Analysis device, analysis system, holder server, analysis method, encryption method, and recording medium

The analysis device and system address the challenge of cross-regional data linkage in mobility services by using homomorphic encryption to securely link and analyze encrypted data, enhancing service improvements while maintaining data privacy.

WO2025120831A1PCT designated stage expired Publication Date: 2025-06-12NEC CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/043934
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-08
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Existing mobility service platforms face challenges in linking data across regions without compromising sensitive information, as plain text data linkage raises privacy concerns while abstracting data limits service improvements.

Method used

An analysis device and system that acquire, analyze, and transmit encrypted utilization data using a homomorphic encryption method, allowing for cross-regional data linkage without exposing sensitive information.

Benefits of technology

Enables cooperation across regions without abstracting sensitive data, ensuring data privacy while improving mobility service functions through comprehensive data analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023043934_12062025_PF_FP_ABST
    Figure JP2023043934_12062025_PF_FP_ABST
Patent Text Reader

Abstract

An analysis device according to the present disclosure comprises: an acquisition means that acquires, from a plurality of holder servers each holding utilization data for a mobility service, the utilization data in a format encrypted by a homomorphic encryption scheme on a region-by-region basis; an analysis means that links a plurality of pieces of encrypted utilization data between the regions to execute analysis relating to the mobility service; and a transmission means that transmits an analysis result in the encrypted format.
Need to check novelty before this filing date? Find Prior Art

Description

Analysis device, analysis system, owner server, analysis method, encryption method, and recording medium

[0001] The present disclosure relates to an analysis device, an analysis system, a holder server, an analysis method, an encryption method, and a recording medium.

[0002] There are technologies that use mobility services such as MaaS (Mobility as a Service) to meet the transportation needs of residents or tourists and solve local issues.

[0003] For example, Patent Document 1 discloses a method for analyzing the travel behavior of users of MaaS transportation services.

[0004] Special Publication No. 2023-519225

[0005] Meanwhile, there are MaaS platforms in each region, and there is a movement to share data between MaaS platforms for use in mobility services. When sharing data between MaaS platforms, if data is shared in plain text without encryption, there are problems from the perspective of protecting personal information, making it difficult to obtain sensitive data such as personal information and confidential information as is. On the other hand, if data is abstracted and shared, it is not possible to expect improvements in the functionality of the mobility services being used.

[0006] An example of an objective of the present disclosure is to provide an analysis device or the like that can be linked across regions without abstracting sensitive data.

[0007] An analysis device in one aspect of the present disclosure includes an acquisition means for acquiring, for each region, utilization data for mobility services from multiple owner servers that hold utilization data, each of the utilization data being encrypted using a homomorphic encryption method; an analysis means for linking the multiple encrypted utilization data between regions to perform analysis on mobility services; and a transmission means for transmitting the analysis results in an encrypted format.

[0008] An analysis system in one aspect of the present disclosure is an analysis system having the above-mentioned analysis device, multiple owner servers for each region, and an aggregation server that aggregates utilization data for each region, and each owner server has a data storage means for storing utilization data for mobility services, an encryption means for encrypting the utilization data stored in the data storage means using a homomorphic encryption method, and an input / output means for transmitting the utilization data in encrypted form to the analysis device.

[0009] In one aspect of the present disclosure, the holder server comprises a data storage means for storing utilization data for mobility services, an encryption means for encrypting the utilization data stored in the data storage means using a homomorphic encryption method, and an input / output means for transmitting the utilization data in encrypted form to an analysis device.

[0010] In one aspect of the present disclosure, an analysis method involves a computer acquiring utilization data for mobility services from multiple owner servers that hold utilization data for each region, each in a format encrypted using homomorphic encryption, linking the multiple encrypted utilization data between regions, performing analysis on mobility services, and transmitting the analysis results in encrypted format.

[0011] In one aspect of the present disclosure, an encryption method includes a computer storing utilization data for a mobility service, encrypting the utilization data using a homomorphic encryption method, and transmitting the utilization data in encrypted form to an analysis device.

[0012] In one aspect of the present disclosure, a recording medium stores a program that causes a computer to obtain, for each region, utilization data from multiple owner servers that hold utilization data for mobility services in a format encrypted using homomorphic encryption, link the multiple encrypted utilization data between regions, perform analysis on mobility services, and transmit the analysis results in an encrypted format.

[0013] According to one example of the effect of the present disclosure, collaboration between regions is possible without abstracting sensitive data.

[0014] Fig. 1 is a block diagram showing the configuration of an analysis system according to the present disclosure. Fig. 2 is a diagram showing a hardware configuration in which the analysis system according to the present disclosure is realized by a computer device and its peripheral devices. Fig. 3 is a flowchart showing the analysis operation according to the present disclosure. Fig. 4 is a block diagram showing the configuration of the analysis system according to the present disclosure. Fig. 5 is a flowchart showing the analysis operation according to the present disclosure.

[0015] Hereinafter, with reference to the drawings, embodiments of an analysis device, an analysis system, an owner server, an analysis method, an encryption method, a program, and a non-transitory recording medium for recording a program according to the present disclosure will be described in detail. The present embodiments do not limit the disclosed technology.

