IP Library Granted Patent US 12,452,042
Granted Patent B2
US 12,452,042 · App. 17/791,907 · Granted Oct 21, 2025

Secure computation apparatus, secure computation method, and program

Inventor: Dai Ikarashi (Musashino, JP)
Assignee: NTT, Inc.
H04L9/085G09C1/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,042
App. No.
17/791,907
Granted
Oct 21, 2025
Kind
B2
Abstract

A secret share value [y]=[δx 2 +ax] is obtained through secure computation using a secret share value [x] of a real number x, and a secret share value [func(x)]=[y(ζy+b)+cx] of an elementary function approximation value z=func(x) of the real number x is obtained and output through secure computation using secret share values [x] and [y]. Here, x, y, and z are real numbers, a, b, c, δ, and ζ are real number coefficients, and a secret share value of · is [·].

Claims (77)

1. A secure computation device for secure computation while concealing data, wherein x, y, and z are real numbers, a, b, c, δ, and ζ are real number coefficients, and a secret share value of · is [·], the secure computation device comprising:

processing circuitry configured to:

obtain a secret share value [y]=[δx 2 +ax] through the secure computation using a secret share value [x] of the real number x; and

obtain and output a secret share value [func(x)]=[y(ζy+b)+cx] of an elementary function approximation value z=func(x) of the real number x through the secure computation using the secret share value [x] and the secret share value [y],

wherein the secret share value [func(x)]=[y(ζy+b)+cx] is obtained through the secure computation while concealing data of the secure computation,

wherein a number of digits that the processing circuitry can handle is finite, and

wherein the secret share value [func(x)] does not overflow the processing circuitry.

2. A secure computation device for secure computation while concealing data, wherein x, y, z, and w are real numbers, a, b, c, d, f, g, α, β, γ, δ, and ζ are real number coefficients, and a secret share value of · is [·], the secure computation device comprising:

processing circuitry configured to:

obtain a secret share value [y]=[δx 2 +ax] through the secure computation using a secret share value [x] of the real number x;

obtain a secret share value [z]=[y(ζy+b)+cx] through the secure computation using the secret share value [x] and the secret share value [y]; and

obtain and output a secret share value [func(x)]=[γ(z(αz+d)+y(βx+f)+gx)] of an elementary function approximation value w=func(x) of the real number x through the secure computation using the secret share value [x], the secret share value [y], and the secret share value [z],

wherein the secret share value [func(x)]=[γ(z(αz+d)+y(βx+f)+gx)] is obtained through the secure computation while concealing data of the secure computation,

wherein a number of digits that the processing circuitry can handle is finite, and

wherein the secret share value [func (x)] does not overflow the processing circuit.

3. A secure computation device for secure computation while concealing data, wherein x, y, and z are real numbers, a, b, c, γ, δ, and ζ are real number coefficients, and a secret share value of · is [·], the secure computation device comprising:

processing circuitry configured to:

obtain a secret share value [y]=[δx 2 +ax] through the secure computation using a secret share value [x] of the real number x; and

obtain and output a secret share value [func(x)]=[γ(y(ζy+b)+cx)] of an elementary function approximation value z=func(x) of the real number x through the secure computation using the secret share value [x] and the secret share value [y],

wherein the secret share value [func(x)]=[γ(y(ζy+b)+cx)] is obtained through the secure computation while concealing data of the secure computation,

wherein a number of digits that the processing circuitry can handle is finite, and

wherein the secret share value [func (x)] does not overflow the processing circuitry.

4. The secure computation device according to claim 1 , wherein

the secret share value [x] is related to χ, p, and L,

χ is a real number, p is a positive integer, L is an integer equal to or greater than 2, [·] is a secret share value obtained by performing linear secret sharing on an element · on a quotient ring modulo p, and {·} is a secret share value obtained by performing linear secret sharing on an element · on a quotient ring modulo 2, and

the processing circuitry is further configured to:

obtain secret share values {χ 0 }, . . . , {χ L−1 } of an L-bit representation χ 0 . . . χ L−1 of the real number χ through the secure computation using a secret share value [χ] of the real number χ;

obtain secret share values {η 0 }, . . . , {η L−1 } of an msb flag sequence η 0 , . . . , η L−1 where a bit η msb corresponding to a most significant bit χ msb of a bit sequence χ 0 . . . χ L−1 is 1 and bits ηξ(ξ ϵ{0, . . . , L−1}) other than the bit η msb are 0 through the secure computation using the secret share values {χ 0 }, . . . , {χ L−1 };

obtain a secret share value {ρ i }={ρ i+1 V χi } where 0≤i<L−1 and a secret share value {ρ L−1 }={χ L−1 } through the secure computation using the secret share values {χ 0 }, . . . , {χ L −1 };

