IP Library › Granted Patent US 12,580,772
Granted Patent B2
US 12,580,772 · App. 18/556,931 · Granted Mar 17, 2026

Secure consolidation system, information processing apparatus, secure consolidation method, and program

Inventors: Koki Hamada (Tokyo, JP); Koji Chida (Tokyo, JP); Masanobu Kii (Tokyo, JP); Atsunori Ichikawa (Tokyo, JP); Junichi Tomida (Tokyo, JP)
Assignee: NTT, Inc.
H04L9/3242H04L9/0618G09C1/00H04L9/0631H04L9/0643H04L2209/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,772
App. No.
18/556,931
Granted
Mar 17, 2026
Kind
B2
Abstract

The secure join system includes the first and second information-processing-apparatuses respectively holding first and second data. The second information-processing-apparatus is configured to: create third and fourth vectors in which a hash-value related to a key-value of the first data in a first vector and a ciphertext of the first data corresponding to the key-value in a second vector are rearranged by permutation; and create a fifth vector having a hash-value related to a key-value of the second data. The first information-processing-apparatus is configured to: search for j in which a hash-value of an i-th element of the fifth vector matches a j-th element value of the third vector for each i and create encrypted data in which a ciphertext of a j-th element value of the fourth vector is set when j is found and a ciphertext of a dummy value is set when j is not found.

Claims (57)

1 . A secure join system that performs secure data join between a first information processing apparatus and a second information processing apparatus, the secure join system comprising the first information processing apparatus and the second information processing apparatus,

the second information processing apparatus being configured to:

receive a first vector having a hash value related to a key value of first data held by the first information processing apparatus as an element and a second vector having an encrypted element generated by applying a re-encryption capable encryption scheme to the first data corresponding to the key value as an element,

after receiving the first and second vectors, create a third vector and a fourth vector that are generated by rearranging respective elements of the first vector and the second vector according to a permutation that is not known to the first information processing apparatus;

create a fifth vector having a hash value related to a key value of second data held by the second information processing apparatus as an element; and

transmit the third vector, the fourth vector, and the fifth vector to the first information processing apparatus, and

the first information processing apparatus being configured to:

after the third vector, the fourth vector, and the fifth vector are received, search for j in which a hash value of an i-th element of the fifth vector matches a value of a j-th element of the third vector for each i and create encrypted data in which a ciphertext of a value of a j-th element of the fourth vector is set as an i-th element in a case where j is found and a ciphertext of a dummy value is set as the i-th element in a case where j is not found; and

transmit the encrypted data to the second information processing apparatus when a match was found,

wherein ID assigned to each piece of data serves as the key value for the data join, and

the second information processing apparatus is further configured to:

generate the third vector and the fourth vector by applying a commutative hash function determined by a secret key to the IDs of the first data and by encrypting values of the first data using the re-encryption capable encryption scheme, and

generate the permutation used for rearranging the first vector and the second vector, and

the first information processing apparatus is further configured to assign, when no element of the third vector matches an element of the fifth vector, as the corresponding element, a dummy ciphertext that is indistinguishable in appearance from a ciphertext of actual data.

2 . The secure join system according to claim 1 ,

wherein, when f and g are commutative hash functions,

the first information processing apparatus being further configured to:

calculate a hash value, by f, of the key value of the first data held by the first information processing apparatus and create the first vector having the hash value as the element and the second vector having the ciphertext of the first data corresponding to the key value as the element; and

transmit the first vector and the second vector to the second information processing apparatus,

when the first vector and the second vector are received, the second information processing apparatus calculates a hash value, by g, of the element of the first vector and rearranges the hash value, by g, of the element of the first vector and the element of the second vector by the permutation to create the third vector and the fourth vector,

the second information processing apparatus creates the fifth vector having a hash value, by g, of the key value of the second data as the element, and

when the third vector, the fourth vector, and the fifth vector are received, the first information processing apparatus calculates a hash value, by f, of the i-th element of the fifth vector, searches for j in which the hash value matches a value of the j-th element of the third vector and creates encrypted data in which the ciphertext of the value of the j-th element of the fourth vector is set as the i-th element in a case where j is found and the ciphertext of the dummy value is set as the i-th element in a case where j is not found.

3 . An information processing apparatus that performs secure data join with another information processing apparatus, the information processing apparatus comprising:

a processor; and

a memory storing program instructions that cause the processor to:

receive a first vector having a hash value related to a key value of first data held by the another information processing apparatus as an element and a second vector having an encrypted element generated by applying a re-encryption capable encryption scheme to the first data corresponding to the key value as an element are received,

after receiving the first and second vectors, create a third vector and a fourth vector that are generated by rearranging respective elements of the first vector and the second vector according to a permutation that is not known to the first information processing apparatus;

create a fifth vector having a hash value related to a key value of second data held by the information processing apparatus as an element; and

transmit the third vector, the fourth vector, and the fifth vector to the another information processing apparatus when a match was found,

wherein ID assigned to each piece of data serves as the key value for the data join, and

the program instructions further cause the processor to:

generate the third vector and the fourth vector by applying a commutative hash function determined by a secret key to the IDs of the first data and by encrypting values of the first data using the re-encryption capable encryption scheme, and

generate the permutation used for rearranging the first vector and the second vector.