[0016] First Embodiment FIG. 1 is a block diagram showing the configuration of an analysis system 10 according to the present disclosure. The analysis system 10 is a system for linking multiple encrypted utilization data between regions to perform analysis of mobility services. Analysis of mobility services, for example, is data analysis to improve the convenience of users of mobility services, such as recommendations for commercial facilities and congestion prediction services based on analysis of behavioral data of users, etc. Examples of mobility services include rental cars, car sharing, ride sharing, rental bicycles, airplanes, taxi dispatch apps, trains, and buses. The regions are not limited to regions such as prefectures or municipalities, and may be between regions smaller than municipalities, and may not necessarily be between neighboring regions.

[0017] The utilization data includes at least data obtained from users of the mobility service application programs, but the utilization data used differs depending on the mobility service being analyzed.

[0018] 1, the analysis system 10 includes an analysis device 100, an aggregation server 20 (20(1), ..., 20(n)) that aggregates utilization data from multiple regions, and an owner server 200 (200(1), ..., 200(k)) owned by multiple entities in each region. The entities include users of mobility service application programs as well as local businesses, such as commercial facility operators, transportation businesses that provide transportation services for people, medical institutions, and government agencies.

[0019] The aggregation server 20 is configured, for example, as a MaaS platform, and cooperates with aggregation servers 20 in other regions via an API (Application Programming Interface) to share utilization data between regions. The aggregation server 20 may store utilization data acquired from multiple owner servers 200 in the region in advance. The analysis device 100 is operated by a person who analyzes mobility services, and the analysis results are provided to operators of application programs for mobility services.

[0020] The analysis device 100 performs analysis of mobility services by linking multiple encrypted utilization data between regions. The analysis device 100 includes an acquisition unit 101, an analysis unit 102, and a transmission unit 103.

[0021] Each of the owner servers 200 in each region includes a data storage unit 201i (i = 1, ..., k) that stores utilization data for mobility services, an encryption unit 202i (i = 1, ..., k) that encrypts the utilization data stored in the data storage unit using homomorphic encryption, and an input / output unit 203i (i = 1, ..., k) that transmits the utilization data in encrypted form to the analysis device 100. In this embodiment, the encryption unit 202 encrypts the utilization data using, for example, an encryption key held in advance. Multiple owner servers 200 are provided, the number of which is equal to the number (k) of entities that provide utilization data, and the value of k may be different in each region. The analysis device 100, which is an essential component of the present disclosure, will be described in detail below.

[0022] 2 is a diagram showing an example of a hardware configuration in which the analysis device 100 according to the present disclosure is realized by a computer device 500 including a processor. As shown in FIG. 2, the analysis device 100 includes a CPU (Central Processing Unit) 501, memories such as a ROM (Read Only Memory) 502 and a RAM (Random Access Memory) 503, a storage device 505 such as a hard disk for storing a program 504, a communication I / F (Interface) 508 for network connection, and an input / output interface 511 for inputting and outputting data. In the present disclosure, utilization data received from each owner server 200 is input to the analysis device 100 via the communication I / F 508.

[0023] The CPU 501 runs an operating system to control the entire analysis device 100 according to the present disclosure. The CPU 501 also reads programs and data into memory from a recording medium 506 attached to, for example, a drive device 507. The CPU 501 also functions as the acquisition unit 101, analysis unit 102, and transmission unit 103 according to the present disclosure, or as part of these units, and executes processing or commands in the flowchart shown in FIG. 3, which will be described later, based on the program.

[0024] The recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. A part of the recording medium in the storage device is a non-volatile storage device, and the program is recorded therein. The program may also be downloaded from an external computer (not shown) connected to a communication network.

[0025] The input device 509 is realized by, for example, a mouse, a keyboard, built-in key buttons, etc., and is used for input operations. The input device 509 is not limited to a mouse, a keyboard, or built-in key buttons, and may be, for example, a touch panel. The output device 510 is realized by, for example, a display, and is used to check output.

[0026] As described above, the analysis device 100 shown in FIG. 1 is realized by the computer hardware shown in FIG. 2. However, the means for realizing each unit of the analysis device 100 in FIG. 1 is not limited to the configuration described above. The analysis device 100 may be realized by a single physically coupled device, or by two or more physically separate devices connected by wire or wirelessly. For example, the input device 509 and the output device 510 may be connected to the computer device 500 via a network. The analysis device 100, the owner server 200, and the aggregation server 20 shown in FIG. 1 may also be configured using cloud computing or the like.

[0027] The acquisition unit 101 is a means for acquiring utilization data for mobility services from a plurality of owner servers 200 that store utilization data for each region, in a format encrypted by homomorphic encryption. Utilization data is data necessary for using a mobility service, and includes, for example, visitor data such as the number of visitors stored by a commercial facility operator, transportation data stored by a transportation operator, mobility movement data, or personal data such as location information of users of a mobility service application program. The acquisition unit 101 acquires utilization data related to the mobility service to be analyzed.

[0028] Homomorphic encryption is a public key encryption method that is homomorphic, and operations performed on ciphertext are maintained even after decryption. In the present disclosure, by encrypting utilization data using homomorphic encryption, the analysis device 100 performs analytical operations in the encrypted format, and obtains analysis results in encrypted format. This allows utilization data provided by the owner server 200 to be analyzed while remaining confidential to other owner servers 200, the aggregation server 20 (platformer), and the person conducting the analysis. Furthermore, the risk of information leakage on the aggregation server 20 can be reduced.

