Statistic calculation method, device, and program

The method and device use homomorphic encryption to combine multiple databases securely, enabling confidential statistical calculations by performing join operations and maintaining data privacy.

WO2025262813A1PCT designated stage Publication Date: 2025-12-26NT T INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/022097
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-18
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing technologies are unable to combine three or more databases while maintaining confidentiality and calculate statistics from the combined database.

Method used

A statistical calculation method and device that utilize homomorphic encryption to perform join processes between multiple databases, allowing for the creation of joined tables and calculation of statistical quantities while keeping each table secret, using operations such as one-to-many, many-to-one, and many-to-many matching.

Benefits of technology

Enables the combination of three or more databases while preserving confidentiality, allowing for the calculation of statistics from the combined database, with the option to add privacy noise for enhanced security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024022097_26122025_PF_FP_ABST
    Figure JP2024022097_26122025_PF_FP_ABST
Patent Text Reader

Abstract

According to the present invention, assuming j = 1,..., m, a participant device A and a participant device Bj perform processing for combining a table held by the participant device A with a table held by the participant device Bj while keeping mutual tables secret, and the participant device Bj acquires a coupling table Jj. Assuming j = 1,..., m, the participant device Bj executes a predetermined operation f for obtaining an intermediate result on homomorphic ciphertext for the coupling table Jj, and obtains a ciphertext EncA (tj) of the intermediate result. At least one of the participant devices A, B1,..., Bm executes a predetermined operation g for obtaining a final result on the homomorphic ciphertext for EncA (t1),..., EncA (tm), thereby obtaining a final result ciphertext EncA (r). The participant device A decodes the ciphertext Enc A (r) to obtain a final result r.
Need to check novelty before this filing date? Find Prior Art

Description

Statistical calculation method, device, and program

[0001] The disclosed technology relates to a technology for combining three or more databases while keeping them confidential, and calculating statistics from the combined databases.

[0002] A technique described in Non-Patent Document 1 is known as a technique for combining two databases while keeping them confidential and calculating statistics from the combined database.

[0003] Kazuma Nozawa and 8 others, "Proposal and Evaluation of a Data Integration Method Suitable for Combining Cross-Organizational Personal Data," CSS2022

[0004] However, there is no known technique for combining three or more databases while keeping them confidential and calculating statistics from the combined database.

[0005] The disclosed technology aims to provide a statistical calculation method, device, and program that can combine three or more databases while keeping them confidential and calculate statistics from the combined databases.

[0006] In one aspect of the disclosed technology, participant device A and participant device B are connected to each other, where j=1,...,m. j The table held by participant device A and participant device B j The participant device B performs the join process with the table held by the participant device B while keeping each table secret. j is the join table J j and a combining step to obtain the participant device B for j=1,...,m. j is the join table J j , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc A (t j ) and the participant devices A, B1,..., B m At least one of Enc A (t1),...,Enc A (t m ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc AA final result acquisition step in which participant device A obtains the ciphertext Enc A and a decoding step of decoding (r) to obtain a final result r.

[0007] In one aspect of the disclosed technology, participant device A i and participant device B, participant device A i The participant device B performs a process of joining the table held by the participant device A with the table held by the participant device B while keeping each table secret, and the participant device B creates a joined table J. i and a join step for i=1,...,n, where participant device B obtains the join table J i , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc Ai (s i ) and the participant device B obtains the intermediate result Enc A1 (s1),...,Enc An (s n ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A1,...,An A final result acquisition step to obtain (r) and participant devices A1,...,A n However, the ciphertext Enc A1,...,An and a decoding step of decoding (r) to obtain a final result r.

[0008] In one aspect of the disclosed technology, participant devices A i and participant device B j And, participant device A i Participant B has a table and device j The participant device B performs the join process with the table held by the participant device B while keeping each table secret. j is the join table J j and a combining step to obtain participant device B for j=1,...,m. j is the join table J j , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc Ai (t j) and a participant device A i ,B1,...,B m At least one of Enc Ai (t1),...,Enc Ai (t m ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc Ai (w i ), and the combining step, the intermediate result obtaining step, and the final result obtaining step are performed for i=1,...,n to obtain Enc A1 (w1),...,Enc An (w n ) and B1,...,B m At least one of Enc A1 (w1),...,Enc An (w n ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A1,...,An (r) and the integration step to obtain (r) and the participant devices A1,...,A n However, the ciphertext Enc A1,...,An and a decoding step of decoding (r) to obtain a final result r.

[0009] According to the disclosed technology, three or more databases can be combined while maintaining confidentiality, and statistics can be calculated from the combined database.

