Calculation device, calculation method, calculation system, and recording medium

The computing device uses homomorphic encryption with multiple keys to securely calculate and output environmental impact, addressing data confidentiality issues in product lifecycle assessments by employing partial decryption and re-encryption, ensuring strong confidentiality and reduced processing load.

WO2026069512A1PCT designated stage Publication Date: 2026-04-02NEC CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing methods for calculating the environmental impact of a product's lifecycle face challenges in securely sharing and processing confidential information across organizations in a supply chain, with concerns about data leakage when using public keys for encryption.

Method used

A computing device and method utilizing homomorphic encryption with multiple encryption keys to securely calculate and output the environmental impact in an encrypted format, employing partial decryption and re-encryption techniques to maintain confidentiality.

Benefits of technology

The solution ensures that data from each organization involved in the product lifecycle remains highly confidential by reducing the need for decryption keys at individual organizations, thereby enhancing security and reducing processing load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024034365_02042026_PF_FP_ABST
    Figure JP2024034365_02042026_PF_FP_ABST
Patent Text Reader

Abstract

This calculation device is provided with: an acquisition means for acquiring pieces of provision information pertaining to the amount of environmental load of a business operator pertaining to the lifecycle of a product, at least two of the pieces of provision information being encrypted with different encryption keys using a homomorphic encryption method; a calculation means for executing a secret calculation of the amount of environmental load on the basis of the provision information; and an output means for outputting, in an encrypted format, the calculation result of the secret calculation indicating the amount of environmental load of the lifecycle of the product.
Need to check novelty before this filing date? Find Prior Art

Description

Computing Device, Computing Method, Computing System, and Recording Medium

[0001] The present disclosure relates to a computing device, a computing method, a computing system, and a recording medium.

[0002] For a certain product, it may be necessary to calculate the amount of environmental load over the entire life cycle of the product. For example, the amount of environmental load may be the amount of carbon dioxide emissions (carbon footprint, CFP: Carbon Foot Print).

[0003] When calculating the amount of environmental load, it may be necessary to link data among a plurality of organizations on the supply chain of the product. On the other hand, information such as the amount of activity required for calculating the environmental load may correspond to business confidential information including manufacturing information and procurement information, so it may not be easy to obtain consent for information provision.

[0004] Patent Document 1 describes an information management method in which a trader constituting a supply chain uses a public key to perform encryption and secret calculation of the carbon release amount. In the information management method described in Patent Document 1, among the traders constituting the supply chain, the second trader receives the carbon release amount encrypted by the first trader using the public key, secretly calculates the encrypted carbon release amount, decrypts the calculation result using the secret key corresponding to the public key, encrypts the decrypted calculation result using another public key, and transmits it to the third trader.

[0005] International Publication No. 2024 / 106068

[0006] However, there is a concern that information may be leaked when a secret key for decrypting data encrypted by a certain trader using a public key is held by another trader.

[0007] An example of the object of the present disclosure is to provide a technique for more strongly concealing data of each organization related to the life cycle in calculating the amount of environmental load in the life cycle of a certain product.

[0008] A computing device in one aspect of the present disclosure includes: an acquisition means for acquiring provided information concerning the amount of environmental impact on a business operator related to the product lifecycle, which is encrypted with at least two different encryption keys using homomorphic encryption; a computing means for performing a secure calculation of the amount of environmental impact based on the provided information; and an output means for outputting the calculation result of the secure calculation showing the amount of environmental impact over the product lifecycle in an encrypted format.

[0009] A calculation method in one aspect of this disclosure obtains provided information concerning the amount of environmental impact on a business operator related to the product lifecycle, which is encrypted with at least two different encryption keys using homomorphic encryption schemes; performs a secure calculation of the amount of environmental impact based on the provided information; and outputs the calculation result of the secure calculation showing the amount of environmental impact over the product lifecycle in an encrypted format.

[0010] A program in one aspect of this disclosure causes a computer to perform the following processes: obtain provided information concerning the amount of environmental impact on a business operator throughout the product lifecycle, which is encrypted with at least two different encryption keys using homomorphic encryption; perform a secure calculation of the amount of environmental impact based on the provided information; and output the result of the secure calculation showing the amount of environmental impact throughout the product lifecycle in an encrypted format.

[0011] Each program may be stored on a non-temporary storage medium that is readable by the computer.

[0012] One example of the benefits of this disclosure is that, when calculating the amount of environmental impact throughout the lifecycle of a product, data from each organization involved in the lifecycle can be more securely kept confidential.

[0013] This is a conceptual diagram of a system including a computing device. This is a block diagram showing an example of the functional configuration of a computing device. This is a block diagram showing an example of the functional configuration of a computing system including a computing device. This is a sequence diagram showing an example of the operation of a computing system including a computing device. This is a block diagram showing another example of the functional configuration of a computing system including a computing device. This is a block diagram showing another example of the operation of a computing system including a computing device. This is a sequence diagram showing another example of the operation of a computing system including a computing device. This is a block diagram showing another example of the functional configuration of a computing system including a computing device. This is a block diagram showing another example of the functional configuration of a computing system including a computing device. This is a diagram showing the hardware configuration for realizing the computing device in this disclosure using a computer and its peripheral devices.

[0014] Embodiments of this disclosure will be described in detail with reference to the drawings.

[0015] [Embodiment] Figure 1 is a conceptual diagram of a system including the computing device of the present disclosure.

[0016] The computing device is a device that performs secure computation of provided information regarding the amount of encrypted environmental impact. The amount of environmental impact is a quantity that quantitatively indicates the environmental impact of a product throughout its lifecycle. The amount of environmental impact is, for example, the carbon footprint, water footprint, or the amount of specified raw materials, but is not limited to these examples. Specified raw materials are, for example, cobalt, lead, nickel, etc. The amount of environmental impact throughout the product's lifecycle may be required to be disclosed from an environmental protection perspective.

[0017] In Figure 1, the computing device is connected to the encryption device and the terminal device via a network (NW) so that they can communicate with each other.

[0018] The encryption device is used to encrypt information provided by businesses regarding the amount of environmental impact they have on the product's lifecycle. The encryption method and other details will be described later.

[0019] Here, the product lifecycle can be divided into five stages, as shown in Figure 1: raw material procurement, production, distribution, use / maintenance, and disposal / recycling, but it is not limited to these examples. Businesses involved in the product lifecycle are those involved in at least one of the stages of the product lifecycle, and it is also possible for one business to be involved in multiple stages of the product lifecycle. Furthermore, it is also possible for multiple businesses to be involved in a single stage of the product lifecycle.

[0020] As shown in Figure 1, the encryption device may encrypt information provided regarding the amount of environmental impact at each stage of the product lifecycle, or it may encrypt information provided regarding the amount of environmental impact at multiple stages of the product lifecycle. Furthermore, the encryption device may encrypt information provided by one or more businesses involved in the product lifecycle.