[0029] The acquisition unit 101 receives, for example, in response to an operation for analysis, the utilization data from the plurality of owner servers 200 for each region via a network in a format encrypted by homomorphic encryption. The acquisition unit 101 may acquire the plurality of utilization data stored in the aggregation servers 20 for each region.

[0030] The analysis unit 102 is a means for linking multiple encrypted utilization data between regions and performing analysis related to mobility services. Linking, for example, refers to sharing utilization data between regions and utilizing it for mobility services. The analysis unit 102 performs analysis related to mobility services across multiple regions. For example, the analysis unit 102 performs analysis to provide information useful for users of mobility services when traveling from their current location to another region. More specifically, the analysis includes analysis of recommended commercial facilities when traveling from the current location to another region, and congestion prediction for traveling from the current location to another region. In this case, the analysis unit 102 links utilization data in the current region, utilization data in intermediate regions, and utilization data in the destination region to perform the necessary analysis.

[0031] The analysis unit 102 may calculate the analysis results in an encrypted format by inputting the utilization data in an encrypted format into an analytical model that has been machine-learned in advance. The analytical model is stored in, for example, the storage device 505. The analytical model may also be used in a format encrypted using homomorphic encryption.

[0032] The analysis unit 102 may also perform analysis using multiple analytical models. In this case, the analysis unit 102 may integrate (ensemble) the results calculated by each analytical model. The method for integrating the results calculated by each analytical model is not particularly limited, and may be, for example, averaging or majority voting. The analysis unit 102 may also integrate parameters of multiple analytical models using homomorphic encryption. A known method can be used as the parameter integration method. For example, when integrating, the weight of the parameters corresponding to each model may be changed depending on the characteristics of each model.

[0033] Here, a destination recommendation service will be described as an example of a mobility service in the present disclosure. The destination recommendation service is a service that recommends destinations when a user of a recommendation application program travels across multiple regions, and utilization data is shared between the regions where the user travels.

[0034] The utilization data includes data held by at least one of commercial facility operators, transportation operators, and users of mobility and destination recommendation application programs.

[0035] Utilization data provided by commercial facility operators includes visitor data such as the number of visitors to the commercial facility and attribute information of customers who visited. Customer attribute information is information such as gender or age obtained from payment information used when making payments at the commercial facility. Utilization data provided by transportation operators includes passenger data such as the number of passengers boarding and alighting public transportation such as buses or trains and passenger attribute information. Passenger attribute information is information such as gender or age obtained from payment information used when paying the fare when boarding or alighting a bus. Utilization data obtained from mobility devices includes location information of the mobility device and parking time. This information is obtained from location information obtained from the Global Positioning System (GPS) installed in the mobility device. Utilization information obtained from app users includes location information, destination, means of transportation, payment information, attribute information such as gender or age, and personal data such as customer preference information for food, entertainment, etc.

[0036] The analysis unit 102 analyzes destinations to be recommended to the app user based on at least one of these utilization data. Various known methods may be used as the analysis method. For example, based on the app user's current location and destination and visitor data for each commercial facility, the analysis unit 102 may analyze commercial facilities with a low number of visitors from among commercial facilities located near the route to the destination. The analysis unit 102 may also use information about the user's mode of transportation to analyze commercial facilities that are easily accessible by that mode of transportation. For example, if the mode of transportation is public transportation, the analysis unit 102 may analyze stores near stations, and if the mode of transportation is a private car, the analysis unit 102 may analyze commercial facilities with large parking lots. Furthermore, the analysis unit 102 may analyze commercial facilities with stores that match the customer's preferences based on preference information in the customer information. However, these destination analysis methods are merely examples, and other methods may be used to analyze destinations to be recommended to users.

[0037] Next, a congestion prediction service will be described as an example of a mobility service in the present disclosure. The congestion prediction service is a congestion prediction service for when a user of an application program for the congestion prediction service travels across multiple regions, and utilization data is shared between the regions where the user travels.

[0038] The utilization data includes data held by at least one of commercial facility operators, transportation operators, and users of mobility and congestion prediction application programs.

[0039] Utilization data provided by commercial facility operators includes visitor data such as the number of visitors to the commercial facility and trends in visitor numbers. Utilization data provided by transportation operators includes information on the number of passengers boarding and alighting or congestion information for public transportation such as buses or trains. Utilization data obtained from mobility devices includes location information or time information for mobility devices. Utilization information obtained from app users includes location information, destination, and means of transportation.

[0040] The analysis unit 102 performs congestion analysis for the app user on the way to the destination based on at least one of these utilization data. The analysis method may be any of various known methods. For example, a congestion prediction for traveling to the destination is analyzed based on the user's current location and destination, and congestion information for the public transportation to be used. The congestion prediction may be, for example, the time required to reach the destination or the degree of congestion of the public transportation to be used. The analysis unit 102 may also analyze a less congested route from the user's current location to the destination. However, these congestion prediction analyses are merely examples, and congestion predictions may be performed using other methods.

