[0242] In the seventh embodiment, [e 1 ] 1 , is an example of the "first registration information" of the technology of the present disclosure, and d 1 is an example of the "second registration information" of the technology of the present disclosure, and e 1,1 is an example of the "third registration information" of the technology of the present disclosure. 1 ] 1 , e 1,1 , d 1 ) is the fifth random number to be registered.
[0243] In the seventh embodiment, b in
[52] of [Secret sharing unit 12: concealment of secret information (for secret communication)] i is a sixth random number that conceals secret information.
[0244] In the seventh embodiment, e in
[62] of [Secret sharing unit 12: concealment of secret information (for secret communication)] i is the random number c for deletion i d 1 / b i e i is the seventh random number for generating
[0245] In the seventh embodiment, it is shared ([e 1 ] 1 , e 1,1 , d 1 ), an attacker cannot send the intended secret information. 0 , x 1 is also a random number ([e 1 ] 1 , e 1,1 , d 1 ) can be shared at first. Also, the three a i to a new ([e 1 ] 1 , e 1,1 , d 1 ) before being updated. 1 ] 1 , e 1,1 , d 1 ) confidential information will not be leaked from the information before the update.
[0246] However, d 1 = c 1 = 1. In this case, what is shared is ([e 1 ] 1 , e 1,1 )
Claims
1. A secret sharing device having: a true random number generation unit that generates true random numbers; and a calculation unit that secretly shares a value obtained by multiplying k (k>1) true random numbers from the true random number generation unit, sets one of the k true random numbers as a first random number, calculates its inverse, and combines the inverse with one of the secretly shared shared values to calculate k sets of conversion random numbers.
2. A secret sharing device having: a true random number generation unit that generates true random numbers; and a calculation unit that performs secret calculation on the secret information by adding secret information and a constant or random number including 0 determined from the range of the secret information and the calculation result of a secret calculation, and multiplying the sum by one true random number from the true random number generation unit as a second random number.
3. The secret sharing device according to claim 2, wherein the calculation unit calculates the inverse of the second random number, and further comprises a memory unit that stores the inverse of the second random number.
4. A secret sharing device as described in claim 2, further comprising: a deletion random number obtained by multiplying the inverse of the first random number as described in claim 1 or the inverse of the first random number provided from outside, a third random number obtained from the true random number generation unit, and the inverse of the second random number, multiplied by a deletion random number piece for deleting the second random number in the secret information; and a secret calculation unit that performs secret calculation without performing division using the sharing value as described in claim 1 and the secret information that has been secretly calculated.
5. An assistance device for assisting a sender device and a receiver device which perform encrypted communication with each other, comprising: a true random number generation unit which generates true random numbers; a memory unit which stores the true random numbers generated by the true random number generation unit and transmitted to and stored in the sender device as a first sender random number group, and stores the true random numbers transmitted to and stored in the receiver device, which are different from the first sender random number group, as a first receiver random number group; a secret calculation unit which secretly calculates a second random number group which is a true random number generated by the true random number generation unit and used in encrypted communication between the sender device and the receiver device, using the first sender random number group, and secretly calculates the second random number group using the first receiver random number group; and a communication unit which transmits the second random number group secretly calculated using the first sender random number group to the sender device, and transmits the second random number group secretly calculated using the first receiver random number group to the receiver device.
6. The support device described in claim 5, further comprising: a support value calculation unit that stores a first user random number group stored by each of a plurality of user devices participating in a secure calculation based on secret sharing; a support value calculation unit that calculates a support value required by each of the user devices participating in the secure calculation; and a secure calculation unit that secretly calculates the calculated support value using the first user random number group of each of the plurality of user devices; and wherein the communication unit transmits the secretly calculated support value to each of the plurality of user devices.
7. The support device described in claim 6, wherein the support value calculation unit sets each of the k true random numbers as k first random numbers, calculates the inverses of the k first random numbers, and calculates k sets of conversion random numbers as the support values by combining each of the inverses of the k first random numbers with each of the shared values obtained by secretly sharing the multiplied values of the k first random numbers one by one.
8. The assistance device according to claim 6, comprising: a secret sharing unit that calculates a multiplication value by multiplying the two true random numbers obtained from the true random number generation unit after the first user random number group stored in each of the multiple user devices is stored in the memory unit, and calculates three sets of k shared values from each of the two true random numbers and the multiplication value; a configuration unit that configures a Multiplication Triple by combining each of the three sets of shared values; and a secure calculation unit that secretly calculates the Multiplication Triple with the first user random number of each of the multiple user devices, wherein the communication unit sends information obtained as a result of the secure calculation to each of the multiple user devices.
9. The assistance device described in claim 6, further comprising an identifier assignment unit that assigns an identifier to the first user random number group of each of the plurality of user devices so that the usage status of the first user random number group of each of the plurality of user devices can be determined, and the communication unit sends information obtained as a result of the secret calculation and the identifier to each of the plurality of user devices.
10. A user device comprising: a receiving unit that receives information obtained as a result of the secret calculation and the identifier from the support device described in claim 9; and a decryption unit that decrypts the information obtained as a result of the secret calculation using a first user random number to which the identifier is attached.
