Vehicle search device, investigation agency terminal, vehicle search system, vehicle search method, investigation support method, and recording medium
The vehicle search device uses encrypted search conditions and secure computation to prevent information leakage in criminal investigations, maintaining data confidentiality through homomorphic encryption.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2026-04-02
AI Technical Summary
Existing vehicle information search systems for criminal investigations risk information leakage due to the exposure of search content and history, posing a security threat.
A vehicle search device employing encrypted search conditions through secure computation processes, utilizing homomorphic encryption to maintain data confidentiality during searches and output encrypted results.
Prevents information leakage by ensuring that search conditions and results remain confidential, protecting sensitive investigation data during criminal investigations.
Smart Images

Figure JP2024033795_02042026_PF_FP_ABST
Abstract
Description
Vehicle search device, investigative agency terminal, vehicle search system, vehicle search method, investigation support method, and recording medium
[0001] The present disclosure relates to a vehicle search device, an investigative agency terminal, a vehicle search system, a vehicle search method, an investigation support method, and a recording medium.
[0002] Vehicle information regarding a vehicle may be stored, for example, as a database. And the stored vehicle information may be utilized for criminal investigations.
[0003] Patent Document 1 describes an investigation support system that stores information regarding a vehicle extracted from captured images, searches for a fleeing vehicle, and displays information regarding the vehicle as a vehicle search result.
[0004] Japanese Patent Application Laid-Open No. 2020-137069
[0005] When using vehicle information for criminal investigations, it is necessary to search for vehicle information regarding a vehicle related to a criminal investigation from a database in which the vehicle information is stored. When the search is performed, information related to the investigation may be used. And by performing the search, at least the database administrator may know the search content, search history, etc. Then, there is a risk of leakage of information related to the investigation.
[0006] One of the objects of the present disclosure is to provide a vehicle search device, a vehicle search method, and a recording medium capable of preventing leakage of information related to an investigation when using vehicle information for criminal investigations.
[0007] A vehicle search device according to one aspect of the present disclosure includes an acquisition unit that acquires encrypted search conditions related to a criminal investigation, a search unit that searches for vehicle information by means of a secure computation process using the search conditions, and an output unit that outputs an encrypted search result.
[0008] A vehicle search method according to one aspect of the present disclosure acquires encrypted search conditions related to a criminal investigation, searches for vehicle information by means of a secure computation process using the search conditions, and outputs an encrypted search result.
[0009] A program in one aspect of this disclosure causes a computer to perform a process that obtains encrypted search criteria related to criminal investigations, searches for vehicle information using secure computation processing with the search criteria, and outputs encrypted search results.
[0010] Each program may be stored on a non-temporary storage medium that is readable by the computer.
[0011] One example of the benefits of this disclosure is that it will be possible to prevent the leakage of information related to investigations when vehicle information is used in criminal investigations.
[0012] This is a conceptual diagram showing an example of the application of the vehicle search system in this disclosure. This is a block diagram showing an example of the configuration of the vehicle search system in this disclosure. This is a diagram showing an example of a table containing records to which vehicle information is associated for each predetermined piece of information about a vehicle. This is a diagram showing an example of a table containing records to which vehicle information is associated for each predetermined piece of information about a vehicle. This is a diagram showing an example of a screen that can accept the specification of whether or not to conceal the search conditions. This is a diagram showing an example of a screen that displays the search results together with the concealed search conditions in a format that can identify the hidden search conditions among multiple search conditions. This is a sequence diagram showing an example of the operation of the vehicle search system in this disclosure. This is a block diagram showing an example of the configuration of the vehicle search system in this disclosure. This is a sequence diagram showing an example of the operation of the vehicle search system in this disclosure. This is a block diagram showing an example of the configuration of the vehicle search system in this disclosure. This is a sequence diagram showing an example of the operation of the vehicle search system in this disclosure. This is a block diagram showing an example of the configuration of the vehicle search system in this disclosure. This is a sequence diagram showing an example of the operation of the vehicle search system in this disclosure. This is a block diagram showing an example of the configuration of the vehicle search device in this disclosure. This is a flowchart showing the operation of the vehicle search device in this disclosure. This is a diagram showing an example of the hardware configuration of the vehicle search device in this disclosure.
[0013] Embodiments of this disclosure will be described in detail with reference to the drawings.
[0014] [First Embodiment] Referring to Figure 1, an example of the application of a vehicle search system including a vehicle search device 20 will be described. Figure 1 is a conceptual diagram showing an example of the application of a vehicle search system in this disclosure. Figure 1 shows an in-vehicle device 10, a vehicle search device 20, and an investigative agency terminal 30. The in-vehicle device 10 is a device mounted on a vehicle. The vehicle search system may include multiple in-vehicle devices 10 mounted on multiple vehicles. Here, the vehicle is, for example, a private car. The vehicle may also be a bus or a truck. The vehicle is not limited to these. The investigative agency terminal 30 is a terminal used by an investigative agency conducting a criminal investigation. The investigative agency terminal 30 can be used, for example, by an investigator. The vehicle search system may include multiple investigative agency terminals 30.
[0015] The in-vehicle device 10, the vehicle search device 20, and the investigative agency terminal 30 are connected to a network such as the Internet via wireless or wired communication. The in-vehicle device 10, the vehicle search device 20, and the investigative agency terminal 30 are each connected to each other via the network so that they can communicate with one another.
[0016] The in-vehicle device 10 is implemented, for example, by a car navigation system having a monitor. The in-vehicle device 10 may also be implemented by a device such as a smartphone or tablet. The vehicle search device 20 is a server device built in the cloud or a data center. The server device may also be implemented by an information processing device such as a personal computer. The investigative agency terminal 30 is implemented by an information processing device such as a personal computer. The investigative agency terminal 30 may also be implemented by a device such as a smartphone or tablet.
[0017] Here, the vehicle search device 20 may be, for example, a device managed by a business operator that provides connected car services. The in-vehicle device 10 may be a device installed in a vehicle owned by a user of the connected car service. The connected car service operator can obtain information about the vehicle of the connected car service user from the in-vehicle device 10 and store it in the vehicle search device 20.
[0018] Furthermore, the investigative agency terminal 30 is a terminal used by investigative agencies conducting criminal investigations. Examples of criminal investigations include investigations into accidents and incidents involving vehicles. However, examples of criminal investigations are not limited to these and also include counter-terrorism measures. According to the "principle of covert investigation," information related to investigations may need to be kept confidential. Therefore, in order to utilize vehicle information related to criminal investigations, for example, a database containing vehicle information may be searched. In this case, it is necessary to prevent the leakage of information related to the investigation.
[0019] Referring to Figure 2, an example of the configuration of a vehicle search system including a vehicle search device 20 will be described. Figure 2 is a block diagram showing an example of the configuration of a vehicle search system in this disclosure. The vehicle search system comprises a plurality of in-vehicle devices 10, a vehicle search device 20, and an investigative agency terminal 30. There may be multiple investigative agency terminals 30. Also, in Figure 2, the network interposed between the components is omitted.
[0020] First, let's describe the components of the in-vehicle device 10. Referring to Figure 2, the in-vehicle device 10 includes a data acquisition unit 101 and a data transmission unit 102.
[0021] The data acquisition unit 101 is one embodiment of a data acquisition means for collecting data related to a vehicle. The data acquisition unit 101 collects data related to the vehicle on which the in-vehicle device 10 is installed. The collected vehicle data will be referred to as collected data below.
[0022] The collected data includes the vehicle number and vehicle type of the vehicle on which the in-vehicle device 10 is installed. The vehicle number is, for example, a serial number. The vehicle number may also include a classification number or a character indicating whether the vehicle is for commercial use. The vehicle type may also include the color and classification of the vehicle body. Vehicle classifications include, for example, trucks, sedans, wagons, minivans, etc., but are not limited to these. The collected data may also include vehicle location information logs, mileage, fuel level, driving time, driving frequency, etc. The location information logs include the vehicle's location information and time. Furthermore, the collected data may include the driving pattern of the driver of the vehicle. A driving pattern is information about the driver's driving habits. Specific examples of driving patterns include habits in acceleration and deceleration, steering, and braking. Here, the driver may be the owner of the vehicle or a different person. Furthermore, the collected data may include information about the vehicle owner. Information about the vehicle owner may include, for example, the owner's name, age, and address. The collected data may also include the search history of the navigation system installed in the vehicle.
[0023] The collected data is not limited to these. The collected data may be, for example, information collected for the provision of connected car services. The collected data is collected using publicly known technology. For example, the collected data may be collected by sensors installed in the vehicle. Alternatively, the collected data may be collected by input from the vehicle's driver or owner. The method of collecting the collected data by the data collection unit 101 is not limited to these.
[0024] The data transmission unit 102 is one embodiment of a data transmission means that outputs collected data. The data transmission unit 102 transmits the collected data collected by the data collection unit 101 to the vehicle search device 20.
[0025] The data transmission unit 102 may transmit the collected data at the time the data collection unit 101 has collected the data. Alternatively, the data transmission unit 102 may transmit the collected data at predetermined intervals. For example, the data transmission unit 102 may transmit the collected data at a fixed time each day. In this case, the collected data collected by the data collection unit 101 is temporarily stored in memory. The timing at which the data transmission unit 102 transmits the collected data is not limited to these examples.
[0026] Next, the components of the vehicle search device 20 will be described. Referring again to Figure 2, the vehicle search device 20 comprises a data acquisition unit 201, a storage unit 202, an acquisition unit 203, a search unit 204, and an output unit 205.
[0027] The data acquisition unit 201 is one embodiment of a data acquisition means for acquiring data related to a vehicle. The data acquisition unit 201 acquires collected data transmitted by the data transmission unit 102 in the in-vehicle device 10. The data acquisition unit 201 can acquire collected data transmitted by data transmission units 102 in multiple in-vehicle devices 10. In other words, the data acquisition unit 201 can acquire collected data related to multiple vehicles.
[0028] The storage unit 202 is one embodiment of a storage means that stores a table containing records to which vehicle information is associated for each predetermined piece of information relating to a vehicle. The predetermined information relating to a vehicle and the vehicle information are included in the collected data acquired by the data acquisition unit 201. The storage unit 202 can then format the collected data acquired by the data acquisition unit 201 into the format of the table described above. In other words, the storage unit 202 formats a table containing records to which vehicle information is associated for predetermined data from the collected data. The vehicle information is the data obtained by removing the predetermined data from the collected data. In other words, the content of the vehicle information in the formatted table differs depending on the predetermined data relating to the vehicle.
[0029] Here, the specified information about the vehicle is, for example, the vehicle number. Alternatively, the specified information about the vehicle may be the vehicle type or the vehicle's location. There may be one or more specified pieces of information about the vehicle. If there are multiple specified pieces of information about the vehicle, the table contains records where the vehicle information is associated with the multiple specified pieces of information about the vehicle. Examples of multiple specified pieces of information about a vehicle include, but are not limited to, location information and time.
[0030] The specified information about the vehicle corresponds to the search criteria related to criminal investigations, which will be described later. In other words, the type of search criteria related to criminal investigations corresponds to the type of specified information about the vehicle. The type of search criteria related to criminal investigations and the type of specified information about the vehicle may be the same. The types of search criteria will be explained later. The specified information about the vehicle corresponds to the key information corresponding to the query, which is the search criterion. The vehicle information corresponds to the value associated with the key.
[0031] Here, with reference to the figure, we will describe a table containing records to which vehicle information is associated with each predetermined piece of information about a vehicle. Figure 3-5 shows an example of a table containing records to which vehicle information is associated with each predetermined piece of information about a vehicle.