[0041] Next, a driver's credibility viewing service will be described as an example of a mobility service in the present disclosure. Drivers include ride-sharing drivers, taxi drivers, and the like. The driver's credibility viewing service allows the driver's credibility to be viewed on an application program. In this mobility service, for example, utilization data is linked between the area where the driver currently lives or works and the area where the driver previously lived or worked. The credibility is an index that evaluates the driver not only based on the driver's driving skills but also from the perspective of how it affects the customer's desire to ride.

[0042] The utilization data includes data held by at least one of medical institutions, government agencies, local governments, vehicle inspection and maintenance companies, the driver's previous employer, and users of mobility and driver credit rating viewing application programs.

[0043] Examples of utilization data provided by medical institutions include the driver's medical history or prescription history. Medical history is, for example, information on the names of injuries and illnesses or prescribed medications from electronic medical records. Examples of utilization data provided by administrative agencies include the driver's accident history or traffic violation history. Examples of utilization data provided by local governments include the driver's administrative sanction history, examples of utilization data provided by vehicle inspection and maintenance companies include vehicle inspection information or repair information, and examples of utilization data provided by the driver's previous employer include the driver's work attitude at the previous job, the area where the driver worked, and the type of job, etc.

[0044] The analysis unit 102 calculates the creditworthiness of a specific driver based on, for example, at least one of these utilization data. Various known methods may be used as the analysis method. For example, the analysis unit 102 may calculate the creditworthiness of a driver based on the driver's health condition obtained from the driver's medical history or prescription history. The analysis unit 102 may also calculate the creditworthiness based on the driver's driving skills obtained from the driver's accident history or traffic violation history. The analysis unit 102 may also calculate the creditworthiness of a driver based on information obtained from the driver's administrative sanction history. The analysis unit 102 may also calculate the creditworthiness based on the condition of the vehicle obtained from the vehicle inspection information or repair information of the vehicle driven by the driver. The analysis unit 102 may also increase the creditworthiness of a driver based on the driver's work attitude, driving history, and knowledge of road conditions in the area where the driver drives, obtained from the driver's previous employer. These methods of calculating the creditworthiness are merely examples, and other methods may also be used to calculate the creditworthiness.

[0045] The transmitting unit 103 is a means for transmitting the analysis results in an encrypted format. The transmitting unit 103 transmits the encrypted analysis results to a device that holds a decryption key for decrypting the encrypted analysis results. The transmitting unit 103 transmits the encrypted analysis results to, for example, each owner server 200 that encrypted the utilization data. The transmitting unit 103 may transmit the encrypted analysis results directly to each owner server 200, or may transmit the analysis results via the aggregation server 20.

[0046] The transmitting unit 103 may transmit the analysis results only to the owner servers 200 that have agreed to the shared decryption. In this case, for example, the transmitting unit 103 transmits a message to each of the multiple owner servers 200 to request shared decryption before sending the analysis results. This message includes, for example, a button for transmitting a response indicating whether or not to agree to the shared decryption. Then, the transmitting unit 103 transmits the analysis results to the multiple owner servers 200 that have received a response indicating that they agree to the shared decryption.

[0047] When each owner server 200 receives the encrypted analysis results, it performs distributed decryption on the encrypted analysis results using its own decryption key, and transmits the distributed decrypted analysis results to the provider of the mobility service application program. With this method, the provider of the application program can obtain the analysis results, but does not know the contents of each individual piece of utilization data.

[0048] The operation of the analysis device 100 configured as above will be described with reference to the flowchart of FIG.

[0049] 3 is a flowchart showing an outline of the operation of the analysis device 100 according to the present disclosure. Note that the processing according to this flowchart may be executed based on program control by the processor described above.

[0050] As shown in Fig. 3, first, the acquisition unit 101 acquires utilization data for mobility services from multiple owner servers 200 that store utilization data for each region in a format encrypted using homomorphic encryption (step S101). Next, the analysis unit 102 links the multiple encrypted utilization data between regions and performs analysis on mobility services (step S102). Finally, the transmission unit 103 transmits the analysis results in encrypted format (step S103). This completes the analysis operation of the analysis device 100.

[0051] In the analysis device 100, the acquisition unit 101 acquires utilization data for each region from multiple owner servers 200 that hold utilization data for mobility services in a format encrypted using homomorphic encryption.The analysis unit 102 then links the multiple encrypted utilization data between regions and performs analysis on mobility services.In this way, by analyzing the utilization data provided by the multiple owner servers 200 in encrypted format, it is possible to link sensitive data between regions without abstracting it so that individuals, etc. cannot be identified.

[0052] [Second Embodiment] Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings. Below, descriptions of content that overlaps with the above description will be omitted to the extent that the description of this embodiment is not unclear. As with the computer device shown in FIG. 2, the functions of each component in each embodiment of the present disclosure can be realized not only by hardware but also by a computer device or software based on program control.

[0053] 4 is a block diagram showing the configuration of an analysis system 11 including an analysis device 110 according to the present disclosure. Referring to FIG. 4, the analysis device 110, aggregation servers 21i (i = 1, ..., n), and owner servers 210i (i = 1, ..., k) will be described, focusing on differences from the analysis system 10. In this embodiment, it is assumed that the owner server 210 generates an encryption key for encrypting utilization data and a decryption key for decrypting analysis results.

[0054] <Analysis Device 110> The analysis device 110 includes an acquisition unit 111, an analysis unit 112, a transmission unit 113, a reception unit 114, and an output unit 115. The configuration other than the reception unit 114 and the output unit 115 is basically the same as in the first embodiment.

