US 12,141,322 B2
Analysis query response system, analysis query execution apparatus, analysis query verification apparatus, analysis query response method, and program
Atsunori Ichikawa, Musashino (JP); and Koki Hamada, Musashino (JP)
Assigned to NIPPON TELEGRAPH AND TELEPHONE CORPORATION, Tokyo (JP)
Appl. No. 17/413,578
Filed by NIPPON TELEGRAPH AND TELEPHONE CORPORATION, Tokyo (JP)
PCT Filed Dec. 19, 2019, PCT No. PCT/JP2019/049849
§ 371(c)(1), (2) Date Jun. 14, 2021,
PCT Pub. No. WO2020/130082, PCT Pub. Date Jun. 25, 2020.
Claims priority of application No. 2018-238166 (JP), filed on Dec. 20, 2018.
Prior Publication US 2022/0058290 A1, Feb. 24, 2022
Int. Cl. G06F 21/62 (2013.01); G06F 16/2452 (2019.01)
CPC G06F 21/6254 (2013.01) [G06F 16/2452 (2019.01); G06F 21/6227 (2013.01)] 4 Claims
OG exemplary drawing
 
1. An analysis query response system comprising:
a user terminal that generates and transmits an analysis query, the analysis query including at least information about a function that performs an analysis calculation; and
a database apparatus including an analysis query verification apparatus that includes processing circuitry configured to perform a first verification of whether the analysis query satisfies a predetermined privacy preservation indicator, and an analysis query execution apparatus that includes processing circuitry configured to, in a case where the first verification is successful, performs an analysis corresponding to the analysis query on personal data read from a personal data memory that stores personal data to acquire an analysis result, and apply a predetermined privacy-preserving mechanism to the acquired analysis result,
wherein:
the user terminal generates the analysis query under the predetermined privacy preservation indicator and a predetermined programming language,
the processing circuitry of the analysis query execution apparatus is configured to discard the analysis query in a case where the first verification is unsuccessful,
the user terminal additionally generates and transmits proof information, the proof information being information related to a proof that the analysis query satisfies the predetermined privacy preservation indicator,
the processing circuitry of the analysis query verification apparatus is configured to use the proof information to perform the first verification of whether the analysis query satisfies the predetermined privacy preservation indicator,
the predetermined privacy preservation indicator is ε-differential privacy.