[0010] FIG. 1 is a diagram illustrating an example of the functional configuration of a statistics calculation system according to a first embodiment. FIG. 2 is a diagram illustrating an example of the processing procedure of a statistics calculation method according to the first and second embodiments. FIG. 3 is a diagram illustrating an example of the functional configuration of a statistics calculation system according to a second embodiment. FIG. 4 is a diagram illustrating an example of the functional configuration of a statistics calculation system according to a third embodiment. FIG. 5 is a diagram illustrating an example of the processing procedure of a statistics calculation method according to the third embodiment. FIG. 6 is a diagram illustrating an example of the functional configuration of a join table generation system. FIG. 7 is a diagram illustrating an example of the processing procedure of a join table generation method. FIG. 8 is a diagram illustrating an example of the processing of join table generation. FIG. 9 is a diagram illustrating an example of the processing of join table generation. FIG. 10 is a diagram illustrating an example of the processing of join table generation. FIG. 11 is a diagram illustrating an example of the processing of join table generation. FIG. 12 is a diagram illustrating an example of the processing of join table generation. FIG. 13 is a diagram illustrating an example of the functional configuration of a computer.

[0011] Hereinafter, embodiments of the disclosed technology will be described with reference to the drawings. Note that components having the same functions in the drawings are given the same reference numerals, and redundant description will be omitted.

[0012] [Definitions and Notations] Below, participant device A and participant device B will be used as examples for explanation.

[0013] Participant device A i The definition and notation of (i=1,...,n) are the same as those of participant device A. j The definition and notation of (j=1,...,m) are the same as those of participant device B. That is, in the following definition and notation, A is A i (i=1,...,n), and B is B j (j=1,...,m). n is the participant device A i m is a predetermined integer equal to or greater than 1, which represents the number of participants B j is a predetermined integer of 1 or more that represents the number of

[0014] Each participant device has a table. A table is a collection of data consisting of rows and columns. A column of a table consists of an ID and an attribute, which will be described later. A given ID* and a given attribute a * A table consisting of (ID * ,a * ) is written as

[0015] An ID is information that identifies a row in a table. Information that identifies a row in a table is sometimes called a key.

[0016] An attribute is information that indicates the properties associated with an ID.

[0017] H A,B (ID) is the ID converted by the ID conversion protocol executed by participant device A and participant device B in cooperation. A,B (ID) may also refer to the ID conversion protocol itself that participant device A and participant device B execute in cooperation.

[0018] H A,B No one can derive the original ID from (ID). In other words, participant device A and participant device B can independently derive the ID from H. A,B (ID) cannot be requested.

[0019] Enc A (a) is the ciphertext generated by homomorphic encryption using the key of participant device A for plaintext a. Enc A (a) may also refer to the process of homomorphic encryption itself for plaintext a using the key of participant device A. For the sake of simplicity, plaintext a is used as an example in the explanation. A The target of encryption by Enc is not limited to plaintext a. Any plaintext other than plaintext a can be encrypted by Enc A In addition, the process of homomorphic encryption using the key of participant device A itself can be called Enc A It is sometimes written as:

[0020] Dec A (Enc A (a)) is the Enc A This is the plaintext a decrypted by the decryption process in (a). A (Enc A (a)) is the Enc AIt can also refer to the decryption process (a) itself.

[0021] ID A is a list of table IDs that participant device A has.

[0022] ID B is a list of table IDs that participant device B has.

[0023] ID A∪B is the ID A and ID B It is a list of IDs included in at least one of the above.

[0024] ID A∩B is the ID A and ID B It is a list of IDs that are included in both

[0025] a A is a list of attributes a of the table that participant device A has.

[0026] b B is a list of attributes b of the table held by participant device B.

[0027] The table held by participant device A is ID A List of attributes a A When the list is composed of the two lists, the table held by participant device A is a set of two lists (ID A ,a A ) is used to represent the table held by participant device A. A ,a A ) is written as

[0028] Similarly, participant device B has a table with ID B list and attribute b B When the list is composed of the two lists, the table held by participant device B is a set of two lists (ID B ,b B ) is used to represent the table held by participant device B. B ,b B ) is written as

[0029] f and g are predetermined operations for finding predetermined statistical quantities such as frequency, mean, median, etc. The final result r found by a series of processes using the predetermined operation f and the predetermined operation g represents the value of the statistical quantity. f is a predetermined operation for finding an intermediate result for finding the final result r. For f to be used, g is an operation for finding the final result r from the intermediate result found by f.

[0030] The symbol "~" used in text should be written directly above the character immediately following it, but due to limitations in text notation, it is written immediately before the character in question. In drawings, these symbols are written in their proper position, i.e., directly above the character. For example, "~X" in text is written as follows in drawings: [First Embodiment] The statistics calculation device of the first embodiment performs one-to-many matching. More specifically, the statistics calculation device of the first embodiment performs one-to-many matching between participant device A and participant device B. j (j=1,...,m) calculates statistics while keeping each other's tables secret.

[0031] As shown in FIG. 1, the statistics calculation device of the first embodiment includes participant devices A, B1, . . . , B m For example, the system includes participant device A, participant devices B1, ..., B m can send and receive data to and from each other.

[0032] The statistical calculation method is realized, for example, by the components of the statistical calculation device of the first embodiment performing the processes of steps S1 to S4 shown in FIG.

[0033] <Step S1> Let j=1,...,m, and participant device A and participant device B j The table held by participant device A and participant device B j The participant device B performs the join process with the table held by the participant device B while keeping each table secret. j is the join table J j is acquired (step S1).

