WO2022123744A1 - 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム - Google Patents
秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム Download PDFInfo
- Publication number
- WO2022123744A1 WO2022123744A1 PCT/JP2020/046125 JP2020046125W WO2022123744A1 WO 2022123744 A1 WO2022123744 A1 WO 2022123744A1 JP 2020046125 W JP2020046125 W JP 2020046125W WO 2022123744 A1 WO2022123744 A1 WO 2022123744A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- array
- data
- address value
- hash table
- secret
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/22—Indexing; Data structures therefor; Storage structures
- G06F16/2228—Indexing structures
- G06F16/2255—Hash tables
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/602—Providing cryptographic facilities or services
-
- G—PHYSICS
- G09—EDUCATION; CRYPTOGRAPHY; DISPLAY; ADVERTISING; SEALS
- G09C—CIPHERING OR DECIPHERING APPARATUS FOR CRYPTOGRAPHIC OR OTHER PURPOSES INVOLVING THE NEED FOR SECRECY
- G09C1/00—Apparatus or methods whereby a given sequence of signs, e.g. an intelligible text, is transformed into an unintelligible sequence of signs by transposing the signs or groups of signs or by replacing them by others according to a predetermined system
Definitions
- the present invention relates to a secret calculation, and particularly to an operation in which the order of an array is concealed.
- the hash table is a data structure for high-speed data retrieval based on the key value by encoding the key value of the data with a hash function or the like and associating it with the address value in the data array. This is useful, for example, when data is stored in an external server or the like and it is desired to perform a search by a key value at any time.
- ordinary hash tables do not assume data concealment, and there is a problem that, for example, a server entrusted with data (or hash table) by a user can identify the table structure and thereby observe the user's access tendency. be.
- a secret hash table for example, reference [4, 1]
- Reference names are listed at the end of the specification.
- the secret hash table is a technique for constructing a hash table while keeping the table structure secret from the server, and it is possible to hide the user's access tendency to the server.
- a method of constructing a secret hash table is a method in which the user encrypts all data at hand, constructs a hash table, and entrusts it to a server. In this case, the user's storage area is stored for the number of data n. O (n) is required.
- References [4] and [1] mentioned above are methods for constructing a concealed hash table on a server by a user-server cooperative protocol on the assumption that the server has all the encrypted data. It has the advantage that O (1) is sufficient for the storage area of the user.
- Non-Patent Document 1 shows a method of constructing a secret hash table by secret calculation using multiple servers without requiring any communication between users and servers. Therefore, the communication environment and calculation of the user terminal are shown. Stable performance can be achieved regardless of performance.
- the secret hash method called "Oblivius Greedy Hashing” is stored in two different address values (that is, at which position in the table) for each data to be stored.
- By giving (a value indicating whether or not it should be) a table construction algorithm is realized in which each data is stored in the more vacant of the two storage destinations. This has the advantage that the table size can be kept small compared to other existing methods.
- the present invention has been made in view of the above points, and an object of the present invention is to provide a technique for constructing a secret hash table without increasing the amount of communication while reducing the table size.
- up to Z data can be added to each of the B address values by secret calculation.
- It is a secret hash table construction device that builds a secret hash table that can be stored.
- a storage destination data array including a first address value and a second address value, a flag, and a rank for each address value for each data in the actual data string, and a first address value and a second address value as dummies.
- a second array in which the actual data string and the dummy data string are concatenated is generated.
- a ranking operation for the same data with respect to the first address value of the first array sorted by sorting each of the first array and the second array based on the first address value and the flag in the first array. And sort each of the first sequence and the second sequence based on the ranking.
- a ranking operation for the same data with respect to the second address value of the first array sorted by sorting each of the first array and the second array based on the second address value and the flag in the first array. And In the first array, the address value on the lower rank side of the first address value and the second address value is extracted, and a third array having the extracted address value and the flag is generated.
- the second sequence was sorted using the fourth sequence obtained by comparing each element of the rank array calculated from the address values in the third sequence with Z, and the BZ pieces in the sorted second sequence.
- a secret hash table construction device including an arithmetic unit that outputs elements as the secret hash table is provided.
- a technique for constructing a secret hash table without increasing the amount of communication while reducing the table size is provided.
- FIG. 1 It is a block diagram of a secret hash table construction system. It is a functional block diagram of a server. It is a figure which shows the hardware configuration example of the apparatus. It is a flowchart which shows the processing procedure of Example 1.
- FIG. 2 It is a flowchart which shows the processing procedure of Example 2.
- FIG. 3 It is a flowchart which shows the processing procedure of Example 4.
- FIG. 1 shows a configuration example of a secret hash table construction system according to the present embodiment.
- the secret hash table construction system of the present embodiment has a configuration in which a plurality of servers 100-1 to 100-N are provided in 200 on a communication network.
- Each server is a computer.
- the computer may be a physical machine or a virtual machine provided by the cloud.
- the user terminal 300 shown in FIG. 1 accesses the secret hash table construction system and acquires, for example, the data corresponding to the key.
- the process related to the construction of the secret hash table is executed by the secret calculation by the cooperative protocol between these plurality of servers 100-1 to 100-N.
- the use of a cooperative protocol of a plurality of servers is an example, and the present invention is not limited thereto.
- the present invention is applicable to any technique capable of performing secret calculations. For example, if one server can perform secret calculations, it is also possible to execute the technique according to the present invention on that server.
- FIG. 2 shows a configuration example of the server 100.
- the configuration example of the server 100 shown in FIG. 2 is the configuration when a plurality of servers 100-1 to 100-N are virtually regarded as one server.
- the server 100 shown in FIG. 2 may be called a secret hash table construction system.
- the server 100 may be referred to as a secret hash table construction device.
- the server may be the server 100 shown in FIG.
- the server 100 has an input unit 110, a calculation unit 120, an output unit 130, and a data storage unit 140.
- the arithmetic unit 120 executes a process related to the construction and operation of the secret hash table.
- the data storage unit 140 stores data prepared in advance for calculation, data such as a secret array during calculation, and a table.
- the input unit 110 receives, for example, a request from the user terminal 300 and inputs the request.
- the output unit 140 returns, for example, the calculation result for the request from the user terminal 300 to the user terminal 300.
- the server 100 in the present embodiment can be realized by, for example, causing a computer to execute a program describing the processing contents described in the present embodiment.
- the "computer” may be a physical machine or a virtual machine on the cloud.
- the "hardware” described here is virtual hardware.
- the above program can be recorded on a computer-readable recording medium (portable memory, etc.), saved, and distributed. It is also possible to provide the above program through a network such as the Internet or e-mail.
- FIG. 3 is a diagram showing an example of the hardware configuration of the above computer.
- the computer of FIG. 3 has a drive device 1000, an auxiliary storage device 1002, a memory device 1003, a CPU 1004, an interface device 1005, a display device 1006, an input device 1007, an output device 1008, and the like, which are connected to each other by a bus B, respectively.