[0032] In the table shown in Figure 3, vehicle information is associated with each vehicle number. In Figure 3, vehicle numbers are represented by four-digit numbers, but this is not the only way to represent them. The vehicle information shown in Figure 3 includes the vehicle type and location information of the vehicle associated with the vehicle number. However, the vehicle information is not limited to these. Multiple vehicles may be associated with a single vehicle number. For example, if a vehicle number is a four-digit number, vehicle information for multiple vehicles from different transportation bureaus may be associated with that vehicle number.
[0033] In the table shown in Figure 4 as an example, vehicle information is associated with each time and location. First, multiple locations are associated with each time. Then, the vehicle information of the vehicle that was at that location at that time is associated with the time and location. For example, for the time "yyyy / mm / dd 23:55:55" and location 1, the vehicle information of vehicle A, which was at location 1 at the time "yyyy / mm / dd 23:55:55", is associated. Locations 1, 2, and n are examples of locations. Multiple vehicles may be associated with a time and location.
[0034] The table shown in Figure 5, as an example, consists of multiple tables separated by time. In each table, vehicle information is associated with each location. The vehicle information of a vehicle that was at a certain location at a given time is associated with that location in the table for that time. The vehicle information in Figure 5 may include, for example, the vehicle type and vehicle number. However, the vehicle information is not limited to these. Also, there may be multiple vehicles associated with a time and location.
[0035] Tables containing records associated with vehicle information for each set of predetermined information about a vehicle are not limited to these. For example, the predetermined information about a vehicle may include vehicle type and location information. In this case, the table may associate vehicle information with the vehicle type and the location indicated by the location information.
[0036] Furthermore, the memory unit 202 can, for example, format a table according to desired search conditions. In criminal investigations, the information that investigators can obtain about vehicles may differ depending on the type of crime and the investigation status. In other words, the types of search conditions may differ depending on the type of crime and the investigation status. Therefore, the memory unit 202 may format a table according to the type of information entered as search conditions. In other words, the memory unit 202 may format a table with the type of information entered as search conditions being predetermined information about vehicles.
[0037] The acquisition unit 203 is one embodiment of an acquisition means for acquiring encrypted search conditions related to criminal investigations. The acquisition unit 203 acquires the search conditions related to criminal investigations from the transmission unit 303, which will be described later.
[0038] Search criteria related to criminal investigations are information that can narrow down the list of vehicles. Vehicles narrowed down by these search criteria are those that may be related to a crime. For example, a criminal investigator might consider a vehicle to be potentially related to a crime. The search criteria may result in the identification of one or more vehicles.
[0039] Search criteria for criminal investigations include, for example, vehicle identification numbers. Vehicle identification numbers are serial identification numbers. Vehicle identification numbers may also include classification numbers and business identification characters. Search criteria for criminal investigations may also include the type of vehicle. Furthermore, there may be multiple search criteria for criminal investigations. When there are multiple search criteria for criminal investigations, examples of search criteria include time and location information. Search criteria for criminal investigations are not limited to these. These search criteria allow investigators to narrow down, for example, vehicles that may be involved in a crime.
[0040] The search criteria related to criminal investigations are encrypted using a predetermined encryption method. One example of an encryption method is homomorphic encryption. The search criteria related to criminal investigations are encrypted using homomorphic encryption. In other words, the acquisition unit 203 acquires the search criteria related to criminal investigations that have been encrypted using homomorphic encryption.
[0041] Homomorphic encryption is an encryption method that allows data operations to be performed while the data remains encrypted. Because homomorphic encryption allows data processing to be carried out while the data is encrypted, in addition to data transmission and storage, it is attracting attention from the perspective of protecting privacy and preventing data leaks. Other encryption methods may be used as long as data operations can be performed while the data remains encrypted.
[0042] Search conditions related to criminal investigations may be encrypted by the Single-key fully homomorphic encryption method (single-key method). In the single-key method, the search institution terminal 30 has an encryption key for encrypting search conditions related to criminal investigations. The encryption key corresponds to the public key. Also, the search institution terminal 30 stores a decryption key for decrypting the encrypted search results. The decryption key corresponds to the private key. Examples of the single-key method include fully homomorphic encryption such as the BGV (Brakerski / Fan-Vercauteren) method and the BGV (Brakerski-Gentry-Vaikuntanathan) method. In the present embodiment, an example in which pre-generated encryption keys and decryption keys are used is given.
[0043] When the search conditions related to criminal investigations are encrypted by the Single-key fully homomorphic encryption method (single-key method), the acquisition unit 203 acquires the search conditions related to criminal investigations encrypted by the publicly disclosed encryption key.
[0044] The search criteria related to criminal investigations may be encrypted using a multi-key homomorphic encryption scheme. In the multi-key scheme, the investigative agency terminal 30 holds the encryption key for encrypting the search criteria related to criminal investigations. The investigative agency terminal 30 also stores the decryption key for decrypting the encrypted search results. The encryption key and decryption key correspond to private keys. The vehicle search device 20 does not store the encryption key or decryption key, but holds public parameters. The public parameters correspond to calculation keys generated using the private key at the time of overall system setup. The calculation keys are stored, for example, by a business operator that provides connected car services and manages the vehicle search device 20. The calculation keys are used in secure calculations of the encrypted data. In this embodiment, an example is given in which pre-generated encryption and decryption keys are used. Furthermore, the method of this embodiment can be applied, for example, to the method described in Non-Patent Document 1 (H. Chen et al. “Efficient Multi-Key Homomorphic Encryption with Packed Ciphertexts with Application to Oblivious Neural Network Inference”, Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, 2019). Here, secure computation is a technology that enables computation while data is kept confidential.
[0045] When search conditions related to criminal investigations are encrypted using a multi-key homomorphic encryption scheme (single-key scheme), the acquisition unit 203 acquires the search conditions related to criminal investigations, which have been encrypted with a non-public encryption key.
[0046] The data acquisition unit 201 may acquire an encrypted search condition and an unencrypted search condition. When there are a plurality of search conditions, the acquisition unit 203 may acquire some of the search conditions in an encrypted format and the other search conditions in an unencrypted format. For example, when the search conditions are time and location information, the acquisition unit 203 may acquire the time in an unencrypted format and the location information in an encrypted format. Here, the encryption method for the search condition to be encrypted may be the single-key method or the multi-key method described above.
[0047] The search unit 204 is an aspect of a search means for searching vehicle information by secret calculation processing using a search condition. The search unit 204 searches for vehicle information using the search condition acquired by the acquisition unit 203. The search unit 204 searches for the vehicle information of the vehicle corresponding to the search condition from the table stored in the storage unit 202. The search conditions related to criminal investigation are, as described above, information that can narrow down the vehicles. And the vehicle information as the search result is the vehicle information of the vehicle narrowed down by the search condition.
[0048] For example, when the search condition is a vehicle number, the search unit 204 searches for the vehicle information associated with the vehicle number. That is, the search result is the vehicle information associated with the vehicle number. When the search condition is a vehicle number, for example, the search unit 204 can search for the vehicle information associated with the vehicle number by performing secret calculation processing on the table shown in FIG. 3. The example of the table for performing the secret calculation processing is not limited to FIG. 3.
[0049] Also, when the search conditions are time and location information, the search unit 204 searches for the location indicated by the location information and the vehicle information associated with the time. That is, the search result is the vehicle information associated with the time and the location indicated by the location information. When the search conditions are time and location information, for example, the search unit 204 can search for the vehicle information associated with the vehicle number by performing secret calculation processing on the table shown in FIG. 4. The example of the table for performing the secret calculation processing is not limited to FIG. 4.
[0050] The search unit 204 searches for vehicle information using secure computation. The secure computation using search conditions is, for example, an arithmetic operation using a homomorphic encryption scheme. The search unit 204 may also search for vehicle information using secure computation with search conditions encrypted with a publicly available encryption key. Alternatively, the search unit 204 may also search for vehicle information using secure computation with search conditions encrypted with a non-public encryption key.
[0051] By using homomorphic encryption for secure computation, encrypted data can be manipulated while remaining encrypted. In homomorphic encryption, any function can be performed by combining addition and multiplication.
[0052] Homomorphic encryption includes various types such as additive homomorphisms, multiplicative homomorphisms, somewhat homomorphisms, and fully homomorphic encryption. Additive homomorphisms are encryption methods that allow addition operations to be performed on the ciphertext. Examples of additive homomorphisms include the Goldwasser-Micali cipher, the Paillier cipher, and the Okamoto-Uchiyama cipher. Multiplicative homomorphisms are encryption methods that allow multiplication operations to be performed on the ciphertext. Examples of multiplicative homomorphisms include the ElGamal cipher and the RSA (Rivest-Shamir-Adleman) cipher. Somewhat homomorphisms are encryption methods that allow addition and multiplication operations to be performed on the ciphertext. Somewhat homomorphisms have limitations on the number of multiplication operations that can be performed. Examples of somewhat homomorphisms include the BGN (Boneh-Goh-Nissim) cipher and some lattice ciphers. A fully homomorphic encryption scheme is a type of encryption that allows addition and multiplication operations to be performed on the ciphertext without altering its original form.
[0053] The plaintext M[k] and the ciphertext C[k] are related as shown in equation (1) below (where k is a natural number).
[0054] [Equation 1] C[k] = Enc(M[k]) ... (1) Using additive homomorphism, somewhat homomorphism, or full homomorphism, the addition of plaintext M[1] and plaintext M[2] can be performed using ciphertext C[1] and ciphertext C[2], as shown in equation (2) below.
[0055] [Math 2] C a= Enc(M[1] + M[2]) ... (2) Using multiplicative homomorphism, somewhat homomorphism, or full homomorphism, the multiplication of plaintext M[1] and plaintext M[2] can be performed using ciphertext C[1] and ciphertext C[2] as shown in equation (3) below.
[0056] [Math 3] C m = Enc(M[1] × M[2]) ... (3) Note that the above equations (1) to (3) are a schematic representation of homomorphic encryption operations and do not represent homomorphic encryption in detail. For homomorphic encryption operations, known methods of operation can be selected.
[0057] The following also describes the case where some of the search conditions are encrypted, while others are not. In this case, the data acquisition unit 201 acquires the encrypted search conditions and the unencrypted search conditions. The search unit 204 searches for vehicle information by performing secure computation using the encrypted search conditions on the tables corresponding to the unencrypted search conditions. In other words, by using unencrypted search conditions, the tables to which secure computation is performed can be narrowed down. Therefore, the amount of processing required for secure computation can be reduced.
[0058] For example, let's consider a case where the search criteria are time and location information, the location information is encrypted, and the time is not encrypted. In this case, for example, the search unit 204 performs a search on the table corresponding to the time included in the search criteria from among the multiple tables shown in Figure 5. In this case, the time is an unencrypted search criterion. In other words, the unencrypted search criterion can be used to narrow down the tables to be searched. Then, secure computation processing is performed on the tables to be searched using the encrypted search criterion. In the example shown in Figure 5, the search unit 204 can retrieve vehicle information associated with the time and the location indicated by the location information by performing secure computation processing using the location information, which is an encrypted search criterion.
[0059] Examples where some search criteria are encrypted while others are not are not limited to those shown. Furthermore, the table used for secure computation is not limited to the example in Figure 5.
[0060] The encryption method for search criteria related to criminal investigations is not limited to this. Another example of an encryption method is the PIANO method. For example, the method described in Non-Patent Document 2 (M. Zhou et al. “Piano: Extremely Simple, Single-Server PIR with Sublinear Server Computation”, IEEE S&P 2024, 2024) can be applied to encrypt search criteria.
[0061] The output unit 205 is one form of output means that outputs encrypted search results. The output unit 205 outputs the encrypted search results to the receiving unit 304, which will be described later. The encryption method of the search results differs depending on the encryption method of the search conditions.
[0062] If the search conditions are encrypted using a single-key scheme, the search results are also encrypted using a single-key scheme. In other words, when the search unit 204 searches for vehicle information using search conditions encrypted with a publicly available encryption key, the output unit 205 outputs the search results that are decrypted using a private decryption key that is paired with the encryption key.
