WO2022123744A1 - 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム - Google Patents

秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム Download PDF

Info

Publication number
WO2022123744A1
WO2022123744A1 PCT/JP2020/046125 JP2020046125W WO2022123744A1 WO 2022123744 A1 WO2022123744 A1 WO 2022123744A1 JP 2020046125 W JP2020046125 W JP 2020046125W WO 2022123744 A1 WO2022123744 A1 WO 2022123744A1
Authority
WO
WIPO (PCT)
Prior art keywords
array
data
address value
hash table
secret
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2020/046125
Other languages
English (en)
French (fr)
Inventor
敦謙 市川
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NTT Inc
Original Assignee
Nippon Telegraph and Telephone Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nippon Telegraph and Telephone Corp filed Critical Nippon Telegraph and Telephone Corp
Priority to JP2022567986A priority Critical patent/JP7505583B2/ja
Priority to PCT/JP2020/046125 priority patent/WO2022123744A1/ja
Priority to US18/255,928 priority patent/US12189594B2/en
Publication of WO2022123744A1 publication Critical patent/WO2022123744A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
    • G06F16/22—Indexing; Data structures therefor; Storage structures
    • G06F16/2228—Indexing structures
    • G06F16/2255—Hash tables
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60—Protecting data
    • G06F21/602—Providing cryptographic facilities or services
    • G—PHYSICS
    • G09—EDUCATION; CRYPTOGRAPHY; DISPLAY; ADVERTISING; SEALS
    • G09C—CIPHERING OR DECIPHERING APPARATUS FOR CRYPTOGRAPHIC OR OTHER PURPOSES INVOLVING THE NEED FOR SECRECY
    • G09C1/00—Apparatus or methods whereby a given sequence of signs, e.g. an intelligible text, is transformed into an unintelligible sequence of signs by transposing the signs or groups of signs or by replacing them by others according to a predetermined system