- the program that realizes the processing on the computer is provided by, for example, a recording medium 1001 such as a CD-ROM or a memory card.
- a recording medium 1001 such as a CD-ROM or a memory card.
- the program is installed in the auxiliary storage device 1002 from the recording medium 1001 via the drive device 1000.
- the program does not necessarily have to be installed from the recording medium 1001, and may be downloaded from another computer via the network.
- the auxiliary storage device 1002 stores the installed program and also stores necessary files, data, and the like.
- the memory device 1003 reads and stores the program from the auxiliary storage device 1002 when the program is instructed to start.
- the CPU 1004 realizes the function related to the server 100 according to the program stored in the memory device 1003.
- the interface device 1005 is used as an interface for connecting to a network.
- the display device 1006 displays a GUI (Graphical User Interface) or the like by a program.
- the input device 1007 is composed of a keyboard, a mouse, buttons, a touch panel, and the like, and is used for inputting various operation instructions.
- the output device 1008 outputs the calculation result.
- the concealed value of the value x is referred to as [[x]]
- the process x ⁇ [[x]] is referred to as concealment of x
- [[x]] ⁇ x is referred to as restoration of x.
- the secret sharing method references [6, 5]
- Any concealment / restoration processing technique may be used.
- the comparison operation can be executed with the communication cost O (len) bit in the technique of reference [7].
- the following processing is executed by the arithmetic unit 120 of the server 100. Further, the data prepared in advance, the array obtained by the calculation, the table, etc. are stored in the data storage unit 140.
- the calculation unit 120 performs an operation on the data read from the data storage unit 140, and proceeds with the process while repeating storing the operation result in the data storage unit 140.
- Example 1 First, Example 1 will be described.
- the key ki is an identifier unique to each data, and is used for the purpose of uniquely specifying the data at the time of access or the like.
- the flag e i is a 1-bit value for determining whether or not the data is a dummy.
- the bit length of ki ceil (logn) at the minimum, but redundancy may be acceptable.
- the secret hash table constructed in the first embodiment is a data array of size B ⁇ Z, and is a data structure capable of storing up to Z data in each of the address values of B streets if expressed differently. And. Further, it is assumed that the pseudo-random function used in the first embodiment satisfies PRF ([[k]], [[s]]) ⁇ ⁇ 0, ..., B-1 ⁇ .
- the server 100 constructs a secret hash table by the process described below.
- the process executed by the server 100 will be described according to the procedure of the flowchart of FIG.
- step 101 the server 100 shuffles [[A]] and sets [[A]] ⁇ Shuffle ([[A]]). However, this operation may not be performed depending on the state of the input [[A]] and the safety to be satisfied.
- [[addr p i ]] ⁇ PRF ([[ki]], [[sp]]); i ⁇ ⁇ 0, ..., n-1 ⁇ , p ⁇ ⁇ 0, 1 ⁇ . Also, it is initialized as [[rank pi ]] ⁇ [[ 0 ]].
- ADDR ((3,1,0,0,0), It becomes an array (an array of n data) such as (18,95,0,0,0), ..., (8,78,0,0,0)).
- ADDR ((3,1,0,0,0)
- n data an array of n data
- the explanation may be given without [[]] as appropriate.
- ADDR' ((3,1,0,0,0), (18,95,0,0,0), ..., (8,78, 0,0,0), (0,0,1,0,0), (0,0,1,0,0), ..., (8,8,1,0,0)) (An array of n + BZ data).
- the notation [[ADDR'. [[ADDR']] is an array obtained by extracting only the first address value [[addr 0 i ]] from [[ADDR']] ([[addr 0 0 ]], ..., [[addr 0 n + BZ-1 ] ]. ]])).
- the notation [[ADDR'. addr 1 ]], [[ADDR'. rank 0 ]], [[ADDR'. Rank 1 ]] is defined as an array obtained by extracting [[addr 1 i ]], [[rank 0 i ]], and [[rank 1 i ]] from [[ADDR']], respectively.
- ADDR' ((3,1,0,0,0), (18,95,0,0,0), ..., (8,78,0,0,0), ( 0,0,1,0,0), (0,0,1,0,0), ..., (8,8,1,0,0)), ADDR'.
- pos 0 ((3,0), (18,0), ..., (8,0), (0,1), (0,1), ..., (8) , 1)).
- the dimmy is a predetermined value different from any key ki.
- the server 100 first sorts the data array and the storage destination data array based on the first address value addr 0 i and the flag e i . That is, [[A']] ⁇ Sort ([[ADDR'. Pos 0 ]], [[A']]), and [[ADDR']] ⁇ Sort ([[ADDR'. Pos 0 ]]], [ [ADDR']]) is calculated.
- the data array and the storage destination data array shall be sorted in ascending order by address value and in the order of actual data> dummy data at the same address value, but the subsequent sorting and ascending / descending order of ranking shall be adjusted. You can also change the sort order by doing this.
- ⁇ S106> the server 100 ranks based on the sorted address values. That is, [[ADDR'. rank 0 ]] ⁇ Rank ([[ADDR'.addr 0 ]]) is calculated.
- ADDR'. rank 0 is, for example, ADDR'.
- Rank 0 (1,2,3,4 ...., 1,2,3, ..., 1,2,3,4,5) is an array (an array of n + BZ data). ..
- the server 100 sorts the data array and the storage destination data array in descending order based on the first rank. That is, [[A']] ⁇ Sort ([[ADDR'.rank 0 ]], [[A']]) and [[ADDR']] ⁇ Sort ([[ADDR'.rank 0 ]], [[ ADDR']]) is calculated so that rank 0 i is arranged in descending order. Note that this operation can be similarly realized by simply sorting each array in ascending order and then sorting them in reverse order.
- the server 100 sorts based on the second address value addr 1 i and the flag, as in the process in S105. That is, [[A']] ⁇ Sort ([[ADDR'. Pos 1 ]], [[A']]) and [[ADDR']] ⁇ Sort ([[ADDR'. Pos 1 ]]], [[ ADDR']])) is calculated. At this time, if stable sorting is used, the same address value can be sorted in the order of actual data> dummy data and high rank> low rank.
- ⁇ S109> the server 100 ranks based on the second sorted address value, as in the process in S106. That is, [[ADDR'. rank 1 ]] ⁇ Rank ([[ADDR'.addr 1 ]]) is calculated.
- the server 100 sorts each data in ascending order based on the newly obtained array [[ADDR fin ]]. That is, [[A']] ⁇ Sort ([[ADDR fin ]], [[A']]) and [[ADDR fin ]] ⁇ Sort ([[ADDR fin ]], [[ADDR fin ]]). calculate.
- the server 100 sorts the data array in ascending order using [[Y]]. That is, [[A']] ⁇ Sort ([[Y]], [[A']]) is calculated. After that, only the last BZ elements are output as a hash table, and the others are deleted. In addition, two private keys [[s 0 ]] and [[s 1 ]] are also output as access information attached to the hash table.