[0021] Information provided regarding the amount of environmental impact on businesses throughout the product lifecycle is used to calculate the amount of environmental impact during the product's lifecycle. In other words, the computing device calculates the amount of environmental impact during the product's lifecycle based on multiple pieces of provided information.

[0022] The information provided concerns materials used and activities carried out throughout the lifecycle of a business's products. Therefore, this information may include information that the business wishes to keep confidential. Consequently, it is expected that the information will be encrypted using an encryption device. Furthermore, in this case, to prevent the leakage of confidential information, it may be required that each piece of information be decrypted using a different decryption key. Therefore, it may be required that each piece of information be encrypted using a different encryption key. However, it is not necessarily required that all of the information provided be encrypted.

[0023] Furthermore, the information provided will vary depending on the amount of environmental impact. For example, if the amount of environmental impact is the carbon footprint, the information provided is expected to include carbon dioxide emissions and the amount of materials and activities used to calculate those emissions. The information provided may also include the types of materials and activities. The information provided is not limited to these examples; it is sufficient if the amount of environmental impact can be calculated using the provided information.

[0024] The terminal device is the terminal device of the information user. The terminal device is one that allows the information user to check the amount of environmental impact throughout the product's lifecycle. The terminal device may be, for example, a PC (Personal Computer), but is not limited to this example.

[0025] An information user is a person who uses information that shows the amount of environmental impact during a product's lifecycle, calculated based on the provided information. For example, an information user may be a business that ships a product, but is not limited to this example. Information users and businesses involved in the product's lifecycle may be pre-associated and stored in a memory unit (not shown). Furthermore, an information user may also be one of the businesses involved in the product's lifecycle.

[0026] Next, the configuration of the computing device 100 in the embodiment will be described.

[0027] Figure 2 is a block diagram showing the configuration of the computing device 100. Referring to Figure 2, the computing device 100 comprises an acquisition unit 101, a calculation unit 102, and an output unit 103.

[0028] Next, the configuration of the computing device 100 in the first embodiment will be described in detail.

[0029] The acquisition unit 101 is an example of an acquisition means for acquiring information concerning the amount of environmental impact on businesses related to the product lifecycle, which is encrypted using at least two different encryption keys based on homomorphic encryption. In other words, the acquisition unit 101 acquires information concerning the amount of environmental impact on businesses related to the product lifecycle. The information provided consists of multiple pieces of information, and at least two of these pieces of information are encrypted using at least two different encryption keys based on homomorphic encryption. Because at least two of the pieces of information are encrypted with different encryption keys, the encrypted information cannot be decrypted using the same decryption key, thus providing information encrypted with at least two different encryption keys to a high degree of confidentiality.

[0030] Homomorphic encryption is an encryption method that allows data operations to be performed while the data remains encrypted. Because homomorphic encryption allows data processing to be carried out while the data is encrypted, in addition to data transmission and storage, it is attracting attention from the perspective of protecting privacy and preventing data leaks. Note that other encryption methods may be used as long as data operations can be performed while the data remains encrypted.

[0031] The acquisition unit 101 acquires encrypted provided information from the encryption device. Here, the encryption device may be included in the terminal equipment used by the business operator involved in the product lifecycle, or it may be an independent device that is communicatively connected to the terminal equipment used by the business operator involved in the product lifecycle. Furthermore, when acquiring unencrypted provided information, the acquisition unit 101 may acquire unencrypted provided information from the terminal equipment used by the business operator involved in the product lifecycle.

[0032] The calculation unit 102 is an example of a calculation means that performs a confidential calculation of the amount of environmental load based on the provided information. In this disclosure, an example of handling data encrypted using a homomorphic encryption scheme is shown. Using a homomorphic encryption scheme, encrypted data can be processed while remaining encrypted. In a homomorphic encryption scheme, any function can be calculated by combining addition and multiplication.

[0033] Homomorphic encryption includes various types such as additive homomorphisms, multiplicative homomorphisms, somewhat homomorphisms, and fully homomorphic encryption. Additive homomorphisms are encryption methods that allow addition operations to be performed on the ciphertext. Examples of additive homomorphisms include the Goldwasser-Micali cipher, the Paillier cipher, and the Okamoto-Uchiyama cipher. Multiplicative homomorphisms are encryption methods that allow multiplication operations to be performed on the ciphertext. Examples of multiplicative homomorphisms include the ElGamal cipher and the RSA (Rivest-Shamir-Adleman) cipher. Somewhat homomorphisms are encryption methods that allow addition and multiplication operations to be performed on the ciphertext. Somewhat homomorphisms have limitations on the number of multiplication operations that can be performed. Examples of somewhat homomorphisms include the BGN (Boneh-Goh-Nissim) cipher and some lattice ciphers. A fully homomorphic encryption scheme is one in which addition and multiplication operations can be performed on the ciphertext without altering its original form. Gentry's lattice-based encryption method is an example of a fully homomorphic encryption scheme.

[0034] The plaintext M[k] and the ciphertext C[k] are related as shown in Equation 1 below (where k is a natural number).

[0035] (Equation 1) C[k] = Enc(M[k]) ... (1) Using additive homomorphism, somewhat homomorphism, or full homomorphism, the addition of plaintext M[1] and plaintext M[2] can be performed using ciphertext C[1] and ciphertext C[2], as shown in Equation 2 below.

[0036] (Math 2) C a = Enc(M[1] + M[2]) ... (2) Using multiplicative homomorphism, somewhat homomorphism, or full homomorphism, the multiplication of plaintext M[1] and plaintext M[2] can be performed using ciphertext C[1] and ciphertext C[2], as shown in equation 3 below.

[0037] (Math 3) C m = Enc(M[1] × M[2]) ... (3) Note that equations 1 to 3 above are a schematic representation of homomorphic encryption operations and do not represent homomorphic encryption in detail. For homomorphic encryption operations, known methods of operation can be selected.

[0038] In this disclosure, as described above, the provided information is encrypted using at least two different encryption keys employing homomorphic encryption. This method of using multiple encryption keys is called multi-key homomorphic encryption (multiple-key scheme). For example, the method described in this disclosure can be applied to the method described in Non-Patent Document 1 (H. Chen et al. “Efficient Multi-Key Homomorphic Encryption with Packed Ciphertexts with Application to Oblivious Neural Network Inference”, Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, 2019). In a multi-key system, the encryption key used to encrypt data and the decryption key used to decrypt encrypted data are stored separately for each piece of information provided, each business operator, each encryption device, etc. In this disclosure, the encryption key and decryption key correspond to the private key. It is assumed that the encryption key and decryption key will differ for each piece of information provided, each business operator, each encryption device, etc. The computing device 100 and the information user's terminal device do not store the encryption key or decryption key, but hold public parameters. The public parameters correspond to the calculation key generated using the private key at the time of system-wide setup. The calculation key is stored by the computing device 100. The calculation key is used in secure calculation of encrypted data.

