Secure selective product computation system, secure selective product computation method, secure computation apparatus, and program
A secure selective product computation system ( 100 ) has conditions [c 0 ], . . . , [c n−1 ] and a binary table including m 0,0 , m 0,1 , . . . , m n−1,0 , and m n−1, 1 as inputs, and outputs a total product [A] of multipliers selected according to the conditions. A condition integrator ( 11 ) calculates share values [c i c i+1 ]. A table convertor ( 12 ) generates a 4-value table including m′ 00 , m′ 01 , m′ 10 , and m′ 11 A public value multiplier ( 13 ) calculates [ai]:=[c i c i+1 ](m 00 +m 11 −m 01 −m 10 )+[c i ](m i+1,0 −m i,0 )+[c i+1 ](m i,1 −m i,0 )+m i,0 . A real number multiplier ( 14 ) calculates a value [A] obtained by multiplying all [a i ]. A selective multiplier ( 15 ) multiplies [A] by a multiplier selected from multipliers m n−1, 0 and m n−1,1 according to c n−1 when n is an odd number.
1 . A secure selective product computation system for receiving a sequence of share values [c 0 ], . . . , [c n−1 ] of n conditions c 0 , . . . , c n−1 and a binary table including multipliers m 0,0 , m 0,1 , . . . , m n−1,0 , and m n−1, 1 associating two multipliers of the multipliers with each of the conditions as inputs, and outputting a share value [A] of a total product of the multipliers selected according to the conditions, the secure selective product computation system comprising:
a plurality of secure computation apparatuses, wherein
each secure computation apparatus of the plurality of secure computation apparatuses includes processing circuitry configured to:
calculate, in cooperation with others of the plurality of secure computation apparatuses via communications including transmitting and receiving data over a network, share values [c i c i+1 ] obtained by multiplying the share values [c i ] and the share values [c i+1 ] where i is an even number equal to or greater than 0 or smaller than n;
generate a 4-value table including m′ 00 , m′ 01 , m′ 10 , and m′ 11 where m′ 00 :=m i,0 m i+1,0 , m′ 01 :=m i,0 m i+1,1 , m′ 10 :=m i,1 m i+1,0 , and m′ 11 :=m i,1 m i+1,1 and i is an even number equal to or greater than 0 or smaller than n;
generate share values [a i ] of values a i obtained by calculating [c i c i+1 ](m 00 +m 11 −m 01 −m 10 )+[c i ](m i+1,0 −m i,0 )+[c i+1 ](m i,1 −m i,0 )+m i,0 where i is an even number equal to or greater than 0 or smaller than n;
calculate, in cooperation with others of the plurality of secure computation apparatuses via communications including transmitting and receiving data over the network, a share value [A] of a value A obtained by multiplying all the share values [a i ]; and
multiply, in cooperation with others of the plurality of secure computation apparatuses via communications including transmitting and receiving data over the network, the share value [A] by a multiplier selected from multipliers m n−1, 1 and m n−1,0 according to a condition c n−1 when n is an odd number.
2 . A secure selective product computation method executed by a secure selective product computation system for receiving a sequence of share values [c 0 ], . . . , [c n−1 ] of n conditions c 0 , . . . , c n−1 and a binary table including multipliers m 0,0 , m 0,1 , . . . , m n−1,0 , and m n−1, 1 associating two multipliers of the multipliers with each of the conditions as inputs, and outputting a share value [A] of a total product of the multipliers selected according to the conditions, the secure selective product computation system including a plurality of secure computation apparatuses, the secure selective product computation method comprising:
calculating, by processing circuitry of each secure computation apparatus of the plurality of secure computation apparatuses in cooperation with others of the plurality of secure computation apparatuses via communications including transmitting and receiving data over a network, share values [c i c i+1 ] obtained by multiplying the share values [c i ] and the share values [c i+1 ] where i is an even number equal to or greater than 0 or smaller than n;
generating, by the processing circuitry of each of the plurality of secure computation apparatuses, a 4-value table including m′ 00 , m′ 01 , m′ 10 , and m′ 11 where m′ 00 :=m i,0 m i+1,0 , m′ 01 :=m i,0 m i+1,1 , m′ 10 :=m i,1 m i+1,0 , and m′ 11 :=m i,1 m i+1,1 where i is an even number equal to or greater than 0 or smaller than n;
generating, by the processing circuitry of each of the plurality of secure computation apparatuses, share values [a i ] of values a i obtained by calculating [c i c i+1 ](m 00 +m 11 −m 01 −m 10 )+[c i ](m i+1,0 −m i,0 )+[c i+1 ](m i,1 −m i,0 )+m i,0 where i is an even number i equal to or greater than 0 or smaller than n;
calculating, by the processing circuitry of each secure computation apparatus of the plurality of secure computation apparatuses in cooperation with others of the plurality of secure computation apparatuses via communications including transmitting and receiving data over the network, a share value [A] of a value A obtained by multiplying all the share values [a i ]; and
multiplying, by the processing circuitry of each secure computation apparatus of the plurality of secure computation apparatuses in cooperation with others of the plurality of secure computation apparatuses via communications including transmitting and receiving data over the network, the share value [A] by a multiplier selected from multipliers m n−1,1 and m n−1,0 according to a condition c n−1 when n is an odd number.
3 . A non-transitory computer recording medium storing computer executable instructions which cause the plurality of secure computation apparatuses to perform the secure selective product computation method of claim 2 .