- Example 2 a method of constructing a table equivalent to that of the first embodiment will be shown more efficiently.
- the data array [[A]] (or [[A']]) is always sorted together with the storage destination data array, the number of sorts is simply increased, and the key and the flag are assumed to be large. If the data vi was added, there was a possibility that the efficiency would be deteriorated due to the sorting of the data array.
- the algorithm of the first embodiment is followed in principle, but the number of sorts is reduced by using the encryption in the secret calculation, and the secret hash table is constructed as follows.
- the procedure of the flowchart of FIG. 5 will be described.
- the private key [[s]] may be generated before the start of the protocol.
- the only difference from the first embodiment is that the tag [[tag i ]] is included.
- tag sequence [[Tag d ]] ([[tag d 0 ]], ..., [[tag d BZ-1 ]]) calculated in S204 of the second embodiment, [[[[ Tag']] ⁇ [[Tag]]
- ⁇ S206> the server 100 conceals and randomizes the order of the arrays [[A']] and [[Tag']] ([[A']], [[Tag']]) ⁇ Shuffle ( [[A']], [[Tag']]) are calculated. In this operation, the same shuffle process is executed in parallel in order to randomize while maintaining the correspondence between the two arrays.
- ⁇ S207> the server 100 performs the same processing as in S105 to S113 of the first embodiment.
- the operation is performed only on the storage destination data array without touching the array [[A']] at all.
- each element of [[ADDR fin ]] is changed to ([[addr i ]], [[e i ]], [[tag i ]]. ]) To take over the tag information.
- the server 100 sorts [[ADDR fin ]] in ascending order using [[Y]] obtained in the procedure corresponding to S112 of Example 1. That is, [[ADDR fin ]] ⁇ Sort ([[Y]], [[ADDR fin ]]) is calculated. After that, only the last BZ elements are left, and the others are deleted.
- ⁇ S209> the server 100 restores all the elements of the tag array [[Tag']] and returns them to plaintext. At the same time, all tags included in [[ADDR fin ]] are restored and returned to plain text. Hash table by extracting BZ elements whose corresponding tags are included in [[ADDR fin ]] from the data array [[A']] and arranging them in the order of [[ADDR fin ]]. And. Finally, the hash table and private key [[s 0 ]] and [[s 1 ]] are output.
- Example 3 the data reference method to the secret hash table constructed in the first and second embodiments will be described.
- the server 100 holds the secret hash table (size B ⁇ Z) constructed in Examples 1 and 2 and the secret keys [[s 0 ]] and [[s 1 ]] in the data storage unit 140.
- the user terminal 300 has the key k to be accessed, but this may be selected by the server itself based on the agreement between the servers.
- the procedure shown in the flowchart of FIG. 6 will be described.
- the user terminal 300 sends the secret value [[k]] of the key corresponding to the data to be accessed to the server 100.
- this secret key value can be generated not only by the request from the user terminal 300 to the server 100 but also by the server itself based on the agreement between the servers.
- the server 100 uses a pseudo-random function to provide two address values [[addr 0 ]] ⁇ PRF ([[k]], [[s 0 ]]), [[addr 1 ]] ⁇ PRF ( [[K]], [[s 1 ]]) is calculated, and this is restored to obtain addr 0 and addr 1 .
- the server 100 calculates the inner product [[a]] ⁇ ⁇ [[a]], [[c]]> and returns it to the user terminal 300 or restores it based on the agreement between the servers. Alternatively, this may not be restored and may be used for a completely different secret calculation process.
- the communication amount between the user and the server is an O (logn) bit
- the communication amount between the servers is an O (Zlogn) bit
- Example 4 In the fourth embodiment, the data deletion method in the secret hash table constructed in the first and second embodiments will be described.
- the server 100 holds the hash table (size B ⁇ Z) constructed in Examples 1 and 2 and the private keys [[s 0 ]] and [[s 1 ]] in the data storage unit 140. And. Further, it is assumed that the user has the key k of the data to be deleted, but this may be selected by the server itself based on the agreement between the servers.
- the procedure shown in the flowchart of FIG. 7 will be described.
- S401 the user terminal 300 sends the secret value [[k]] of the key to be deleted to the server 100.
- this secret key value can be generated not only by the request from the user terminal 300 to the server 100 but also by the server itself based on the agreement between the servers.
- the server 100 uses a pseudo-random function to provide two address values [[addr 0 ]] ⁇ PRF ([[k]], [[s 0 ]]), [[addr 1 ]] ⁇ PRF ( [[K]], [[s 1 ]]) is calculated, and this is restored to obtain addr 0 and addr 1 .
- Example 5 In the fifth embodiment, a method of disassembling the hash table constructed in the first and second embodiments and extracting all the data will be described. As a premise, it is assumed that the server 100 holds the hash table (size B ⁇ Z) constructed in the first and second embodiments in the data storage unit 140. Hereinafter, the procedure shown in the flowchart of FIG. 8 will be described.
- [[Table]] Sort ([[E]], [[Table]]).
- ⁇ S502> the server 100 sets the first n data of [[Table]] into an array [[A]] and deletes the rest.
- a secret hash table can be constructed without communication with the user by using the secret calculation.
- the secret calculation process called ranking the number of secret sorts required for table construction can be greatly reduced, and the communication cost can be greatly reduced as compared with the conventional method.
- the amount of communication between servers is changed from ⁇ (nlog 2.5 n) to O while maintaining the merit of the conventional method of reducing the table size by allocating two types of address values to each data. It can be reduced to (nlog 2 n). It is also possible to operate on the built table.
- a secret hash table construction device that can store up to Z data in each B-style address value is constructed by secret calculation from an actual data string containing a plurality of data having a key and a flag indicating whether or not the data is a dummy. It is a secret hash table construction device that A storage destination data array including a first address value and a second address value, a flag, and a rank for each address value for each data in the actual data string, and a first address value and a second address value as dummies.
- a first array that concatenates the flag and the storage destination data array including the rank for each address value.
- a second array in which the actual data string and the dummy data string are concatenated is generated.
- a ranking operation for the same data with respect to the first address value of the first array sorted by sorting each of the first array and the second array based on the first address value and the flag in the first array.
- sort each of the first sequence and the second sequence based on the ranking.
- a ranking operation for the same data with respect to the second address value of the first array sorted by sorting each of the first array and the second array based on the second address value and the flag in the first array.
- a secret hash table construction device including an arithmetic unit that outputs elements as the secret hash table.
- the calculation unit concatenates the actual data string and the dummy data string by using a tag column having a tag indicating each data in the actual data string and each data in the dummy data string.
- the secret hash table construction device according to item 1, wherein the secret hash table is generated without performing a sort other than the sort based on the fourth array with respect to the second array.