Definitions

  • the present invention relates to a secret calculation, and particularly to an operation in which the order of an array is concealed.
  • the hash table is a data structure for high-speed data retrieval based on the key value by encoding the key value of the data with a hash function or the like and associating it with the address value in the data array. This is useful, for example, when data is stored in an external server or the like and it is desired to perform a search by a key value at any time.
  • ordinary hash tables do not assume data concealment, and there is a problem that, for example, a server entrusted with data (or hash table) by a user can identify the table structure and thereby observe the user's access tendency. be.
  • a secret hash table for example, reference [4, 1]
  • Reference names are listed at the end of the specification.
  • the secret hash table is a technique for constructing a hash table while keeping the table structure secret from the server, and it is possible to hide the user's access tendency to the server.
  • a method of constructing a secret hash table is a method in which the user encrypts all data at hand, constructs a hash table, and entrusts it to a server. In this case, the user's storage area is stored for the number of data n. O (n) is required.
  • References [4] and [1] mentioned above are methods for constructing a concealed hash table on a server by a user-server cooperative protocol on the assumption that the server has all the encrypted data. It has the advantage that O (1) is sufficient for the storage area of the user.
  • Non-Patent Document 1 shows a method of constructing a secret hash table by secret calculation using multiple servers without requiring any communication between users and servers. Therefore, the communication environment and calculation of the user terminal are shown. Stable performance can be achieved regardless of performance.
  • the secret hash method called "Oblivius Greedy Hashing” is stored in two different address values (that is, at which position in the table) for each data to be stored.
  • By giving (a value indicating whether or not it should be) a table construction algorithm is realized in which each data is stored in the more vacant of the two storage destinations. This has the advantage that the table size can be kept small compared to other existing methods.
  • the present invention has been made in view of the above points, and an object of the present invention is to provide a technique for constructing a secret hash table without increasing the amount of communication while reducing the table size.
  • up to Z data can be added to each of the B address values by secret calculation.
  • It is a secret hash table construction device that builds a secret hash table that can be stored.
  • a storage destination data array including a first address value and a second address value, a flag, and a rank for each address value for each data in the actual data string, and a first address value and a second address value as dummies.
  • a second array in which the actual data string and the dummy data string are concatenated is generated.
  • a ranking operation for the same data with respect to the first address value of the first array sorted by sorting each of the first array and the second array based on the first address value and the flag in the first array. And sort each of the first sequence and the second sequence based on the ranking.
  • a ranking operation for the same data with respect to the second address value of the first array sorted by sorting each of the first array and the second array based on the second address value and the flag in the first array. And In the first array, the address value on the lower rank side of the first address value and the second address value is extracted, and a third array having the extracted address value and the flag is generated.
  • the second sequence was sorted using the fourth sequence obtained by comparing each element of the rank array calculated from the address values in the third sequence with Z, and the BZ pieces in the sorted second sequence.
  • a secret hash table construction device including an arithmetic unit that outputs elements as the secret hash table is provided.
  • a technique for constructing a secret hash table without increasing the amount of communication while reducing the table size is provided.
  • FIG. 1 It is a block diagram of a secret hash table construction system. It is a functional block diagram of a server. It is a figure which shows the hardware configuration example of the apparatus. It is a flowchart which shows the processing procedure of Example 1.
  • FIG. 2 It is a flowchart which shows the processing procedure of Example 2.
  • FIG. 3 It is a flowchart which shows the processing procedure of Example 4.
  • FIG. 1 shows a configuration example of a secret hash table construction system according to the present embodiment.
  • the secret hash table construction system of the present embodiment has a configuration in which a plurality of servers 100-1 to 100-N are provided in 200 on a communication network.
  • Each server is a computer.
  • the computer may be a physical machine or a virtual machine provided by the cloud.
  • the user terminal 300 shown in FIG. 1 accesses the secret hash table construction system and acquires, for example, the data corresponding to the key.
  • the process related to the construction of the secret hash table is executed by the secret calculation by the cooperative protocol between these plurality of servers 100-1 to 100-N.
  • the use of a cooperative protocol of a plurality of servers is an example, and the present invention is not limited thereto.
  • the present invention is applicable to any technique capable of performing secret calculations. For example, if one server can perform secret calculations, it is also possible to execute the technique according to the present invention on that server.
  • FIG. 2 shows a configuration example of the server 100.
  • the configuration example of the server 100 shown in FIG. 2 is the configuration when a plurality of servers 100-1 to 100-N are virtually regarded as one server.
  • the server 100 shown in FIG. 2 may be called a secret hash table construction system.
  • the server 100 may be referred to as a secret hash table construction device.
  • the server may be the server 100 shown in FIG.
  • the server 100 has an input unit 110, a calculation unit 120, an output unit 130, and a data storage unit 140.
  • the arithmetic unit 120 executes a process related to the construction and operation of the secret hash table.
  • the data storage unit 140 stores data prepared in advance for calculation, data such as a secret array during calculation, and a table.
  • the input unit 110 receives, for example, a request from the user terminal 300 and inputs the request.
  • the output unit 140 returns, for example, the calculation result for the request from the user terminal 300 to the user terminal 300.
  • the server 100 in the present embodiment can be realized by, for example, causing a computer to execute a program describing the processing contents described in the present embodiment.
  • the "computer” may be a physical machine or a virtual machine on the cloud.
  • the "hardware” described here is virtual hardware.
  • the above program can be recorded on a computer-readable recording medium (portable memory, etc.), saved, and distributed. It is also possible to provide the above program through a network such as the Internet or e-mail.
  • FIG. 3 is a diagram showing an example of the hardware configuration of the above computer.
  • the computer of FIG. 3 has a drive device 1000, an auxiliary storage device 1002, a memory device 1003, a CPU 1004, an interface device 1005, a display device 1006, an input device 1007, an output device 1008, and the like, which are connected to each other by a bus B, respectively.
  • the program that realizes the processing on the computer is provided by, for example, a recording medium 1001 such as a CD-ROM or a memory card.
  • a recording medium 1001 such as a CD-ROM or a memory card.
  • the program is installed in the auxiliary storage device 1002 from the recording medium 1001 via the drive device 1000.
  • the program does not necessarily have to be installed from the recording medium 1001, and may be downloaded from another computer via the network.
  • the auxiliary storage device 1002 stores the installed program and also stores necessary files, data, and the like.
  • the memory device 1003 reads and stores the program from the auxiliary storage device 1002 when the program is instructed to start.
  • the CPU 1004 realizes the function related to the server 100 according to the program stored in the memory device 1003.
  • the interface device 1005 is used as an interface for connecting to a network.
  • the display device 1006 displays a GUI (Graphical User Interface) or the like by a program.
  • the input device 1007 is composed of a keyboard, a mouse, buttons, a touch panel, and the like, and is used for inputting various operation instructions.
  • the output device 1008 outputs the calculation result.
  • the concealed value of the value x is referred to as [[x]]
  • the process x ⁇ [[x]] is referred to as concealment of x
  • [[x]] ⁇ x is referred to as restoration of x.
  • the secret sharing method references [6, 5]
  • Any concealment / restoration processing technique may be used.
  • the comparison operation can be executed with the communication cost O (len) bit in the technique of reference [7].
  • the following processing is executed by the arithmetic unit 120 of the server 100. Further, the data prepared in advance, the array obtained by the calculation, the table, etc. are stored in the data storage unit 140.
  • the calculation unit 120 performs an operation on the data read from the data storage unit 140, and proceeds with the process while repeating storing the operation result in the data storage unit 140.
  • Example 1 First, Example 1 will be described.
  • the key ki is an identifier unique to each data, and is used for the purpose of uniquely specifying the data at the time of access or the like.
  • the flag e i is a 1-bit value for determining whether or not the data is a dummy.
  • the bit length of ki ceil (logn) at the minimum, but redundancy may be acceptable.
  • the secret hash table constructed in the first embodiment is a data array of size B ⁇ Z, and is a data structure capable of storing up to Z data in each of the address values of B streets if expressed differently. And. Further, it is assumed that the pseudo-random function used in the first embodiment satisfies PRF ([[k]], [[s]]) ⁇ ⁇ 0, ..., B-1 ⁇ .
  • the server 100 constructs a secret hash table by the process described below.
  • the process executed by the server 100 will be described according to the procedure of the flowchart of FIG.
  • step 101 the server 100 shuffles [[A]] and sets [[A]] ⁇ Shuffle ([[A]]). However, this operation may not be performed depending on the state of the input [[A]] and the safety to be satisfied.
  • [[addr p i ]] ⁇ PRF ([[ki]], [[sp]]); i ⁇ ⁇ 0, ..., n-1 ⁇ , p ⁇ ⁇ 0, 1 ⁇ . Also, it is initialized as [[rank pi ]] ⁇ [[ 0 ]].
  • ADDR ((3,1,0,0,0), It becomes an array (an array of n data) such as (18,95,0,0,0), ..., (8,78,0,0,0)).
  • ADDR ((3,1,0,0,0)
  • n data an array of n data
  • the explanation may be given without [[]] as appropriate.
  • ADDR' ((3,1,0,0,0), (18,95,0,0,0), ..., (8,78, 0,0,0), (0,0,1,0,0), (0,0,1,0,0), ..., (8,8,1,0,0)) (An array of n + BZ data).
  • the notation [[ADDR'. [[ADDR']] is an array obtained by extracting only the first address value [[addr 0 i ]] from [[ADDR']] ([[addr 0 0 ]], ..., [[addr 0 n + BZ-1 ] ]. ]])).
  • the notation [[ADDR'. addr 1 ]], [[ADDR'. rank 0 ]], [[ADDR'. Rank 1 ]] is defined as an array obtained by extracting [[addr 1 i ]], [[rank 0 i ]], and [[rank 1 i ]] from [[ADDR']], respectively.
  • ADDR' ((3,1,0,0,0), (18,95,0,0,0), ..., (8,78,0,0,0), ( 0,0,1,0,0), (0,0,1,0,0), ..., (8,8,1,0,0)), ADDR'.
  • pos 0 ((3,0), (18,0), ..., (8,0), (0,1), (0,1), ..., (8) , 1)).
  • the dimmy is a predetermined value different from any key ki.
  • the server 100 first sorts the data array and the storage destination data array based on the first address value addr 0 i and the flag e i . That is, [[A']] ⁇ Sort ([[ADDR'. Pos 0 ]], [[A']]), and [[ADDR']] ⁇ Sort ([[ADDR'. Pos 0 ]]], [ [ADDR']]) is calculated.
  • the data array and the storage destination data array shall be sorted in ascending order by address value and in the order of actual data> dummy data at the same address value, but the subsequent sorting and ascending / descending order of ranking shall be adjusted. You can also change the sort order by doing this.
  • ⁇ S106> the server 100 ranks based on the sorted address values. That is, [[ADDR'. rank 0 ]] ⁇ Rank ([[ADDR'.addr 0 ]]) is calculated.
  • ADDR'. rank 0 is, for example, ADDR'.
  • Rank 0 (1,2,3,4 ...., 1,2,3, ..., 1,2,3,4,5) is an array (an array of n + BZ data). ..
  • the server 100 sorts the data array and the storage destination data array in descending order based on the first rank. That is, [[A']] ⁇ Sort ([[ADDR'.rank 0 ]], [[A']]) and [[ADDR']] ⁇ Sort ([[ADDR'.rank 0 ]], [[ ADDR']]) is calculated so that rank 0 i is arranged in descending order. Note that this operation can be similarly realized by simply sorting each array in ascending order and then sorting them in reverse order.