[0063] If the search conditions are encrypted using a multi-key scheme, the search results are also encrypted using a multi-key scheme. In other words, when the search unit 204 searches for vehicle information using search conditions encrypted with a non-public encryption key, the output unit 205 outputs the search results that have been decrypted using a non-public decryption key that is paired with the encryption key.
[0064] The components of the investigative agency terminal 30 will now be described. Referring again to Figure 2, the investigative agency terminal 30 comprises a reception unit 301, a search condition encryption unit 302, a transmission unit 303, a receiving unit 304, a decryption unit 305, and a display control unit 306.
[0065] The reception unit 301 is one form of a reception means for receiving search conditions related to criminal investigations. The reception unit 301 can receive search conditions related to criminal investigations, for example, through input by an investigator. The display control unit 306, which will be described later, may display a screen that can receive search conditions related to criminal investigations. The investigator can then input the search conditions related to criminal investigations into this screen. As a result, the reception unit 301 can receive search conditions related to criminal investigations through screen input, but the method of receiving search conditions related to criminal investigations is not limited to these. For example, the search conditions related to criminal investigations may be entered by voice input by the investigator. In other words, the reception unit 301 can receive search conditions related to criminal investigations through voice input. The search conditions related to criminal investigations are as described above. There may be multiple search conditions related to criminal investigations.
[0066] If there are multiple search conditions related to a criminal investigation, the reception unit 301 may accept a designation that some of the search conditions should not be kept confidential. Depending on the case under investigation, it may not be necessary to keep all search conditions confidential. For example, the time of the investigation may not need to be kept confidential, but the location information of the investigation may need to be kept confidential. Therefore, the reception unit 301 may accept a designation that some of the search conditions should be kept confidential, and other search conditions should not be kept confidential. Search conditions for which a designation to be kept confidential is encrypted by the search condition encryption unit 302, which will be described later. Search conditions for which a designation to not be kept confidential is not encrypted by the search condition encryption unit 302, which will be described later.
[0067] The reception unit 301 can, for example, accept a designation to not conceal some of the search conditions through screen input. At this time, the display control unit 306, which will be described later, displays a screen that can accept a designation to not conceal some of the search conditions. The display control unit 306 can display the screen that can accept a designation to not conceal some of the search conditions on, for example, the investigative agency terminal 30.
[0068] The reception unit 301 can accept a designation to not conceal search conditions for some of multiple search conditions, based on input to a screen that accepts such designations, as shown in Figure 6 as an example. Figure 6 is a diagram showing an example of a screen that accepts designations to not conceal search conditions. The search conditions shown in Figure 6 are just examples and are not limited to these.
[0069] Figure 6 shows a "Location" column and a "Time" column. In this case, the search criteria are time and location information. The input in the "Location" column corresponds to the location information of the search criteria. For example, the investigator enters the location information and time of the subject of investigation into the "Location" column and the "Time" column, respectively. In Figure 6, there is a checkbox to the left of each search criterion column. The investigator can check the search criteria that should not be kept secret. However, it is not possible to check all search criteria. If all search criteria were checked, all search criteria would not be kept secret. In this way, the investigator can use the screen shown as an example in Figure 6 to specify that some of the search criteria should not be kept secret. For search criteria that the investigator has checked, the reception unit 301 accepts the specification that those search criteria should not be kept secret. Conversely, for search criteria that the investigator has not checked, the reception unit 301 accepts the specification that those search criteria should be kept secret.
[0070] In the example screen shown in Figure 6, the reception unit 301 accepted a specification that the search conditions should not be kept secret, but it may also accept a specification that the search conditions should be kept secret. For example, in the investigative agency terminal 30, investigators may be able to check the search conditions they want to keep secret. In this case, it is necessary to check one or more search conditions. This is because if none of the multiple search conditions are checked, none of the search conditions will be kept secret. For search conditions for which a specification to keep secret has not been accepted, the reception unit 301 accepts a specification that they should not be kept secret.
[0071] The method for receiving the specification of whether or not to keep the search conditions confidential is not limited to these. Also, although there were multiple search conditions in Figure 6, the receiving unit 301 may also accept the specification to keep the search conditions confidential even if there is only one search condition.
[0072] The search condition encryption unit 302 is one embodiment of a search condition encryption means for encrypting search conditions. The search condition encryption unit 302 encrypts the search conditions received by the reception unit 301. The search condition encryption unit 302 can encrypt the search conditions using a homomorphic encryption scheme. The homomorphic encryption scheme is as described above.
[0073] The search condition encryption unit 302 may encrypt the search conditions using a single-key scheme. In other words, the search condition encryption unit 302 may encrypt the search conditions using a publicly available encryption key. Alternatively, the search condition encryption unit 302 may encrypt the search conditions using a multi-key scheme. In other words, the search condition encryption unit 302 may encrypt the search conditions using a private encryption key.
[0074] The search condition encryption unit 302 encrypts the search conditions for which the reception unit 301 has specified that some of the search conditions should not be kept confidential. In other words, the search condition encryption unit 302 does not encrypt the search conditions for which the reception unit 301 has specified that they should not be kept confidential.
[0075] The encryption method for the search results by the search condition encryption unit 302 is not limited to these. The search condition encryption unit 302 may also encrypt the search results using the PIANO method described above.
[0076] The transmission unit 303 is one embodiment of a transmission means for transmitting encrypted search conditions. The transmission unit 303 transmits the search conditions encrypted by the search condition encryption unit 302. The transmission unit 303 transmits the encrypted search conditions to the acquisition unit 203 in the vehicle search device 20. When the reception unit 301 receives a specification for each of the multiple search conditions whether or not to keep the search conditions confidential, the transmission unit 303 transmits the encrypted search conditions and the unencrypted search conditions.
[0077] The receiving unit 304 is one form of receiving means that receives vehicle information retrieved by secure computation processing using search conditions in an encrypted format as search results. The receiving unit 304 receives encrypted search results from the output unit 205 of the vehicle search device 20. The search results are vehicle information retrieved by the search unit 204 by secure computation processing using search conditions.
[0078] The encryption method used for search results varies depending on the encryption method used for the search criteria. If the search criteria are encrypted using a single-key scheme, the search results are also encrypted using a single-key scheme. If the search criteria are encrypted using a multi-key scheme, the search results are also encrypted using a multi-key scheme.
[0079] The decryption unit 305 is one embodiment of a decryption means for decrypting encrypted search results. The decryption unit 305 decrypts the search results received by the receiving unit 304. The decryption method of the search results differs depending on the encryption method of the search conditions. If the search conditions are encrypted using a single-key scheme, the decryption unit 305 decrypts using the single-key scheme. That is, the decryption unit 305 decrypts the search results using a non-public decryption key that is paired with the encryption key. If the search conditions are encrypted using a multi-key scheme, the decryption unit 305 decrypts using the multi-key scheme. That is, the decryption unit 305 decrypts the search results using a non-public decryption key that is paired with the encryption key.
[0080] The display control unit 306 is one embodiment of a display control means for displaying decoded search results. The display control unit 306 displays the decoded search results on the screen of the investigative agency terminal 30, for example. The display control unit 306 may also display the decoded search results on a device (not shown) different from the investigative agency terminal 30. An example of a device different from the investigative agency terminal 30 is a display used by the investigative agency. The display control unit 306 should display the search results on a device that allows investigators to confirm the search results.
[0081] The display control unit 306 may display a list of vehicle information for multiple vehicles if the search results include vehicle information for multiple vehicles.
[0082] Furthermore, the display control unit 306 may display the search conditions along with the decrypted search results. In addition, the display control unit 306 may display the concealed search conditions in an identifiable format.
[0083] Referring to the diagram, we will explain the screen in which hidden search criteria are displayed along with the search results in an identifiable format. Figure 7 shows an example of a screen in which hidden search criteria are displayed along with the search results in an identifiable format. In the example screen shown in Figure 7, the search criteria are displayed at the top and the search results are displayed at the bottom. In the example shown in Figure 7, the search criteria are time and location information. The "Location" on the screen corresponds to the location information of the search criteria. A padlock icon is next to the "Location" display. The padlock icon indicates that the location information search criterion is hidden. In other words, search criteria with a padlock icon are hidden search criteria. Since there is no padlock icon next to the "Time" display, it can be seen that the time search criterion was not hidden. In this way, hidden search criteria can be identified by the padlock icon.
[0084] The method of displaying hidden search criteria in an identifiable format is not limited to displaying a padlock icon. For example, text such as "Hidden!" could be displayed next to the hidden search criteria.
[0085] The example screen shown in Figure 7 is an example where some of the multiple search conditions are hidden. Even when all of the multiple search conditions are hidden, the display control unit 306 may display the hidden search conditions in an identifiable format. For example, the display control unit 306 may mark all search conditions with a padlock icon. Also, even when there is only one search condition, the display control unit 306 may display in an identifiable format that the search condition has been hidden.
[0086] The display control unit 306 may also display a screen on which search conditions can be entered. In this case, the display control unit 306 may display a screen on which it is possible to specify that some of the multiple search conditions should not be kept secret, as shown as an example in Figure 6. The display control unit 306 can display a screen on which it is possible to specify that some of the multiple search conditions should not be kept secret, for example, on the screen of the investigative agency terminal 30.
[0087] Referring to Figure 8, an example of the operation of the vehicle search system will be described. Figure 8 is a sequence diagram showing an example of the operation of the vehicle search system in this disclosure. The operation of the in-vehicle device 10, the vehicle search device 20, and the investigative agency terminal 30, which are included in the vehicle search system, will be described.
[0088] First, in the in-vehicle device 10, the data acquisition unit 101 collects data (collected data) related to the vehicle (step S101). The data transmission unit 102 transmits the collected data collected by the data acquisition unit 101 (step S102).
[0089] In the vehicle search device 20, the data acquisition unit 201 acquires the collected data (step S103). Then, the storage unit 202 stores a table containing records to which vehicle information is associated for each predetermined piece of information about a vehicle (step S104).
[0090] Next, in the investigative agency terminal 30, the reception unit 301 receives search conditions related to criminal investigation (step S105). Then, the search condition encryption unit 302 encrypts the search conditions (step S106). The transmission unit 303 transmits the encrypted search conditions (step S107).
[0091] In the vehicle search device 20, the acquisition unit 203 acquires encrypted search conditions related to criminal investigations (step S108). Then, the search unit 204 searches for vehicle information using secure computation processing based on the search conditions (step S109). Finally, the output unit 205 outputs the encrypted search results (step S110).
[0092] Finally, in the investigative agency terminal 30, the receiving unit 304 receives the encrypted search results (step S111). The decryption unit 305 decrypts the encrypted search results (step S112). The display control unit 306 displays the decrypted search results (step S113).
[0093] This concludes the operation of the vehicle search system.
[0094] In this embodiment, the vehicle search device 20 has an acquisition unit 203 that acquires encrypted search conditions related to criminal investigations. The search unit 204 then searches for vehicle information using secure computation processing based on the search conditions, and the output unit 205 outputs the encrypted search results. Vehicle information may be stored, for example, in a database. When the stored vehicle information is used in criminal investigations, the information related to the investigation must be kept confidential. The configuration of the vehicle search device 20 makes it possible to prevent the leakage of information related to the investigation when vehicle information is used in criminal investigations.
[0095] When using vehicle information in criminal investigations, it is necessary to search for vehicle information related to the investigation from a database containing vehicle data. When vehicle information is searched, information related to the investigation may be used. Furthermore, when vehicle information is searched, at least the database administrator may become aware of the search content and search history. This poses a risk of leakage of information related to the investigation.