- the calculation unit calculates two address values from the key value to be accessed, acquires 2Z data corresponding to the two address values from the secret hash table, and of the 2Z data, the key.
- the secret hash table construction device according to item 1 or 2, which returns data having the same key value as the value.
- the calculation unit calculates two address values from the key value to be deleted, acquires 2Z data corresponding to the two address values from the secret hash table, and out of the 2Z data data.
- the secret hash table construction device according to any one of the items 1 to 3 for deleting data having the same key value as the key value.
- the calculation unit sorts all the data in the secret hash table based on the flag, and acquires the predetermined number of data at the beginning as the actual data string in any one of the first to fourth terms.
- the described secret hash table construction device (Section 6) A secret hash table that can store up to Z data in each of the B address values is constructed by secret calculation from an actual data string containing a plurality of data having a key and a flag indicating whether or not the data is a dummy.
- a storage destination data array including a first address value and a second address value, a flag, and a rank for each address value for each data in the actual data string, and a first address value and a second address value as dummies. And generate a first array that concatenates the flag and the storage destination data array including the rank for each address value.
- a second array in which the actual data string and the dummy data string are concatenated is generated.
- a ranking operation for the same data with respect to the first address value of the first array sorted by sorting each of the first array and the second array based on the first address value and the flag in the first array. And sort each of the first sequence and the second sequence based on the ranking.
- a ranking operation for the same data with respect to the second address value of the first array sorted by sorting each of the first array and the second array based on the second address value and the flag in the first array. And In the first array, the address value on the lower rank side of the first address value and the second address value is extracted, and a third array having the extracted address value and the flag is generated. The second sequence was sorted using the fourth sequence obtained by comparing each element of the rank array calculated from the address values in the third sequence with Z, and the BZ pieces in the sorted second sequence.
- a secret hash table construction system including an arithmetic unit that outputs elements as the secret hash table.
- a secret hash table that can store up to Z data in each B-style address value is constructed by secret calculation from an actual data string containing multiple data having a key and a flag indicating whether the data is dummy or not. It is a secret hash table construction method executed by the secret hash table construction system.
- a ranking operation for the same data with respect to the second address value of the first array sorted by sorting each of the first array and the second array based on the second address value and the flag in the first array.
- the steps to do In the first array a step of extracting the address value on the lower rank side of the first address value and the second address value and generating a third array having the extracted address value and the flag.
- the second sequence was sorted using the fourth sequence obtained by comparing each element of the rank array calculated from the address values in the third sequence with Z, and the BZ pieces in the sorted second sequence.
- a method of constructing a secret hash table including a step of outputting an element as the secret hash table.