  • the server 100 sorts based on the second address value addr 1 i and the flag, as in the process in S105. That is, [[A']] ⁇ Sort ([[ADDR'. Pos 1 ]], [[A']]) and [[ADDR']] ⁇ Sort ([[ADDR'. Pos 1 ]]], [[ ADDR']])) is calculated. At this time, if stable sorting is used, the same address value can be sorted in the order of actual data> dummy data and high rank> low rank.
  • ⁇ S109> the server 100 ranks based on the second sorted address value, as in the process in S106. That is, [[ADDR'. rank 1 ]] ⁇ Rank ([[ADDR'.addr 1 ]]) is calculated.
  • the server 100 sorts each data in ascending order based on the newly obtained array [[ADDR fin ]]. That is, [[A']] ⁇ Sort ([[ADDR fin ]], [[A']]) and [[ADDR fin ]] ⁇ Sort ([[ADDR fin ]], [[ADDR fin ]]). calculate.
  • the server 100 sorts the data array in ascending order using [[Y]]. That is, [[A']] ⁇ Sort ([[Y]], [[A']]) is calculated. After that, only the last BZ elements are output as a hash table, and the others are deleted. In addition, two private keys [[s 0 ]] and [[s 1 ]] are also output as access information attached to the hash table.
  • Example 2 a method of constructing a table equivalent to that of the first embodiment will be shown more efficiently.
  • the data array [[A]] (or [[A']]) is always sorted together with the storage destination data array, the number of sorts is simply increased, and the key and the flag are assumed to be large. If the data vi was added, there was a possibility that the efficiency would be deteriorated due to the sorting of the data array.
  • the algorithm of the first embodiment is followed in principle, but the number of sorts is reduced by using the encryption in the secret calculation, and the secret hash table is constructed as follows.
  • the procedure of the flowchart of FIG. 5 will be described.
  • the private key [[s]] may be generated before the start of the protocol.
  • the only difference from the first embodiment is that the tag [[tag i ]] is included.
  • tag sequence [[Tag d ]] ([[tag d 0 ]], ..., [[tag d BZ-1 ]]) calculated in S204 of the second embodiment, [[[[ Tag']] ⁇ [[Tag]]
  • ⁇ S206> the server 100 conceals and randomizes the order of the arrays [[A']] and [[Tag']] ([[A']], [[Tag']]) ⁇ Shuffle ( [[A']], [[Tag']]) are calculated. In this operation, the same shuffle process is executed in parallel in order to randomize while maintaining the correspondence between the two arrays.
  • ⁇ S207> the server 100 performs the same processing as in S105 to S113 of the first embodiment.
  • the operation is performed only on the storage destination data array without touching the array [[A']] at all.
  • each element of [[ADDR fin ]] is changed to ([[addr i ]], [[e i ]], [[tag i ]]. ]) To take over the tag information.
  • the server 100 sorts [[ADDR fin ]] in ascending order using [[Y]] obtained in the procedure corresponding to S112 of Example 1. That is, [[ADDR fin ]] ⁇ Sort ([[Y]], [[ADDR fin ]]) is calculated. After that, only the last BZ elements are left, and the others are deleted.
  • ⁇ S209> the server 100 restores all the elements of the tag array [[Tag']] and returns them to plaintext. At the same time, all tags included in [[ADDR fin ]] are restored and returned to plain text. Hash table by extracting BZ elements whose corresponding tags are included in [[ADDR fin ]] from the data array [[A']] and arranging them in the order of [[ADDR fin ]]. And. Finally, the hash table and private key [[s 0 ]] and [[s 1 ]] are output.
  • Example 3 the data reference method to the secret hash table constructed in the first and second embodiments will be described.
  • the server 100 holds the secret hash table (size B ⁇ Z) constructed in Examples 1 and 2 and the secret keys [[s 0 ]] and [[s 1 ]] in the data storage unit 140.
  • the user terminal 300 has the key k to be accessed, but this may be selected by the server itself based on the agreement between the servers.
  • the procedure shown in the flowchart of FIG. 6 will be described.
  • the user terminal 300 sends the secret value [[k]] of the key corresponding to the data to be accessed to the server 100.
  • this secret key value can be generated not only by the request from the user terminal 300 to the server 100 but also by the server itself based on the agreement between the servers.
  • the server 100 uses a pseudo-random function to provide two address values [[addr 0 ]] ⁇ PRF ([[k]], [[s 0 ]]), [[addr 1 ]] ⁇ PRF ( [[K]], [[s 1 ]]) is calculated, and this is restored to obtain addr 0 and addr 1 .
  • the server 100 calculates the inner product [[a]] ⁇ ⁇ [[a]], [[c]]> and returns it to the user terminal 300 or restores it based on the agreement between the servers. Alternatively, this may not be restored and may be used for a completely different secret calculation process.
  • the communication amount between the user and the server is an O (logn) bit
  • the communication amount between the servers is an O (Zlogn) bit
  • Example 4 In the fourth embodiment, the data deletion method in the secret hash table constructed in the first and second embodiments will be described.
  • the server 100 holds the hash table (size B ⁇ Z) constructed in Examples 1 and 2 and the private keys [[s 0 ]] and [[s 1 ]] in the data storage unit 140. And. Further, it is assumed that the user has the key k of the data to be deleted, but this may be selected by the server itself based on the agreement between the servers.
  • the procedure shown in the flowchart of FIG. 7 will be described.
  • S401 the user terminal 300 sends the secret value [[k]] of the key to be deleted to the server 100.
  • this secret key value can be generated not only by the request from the user terminal 300 to the server 100 but also by the server itself based on the agreement between the servers.
  • the server 100 uses a pseudo-random function to provide two address values [[addr 0 ]] ⁇ PRF ([[k]], [[s 0 ]]), [[addr 1 ]] ⁇ PRF ( [[K]], [[s 1 ]]) is calculated, and this is restored to obtain addr 0 and addr 1 .
  • Example 5 In the fifth embodiment, a method of disassembling the hash table constructed in the first and second embodiments and extracting all the data will be described. As a premise, it is assumed that the server 100 holds the hash table (size B ⁇ Z) constructed in the first and second embodiments in the data storage unit 140. Hereinafter, the procedure shown in the flowchart of FIG. 8 will be described.
  • [[Table]] Sort ([[E]], [[Table]]).
  • ⁇ S502> the server 100 sets the first n data of [[Table]] into an array [[A]] and deletes the rest.
  • a secret hash table can be constructed without communication with the user by using the secret calculation.
  • the secret calculation process called ranking the number of secret sorts required for table construction can be greatly reduced, and the communication cost can be greatly reduced as compared with the conventional method.
  • the amount of communication between servers is changed from ⁇ (nlog 2.5 n) to O while maintaining the merit of the conventional method of reducing the table size by allocating two types of address values to each data. It can be reduced to (nlog 2 n). It is also possible to operate on the built table.
  • a secret hash table construction device that can store up to Z data in each B-style address value is constructed by secret calculation from an actual data string containing a plurality of data having a key and a flag indicating whether or not the data is a dummy. It is a secret hash table construction device that A storage destination data array including a first address value and a second address value, a flag, and a rank for each address value for each data in the actual data string, and a first address value and a second address value as dummies.
  • a first array that concatenates the flag and the storage destination data array including the rank for each address value.
  • a second array in which the actual data string and the dummy data string are concatenated is generated.
  • a ranking operation for the same data with respect to the first address value of the first array sorted by sorting each of the first array and the second array based on the first address value and the flag in the first array.
  • sort each of the first sequence and the second sequence based on the ranking.
  • a ranking operation for the same data with respect to the second address value of the first array sorted by sorting each of the first array and the second array based on the second address value and the flag in the first array.
  • a secret hash table construction device including an arithmetic unit that outputs elements as the secret hash table.
  • the calculation unit concatenates the actual data string and the dummy data string by using a tag column having a tag indicating each data in the actual data string and each data in the dummy data string.
  • the secret hash table construction device according to item 1, wherein the secret hash table is generated without performing a sort other than the sort based on the fourth array with respect to the second array.
  • the calculation unit calculates two address values from the key value to be accessed, acquires 2Z data corresponding to the two address values from the secret hash table, and of the 2Z data, the key.
  • the secret hash table construction device according to item 1 or 2, which returns data having the same key value as the value.
  • the calculation unit calculates two address values from the key value to be deleted, acquires 2Z data corresponding to the two address values from the secret hash table, and out of the 2Z data data.
  • the secret hash table construction device according to any one of the items 1 to 3 for deleting data having the same key value as the key value.
  • the calculation unit sorts all the data in the secret hash table based on the flag, and acquires the predetermined number of data at the beginning as the actual data string in any one of the first to fourth terms.
  • the described secret hash table construction device (Section 6) A secret hash table that can store up to Z data in each of the B address values is constructed by secret calculation from an actual data string containing a plurality of data having a key and a flag indicating whether or not the data is a dummy.
  • a storage destination data array including a first address value and a second address value, a flag, and a rank for each address value for each data in the actual data string, and a first address value and a second address value as dummies. And generate a first array that concatenates the flag and the storage destination data array including the rank for each address value.
  • a second array in which the actual data string and the dummy data string are concatenated is generated.
  • a ranking operation for the same data with respect to the first address value of the first array sorted by sorting each of the first array and the second array based on the first address value and the flag in the first array. And sort each of the first sequence and the second sequence based on the ranking.
  • a ranking operation for the same data with respect to the second address value of the first array sorted by sorting each of the first array and the second array based on the second address value and the flag in the first array. And In the first array, the address value on the lower rank side of the first address value and the second address value is extracted, and a third array having the extracted address value and the flag is generated. The second sequence was sorted using the fourth sequence obtained by comparing each element of the rank array calculated from the address values in the third sequence with Z, and the BZ pieces in the sorted second sequence.
  • a secret hash table construction system including an arithmetic unit that outputs elements as the secret hash table.
  • a secret hash table that can store up to Z data in each B-style address value is constructed by secret calculation from an actual data string containing multiple data having a key and a flag indicating whether the data is dummy or not. It is a secret hash table construction method executed by the secret hash table construction system.
  • a ranking operation for the same data with respect to the second address value of the first array sorted by sorting each of the first array and the second array based on the second address value and the flag in the first array.
  • the steps to do In the first array a step of extracting the address value on the lower rank side of the first address value and the second address value and generating a third array having the extracted address value and the flag.
  • the second sequence was sorted using the fourth sequence obtained by comparing each element of the rank array calculated from the address values in the third sequence with Z, and the BZ pieces in the sorted second sequence.
  • a method of constructing a secret hash table including a step of outputting an element as the secret hash table.
  • (Section 8) A program for causing a computer to function as an arithmetic unit in the secret hash table construction device according to any one of the items 1 to 5.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Databases & Information Systems (AREA)
  • Data Mining & Analysis (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
  • Storage Device Security (AREA)