[0055] The receiving unit 114 decrypts the analysis result by combining the results of the shared decryption performed by the owner server 210. The specific operation of the receiving unit 114 will be described later.

[0056] The output unit 115 is a means for displaying the decrypted analysis result on a display device such as a display etc. The output unit 115 may transmit the analysis result to the provider of the application program.

[0057] <Owner Server 210> Each of the owner servers 210 includes a data storage unit 211i (i = 1, ..., k) that stores utilization data for multiple mobility services, an encryption unit 212i (i = 1, ..., k) that encrypts the utilization data stored in the data storage unit using a homomorphic encryption method, an input / output unit 213i (i = 1, ..., k) that transmits the utilization data to the analysis device 110 in encrypted form, as well as a key generation unit 214i (i = 1, ..., k) that generates an encryption key and a decryption key, an encryption key storage unit 215i (i = 1, ..., k) that stores the encryption key generated by the key generation unit 214, a decryption key storage unit 216i (i = 1, ..., k) that stores the decryption key generated by the key generation unit 214, and a decryption unit 217i (i = 1, ..., k) that decrypts the encrypted analysis results received from the analysis device 110 using the decryption key.

[0058] The key generation unit 214 generates a key pair of an encryption key and a decryption key in a homomorphic public key cryptosystem. The key generation unit 214 generates the key pair of an encryption key and a decryption key using various known techniques. For example, the key generation unit 214 of each holder server 210 generates an individual key pair of an encryption key and a decryption key and stores them in the encryption key storage unit 215 and the decryption key storage unit 216, respectively (multi-key homomorphic encryption).

[0059] Alternatively, each owner server 210 in the same region may use a single key pair of encryption and decryption keys (single-key homomorphic encryption). In this case, the key generation unit 214 of any one owner server 210 among the multiple owner servers 210 generates a key pair of encryption and decryption keys and transmits the encryption key and decryption key to the encryption key storage unit 215 and decryption key storage unit 216 of each owner server 210, respectively. The owner server 210 that generates the key pair of encryption and decryption keys may be predetermined or selected randomly.

[0060] Alternatively, a composite key may be generated by combining the encryption keys generated by the key generation units 214 of the respective holder servers 210 in the same region (threshold homomorphic encryption). In this case, each key generation unit 214 transmits the generated encryption key to the key generation unit 214 of one of the holder servers 210. The key generation unit 214 that receives the encryption key from another holder server 210 generates a composite key of the encryption keys using a known method. The holder server 210 that generates the composite key may be predetermined or selected randomly.

[0061] The decryption unit 217 uses a decryption key to decrypt the analysis results in encrypted form received from the analysis device 110. When the utilization data is encrypted using multi-key homomorphic encryption or threshold homomorphic encryption, among the examples of encryption methods described above, the decryption unit 217 communicates with the decryption units 217 of other holder servers 210 in the same region and performs distributed decryption of the analysis results using a decryption key corresponding to the encryption key used to encrypt the utilization data.

[0062] In this specification, shared decryption refers to each owner server 210 calculating a shared decryption result in the sense of an "incomplete decryption result," rather than dividing a ciphertext corresponding to a single piece of data into multiple parts. The input / output unit 213 then transmits the shared decryption result to the analysis device 110 or a device (application program provider) that wishes to obtain the decryption result. The analysis device 110 or provider server that receives the shared decryption result combines the incomplete shared decryption results to obtain a complete decryption result. While the present disclosure describes a case in which the shared decryption result is transmitted to the analysis device 110, it may also be transmitted to the application program provider. In this case, the application program provider server would have components equivalent to the receiving unit 114 and output unit 115 of the present disclosure.

[0063] On the other hand, if the utilization data is encrypted using single-key homomorphic encryption, the decryption unit 217 of the owner server 210, which generated the key pair of the encryption key and the decryption key, decrypts the analysis result. The decryption unit 217 transmits the decrypted analysis result to the analysis device 110 or the application program provider via the input / output unit 213.

[0064] Here, an example of a shared decryption method in multi-key homomorphic encryption or threshold homomorphic encryption will be described. The shared decryption method described below employs the method described in Chen et al., "Efficient Multi-Key Homomorphic Encryption with Packed Ciphertexts with Application to Oblivious Neural Network Inference," In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (pp. 395-412). However, this shared coding method is just an example, and a different method may be used. The holder server 210i (i = 1, ..., k) in each region receives the decryption key s i In addition, the ciphertext ct has integer coefficients as shown in the following formula (1), and (X n +1) is the polynomial ring.

[0065] In addition, in formula (1), when q is an integer, it is expressed as Rq = R / (q·R), and the coefficient has a value on modq, and (X n +1). For simplicity, in this disclosure, it is assumed that k people (devices each having k decryption keys) are involved in the calculation, and ct is the ciphertext of the calculation result.