[0034] Joined Table J j is the table held by participant device A and participant device B. jIt is a table that is right outer joined with the table that has

[0035] Joined Table J j is (H A,Bj (ID Bj ),Enc A (a A∩Bj |⊥),b A∩Bj ) can be written as Enc A (a A∩Bj |⊥) is the ID A For IDs included in A (a A ) and ID A For IDs not included in A a is a list of encrypted attributes a with corresponding (⊥) A∩Bj is the join table J j means the list of attributes b in

[0036] The process in step S1 is performed by a participant device A and a participant device B. j The system consists of two devices, participant device A and participant device B. j The process of step S1 is performed by performing the above process performed by one device for each of j=1, . . . , m.

[0037] The process of step S1 can be performed using an existing method, such as the method described in Reference 1, which uses a one-way commutative function.

[0038] [Reference 1] Kazuma Nozawa and 8 others, "Proposal and Evaluation of a Data Linkage Method Suitable for Combining Cross-Organizational Personal Data," CSS2022. Another example of the processing in step S1 is the processing described in [Example of Generating a Joined Table] below.

[0039] <Step S2> For j=1,...,m, participant device B j is the join table J j , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc A (t j ) is obtained (step S2).

[0040] Joined Table J j A given operation f that obtains an intermediate result for t is evaluated under homomorphic encryption. j =f(a A∩Bj |⊥,b A∩Bj ), the ciphertext of the intermediate result is Enc A (t j ) can be written as

[0041] By the process of step S2, the ciphertext Enc A (t1),...,Enc A (t m ) is obtained.

[0042] <Step S3> Participant devices A, B1, ..., B m At least one of Enc A (t1),...,Enc A (t m ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A (r) is obtained (step S3).

[0043] The resulting ciphertext Enc A (r) is sent to participant device A.

[0044] The final ciphertext, Enc A The process of obtaining (r) is performed by one participant device B. j may be performed, or the participant devices B1,...,B m may cooperate with each other, or participant device B j The final result, ciphertext Enc A The participant device performs the process to obtain (r) and sends the ciphertext Enc A (t1),...,Enc A (t m ) are collected. The final ciphertext Enc A The participant device that performs the process to obtain (r) receives the collected ciphertext Enc A (t1),...,Enc A (t m ) is used for processing.

[0045] Enc A (t1),...,Enc A (t m ) is evaluated under homomorphic encryption, so that r=g(t1,...,t m ), the final ciphertext is Enc A It can be written as (r).

[0046] <Step S4> Participant device A generates the ciphertext Enc A (r) is decrypted to obtain the final result r (step S4).

[0047] That is, participant device A performs decryption processing Dec using the participant device A's key. A (Enc A By performing (r)), we obtain the final result r. As mentioned earlier, the final result r is the statistic we were trying to obtain.

[0048] Participant device A sends the final result r to participant devices B1,...,B m The information may be transmitted to at least one of the following:

[0049] By this process, three or more databases can be combined while maintaining confidentiality, and statistics can be calculated from the combined database.

[0050] In addition, when adding privacy noise to the final result r, when adding it to the ciphertext, the noise generated by participant device A and the noise generated by participant device B are j The noise transmitted to participant device B j is the intermediate result of the ciphertext Enc A (t i ) or the final resulting ciphertext Enc A It may be added to (r).

[0051] [Second embodiment] The statistics calculation device of the second embodiment performs many-to-one matching. More specifically, the statistics calculation device of the second embodiment includes participant device A i (i=1,...,n) and participant device B calculate statistics while keeping each other's tables secret.

[0052] As shown in FIG. 3, the statistics calculation device of the second embodiment is configured by participant devices A1, . . . , A n , B. n , participant device B can transmit and receive data to and from each other.

[0053] The statistical calculation method is realized, for example, by the components of the statistical calculation device of the second embodiment performing the processes of steps S1 to S4 shown in FIG.

[0054] <Step S1> For i=1,...,n, participant device A i and participant device B, participant device A i The participant device B performs a process of joining the table held by the participant device A with the table held by the participant device B while keeping each table secret, and the participant device B creates a joined table J. i is acquired (step S1).

[0055] Joined Table J i Participant device A i This table is a right outer join of the table held by participant device A and the table held by participant device B.

[0056] Joined Table J i is (H Ai,B (ID B ),Enc Ai (a Ai∩B |⊥),b Ai∩B ) can be written as Enc Ai (a Ai∩B |⊥) is the ID Ai For IDs included in Ai (a Ai ) and ID Ai For IDs not included in Ai a is a list of encrypted attributes a with corresponding (⊥) Ai∩B is the join table J i means the list of attributes b in

[0057] The process in step S1 is performed by participant device A. i The system consists of one device, Participant Device A, and one device, Participant Device B, which performs the processing.i The process of step S1 is performed by performing the process performed by one device A and one device B, for each of i=1, . . . , n.

[0058] The process of step S1 can be performed using an existing method, such as the method described in Reference 1, which uses a one-way commutative function.

[0059] Another example of the process in step S1 is the process described in [Example of Join Table Generation] below.

[0060] <Step S2> For i=1,...,n, participant device B creates a join table J i , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc Ai (s i ) is obtained (step S2).