Abstract

データを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築装置であって、前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、前記実データ列とダミーのデータ列とを連結した第2配列を生成し、アドレス値に対して同一データに対するランク付け操作を行って、当該ランク付けに基づいて、前記第1配列と前記第2配列から、前記秘匿ハッシュテーブルを構築する演算部を備える。

Description

秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム
 本発明は、秘密計算に関するものであり、特に配列の順序を秘匿した操作に関するものである。
 ハッシュテーブルは、データのキー値をハッシュ関数等により符号化しデータ配列におけるアドレス値との紐付けを行うことで、キー値に基づくデータ検索を高速で行うためのデータ構造である。これは例えば、外部サーバ等にデータを預け、随時キー値による検索を行いたい場合などに有用である。
 しかし、通常のハッシュテーブルはデータ秘匿を想定するものではなく、例えばユーザからデータ(ないしハッシュテーブル)を委託されたサーバがテーブル構造を識別でき、それによりユーザのアクセス傾向を観測しうるという問題がある。こうした問題を解決する既存の方法として、秘匿ハッシュテーブル(例えば、参考文献[4,1])がある。なお、参考文献名については、明細書の最後にまとめて記載した。秘匿ハッシュテーブルは、サーバに対してテーブル構造を秘匿したままでハッシュテーブルを構築させる技術であり、サーバに対してユーザのアクセス傾向を秘匿できる。
 秘匿ハッシュテーブル構築方法として自明に挙げられるのは、ユーザが全てのデータを手元で暗号化しハッシュテーブルを構築、サーバへ委託する方法であるが、この場合データ数nに対してユーザの記憶領域がO(n)必要となる。上記に挙げた参考文献[4]及び[1]は、全ての暗号化データをサーバが持っている前提で、ユーザ・サーバの協調プロトコルによってサーバ上に秘匿ハッシュテーブルを構築する方法であり、この時ユーザの記憶領域はO(1)で十分であるという利点を持つ。
 しかしながら、参考文献[4,1]の技術は秘匿ハッシュテーブル構築の際、ユーザ・サーバ間で非常に多くの通信を要するという課題がある。現実に、ユーザの通信環境や計算性能が必ずしも好条件であるとは限らないことからも、上記コストは可能な限り低減されることが望ましい。これを解決した方法の1つに、非特許文献1に開示された技術が挙げられる。この文献には、複数台のサーバを利用した秘密計算により、ユーザ・サーバ間での通信を一切要さずに秘匿ハッシュテーブルを構築する手法が示されており、そのためユーザ端末の通信環境や計算性能を問わず安定した性能を実現できる。
 特に、非特許文献1にて示される手法のうち"Oblivious Greedy Hashing"と呼ばれる秘匿ハッシュ法は、格納されるべき各データに対してそれぞれ2通りのアドレス値(すなわち、テーブルのどの位置に格納されるべきかを示す値)を与えることで、各データが2つの格納先のより空いている方へと格納されるようなテーブル構築アルゴリズムを実現している。これにより、他の既存手法に比較してテーブルサイズを小さく抑えられるといった利点がある。
市川敦謙,濱田浩気,菊池亮,五十嵐大.3 パーティ計算上の最適秘匿ハッシュと劣対数効率のOblivious RAM.暗号と情報セキュリティシンポジウム(SCIS)2020 予稿集(2020).
 非特許文献1に開示されているOblivious Greedy Hashingはテーブルサイズが小さく、参考文献[4,1]に開示の技術と違いユーザ・サーバ間での通信が不要であるといったメリットの一方で、テーブル構築の際、単純にシステム全体の通信量で比較した場合に非常に多くの通信を要する欠点もある。具体的には、nをテーブルに格納するデータの総数とすると、参考文献[4]や[1]の手法で秘匿ハッシュテーブルを構築する際にはO(nlog2n)ビットの通信を要するのに対し、Oblivious Greedy HashingはO(Z×nlog2n)ビットの通信が必要となる。ここで、Zとは方式の安全性にまつわるパラメータであり、非特許文献1ではZ=2logεnが例示されている。
 本発明は上記の点に鑑みてなされたものであり、テーブルサイズを小さくしつつ、通信量を増大させないで秘匿ハッシュテーブルを構築する技術を提供することを目的とする。
 開示の技術によれば、キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築装置であって、
 前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
 前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
 前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
 前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
 前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
 前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
 演算部を備える秘匿ハッシュテーブル構築装置が提供される。
 開示の技術によれば、テーブルサイズを小さくしつつ、通信量を増大させないで秘匿ハッシュテーブルを構築する技術が提供される。
秘匿ハッシュテーブル構築システムの構成図である。 サーバの機能構成図である。 装置のハードウェア構成例を示す図である。 実施例1の処理手順を示すフローチャートである。 実施例2の処理手順を示すフローチャートである。 実施例3の処理手順を示すフローチャートである。 実施例4の処理手順を示すフローチャートである。 実施例5の処理手順を示すフローチャートである。
 以下、図面を参照して本発明の実施の形態(本実施の形態)を説明する。以下で説明する実施の形態は一例に過ぎず、本発明が適用される実施の形態は、以下の実施の形態に限られるわけではない。
 (実施の形態の概要)
 本実施の形態では、複数台のサーバを用いてユーザ・サーバ間通信コストを削減した効率的な秘匿ハッシュテーブル構築方法、及び操作方法について説明する。本実施の形態に係る技術により、各データに2通りの格納先を付与することでOblivious Greedy Hashingと同等にテーブルサイズを小さく抑えつつも、サーバ間通信量O(nlog2n)ビットのみでテーブル構築が可能である。以下、本実施の形態のシステム構成、及び処理手順について詳細に説明する。
 (システム構成)
 図1に、本実施の形態における秘匿ハッシュテーブル構築システムの構成例を示す。図1に示すように、本実施の形態の秘匿ハッシュテーブル構築システムは、複数のサーバ100-1~100-Nが通信ネットワーク上200に備えられた構成を有する。各サーバはコンピュータである。当該コンピュータは物理マシンであってもよいし、クラウドにより提供される仮想マシンであってもよい。
 図1に示すユーザ端末300が、秘匿ハッシュテーブル構築システムにアクセスして、例えばキーに対応するデータを取得する。
 本実施の形態では、これら複数のサーバ100-1~100-N間の協調プロトコルにより秘密計算で秘匿ハッシュテーブル構築に係る処理を実行する。ただし、本発明の実施にあたって、複数サーバの協調プロトコルを使用することは例であり、これに限定されるわけではない。本発明は、秘密計算を行うことができるどのような技術にも適用可能である。例えば、1つのサーバで秘密計算を行うことができる場合に、そのサーバで本発明に係る技術を実行することも可能である。
 図2に、サーバ100の構成例を示す。図2に示すサーバ100の構成例は、複数のサーバ100-1~100-Nを仮想的に1つのサーバとみなした場合のその構成である。この場合、図2に示すサーバ100を秘匿ハッシュテーブル構築システムと呼んでもよい。また、当該サーバ100を、秘匿ハッシュテーブル構築装置と呼んでもよい。また、1つのサーバで秘密計算を行う場合におけるそのサーバが図2に示すサーバ100であってもよい。
 図2に示すように、サーバ100は、入力部110、演算部120、出力部130、データ格納部140を有する。演算部120は、秘匿ハッシュテーブル構築及び操作に係る処理を実行する。データ格納部140には、計算にあたって予め用意しておくデータ、計算途中の秘匿した配列等のデータ、テーブルが格納される。入力部110は、例えば、ユーザ端末300からの要求を受信し、入力する。出力部140は、例えば、ユーザ端末300からの要求に対する演算結果をユーザ端末300に返す。
  (ハードウェア構成例)
 本実施の形態におけるサーバ100(秘匿ハッシュテーブル構築装置)は、例えば、コンピュータに、本実施の形態で説明する処理内容を記述したプログラムを実行させることにより実現可能である。なお、この「コンピュータ」は、物理マシンであってもよいし、クラウド上の仮想マシンであってもよい。仮想マシンを使用する場合、ここで説明する「ハードウェア」は仮想的なハードウェアである。
 上記プログラムは、コンピュータが読み取り可能な記録媒体(可搬メモリ等)に記録して、保存したり、配布したりすることが可能である。また、上記プログラムをインターネットや電子メール等、ネットワークを通して提供することも可能である。
 図3は、上記コンピュータのハードウェア構成例を示す図である。図3のコンピュータは、それぞれバスBで相互に接続されているドライブ装置1000、補助記憶装置1002、メモリ装置1003、CPU1004、インタフェース装置1005、表示装置1006、入力装置1007、出力装置1008等を有する。
 当該コンピュータでの処理を実現するプログラムは、例えば、CD-ROM又はメモリカード等の記録媒体1001によって提供される。プログラムを記憶した記録媒体1001がドライブ装置1000にセットされると、プログラムが記録媒体1001からドライブ装置1000を介して補助記憶装置1002にインストールされる。但し、プログラムのインストールは必ずしも記録媒体1001より行う必要はなく、ネットワークを介して他のコンピュータよりダウンロードするようにしてもよい。補助記憶装置1002は、インストールされたプログラムを格納すると共に、必要なファイルやデータ等を格納する。
 メモリ装置1003は、プログラムの起動指示があった場合に、補助記憶装置1002からプログラムを読み出して格納する。CPU1004は、メモリ装置1003に格納されたプログラムに従って、当該サーバ100に係る機能を実現する。インタフェース装置1005は、ネットワークに接続するためのインタフェースとして用いられる。表示装置1006はプログラムによるGUI(Graphical User Interface)等を表示する。入力装置1007はキーボード及びマウス、ボタン、又はタッチパネル等で構成され、様々な操作指示を入力させるために用いられる。出力装置1008は演算結果を出力する。
 (秘密計算に係る基本的な処理について)
 まず、サーバ100の演算部120により実行される秘匿ハッシュテーブル構築や操作の処理において前提となる、秘密計算に係る基本的な処理について説明する。これら基本的な処理自体は既存技術である。
 <秘匿化・復元>
 以下では、値xの秘匿値を[[x]]と表し、処理x→[[x]]をxの秘匿化、[[x]]→xをxの復元と呼ぶ。本実施の形態では、秘匿化・復元処理を行うための技術として秘密分散法(参考文献[6,5])を使用することを想定しているが、同等の機能及び安全性を満たす方法ならばどのような秘匿化・復元処理技術を用いてもよい。
 <基本演算>
 秘匿値同士の加算・減算・乗算をそれぞれ以下のように表す。
 [[a+b]]←[[a]]+[[b]]
 [[a‐b]]←[[a]]‐[[b]]
 [[a×b]]←[[a]]×[[b]]
 a、bがlenビットで表現される空間にあるとすると、参考文献[7]の技術では加算と減算を通信コスト0、乗算を通信コストO(len)ビットで実行できる。
 <比較>
 秘匿値同士の比較を以下のように表す。
  [[c]]←[[[a]]=?[[b]]]
 上記の比較は、aとbが等しいかどうかの判定結果がc(1ビット数)であることを示す。正しければ1、そうでなければ0になる。
  [[d]]←[[[a]]≦?[[b]]]
 上記の比較は、aがb以下であるか否かの判定結果がd(1ビット数)であることを示す。正しければ1、そうでなければ0になる。
 比較の演算は、a、bがlenビットで表現される空間にあるとすると、参考文献[7]の技術では通信コストO(len)ビットで実行できる。
 <内積>
 秘匿値のベクトル又は配列[[a]]=([[a0]],...,[[an-1]]),[[b]]=([[b0]],...,[[bn-1]])の内積を以下のように表す。
  [[c]]←<[[a]],[[b]]>
 ベクトルa,bの各要素がそれぞれlenビットで表現される空間にあるとすると、参考文献[7]の技術では内積を通信コストO(len)ビットで実行できる。
 <配列のシャッフル>
 秘密の配列[[A]]をシャッフルする処理を以下のように表す。
  [[A′]]←Shuffle([[A]])
 Aがlenビットの要素をn個持つ配列であるとき、参考文献[3]の技術ではこの処理を通信コストO(len・n)ビットで実行できる。
 <安定ソート>
 秘密のキー配列[[K]]及びソート対象配列[[A]]に対し、[[A]]を[[K]]の各値に基づきソートする処理を以下のように表す。
  [[A′]]←Sort([[K]],[[A]])
 この処理はKに関して昇順・降順のいずれも可能である。Kがlenビットの要素をn個持つ配列、Aがmビットの要素をn個持つ配列であるとき、参考文献[3]の技術ではこの処理を通信コストO(len・nlogn+mn)ビットで実行できる。
 <同一データのランク付け>
 配列[[A]]=([[a0]],...,[[an-1]])を、ソート済みの配列の配列とする。このとき、同一データに対するランク付け操作を下記のように表す。
  [[B]]←Rank([[A]])
 ただし、[[B]]=([[b0]],...,[[bn-1]])であり、各biは以下を満たす:
 ・b0=1
 ・全てのi∈{1,...,n‐1}において、ai-1≠aiならばbi=1
 ・全てのi∈{1,...,n‐1}において、ai-1=aiならばbi=bi-1+1
 具体的に、例えばA=(0,0,0,0,1,1,2,2,2)のとき、B=(1,2,3,4,1,2,1,2,3)となる。参考文献[1]に開示されているRange Prefix Sumを用いれば、この操作を通信コストO(nlogn)で実行できる。
 <擬似ランダム関数>
 値a,sをそれぞれ、擬似ランダム関数の入力及び秘密鍵であるとする。秘匿値[[a]],[[s]]に対し、秘密の疑似ランダム値を計算する操作を以下のように表す。
  [[r]]←PRF([[a]],[[s]])
 aのビット長をlenとすると、この秘密計算処理は例えば参考文献[2]の技術を用いて通信コストO(len)で実現できる。
 <秘密計算による暗号化>
 値a,sをそれぞれ、ブロック暗号の平文及び秘密鍵であるとする。秘匿値[[a]],[[s]]に対し、秘密計算により暗号文を生成する操作を以下のように表す。