[0066] The acquisition unit 111 acquires the ciphertext from each owner server 210i (i=1, . . . , k) for each region, and the analysis unit 112 analyzes the ciphertext while it is still encrypted, and the ciphertext of the analysis result is expressed as ct=(c 0 , c 1 , ..., c k ) and the sending unit 113 sends the following to the owner server 210i (i=1, . . . , k): i (i=1, . . . , k) are transmitted to the respective owner servers 210. Next, the decryption unit 217 of each owner server 210 transmits the decryption key s i Specifically, each i-th owner server 210 performs shared decryption using the shared decryption result μ i is calculated by the formula (2). In the formula (2), ei is noise sampled from the noise distribution φ. Each decoding unit 217 transmits these distributed decoding results to the analysis device 110.

[0067]

[0068] Next, the analysis device 110 combines the distributed decoding results and performs decoding. Specifically, the analysis device 110 performs decoding by combining μ i from the i-th owner server 210 and calculates the plaintext m using equation (3). The analysis device 100 receives similar analysis and decryption results from the owner servers 210 for each region and calculates the plaintext m.

[0069] however,

[0070] Note that equation (4) indicates the value of x rounded off to the nearest whole number, and when t is an integer in equation (3), the plaintext m∈R t is.

[0071] The operation of the analysis system 11 configured as above will be described with reference to the flowchart of FIG.

[0072] FIG. 5 is a flowchart showing an overview of the operation of the analysis system 11 according to the present disclosure. The processing according to this flowchart may be executed based on program control by the aforementioned processor. The flow in FIG. 5 illustrates a case in which utilization data is encrypted using multi-key homomorphic encryption, which generates individual key pairs in multiple holder servers 210. Furthermore, the flow (S201) in which the key pair is generated by the key generation unit 214 and the flow (S202) in which the encryption unit 212 encrypts the utilization data do not need to be executed consecutively.

[0073] 5, first, in each of the multiple owner servers 210, the key generation unit 214 generates a key pair of an encryption key and a decryption key, and stores the key pair in the encryption key storage unit 215 and the decryption key storage unit 216, respectively (step S201). Next, the encryption unit 212 encrypts the utilization data stored in the data storage unit 211 using the encryption key by homomorphic encryption (step S202). Next, the input / output unit 213 transmits the utilization data in encrypted form to the aggregation server 21 (step S203).

[0074] The aggregation server 21 receives encrypted utilization data from multiple holder servers 210 in the region (step S204), and transmits it to the analysis device 110 based on a request from the analysis device 110 (step S205).

[0075] In the analysis device 110, the acquisition unit 111 acquires utilization data from multiple owner servers 210 for each region in a format encrypted using homomorphic encryption (step S206). Next, the analysis unit 112 links the multiple encrypted utilization data between regions and performs analysis on mobility services (step S207). Next, the transmission unit 113 transmits the analysis results in encrypted format to each owner server 210 (step S208).

[0076] Again, in each of the multiple owner servers 210, the input / output unit 213 receives the analysis result in encrypted form (step S209). Next, the decryption unit 217 performs shared decryption of the encrypted analysis result using the decryption key stored in the decryption key storage unit 216 (step S210). Next, the input / output unit 213 transmits the shared decrypted analysis result to the analysis device 110 (step S211).

[0077] Furthermore, in the analysis device 110, the receiving unit 114 combines the results of the shared decryption performed by the owner server 200 to decrypt the analysis result (step S212). Finally, the output unit 115 outputs the decrypted analysis result (step S213). This completes the analysis operation of the analysis system 11.

[0078] In the multiple owner servers 210 in this embodiment, each key generation unit 214 generates a key pair of an encryption key and a decryption key, and the encryption unit 212 encrypts the utilization data using the individual encryption key generated by each owner server 210. In this case, the utilization data cannot be decrypted unless the decryption key paired with the encryption key is used, thereby further improving confidentiality.

[0079] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.

[0080] For example, although multiple operations are described in a sequential order in the form of a flowchart, the order of description does not limit the order in which the multiple operations are performed. Therefore, when implementing each embodiment, the order of the multiple operations can be changed within the scope that does not affect the content.

[0081] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes.

[0082] (Supplementary Note 1) An analysis device comprising: an acquisition means for acquiring, for each region, utilization data for mobility services from a plurality of owner servers that hold the utilization data, each of the utilization data in a format encrypted by homomorphic encryption; an analysis means for linking the plurality of encrypted utilization data between regions and performing analysis on mobility services; and a transmission means for transmitting the analysis results in an encrypted format.

[0083] (Appendix 2) The analysis device described in Appendix 1, wherein the analysis means uses an aggregation server in each region that stores utilization data received from the multiple holder servers to link the utilization data between regions.

[0084] (Supplementary Note 3) The analysis device according to Supplementary Note 1 or Supplementary Note 2, wherein the mobility service is a destination recommendation service, and the utilization data includes data held by at least one of a commercial facility operator, a transportation operator, and a user of an application program for mobility and destination recommendation.

[0085] (Supplementary Note 4) The analysis device according to Supplementary Note 1 or Supplementary Note 2, wherein the mobility service is a congestion prediction service, and the utilization data includes data held by at least one of a commercial facility operator, a transportation operator, and a user of a mobility and congestion prediction application program.

[0086] (Appendix 5) The analysis device described in Appendix 1 or Appendix 2, wherein the mobility service is a driver's credit rating viewing service, and the utilization data includes data held by at least one of a medical institution, a government agency, a local government, a vehicle inspection and maintenance company, the driver's previous employer, and a user of a mobility and driver's credit rating viewing application program.