[0061] Joined Table J i A given operation f that obtains an intermediate result for s is evaluated under homomorphic encryption. i =f(a Ai∩B |⊥,b Ai∩B ), the ciphertext of the intermediate result is Enc Ai (s i ) can be written as

[0062] By the process of step S2, the ciphertext Enc A1 (s1),...,Enc An (s n ) is obtained.

[0063] <Step S3> Participant device B receives Enc A1 (s1),...,Enc An (s n ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A1,...,An (r) is obtained (step S3). The predetermined operation g is performed on the ciphertext of the multi-key homomorphic encryption or the ciphertext of the threshold homomorphic encryption.

[0064] The resulting ciphertext Enc A1,...,An(r) is the participant device A1,...,A n will be sent to.

[0065] Enc A1 (s1),...,Enc An (s n ) is evaluated under homomorphic encryption, so that r=g(s1,...,s n ), the final ciphertext is Enc A1,...,An It can be written as (r).

[0066] <Step S4> Participant devices A1,...,A n But the ciphertext Enc A1,...,An (r) is decoded to obtain the final result r (step S4). As mentioned above, the final result r is the statistic that was being sought.

[0067] That is, participant devices A1,...,A n are participant devices A1,...,A n Decryption process using the key Dec A1,...,An (Enc A1,...,An By performing (r)), the final result r is obtained. A1,...,An (Enc A1,...,An (r)) is a decryption process for multi-key homomorphic encryption or a decryption process for threshold homomorphic encryption.

[0068] Participant device A1,...,A n may send the final result r to participant device B.

[0069] By this process, three or more databases can be combined while maintaining confidentiality, and statistics can be calculated from the combined database.

[0070] In addition, when adding privacy noise to the final result r, when adding it to the ciphertext, participant device A i The noise generated by the participant device B is sent to the participant device B, and the participant device B converts the intermediate result into the ciphertext Enc Ai (s i ) or the final resulting ciphertext Enc A1,...,An It may be added to (r).

[0071] [Third Embodiment] The statistics calculation device of the third embodiment performs many-to-many matching. More specifically, the statistics calculation device of the third embodiment includes participant devices A, B, C, D, E, F, F, G, H, I, J, J, K, J, L, L, L, M, M, N, and S. i (i=1,...,n) and participant device B j (j=1,...,m) calculates statistics while keeping each other's tables secret.

[0072] As shown in FIG. 4, the statistics calculation device of the third embodiment is configured by participant devices A1, . . . , A n , participant device B1,...,B m For example, the participant devices A1,...,A n , participant device B1,...,B m can send and receive data to and from each other.

[0073] The statistical calculation method is realized, for example, by the components of the statistical calculation device of the third embodiment performing the processes of steps S1 and S4 shown in FIG.

[0074] Participant device A1,...,A n , participant device B1,...,B m By performing the processes from step S11 to step S13 described below for i=1,...,n, Enc A1 (w1),...,Enc An (w n ) is obtained (step S1).

[0075] Steps S11 to S13 will be described below. The processing of steps S11 to S13 is the same as that of steps S1 to S3 in the first embodiment, where one-to-many matching is performed, except that participant device A is i It supports the following processing.

[0076] <Step S11> For j=1,...,m, participant device A i and participant device B j And, participant device A i Participant B has a table and device j The participant device B performs the join process with the table held by the participant device B while keeping each table secret. j is the join table Jj is acquired (step S11).

[0077] Joined Table J j Participant device A i Participant B has a table and device j It is a table that is right outer joined with the table that has

[0078] Joined Table J j is (H Ai,Bj (ID Bj ),Enc Ai (a Ai∩Bj |⊥),b Ai∩Bj ) can be written as Enc Ai (a Ai∩Bj |⊥) is the ID Ai For IDs included in Ai (a Ai ) and ID Ai For IDs not included in Ai a is a list of encrypted attributes a with corresponding (⊥) Ai∩Bj is the join table J j means the list of attributes b in

[0079] The process in step S11 is performed by participant device A. i and participant device B. j The process is performed by one device: Participant device A i and participant device B. j The process of step S1 is performed by performing the above process performed by one device for each of j=1, . . . , m.

[0080] The process of step S11 can be performed using an existing method, such as the method described in Reference 1, which uses a one-way commutative function.

[0081] Another example of the process of step S11 is the process described in [Example of Join Table Generation] below.

[0082] <Step S12> For j=1,...,m, participant device B j is the join table J j, a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc Ai (t j ) is obtained (step S12).

[0083] Joined Table J j A given operation f that obtains an intermediate result for t is evaluated under homomorphic encryption. j =f(a Ai∩Bj |⊥,b Ai∩Bj ), the ciphertext of the intermediate result is Enc Ai (t j ) can be written as

[0084] By the process of step S12, the ciphertext Enc Ai (t1),...,Enc Ai (t m ) is obtained.

[0085] <Step S13> Participant Device A i ,B1,...,B m At least one of Enc Ai (t1),...,Enc Ai (t m ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc Ai (w i ) is obtained (step S13).