- (Section 8) A program for causing a computer to function as an arithmetic unit in the secret hash table construction device according to any one of the items 1 to 5.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Databases & Information Systems (AREA)
- Data Mining & Analysis (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- Storage Device Security (AREA)
Abstract
Description
前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
演算部を備える秘匿ハッシュテーブル構築装置が提供される。
本実施の形態では、複数台のサーバを用いてユーザ・サーバ間通信コストを削減した効率的な秘匿ハッシュテーブル構築方法、及び操作方法について説明する。本実施の形態に係る技術により、各データに2通りの格納先を付与することでOblivious Greedy Hashingと同等にテーブルサイズを小さく抑えつつも、サーバ間通信量O(nlog2n)ビットのみでテーブル構築が可能である。以下、本実施の形態のシステム構成、及び処理手順について詳細に説明する。
図1に、本実施の形態における秘匿ハッシュテーブル構築システムの構成例を示す。図1に示すように、本実施の形態の秘匿ハッシュテーブル構築システムは、複数のサーバ100-1~100-Nが通信ネットワーク上200に備えられた構成を有する。各サーバはコンピュータである。当該コンピュータは物理マシンであってもよいし、クラウドにより提供される仮想マシンであってもよい。
本実施の形態におけるサーバ100(秘匿ハッシュテーブル構築装置)は、例えば、コンピュータに、本実施の形態で説明する処理内容を記述したプログラムを実行させることにより実現可能である。なお、この「コンピュータ」は、物理マシンであってもよいし、クラウド上の仮想マシンであってもよい。仮想マシンを使用する場合、ここで説明する「ハードウェア」は仮想的なハードウェアである。
まず、サーバ100の演算部120により実行される秘匿ハッシュテーブル構築や操作の処理において前提となる、秘密計算に係る基本的な処理について説明する。これら基本的な処理自体は既存技術である。
以下では、値xの秘匿値を[[x]]と表し、処理x→[[x]]をxの秘匿化、[[x]]→xをxの復元と呼ぶ。本実施の形態では、秘匿化・復元処理を行うための技術として秘密分散法(参考文献[6,5])を使用することを想定しているが、同等の機能及び安全性を満たす方法ならばどのような秘匿化・復元処理技術を用いてもよい。
秘匿値同士の加算・減算・乗算をそれぞれ以下のように表す。
[[a‐b]]←[[a]]‐[[b]]
[[a×b]]←[[a]]×[[b]]
a、bがlenビットで表現される空間にあるとすると、参考文献[7]の技術では加算と減算を通信コスト0、乗算を通信コストO(len)ビットで実行できる。
秘匿値同士の比較を以下のように表す。
上記の比較は、aとbが等しいかどうかの判定結果がc(1ビット数)であることを示す。正しければ1、そうでなければ0になる。
上記の比較は、aがb以下であるか否かの判定結果がd(1ビット数)であることを示す。正しければ1、そうでなければ0になる。
秘匿値のベクトル又は配列[[a]]=([[a0]],...,[[an-1]]),[[b]]=([[b0]],...,[[bn-1]])の内積を以下のように表す。
ベクトルa,bの各要素がそれぞれlenビットで表現される空間にあるとすると、参考文献[7]の技術では内積を通信コストO(len)ビットで実行できる。
秘密の配列[[A]]をシャッフルする処理を以下のように表す。
Aがlenビットの要素をn個持つ配列であるとき、参考文献[3]の技術ではこの処理を通信コストO(len・n)ビットで実行できる。
秘密のキー配列[[K]]及びソート対象配列[[A]]に対し、[[A]]を[[K]]の各値に基づきソートする処理を以下のように表す。
この処理はKに関して昇順・降順のいずれも可能である。Kがlenビットの要素をn個持つ配列、Aがmビットの要素をn個持つ配列であるとき、参考文献[3]の技術ではこの処理を通信コストO(len・nlogn+mn)ビットで実行できる。
配列[[A]]=([[a0]],...,[[an-1]])を、ソート済みの配列の配列とする。このとき、同一データに対するランク付け操作を下記のように表す。
ただし、[[B]]=([[b0]],...,[[bn-1]])であり、各biは以下を満たす:
・b0=1
・全てのi∈{1,...,n‐1}において、ai-1≠aiならばbi=1
・全てのi∈{1,...,n‐1}において、ai-1=aiならばbi=bi-1+1
具体的に、例えばA=(0,0,0,0,1,1,2,2,2)のとき、B=(1,2,3,4,1,2,1,2,3)となる。参考文献[1]に開示されているRange Prefix Sumを用いれば、この操作を通信コストO(nlogn)で実行できる。
値a,sをそれぞれ、擬似ランダム関数の入力及び秘密鍵であるとする。秘匿値[[a]],[[s]]に対し、秘密の疑似ランダム値を計算する操作を以下のように表す。
aのビット長をlenとすると、この秘密計算処理は例えば参考文献[2]の技術を用いて通信コストO(len)で実現できる。
値a,sをそれぞれ、ブロック暗号の平文及び秘密鍵であるとする。秘匿値[[a]],[[s]]に対し、秘密計算により暗号文を生成する操作を以下のように表す。
aのビット長をlenとすると、この秘密計算処理は参考文献[2]の技術を用いて通信コストO(len)で実現できる。
まず、実施例1を説明する。本実施例1では、サーバ100が、データ格納部140に格納されているキーkiとフラグeiからなるデータai=(ki,ei)を用いて秘匿ハッシュテーブルを構築する方法を示す。キーkiはデータ毎に固有の識別子であり、アクセスの際などにデータを一意に特定する目的に用いる。
S101において、サーバ100は、[[A]]に対してシャッフルを行い[[A]]←Shuffle([[A]])とする。ただしこの操作は、入力となる[[A]]の状態や満たすべき安全性によっては実行しなくてもよいものとする。
S102において、サーバ100は、[[A]]に対して、格納先データ配列[[ADDR]]=(([[addr0 0]],[[addr1 0]],[[e0]],[[rank0 0]],[[rank1 0]]),...,([[addr0 n-1]],[[addr1 n-1]],[[en-1]],[[rank0 n-1]],[[rank1 n-1]]))を計算する。
S103において、サーバ100は、ダミーの格納先データ配列[[ADDRd]]=([[d0]],...,[[dBZ-1]]);di=(floor(i/Z),floor(i/Z),1,0,0)を生成する。
S104において、サーバ100は、ダミーのデータ列[[Ad]]=([[ad 0]],...,[[ad BZ-1]]);ad i=(dummy,1)を生成する。ただし、ここでdummyは予め定めておいた、いずれのキーkiとも異なる値であるとする。この[[Ad]]を実データ列[[A]]の末尾に連結し、長さn+BZの配列[[A′]]=[[A]]||[[Ad]]とする。
S105において、サーバ100はまず、1番目のアドレス値addr0 iとフラグeiに基づいてデータ配列と格納先データ配列のそれぞれのソートを行う。すなわち、[[A′]]←Sort([[ADDR′.pos0]],[[A′]])、及び[[ADDR′]]←Sort([[ADDR′.pos0]],[[ADDR′]])を計算する。
S106において、サーバ100は、ソート済みのアドレス値に基づきランク付けを行う。すなわち、[[ADDR′.rank0]]←Rank([[ADDR′.addr0]])を計算する。
S107において、サーバ100は、データ配列及び格納先データ配列を、1番目のランクに基づき降順でソートする。すなわち、[[A′]]←Sort([[ADDR′.rank0]],[[A′]])及び[[ADDR′]]←Sort([[ADDR′.rank0]],[[ADDR′]])を、rank0 iが大きい順に並ぶよう計算する。なお、この操作は単に各配列を昇順でソートしたうえ、逆順に並べ替えることでも同様に実現できる。
S108において、サーバ100は、S105での処理と同様に、今度は2番目のアドレス値addr1 iとフラグに基づいてソートを行う。すなわち、[[A′]]←Sort([[ADDR′.pos1]],[[A′]])及び[[ADDR′]]←Sort([[ADDR′.pos1]],[[ADDR′]])を計算する。この時、安定ソートを用いれば、同アドレス値においては実データ>ダミーデータかつ高ランク>低ランクの順で並べ替えることができている。