[0096] However, the acquisition unit 203 acquires encrypted search conditions related to criminal investigations. Therefore, it is possible to prevent the leakage of information related to the investigation from the search conditions. Furthermore, the search unit 204 searches for vehicle information using secure computation processing with the search conditions. Secure computation processing makes it possible to keep the data being processed confidential. One example of secure computation processing is arithmetic processing using homomorphic encryption. Homomorphic encryption is an encryption method that allows data calculations to be performed while the data remains in ciphertext form. Therefore, it is possible to prevent the leakage of information related to the investigation during the process in which the search unit 204 searches for vehicle information. In addition, the output unit 205 outputs encrypted search results. Therefore, it is possible to prevent the leakage of information related to the investigation from the search results.
[0097] Here, the search criteria are information that allows for narrowing down the vehicles. The vehicle information, on the other hand, is the vehicle information of the vehicles narrowed down by the search criteria. Investigators may want to obtain vehicle information of vehicles that may be involved in a crime. Therefore, by using information that allows for narrowing down the vehicles as search criteria, investigators can obtain vehicle information of vehicles that may be involved in a crime.
[0098] One example of a search criterion is the vehicle number. The search unit 204 searches for vehicle information associated with the vehicle number. Investigators may, as a result of their investigation, know the vehicle number of a vehicle that may be involved in a crime. They may then need more information about that vehicle. In this case, the search unit 204 searches for vehicle information associated with the vehicle number, which is the search criterion. As a result, investigators can obtain vehicle information about vehicles that may be involved in a crime.
[0099] Other examples of search conditions include time and location information. The search unit 204 searches for vehicle information associated with the location and time indicated by the location information. Investigators may know, as a result of their investigation, when and where a vehicle potentially related to a crime was located. In other words, investigators may know the location of a vehicle potentially related to a crime and the time it was at that location. Furthermore, they may want more information about the vehicle potentially related to a crime. In this case, the search unit 204 searches for vehicle information associated with the time and location indicated by the location information, which are the search conditions. As a result, investigators can obtain vehicle information about the vehicle potentially related to a crime.
[0100] In this embodiment, the vehicle search device 20 has a data acquisition unit 201 that acquires collected data related to vehicles. The storage unit 202 then formats the collected data into a table format containing records to which vehicle information is associated for each predetermined piece of information related to the vehicle, and stores it. As described above, the predetermined information related to the vehicle and the vehicle information are included in the collected data acquired by the data acquisition unit 201. The predetermined information related to the vehicle corresponds to key information corresponding to the query, which is a search condition, and the vehicle information corresponds to the value associated with the key. The storage unit 202 formats the collected data into a table format containing records to which vehicle information is associated for each predetermined piece of information related to the vehicle. Therefore, it becomes possible to search using various search conditions.
[0101] In criminal investigations, the investigative information that investigators obtain about vehicles varies depending on the outcome of the investigation. For example, the investigative information that investigators obtain about vehicles may differ depending on whether they are investigating an accident involving a vehicle or a counter-terrorism case. Therefore, investigators may want to use the obtained investigative information as search criteria to search for vehicle information. In other words, it is desirable to be able to search for vehicle information using various search criteria depending on the investigation situation. The storage unit 202 formats the collected data into a table format that includes records to which vehicle information is associated for each predetermined piece of information about the vehicle. For example, the storage unit 202 can format the table using the investigative information obtained by the investigator as predetermined information about the vehicle. As a result, it becomes possible to search for vehicle information using the investigative information obtained by the investigator as search criteria. In other words, it becomes possible to search for vehicle information using various search criteria depending on the investigation situation.
[0102] In this embodiment, the vehicle search device 20 has an acquisition unit 203 that acquires encrypted search conditions and unencrypted search conditions. The search unit 204 then searches for vehicle information by performing secure computation using the encrypted search conditions on tables corresponding to the unencrypted search conditions. Depending on the case under investigation, it may not be necessary to conceal all search conditions. For example, depending on the case under investigation, some investigation information may be made public. In such cases, the acquisition unit 203 may acquire encrypted search conditions and unencrypted search conditions. The search unit 204 uses the unencrypted search conditions to narrow down the tables to be searched. Then, the search unit 204 performs a search on the tables to be searched using the encrypted search information. In other words, the search unit 204 performs secure computation using the encrypted search information on the tables to be searched. By using unencrypted search conditions, the search unit 204 can narrow down the tables to which secure computation is performed. Therefore, the amount of processing required for secure computation can be reduced.
[0103] In this modified configuration, the investigative agency terminal 30 has a search condition encryption unit 302 that encrypts the search conditions. The transmission unit 303 then transmits the encrypted search conditions. The receiving unit 304 receives the vehicle information retrieved through secure computation using the search conditions in an encrypted format. The decryption unit 305 then decrypts the encrypted search results, and the display control unit 306 displays the decrypted search results. The configuration of the investigative agency terminal 30 makes it possible to prevent the leakage of information related to the investigation when vehicle information is used in criminal investigations.
[0104] The search condition encryption unit 302 encrypts the search conditions, and the transmission unit 303 transmits the encrypted search conditions, thereby preventing the leakage of information related to the investigation from the search conditions. Furthermore, the receiving unit 304 receives the search results in an encrypted format, thereby preventing the leakage of information related to the investigation from the search results. The decryption unit 305 then decrypts the encrypted search results, and the display control unit 306 displays the decrypted search results, allowing investigators, for example, to confirm the vehicle information in the search results. In other words, it becomes possible to utilize the vehicle information in criminal investigations.
[0105] In this embodiment, the investigative agency terminal 30 has a reception unit 301 that receives search conditions related to criminal investigations. At this time, the reception unit 301 accepts a designation that some of the search conditions should not be kept secret. As described above, depending on the case being investigated, it may not be necessary to keep all search conditions secret. In such cases, the reception unit 301 may accept a designation that some of the search conditions should not be kept secret. The search condition encryption unit 302 then encrypts the search conditions for which the designation to keep secret has been accepted. The transmission unit 303 transmits the encrypted search conditions and the unencrypted search conditions. As a result, the vehicle search device 20 performs a secure computation process using the encrypted search conditions on the tables corresponding to the unencrypted search conditions to retrieve vehicle information. In other words, by using unencrypted search conditions in the search performed by the vehicle search device 20, the tables for which secure computation is performed can be narrowed down. Therefore, the amount of processing required for secure computation can be reduced.
[0106] In this embodiment, the investigative agency terminal 30 displays the concealed search conditions along with the decoded search results in an identifiable format, as indicated by the display control unit 306. When the reception unit 301 receives a designation that some of the multiple search conditions should not be concealed, the search conditions include both concealed and unconcealed search conditions. Therefore, for example, an investigator may want to know which search conditions are concealed and which are not. To address this, when the display control unit 306 displays the search conditions along with the search results, the concealed search conditions are displayed in an identifiable format, allowing the investigator to identify the concealed search conditions.
[0107] [Modification 1] Next, the vehicle search system in Modification 1 of this embodiment will be described with reference to the drawings. To the extent that the description of this modification does not become unclear, explanations that overlap with the above description will be omitted. The collected data may be encrypted in the in-vehicle device 10. The collected data is encrypted, for example, by a homomorphic encryption scheme. In this modification, the collected data is encrypted by a single-key scheme.
[0108] In a single-key system, the in-vehicle device 10 holds the encryption key for encrypting the collected data, and the investigative agency terminal 30 holds the encryption key for encrypting the search conditions related to criminal investigations. Here, the encryption key for encrypting the collected data and the encryption key for encrypting the search conditions related to criminal investigations are the same. The investigative agency terminal 30 also stores the decryption key for decrypting the encrypted search results. The encryption keys held by the in-vehicle device 10 and the investigative agency terminal 30 correspond to public keys. The decryption key stored by the investigative agency terminal 30 corresponds to a private key.
[0109] Referring to Figure 9, a modified configuration of the vehicle search system including the vehicle search device 20 will be described. Figure 9 is a block diagram showing an example of the configuration of the vehicle search system in this disclosure. The system configuration example shown in Figure 9 differs from the system configuration example shown in Figure 2 in that the in-vehicle device 10 includes a data encryption unit 103.
[0110] First, let's describe the components of the in-vehicle device 10. The data acquisition unit 101 and the data transmission unit 102 have the same configuration as described using Figure 2.
[0111] The data encryption unit 103 is one embodiment of a data encryption means for encrypting vehicle-related data. The data encryption unit 103 encrypts the collected data collected by the data collection unit 101. In this modified example, the collected data is encrypted using a single-key scheme. That is, the data encryption unit 103 encrypts the collected data using a publicly available encryption key. The single-key scheme is as described above.
[0112] The data transmission unit 102 transmits the encrypted collected data. The collected data is encrypted by the data encryption unit 103 using a publicly available encryption key.
[0113] Next, the components of the vehicle search device 20 will be described. The components of the vehicle search device 20 are the same as those described using Figure 2.
[0114] The data acquisition unit 201 acquires encrypted collected data. In this modified example, the collected data is encrypted using a publicly available encryption key. In other words, the data acquisition unit 201 acquires collected data that has been encrypted using a publicly available encryption key.
[0115] The storage unit 202 formats the encrypted collected data into the table format described above. That is, the storage unit 202 formats the data into a table format that includes records to which vehicle information is associated for each predetermined piece of information about a vehicle. The storage unit 202 then stores the formatted table in an encrypted format. The encryption method is a single-key method.
[0116] The acquisition unit 203 acquires search conditions related to criminal investigations, which have been encrypted using a publicly available encryption key. The acquisition unit 203 also acquires encrypted search results from the transmission unit 303. The encryption method for the search conditions is a single-key scheme.
[0117] The search unit 204 retrieves vehicle information using secure computation processing based on search conditions. Both the search conditions and the collected data stored in the storage unit 202 are encrypted using a single-key scheme. The secure computation processing is an arithmetic operation using homomorphic encryption.
[0118] The output unit 205 outputs the search results, encrypted using a single-key scheme, to the investigative agency terminal 30.
[0119] The components of the investigative agency terminal 30 will now be described. The components of the investigative agency terminal 30 are the same as those described using Figure 2.
[0120] The search condition encryption unit 302 encrypts the search conditions using a publicly available encryption key. In other words, the search conditions are encrypted using a single-key scheme. The transmission unit 303 then transmits the search conditions related to criminal investigations, encrypted using the single-key scheme, to the vehicle search device 20. The receiving unit 304 receives the search results, which have been encrypted using the single-key scheme.
[0121] The decryption unit 305 decrypts the search results using a non-public decryption key that is paired with the encryption key. The search results are encrypted using a single-key scheme. Therefore, the decryption unit 305 decrypts the encrypted search results using a non-public decryption key that is paired with the encryption key.
[0122] Referring to Figure 10, an example of the operation of the vehicle search system will be described. Figure 10 is a sequence diagram showing an example of the operation of the vehicle search system in this disclosure. The operation of the in-vehicle device 10, the vehicle search device 20, and the investigative agency terminal 30, which are included in the vehicle search system, will be described.
[0123] Step S201 is the same as step S101 explained using Figure 8. The data encryption unit 103 encrypts the vehicle data (collected data) (step S202). At this time, the data encryption unit 103 encrypts the collected data using a single-key scheme. In other words, the data encryption unit 103 encrypts the collected data using a publicly available encryption key. Then, the data transmission unit 102 transmits the encrypted collected data (step S203). Steps S204 and S205 are the same as steps S103 and S104 explained in Figure 8, respectively. At this time, the collected data is encrypted using a single-key scheme.
[0124] Steps S206 to S212 are the same as steps S105 to S111 described in Figure 8. At this time, the search conditions and search results related to the criminal investigation are encrypted using a single-key scheme.
[0125] The decryption unit 305 decrypts the search results using a confidential decryption key that is paired with the encryption key (step S213). Then, the display control unit 306 displays the decrypted search results (step S214).
[0126] This concludes the operation of the vehicle search system.