[0087] (Supplementary Note 6) The analysis device according to any one of Supplementary Notes 1 to 5, wherein the transmission means transmits the analysis result to each of a plurality of owner servers that have agreed to the shared decryption.

[0088] (Supplementary Note 7) The analysis device described in any one of Supplementary Notes 1 to 6 further comprises: a receiving means that combines the results of distributed decryption performed by multiple holder servers in each region to decrypt the analysis result; and an output means that outputs the decrypted analysis result.

[0089] (Supplementary Note 8) The analysis device according to any one of Supplementary Notes 1 to 7, wherein the analysis means performs the analysis using an analytical model used for the analysis.

[0090] (Supplementary Note 9) The analysis device according to Supplementary Note 8, wherein the analysis means performs the analysis using an analytical model in encrypted form.

[0091] (Supplementary Note 10) The analysis device according to Supplementary Note 8 or Supplementary Note 9, wherein the analysis means integrates analysis results obtained by using each of a plurality of analysis models.

[0092] (Supplementary Note 11) An analytical system having an analytical device according to any one of Supplements 1 to 10, a plurality of owner servers for each region, and an aggregation server that aggregates utilization data for each region, wherein each of the owner servers comprises: a data storage means that stores utilization data for mobility services; an encryption means that encrypts the utilization data using a homomorphic encryption method; and an input / output means that transmits the utilization data to the analytical device in an encrypted form.

[0093] (Supplementary Note 12) The analysis system described in Supplementary Note 11, wherein the holder server further comprises: a key generation means for generating a key pair of an encryption key and a decryption key of a homomorphic public key cryptosystem; and a decryption means for decrypting the encrypted analysis results received from the analysis device using the decryption key; wherein the encryption means encrypts the utilization data using the encryption key; and the input / output means transmits the decrypted analysis results to a server device of a business operator of the analysis device or application program.

[0094] (Supplementary Note 13) The analysis system described in Supplementary Note 12, wherein the key generation means of one of the multiple owner servers generates a key pair consisting of a single encryption key and a single decryption key, each of the encryption means encrypts the utilization data using the single encryption key through a homomorphic encryption method, and each of the decryption means decrypts the analysis results using the single decryption key.

[0095] (Appendix 14) The analysis system described in Appendix 12, wherein the encryption means encrypts the utilization data using a homomorphic encryption method using an encryption key generated on each of the multiple owner servers, and the decryption means decrypts the analysis results using a decryption key generated on each of the multiple owner servers.

[0096] (Supplementary Note 15) The analysis system described in Supplementary Note 12, wherein the encryption means encrypts the utilization data using a homomorphic encryption method using a composite key of encryption keys generated by each of the multiple owner servers, and the decryption means decrypts the analysis results using a decryption key generated by each of the multiple owner servers.

[0097] (Supplementary Note 16) An owner server comprising: a data storage means for storing utilization data for mobility services; an encryption means for encrypting the utilization data using a homomorphic encryption method; and an input / output means for transmitting the utilization data in encrypted form to an analysis device.

[0098] (Supplementary Note 17) An analysis method in which a computer acquires, for each region, utilization data for mobility services from a plurality of owner servers that hold the data, each of the data in a format encrypted using homomorphic encryption; links the plurality of encrypted utilization data between regions, performs an analysis on mobility services, and transmits the analysis results in an encrypted format.

[0099] (Supplementary Note 18) An encryption method in which a computer stores utilization data for a mobility service, encrypts the utilization data using a homomorphic encryption method, and transmits the utilization data in encrypted form to an analysis device.

[0100] (Supplementary Note 19) A recording medium storing a program that causes a computer to execute the following operations: obtain, for each region, utilization data for mobility services from multiple owner servers that hold the data, each of the utilization data in a format encrypted using homomorphic encryption; link the multiple encrypted utilization data between regions, perform analysis on mobility services, and transmit the analysis results in an encrypted format.

[0101] (Supplementary Note 20) A recording medium storing a program that causes a computer to execute the following steps: store utilization data for a mobility service; encrypt the utilization data using a homomorphic encryption method; and transmit the utilization data in encrypted form to an analysis device.

[0102] Some or all of the configurations described in Supplements 2 to 10 that are dependent on Supplement 1 above may also be dependent on Supplement 17 and Supplement 20 in the same dependency relationship as Supplements 2 to 10. Not limited to Supplements 1, 17, and 20, some or all of the configurations described as Supplements may be made dependent on various hardware, software, various recording devices for recording software, or systems, within the scope of each of the above-mentioned embodiments.

[0103] 10, 11 Analysis system 20, 21 Aggregation server 100, 110 Analysis device 101, 111 Acquisition unit 102, 112 Analysis unit 103, 113 Transmission unit 200, 210 Holder server 201, 211 Data storage unit 202, 212 Encryption unit 203, 213 Input / output unit 214 Key generation unit 215 Encryption key storage unit 216 Decryption key storage unit 217 Decryption unit 500 Computer device 501 CPU 502 ROM 503 RAM 504 Program 505 Storage device 506 Recording medium 507 Drive device 508 Communication interface 511 Input / output interface 512 Bus

Claims

1. An analysis apparatus comprising: an acquisition means for acquiring, from a plurality of holder servers each holding utilization data for mobility services, each of the utilization data in a form encrypted by a somewhat homomorphic encryption method for each region; an analysis means for performing an analysis related to mobility services by linking the plurality of encrypted utilization data across regions; and a transmission means for transmitting the analysis result in an encrypted form.