[0039] The calculation unit 102 may perform secure computation based on the information provided for the entire product lifecycle, or it may perform secure computation based on the information provided for each stage of the product lifecycle as described above.

[0040] Furthermore, the amount of environmental impact includes the carbon footprint, water footprint, and the amount of specific raw materials used throughout the product's lifecycle. The calculation unit 102 may perform secure computation using calculation formulas and algorithms corresponding to the amount of environmental impact.

[0041] The output unit 103 is an example of output means that outputs the calculation result of the secret calculation indicating the amount of environmental load in the product life cycle in an encrypted format. Since the calculation result of the secret calculation is in an encrypted format, the output unit 103 outputs the calculation result in the encrypted format. The calculation result is information indicating the amount of environmental load in the product life cycle, and it becomes information that can be confirmed by the information user by decrypting it.

[0042] Therefore, it is necessary to perform a predetermined process on the calculation result in the encrypted format so that the information user can confirm the amount of environmental load that is the calculation result. The output unit 103 outputs the calculation result in the encrypted format to an output destination that executes the predetermined process.

[0043] The predetermined process is, for example, partial decryption or re-encryption, etc., but is not limited to these examples. Note that partial decryption and re-encryption will be described later.

[0044] Also, the output unit 103 may output an instruction to execute the predetermined process to an output destination that executes the predetermined process. Further, the output unit 103 may output an instruction to output the result of executing the predetermined process to the terminal device of the information user to an output destination that executes the predetermined process. These instructions may be performed by another device that controls the calculation system.

[0045] Also, the output unit 103 may output the calculation result in the encrypted format to an output destination corresponding to the information user associated with the business operator. The output destination is an output destination that executes the predetermined process, and the output destination differs according to the content of the predetermined process. The content of the predetermined process may be set uniformly in advance, or may be set according to the information user.

[0046] Also, the output unit 103 may output part or all of the calculation result in the encrypted format according to the content of the predetermined process and the output destination.

[0047] Next, the content of the predetermined process will be described. As described above, the predetermined process is, for example, partial decryption or re-encryption. When using the multiple-key method, since the information user does not have the decryption key for decrypting the encrypted provider information, in order to decrypt the calculation result in encrypted form, a predetermined process such as partial decryption or re-encryption is required.

[0048] First, partial decryption will be described. Partial decryption is a process of decrypting a part of the calculation result corresponding to each of a plurality of encryption keys using the decryption key corresponding to each of the plurality of encryption keys among the calculation results of the secret calculation based on the data encrypted by the plurality of encryption keys. In the present disclosure, partial decryption is executed by the encryption device.

[0049] In the secret calculation of the amount of environmental load, when using the multiple-key format and the process of partial decryption, the decryption key that can decrypt the encrypted provider information is stored only in each of the encryption devices. Therefore, compared with the case where the calculation device executes calculation using the provider information decrypted by the decryption key or the case where the terminal device of the information user decrypts the calculation result of the secret calculation using the decryption key, in the secret calculation of the amount of environmental load, by performing the multiple-key format and the process of partial decryption, the provider information can be more securely concealed.

[0050] FIG. 3 is a block diagram showing an example of the functional configuration of the calculation system 1 when performing partial decryption. The calculation system 1 includes a calculation device 100, encryption devices 200-1 to 200-n, and a terminal device 300A.

[0051] The encryption device 200-1 is an encryption device that encrypts the provider information regarding the amount of the environmental load of the provider. The encryption device 200-1 includes an acquisition unit 201, an encryption unit 202, a decryption unit 203, and an output unit 204. Here, although the encryption keys and decryption keys stored in the encryption devices 200-1 to 200-n are different, the functional configurations may be the same. Here, n is an arbitrary integer of 2 or more.

[0052] The acquisition unit 201 is an example of an acquisition means for acquiring data. The acquisition unit 201 acquires information from, for example, terminal devices or databases of businesses involved in the product lifecycle. The acquisition unit 201 also acquires calculation results in encrypted format from the computing device 100.

[0053] The encryption unit 202 is an example of an encryption means that encrypts data using an encryption key. For example, the encryption unit 202 encrypts the provided information using an encryption key stored in the encryption device 200-1.

[0054] The decryption unit 203 is an example of a decryption means that decrypts data using a decryption key. For example, the decryption unit 203 partially decrypts the portion of the encrypted calculation result that corresponds to the encryption key stored in the encryption device 200-1.

[0055] The output unit 204 is an example of an output means for outputting data. For example, the output unit 204 outputs the partially decoded calculation result to the information user's terminal device 300A. In this case, the output unit 204 may also output the partially decoded calculation result to the terminal device 300A via another device, such as a device that controls the calculation system.

[0056] The calculation result partially decrypted by the decryption unit 203 may be re-encrypted using an encryption key that can be decrypted by the information user's terminal device 300A. In this case, the encryption unit 202 encrypts the partially decrypted calculation result. The encryption method is not particularly limited, and for example, an End-to-End (E2E) encryption method may be used. The output unit 204 then outputs the partially decrypted result in the encrypted format to the terminal device 300A. Furthermore, the encryption of the partially decrypted calculation result may be performed in response to an instruction to encrypt the partially decrypted calculation result so that it can be decrypted by an information user associated with the business operator. For example, this instruction may be output by the output unit 103 of the computing device 100, or by another device that controls the computing system 1.

[0057] Terminal device 300A is a terminal device used by information users associated with a business operator. Information users use terminal device 300A to check the amount of environmental load, which is the calculation result. Terminal device 300A comprises an acquisition unit 301, a merging unit 302, and an output unit 303.

[0058] The acquisition unit 301 is an example of an acquisition means for acquiring data. The acquisition unit 301 acquires, for example, partially decrypted calculation results from each of the encryption devices 200-1 to 200-n.

[0059] The merge unit 302 is an example of a merging means for merging partially decrypted calculation results. Generally, each of the partially decrypted calculation results is not data that can be viewed by the information user. Therefore, the merge unit 302 converts the calculation results into plaintext, which is an unencrypted state, by merging the partially decrypted calculation results. Note that known techniques can be used for the merging process performed by the merge unit 302.

[0060] Furthermore, for example, partially decoded calculation results may contain noise. In this case, the merging unit 302 performs noise removal processing in addition to merging the partially decoded calculation results.