[0127] In this modified example, the vehicle search device 20 has a data acquisition unit 201 that acquires encrypted collected data. The collected data is encrypted using, for example, a homomorphic encryption scheme. The collected data is data related to the vehicle. For the vehicle owner, it may be desirable to keep the collected data confidential. Therefore, the data acquisition unit 201 acquires encrypted collected data. This makes it possible to prevent the leakage of the collected data.
[0128] In this modified example, the collected data is encrypted using a single-key scheme. That is, the data acquisition unit 201 acquires the collected data encrypted with a publicly available encryption key. In the investigative agency terminal 30, the search condition encryption unit 302 encrypts the search conditions using a publicly available encryption key. In a single-key scheme, ciphertexts encrypted with the same encryption key can be computed. The collected data and search conditions are encrypted with a publicly available encryption key. Therefore, vehicle information can be searched in the search unit 204. Then, the decryption unit 305 decrypts the search results using a non-public decryption key that is paired with the encryption key, thereby obtaining the search results in plain text. In other words, investigators can obtain vehicle information as a search result.
[0129] [Modification 2] Next, a vehicle search system in Modification 2 of this embodiment will be described with reference to the drawings. To the extent that the description of this modification does not become unclear, explanations that overlap with the above description will be omitted. The collected data may be encrypted in the in-vehicle device 10. In this modification, the collected data is encrypted using a multi-key scheme. Then, the search results are partially decrypted in the in-vehicle device 10.
[0130] In this modified example, the multi-key system stores an encryption key for encrypting collected data and a decryption key for decrypting encrypted search results on the in-vehicle device 10 side. The investigative agency terminal 30 side stores an encryption key for encrypting search conditions related to criminal investigations and a decryption key for decrypting encrypted search conditions. In this modified example, the encryption key and decryption key correspond to private keys. The encryption key and decryption key are different for the in-vehicle device 10 and the investigative agency terminal 30. The vehicle search device 20 side does not store encryption or decryption keys, but holds public parameters. The public parameters correspond to calculation keys generated using the private key at the time of system-wide setup. The calculation keys are stored in the in-vehicle device 10. The calculation keys are used in secure calculations of encrypted data.
[0131] In this modified version, in order to decrypt the encrypted search conditions, each in-vehicle device 10 and the investigative agency terminal 30 partially decrypt the search conditions. Then, the investigative agency terminal 30 combines the multiple partially decrypted search results to obtain the plaintext search results.
[0132] Referring to Figure 11, a modified configuration of the vehicle search system including the vehicle search device 20 will be described. Figure 11 is a block diagram showing an example of the configuration of the vehicle search system in this disclosure. The system configuration example shown in Figure 11 differs from the system configuration example shown in Figure 9 in that the in-vehicle device 10 further comprises a search result receiving unit 104, a second decryption unit 105, and a search result transmission unit 106. In other words, the system configuration example shown in Figure 11 differs from the system configuration example shown in Figure 2 in that the in-vehicle device 10 comprises a data encryption unit 103, a search result receiving unit 104, a second decryption unit 105, and a search result transmission unit 106.
[0133] First, let's describe the components of the in-vehicle device 10. The data acquisition unit 101 and the data transmission unit 102 have the same configuration as described using Figure 2.
[0134] The data encryption unit 103 encrypts the collected data collected by the data collection unit 101. In this modified example, the collected data is encrypted using a multi-key scheme. That is, the data encryption unit 103 encrypts the collected data using a non-public encryption key. The multi-key scheme is as described above.
[0135] The data transmission unit 102 transmits the collected data, which has been encrypted. The collected data is encrypted by the data encryption unit 103 using a non-public encryption key.
[0136] The search result receiving unit 104 is one embodiment of a search result receiving means for receiving encrypted search results. The search result receiving unit 104 receives encrypted search results from the output unit 205 of the vehicle search device 20. At this time, the search results are encrypted using a multi-key scheme.
[0137] The second decryption unit 105 is one embodiment of a second decryption means that partially decrypts the search results using a non-public decryption key paired with the encryption key. The decryption key is different for each in-vehicle device 10. Therefore, the search results are partially decrypted in the second decryption unit 105 of each in-vehicle device 10. Since the partially decrypted search results are not plaintext, investigation information and the like are not leaked to the in-vehicle device 10.
[0138] The search result transmission unit 106 is one embodiment of the search result transmission means that transmits partially decoded search results to the investigative agency terminal 30. The search result transmission unit 106 in each in-vehicle device 10 transmits the search results that have been partially decoded by the second decoding unit 105. In other words, the investigative agency terminal 30 receives the search results that have been partially decoded by multiple in-vehicle devices 10.
[0139] Next, the components of the vehicle search device 20 will be described. The components of the vehicle search device 20 are the same as those described using Figure 2.
[0140] The data acquisition unit 201 acquires encrypted collected data. In this modified example, the collected data is encrypted with a private encryption key. In other words, the data acquisition unit 201 acquires collected data that has been encrypted with a private encryption key.
[0141] The storage unit 202 formats the encrypted collected data into the table format described above. That is, the storage unit 202 formats the data into a table format that includes records to which vehicle information is associated for each predetermined piece of information about a vehicle. The storage unit 202 then stores the formatted table in an encrypted format. The encryption method is a multi-key method.
[0142] The acquisition unit 203 acquires search conditions related to criminal investigations, which have been encrypted using a non-public encryption key. The acquisition unit 203 also acquires encrypted search results from the transmission unit 303. The encryption method for the search conditions is a multi-key method.
[0143] The search unit 204 retrieves vehicle information using secure computation processing based on search conditions. Both the search conditions and the collected data stored in the storage unit 202 are encrypted using a multi-key scheme. The secure computation processing is an arithmetic process using homomorphic encryption.
[0144] The output unit 205 outputs the search results, encrypted using a multi-key scheme, to the in-vehicle device 10 and the investigative agency terminal 30. The output unit 205 can output encrypted search results to multiple in-vehicle devices 10.
[0145] The components of the investigative agency terminal 30 will now be described. The components of the investigative agency terminal 30 are the same as those described using Figure 2.
[0146] The search condition encryption unit 302 encrypts the search conditions using a non-public encryption key. In other words, the search conditions are encrypted using a multi-key system. The transmission unit 303 then transmits the search conditions related to criminal investigations, which have been encrypted using the multi-key system, to the vehicle search device 20.
[0147] The receiving unit 304 receives encrypted search results from the output unit 205 of the vehicle search device 20. The encrypted search results received from the vehicle search device 20 are partially decrypted by the decryption unit 305.
[0148] Furthermore, the receiving unit 304 receives partially decoded search results from the search result transmission unit 106 in the in-vehicle device 10. The receiving unit 304 may receive partially decoded search results from multiple search result transmission units 106 in the in-vehicle devices 10. The partially decoded search results received from the in-vehicle device 10 are combined with the partially decoded search results by the decoding unit 305 in the decoding unit 305.
[0149] The decryption unit 305 partially decrypts the search results using a non-public decryption key paired with the encryption key. The decryption unit 305 partially decrypts the search results received by the receiving unit 304 from the output unit 205. The search results are encrypted using a multi-key scheme. Therefore, the decryption unit 305 partially decrypts the encrypted search results using a non-public decryption key paired with the encryption key.
[0150] Furthermore, the decoding unit 305 decodes the search results by combining the partially decoded search results received by the receiving unit 304 from the search result transmission unit 106 with the partially decoded search results in the decoding unit 305. The decoding unit 305 may also combine the partially decoded search results received from the search result transmission units 106 of multiple in-vehicle devices 10 with the partially decoded search results in the decoding unit 305. By combining multiple partially decoded search results in the decoding unit 305, plaintext search results are obtained.
[0151] Referring to Figure 12, an example of the operation of the vehicle search system will be described. Figure 12 is a sequence diagram showing an example of the operation of the vehicle search system in this disclosure. The operation of the in-vehicle device 10, the vehicle search device 20, and the investigative agency terminal 30, which are included in the vehicle search system, will be described.
[0152] Step S301 is the same as step S101 explained using Figure 8. The data encryption unit 103 encrypts the vehicle data (collected data) (step S302). At this time, the data encryption unit 103 encrypts the collected data using a multi-key scheme. In other words, the data encryption unit 103 encrypts the collected data using a non-public encryption key. Then, the data transmission unit 102 transmits the encrypted collected data (step S303). Steps S304 and S305 are the same as steps S103 and S104 explained in Figure 8, respectively. At this time, the collected data is encrypted using a multi-key scheme.
[0153] Steps S306 to S310 are the same as steps S105 to S109 described in Figure 8. At this time, the search conditions and search results related to criminal investigations are encrypted using a multi-key scheme. The output unit 205 outputs the encrypted search results to the in-vehicle device 10 and the investigative agency terminal 30.
[0154] In the in-vehicle device 10, the search result receiving unit 104 receives the encrypted search results (step S312). The second decryption unit 105 partially decrypts the search results using a non-public decryption key paired with the encryption key (step S313). Then, the search result transmission unit 106 transmits the partially decrypted search results to the investigative agency terminal 30 (step S314).
[0155] In the investigative agency terminal 30, the receiving unit 304 receives the encrypted search results (step S315). The decryption unit 305 partially decrypts the search results using a non-public decryption key paired with the encryption key (step S316). The receiving unit 304 receives the partially decrypted search results from the in-vehicle device 10 (step S317). The decryption unit 305 decrypts the search results by combining the partially decrypted search results in the decryption unit 305 with the partially decrypted search results in the second decryption unit 105 (step S318). Then, the display control unit 306 displays the decrypted search results (step S319).
[0156] This concludes the operation of the vehicle search system.
[0157] Here, the order of steps S315 and S316 and step S317 does not matter. Steps S315 and S316 may be performed after step S317. Also, steps S315 and S316 and step S317 may be processed in parallel. In other words, in step S318, before the decoding unit 305 combines the partially decoded search results, it is sufficient that the partially decoded search results from the investigative agency terminal 30 and the partially decoded search results from the in-vehicle device 10 are available.
[0158] In this modified example, the vehicle search device 20 has a data acquisition unit 201 that acquires encrypted collected data. The collected data is data related to the vehicle. For the vehicle owner, it may be desirable to keep the collected data confidential. Therefore, the data acquisition unit 201 acquires encrypted collected data. This makes it possible to prevent the leakage of the collected data.
[0159] In this modified example, the collected data is encrypted using a multi-key scheme. That is, in the in-vehicle device 10, the data encryption unit 103 encrypts the collected data with a non-public encryption key. At this time, the encryption key and decryption key are different for each in-vehicle device 10 installed in the vehicle. Therefore, it is not possible to decrypt collected data encrypted by a different in-vehicle device 10. In other words, it is possible to prevent collected data collected by one in-vehicle device 10 from being leaked to other in-vehicle devices 10, etc.
[0160] Furthermore, in the investigative agency terminal 30, the search condition encryption unit 302 encrypts the search conditions using a confidential encryption key. At this time, the encryption key and decryption key are different on the investigative agency terminal 30 side and on the in-vehicle device 10 side. Therefore, it is possible to prevent the leakage of information related to the investigation from the search conditions encrypted by the search condition encryption unit 302.
[0161] In the multi-key scheme, calculations can be performed even between ciphertexts encrypted with different encryption keys, allowing the search unit 204 to retrieve vehicle information.
[0162] Then, the second decryption unit 105 of the in-vehicle device 10 and the decryption unit 305 of the investigative agency terminal 30 partially decrypt the search results using a non-public decryption key paired with the encryption key. Furthermore, the decryption unit 305 decrypts the search results by combining the search results partially decrypted by the in-vehicle device 10 with the search results partially decrypted by the decryption unit 305. As a result, plaintext search results are obtained. In other words, investigators can obtain vehicle information as search results.