2. The analysis apparatus according to claim 1, wherein the analysis means links the utilization data across regions using an aggregation server in which the utilization data received from the plurality of holder servers in each region is stored.

3. The analysis apparatus according to claim 1 or 2, wherein the mobility service is a destination recommendation service, and the utilization data includes data held by at least any one of commercial facility operators, transportation operators, and users of mobility and destination recommendation application programs.

4. The analysis apparatus according to claim 1 or 2, wherein the mobility service is a congestion prediction service, and the utilization data includes data held by at least any one of commercial facility operators, transportation operators, and users of mobility and congestion prediction application programs.

5. The analysis apparatus according to claim 1 or 2, wherein the mobility service is a driver's credit rating viewing service, and the utilization data includes data held by at least any one of medical institutions, administrative agencies, local governments, vehicle inspection and maintenance operators, the driver's former workplaces, and users of mobility and driver's credit rating viewing application programs.

6. The analysis apparatus according to any one of claims 1 to 5, wherein the transmission means transmits the analysis result to each of the plurality of holder servers that have agreed to distributed decryption.

7. The analysis apparatus according to any one of claims 1 to 6, further comprising: a reception means for decrypting the analysis result by combining the results of distributed decryption by the plurality of holder servers in each region; and an output means for outputting the decrypted analysis result.

8. The analysis apparatus according to any one of claims 1 to 7, wherein the analysis means performs the analysis using an analysis model used for the analysis.

9. The analysis apparatus according to claim 8, wherein the analysis means performs the analysis using an encrypted analysis model.

10. The analysis device according to claim 8 or claim 9, wherein the analysis means integrates analysis results obtained by analyzing using each of a plurality of analysis models.

11. An analysis system comprising the analysis device according to any one of claims 1 to 10, a plurality of holder servers for each region, and an aggregation server that aggregates utilization data for each region, wherein each of the holder servers includes: a data storage means for storing utilization data for mobility services; an encryption means for encrypting the utilization data by a somewhat homomorphic encryption method; and an input / output means for transmitting the utilization data in an encrypted form to the analysis device.

12. The holder server further includes a key generation means for generating a key pair of an encryption key and a decryption key of a public key encryption method having somewhat homomorphic property, and a decryption means for decrypting the encrypted analysis result received from the analysis device with the decryption key, wherein the encryption means encrypts the utilization data with the encryption key, and the input / output means transmits the decrypted analysis result to the analysis device or a server device of an operator of an application program. The analysis system according to claim 11.

13. Among the plurality of holder servers, the key generation means of any one of the holder servers generates a key pair of a single encryption key and a single decryption key, each of the encryption means encrypts the utilization data by a somewhat homomorphic encryption method with the single encryption key, and each of the decryption means decrypts the analysis result with the single decryption key. The analysis system according to claim 12.

14. The encryption means encrypts the utilization data by a somewhat homomorphic encryption method using the encryption keys generated by each of the plurality of holder servers, and the decryption means decrypts the analysis result using the decryption keys generated by each of the plurality of holder servers. The analysis system according to claim 12.

15. The encryption means encrypts the utilization data by a somewhat homomorphic encryption method using a composite key of the encryption keys generated by each of the plurality of holder servers, and the decryption means decrypts the analysis result using the decryption keys generated by each of the plurality of holder servers. The analysis system according to claim 12.

16. A holder server comprising: data storage means for storing utilization data for mobility services; encryption means for encrypting the utilization data by a somewhat homomorphic encryption method; and input / output means for transmitting the utilization data in an encrypted form to an analysis device.

17. An analysis method in which a computer obtains, for each region, the utilization data for mobility services from a plurality of holder servers that hold the utilization data, in a form encrypted by a somewhat homomorphic encryption method for each of the utilization data, cooperates the plurality of encrypted utilization data across regions, executes analysis regarding mobility services, and transmits the analysis result in an encrypted form.

18. An encryption method in which a computer stores utilization data for mobility services, encrypts the utilization data by a somewhat homomorphic encryption method, and transmits the utilization data in an encrypted form to an analysis device.

19. A recording medium storing a program for causing a computer to execute: obtaining, for each region, the utilization data for mobility services from a plurality of holder servers that hold the utilization data, in a form encrypted by a somewhat homomorphic encryption method for each of the utilization data; cooperating the plurality of encrypted utilization data across regions; executing analysis regarding mobility services; and transmitting the analysis result in an encrypted form.

20. A recording medium storing a program for causing a computer to execute: storing utilization data for mobility services; encrypting the utilization data by a somewhat homomorphic encryption method; and transmitting the utilization data in an encrypted form to an analysis device.

Citation Information

Patent Citations

  • Service vehicle reservation system

    JP2003288516A

  • Electronic commerce system, service providing server, third party organization server, electronic commerce method, and program

    JP2019125883A

  • Market sign management system, market sign management method, and market sign management program

    JP2020154950A

  • Information processing device

    JP2021076469A

  • Method and system for data analysis service mediation based on blockchain and homomorphic encryption

    KR102471210B1