S109において、サーバ100は、S106での処理と同様に、2番目のソート済みアドレス値に基づきランク付けを行う。すなわち、[[ADDR′.rank1]]←Rank([[ADDR′.addr1]])を計算する。
S110において、サーバ100は、格納先データ配列[[ADDR′]]の各要素[[bi]]=([[addr0 i]],[[addr1 i]],[[ei]],[[rank0 i]],[[rank1 i]])について、それぞれランクの低い側のアドレス値を抽出する。すなわち、大小比較[[zi]]←[[[rank0 i]]≦?[[rank1 i]]]に基づき、[[addri]]←[[addr1 i]]+[[zi]]×([[addr0 i]]‐[[addr1 i]])を計算する。その後、選ばれたアドレス値とフラグを併せた配列[[ADDRfin]]=(([[addr0]],[[e0]]),...,([[addrn+BZ-1]],[[en+BZ-1]]))を計算する。
S111において、サーバ100は、新たに得た配列[[ADDRfin]]に基づき、各データを昇順でソートする。すなわち、[[A′]]←Sort([[ADDRfin]],[[A′]])及び[[ADDRfin]]←Sort([[ADDRfin]],[[ADDRfin]])を計算する。
S112において、サーバ100は、[[ADDRfin]]のアドレス値部分のみを抽出した配列[[ADDRfin.addr]]を用いて、ランク配列[[R]]=Rank([[ADDRfin.addr]])を計算し、さらに[[R]]の各要素[[ri]]に対して大小比較[[yi]]←[[[ri]]≦?Z]を計算した結果の配列[[Y]]=([[y0]],...,[[yn+BZ-1]])を得る。このとき、yi=1のデータはテーブルに格納され、yi=0のデータは削除されることを示している。
S113において、サーバ100は、[[Y]]を用いてデータ配列を昇順でソートする。すなわち、[[A′]]←Sort([[Y]],[[A′]])を計算する。その後、末尾のBZ個の要素のみをハッシュテーブルとして出力し、その他は削除する。また、ハッシュテーブルに付随するアクセス用情報として2つの秘密鍵[[s0]],[[s1]]も出力する。
次に、実施例2を説明する。本実施例2では、実施例1と同等のテーブル構築を、より効率的に行う方法を示す。実施例1では、常に格納先データ配列と共にデータ配列[[A]](ないし[[A′]])がソートされており、単にソート回数が増していた他、仮にキーとフラグに対して大きなデータviが付与されていた場合、データ配列のソートのために効率悪化を招く可能性もあった。
S201において、サーバ100は、実施例1のS101と同様に、[[A]]に対してシャッフルを行い[[A]]←Shuffle([[A]])とする。ただしこの操作は、入力となる[[A]]の状態や満たすべき安全性によっては実行しなくてもよいものとする。
S202において、サーバ100は、秘匿化されたブロック暗号の秘密鍵[[s]]を生成し、[[A]]に対応する秘密のタグ配列[[Tag]]=([[tag0]],...,[[tagn-1]]);[[tagi]]←Enc([[i]],[[s]])を計算する。なお、秘密鍵[[s]]はプロトコルの開始以前に生成していても構わないとする。
S203において、サーバ100は、実施例1のS102と同様に、格納先データ配列[[ADDR]]=(([[addr0 0]],[[addr1 0]],[[e0]],[[rank0 0]],[[rank1 0]],[[tag0]]),...,([[addr0 n-1]],[[addr1 n-1]],[[en-1]],[[rank0 n-1]],[[rank1 n-1]],[[tagn-1]]))を計算する。実施例1とは、タグ[[tagi]]が含まれていることのみが異なる。
S204において、サーバ100は、実施例1のS103と同様に、ダミーの格納先データ配列[[ADDRd]]=([[d0]],...,[[dBZ-1]]);[[di]]=([[floor(i/Z)]],[[floor(i/Z)]],[[1]],[[0]],[[0]],[[tagd i]])を生成し、[[ADDR′]]=[[ADDR]]||[[ADDRd]]とする。ただし、[[tagd i]]←PRF([[n+i]],[[s]])であるとする。
S205において、サーバ100は、実施例1のS104と同様に、ダミーのデータ列[[Ad]]=([[ad 0]],...,[[ad BZ-1]]);ad i=(dummy,1)を生成し、[[A′]]=[[A]]||[[Ad]]とする。また、本実施例2のS204で計算したタグの列[[Tagd]]=([[tagd 0]],...,[[tagd BZ-1]])を用いて、[[Tag′]]←[[Tag]]||[[Tagd]]とする。
S206において、サーバ100は、配列[[A′]]及び[[Tag′]]の並び順を秘匿・ランダマイズするために、([[A′]],[[Tag′]])←Shuffle([[A′]],[[Tag′]])を計算する。この操作では、2つの配列の対応関係を保ったままランダマイズするため、並列に同じシャッフル処理を実行している。
S207において、サーバ100は、実施例1のS105~S113と同様の処理を行う。ただし、実施例2において、実施例1のS105~S112に対応する各手順においては配列[[A′]]には一切手を触れず格納先データ配列のみに操作を行うこととし、また、実施例1のS110に対応する手順で新たな格納先データ配列を得る際には[[ADDRfin]]の各要素を([[addri]],[[ei]],[[tagi]])として、タグ情報を引き継ぐようにする。
S208において、サーバ100は、実施例1のS112に対応する手順で得た[[Y]]を用いて[[ADDRfin]]を昇順でソートする。すなわち、[[ADDRfin]]←Sort([[Y]],[[ADDRfin]])を計算する。その後、末尾のBZ個の要素のみ残し、その他は削除する。
S209において、サーバ100は、タグ配列[[Tag′]]の全ての要素を復元し、平文に戻す。同時に、[[ADDRfin]]に含まれる全てのタグを復元し、平文に戻す。データ配列[[A′]]の中から、対応するタグが[[ADDRfin]]に含まれるような要素BZ個を取り出し、[[ADDRfin]]の並び順の通りに並べることでハッシュテーブルとする。最後にハッシュテーブルと秘密鍵[[s0]],[[s1]]を出力する。
次に、実施例3を説明する。実施例3では、実施例1、2で構築した秘匿ハッシュテーブルへのデータ参照方法について説明する。前提として、サーバ100は、実施例1ないし2で構築された秘匿ハッシュテーブル(サイズB×Z)と秘密鍵[[s0]]、[[s1]]をデータ格納部140に保持しているとする。また、ユーザ端末300はアクセスしたいキーkを持っているとするが、これはサーバ同士の合意に基づいてサーバ自身で選定しても構わない。以下、図6のフローチャートに示す手順に沿って説明する。
S301において、ユーザ端末300は、サーバ100に対し、アクセスしたいデータに対応するキーの秘匿値[[k]]を送る。ただし、この秘匿キー値はユーザ端末300からサーバ100への要求だけでなく、サーバ間合意に基づくサーバ自身による生成も可能である。
S302において、サーバ100は、疑似ランダム関数を用いて、2つのアドレス値[[addr0]]←PRF([[k]],[[s0]]),[[addr1]]←PRF([[k]],[[s1]])を計算し、これを復元してaddr0,addr1を得る。
S303において、サーバ100は、データ格納部140に格納されているハッシュテーブルからaddr0、addr1に対応する2Z個の要素を取り出す。すなわち、ハッシュテーブルを配列[[Table]]=([[a0]],...,[[aBZ-1]])と読み替えた場合に、[[a]]=([[aZ×addr0]],...,[[aZ×addr0+Z-1]],[[aZ×addr1]],...,[[aZ×addr1+Z-1]])を取得する。
S304において、サーバ100は、[[a]]の各データ[[aj]]について、キーの比較を行い[[c]]=([[c0]],...,[[c2Z-1]]);[[cj]]=[[[kj]]=?[[k]]]を計算する。
S305において、サーバ100は、内積[[a]]←<[[a]],[[c]]>を計算し、これをユーザ端末300へ返送するか、又はサーバ間合意に基づき復元する。あるいは、これを復元せず、全く別の秘密計算処理に用いてもよい。