[0061] The output unit 303 is an example of an output means for outputting data. For example, the output unit 303 outputs the calculation result in plain text to a display device provided inside or outside the terminal device 300A. Alternatively, for example, the output unit 30 may output the calculation result in plain text for storage in a database provided inside or outside the terminal device 300A.

[0062] The operation of the computing system 1 configured as described above will be explained with reference to the sequence diagram in Figure 4.

[0063] First, the acquisition unit 201 of the encryption devices 200-1 to 200-n acquires the provided information (step S101).

[0064] Next, the encryption units 202 of the encryption devices 200-1 to 200-n encrypt the provided information acquired in step S101 (step S102).

[0065] Next, the output units 204 of the encryption devices 200-1 to 200-n output the encrypted information provided in step S102 to the computing device 100 (step S103).

[0066] Next, the acquisition unit 101 of the computing device 100 acquires the encrypted provided information output in step S103 (step S104).

[0067] Furthermore, each of the processes in steps S101 to S104 may be performed for each encryption device, and may be performed simultaneously or at different times.

[0068] Next, the calculation unit 102 of the computing device 100 performs secure calculation based on the encrypted information provided in step S104 (step S105).

[0069] Next, the output unit 103 of the computing device 100 outputs the calculation results of step S105 in encrypted form to the encryption devices 200-1 to 200-n, respectively (step S106). In step S106, the output unit 103 may further output an instruction to the encryption device used by the business operator to partially decrypt the encrypted calculation results using the business operator's encryption key. In step S106, the output unit 103 may further output an instruction to the encryption device used by the business operator to output the partially decrypted calculation results to the terminal device of the information user associated with the business operator. In step S106, the output unit 103 may further output an instruction to the encryption device used by the business operator to encrypt the partially decrypted calculation results so that the information user associated with the business operator can decrypt them. In step S106, if the provided information includes unencrypted information, the output unit 103 may further output the unencrypted information to the terminal device 300A.

[0070] Next, the acquisition unit 201 of encryption device 200-n acquires the encrypted calculation result output in step S106 from encryption device 200-1 (step S107).

[0071] Next, the decryption unit 203 of encryption device 200-n partially decrypts the encrypted calculation result obtained in step S107 (step S108).

[0072] Next, the output unit 204 of encryption device 200-n outputs the calculation result partially decrypted in step S108 to the terminal device 300A (step S109).

[0073] Next, the acquisition unit 301 of the terminal device 300A acquires the partially decoded calculation result output in step S109 (step S110).

[0074] Furthermore, each of the processes in steps S106 to S110 may be performed for each encryption device, and may be performed simultaneously or at different times.

[0075] Next, the merge unit 302 of the terminal device 300A merges the partially decoded calculation results obtained in step S110 (step S111).

[0076] Then, the output unit 303 of the terminal device 300A outputs the calculation result showing the amount of environmental load, which was merged in step S111 (step S112).

[0077] With this, the calculation system 1 completes its series of operations.

[0078] Next, we will explain re-encryption. Re-encryption is the process of re-encrypting data that has been encrypted using multiple encryption keys so that it can be decrypted using a decryption key different from the decryption key corresponding to the multiple encryption keys. In this disclosure, re-encryption is performed by a proxy server. The proxy server that performs re-encryption may be a single proxy server or multiple proxy servers. In the following description, when multiple proxy servers perform re-encryption, it is referred to as distributed re-encryption.

[0079] In this disclosure, the method described in Non-Patent Document 2 (YASUDA, Satoshi, et al. Multi-key homomorphic proxy re-encryption. In: International Conference on Information Security. Springer, Cham, 2018. pp. 328-346.) can be applied to the method of re-encrypting multi-key data using a single proxy server. In a multi-key scheme, the encryption keys for encrypting each of the multiple pieces of provided information are stored in the encryption devices that encrypt each of the multiple pieces of provided information. The re-encryption key is generated from the multiple private keys of the information provider and the public key of the information user. The re-encryption key is generated, for example, using a key switching key generation technique. The re-encryption key is stored by the proxy server 400. Furthermore, similar to the case of partial decryption, the computing device 100 and the information user's terminal device do not store the information provider's encryption key or decryption key, but instead hold public parameters. The public parameters correspond to the calculation key generated using the private key at the time of system-wide setup. The calculation key is stored by the computing device 100. The calculation key is used in secure computation of the encrypted data. In addition, in this disclosure, a method of re-encrypting multi-key data using multiple proxy servers may be used. In this case, the re-encryption key becomes a share of the re-encryption key through a secret sharing process, and each of the multiple proxy servers stores a different share of the re-encryption key. Here, the secret sharing method can be, for example, n-out-of-n additive secret sharing or t-out-of-n replication secret sharing, but is not particularly limited. In the re-encryption method using multiple proxy servers, even if a portion of the re-encryption key share is leaked, this alone does not mean that the information user's decryption key will be leaked, thus providing high security. Multiple proxy servers output the shares of the re-encrypted ciphertext, each using the re-encryption key share, to the computing device 100 and the information user's terminal device. The information user's terminal device can decrypt the re-encrypted ciphertext shares and the calculation results obtained by secure computation using the re-encrypted ciphertext shares using the secret key stored in its own device.

[0080] The data to be re-encrypted is primarily assumed to be the result of a secure computation, but it may also be multiple pieces of information that have been encrypted using multiple encryption keys.

[0081] In secure computation of environmental impact, when using a multi-key format and re-encryption of the computation results, the decryption key capable of decrypting the encrypted provided information is stored only in each encryption device. Furthermore, the decryption key capable of decrypting the re-encrypted computation results cannot decrypt the encrypted provided information. Therefore, compared to cases where a computing device performs calculations using the provided information decrypted with a decryption key, or where an information user's terminal device decrypts the computation results using a decryption key, using a multi-key format and re-encryption of the computation results in secure computation of environmental impact provides stronger confidentiality of the provided information. In addition, by using a multi-key format and re-encryption of the computation results in secure computation of environmental impact, there is no need to have each encryption device perform partial decryption, thus eliminating the burden of partial decryption on each encryption device and the need to request partial decryption from each encryption device.

[0082] Furthermore, when using a multi-key format and re-encryption of provided information in secure computation of environmental impact, the decryption key capable of decrypting the encrypted provided information is stored only in each encryption device. Moreover, the decryption key capable of decrypting the re-encrypted provided information is stored only in the information user's terminal device. Therefore, compared to when a computing device performs calculations using provided information decrypted with a decryption key, using a multi-key format and re-encryption of confidential provided information in secure computation of environmental impact provides stronger security for the provided information. In addition, when using a multi-key format and re-encryption of provided information, the computation result of the secure computation contains less information related to encryption because the number of encryption keys is reduced from multiple to one. Therefore, using a multi-key format and re-encryption of provided information reduces the processing load of the secure computation compared to when a multi-key format and re-encryption of the computation result of the secure computation are used.

