Encrypted Data Computation System with Magnitude Relation Determination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encrypted data computation systems cannot perform addition and subtraction operations on encrypted numerical values or determine the magnitude relation between a minuend and a subtrahend in such operations.

Innovation Solution

An encrypted data computation system comprising a client terminal, computation device, and computation assist device, which generate and utilize encryption keys, secondary computation keys, and tertiary computation keys to perform primary, secondary, and tertiary computation processes, allowing for encrypted addition-subtraction and determining the magnitude relation between encrypted values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If encrypted data computation is performed using existing magnitude comparison methods, then the magnitude relation between two encrypted values can be determined, but addition and subtraction operations on encrypted data cannot be performed

Engineering Contradiction:
Improvecomputation capabilityVSAvoidcomputation correctness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The invention segments the computation process into three distinct stages: primary computation (addition-subtraction of encrypted data), secondary computation (randomization), and tertiary computation (magnitude determination). This segmentation allows each stage to perform its specific function while maintaining the overall security and correctness of the encrypted data computation system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces intermediary computation devices and intermediary data structures (such as the encrypted differential privacy parameter and randomized values) that facilitate the transition between different computation stages. These intermediaries enable the system to perform addition-subtraction operations on encrypted data while preserving security properties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If encrypted data is used for computation, then data secrecy is maintained, but the ability to perform arithmetic operations and determine magnitude relations is lost

Engineering Contradiction:
Improvedata secrecyVSAvoidarithmetic operation capability
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-establishing encrypted differential privacy parameters and pre-randomizing encrypted data before computation. This preliminary preparation enables subsequent addition-subtraction operations to be performed on encrypted data without compromising secrecy, as the randomization is already in place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention changes parameters by transforming encrypted data through multiple computation stages, each with different parameter requirements. The primary computation stage uses parameters suitable for addition-subtraction, while the tertiary computation stage uses parameters optimized for magnitude determination, allowing both operations to succeed while maintaining secrecy.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multiple computation operations are supported on encrypted data, then versatility improves, but system complexity increases

Engineering Contradiction:
Improveoperation typeVSAvoidcomputation system structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The invention creates a universal encrypted data computation system that can handle multiple operation types (addition, subtraction, and magnitude determination) through a unified three-stage computation framework. This multi-functional design allows the same system structure to support various operations without requiring separate specialized systems for each operation type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10116439B2Encrypted data computation system, device, and program
Publication Date: 2018.10.30 KK TOSHIBA
  • US10116439B2 patent drawing
  • US10116439B2 patent drawing
  • US10116439B2 patent drawing

AI summary

According to one embodiment, an encryption device encrypts each of numerical values based on an encryption key, and generates encrypted data. On the basis of each of the encrypted data, a computation device generates a primary computation result corresponding to data in which a computation result of an expression that has added and subtracted each of the numerical values is encrypted. On the basis of the primary computation result, a secondary computation key and random numbers, a computation assist device generates a secondary computation result. The computation device generates a tertiary computation result based on the secondary computation result and a tertiary computation key, and decides the magnitude relation between a minuend and a subtrahend in the expression based on the tertiary computation result.