本実施例4では、実施例1、2で構築した秘匿ハッシュテーブルでのデータ削除方法を説明する。前提として、サーバ100は、実施例1ないし2で構築されたハッシュテーブル(サイズB×Z)と秘密鍵[[s0]],[[s1]]をデータ記憶部140に保持しているとする。また、ユーザは削除したいデータのキーkを持っているとするが、これはサーバ同士の合意に基づいてサーバ自身で選定しても構わない。以下、図7のフローチャートに示す手順に沿って説明する。
S401において、ユーザ端末300は、サーバ100に対し、削除したいキーの秘匿値[[k]]を送る。ただし、この秘匿キー値はユーザ端末300からサーバ100への要求だけでなく、サーバ間合意に基づくサーバ自身による生成も可能である。
S402において、サーバ100は、疑似ランダム関数を用いて、2つのアドレス値[[addr0]]←PRF([[k]],[[s0]]),[[addr1]]←PRF([[k]],[[s1]])を計算し、これを復元してaddr0,addr1を得る。
S403において、サーバ100は、データ格納部140に保持しているハッシュテーブルからaddr0、addr1に対応する2Z個の要素を取り出す。すなわち、ハッシュテーブルを配列[[Table]]=([[a0]],...,[[aBZ-1]])と読み替えた場合に、[[a]]=([[aZ×addr0]],...,[[aZ×addr0+Z-1]]、[[aZ×addr1]],...,[[aZ×addr1+Z-1]])を取得する。
S404において、サーバ100は、[[a]]の各データ[[aj]]について、キーの比較に基づきデータ([[k]],[[e]])の削除処理を行う。すなわち、全てのjに関して[[kj]]=[[kj]]+[[[kj]]=?[[k]]]×(dummy-[[kj]]),[[ej]]=[[ej]]+[[[kj]]=?[[k]]]を計算する。
最後に、サーバ100は[[a]]の各要素をハッシュテーブルの元の位置に上書きする。
本実施例4の通信量は実施例3と等価である。
本実施例5では、実施例1、2で構築したハッシュテーブルの解体・全データの抽出方法について説明する。前提として、サーバ100は実施例1ないし2で構築されたハッシュテーブル(サイズB×Z)をデータ格納部140に保持しているとする。以下、図8のフローチャートに示す手順に沿って説明する。
S501において、サーバ100は、ハッシュテーブルの全データを、そのフラグに基づき昇順でソートする。すなわち、テーブルを配列[[Table]]=([[a0]],...,[[aBZ-1]])と読み替え、またテーブルからフラグのみを抽出した配列を[[E]]=([[e0]],...,[[eBZ-1]])とした場合に、[[Table]]=Sort([[E]],[[Table]])とする。
S502において、サーバ100は、[[Table]]の先頭nデータを配列[[A]]とし、残りを削除する。
本実施の形態によれば、秘密計算を用いることでユーザとの通信を介さず秘匿ハッシュテーブルを構築できる。その際、ランク付けという秘密計算処理を利用することで、テーブル構築に必要な秘匿ソートの回数を大きく減らし、従来法よりも通信コストを大きく削減できる。
本明細書には、少なくとも下記各項の秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラムが開示されている。
(第1項)
キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築装置であって、
前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
演算部を備える秘匿ハッシュテーブル構築装置。
(第2項)
前記演算部は、前記実データ列における各データと前記ダミーのデータ列における各データとを示すタグを有するタグの列を使用することにより、前記実データ列と前記ダミーのデータ列とを連結した前記第2配列に対して、前記第4配列に基づくソート以外のソートを行うことなく、前記秘匿ハッシュテーブルを生成する
第1項に記載の秘匿ハッシュテーブル構築装置。
(第3項)
前記演算部は、アクセス対象のキー値から2つのアドレス値を計算し、前記秘匿ハッシュテーブルから、前記2つのアドレス値に対応する2Z個のデータを取得し、2Z個のデータのうち、前記キー値と同一のキー値を有するデータを返す
第1項又は第2項に記載の秘匿ハッシュテーブル構築装置。
(第4項)
前記演算部は、削除対象のキー値から2つのアドレス値を計算し、前記秘匿ハッシュテーブルから、前記2つのアドレス値に対応する2Z個のデータを取得し、2Z個のデータのデータのうち、前記キー値と同一のキー値を有するデータを削除する
第1項ないし第3項のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置。
(第5項)
前記演算部は、前記秘匿ハッシュテーブルにおける全データを、そのフラグに基づいてソートし、先頭の所定個数のデータを前記実データ列として取得する
第1項ないし第4項のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置。
(第6項)
キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築システムであって、
前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
演算部を備える秘匿ハッシュテーブル構築システム。
(第7項)
キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築システムが実行する秘匿ハッシュテーブル構築方法であって、
前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成するステップと、
前記実データ列とダミーのデータ列とを連結した第2配列を生成するステップと、
前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートするステップと、
前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行うステップと、
前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成するステップと、
前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力するステップと
を備える秘匿ハッシュテーブル構築方法。
(第8項)
コンピュータを、第1項ないし第5項のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置における演算部として機能させるためのプログラム。
[1] T-H. H. Chan, Y. Guo, W-K. Lin, and E. Shi. Oblivious hashing revisited, and applications to asymptotically efficient ORAM and OPRAM. Cryptology ePrint Archive, Report 2017/924, 2017.
[2] K. Chida, K. Hamada, D. Ikarashi, R. Kikuchi, and B. Pinkas. High-throughput secure AES computation. In WAHC@CCS 2018, pages 13-24, 2018.
[3] K. Chida, K. Hamada, D. Ikarashi, R. Kikuchi, N. Kiribuchi, B. Pinkas. Anefficient secure threeparty sorting protocol with an honest majority. CryptologyePrint Archive, Report 2019/695 (2019), https://eprint.iacr.org/2019/695
[4] O. Goldreich and R. Ostrovsky. Software protection and simulation on oblivious RAMs. J. ACM, 43(3):431-473, May 1996. 8
[5] M. Ito, A. Saito, and T. Nishizeki. Secret sharing schemes realizing general access structures. Proceedings of the IEEE Global Telecommunication Conference, Globecom 87, pp. 99-102, 1987.
[6] A. Shamir. How to share a secret. Commun. ACM, Vol. 22, No. 11, pp. 612-613, 1979.
[7] 桐淵直人,五十嵐大,濱田浩気,菊池亮.プログラマブルな秘密計算ライブラリMEVAL3.暗号と情報セキュリティシンポジウム(SCIS)2018 予稿集(2018).