[0163] [Modification 3] Next, the vehicle search system in Modification 3 of this embodiment will be described with reference to the drawings. To the extent that the description of this modification does not become unclear, explanations that overlap with the above description will be omitted. The collected data may be encrypted in the in-vehicle device 10. In this modification, the collected data is encrypted using a multi-key scheme. In this modification, the vehicle search system includes a decryption server 40 that partially decrypts the search results. In Modification 2, each in-vehicle device 10 performed partial decryption of the search results, whereas in this modification, the decryption server 40 performs partial decryption of the search results all at once.
[0164] The decryption server 40 may be, for example, a device managed by a business operator providing connected car services. The decryption server 40 is a server device built in the cloud or a data center. The server device may be implemented by an information processing device such as a personal computer.
[0165] In this modified example, the multiple-key system stores the encryption key for encrypting the collected data on the in-vehicle device 10 side. The encryption key is different for each in-vehicle device 10. The decryption server 40 side stores the decryption key for decrypting the encrypted search results. The decryption key corresponds to the encryption key. In other words, the decryption server 40 side stores multiple decryption keys in a single location, corresponding to each of the encryption keys of the multiple in-vehicle devices 10. In addition, the investigative agency terminal 30 side stores the encryption key for encrypting the search conditions related to criminal investigations and the decryption key for decrypting the encrypted search conditions. In this modified example, the encryption key and decryption key correspond to the secret key. The encryption key and decryption key are different for each in-vehicle device 10 and the investigative agency terminal 30. The vehicle search device 20 side does not store the encryption key or decryption key, but holds public parameters. The public parameters correspond to the calculation key generated using the secret key at the time of system-wide setup. The calculation key is stored in the in-vehicle device 10. The calculation key is used in the secure calculation of the encrypted data.
[0166] In this modified version, the decryption server 40 and the investigative agency terminal 30 partially decrypt the encrypted search conditions in order to decrypt them. The decryption server 40 stores the decryption keys for multiple in-vehicle devices 10 together. Therefore, the partial decryption that was previously performed on each in-vehicle device 10 can be performed collectively on the decryption server 40. Then, the investigative agency terminal 30 combines the multiple partially decrypted search results to obtain the plaintext search results.
[0167] Referring to Figure 13, a modified configuration of the vehicle search system including the vehicle search device 20 will be described. Figure 13 is a block diagram showing an example of the configuration of the vehicle search system in this disclosure. The system configuration example shown in Figure 13 differs from the system configuration example shown in Figure 2 in that the vehicle search system includes a decryption server 40 and the in-vehicle device 10 includes a data encryption unit 103. Another difference from the system configuration example shown in Figure 11 is that the vehicle search system includes a decryption server 40, and the in-vehicle device 10 does not include a search result receiving unit 104, a second decryption unit 105, and a search result transmission unit 106.
[0168] First, let's describe the components of the in-vehicle device 10. The data acquisition unit 101 and the data transmission unit 102 have the same configuration as described using Figure 2.
[0169] The data encryption unit 103 encrypts the collected data collected by the data collection unit 101. In this modified example, the collected data is encrypted using a multi-key scheme. That is, the data encryption unit 103 encrypts the collected data using a non-public encryption key. The multi-key scheme is as described above.
[0170] The data transmission unit 102 transmits the collected data, which has been encrypted. The collected data is encrypted by the data encryption unit 103 using a non-public encryption key.
[0171] Next, the components of the vehicle search device 20 will be described. The components of the vehicle search device 20 are the same as those described using Figure 2.
[0172] The data acquisition unit 201 acquires encrypted collected data. In this modified example, the collected data is encrypted with a private encryption key. That is, the data acquisition unit 201 acquires the collected data encrypted with a private encryption key, and the storage unit 202 formats the encrypted collected data into the table format described above. That is, the storage unit 202 formats the data into a table format that includes records to which vehicle information is associated for each predetermined piece of information about the vehicle. The storage unit 202 then stores the formatted table in an encrypted format. The encryption method is a multi-key method.
[0173] The acquisition unit 203 acquires search conditions related to criminal investigations, which have been encrypted using a non-public encryption key. The acquisition unit 203 then receives the encrypted search results from the transmission unit 303. The encryption method for the search conditions is a multi-key method.
[0174] The search unit 204 retrieves vehicle information using secure computation processing based on search conditions. Both the search conditions and the collected data stored in the storage unit 202 are encrypted using a multi-key scheme. The secure computation processing is an arithmetic process using homomorphic encryption.
[0175] The output unit 205 outputs the search results encrypted using a multi-key scheme to the decryption server 40 and the investigative agency terminal 30.
[0176] Next, the decryption server 40 will be described.
[0177] The search result receiving unit 401 is one embodiment of a search result receiving means that acquires search results encrypted with a non-public encryption key. The search result receiving unit 401 receives encrypted search results from the output unit 205 of the vehicle search device 20. At this time, the search results are encrypted using a multi-key scheme.
[0178] The second decryption unit 402 is one embodiment of a second decryption means that partially decrypts the search results using a non-public decryption key paired with the encryption key. The decryption key is different for each in-vehicle device 10. Therefore, the decryption server 40 manages the decryption keys of each in-vehicle device 10 collectively. Then, the second decryption unit 402 partially decrypts the search results collectively. In other words, if the partial decryption requires the decryption keys of multiple in-vehicle devices 10, the decryption server 40 uses the decryption keys of the multiple in-vehicle devices 10 to partially decrypt the search results. Since the partially decrypted search results are not plaintext, investigation information and other sensitive data are not leaked to the decryption server 40.
[0179] The search result transmission unit 403 is one embodiment of a search result transmission means for transmitting partially decoded search results. The search result transmission unit 403 transmits the partially decoded search results to the investigative agency terminal 30.
[0180] Finally, the components of the investigative agency terminal 30 will be described. The components of the investigative agency terminal 30 are the same as those described using Figure 2.
[0181] The search condition encryption unit 302 encrypts the search conditions using a non-public encryption key. In other words, the search conditions are encrypted using a multi-key system. The transmission unit 303 then transmits the search conditions related to criminal investigations, which have been encrypted using the multi-key system, to the vehicle search device 20.
[0182] The receiving unit 304 receives encrypted search results from the output unit 205 of the vehicle search device 20. The encrypted search results received from the vehicle search device 20 are partially decrypted in the decryption unit 305. The receiving unit 304 also receives partially decrypted search results from the search result transmission unit 403 of the decryption server 40. The partially decrypted search results received from the decryption server 40 are combined with the partially decrypted search results in the decryption unit 305.
[0183] The decryption unit 305 partially decrypts the search results using a non-public decryption key paired with the encryption key. The decryption unit 305 partially decrypts the search results received by the receiving unit 304 from the output unit 205. The search results are encrypted using a multi-key scheme. Therefore, the decryption unit 305 partially decrypts the encrypted search results using a non-public decryption key paired with the encryption key.
[0184] Furthermore, the decoding unit 305 decodes the search results by combining the partially decoded search results received by the receiving unit 304 from the search result transmission unit 403 with the partially decoded search results in the decoding unit 305. The plaintext search results are obtained by combining multiple partially decoded search results in the decoding unit 305.
[0185] Referring to Figure 14, an example of the operation of the vehicle search system will be described. Figure 10 is a sequence diagram showing an example of the operation of the vehicle search system in this disclosure. The operation of the in-vehicle device 10, the vehicle search device 20, and the investigative agency terminal 30, which are included in the vehicle search system, will be described.
[0186] Step S401 is the same as step S101 explained using Figure 8. The data encryption unit 103 encrypts the vehicle data (collected data) (step S402). At this time, the data encryption unit 103 encrypts the collected data using a multi-key scheme. In other words, the data encryption unit 103 encrypts the collected data using a non-public encryption key. Then, the data transmission unit 102 transmits the encrypted collected data (step S403). Steps S404 and S405 are the same as steps S103 and S104 explained in Figure 8, respectively. At this time, the collected data is encrypted using a multi-key scheme.
[0187] Steps S406 to S410 are the same as steps S105 to S109 described in Figure 8. At this time, the search conditions and search results related to criminal investigations are encrypted using a multi-key scheme. The output unit 205 outputs the encrypted search results to the decryption server 40 and the investigative agency terminal 30 (step S411).
[0188] In the decryption server 40, the search result receiving unit 401 receives the encrypted search results (step S412). The second decryption unit 402 partially decrypts the search results using a non-public decryption key paired with the encryption key (step S413). Then, the search result transmission unit 403 transmits the partially decrypted search results to the investigative agency terminal 30 (step S414).
[0189] In the investigative agency terminal 30, the receiving unit 304 receives the encrypted search results (step S415). The decryption unit 305 partially decrypts the search results using a non-public decryption key paired with the encryption key (step S416). The receiving unit 304 receives the partially decrypted search results from the decryption server 40 (step S417). The decryption unit 305 decrypts the search results by combining the partially decrypted search results in the decryption unit 305 with the partially decrypted search results in the second decryption unit 402 (step S418). Then, the display control unit 306 displays the decrypted search results (step S419).
[0190] This concludes the operation of the vehicle search system.
[0191] Here, the order of steps S415 and S416 and step S417 does not matter. Steps S415 and S416 may be performed after step S417. Also, steps S415 and S416 and step S417 may be processed in parallel. In other words, in step S418, before the decoding unit 305 combines the partially decoded search results, it is sufficient that the partially decoded search results from the investigative agency terminal 30 and the partially decoded search results from the in-vehicle device 10 are available.
[0192] In this modified example, the vehicle search device 20 has a data acquisition unit 201 that acquires encrypted collected data. The collected data is data related to the vehicle. For the vehicle owner, it may be desirable to keep the collected data confidential. Therefore, the data acquisition unit 201 acquires encrypted collected data. This makes it possible to prevent the leakage of the collected data.
[0193] In this modified example, the collected data is encrypted using a multi-key scheme. That is, in the in-vehicle device 10, the data encryption unit 103 encrypts the collected data with a non-public encryption key. At this time, the encryption key and decryption key are different for each in-vehicle device 10 installed in the vehicle. Therefore, it is not possible to decrypt collected data encrypted by a different in-vehicle device 10. In other words, it is possible to prevent collected data collected by one in-vehicle device 10 from being leaked to other in-vehicle devices 10, etc.
[0194] Furthermore, in the investigative agency terminal 30, the search condition encryption unit 302 encrypts the search conditions using a confidential encryption key. At this time, the encryption key and decryption key are different on the investigative agency terminal 30 side and on the in-vehicle device 10 side. Therefore, it is possible to prevent the leakage of information related to the investigation from the search conditions encrypted by the search condition encryption unit 302.
[0195] In the multi-key scheme, calculations can be performed even between ciphertexts encrypted with different encryption keys, allowing the search unit 204 to retrieve vehicle information.
[0196] Then, the decryption unit 305 of the investigative agency terminal 30 partially decrypts the search results using a confidential decryption key paired with the encryption key. Similarly, the second decryption unit 402 of the decryption server 40 partially decrypts the search results using a confidential decryption key paired with the encryption key. The decryption server 40 stores multiple decryption keys, each corresponding to the encryption key of the multiple in-vehicle devices 10, in a single location. Therefore, in the modified example 3, the partial decryption that was performed on each in-vehicle device 10 can now be performed collectively by the decryption server 40. Depending on the condition of the in-vehicle device 10 and the vehicle on which it is installed, partial decryption may not be possible on the in-vehicle device 10. However, by having the decryption server 40 perform partial decryption collectively, it is possible to prevent situations where partial decryption is not possible.
[0197] Furthermore, the decoding unit 305 decodes the search results by combining the partially decoded search results from the in-vehicle device 10 with the partially decoded search results from the decoding unit 305. As a result, plaintext search results are obtained. In other words, investigators can obtain vehicle information as search results.
[0198] [Second Embodiment] Next, the vehicle search device 50 in the second embodiment will be described with reference to the drawings. To the extent that the description of this embodiment does not become unclear, explanations that overlap with the above description will be omitted.
