TEE (Trusted Execution Environment)を用いた プライバシー保護データ解析に向けた安全性指標の導入と アルゴリズムの開発

2026-08-20 統計数理研究所

統計数理研究所、電気通信大学、産業技術総合研究所の研究グループは、TEE(Trusted Execution Environment)を利用し、サイドチャネル攻撃にも耐えるプライバシー保護データ解析アルゴリズムを開発した。拡張型シャッフルモデルを1台のTEE搭載サーバで実現し、悪意あるユーザーだけでなく、サーバ管理者によるデータ閲覧や攻撃からも個人情報を保護する。特に、出力データだけでなくメモリアクセスパターンや制御フローからの情報漏洩まで考慮した新たな安全性指標「FODP(Fully Oblivious Differential Privacy)」を導入。ダミーデータや「bot」により攻撃者が得られる情報を制限しつつ、非対称幾何分布を用いて計算負荷を抑えた。大規模評価では、ユーザー数・カテゴリー数が各1億の場合、中央集権型方式の約270日に対して16時間以下で処理でき、同等の精度も実現した。

TEE (Trusted Execution Environment)を用いた プライバシー保護データ解析に向けた安全性指標の導入と アルゴリズムの開発
図1: 開発したアルゴリズム。シャッフルデータとサイドチャネル情報(メモリアクセスパターン・制御フロー)から元データが漏洩しないことをFODP(Fully Oblivious Differential Privacy)によって数理的に保証する。

<関連情報>

信頼できるプロセッサを備えた拡張シャッフルモデルにおける周波数推定のための完全秘匿差分プライバシー
Fully Oblivious Differential Privacy for Frequency Estimation in the Augmented Shuffle Model with Trusted Processors

Takao Murakami,Yuichi Sei,Reo Eriguchi
The 35th USENIX Security Symposium (USENIX Security 2026)

In the shuffle model of DP (Differential Privacy), a shuffler randomly permutes users’ data to achieve high accuracy and privacy. Recent studies show that most existing shuffle protocols are vulnerable to collusion attacks by the data collector and users. They address this issue by introducing the augmented shuffle model that incorporates random sampling and dummy data addition into the shuffler. However, it remains open how to ensure the shuffler follows the protocol and does not collude with the data collector in this model.

We address this trust issue by thoroughly exploring the augmented shuffle model with TEEs (Trusted Execution Environments). We first introduce a new privacy notion, FODP (Fully Oblivious DP), which strengthens DP to prevent various TEE side-channel attacks based on external/internal memory access patterns and control flows. We propose a general framework for FODP algorithms based on memory-size obfuscation and three concrete algorithms within it. We also improve the efficiency of our algorithms by using the count-min sketch and optimizing the number of hashes. We evaluate our algorithms on Intel SGX and demonstrate their effectiveness through comparisons with nine baselines.

1604情報ネットワーク
ad
ad
Follow
ad
タイトルとURLをコピーしました