  [[c]]←Enc([[a]],[[s]])
 aのビット長をlenとすると、この秘密計算処理は参考文献[2]の技術を用いて通信コストO(len)で実現できる。
 以下、本実施の形態に係るサーバ100が実行する処理の具体例について、実施例1~5を用いて説明する。以下の処理はサーバ100の演算部120により実行される。また、予め用意しておくデータ、計算により得られる配列、テーブル等はデータ格納部140に格納される。演算部120は、データ格納部140から読み出したデータに対して演算を行い、演算結果をデータ格納部140に格納することを繰り返しながら処理を進める。
 なお、下記の各実施例における処理は一例である。例えば、1と0の意味や、昇順/降順などが、下記の各実施例におけるものと逆であってもよい。
 (実施例1)
 まず、実施例1を説明する。本実施例1では、サーバ100が、データ格納部140に格納されているキーkiとフラグeiからなるデータai=(ki,ei)を用いて秘匿ハッシュテーブルを構築する方法を示す。キーkiはデータ毎に固有の識別子であり、アクセスの際などにデータを一意に特定する目的に用いる。
 フラグeiはデータがダミーか否かを判定する1bitの値であり、ここではei=0なら実際のデータ、ei=1ならダミーデータであるとする。なお、データの総数がnの場合において、kiのビット長は最小でceil(logn)となるが、冗長性があっても構わないとする。また、各データにはキーとフラグ以外にも、任意の情報viを付与し、ai=(ki,ei,vi)のようにしても良いとする。
 前提として、サーバ100が、データ格納部140の中に、秘匿化されたデータ列[[A]]=([[a0]],...,[[an-1]]);[[ai]]=([[ki]],[[ei]])を保持しているものとする。
 また、以下では事前に秘匿化された秘密鍵[[s0]],[[s1]]を生成し、データ格納部140に保持しておくものとするが、プロトコル中に逐次生成しても構わない。
 本実施例1で構築する秘匿ハッシュテーブルは、サイズB×Zのデータ配列であり、別の表現をするならばB通りのアドレス値にそれぞれ最大Z個までのデータを格納できるデータ構造である、とする。また、本実施例1で用いる擬似ランダム関数は、PRF([[k]],[[s]])∈{0,...,B‐1}を満たすとする。
 上記の前提の下、サーバ100は、以下で説明する処理により、秘匿ハッシュテーブルを構築する。図4のフローチャートの手順に沿って、サーバ100が実行する処理を説明する。
  <S101(ステップ101)>
 S101において、サーバ100は、[[A]]に対してシャッフルを行い[[A]]←Shuffle([[A]])とする。ただしこの操作は、入力となる[[A]]の状態や満たすべき安全性によっては実行しなくてもよいものとする。
  <S102>
 S102において、サーバ100は、[[A]]に対して、格納先データ配列[[ADDR]]=(([[addr0 0]],[[addr1 0]],[[e0]],[[rank0 0]],[[rank1 0]]),...,([[addr0 n-1]],[[addr1 n-1]],[[en-1]],[[rank0 n-1]],[[rank1 n-1]]))を計算する。
 ただし、[[addrp i]]←PRF([[ki]],[[sp]]);i∈{0,...,n‐1},p∈{0,1}とし、また[[rankp i]]←[[0]]と初期化する。ここでaddr0 i,addr1 iはそれぞれAのi番目のデータai=(ki,ei)に対応する2通りのアドレス値に相当し、またrankp iは後にランク付けをする際のランク保持用領域である。
 なお、データのイメージを説明する便宜上、秘匿の記号[[]]なしで説明を行うこととすると、この時点でのADDRは、例えば、ADDR=((3,1,0,0,0),(18,95,0,0,0),......,(8,78,0,0,0))といった配列(n個のデータの配列)になる。以下、適宜、[[]]なしで説明を行う場合がある。
  <S103>
 S103において、サーバ100は、ダミーの格納先データ配列[[ADDRd]]=([[d0]],...,[[dBZ-1]]);di=(floor(i/Z),floor(i/Z),1,0,0)を生成する。
 これは2通りのアドレス値addr0 i,addr1 iが同じ値floor(i/Z)∈{0,...,B‐1}を指しているダミーの格納先データを、アドレス値0,...,B‐1ごとにZ個ずつ保持する配列である。
 サーバ100は、このダミーの[[ADDRd]]を、実データに関する格納先データ配列[[ADDR]]の末尾に連結し、長さn+BZの配列[[ADDR′]]=[[ADDR]]||[[ADDRd]]とする。
 この時点でのADDR´は、例えば、ADDR´=((3,1,0,0,0),(18,95,0,0,0),......,(8,78,0,0,0),(0,0,1,0,0),(0,0,1,0,0),......,(8,8,1,0,0))といった配列(n+BZ個のデータの配列)になる。
 なお、以下では格納先データ配列[[ADDR′]]に対して、記法[[ADDR′.addr0]]を、[[ADDR′]]から1番目のアドレス値[[addr0 i]]のみを取り出した配列([[addr0 0]],...,[[addr0 n+BZ-1]])であると定義する。同様に、記法[[ADDR′.addr1]],[[ADDR′.rank0]],[[ADDR′.rank1]]を、それぞれ[[ADDR′]]から[[addr1 i]],[[rank0 i]],[[rank1 i]]を取り出した配列と定義する。
 さらに、記法[[ADDR′.pos0]],[[ADDR′.pos1]]によって、それぞれ[[ADDR′]]からペア([[addr0 i]],[[ei]])、([[addr1 i]],[[ei]])を抽出した配列であるとする。
 例えば、ADDR´=((3,1,0,0,0),(18,95,0,0,0),......,(8,78,0,0,0),(0,0,1,0,0),(0,0,1,0,0),......,(8,8,1,0,0))であるとすると、ADDR′.pos0=((3,0),(18,0),......,(8,0),(0,1),(0,1),......,(8,1))となる。
  <S104>
 S104において、サーバ100は、ダミーのデータ列[[Ad]]=([[ad 0]],...,[[ad BZ-1]]);ad i=(dummy,1)を生成する。ただし、ここでdummyは予め定めておいた、いずれのキーkiとも異なる値であるとする。この[[Ad]]を実データ列[[A]]の末尾に連結し、長さn+BZの配列[[A′]]=[[A]]||[[Ad]]とする。
 この時点でのA´は、例えば、A´=((11,0),(101,0),......,(3,0),(dummy,1),(dummy,1),......,(dummy,1))といった配列(n+BZ個のデータの配列)になる。
  <S105>
 S105において、サーバ100はまず、1番目のアドレス値addr0 iとフラグeiに基づいてデータ配列と格納先データ配列のそれぞれのソートを行う。すなわち、[[A′]]←Sort([[ADDR′.pos0]],[[A′]])、及び[[ADDR′]]←Sort([[ADDR′.pos0]],[[ADDR′]])を計算する。
 この時、データ配列及び格納先データ配列はアドレス値による昇順かつ同アドレス値においては実データ>ダミーデータの順で並べ替えられるものとするが、以後のソートやランク付けの昇順・降順を調整することでソート順序を変更することもできる。
 ソート後のA´は、例えば、A´=((3,0),(dummy,1),(dummy,1),......,(11,0),(dummy,1),,......,)といった配列(n+BZ個のデータの配列)になる。
  <S106>
 S106において、サーバ100は、ソート済みのアドレス値に基づきランク付けを行う。すなわち、[[ADDR′.rank0]]←Rank([[ADDR′.addr0]])を計算する。
 ADDR′.rank0は、例えば、ADDR′.rank0=(1,2,3,4,....,1,2,3,....,1,2,3,4,5)といった配列(n+BZ個のデータの配列)になる。
  <S107>
 S107において、サーバ100は、データ配列及び格納先データ配列を、1番目のランクに基づき降順でソートする。すなわち、[[A′]]←Sort([[ADDR′.rank0]],[[A′]])及び[[ADDR′]]←Sort([[ADDR′.rank0]],[[ADDR′]])を、rank0 iが大きい順に並ぶよう計算する。なお、この操作は単に各配列を昇順でソートしたうえ、逆順に並べ替えることでも同様に実現できる。
  <S108>
 S108において、サーバ100は、S105での処理と同様に、今度は2番目のアドレス値addr1 iとフラグに基づいてソートを行う。すなわち、[[A′]]←Sort([[ADDR′.pos1]],[[A′]])及び[[ADDR′]]←Sort([[ADDR′.pos1]],[[ADDR′]])を計算する。この時、安定ソートを用いれば、同アドレス値においては実データ>ダミーデータかつ高ランク>低ランクの順で並べ替えることができている。
  <S109>
 S109において、サーバ100は、S106での処理と同様に、2番目のソート済みアドレス値に基づきランク付けを行う。すなわち、[[ADDR′.rank1]]←Rank([[ADDR′.addr1]])を計算する。
  <S110>
 S110において、サーバ100は、格納先データ配列[[ADDR′]]の各要素[[bi]]=([[addr0 i]],[[addr1 i]],[[ei]],[[rank0 i]],[[rank1 i]])について、それぞれランクの低い側のアドレス値を抽出する。すなわち、大小比較[[zi]]←[[[rank0 i]]≦?[[rank1 i]]]に基づき、[[addri]]←[[addr1 i]]+[[zi]]×([[addr0 i]]‐[[addr1 i]])を計算する。その後、選ばれたアドレス値とフラグを併せた配列[[ADDRfin]]=(([[addr0]],[[e0]]),...,([[addrn+BZ-1]],[[en+BZ-1]]))を計算する。
  <S111>
 S111において、サーバ100は、新たに得た配列[[ADDRfin]]に基づき、各データを昇順でソートする。すなわち、[[A′]]←Sort([[ADDRfin]],[[A′]])及び[[ADDRfin]]←Sort([[ADDRfin]],[[ADDRfin]])を計算する。
  <S112>
 S112において、サーバ100は、[[ADDRfin]]のアドレス値部分のみを抽出した配列[[ADDRfin.addr]]を用いて、ランク配列[[R]]=Rank([[ADDRfin.addr]])を計算し、さらに[[R]]の各要素[[ri]]に対して大小比較[[yi]]←[[[ri]]≦?Z]を計算した結果の配列[[Y]]=([[y0]],...,[[yn+BZ-1]])を得る。このとき、yi=1のデータはテーブルに格納され、yi=0のデータは削除されることを示している。
  <S113>
 S113において、サーバ100は、[[Y]]を用いてデータ配列を昇順でソートする。すなわち、[[A′]]←Sort([[Y]],[[A′]])を計算する。その後、末尾のBZ個の要素のみをハッシュテーブルとして出力し、その他は削除する。また、ハッシュテーブルに付随するアクセス用情報として2つの秘密鍵[[s0]],[[s1]]も出力する。
 本実施例1において、[[ki]]をO(logN)ビットとし、B×Z=O(n)とすれば、サーバ間通信量はソート、ランク付け及び比較によりO(nlog2n)ビットとなる。
 (実施例2)
 次に、実施例2を説明する。本実施例2では、実施例1と同等のテーブル構築を、より効率的に行う方法を示す。実施例1では、常に格納先データ配列と共にデータ配列[[A]](ないし[[A′]])がソートされており、単にソート回数が増していた他、仮にキーとフラグに対して大きなデータviが付与されていた場合、データ配列のソートのために効率悪化を招く可能性もあった。
 本実施例2では原則として実施例1のアルゴリズムを踏襲しつつも、秘密計算上での暗号化を利用してソート回数を削減し、以下のように秘匿ハッシュテーブルを構築する。以下、図5のフローチャートの手順に沿って説明する。
  <S201>
 S201において、サーバ100は、実施例1のS101と同様に、[[A]]に対してシャッフルを行い[[A]]←Shuffle([[A]])とする。ただしこの操作は、入力となる[[A]]の状態や満たすべき安全性によっては実行しなくてもよいものとする。
  <S202>
 S202において、サーバ100は、秘匿化されたブロック暗号の秘密鍵[[s]]を生成し、[[A]]に対応する秘密のタグ配列[[Tag]]=([[tag0]],...,[[tagn-1]]);[[tagi]]←Enc([[i]],[[s]])を計算する。なお、秘密鍵[[s]]はプロトコルの開始以前に生成していても構わないとする。
  <S203>
 S203において、サーバ100は、実施例1のS102と同様に、格納先データ配列[[ADDR]]=(([[addr0 0]],[[addr1 0]],[[e0]],[[rank0 0]],[[rank1 0]],[[tag0]]),...,([[addr0 n-1]],[[addr1 n-1]],[[en-1]],[[rank0 n-1]],[[rank1 n-1]],[[tagn-1]]))を計算する。実施例1とは、タグ[[tagi]]が含まれていることのみが異なる。
  <S204>
 S204において、サーバ100は、実施例1のS103と同様に、ダミーの格納先データ配列[[ADDRd]]=([[d0]],...,[[dBZ-1]]);[[di]]=([[floor(i/Z)]],[[floor(i/Z)]],[[1]],[[0]],[[0]],[[tagd i]])を生成し、[[ADDR′]]=[[ADDR]]||[[ADDRd]]とする。ただし、[[tagd i]]←PRF([[n+i]],[[s]])であるとする。
  <S205>
 S205において、サーバ100は、実施例1のS104と同様に、ダミーのデータ列[[Ad]]=([[ad 0]],...,[[ad BZ-1]]);ad i=(dummy,1)を生成し、[[A′]]=[[A]]||[[Ad]]とする。また、本実施例2のS204で計算したタグの列[[Tagd]]=([[tagd 0]],...,[[tagd BZ-1]])を用いて、[[Tag′]]←[[Tag]]||[[Tagd]]とする。
  <S206>
 S206において、サーバ100は、配列[[A′]]及び[[Tag′]]の並び順を秘匿・ランダマイズするために、([[A′]],[[Tag′]])←Shuffle([[A′]],[[Tag′]])を計算する。この操作では、2つの配列の対応関係を保ったままランダマイズするため、並列に同じシャッフル処理を実行している。
  <S207>
 S207において、サーバ100は、実施例1のS105~S113と同様の処理を行う。ただし、実施例2において、実施例1のS105~S112に対応する各手順においては配列[[A′]]には一切手を触れず格納先データ配列のみに操作を行うこととし、また、実施例1のS110に対応する手順で新たな格納先データ配列を得る際には[[ADDRfin]]の各要素を([[addri]],[[ei]],[[tagi]])として、タグ情報を引き継ぐようにする。