[0199] Referring to Figure 15, the configuration of the vehicle search device 50 will be described. Figure 15 is a block diagram showing an example of the configuration of the vehicle search device in this disclosure. The vehicle search device 50 comprises an acquisition unit 501, a search unit 502, and an output unit 503.
[0200] The acquisition unit 501 is one embodiment of an acquisition means for acquiring encrypted search conditions related to criminal investigations. The acquisition unit 501 acquires the search conditions related to criminal investigations from the investigative agency terminal 30. The search conditions related to criminal investigations are information that can narrow down the vehicles. Examples of search conditions related to criminal investigations are as described above.
[0201] The search criteria related to criminal investigations are encrypted using a predetermined encryption method. One example of an encryption method is homomorphic encryption. The search criteria related to criminal investigations are encrypted using homomorphic encryption. In other words, the acquisition unit 501 acquires the search criteria related to criminal investigations that have been encrypted using homomorphic encryption. The search criteria related to criminal investigations may also be encrypted using a single-key homomorphic encryption method. Alternatively, the search criteria related to criminal investigations may also be encrypted using a multi-key homomorphic encryption method.
[0202] The search unit 502 is one embodiment of a search means that searches for vehicle information by performing a secure computation process using search conditions. The search unit 502 searches for vehicle information using the search conditions acquired by the acquisition unit 501. The search unit 502 searches for vehicle information using a secure computation process. The secure computation process using search conditions is, for example, an arithmetic process using a homomorphic encryption scheme. The search unit 502 may also search for vehicle information by performing a secure computation process using search conditions encrypted with a publicly available encryption key. Alternatively, the search unit 502 may also search for vehicle information by performing a secure computation process using search conditions encrypted with a non-public encryption key.
[0203] The output unit 503 is one form of output means that outputs encrypted search results. The output unit 503 outputs the encrypted search results to the investigative agency terminal 30. The encryption method of the search results differs depending on the encryption method of the search conditions. If the search conditions are encrypted using a single-key scheme, the search results are also encrypted using a single-key scheme. In other words, when the search unit 502 searches for vehicle information using search conditions encrypted with a publicly available encryption key, the output unit 503 outputs the search results that are decrypted using a non-public decryption key that is paired with the encryption key.
[0204] Referring to Figure 16, the operation of the vehicle search device 50, which includes an acquisition unit 501, a search unit 502, and an output unit 503, will be described. Figure 16 is a flowchart showing the operation of the vehicle search device in this disclosure.
[0205] In step S501, the acquisition unit 501 acquires encrypted search conditions related to criminal investigations. In step S502, the search unit 502 searches for vehicle information using secure computation processing based on the search conditions. In step S503, the output unit 503 outputs encrypted search results.
[0206] This concludes the operation of the vehicle search device 50.
[0207] In this embodiment, the vehicle search device 50 has an acquisition unit 501 that acquires encrypted search conditions related to criminal investigations. The search unit 502 then searches for vehicle information using secure computation processing based on the search conditions, and the output unit 503 outputs the encrypted search results. Vehicle information may be stored, for example, in a database. When the stored vehicle information is used in criminal investigations, it is necessary to keep the information related to the investigation confidential. The configuration of the vehicle search device 50 makes it possible to prevent the leakage of information related to the investigation when vehicle information is used in criminal investigations.
[0208] [Hardware Configuration Example] The figure shows an example of the hardware configuration of the vehicle search device 60 in this disclosure. The vehicle search device 60 is implemented by a computer. The vehicle search device 20 is an example of when the vehicle search device 20 or the vehicle search device 50 is implemented by a computer.
[0209] The vehicle search device 60 includes a processor 601, a ROM (Read Only Memory) 602, a RAM (Random Access Memory) 603, a storage device 604 such as a hard disk for storing programs, an input / output interface 605 for data input and output, and a communication interface 606 for network connection. Each component is connected via a bus 607.
[0210] The processor 601 controls the entire computer by running the operating system. Examples of the processor 601 include a CPU (Central Processing Unit), a DSP (Digital Signal Processor), and a GPU (Graphics Processing Unit). The processor 601 loads programs stored in, for example, a ROM 602 or a storage device 604. Then, the processor 601 executes each process coded in the program. The processor 601 may execute processes or instructions in the illustrated flowchart based on the program.
[0211] ROM 602 stores application programs, programs related to each embodiment, etc. RAM 603 is used as the work area of processor 601.
[0212] The storage device 604 may be, for example, a semiconductor memory such as flash memory, or an HDD (Hard Disk Driver). The storage device 604 stores, for example, an OS (Operating System) program, application programs, programs according to each embodiment, and so on.
[0213] The input / output interface 605 is connected to peripheral devices (not shown). The connection method may be a wired network or a wireless network.
[0214] The communication interface 606 is connected to a communication network (not shown), such as a LAN (Local Network) or WAN (Wide Area Network), via a wireless or wired network. The communication network may consist of multiple communication networks. This allows the computer to connect to external devices via the communication network. The vehicle search device 60 may have components other than those shown in Figure 7. For example, the vehicle search device 60 may include a drive device. For example, the processor 601 may be mounted on a drive device or the like and read programs and data stored on a non-temporary tangible recording medium into the RAM 603.
[0215] Although the present disclosure has been described above with reference to embodiments, the present disclosure is not limited to the embodiments described above. Various modifications to the configuration and details of the present disclosure are possible, as can be understood by those skilled in the art within the scope of the present disclosure. Furthermore, the configurations in each embodiment can be combined with one another, as long as they do not depart from the scope of the present disclosure.
[0216] Some or all of the above embodiments may also be described as follows, but are not limited to the following:
[0217] (Note 1) A vehicle search device comprising: an acquisition means for acquiring encrypted search conditions related to criminal investigations; a search means for searching for vehicle information by secure computation processing using the search conditions; and an output means for outputting encrypted search results.
[0218] (Note 2) The vehicle search device described in Note 1, wherein the search conditions are information that can narrow down the vehicles, and the vehicle information is the vehicle information of the vehicles narrowed down by the search conditions.
[0219] (Note 3) The vehicle search device according to Note 2, wherein the search conditions include a vehicle number, and the search means searches for the vehicle information associated with the vehicle number.
[0220] (Note 4) The vehicle search device according to Note 2 or 3, wherein the search conditions include time and location information, and the search means searches for the vehicle information associated with the location indicated by the location information and the time.
[0221] (Note 5) The vehicle search device described in any one of Notes 1 to 4, wherein the secure computation process is an arithmetic process using a homomorphic encryption scheme.
[0222] (Note 6) The vehicle search device according to any one of Notes 1 to 5, wherein the acquisition means acquires the search conditions encrypted with a publicly available encryption key, and the output means outputs the search results decrypted with a private decryption key paired with the encryption key.
[0223] (Note 7) The vehicle search device according to any one of Notes 1 to 5, wherein the acquisition means acquires the search conditions encrypted with a non-public encryption key, and the output means outputs the search results decrypted with a non-public decryption key paired with the encryption key.
[0224] (Appendix 8) A vehicle search device according to any one of the appendices 1 to 7, further comprising a storage means for storing a table containing records associated with the vehicle information for each predetermined piece of information relating to a vehicle, wherein the search means searches for the vehicle information by performing the secure computation process using the search conditions on the table.
[0225] (Note 9) The vehicle search device according to Note 8, further comprising data acquisition means for acquiring collected data relating to vehicles, wherein the storage means formats the collected data into the table format and stores it.
[0226] (Note 10) The vehicle search device according to Note 8 or 9, wherein the acquisition means acquires encrypted search conditions and unencrypted search conditions, and the search means searches for the vehicle information by performing the secure computation process using the encrypted search conditions on the table corresponding to the unencrypted search conditions.
[0227] (Note 11) The vehicle search device according to Note 9, wherein the data acquisition means acquires the encrypted collected data, and the storage means formats the encrypted collected data into the table format and stores it in the encrypted format.
[0228] (Note 12) The vehicle search device described in Note 11, wherein the collected data is encrypted using a homomorphic encryption scheme.
[0229] (Note 13) An investigative agency terminal comprising: a receiving means for receiving search conditions related to criminal investigations; a search condition encryption means for encrypting the search conditions; a transmitting means for transmitting the encrypted search conditions; a receiving means for receiving vehicle information retrieved by secure computation processing using the search conditions in an encrypted format as search results; a decryption means for decrypting the encrypted search results; and a display control means for displaying the decrypted search results.
[0230] (Note 14) The receiving means is the investigative agency terminal described in Note 13, which accepts a designation that the search conditions will not be kept confidential for some of the multiple search conditions.
[0231] (Note 15) The investigative agency terminal described in Note 14, wherein the search condition encryption means encrypts the search conditions for which confidentiality has been designated, and the transmission means transmits the encrypted search conditions and the unencrypted search conditions.
[0232] (Note 16) The display control means is an investigative agency terminal as described in Note 14 or 15, which displays the concealed search conditions together with the decoded search results in an identifiable format.
[0233] (Note 17) The investigative agency terminal according to any one of Notes 13 to 16, wherein the search condition encryption means encrypts the search conditions using a publicly available encryption key, and the decryption means decrypts the search results using a private decryption key paired with the encryption key.
[0234] (Note 18) The investigative agency terminal according to any one of Notes 13 to 16, wherein the search condition encryption means encrypts the search conditions with a non-public encryption key, and the decryption means partially decrypts the search results with a non-public decryption key paired with the encryption key, and decrypts the search results by combining the partially decrypted search results with the decrypted search results in an in-vehicle device.
[0235] (Note 19) The investigative agency terminal according to any one of Notes 13 to 16, wherein the search condition encryption means encrypts the search conditions with a non-public encryption key, and the decryption means partially decrypts the search results with a non-public decryption key paired with the encryption key, and decrypts the search results by combining them with the partially decrypted search results at the decryption server.
[0236] (Note 20) A vehicle search device comprising: an acquisition means for acquiring encrypted search conditions related to criminal investigations; a search means for searching for vehicle information by secure computation processing using the search conditions; and an output means for outputting encrypted search results; and an investigative agency terminal comprising: an acceptance means for receiving the search conditions; a search condition encryption means for encrypting the search conditions; a transmission means for transmitting the encrypted search conditions; a receiving means for receiving vehicle information retrieved by secure computation processing using the search conditions in an encrypted format as search results; a decryption means for decrypting the encrypted search results; and a display control means for displaying the decrypted search results.
[0237] (Note 21) The vehicle search device further comprises: data acquisition means for acquiring collected data relating to a vehicle encrypted with a publicly available encryption key; storage means for organizing the encrypted collected data into a table containing records to which the vehicle information is associated for each predetermined piece of information relating to a vehicle, and storing it in an encrypted format, wherein the search condition encryption means encrypts the search conditions with the encryption key, and the decryption means decrypts the search results with a non-public decryption key paired with the encryption key, as described in Note 20.
[0238] (Note 22) The vehicle search device further comprises: data acquisition means for acquiring collected data relating to a vehicle encrypted with a non-public encryption key; storage means for arranging the encrypted collected data into a table containing records to which the vehicle information is associated for each predetermined piece of information relating to a vehicle, and storing it in an encrypted format, wherein the search condition encryption means encrypts the search conditions with the encryption key; and the decryption means partially decrypts the search results with a non-public decryption key paired with the encryption key, and combines the partially decrypted search results with the results in an in-vehicle device, as described in Note 20.
[0239] (Note 23) The vehicle search system according to Note 22 further includes an in-vehicle device comprising: data collection means for collecting the collected data; data encryption means for encrypting the collected data with the encryption key; data transmission means for outputting the encrypted collected data; and a second decryption means for partially decrypting the search results with a non-public decryption key paired with the encryption key, wherein the vehicle search device further comprises: data acquisition means for acquiring the encrypted collected data; and storage means for formatting the encrypted collected data into a table to which the vehicle information is associated with the search conditions, and storing it in an encrypted format.