4 . An information processing apparatus that performs secure data join with another information processing apparatus, the information processing apparatus comprising:

a processor; and

a memory storing program instructions that cause the processor to:

receive a third vector and a fourth vector that are generated at the another information processing apparatus by rearranging respective elements of the first vector and the second vector according to a permutation that is not known to the first information processing apparatus, the first vector having a hash value related to a key value of first data held by the information processing apparatus as an element and the second vector having an encrypted element generated by applying a re-encryption capable encryption scheme to the first data corresponding to the key value as an element, and a fifth vector having a hash value related to a key value of second data held by the another information processing apparatus as an element,

search for j in which a hash value of an i-th element of the fifth vector matches a value of a j-th element of the third vector for each i and create encrypted data in which a ciphertext of a value of a j-th element of the fourth vector is set as an i-th element in a case where j is found and a ciphertext of a dummy value is set as an i-th element in a case where j is not found; and

transmit the encrypted data to the another information processing apparatus when a match was found,

wherein ID assigned to each piece of data serves as the key value for the data join, and

the program instructions cause the processor to assign, when no element of the third vector matches an element of the fifth vector, as the corresponding element, a dummy ciphertext that is indistinguishable in appearance from a ciphertext of actual data.

5 . A secure join method for performing secure data join between a first information processing apparatus and a second information processing apparatus, the secure join method comprising:

receiving, by the second information processing apparatus, a first vector having a hash value related to a key value of first data held by the first information processing apparatus as an element and a second vector having an encrypted element generated by applying a re-encryption capable encryption scheme to the first data corresponding to the key value as an element,

after receiving the first and second vectors, creating, by the second information processing apparatus, a third vector and a fourth vector that are generated by rearranging respective elements of the first vector and the second vector according to a permutation that is not known to the first information processing apparatus;

creating, by the second information processing apparatus, a fifth vector having a hash value related to a key value of second data held by the second information processing apparatus as an element; and

transmitting, by the second information processing apparatus, the third vector, the fourth vector, and the fifth vector to the first information processing apparatus, and

after the third vector, the fourth vector, and the fifth vector are received, searching, by the first information processing apparatus, for j in which a hash value of an i-th element of the fifth vector matches a value of a j-th element of the third vector for each i and creating encrypted data in which a ciphertext of a value of a j-th element of the fourth vector is set as an i-th element in a case where j is found and a ciphertext of a dummy value is set as the i-th element in a case where j is not found; and

transmitting, by the first information processing apparatus, the encrypted data to the second information processing apparatus when a match was found,

wherein ID assigned to each piece of data serves as the key value for the data join, and

the secure join method further comprises:

generating, by the second information processing apparatus, the third vector and the fourth vector by applying a commutative hash function determined by a secret key to the IDs of the first data and by encrypting values of the first data using the re-encryption capable encryption scheme, and

generating, by the second information processing apparatus, a permutation used for rearranging the first vector and the second vector is, and

wherein the secure join method further comprises:

assigning, when no element of the third vector matches an element of the fifth vector, as the corresponding element, a dummy ciphertext that is indistinguishable in appearance from a ciphertext of actual data.

6 . A non-transitory computer-readable recording medium having stored therein a program for causing the first information processing apparatus and the second information processing apparatus to execute the secure join method according to claim 5 .

7 . The secure join system according to claim 1 , wherein the first information processing apparatus does not transmit a ciphertext of the first data itself to the second information processing apparatus.

8 . The secure join system according to claim 1 , wherein the dummy ciphertext is generated by using the same encryption scheme used to generate the encrypted element included in the second vector.

Assignments (2)
CHANGE OF NAME Recorded Aug 15, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072491/0021 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2023
From: HAMADA, KOKI; CHIDA, KOJI; KII, MASANOBU; ICHIKAWA, ATSUNORI; TOMIDA, JUNICHI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 065323/0120 →
Continuity (1)
Related Publication 20240214213A1 · Jun 27, 2024
References Cited (15)
US 11797540B2 · Ikarashi · 2023 [cited by examiner]
US 11888973B2 · Ikarashi · 2024 [cited by examiner]
US 12079363B2 · Ikarashi · 2024 [cited by examiner]
US 20120011108A1 · Bensberg · 2012 [cited by examiner]
US 20130159731A1 · Furukawa · 2013 [cited by examiner]
US 20130179684A1 · Furukawa · 2013 [cited by examiner]
US 20160182222A1 · Rane · 2016 [cited by examiner]
US 20170255675A1 · Chavan · 2017 [cited by examiner]
US 20190205561A1 · Sierra · 2019 [cited by examiner]
US 20190251069A1 · Walker · 2019 [cited by examiner]
US 20210182419A1 · Ikarashi · 2021 [cited by examiner]
US 20210263921A1 · Ikarashi · 2021 [cited by examiner]
US 20210314145A1 · Ikarashi · 2021 [cited by examiner]
US 20240214212A1 · Hamada · 2024 [cited by examiner]
Koji Chida, Dai Igarashi, Koki Hamada, Katsumi Takahashi, “Anonymous Equijoin Protocol and its Applications”, In SCIS, pp. 1-8, Jan. 25-28, 2011. [cited by applicant]