obtain a secret share value [θ] of a count value θ indicating the number of elements being 1 among ρ 0 , . . . , ρ L−1 through the secure computation using secret share values {ρ 0 }, . . . , {ρ L−1 };

obtain a secret share value [ν] of an msb flag value ν=η 0 . . . η L−1 obtained by bit-connecting the msb flag sequence η 0 , . . . , η L−1 through the secure computation using the secret share values {η 0 }, . . . , {η L−1 };

obtain the secret share value [x]=[χ][ν] through the secure computation using the secret share value [χ] and the secret share value [ν]; and

obtain and output [log χ]=[func(x)]−[θ] through the secure computation using the secret share value [func(x)] and the secret share value [θ].

5. A secure computation method for secure computation while concealing data, wherein x, y, and z are real numbers, a, b, c, δ, and ζ are real number coefficients, and a secret share value of · is [·], the secure computation method, performed by processing circuitry, comprising:

obtaining a secret share value [y]=[δx 2 +ax] through the secure computation using a secret share value [x] of the real number x; and

obtaining and outputting a secret share value [func(x)]=[y(ζy+b)+cx] of an elementary function approximation value z=func(x) of the real number x through the secure computation using the secret share value [x] and the secret share value [y],

wherein the secret share value [func(x)]=[y(ζy+b)+cx] is obtained through the secure computation while concealing data of the secure computation,

wherein a number of digits that the processing circuitry can handle is finite, and

wherein the secret share value [func(x)] does not overflow the processing circuitry.

6. A secure computation method for secure computation while concealing data, wherein x, y, z, and w are real numbers, a, b, c, d, f, g, α, β, γ, δ, and ζ are real number coefficients, and a secret share value of · is [·], the secure computation method, performed by processing circuitry, comprising:

obtaining a secret share value [y]=[δx 2 +ax] through the secure computation using a secret share value [x] of the real number x;

obtaining a secret share value [z]=[y(ζy+b)+cx] through the secure computation using the secret share value [x] and the secret share value [y]; and

obtaining and outputting a secret share value [func(x)]=[γ(z(αz+d)+y(βx+f)+gx)] of an elementary function approximation value w=func(x) of the real number x through the secure computation using the secret share value [x], the secret share value [y], and the secret share value [z],

wherein the secret share value [func(x)]=[γ(z(αz+d)+y(βx+f)+gx)] is obtained through the secure computation while concealing data of the secure computation,

wherein a number of digits that the processing circuitry can handle is finite, and

wherein the secret share value [func(x)] does not overflow the processing circuitry.

7. A secure computation method for secure computation while concealing data, wherein x, y, and z are real numbers, a, b, c, γ, δ, and ζ are real number coefficients, and a secret share value of · is [·], the secure computation method, performed by processing circuitry, comprising:

obtaining a secret share value [y]=[δx 2 +ax] through the secure computation using a secret share value [x] of the real number x; and

obtaining and outputting a secret share value [func(x)]=[γ(y(ζy+b)+cx)] of an elementary function approximation value z=func(x) of the real number x through the secure computation using the secret share value [x] and the secret share value [y],

wherein the secret share value [func(x)]=[γ(y(ζy+b)+cx)] is obtained through the secure computation while concealing data of the secure computation,

wherein a number of digits that the processing circuitry can handle is finite, and

wherein the secret share value [func(x)] does not overflow the processing circuitry.

8. A non-transitory computer-readable recording medium storing a program for causing a computer to perform the method of claim 5 .

9. The secure computation device according to claim 2 , wherein

the secret share value [x] is related to χ, p, and L,

χ is a real number, p is a positive integer, L is an integer equal to or greater than 2, [·] is a secret share value obtained by performing linear secret sharing on an element · on a quotient ring modulo p, and {·} is a secret share value obtained by performing linear secret sharing on an element · on a quotient ring modulo 2, and

the processing circuitry is further configured to:

obtain secret share values {χ 0 }, . . . , {χ L−1 } of an L-bit representation χ 0 . . . χ L−1 of the real number χ through the secure computation using a secret share value [χ] of the real number x;

obtain secret share values {η 0 }, . . . , {η L−1 } of an msb flag sequence η 0 , . . . , η L−1 where a bit η msb corresponding to a most significant bit χ msb of a bit sequence χ 0 . . . χ L−1 is 1 and bits ηξ(ξ ϵ{0, . . . , L−1}) other than the bit η msb are 0, through the secure computation using the secret share values {η 0 }, . . . , {η L−1 };