[0086] The final ciphertext, Enc Ai (w i ) is obtained by one participant device B j may be performed, or the participant devices B1,...,B m may cooperate with each other, or participant device B j Participant devices other than participant device A may cooperate with each other. i The final ciphertext Enc Ai (w i ) to the participant device, which performs the process of obtaining the ciphertext Enc Ai (t1),...,Enc Ai (t m ) are collected. The final ciphertext Enc Ai (w iThe participant device processes the collected ciphertext Enc Ai (t1),...,Enc Ai (t m ) is used for processing.

[0087] Enc Ai (t1),...,Enc Ai (t m ) is a given operation g using the homomorphic encrypted text Enc Ai Since it is executed on g(Enc Ai (t1),...,Enc Ai (t m ))=Enc Ai (g(t1,...,t m )) can be transformed as follows. i =g(t1,...,t m ), as shown above, the final ciphertext is Enc Ai (w i ) can be written as

[0088] <Step S5> B1,...,B m At least one of Enc A1 (w1),...,Enc An (w n ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A1,...,An (r) is obtained (step S5). The predetermined operation g is performed on the ciphertext of the multi-key homomorphic encryption or the ciphertext of the threshold homomorphic encryption.

[0089] The resulting ciphertext Enc A1,...,An (r) is the participant device A1,...,A n will be sent to.

[0090] Enc A1 (w1),...,Enc An (w n ) is evaluated under homomorphic encryption, so that r=g(w1,...,w n ), the final ciphertext is Enc A1,...,An It can be written as (r).

[0091] <Step S6> Participant devices A1,...,A n But the ciphertext Enc A1,...,An (r) is decoded to obtain the final result r (step S6). As mentioned above, the final result r is the statistic that was being sought.

[0092] That is, participant devices A1,...,A n are participant devices A1,...,A n Decryption process using the key Dec A1,...,An (Enc A1,...,An By performing (r)), the final result r is obtained. A1,...,An (Enc A1,...,An (r)) is a decryption process for multi-key homomorphic encryption or a decryption process for threshold homomorphic encryption.

[0093] Participant device A1,...,A n The final result r is calculated by dividing the participant devices B1,...,B m The information may be transmitted to at least one of the following:

[0094] By this process, three or more databases can be combined while maintaining confidentiality, and statistics can be calculated from the combined database.

[0095] In addition, when adding privacy noise to the final result r, when adding it to the ciphertext, participant device A i Generated by participant device B j The noise transmitted to participant device B j is the intermediate result of the ciphertext Enc Ai (w i ) or the final resulting ciphertext Enc A1,...,An It may be added to (r).

[0096] [Example of Join Table Generation] As shown in Fig. 6, the join table generation system includes, for example, a first device A and a second device B. Each of the first device A and the second device B is also a join table generation device. The first device A generates a join table from participant devices A, A1, ..., A n The second device B corresponds to one of the participant devices B, B1, ..., B m It corresponds to either of the following.

[0097] The first device A includes, for example, a feature vector generation unit A1, a first random number sequence generation unit A2, a third random number sequence generation unit A3, and a fifth random number sequence generation unit A4.

[0098] The second device B includes, for example, a second random number sequence generation unit B1, a fourth random number sequence generation unit B2, and a combination unit B3.

[0099] The joining table generating method is realized, for example, by the first device A and the second device B performing the processes of steps 1 to 8 shown in FIG.

[0100] The database held by the first device A is referred to as the first database. The first database is composed of each key and at least one attribute value corresponding to each key. The set of keys in the first database is referred to as the first key set.

[0101] Similarly, the database held by the second device B is a second database. The second database is composed of each key and at least one attribute value corresponding to each key. The set of keys in the second database is a second set of keys.

[0102] In the following, for the sake of simplicity, an example will be described in which there is one attribute value corresponding to each key.

[0103] <Step 1> The first device A and the second device B execute a PC (Permuted Characteristic) protocol using the first key set and the second key set as input, and the first device A obtains a feature vector e indicating whether the π(i)th key in the second key set is included in the first key set (Step 1).

[0104] π is a permutation. For example, π is a random permutation. π(i) is the value of i permuted by the permutation π.

[0105] The processing of step 1 is performed between the feature vector generation unit A1 of the first device A and the second device B. As a result, the feature vector generation unit A1 of the first device A obtains the feature vector e.

[0106] The PC protocol is a set X = {x1,...,x n} and the set Y={y1,...,y n}, the sender and the receiver keep their inputs hidden from each other, and the sender and the receiver use the permutation π and the feature vector e = (e1, ..., e n ) (where, for i∈{1,...,n}, x π(i) When is included in Y, e i =1, x π(i) When is not included in Y, e i = 0) as the output.

[0107] As shown in the example in Figure 8, the first key set ID A ={1,3,5,7}, and the second key set ID B ={3,4,6,7}, and the second key set ID B The set in which the i-th element of is placed in the π(i)th position is ~ID B ={4,7,3,6}. In this case, for example, the feature vector e={0,1,1,0}. Note that the dashed-dotted box BB1 in FIG. 8 indicates that the correspondence is not visible.

[0108] <Step 2> The first device A and the second device B execute an OPRF (Oblivious Pseudo Random Function) protocol using the first key set as input, and the first device A obtains a first random number sequence, which is a sequence of random numbers related to the first key set (Step 2). The processing of this Step 1 is performed between the first random number sequence generation unit A2 of the first device A and the second device B. As a result, the first random number sequence generation unit A2 of the first device A obtains the first random number sequence.