11. A sender device comprising: a random number calculation unit which sets a required number of random numbers from the first sender random number group or the second sender random number group as described in claim 5 as a first variance value group, and calculates random numbers used as coefficients of orders other than the constant term of the first variance value group from the first variance value group and secret information held by the sender device; a variance value calculation unit which calculates a second variance value group using the secret information held by the sender device, the random numbers, and random numbers of orders having the random numbers as coefficients; and a communication unit which sends the second variance value group to a receiver device.
12. A receiver device comprising a restoration unit that restores the secret information from the second group of shared values sent from the sender device described in claim 11, a first group of shared values which are a required number of random numbers from the first sender random number group or the second sender random number group sent from the support device described in claim 5, and an order whose coefficient is the random numbers used in the second group of shared values.
13. A verification request device that requests verification that it is the identity of the authentication information registered in a verifier device, comprising: a transformation unit that transforms transmission information obtained by secretly calculating information that combines the authentication information registered in the verifier device with information that differs for each transmission so that it can be verified by secret calculation; and a transmission unit that transmits the transformed transmission information to the verifier device, wherein the transformed transmission information is transformed such that the result of the secret subtraction becomes a value indicating a match only when the registered authentication information, the information that differs for each transmission, and the transformed transmission information match by secret subtraction using secret sharing.
14. A verifier device that registers authentication information as described in claim 13, comprising: a receiving unit that receives the transformed transmission information; and a verification unit that performs secret subtraction as described in claim 13 on the registered authentication information in the received transmission information, information that differs for each transmission, and the transformed transmission information, and verifies whether the result of the secret subtraction is a value that indicates a match.
15. A transmitting device that transmits secret information of its own device to a receiving device, comprising: a sharing unit that shares with the receiving device a portion of multiple random numbers from a true random number generation unit as a fifth random number; and a transmitting unit that performs a secret calculation on the secret information by multiplying the secret information by a sixth random number from the true random number generation unit and transmits the secret information to the receiving device, and also transmits to the receiving device a seventh random number generated from the true random number generation unit and a deletion random number that deletes the sixth random number from the registered fifth random number.
16. A secret sharing device comprising: a calculation unit that performs secret calculation on secret information by multiplying the secret information by one true random number from a true random number generation unit; calculates a random number used as a coefficient of an order other than the constant term of the first shared value group from a first shared value group that is first registration information and a fourth random number from the true random number generation unit; calculates a second shared value group using the fourth random number and the calculated random number; performs secret calculation without performing division using a deletion random number for deleting the one true random number in the secret information obtained by multiplying the product of the second registration information and the third registration information by the inverse of the product of the fourth random number and the one true random number, the first shared value, the second shared value, and the secret information that has been secretly calculated; and a communication unit that transmits the value calculated by the calculation unit.
17. A secret sharing program that causes a computer to execute a process of secretly sharing a value obtained by multiplying k (k>1) true random numbers from a true random number generator, designating one of the k true random numbers as a first random number, calculating its inverse, and combining the inverse with one of the secretly shared shares to calculate k sets of conversion random numbers.
18. A secret sharing program that causes a computer to execute a process of performing a secret calculation on the secret information by adding the secret information and a constant or random number, including 0, determined based on the range of the secret information and the calculation result of the secret calculation, and multiplying the added value by one true random number from a true random number generator as a second random number.
19. The secret sharing program according to claim 18, wherein the processing further includes: calculating the inverse of the second random number; and storing the inverse of the second random number in a memory unit.
20. The secret sharing program as claimed in claim 17, further comprising the step of performing a secret calculation without performing division using a deletion random number obtained by multiplying the inverse of the first random number as claimed in claim 17 or the inverse of a first random number provided from outside, a third random number obtained from the true random number generation unit, and the inverse of the second random number to obtain a deletion random number piece for deleting the second random number in the secret information, the sharing value as claimed in claim 16, and the secret information that has been secretly calculated.
21. A program causing a computer to execute a process for supporting a sender device and a receiver device which perform encrypted communication with each other, the process comprising: storing true random numbers generated by a true random number generation unit and transmitted to and stored in the sender device as a first sender random number group, and storing the true random numbers different from the first sender random number group and transmitted to and stored in the receiver device in a memory unit as a first receiver random number group; secretly calculating a second random number group which is a true random number generated by the true random number generation unit and used in encrypted communication between the sender device and the receiver device, using the first sender random number group, and secretly calculating the second random number group using the first receiver random number group; transmitting the second random number group secretly calculated using the first sender random number group to the sender device via the communication unit, and transmitting the second random number group secretly calculated using the first receiver random number group to the receiver device via the communication unit; Support programs, including:
22. The assistance program of claim 21, wherein the processing further includes: storing in the memory unit a first user random number group stored by each of a plurality of user devices participating in a secure computation based on secret sharing; calculating a support value required by each of the user devices participating in the secure computation; secretly calculating the calculated support value using the first user random number group of each of the plurality of user devices; and transmitting the secretly calculated support value to each of the plurality of user devices via a communication unit.