[0083] Figure 5 is a block diagram showing an example of the functional configuration of the computing system 2 when re-encryption is performed using a single proxy server. The computing system 2 comprises a computing device 100, encryption devices 200-1 to 200-n, a terminal device 300B, and a proxy server 400.

[0084] The functional configurations of the computing device 100 and the encryption devices 200-1 to 200-n are the same as those described in Figures 2 and 3, and are therefore omitted. Note that in the computing system 2, the encryption devices 200-1 to 200-n do not necessarily need to include a decryption unit 203.

[0085] The proxy server 400 is a server that performs the re-encryption process. The proxy server 400 comprises an acquisition unit 401, a re-encryption unit 402, and an output unit 403.

[0086] The acquisition unit 401 is an example of an acquisition means for acquiring data. For example, the acquisition unit 401 acquires calculation results from the computing device 100 in a format encrypted using a multi-key scheme. Alternatively, for example, the acquisition unit 401 acquires provided information encrypted with multiple different encryption keys from encryption devices 200-1 to 200-n.

[0087] The re-encryption unit 402 is an example of a re-encryption means that re-encrypts data that can be decrypted with multiple different decryption keys so that it can be decrypted with a different decryption key. The re-encryption unit 402 re-encrypts the data using a re-encryption key that corresponds to multiple different decryption keys. The re-encryption key is stored by the proxy server 400. The re-encryption unit 402 re-encrypts, for example, calculation results in a format encrypted with a multi-key scheme. Alternatively, for example, the re-encryption unit 402 re-encrypts provided information encrypted with multiple different encryption keys. Here, the data that the re-encryption unit 402 re-encrypts is provided information or calculation results.

[0088] The output unit 403 is an example of an output means for outputting data. For example, the output unit 403 outputs the re-encrypted calculation result to the terminal device 300B. Alternatively, for example, the output unit 403 outputs the re-encrypted provided information to the computing device.

[0089] Terminal device 300B includes a decoding unit 304 in place of the merging unit 302 of terminal device 300A in Figure 3. The functional configurations of the acquisition unit 301 and output unit 303 are the same as those described in Figure 3 and are therefore omitted.

[0090] The decryption unit 304 is an example of a decryption means for decrypting data. For example, the decryption unit 304 decrypts the encrypted calculation result using a decryption key that can decrypt the data re-encrypted by the proxy server 400.

[0091] Figure 6 is a block diagram showing an example of the functional configuration of the computing system 3 when re-encryption is performed using multiple proxy servers.

[0092] The computing system 3 comprises a computing device 100, encryption devices 200-1 to 200-n, a terminal device 300B, and proxy servers 400-1 to 400-n, where n is any integer greater than or equal to 2.

[0093] The computer 100, encryption devices 200-1 to 200-n, and terminal device 300B are described in the same way as in Figures 2, 3, and 5, respectively, so their descriptions are omitted.

[0094] Proxy servers 400-1 to 400-n each include re-encryption units 402-1 to 402-n, respectively, instead of the functional configuration of the re-encryption unit 402 of proxy server 400 shown in Figure 5.

[0095] The re-encryption units 402-1 to 402-n are an example of a re-encryption means that re-encrypts data that can be decrypted by multiple different decryption keys so that it can be decrypted by another decryption key. The re-encryption units 402-1 to 402-n re-encrypt the data using shares (fragments) of re-encryption keys corresponding to multiple different decryption keys, which are stored by each of the proxy servers 400-1 to 400-n.

[0096] The operation of the computing system 2 configured as described above when re-encrypting the calculation result of a secure computation will be explained with reference to the sequence diagram in Figure 7. Note that the operation of the computing system 3 when re-encrypting the calculation result of a secure computation is the same as the operation of the computing system 2, and "proxy server 400" should be read as "proxy servers 400-1 to 400-n" and "re-encryption unit 402" should be read as "re-encryption unit 402-1 to 402-n".

[0097] First, the acquisition unit 201 of the encryption devices 200-1 to 200-n acquires the provided information (step S201).

[0098] Next, the encryption units 202 of the encryption devices 200-1 to 200-n encrypt the provided information acquired in step S201 (step S202).

[0099] Next, the output units 204 of the encryption devices 200-1 to 200-n output the encrypted information provided in step S202 to the computing device 100 (step S203).

[0100] Next, the acquisition unit 101 of the computing device 100 acquires the encrypted provided information output in step S203 (step S204).

[0101] Furthermore, each of the processes in steps S201 to S204 may be performed for each encryption device, and may be performed simultaneously or at different times.

[0102] Next, the calculation unit 102 of the computing device 100 performs secure calculation based on the encrypted information provided in step S204 (step S205).

[0103] Next, the output unit 103 of the computing device 100 outputs the calculation result from step S205 to the proxy server 400 in an encrypted format (step S206). In step S206, the output unit 103 may further output an instruction to the proxy server 400 to re-encrypt the calculation result in the encrypted format. Alternatively, in step S206, the output unit 103 may further output an instruction to the proxy server 400 to output the re-encrypted calculation result to the terminal device of the information user associated with the business operator.

[0104] Next, the acquisition unit 401 of the proxy server 400 acquires the encrypted calculation result output in step S206 (step S207).

[0105] Next, the re-encryption unit 402 of the proxy server 400 re-encrypts the calculation result in the encrypted format obtained in step S207 (step S208).

[0106] Next, the output unit 403 of the proxy server 400 outputs the calculation result in a format that has been re-encrypted in step S208 and is decryptable on the information user's terminal device 300B (step S209).

[0107] Next, the acquisition unit 301 of the terminal device 300B acquires the calculation result output in step S209 in an encrypted format that can be decrypted on the information user's terminal device 300B (step S210).

[0108] Next, the decryption unit 304 of the terminal device 300B decrypts the encrypted calculation result obtained in step S210 (step S211).

[0109] Then, the output unit 303 of the terminal device 300B outputs the calculation result indicating the amount of environmental load, which was decoded in step S211 (step S212).

[0110] With this, the calculation system 2 completes its series of operations.

[0111] Furthermore, the operation of the aforementioned computing system 2 when re-encrypting the provided information will be explained with reference to the sequence diagram in Figure 8. Note that the operation of computing system 3 when re-encrypting the provided information is the same as the operation of computing system 2, and "proxy server 400" should be read as "proxy servers 400-1 to 400-n" and "re-encryption unit 402" should be read as "re-encryption unit 402-1 to 402-n".

[0112] First, the acquisition unit 201 of the encryption devices 200-1 to 200-n acquires the provided information (step S301).

[0113] Next, the encryption units 202 of the encryption devices 200-1 to 200-n encrypt the provided information acquired in step S301 (step S302).