  <S208>
 S208において、サーバ100は、実施例1のS112に対応する手順で得た[[Y]]を用いて[[ADDRfin]]を昇順でソートする。すなわち、[[ADDRfin]]←Sort([[Y]],[[ADDRfin]])を計算する。その後、末尾のBZ個の要素のみ残し、その他は削除する。
  <S209>
 S209において、サーバ100は、タグ配列[[Tag′]]の全ての要素を復元し、平文に戻す。同時に、[[ADDRfin]]に含まれる全てのタグを復元し、平文に戻す。データ配列[[A′]]の中から、対応するタグが[[ADDRfin]]に含まれるような要素BZ個を取り出し、[[ADDRfin]]の並び順の通りに並べることでハッシュテーブルとする。最後にハッシュテーブルと秘密鍵[[s0]],[[s1]]を出力する。
 本実施例2において、[[ki]]をO(logn)ビットとし、B×Z=O(n)とすれば、サーバ間通信量はソート、ランク付け及び比較によりO(nlog2n)ビットとなる。実施例1では任意のデータviを含む組(ki,ei,vi)のデータサイズがω(logn)ビットとなる場合にサーバ間通信量がω(nlog2n)ビットとなってしまうのに対し、本実施例はviのサイズに関わらずO(nlog2n)ビットで済む利点がある。
 (実施例3)
 次に、実施例3を説明する。実施例3では、実施例1、2で構築した秘匿ハッシュテーブルへのデータ参照方法について説明する。前提として、サーバ100は、実施例1ないし2で構築された秘匿ハッシュテーブル(サイズB×Z)と秘密鍵[[s0]]、[[s1]]をデータ格納部140に保持しているとする。また、ユーザ端末300はアクセスしたいキーkを持っているとするが、これはサーバ同士の合意に基づいてサーバ自身で選定しても構わない。以下、図6のフローチャートに示す手順に沿って説明する。
  <S301>
 S301において、ユーザ端末300は、サーバ100に対し、アクセスしたいデータに対応するキーの秘匿値[[k]]を送る。ただし、この秘匿キー値はユーザ端末300からサーバ100への要求だけでなく、サーバ間合意に基づくサーバ自身による生成も可能である。
  <S302>
 S302において、サーバ100は、疑似ランダム関数を用いて、2つのアドレス値[[addr0]]←PRF([[k]],[[s0]]),[[addr1]]←PRF([[k]],[[s1]])を計算し、これを復元してaddr0,addr1を得る。
  <S303>
 S303において、サーバ100は、データ格納部140に格納されているハッシュテーブルからaddr0、addr1に対応する2Z個の要素を取り出す。すなわち、ハッシュテーブルを配列[[Table]]=([[a0]],...,[[aBZ-1]])と読み替えた場合に、[[a]]=([[aZ×addr0]],...,[[aZ×addr0+Z-1]],[[aZ×addr1]],...,[[aZ×addr1+Z-1]])を取得する。
  <S304>
 S304において、サーバ100は、[[a]]の各データ[[aj]]について、キーの比較を行い[[c]]=([[c0]],...,[[c2Z-1]]);[[cj]]=[[[kj]]=?[[k]]]を計算する。
  <S305>
 S305において、サーバ100は、内積[[a]]←<[[a]],[[c]]>を計算し、これをユーザ端末300へ返送するか、又はサーバ間合意に基づき復元する。あるいは、これを復元せず、全く別の秘密計算処理に用いてもよい。
 本実施例3において、ユーザ・サーバ間の通信量O(logn)ビットであり、サーバ間通信量はO(Zlogn)ビットである。
 (実施例4)
 本実施例4では、実施例1、2で構築した秘匿ハッシュテーブルでのデータ削除方法を説明する。前提として、サーバ100は、実施例1ないし2で構築されたハッシュテーブル(サイズB×Z)と秘密鍵[[s0]],[[s1]]をデータ記憶部140に保持しているとする。また、ユーザは削除したいデータのキーkを持っているとするが、これはサーバ同士の合意に基づいてサーバ自身で選定しても構わない。以下、図7のフローチャートに示す手順に沿って説明する。
  <S401>
 S401において、ユーザ端末300は、サーバ100に対し、削除したいキーの秘匿値[[k]]を送る。ただし、この秘匿キー値はユーザ端末300からサーバ100への要求だけでなく、サーバ間合意に基づくサーバ自身による生成も可能である。
  <S402>
 S402において、サーバ100は、疑似ランダム関数を用いて、2つのアドレス値[[addr0]]←PRF([[k]],[[s0]]),[[addr1]]←PRF([[k]],[[s1]])を計算し、これを復元してaddr0,addr1を得る。
  <S403>
 S403において、サーバ100は、データ格納部140に保持しているハッシュテーブルからaddr0、addr1に対応する2Z個の要素を取り出す。すなわち、ハッシュテーブルを配列[[Table]]=([[a0]],...,[[aBZ-1]])と読み替えた場合に、[[a]]=([[aZ×addr0]],...,[[aZ×addr0+Z-1]]、[[aZ×addr1]],...,[[aZ×addr1+Z-1]])を取得する。
  <S404>
 S404において、サーバ100は、[[a]]の各データ[[aj]]について、キーの比較に基づきデータ([[k]],[[e]])の削除処理を行う。すなわち、全てのjに関して[[kj]]=[[kj]]+[[[kj]]=?[[k]]]×(dummy-[[kj]]),[[ej]]=[[ej]]+[[[kj]]=?[[k]]]を計算する。
  <S405>
 最後に、サーバ100は[[a]]の各要素をハッシュテーブルの元の位置に上書きする。
本実施例4の通信量は実施例3と等価である。
 (実施例5)
 本実施例5では、実施例1、2で構築したハッシュテーブルの解体・全データの抽出方法について説明する。前提として、サーバ100は実施例1ないし2で構築されたハッシュテーブル(サイズB×Z)をデータ格納部140に保持しているとする。以下、図8のフローチャートに示す手順に沿って説明する。
  <S501>
 S501において、サーバ100は、ハッシュテーブルの全データを、そのフラグに基づき昇順でソートする。すなわち、テーブルを配列[[Table]]=([[a0]],...,[[aBZ-1]])と読み替え、またテーブルからフラグのみを抽出した配列を[[E]]=([[e0]],...,[[eBZ-1]])とした場合に、[[Table]]=Sort([[E]],[[Table]])とする。
  <S502>
 S502において、サーバ100は、[[Table]]の先頭nデータを配列[[A]]とし、残りを削除する。
 本実施例では、1ビットの情報に基づくソート1回のみ行うため、サーバ間通信量はO(nlogn)となる。
 (実施の形態の効果)
 本実施の形態によれば、秘密計算を用いることでユーザとの通信を介さず秘匿ハッシュテーブルを構築できる。その際、ランク付けという秘密計算処理を利用することで、テーブル構築に必要な秘匿ソートの回数を大きく減らし、従来法よりも通信コストを大きく削減できる。
 すなわち、秘匿ハッシュテーブルの構築において、各データに2通りのアドレス値を割り振ることでテーブルサイズを小さくするという従来法のメリットをそのままに、サーバ間通信量をω(nlog2.5n)からO(nlog2n)へと削減できる。構築済みのテーブルへの操作も可能である。
 (付記)
 本明細書には、少なくとも下記各項の秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラムが開示されている。
(第1項)
 キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築装置であって、
 前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
 前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
 前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
 前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
 前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
 前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
 演算部を備える秘匿ハッシュテーブル構築装置。
(第2項)
 前記演算部は、前記実データ列における各データと前記ダミーのデータ列における各データとを示すタグを有するタグの列を使用することにより、前記実データ列と前記ダミーのデータ列とを連結した前記第2配列に対して、前記第4配列に基づくソート以外のソートを行うことなく、前記秘匿ハッシュテーブルを生成する
 第1項に記載の秘匿ハッシュテーブル構築装置。
(第3項)
 前記演算部は、アクセス対象のキー値から2つのアドレス値を計算し、前記秘匿ハッシュテーブルから、前記2つのアドレス値に対応する2Z個のデータを取得し、2Z個のデータのうち、前記キー値と同一のキー値を有するデータを返す
 第1項又は第2項に記載の秘匿ハッシュテーブル構築装置。
(第4項)
 前記演算部は、削除対象のキー値から2つのアドレス値を計算し、前記秘匿ハッシュテーブルから、前記2つのアドレス値に対応する2Z個のデータを取得し、2Z個のデータのデータのうち、前記キー値と同一のキー値を有するデータを削除する
 第1項ないし第3項のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置。
(第5項)
 前記演算部は、前記秘匿ハッシュテーブルにおける全データを、そのフラグに基づいてソートし、先頭の所定個数のデータを前記実データ列として取得する
 第1項ないし第4項のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置。
(第6項)
 キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築システムであって、
 前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
 前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
 前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
 前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
 前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
 前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
 演算部を備える秘匿ハッシュテーブル構築システム。
(第7項)
 キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築システムが実行する秘匿ハッシュテーブル構築方法であって、
 前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成するステップと、
 前記実データ列とダミーのデータ列とを連結した第2配列を生成するステップと、
 前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートするステップと、
 前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行うステップと、
 前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成するステップと、
 前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力するステップと
 を備える秘匿ハッシュテーブル構築方法。
(第8項)
 コンピュータを、第1項ないし第5項のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置における演算部として機能させるためのプログラム。
 以上、本実施の形態について説明したが、本発明はかかる特定の実施形態に限定されるものではなく、特許請求の範囲に記載された本発明の要旨の範囲内において、種々の変形・変更が可能である。
 [参考文献]
[1] T-H. H. Chan, Y. Guo, W-K. Lin, and E. Shi. Oblivious hashing revisited, and applications to asymptotically efficient ORAM and OPRAM. Cryptology ePrint Archive, Report 2017/924, 2017.
[2] K. Chida, K. Hamada, D. Ikarashi, R. Kikuchi, and B. Pinkas. High-throughput secure AES computation. In WAHC@CCS 2018, pages 13-24, 2018.
[3] K. Chida, K. Hamada, D. Ikarashi, R. Kikuchi, N. Kiribuchi, B. Pinkas. Anefficient secure threeparty sorting protocol with an honest majority. CryptologyePrint Archive, Report 2019/695 (2019), https://eprint.iacr.org/2019/695
[4] O. Goldreich and R. Ostrovsky. Software protection and simulation on oblivious RAMs. J. ACM, 43(3):431-473, May 1996. 8
[5] M. Ito, A. Saito, and T. Nishizeki. Secret sharing schemes realizing general access structures. Proceedings of the IEEE Global Telecommunication Conference, Globecom 87, pp. 99-102, 1987.
[6] A. Shamir. How to share a secret. Commun. ACM, Vol. 22, No. 11, pp. 612-613, 1979.
[7] 桐淵直人,五十嵐大,濱田浩気,菊池亮.プログラマブルな秘密計算ライブラリMEVAL3.暗号と情報セキュリティシンポジウム(SCIS)2018 予稿集(2018).
100 サーバ
110 入力部
120 演算部
130 出力部
140 データ格納部
200 通信ネットワーク
300 ユーザ端末
1000 ドライブ装置
1001 記録媒体
1002 補助記憶装置
1003 メモリ装置
1004 CPU
1005 インタフェース装置
1006 表示装置
1007 入力装置