23. The assistance program of claim 22, wherein calculating the assistance value comprises: setting each of the k true random numbers as k first random numbers; calculating the inverses of the k first random numbers; and combining each of the inverses of the k first random numbers with each of the shared values obtained by secretly sharing the multiplied values of the k first random numbers, one by one, to calculate k sets of conversion random numbers as the assistance value.
24. The assistance program of claim 22, further comprising the steps of: after the first user random number group stored in each of the plurality of user devices is stored in the memory unit, calculating a multiplication value by multiplying the two true random numbers obtained from the true random number generation unit, and calculating three sets of k variance values from each of the two true random numbers and the multiplication value; constructing a Multiplication Triple by combining each of the three sets of variance values; secretly calculating the Multiplication Triple using the first user random numbers of each of the plurality of user devices; and sending information obtained as a result of the secret calculation to each of the plurality of user devices via a communication unit.
25. The assistance program described in claim 22, wherein the processing further includes: assigning an identifier to the first user random number of each of the multiple user devices so that the usage status of the first user random number of each of the multiple user devices is known; and sending information obtained as a result of the secret calculation and the identifier to each of the multiple user devices via a communication unit.
26. A user device program that causes a computer to execute a process including: receiving information obtained as a result of the secret calculation and the identifier sent by the processing of the assistance program described in claim 25; and decrypting the information obtained as a result of the secret calculation using the first user random number to which the identifier is attached.
27. A sender program that causes a computer to execute processes including: setting a required number of random numbers from the first sender random number group or the second sender random number group described in claim 21 as a first variance value group, and calculating random numbers used as coefficients of orders other than the constant term of the first variance value group from the first variance value group and secret information held by the sender device; calculating a second variance value group using the secret information held by the sender device, the random numbers, and a random number of an order having the random number as a coefficient; and sending the second variance value group to a receiver device.
28. A receiver program that causes a computer to execute a process that includes restoring the secret information from the second group of distributed values described in claim 26 sent from the sender device, a first group of distributed values that is a required number of random numbers from the first sender random number group or the second sender random number group in the processing of the assistance program described in claim 20, and an order whose coefficient is the random numbers used in the second group of distributed values.
29. A verification request program that causes a computer to execute a process to request verification that the user is the identity of the authentication information registered in a verifier device, the process including: transforming transmission information obtained by secretly calculating information that combines the authentication information registered in the verifier device with information that differs for each transmission so that it can be verified by secret calculation; and transmitting the transformed transmission information to the verifier device; the transformed transmission information is transformed such that the result of secret subtraction becomes 0 only when the registered authentication information, the information that differs for each transmission, and the transformed transmission information match through secret subtraction using secret sharing.
30. A verifier program causing a computer to execute the verification process described in claim 29, the process including: receiving the transformed transmission information; performing a secret subtraction as described in claim 28 on the registered authentication information in the received transmission information, information that differs for each transmission, and the transformed transmission information, and verifying whether the result of the secret subtraction is 0 or not.
31. A transmission program that causes a computer to execute a process for transmitting secret information to a receiving device, the process including: sharing with the receiving device a portion of multiple random numbers from a true random number generation unit as a fifth random number; performing a secret calculation on the secret information by multiplying the secret information by a sixth random number from the true random number generation unit and transmitting the secret information to the receiving device; and transmitting to the receiving device a seventh random number generated from the true random number generation unit and a deletion random number that deletes the sixth random number from the registered fifth random number.
32. A secret sharing program that causes a computer to execute processes including: performing a secret calculation on secret information by multiplying the secret information by one true random number from a true random number generation unit; calculating a random number used as a coefficient of an order other than the constant term of the first shared value group from a first shared value group that is first registration information and a fourth random number from the true random number generation unit; calculating a second shared value group using the fourth random number and the calculated random number; performing a secret calculation without performing division using a deletion random number for deleting the one true random number in the secret information obtained by multiplying the product of the second registration information and the third registration information by the inverse of the product of the fourth random number and the one true random number, the first shared value, the second shared value, and the secret information that has been secretly calculated; and sending the calculated value via a communication unit.
33. A secret sharing device comprising: a true random number generation unit that generates true random numbers using a natural phenomenon that cannot be controlled by humans; and a secret sharing unit that directly obtains a plurality of the true random numbers from the true random number generation unit, calculates n shared values from one piece of secret information using one or more of the true random numbers, and calculates n shared values that can restore the secret information by collecting k (n≧k>1) of the shared values, but cannot restore the secret information with k-1 or fewer shared values, wherein the true random number generation unit and the secret sharing unit are configured on a single semiconductor.
Citation Information
Patent Citations
Secret information management system, secret information management method, secret information management program and terminal program for secret information management system
JP2005346659A
Input person's device, computation assisting device, device, secret computing device, and program
JP2019144405A
Sharing device, secure computation device, verification restoration device, sharing system, secure computation verification restoration system, and program
JP2020056840A
Quantum cryptography key distribution method, device, and system
JP2022549047A
Communication terminal, communication system, communication method and communication program
WO2012025987A1