[0114] Next, the output units 204 of the encryption devices 200-1 to 200-n output the encrypted information provided in step S302 to the proxy server 400 (step S303).

[0115] Next, the acquisition unit 401 of the proxy server 400 acquires the encrypted provided information output in step S303 (step S304).

[0116] Next, the re-encryption unit 402 of the proxy server 400 re-encrypts the encrypted provided information obtained in step S304 (step S305).

[0117] Next, the output unit 403 of the proxy server 400 outputs the information provided, which has been re-encrypted in step S305 and encrypted so that it can be decrypted on the information user's terminal device 300B, to the computing device 100 (step S306).

[0118] Next, the acquisition unit 101 of the computing device 100 acquires the provided information, which was output in step S306 and encrypted so that it can be decrypted on the information user's terminal device 300B (step S307).

[0119] Next, the calculation unit 102 of the computing device 100 performs secure calculation (step S308) based on the provided information, which was obtained in step S307 and encrypted so that it can be decrypted on the information user's terminal device 300B.

[0120] Next, the output unit 103 of the computing device 100 outputs the calculation result calculated in step S308, in an encrypted format that can be decrypted by the information user's terminal device 300B, to the terminal device 300B (step S309).

[0121] Next, the acquisition unit 301 of the terminal device 300B acquires the calculation result output in step S309 in an encrypted format that can be decrypted on the information user's terminal device 300B (step S310).

[0122] Next, the decryption unit 304 of the terminal device 300B decrypts the calculation result obtained in step S310, which is encrypted in a format that can be decrypted on the information user's terminal device 300B (step S311).

[0123] Then, the output unit 303 of the terminal device 300B outputs the calculation result indicating the amount of environmental load, which was decoded in step S311 (step S312).

[0124] With this, the calculation system 2 completes its series of operations.

[0125] The computing device in the above-described embodiment comprises an acquisition unit, a calculation unit, and an output unit. The acquisition unit acquires provided information regarding the amount of environmental impact on a business operator related to the product lifecycle, which is encrypted using at least two different encryption keys employing homomorphic encryption. The calculation unit performs a secure calculation of the amount of environmental impact based on the provided information. The output unit outputs the calculation result of the secure calculation, which shows the amount of environmental impact during the product lifecycle, in an encrypted format.

[0126] The computing device in this embodiment reduces the number of businesses that need to store decryption keys capable of decrypting encrypted information. As a result, the computing device in this embodiment can more securely conceal data from each organization involved in the lifecycle of a product when calculating the amount of environmental impact throughout the product's lifecycle.

[0127] [Modification 1] Next, Modification 1 of the present disclosure will be described with reference to the drawings. To the extent that the description of this modification does not become unclear, explanations that overlap with the above description will be omitted.

[0128] Figure 9 is a block diagram showing the configuration of a computing device. In Figure 9, computing system 1A includes an encryption device 200A-1 in place of the encryption device 200-1 which is part of computing system 1.

[0129] The encryption device 200A-1 includes a determination unit 205 in addition to the configuration of the encryption device 200-1.

[0130] The determination unit 205 includes a determination means for determining whether or not encryption of the provided information is necessary. For example, the determination unit 205 may determine whether or not encryption of the provided information is necessary using criteria for determining whether or not encryption of the provided information is necessary. In this case, for example, the criteria for determining whether or not encryption of the provided information is necessary may be the type of provided information, information identifying the business operator involved in the provided information, or the number of business operators involved in the provided information. Alternatively, for example, the determination unit 205 may determine whether or not encryption of the provided information is necessary by inputting the provided information into a trained model that has learned the relationship between the provided information and information indicating whether or not the provided information has been encrypted.

[0131] The encryption unit 202 encrypts the provided information according to the determination result of the determination unit 205.

[0132] Furthermore, the output unit 204 outputs either encrypted or unencrypted information.

[0133] Generally, encrypted data is large, resulting in a high processing load. According to this modified example 1, since the provided information can be encrypted as needed, the processing load related to sending and receiving the provided information and secure computation can be reduced in some cases.

[0134] [Modification 2] Next, Modification 2 of the present disclosure will be described with reference to the drawings. To the extent that the description of this modification does not become unclear, explanations that overlap with the above description will be omitted.

[0135] Figure 10 is a block diagram showing the configuration of a computing device. In Figure 10, computing system 1B includes an information generation device 500 in addition to the configuration of computing system 1.

[0136] The information generation device 500 is a device that generates information related to calculation results indicating the amount of environmental load. The information generation device 500 comprises an acquisition unit 501, a generation unit 502, and an output unit 503.

[0137] The acquisition unit 501 is an example of an acquisition means for acquiring calculation results in plain text from the terminal device 300A. For example, the output unit 303 of the terminal device 300A outputs the calculation results indicating the amount of environmental load in plain text format to the information generation device 500, and the acquisition unit 501 acquires said calculation results. In addition, the output unit 303 of the terminal device 300A may output the calculation results indicating the amount of environmental load in plain text format to the information generation device 500 when there is an operation input for generating explanatory text in the terminal device 300A.

[0138] The generation unit 502 is an example of a generation means that generates an explanatory text for the calculation results by inputting the calculation results into a large-scale language model. The prompt that instructs the large-scale language model to generate an explanatory text for the calculation results may be set in advance as a system message of the large-scale language model, or it may be input together with the calculation results.

[0139] Furthermore, the generation unit 502 may generate an explanatory text for the calculation results by inputting information related to the calculation results into the large-scale language model, in addition to the calculation results themselves. Information related to the calculation results may include, for example, the type of environmental load shown by the calculation results, or information indicating the product for which the environmental load was calculated. Information related to the calculation results may also include, for example, a comparison target for the environmental load shown by the calculation results. The comparison target may be, for example, the amount of environmental load of the same product in the past, or the amount of environmental load of similar products from the same company or other companies in the past or at the same time. Inputting this information may enrich the explanatory text.

[0140] Furthermore, if the amount of environmental impact at each stage of the product lifecycle is calculated, the generation unit 502 may generate an explanatory text that includes information indicating which stage of the business operator should be asked to make improvements. In this case, the prompt that instructs the large-scale language model to generate an explanatory text of the calculation results may include, for example, an instruction to output information indicating which stage of the business operator should be asked to make improvements. In this case, for example, the generation unit 502 may generate an explanatory text of the calculation results by inputting the comparison targets for the amount of environmental impact at each stage of the product lifecycle into the large-scale language model in addition to the calculation results.

[0141] The output unit 503 is an example of an output means for outputting explanatory text. The output unit 503 outputs explanatory text to, for example, the terminal device 300A. In this case, the output unit 303 of the terminal device 300A may output explanatory text to a display device provided inside or outside the terminal device 300A.