[0109] The OPRF protocol is based on a sender with no input and a set Y = {y1, ..., y n}, the sender calculates a key SK of a random pseudo-random function f as the output while hiding each other's input, and the receiver calculates the pseudo-random function values ​​f(SK,y1), ..., f(SK,y n ) as output.

[0110] As shown in the example in Figure 9, the first key set ID A ={1,3,5,7}. In this case, for example, the first random number sequence H1(IDA ) = {H1(1),H1(3),H1(5),H1(7)}. H1 is the SK obtained as an output by the second device B, which is the sender in the definition of the OPRF protocol above. B H1 is a pseudorandom function f determined by the following equation: H1 is, for example, a hash function.

[0111] <Step 3> The second device B obtains a second random number sequence, which is a sequence of random numbers related to the second key set, using the pseudorandom function determined by the OPRF protocol executed to obtain the first random number sequence (Step 3).

[0112] The process of step 3 is performed by the second random number sequence generation unit B1 of the second device B. That is, the second random number sequence generation unit B1 of the second device B obtains the second random number sequence.

[0113] ID B ={3,4,6,7}, as in the example of FIG. 9, the second random number sequence H1(~ID B ) = {H1(4),H1(7),H1(3),H1(6)}. In this example, ID B ~ID replaced by substitution π B As in this example, a second random number sequence may be obtained by further using the permutation π.

[0114] For example, the second random number sequence generator B1 of the second device B generates the SK B H1 is calculated using a pseudorandom function f determined by:

[0115] <Step 4> The first device A and the second device B execute the OT (Oblivious Transfer) protocol using as input the second random number sequence and a set of numbers of elements in the feature vector e that indicate that they are not included as keys in the first database, and the first device A obtains a third random number sequence consisting of random numbers of numbers included in the set of numbers from among the random numbers included in the second random number sequence (Step 4).

[0116] The process of step 4 is carried out between the third random number sequence generation unit A3 of the first device A and the second device B. As a result, the third random number sequence generation unit A3 of the first device A obtains the third random number sequence.

[0117] For example, if the feature vector e={0,1,1,0}, the number set will be {1,4}. In this case, as shown in the example of FIG. 10, the third random number sequence H1(~ID B )={H1(4),⊥,⊥,H1(6)}, where ⊥ is a predetermined dummy value. The dummy value is, for example, a random value.

[0118] The OT protocol is a set X = {x1,...,x n} and a receiver with a set S ⊆ {1,...,n}, each input is hidden. The sender does not get any information, and the receiver gets {x i} i∈S It is a protocol that calculates as output.

[0119] <Step 5> The first device A and the second device B execute the OPRF protocol using the second random number sequence as input, and the second device obtains a fourth random number sequence, which is a sequence of random numbers related to the second random number sequence (step 5).

[0120] The processing of step 5 is carried out between the fourth random number sequence generation unit B2 of the second device B and the first device A. As a result, the fourth random number sequence generation unit B2 of the second device B obtains a fourth random number sequence.

[0121] Second random number sequence H1(~ID B )={H1(4),H1(7),H1(3),H1(6)}, then, as in the example of FIG. 11, the fourth random number sequence H2(H1(~ID B )) = {H2(H1(4)),H2(H1(7)),H2(H1(3)),H2(H1(6))}. H2 is the SK obtained as an output by the first device A, which is the sender in the definition of the OPRF protocol. A H2 is a pseudorandom function f determined by the following equation: H2 is, for example, a hash function.

[0122] <Step 6> The first device A obtains a fifth random number sequence, which is a sequence of random numbers obtained by perturbing the random numbers included in the first random number sequence and the random numbers included in the third random number sequence using a pseudorandom function determined by the OPRF protocol executed to obtain the fourth random number sequence (Step 6).

[0123] The process of step 6 is performed by the fifth random number sequence generation unit A4 of the first device A. That is, the fifth random number sequence generation unit A4 of the first device A obtains the fifth random number sequence.

[0124] First random number sequence H1(ID A ) = {H1(1),H1(3),H1(5),H1(7)}, and the third random number sequence H1(~ID B )={H1(4),⊥,⊥,H1(6)}, as in the example of FIG. 11, the fifth random number sequence H2(H1(ID U ) = {H2(H1(1)), ..., H2(H1(7)), H2(H1(4)), H2(H1(6))}. As in this example, the third random number sequence H1(~ID B The dummy value ⊥ in the fifth random number sequence may not be randomized or inserted into the fifth random number sequence. For example, the fifth random number sequence generator A4 of the first device A may generate the fifth random number sequence SK obtained in step 5. A The calculation of H2 is performed using a pseudorandom function f determined by the following equation: The calculation of H2 is an example of randomization performed by the fifth random number sequence generation unit A4 of the first device A.

[0125] <Step 7> The first device A transmits to the second device B a sequence of elements obtained by rearranging elements including each random number included in the fifth random number sequence and a secret value obtained by encrypting a value included in the set of attribute values ​​in the first database corresponding to each random number using homomorphic encryption or a predetermined value corresponding to each random number (step 7).