110 入力部
120 演算部
130 出力部
140 データ格納部
200 通信ネットワーク
300 ユーザ端末
1000 ドライブ装置
1001 記録媒体
1002 補助記憶装置
1003 メモリ装置
1004 CPU
1005 インタフェース装置
1006 表示装置
1007 入力装置
Claims (8)
- キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築装置であって、
前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
演算部を備える秘匿ハッシュテーブル構築装置。 - 前記演算部は、前記実データ列における各データと前記ダミーのデータ列における各データとを示すタグを有するタグの列を使用することにより、前記実データ列と前記ダミーのデータ列とを連結した前記第2配列に対して、前記第4配列に基づくソート以外のソートを行うことなく、前記秘匿ハッシュテーブルを生成する
請求項1に記載の秘匿ハッシュテーブル構築装置。 - 前記演算部は、アクセス対象のキー値から2つのアドレス値を計算し、前記秘匿ハッシュテーブルから、前記2つのアドレス値に対応する2Z個のデータを取得し、2Z個のデータのうち、前記キー値と同一のキー値を有するデータを返す
請求項1又は2に記載の秘匿ハッシュテーブル構築装置。 - 前記演算部は、削除対象のキー値から2つのアドレス値を計算し、前記秘匿ハッシュテーブルから、前記2つのアドレス値に対応する2Z個のデータを取得し、2Z個のデータのデータのうち、前記キー値と同一のキー値を有するデータを削除する
請求項1ないし3のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置。 - 前記演算部は、前記秘匿ハッシュテーブルにおける全データを、そのフラグに基づいてソートし、先頭の所定個数のデータを前記実データ列として取得する
請求項1ないし4のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置。 - キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築システムであって、
前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
演算部を備える秘匿ハッシュテーブル構築システム。 - キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築システムが実行する秘匿ハッシュテーブル構築方法であって、
前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成するステップと、
前記実データ列とダミーのデータ列とを連結した第2配列を生成するステップと、
前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートするステップと、
前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行うステップと、
前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成するステップと、
前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力するステップと
を備える秘匿ハッシュテーブル構築方法。 - コンピュータを、請求項1ないし5のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置における演算部として機能させるためのプログラム。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2022567986A JP7505583B2 (ja) | 2020-12-10 | 2020-12-10 | 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム |
| PCT/JP2020/046125 WO2022123744A1 (ja) | 2020-12-10 | 2020-12-10 | 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム |
| US18/255,928 US12189594B2 (en) | 2020-12-10 | 2020-12-10 | Secret hash table construction apparatus, secret hash table construction system, secret hash table construction method and program |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2020/046125 WO2022123744A1 (ja) | 2020-12-10 | 2020-12-10 | 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022123744A1 true WO2022123744A1 (ja) | 2022-06-16 |
Family
ID=81973434
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2020/046125 Ceased WO2022123744A1 (ja) | 2020-12-10 | 2020-12-10 | 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US12189594B2 (ja) |
| JP (1) | JP7505583B2 (ja) |
| WO (1) | WO2022123744A1 (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2024176307A1 (ja) * | 2023-02-20 | 2024-08-29 | 日本電信電話株式会社 | データ管理システム、方法、及びプログラム |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12333039B2 (en) * | 2020-01-16 | 2025-06-17 | Nippon Telegraph And Telephone Corporation | Secret hash table construction system, reference system, methods for the same |
| CN118069742B (zh) * | 2024-02-22 | 2025-06-27 | 北京火山引擎科技有限公司 | 数据处理方法、装置、电子设备、存储介质及产品 |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7017162B2 (en) * | 2001-07-10 | 2006-03-21 | Microsoft Corporation | Application program interface for network software platform |
| US8468244B2 (en) * | 2007-01-05 | 2013-06-18 | Digital Doors, Inc. | Digital information infrastructure and method for security designated data and with granular data stores |
| US9141823B2 (en) * | 2013-03-15 | 2015-09-22 | Veridicom, Sa De Cv | Abstraction layer for default encryption with orthogonal encryption logic session object; and automated authentication, with a method for online litigation |
| EP3392864B1 (en) * | 2015-12-14 | 2020-10-28 | Hitachi, Ltd. | Data processing system and data processing method |
| US12333039B2 (en) * | 2020-01-16 | 2025-06-17 | Nippon Telegraph And Telephone Corporation | Secret hash table construction system, reference system, methods for the same |
-
2020
- 2020-12-10 JP JP2022567986A patent/JP7505583B2/ja active Active
- 2020-12-10 US US18/255,928 patent/US12189594B2/en active Active
- 2020-12-10 WO PCT/JP2020/046125 patent/WO2022123744A1/ja not_active Ceased
Non-Patent Citations (3)
| Title |
|---|
| ASHAROV, G. ET AL.: "OptORAMa: Optimal Oblivious RAM", CRYPTOLOGY EPRINT ARCHIVE: REPORT 2018/892, VER. 20191012 :17480 9, 12 October 2019 (2019-10-12), pages 1 - 71, XP055944968, Retrieved from the Internet <URL:https://eprint.iacr.org/2018/892> * |
| CHAN, T-H. H. ET AL.: "Perfectly Secure Oblivious Parallel RAM", CRYPTOLOGY EPRINT ARCHIVE: REPORT 2018/364, VER . 20181002 :155559, 2 October 2018 (2018-10-02), pages 1 - 54, XP061027284, Retrieved from the Internet <URL:https://eprint.iacr.org/2018/364> * |
| KUSHILEVITZ, E. ET AL., S UB-LOGARITHMIC DISTRIBUTED OBLIVIOUS RAM WITH SMALL BLOCK SIZE, vol. 3, 17 November 2018 (2018-11-17), pages 1 - 42, Retrieved from the Internet <URL:https://arxiv.org/abs/1802.05145>> * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2024176307A1 (ja) * | 2023-02-20 | 2024-08-29 | 日本電信電話株式会社 | データ管理システム、方法、及びプログラム |
Also Published As
| Publication number | Publication date |
|---|---|
| JP7505583B2 (ja) | 2024-06-25 |
| US12189594B2 (en) | 2025-01-07 |
| JPWO2022123744A1 (ja) | 2022-06-16 |
| US20240028576A1 (en) | 2024-01-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11843687B2 (en) | Systems, devices, and processes for homomorphic encryption | |
| Pornin et al. | More efficient algorithms for the NTRU key generation using the field norm | |
| JP6693508B2 (ja) | 秘密計算システム、サーバ装置、秘密計算方法、および、プログラム | |
| KR102550812B1 (ko) | 동형 암호를 이용한 암호문 비교 방법 및 이를 수행하기 위한 장치 | |
| Baldimtsi et al. | Sorting and searching behind the curtain | |
| CN107077469B (zh) | 服务器装置、检索系统、终端装置以及检索方法 | |
| Chida et al. | An efficient secure three-party sorting protocol with an honest majority | |
| US12333039B2 (en) | Secret hash table construction system, reference system, methods for the same | |
| Grassi et al. | From farfalle to megafono via ciminion: The PRF hydra for MPC applications | |
| Jayapandian et al. | Secure and efficient online data storage and sharing over cloud environment using probabilistic with homomorphic encryption | |
| JP7505583B2 (ja) | 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム | |
| JPWO2016148281A1 (ja) | 秘匿文字列計算システム及び方法と装置並びにプログラム | |
| Hoang | A novel structure of fast and efficient multiple image encryption | |
| Shi et al. | Exploiting non-full key additions: full-fledged automatic Demirci-Selcuk meet-in-the-middle cryptanalysis of skinny | |
| Liu et al. | Efficient dynamic multi-client searchable encryption supporting fuzzy search | |
| JPWO2020145340A1 (ja) | 秘密配列アクセス装置、秘密配列アクセス方法、およびプログラム | |
| El Hanouti et al. | A lightweight hash function for cryptographic and pseudo-cryptographic applications | |
| WO2020152831A1 (ja) | 情報処理装置、秘密計算方法及びプログラム | |
| Bambury et al. | Cryptanalysis of an efficient signature based on isotropic quadratic forms | |
| JPWO2016113878A1 (ja) | 秘匿検索システム、秘匿検索プログラム及び変換後検索鍵生成装置 | |
| CN118332159A (zh) | 保护隐私的数值范围查询方法、索引构建方法及装置 | |
| Alekseychuk et al. | Cryptographic properties of a new national encryption standard of Ukraine | |
| JP6693503B2 (ja) | 秘匿検索システム、サーバ装置、秘匿検索方法、検索方法、およびプログラム | |
| Liang et al. | A Framework of Private Set Intersection Protocols. | |
| Lau et al. | A new encryption scheme based on rank metric codes |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20965126 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2022567986 Country of ref document: JP Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18255928 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20965126 Country of ref document: EP Kind code of ref document: A1 |