Claims (8)

  1.  キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築装置であって、
     前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
     前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
     前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
     前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
     前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
     前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
     演算部を備える秘匿ハッシュテーブル構築装置。
  2.  前記演算部は、前記実データ列における各データと前記ダミーのデータ列における各データとを示すタグを有するタグの列を使用することにより、前記実データ列と前記ダミーのデータ列とを連結した前記第2配列に対して、前記第4配列に基づくソート以外のソートを行うことなく、前記秘匿ハッシュテーブルを生成する
     請求項1に記載の秘匿ハッシュテーブル構築装置。
  3.  前記演算部は、アクセス対象のキー値から2つのアドレス値を計算し、前記秘匿ハッシュテーブルから、前記2つのアドレス値に対応する2Z個のデータを取得し、2Z個のデータのうち、前記キー値と同一のキー値を有するデータを返す
     請求項1又は2に記載の秘匿ハッシュテーブル構築装置。
  4.  前記演算部は、削除対象のキー値から2つのアドレス値を計算し、前記秘匿ハッシュテーブルから、前記2つのアドレス値に対応する2Z個のデータを取得し、2Z個のデータのデータのうち、前記キー値と同一のキー値を有するデータを削除する
     請求項1ないし3のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置。
  5.  前記演算部は、前記秘匿ハッシュテーブルにおける全データを、そのフラグに基づいてソートし、先頭の所定個数のデータを前記実データ列として取得する
     請求項1ないし4のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置。
  6.  キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築システムであって、
     前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成し、
     前記実データ列とダミーのデータ列とを連結した第2配列を生成し、
     前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートし、
     前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行い、
     前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成し、
     前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力する
     演算部を備える秘匿ハッシュテーブル構築システム。
  7.  キーと、データがダミーか否かを示すフラグとを有するデータを複数個含む実データ列から、秘密計算により、B通りのアドレス値にそれぞれ最大Z個までのデータを格納できる秘匿ハッシュテーブルを構築する秘匿ハッシュテーブル構築システムが実行する秘匿ハッシュテーブル構築方法であって、
     前記実データ列の各データに対する、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列と、ダミーとしての、第1アドレス値及び第2アドレス値と、フラグと、アドレス値毎のランクとを含む格納先データ配列とを連結した第1配列を生成するステップと、
     前記実データ列とダミーのデータ列とを連結した第2配列を生成するステップと、
     前記第1配列における第1アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第1アドレス値に対して同一データに対するランク付け操作を行い、当該ランク付けに基づいて前記第1配列と前記第2配列のそれぞれをソートするステップと、
     前記第1配列における第2アドレス値とフラグに基づいて、前記第1配列と前記第2配列のそれぞれをソートし、ソートした前記第1配列の第2アドレス値に対して同一データに対するランク付け操作を行うステップと、
     前記第1配列において、第1アドレス値と第2アドレス値のうち、ランクの低い側のアドレス値を抽出し、抽出したアドレス値とフラグを有する第3配列を生成するステップと、
     前記第3配列におけるアドレス値から計算されたランク配列の各要素とZとの比較により得られた第4配列を用いて、前記第2配列をソートし、ソートした前記第2配列におけるBZ個の要素を前記秘匿ハッシュテーブルとして出力するステップと
     を備える秘匿ハッシュテーブル構築方法。
  8.  コンピュータを、請求項1ないし5のうちいずれか1項に記載の秘匿ハッシュテーブル構築装置における演算部として機能させるためのプログラム。
PCT/JP2020/046125 2020-12-10 2020-12-10 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム Ceased WO2022123744A1 (ja)