[0126] The process of step 7 is performed by the encryption unit A5 of the first device A.

[0127] The rearrangement is performed, for example, randomly.

[0128] In the example of FIG. 12 , attribute a is a categorical attribute, and its attribute value is one of α, β, and γ. Furthermore, the attribute value of attribute a corresponding to H2(H1(1)) is γ, ..., the attribute value of attribute a corresponding to H2(H1(7)) is β. In this case, the encryption unit A5 sets the attribute value of attribute a corresponding to H2(H1(1)) to (E(0),E(0),E(1)), ..., the attribute value of attribute a corresponding to H2(H1(7)) to (E(0),E(1),E(0)). In this way, the encryption unit A5 may convert each attribute value into a one-hot vector and then encrypt each element of the converted one-hot vector. E indicates encryption using homomorphic encryption. Since H2(H1(4)) and H2(H1(6)) are derived from the second database, the encryption unit A5 assigns predetermined values ​​(E(0), E(0), E(0)) to H2(H1(4)) and H2(H1(6)), respectively. In this case, the element sequence sent to the second device B is, for example, as shown in SE1 in FIG. 12. In the element sequence SE1, the fifth random number sequence H2(H1(ID U The part between H2(H1(1)) and H2(H1(7)) in

[0129] If the attribute is a numerical attribute rather than a categorical attribute, the encryption unit A5 may directly encrypt the numerical value, which is the attribute value, using homomorphic encryption.

[0130] <Step 8> The second device B uses the fourth random number sequence and the element sequence to generate a combined database that associates values ​​included in the set of attribute values ​​of the second database with secret values ​​or predetermined values ​​of elements included in the element sequence (step 8).

[0131] The processing of step 8 is performed by the combining unit B3 of the second device B. For example, the combined database is generated using the fourth random number sequence and the random number H2(H1(ID)) included in the element sequence as a combining key.

[0132] In the example of FIG. 12, attribute b is a categorical attribute, and takes either a # or a $ as an attribute value. Also, in the second database, the attribute value of attribute b corresponding to H2(H1(4)) is #, the attribute value of attribute b corresponding to H2(H1(7)) is $, the attribute value of attribute b corresponding to H2(H1(3)) is #, and the attribute value of attribute b corresponding to H2(H1(6)) is $. In this case, the combined database generated by the combining unit B3 is, for example, DB1 in FIG. 12. This combined database is called combined table J. i It corresponds to.

[0133] [Modifications] The specific configurations of the embodiments of the disclosed technology are not limited to the configurations described above. The specific configurations of the embodiments of the disclosed technology can be appropriately modified in design, etc., within the scope of the spirit of the embodiments of the disclosed technology.

[0134] The various processes described in the embodiments of the disclosed technology may not only be performed chronologically in the order described, but may also be performed in parallel or individually depending on the processing capacity of the device performing the processes or as needed.

[0135] For example, data may be exchanged directly between the components of the statistical calculation device, or may be exchanged via a storage unit (not shown).

[0136] Furthermore, a device (terminal) for using the device, system, or method of the present invention via a network (telecommunications line) may also be provided. The "device (terminal) for use" may be provided with functions (e.g., control function, decoding function, restoration function, input / output function, etc.) necessary to obtain the effects of implementing the device, system, or method of the present invention.

[0137] It goes without saying that other modifications are possible without departing from the spirit of the present invention.

[0138] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.

[0139] [Program, Recording Medium] The functions realized by the components described in this specification may be implemented in circuitry or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), CPUs (Central Processing Units), conventional circuits, and / or combinations thereof, programmed to realize the described functions. A processor includes transistors and other circuits and is considered to be circuitry or processing circuitry. A processor may also be a programmed processor that executes a program stored in a memory.

[0140] In this specification, a circuitry, unit, or means is hardware that is programmed to realize or performs the described functions, which may be any hardware disclosed herein or any hardware known to be programmed to realize or perform the described functions.

[0141] If the hardware is a processor considered to be a type of circuitry, the circuitry, means, or unit is a combination of the hardware and software used to configure the hardware and / or processor.

[0142] The various processes described above can be implemented by loading a program that executes each step of the above method into the recording unit 2020 of the computer 2000 shown in Figure 13, and operating the control unit 2010, input unit 2030, output unit 2040, display unit 2050, etc.

[0143] The program describing the processing contents can be recorded on a computer-readable recording medium, which may be, for example, a magnetic recording device, an optical disk, a magneto-optical recording medium, a semiconductor memory, or any other suitable recording medium.

[0144] The program may be distributed by, for example, selling, transferring, lending, etc. portable recording media such as DVDs and CD-ROMs on which the program is recorded. Furthermore, the program may be stored in a storage device of a server computer, and then transferred from the server computer to other computers via a network, thereby distributing the program.