[0142] According to this modified version 2, explanatory text regarding the amount of environmental impact can be output in a way that information users can verify, potentially promoting the calculation, understanding, and disclosure of the amount of environmental impact.

[0143] The above describes examples of applying Modification 1 and Modification 2 to the calculation system 1. However, Modification 1 and Modification 2 may also be applied to other calculation systems 2 or 3, etc. Furthermore, Modification 1 may be applied to calculation system 1B, and Modification 2 may be applied to calculation system 1A.

[0144] [Hardware Configuration] Some or all of the components of each device or system in each embodiment of the present disclosure described above are realized by any combination of an information processing device 1000 and a program, for example, as shown in Figure 11. The information processing device 1000 includes, as an example, the following configuration.

[0145] - CPU (Central Processing Unit) 1001 - ROM (Read Only Memory) 1002 - RAM (Random Access Memory) 1003 - Program 1004 loaded into RAM 1003 - Storage device 1005 that stores the program 1004 - Drive device 1007 that reads and writes to the recording medium 1006 - Communication I / F 1008 that connects to the communication network 1009 - Input / Output I / F 1010 that performs data input and output - Bus 1011 that connects each component Note that I / F is an abbreviation for Interface.

[0146] Each component of each device or system in each embodiment is realized by the CPU 1001 acquiring and executing a program that realizes its function. The program that realizes the function of each component of each device is, for example, stored in advance in the storage device 1005 or RAM 1003 and read by the CPU 1001 as needed. The program 1004 may be supplied to the CPU 1001 via a communication network, or it may be stored in advance in the recording medium 1006 and read by the drive device 1007 and supplied to the CPU 1001.

[0147] There are various variations in how each device is implemented. For example, each device or system may be implemented by any combination of a separate information processing device 1000 and a program for each component. Alternatively, the multiple components of each device may be implemented by any combination of a single information processing device 1000 and a program.

[0148] Furthermore, some or all of the components of each device or system are realized by general-purpose or dedicated circuits, including processors, or combinations thereof. Examples of circuits include CPUs, GPUs (Graphics Processing Units), FPGAs (Field Programmable Gate Arrays), and AI (Artificial Intelligence) processing LSIs (Large Scale Integration). These may consist of a single chip or multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the aforementioned circuits and programs.

[0149] When some or all of the components of each device or system are implemented by multiple information processing devices or circuits, these multiple information processing devices or circuits may be centrally located or distributed. For example, the information processing devices or circuits may be implemented in a form in which each is connected via a communication network, such as a client-server system or a cloud computing system.

[0150] Although the present disclosure has been described above with reference to the embodiments described herein, the present disclosure is not limited to the embodiments described above. Various modifications to the structure and details of the present disclosure can be understood by those skilled in the art within the scope of the present disclosure.

[0151] Furthermore, although multiple operations are described sequentially in flowchart format, the order in which they are described does not limit the order in which they must be performed. Therefore, when implementing each embodiment, the order of the multiple operations may be changed to the extent that it does not impair the content.

[0152] Some or all of the above embodiments may also be described as follows, but are not limited to the following:

[0153] [Note 1] A computing device comprising: an acquisition means for acquiring provided information concerning the amount of environmental burden on a business operator related to the product lifecycle, which is encrypted with at least two different encryption keys using homomorphic encryption; a calculation means for performing a secure calculation of the amount of environmental burden based on the provided information; and an output means for outputting the calculation result of the secure calculation, which shows the amount of environmental burden during the product lifecycle, in an encrypted format.

[0154] [Note 2] The calculation device described in Note 1, wherein the output means outputs the calculation result in encrypted form to an encryption device used by the business operator.

[0155] [Note 3] The calculation device according to Note 2, wherein the output means further outputs an instruction to the encryption device used by the business operator to partially decrypt the calculation result in encrypted form using the encryption key of the business operator.

[0156] [Note 4] The computing device according to Note 2 or 3, wherein the output means further outputs an instruction to the encryption device used by the business operator to output the partially decrypted calculation result to the terminal device of an information user associated with the business operator.

[0157] [Note 5] The computing device according to any one of Notes 2 to 4, wherein the output means further outputs an instruction to the encryption device used by the business operator to encrypt the partially decrypted calculation result so that it can be decrypted by an information user associated with the business operator.

[0158] [Note 6] The computing device according to any one of Notes 1 to 5, wherein the output means outputs the calculation result in encrypted form to a proxy server that re-encrypts it so that it can be decrypted using an encryption key held by an information user associated with the business operator.

[0159] [Note 7] The computing device according to Note 6, wherein the output means further outputs an instruction to the proxy server to re-encrypt the calculation result in the encrypted format.

[0160] [Note 8] The computing device according to Note 6 or 7, wherein the output means further outputs an instruction to the proxy server to output the re-encrypted calculation result to the terminal device of the information user.

[0161] [Note 9] The calculation device according to any one of Notes 1 to 8, wherein the output means outputs the calculation result in encrypted form to an output destination corresponding to the information user associated with the business operator.

[0162] [Note 10] The computing device according to any one of Notes 1 to 9, wherein the output means outputs the provided information to a proxy server that re-encrypts it so that it can be decrypted using an encryption key held by an information user associated with the business operator; the acquisition means acquires the re-encrypted provided information from the proxy server; the calculation means performs the secure calculation based on the re-encrypted provided information; and the output means outputs the calculation result in encrypted form to a terminal device used by the information user.

[0163] [Note 11] The computing device according to any one of Notes 6 to 8 and 10, wherein the proxy server is a plurality of proxy servers each possessing a fragment of the re-encryption key.

[0164] [Note 12] The calculation means is a calculation device according to any one of Notes 1 to 11, which performs the confidential calculation at each stage in the lifecycle in which the business operator is active.

[0165] [Note 13] The amount of the environmental load is the carbon footprint, as described in any of Notes 1 to 12.

[0166] [Note 14] The amount of the environmental load is the water footprint, as determined by the calculation device described in any of Notes 1 to 13.

[0167] [Note 15] The amount of environmental load is the amount of predetermined raw materials used in the life cycle of the product, as described in any of Notes 1 to 14.

[0168] [Appendix 16] A computing system comprising: a computing device described in any of Appendices 1 to 15; an encryption device for encrypting information provided by the business operator regarding the amount of environmental impact; and a terminal device used by information users associated with the business operator.

[0169] [Note 17] The calculation system according to Note 16, further comprising an information generation device, the information generation device comprising: an acquisition means for acquiring the calculation result in plain text from the terminal device; a generation means for generating an explanatory text of the calculation result by inputting the calculation result into a large-scale language model; and an output means for outputting the explanatory text.

[0170] [Note 18] The encryption device is a calculation system as described in Note 16 or 17, comprising a determination means for determining whether or not the provided information needs to be encrypted.