[0240] (Note 24) The vehicle search system according to Note 20, further comprising: a search result acquisition means for acquiring the search results encrypted with a non-public encryption key; a second decryption means for partially decrypting the search results with a non-public decryption key paired with the encryption key; and a search result output means for outputting the partially decrypted search results, wherein the search condition encryption means encrypts the search conditions with the encryption key, and the decryption means partially decrypts the search results with a non-public decryption key paired with the encryption key and combines them with the search results partially decrypted by the second decryption means.
[0241] (Note 25) A vehicle search device comprising: an acquisition means for acquiring search conditions related to criminal investigations encrypted with a non-public encryption key; a search means for searching for vehicle information by secure computation processing using the search conditions; and an output means for outputting encrypted search results; and a decryption server comprising: a search result acquisition means for acquiring the encrypted search results; a second decryption means for partially decrypting the search results using a non-public decryption key paired with the encryption key; and a search result output means for outputting the partially decrypted search results.
[0242] (Note 26) A vehicle search method comprising: obtaining encrypted search conditions related to criminal investigations; searching for vehicle information by performing secure computation using the said search conditions; and outputting encrypted search results.
[0243] (Note 27) A recording medium that stores a program that causes a computer to execute a process that obtains encrypted search conditions related to criminal investigations, searches for vehicle information using secure computation processing with the said search conditions, and outputs encrypted search results.
[0244] (Note 28) A program that causes a computer to perform the following operations: obtain encrypted search conditions related to criminal investigations, search for vehicle information using secure computation processing with the said search conditions, and output encrypted search results.
[0245] (Note 29) An investigation support method comprising: receiving search conditions related to a criminal investigation; encrypting the search conditions; transmitting the encrypted search conditions; receiving vehicle information retrieved by secure computation using the search conditions in an encrypted format; decrypting the encrypted search results; and displaying the decrypted search results.
[0246] (Note 30) A recording medium that stores a program that causes a computer to perform the following processes: receiving search conditions related to criminal investigation, encrypting the search conditions, transmitting the encrypted search conditions, receiving vehicle information retrieved by secure computation using the search conditions in encrypted form, decrypting the encrypted search results, and displaying the decrypted search results.
[0247] (Note 31) A program that causes a computer to perform the following processes: receiving search conditions related to a criminal investigation, encrypting the search conditions, transmitting the encrypted search conditions, receiving vehicle information retrieved by secure computation using the search conditions in encrypted form, decrypting the encrypted search results, and displaying the decrypted search results.
[0248] Some or all of the configurations described in Appendix 2-12, which are dependent on Appendix 1 above, may also be dependent on Appendix 26-28 in the same manner as in Appendix 2-12. Some or all of the configurations described in Appendix 14-19, which are dependent on Appendix 13 above, may also be dependent on Appendix 29-31 in the same manner as in Appendix 14-19. Not limited to Appendix 1, 26-28 and Appendix 13, 29-31, some or all of the configurations described as appendices may also be dependent on various hardware, software, various recording devices or systems for recording software, without departing from the embodiments described above.
[0249] 10 In-vehicle device 101 Data acquisition unit 102 Data transmission unit 103 Data encryption unit 104 Search result receiving unit 105 Second decryption unit 106 Search result transmission unit 20 Vehicle search device 201 Data acquisition unit 202 Storage unit 203 Acquisition unit 204 Search unit 205 Output unit 30 Investigative agency terminal 301 Reception unit 302 Search condition encryption unit 303 Transmission unit 304 Receiving unit 305 Decryption unit 306 Display control unit 40 Decryption server 401 Search result receiving unit 402 Second decryption unit 403 Search result transmission unit 50 Vehicle search device 501 Acquisition unit 502 Search unit 503 Output unit 60 Vehicle search device 601 Processor 602 ROM 603 RAM 604 Storage device 605 Input / output interface 606 Communication interface 607 bus
Claims
1. A vehicle search device comprising: an acquisition means for acquiring encrypted search conditions related to criminal investigations; a search means for searching for vehicle information by secure computation processing using the search conditions; and an output means for outputting encrypted search results.
2. The vehicle search device according to claim 1, wherein the search conditions are information that can narrow down the number of vehicles, and the vehicle information is vehicle information of the vehicles narrowed down by the search conditions.
3. The vehicle search device according to claim 2, wherein the search conditions include a vehicle number, and the search means searches for the vehicle information associated with the vehicle number.
4. The vehicle search device according to claim 2 or 3, wherein the search conditions include time and location information, and the search means searches for vehicle information associated with the location indicated by the location information and the time.
5. The vehicle search device according to any one of claims 1 to 4, wherein the secure computation process is an arithmetic process using a homomorphic encryption scheme.
6. The vehicle search device according to any one of claims 1 to 5, wherein the acquisition means acquires the search conditions encrypted with a publicly available encryption key, and the output means outputs the search results decrypted with a private decryption key paired with the encryption key.
7. The vehicle search device according to any one of claims 1 to 5, wherein the acquisition means acquires the search conditions encrypted with a non-public encryption key, and the output means outputs the search results decrypted with a non-public decryption key paired with the encryption key.
8. A vehicle search device according to any one of claims 1 to 7, further comprising a storage means for storing a table containing records associated with the vehicle information for each predetermined piece of information relating to a vehicle, wherein the search means retrieves the vehicle information by performing the secure computation process using the search conditions on the table.
9. The vehicle search device according to claim 8, further comprising data acquisition means for acquiring collected data relating to a vehicle, wherein the storage means formats the collected data into the format of the table and stores it.
10. The vehicle search device according to claim 8 or 9, wherein the acquisition means acquires encrypted search conditions and unencrypted search conditions, and the search means searches for the vehicle information by performing the secure computation process using the encrypted search conditions on the table corresponding to the unencrypted search conditions.
11. The vehicle search device according to claim 9, wherein the data acquisition means acquires the collected data in encrypted form, and the storage means formats the collected data in the form of a table and stores it in encrypted form.
12. The vehicle search device according to claim 11, wherein the collected data is encrypted using a homomorphic encryption scheme.
13. An investigative agency terminal comprising: a receiving means for receiving search conditions related to criminal investigations; a search condition encryption means for encrypting the search conditions; a transmitting means for transmitting the encrypted search conditions; a receiving means for receiving vehicle information retrieved by secure computation processing using the search conditions in an encrypted format as search results; a decryption means for decrypting the encrypted search results; and a display control means for displaying the decrypted search results.
14. The investigative agency terminal according to claim 13, wherein the receiving means accepts a designation that the search conditions will not be kept confidential for a portion of the plurality of search conditions.
15. The investigative agency terminal according to claim 14, wherein the search condition encryption means encrypts the search condition for which a designation to be kept confidential has been received, and the transmission means transmits the encrypted search condition and the unencrypted search condition.
16. The investigative agency terminal according to claim 14 or 15, wherein the display control means displays the concealed search conditions together with the decoded search results in an identifiable format.
17. The investigative agency terminal according to any one of claims 13 to 16, wherein the search condition encryption means encrypts the search conditions with a publicly available encryption key, and the decryption means decrypts the search results with a private decryption key paired with the encryption key.
18. The investigative agency terminal according to any one of claims 13 to 16, wherein the search condition encryption means encrypts the search conditions with a non-public encryption key, and the decryption means partially decrypts the search results with a non-public decryption key paired with the encryption key, and decrypts the search results by combining the partially decrypted search results with the decrypted search results in an in-vehicle device.
19. The investigative agency terminal according to any one of claims 13 to 16, wherein the search condition encryption means encrypts the search conditions with a non-public encryption key, and the decryption means partially decrypts the search results with a non-public decryption key paired with the encryption key, and decrypts the search results by combining the partially decrypted search results with the decryption server.
20. A vehicle search device comprising: an acquisition means for acquiring encrypted search conditions related to criminal investigations; a search means for searching for vehicle information by secure computation processing using the search conditions; and an output means for outputting encrypted search results; and an investigative agency terminal comprising: a reception means for receiving the search conditions; a search condition encryption means for encrypting the search conditions; a transmission means for transmitting the encrypted search conditions; a reception means for receiving vehicle information retrieved by secure computation processing using the search conditions in an encrypted format as search results; a decryption means for decrypting the encrypted search results; and a display control means for displaying the decrypted search results.
21. The vehicle search device further comprises: data acquisition means for acquiring collected data relating to a vehicle encrypted with a publicly available encryption key; storage means for organizing the encrypted collected data into a table containing records associated with the vehicle information for each predetermined piece of information relating to a vehicle, and storing it in an encrypted format, wherein the search condition encryption means encrypts the search conditions with the encryption key, and the decryption means decrypts the search results with a non-public decryption key paired with the encryption key, the vehicle search system according to claim 20.
22. The vehicle search device further comprises: data acquisition means for acquiring collected data relating to a vehicle encrypted with a non-public encryption key; storage means for formatting the encrypted collected data into a table containing records associated with the vehicle information for each predetermined piece of information relating to a vehicle, and storing it in an encrypted format, wherein the search condition encryption means encrypts the search conditions with the encryption key; and the decryption means partially decrypts the search results with a non-public decryption key paired with the encryption key, and combines the partially decrypted search results with the results in an in-vehicle device, as described in claim 20.
23. The vehicle search system according to claim 22, further comprising: data collection means for collecting the collected data; data encryption means for encrypting the collected data with the encryption key; data transmission means for outputting the encrypted collected data; and a second decryption means for partially decrypting the search results with a non-public decryption key paired with the encryption key, wherein the vehicle search device further comprises: data acquisition means for acquiring the encrypted collected data; and storage means for formatting the encrypted collected data into a table to which the vehicle information is associated with the search conditions and storing it in an encrypted format.
24. A vehicle search system according to claim 20, further comprising: a search result acquisition means for acquiring the search results encrypted with a non-public encryption key; a second decryption means for partially decrypting the search results with a non-public decryption key paired with the encryption key; and a search result output means for outputting the partially decrypted search results, wherein the search condition encryption means encrypts the search conditions with the encryption key, and the decryption means partially decrypts the search results with a non-public decryption key paired with the encryption key and combines them with the search results partially decrypted by the second decryption means.
25. A vehicle search device comprising: an acquisition means for acquiring search conditions related to criminal investigations encrypted with a non-public encryption key; a search means for searching for vehicle information by secure computation processing using the search conditions; and an output means for outputting encrypted search results; and a decryption server comprising: a search result acquisition means for acquiring the encrypted search results; a second decryption means for partially decrypting the search results using a non-public decryption key paired with the encryption key; and a search result output means for outputting the partially decrypted search results.
26. A vehicle search method comprising obtaining encrypted search criteria related to criminal investigation, searching for vehicle information using secure computation processing with the said search criteria, and outputting encrypted search results.
27. A recording medium that stores a program that causes a computer to execute a process that obtains encrypted search conditions related to criminal investigations, searches for vehicle information using secure computation processing with the said search conditions, and outputs encrypted search results.
28. A method for supporting criminal investigations, comprising: receiving search conditions related to a criminal investigation; encrypting the search conditions; transmitting the encrypted search conditions; receiving vehicle information retrieved by secure computation using the search conditions in an encrypted format as search results; decrypting the encrypted search results; and displaying the decrypted search results.
29. A recording medium that stores a program that causes a computer to perform the following processes: receiving search conditions related to a criminal investigation, encrypting the search conditions, transmitting the encrypted search conditions, receiving vehicle information retrieved by secure computation using the search conditions in an encrypted format as search results, decrypting the encrypted search results, and displaying the decrypted search results.
Citation Information
Patent Citations
Computer system and data management method
JP2018097034A
Search support system and search support method
JP2020137069A
Secret retrieval system, management device, secret retrieval method, and secret retrieval program
WO2017061024A1