[0145] A computer that executes such a program may first temporarily store the program recorded on a portable recording medium or transferred from a server computer in its own storage device. Then, when executing a process, the computer reads the program stored on its own recording medium and executes the process in accordance with the read program. Alternatively, the computer may read the program directly from a portable recording medium and execute the process in accordance with the program. Furthermore, the computer may execute the process in accordance with the program each time a program is transferred from a server computer to the computer. Alternatively, the server computer may not transfer the program to the computer, but may instead execute the process through a so-called ASP (Application Service Provider) service, which realizes the processing function by issuing an execution instruction and obtaining the results. Furthermore, the server computer may execute the process at the terminal using a so-called SaaS (Software as a Service) service, which allows users to use part of a server computer along with the program. In this embodiment, the program includes information used for processing by an electronic computer that is equivalent to a program (such as data that is not a direct instruction to a computer but has properties that dictate computer processing).

[0146] Furthermore, in this embodiment, the device is configured by executing a predetermined program on a computer, but at least a part of the processing contents may be realized by hardware.

Claims

1. For j=1,...,m, participant device A and participant device B j The table held by participant device A and participant device B j The participant device B performs the join process with the table held by the participant device B while keeping each table secret. j is the join table J j and a combining step to obtain participant device B for j=1,...,m. j is the join table J j , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc A (t j ) and the participant devices A, B1,..., B m At least one of Enc A (t1),...,Enc A (t m ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A A final result acquisition step of obtaining (r), and a participant device A obtaining the ciphertext Enc A a decoding step of decoding (r) to obtain a final result r; 2. For i=1,...,n, participant device A i and participant device B, participant device A i The participant device B performs a process of joining the table held by the participant device A with the table held by the participant device B while keeping each table secret, and the participant device B creates a joined table J. i and a join step in which participant B obtains the join table J for i=1,...,n. i , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc Ai (s i ) and the participant device B obtains the intermediate result. A1 (s1),...,Enc An (s n ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A1,...,An A final result acquisition step to obtain (r), and participant devices A1,...,A n However, the ciphertext Enc A1,...,An a decoding step of decoding (r) to obtain a final result r; 3. For j=1,...,m, participant device A i and participant device B j And, participant device A i Participant B has a table and device j The participant device B performs the join process with the table held by the participant device B while keeping each table secret. j is the join table J j and a combining step to obtain participant device B for j=1,...,m. j is the join table J j , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc Ai (t j ) and an intermediate result acquisition step for obtaining the participant device A. i ,B1,...,B m At least one of Enc Ai (t1),...,Enc Ai (t m ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc Ai (w i ), and by performing the processes of the combining step, the intermediate result obtaining step, and the final result obtaining step for i=1,...,n, Enc A1 (w1),...,Enc An (w n ) and B1,...,B m At least one of Enc A1 (w1),...,Enc An (w n ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A1,...,An (r) and the integration step to obtain (r) and the participant devices A1,...,A n However, the ciphertext Enc A1,...,An a decoding step of decoding (r) to obtain a final result r; 4. Participant device A and participant devices B1,...,B m a statistics calculation device including a participant device A and a participant device B, where j=1,...,m; j The table held by participant device A and participant device B j The participant device B performs the join process with the table held by the participant device B while keeping each table secret. j is the join table J j and for j=1,...,m, participant device B j is the join table J j , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc A (t j ) and participant devices A, B1,..., B m At least one of Enc A (t1),...,Enc A (t m ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A (r), and participant device A obtains the ciphertext Enc A A statistical calculation device that decodes (r) to obtain a final result r.

5. Participant device A1,...,A n and participant device B, where i=1,...,n, i and participant device B, participant device A i The participant device B performs a process of joining the table held by the participant device A with the table held by the participant device B while keeping each table secret, and the participant device B creates a joined table J. i For i=1,...,n, participant device B obtains the join table J i , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc Ai (s i ) and participant device B receives Enc A1 (s1),...,Enc An (s n ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A1,...,An (r) is obtained, and participant devices A1,...,A n However, the ciphertext Enc A1,...,An A statistical calculation device that decodes (r) to obtain a final result r.

6. Participant device A1,...,A n and participant devices B1,...,B m a statistics calculation device including a participant device A, for j=1,...,m; i and participant device B j And, participant device A i Participant B has a table and device j The participant device B performs the join process with the table held by the participant device B while keeping each table secret. j is the join table J j and for j=1,...,m, participant device B j is the join table J j , a predetermined operation f to obtain an intermediate result is executed on the homomorphic ciphertext, and the ciphertext Enc Ai (t j ) and participant device A i ,B1,...,B m At least one of Enc Ai (t1),...,Enc Ai (t m ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc Ai (w i ), and by performing the combining step, the intermediate result obtaining step, and the final result obtaining step for i=1,...,n, Enc A1 (w1),...,Enc An (w n ) and B1,...,B m At least one of Enc A1 (w1),...,Enc An (w n ), a predetermined operation g to obtain the final result is executed on the homomorphic ciphertext to obtain the final ciphertext Enc A1,...,An (r) is obtained, and participant devices A1,...,A n However, the ciphertext Enc A1,...,An and decoding (r) to obtain a final result r.

7. A statistics calculation device that is a participant device of any of the statistics calculation devices of claims 4 to 6.

8. A program for causing a computer to execute each step of the statistical quantity acquisition method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Encrypted statistical processing system, device, method, and program

    WO2012169153A1