obtain a secret share value {ρ i }={ρ i+1 V χi } where 0≤i<L−1 and a secret share value {ρ L−1 }={χ L−1 } through the secure computation using the secret share values {χ 0 }, . . . , {χ L −1 };

obtain a secret share value [θ] of a count value θ indicating the number of elements being 1 among ρ 0 , . . . , ρ L−1 through the secure computation using secret share values {ρ 0 ), . . . , {p L−1 };

obtain a secret share value [ν] of an msb flag value ν=η 0 . . . n L−1 obtained by bit-connecting the msb flag sequence η 0 , . . . , η L−1 through the secure computation using the secret share values {η 0 }, . . . , {η L−1 };

obtain the secret share value [x]=[χ][ν] through the secure computation using the secret share value [χ] and the secret share value [ν]; and

obtain and output [log χ]=[func(x)]−[θ] through the secure computation using the secret share value [func(x)] and the secret share value [θ].

10. The secure computation device according to claim 3 , wherein

the secret share value [x] is related to χ, p, and L,

χ is a real number, p is a positive integer, L is an integer equal to or greater than 2, [·] is a secret share value obtained by performing linear secret sharing on an element · on a quotient ring modulo p, and {·} is a secret share value obtained by performing linear secret sharing on an element · on a quotient ring modulo 2, and

the processing circuitry is further configured to:

obtain secret share values {χ 0 }, . . . , {χ L−1 } of an L-bit representation χ 0 . . . χ L−1 of the real number χ through the secure computation using a secret share value [χ] of the real number x;

obtain secret share values {η 0 }, . . . , {η L−1 } of an msb flag sequence η 0 , . . . , η L−1 where a bit η msb corresponding to a most significant bit χ msb of a bit sequence χ 0 . . . χ L−1 is 1 and bits ηξ(ξ ϵ{0, . . . , L−1}) other than the bit η msb are 0 through the secure computation using the secret share values {χ 0 }, . . . , {χ L−1 };

obtain a secret share value {ρ i }={ρ i +V χi } where 0≤i<L−1 and a secret share value {ρ L−1 }={χ L−1 } through the secure computation using the secret share values {χ 0 }, . . . , {χ L −1 };

obtain a secret share value [θ] of a count value θ indicating the number of elements being 1 among ρ 0 , . . . , ρ L−1 through the secure computation using secret share values {ρ 0 }, . . . , {ρ L−1 };

obtain a secret share value [ν] of an msb flag value ν=η 0 . . . η L−1 obtained by bit-connecting the msb flag sequence η 0 , . . . , η L−1 through the secure computation using the secret share values {η 0 }, . . . , {η L−1 };

obtain the secret share value [x]=[χ][ν] through the secure computation using the secret share value [χ] and the secret share value [ν]; and

obtain and output [log χ]=[func(x)]−[θ] through the secure computation using the secret share value [func(x)] and the secret share value [θ].

11. A non-transitory computer-readable recording medium storing a program for causing a computer to perform the method of claim 6 .

12. A non-transitory computer-readable recording medium storing a program for causing a computer to perform the method of claim 7 .

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072801/0812 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2022
From: IKARASHI, DAI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 060621/0774 →
Continuity (1)
Related Publication 20220407682A1 · Dec 22, 2022
References Cited (12)
US 20170365192A1 · Ikarashi · 2017 [cited by examiner]
US 20180011996A1 · Dolev · 2018 [cited by examiner]
US 20180225431A1 · Ikarashi · 2018 [cited by examiner]
US 20180373834A1 · Cho · 2018 [cited by examiner]
US 20190228299A1 · Chandran · 2019 [cited by examiner]
US 20200366466A1 · Ikarashi · 2020 [cited by examiner]
US 20210287573A1 · Hamada · 2021 [cited by examiner]
WO 2019225531A1 · 2019 [cited by applicant]
Ikarashi, “Secure Real Number Operations for Secure Al—O(lpl)-Bit Communication and O(1)-Round Right Shift Protocol-”, CSS2019, 2019, 16 pages including English Translation. [cited by applicant]
Toomas Krips et al., “Hybrid Model of Fixed and Floating Point Numbers in Secure Multiparty Computations”, ICAR, International Association for Cryptologic Research, Dec. 23, 2014, total 24 pages. [cited by applicant]
Abdelrahaman Aly et al., “Benchmarking Privacy Preserving Scientific Operations”, ACNS 2019, LNCS 11464, 2019, pp. 509-529, total 21 pages. [cited by applicant]
Mehrdad Aliasgari et al., “Secure Computation on Floating Point Numbers”, IACR, International Association for Cryptologic Research, 2012, total 27 pages. [cited by applicant]