[0171] [Note 19] A calculation method comprising: obtaining provided information concerning the amount of environmental burden on a business operator related to the product lifecycle, which is encrypted using two or more different encryption keys with homomorphic encryption schemes; performing a secure calculation of the amount of environmental burden based on the provided information; and outputting the calculation result of the secure calculation, which shows the amount of environmental burden during the product lifecycle, in an encrypted format.

[0172] [Note 20] A recording medium that stores a program that causes a computer to perform the following processing: acquire provided information concerning the amount of environmental burden on a business operator related to the product lifecycle, which is encrypted with at least two different encryption keys using homomorphic encryption; perform a secure calculation of the amount of environmental burden based on the provided information; and output the calculation result of the secure calculation, which shows the amount of environmental burden during the product lifecycle, in an encrypted format.

[0173] Furthermore, some or all of the configurations described in Appendices 2 to 18, which are dependent on Appendice 1 (Computing Device) as described above, may also be dependent on Appendice 19 (Calculation Method) and Appendice 20 (Program) in the same dependent relationship as Appendices 2 to 18. Moreover, not limited to Appendices 1, 19, and 20, some or all of the configurations described as appendices may also be dependent on various hardware, software, various recording means for recording software, or systems, without departing from the embodiments described above.

[0174] 1 Calculation System 1A Calculation System 1B Calculation System 2 Calculation System 3 Calculation System 100 Calculation Device 101 Acquisition Unit 102 Calculation Unit 103 Output Unit 200-1 Encryption Device 200-n Encryption Device 200A-1 Encryption Device 200A-n Encryption Device 201 Acquisition Unit 202 Encryption Unit 203 Decryption Unit 204 Output Unit 205 Judgment Unit 300A Terminal Device 300B Terminal Device 301 Acquisition Unit 302 Merge Unit 303 Output Unit 304 Decryption Unit 400 Proxy Server 400-1 Proxy Server 400-n Proxy Server 401 Acquisition Unit 402 Re-encryption Unit 402-1 Re-encryption Unit 402-n Re-encryption Unit 403 Output Unit 500 Information generation device 501 Acquisition unit 502 Generation unit 503 Output unit 1000 Information processing device 1001 CPU 1002 ROM 1003 RAM 1004 Program 1005 Storage device 1006 Recording medium 1007 Drive device 1008 Communication I / F 1009 Communication network 1010 Input / output I / F 1011 Bus

Claims

1. A computing device comprising: an acquisition means for acquiring information relating to the amount of environmental impact on a business operator related to the product lifecycle, which is encrypted using at least two different encryption keys employing homomorphic encryption; a calculation means for performing a secure calculation of the amount of environmental impact based on the provided information; and an output means for outputting the calculation result of the secure calculation, which indicates the amount of environmental impact during the product lifecycle, in an encrypted format.

2. The calculation device according to claim 1, wherein the output means outputs the calculation result in an encrypted form to an encryption device used by the business operator.

3. The computing device according to claim 2, wherein the output means further outputs an instruction to the encryption device used by the business operator to partially decrypt the encrypted calculation result using the encryption key of the business operator.

4. The computing device according to claim 2 or 3, wherein the output means further outputs an instruction to the encryption device used by the business operator to output the partially decrypted calculation result to a terminal device of an information user associated with the business operator.

5. The computing device according to any one of claims 2 to 4, wherein the output means further outputs an instruction to the encryption device used by the business operator to encrypt the partially decrypted calculation result so that it can be decrypted by an information user associated with the business operator.

6. The computing device according to any one of claims 1 to 5, wherein the output means outputs the calculation result in encrypted form to a proxy server that re-encrypts it so that it can be decrypted using an encryption key held by an information user associated with the business operator.

7. The computing apparatus according to claim 6, wherein the output means further outputs an instruction to the proxy server to re-encrypt the calculation result in encrypted form.

8. The computing apparatus according to claim 6 or 7, wherein the output means further outputs an instruction to the proxy server to output the re-encrypted calculation result to the terminal device of the information user.

9. The computing device according to any one of claims 1 to 8, wherein the output means outputs the calculation result in an encrypted format to an output destination corresponding to an information user associated with the business operator.

10. The computing device according to any one of claims 1 to 9, wherein the output means outputs the provided information to a proxy server that re-encrypts it so that it can be decrypted using an encryption key held by an information user associated with the business operator; the acquisition means acquires the re-encrypted provided information from the proxy server; the calculation means performs the secure calculation based on the re-encrypted provided information; and the output means outputs the calculation result in encrypted form to a terminal device used by the information user.

11. The computing device according to any one of claims 6 to 8 and 10, wherein the proxy server is a plurality of proxy servers each possessing a fragment of a re-encryption key.

12. The computing device according to any one of claims 1 to 11, wherein the computing means performs the confidential computing at each stage in which the business operator is active during the lifecycle.

13. The calculation device according to any one of claims 1 to 12, wherein the amount of the environmental load is the carbon footprint.

14. The calculation device according to any one of claims 1 to 13, wherein the amount of the environmental load is the water footprint.

15. The calculation device according to any one of claims 1 to 14, wherein the amount of the environmental load is the amount of a predetermined raw material used in the life cycle of the product.

16. A computing system comprising: a computing device according to any one of claims 1 to 15; an encryption device for encrypting information provided by the business operator regarding the amount of environmental impact; and a terminal device used by an information user associated with the business operator.

17. The calculation system according to claim 16, further comprising an information generation device, the information generation device comprising: an acquisition means for acquiring the calculation result in plain text from the terminal device; a generation means for generating an explanatory text of the calculation result by inputting the calculation result into a large-scale language model; and an output means for outputting the explanatory text.

18. The computing system according to claim 16 or 17, wherein the encryption device comprises a determination means for determining whether or not it is necessary to encrypt the information to be provided.

19. A calculation method comprising: obtaining provided information concerning the amount of environmental burden on a business operator related to the product lifecycle, which is encrypted using two or more different encryption keys with homomorphic encryption; performing a secure calculation of the amount of environmental burden based on the provided information; and outputting the calculation result of the secure calculation, which shows the amount of environmental burden during the product lifecycle, in an encrypted format.

20. A recording medium that stores a program that causes a computer to perform the following processing: acquire provided information concerning the amount of environmental impact of a business operator related to the product lifecycle, which is encrypted using at least two different encryption keys with homomorphic encryption; perform a secure calculation of the amount of environmental impact based on the provided information; and output the calculation result of the secure calculation, which shows the amount of environmental impact of the product lifecycle, in an encrypted format.

Citation Information

Patent Citations

  • Data sharing system, data sharing method and data sharing program

    JP7011874B1

  • Information management method and information management system

    WO2024106068A1