Priority Applications (3)

Application Number Priority Date Filing Date Title
JP2022567986A JP7505583B2 (ja) 2020-12-10 2020-12-10 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム
PCT/JP2020/046125 WO2022123744A1 (ja) 2020-12-10 2020-12-10 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム
US18/255,928 US12189594B2 (en) 2020-12-10 2020-12-10 Secret hash table construction apparatus, secret hash table construction system, secret hash table construction method and program

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2020/046125 WO2022123744A1 (ja) 2020-12-10 2020-12-10 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム

Publications (1)

Publication Number Publication Date
WO2022123744A1 true WO2022123744A1 (ja) 2022-06-16

Family

ID=81973434

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2020/046125 Ceased WO2022123744A1 (ja) 2020-12-10 2020-12-10 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム

Country Status (3)

Country Link
US (1) US12189594B2 (ja)
JP (1) JP7505583B2 (ja)
WO (1) WO2022123744A1 (ja)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2024176307A1 (ja) * 2023-02-20 2024-08-29 日本電信電話株式会社 データ管理システム、方法、及びプログラム

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12333039B2 (en) * 2020-01-16 2025-06-17 Nippon Telegraph And Telephone Corporation Secret hash table construction system, reference system, methods for the same
CN118069742B (zh) * 2024-02-22 2025-06-27 北京火山引擎科技有限公司 数据处理方法、装置、电子设备、存储介质及产品

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7017162B2 (en) * 2001-07-10 2006-03-21 Microsoft Corporation Application program interface for network software platform
US8468244B2 (en) * 2007-01-05 2013-06-18 Digital Doors, Inc. Digital information infrastructure and method for security designated data and with granular data stores
US9141823B2 (en) * 2013-03-15 2015-09-22 Veridicom, Sa De Cv Abstraction layer for default encryption with orthogonal encryption logic session object; and automated authentication, with a method for online litigation
EP3392864B1 (en) * 2015-12-14 2020-10-28 Hitachi, Ltd. Data processing system and data processing method
US12333039B2 (en) * 2020-01-16 2025-06-17 Nippon Telegraph And Telephone Corporation Secret hash table construction system, reference system, methods for the same

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
ASHAROV, G. ET AL.: "OptORAMa: Optimal Oblivious RAM", CRYPTOLOGY EPRINT ARCHIVE: REPORT 2018/892, VER. 20191012 :17480 9, 12 October 2019 (2019-10-12), pages 1 - 71, XP055944968, Retrieved from the Internet <URL:https://eprint.iacr.org/2018/892> *
CHAN, T-H. H. ET AL.: "Perfectly Secure Oblivious Parallel RAM", CRYPTOLOGY EPRINT ARCHIVE: REPORT 2018/364, VER . 20181002 :155559, 2 October 2018 (2018-10-02), pages 1 - 54, XP061027284, Retrieved from the Internet <URL:https://eprint.iacr.org/2018/364> *
KUSHILEVITZ, E. ET AL., S UB-LOGARITHMIC DISTRIBUTED OBLIVIOUS RAM WITH SMALL BLOCK SIZE, vol. 3, 17 November 2018 (2018-11-17), pages 1 - 42, Retrieved from the Internet <URL:https://arxiv.org/abs/1802.05145&gt> *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2024176307A1 (ja) * 2023-02-20 2024-08-29 日本電信電話株式会社 データ管理システム、方法、及びプログラム

Also Published As

Publication number Publication date
JP7505583B2 (ja) 2024-06-25
US12189594B2 (en) 2025-01-07
JPWO2022123744A1 (ja) 2022-06-16
US20240028576A1 (en) 2024-01-25

Similar Documents

Publication Publication Date Title
US11843687B2 (en) Systems, devices, and processes for homomorphic encryption
Pornin et al. More efficient algorithms for the NTRU key generation using the field norm
JP6693508B2 (ja) 秘密計算システム、サーバ装置、秘密計算方法、および、プログラム
KR102550812B1 (ko) 동형 암호를 이용한 암호문 비교 방법 및 이를 수행하기 위한 장치
Baldimtsi et al. Sorting and searching behind the curtain
CN107077469B (zh) 服务器装置、检索系统、终端装置以及检索方法
Chida et al. An efficient secure three-party sorting protocol with an honest majority
US12333039B2 (en) Secret hash table construction system, reference system, methods for the same
Grassi et al. From farfalle to megafono via ciminion: The PRF hydra for MPC applications
Jayapandian et al. Secure and efficient online data storage and sharing over cloud environment using probabilistic with homomorphic encryption
JP7505583B2 (ja) 秘匿ハッシュテーブル構築装置、秘匿ハッシュテーブル構築システム、秘匿ハッシュテーブル構築方法、及びプログラム
JPWO2016148281A1 (ja) 秘匿文字列計算システム及び方法と装置並びにプログラム
Hoang A novel structure of fast and efficient multiple image encryption
Shi et al. Exploiting non-full key additions: full-fledged automatic Demirci-Selcuk meet-in-the-middle cryptanalysis of skinny
Liu et al. Efficient dynamic multi-client searchable encryption supporting fuzzy search
JPWO2020145340A1 (ja) 秘密配列アクセス装置、秘密配列アクセス方法、およびプログラム
El Hanouti et al. A lightweight hash function for cryptographic and pseudo-cryptographic applications
WO2020152831A1 (ja) 情報処理装置、秘密計算方法及びプログラム
Bambury et al. Cryptanalysis of an efficient signature based on isotropic quadratic forms
JPWO2016113878A1 (ja) 秘匿検索システム、秘匿検索プログラム及び変換後検索鍵生成装置
CN118332159A (zh) 保护隐私的数值范围查询方法、索引构建方法及装置
Alekseychuk et al. Cryptographic properties of a new national encryption standard of Ukraine
JP6693503B2 (ja) 秘匿検索システム、サーバ装置、秘匿検索方法、検索方法、およびプログラム
Liang et al. A Framework of Private Set Intersection Protocols.
Lau et al. A new encryption scheme based on rank metric codes

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20965126

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2022567986

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 18255928

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20965126

Country of ref document: EP

Kind code of ref document: A1