Fully homomorphic encryption based on non-cyclotomic rings

AE202602403AUndeterminedDWALLET LABS LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
AE202602403
Authority / Receiving Office
AE · AE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-10-01
Filing Date
2025-01-14

Smart Images

  • Figure ABST_ABST
    Figure ABST_ABST
Patent Text Reader

Abstract

A processor-based method of fully homomorphic encryption, comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring; wherein the first non-cyclotomic ring is a quotient of: a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:the third non-cyclotomic ring, and a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.  
Need to check novelty before this filing date? Find Prior Art

Description

FULLY HOMOMORPHIC ENCRYPTION BASED ON NON-CYCLOTOMIC RINGSTECHNICAL FIELDThe presently disclosed subject matter relates to data security, and in particular to methods of encryption and decryption.BACKGROUND Problems of performing fully homomorphic encryption and decryption have been recognized in the conventional art and various techniques have been developed to provide solutions. SUMMARYAccording to one aspect of the presently disclosed subject matter there is a processing circuitry (PC)-based method of fully homomorphic encryption, the method comprising:encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.In addition to the above features, the method according to this aspect of the presently disclosed subject matter can comprise one or more of features (i) to (xxii) listed below, in any desired combination or permutation which is technically possible: (i) the irreducible non-cyclotomic polynomial is one of:f(x) = xn + x – b, or f(x) = xn - x + b; and the first ideal is:x-b wherein b is an integer.(ii) the method further comprising, prior to the encrypting: encoding a given plaintext, of a given plaintext space, to the element of the first non-cyclotomic ring, the encoding being based on:  EncodedElement =  wherein EncodedElement denotes the element of the first non-cyclotomic ring, FirstIdeal denotes the first ideal, and  wherein m denotes the given plaintext, and wherein mi is based on: m =  and wherein f(b) is equivalent to a size of the given plaintext space.(iii) the third non-cyclotomic ring is an order of a field, the field being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial. (iv) the third non-cyclotomic ring is a final extension ring of a series of extension rings, the series of extension rings successively extending the fourth non-cyclotomic ring, the series of extension rings being of a given series length,wherein each successive extension ring is based on an equation:CurrentNonCyclotomicExtensionRing = PredecessorNonCyclotomicRing[t] / MinimalPolynomialwherein PredecessorNonCyclotomicRing denotes a respective immediately preceding extension ring of the series, t is a respective additional algebraic element, and wherein MinimalPolynomial denotes a respective minimal polynomial, the respective minimal polynomial being based on an equation:MinimalPolynomial =  wherein FirstIdeal denotes the first ideal, and wherein each aj is a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal, n is a respective given integer greater than 1,and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing[t], and the minimal polynomial is irreducible in PredecessorNonCyclotomicRing.(v) the given series length is 1, and wherein the final extension ring of the series of final extensions rings is based on: CurrentNonCyclotomicExtensionRing = FourthNonCyclotomicRing[t] / MinimalPolynomial where FourthNonCyclotomicRing denotes the fourth non-cyclotomic ring. (vi) the minimal polynomial defining the final extension ring is one of:%2. tn2 + tn + x, or %2. tn2 - tn + x, or%2. tn2 + tn + x, or%2. tn2 - tn + x,wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings.(vii) the minimal polynomial defining the final extension ring is one of:%2. tn2 + tn + btn-1, or%2. tn2 - tn + btn-1, or%2. tn2 + tn - btn-1, or%2. tn2 - tn - btn-1,  wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, andwherein tn-1 denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring.  (viii) the method further comprising, prior to the encrypting, encoding a given number of plaintexts to an element of the first non-cyclotomic ring, wherein the encoding comprises: a) generating, for each plaintext of the given number of plaintexts, a respective per-plaintext ring element of the first non-cyclotomic ring, the generating being based on: PerPlaintextRingElement = wherein PerPlaintextRingElement denotes the element of the first non-cyclotomic ring, and wherein m denotes the given plaintext, and wherein mi is based on: m =  and wherein f(b) is equivalent to a size of the given plaintext space; andb) calculating an encoded element based on the formula:EncodedElementc0 =  wherein EncodedElementc0 denotes the element of the first non-cyclotomic ring, n denotes the given number of plaintexts, PerPlaintextRingElementidenotes a respective per-plaintext ring element, and denotes a respective Lagrange coefficient.(ix)the given number of plaintexts is: wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring.(x) the encrypting the element of a first non-cyclotomic ring comprises:calculating a linear combination, over the second non-cyclotomic ring of, at least:%3. the element of the first non-cyclotomic ring, %3. a sum of, at least:%5. a product of, at least, an encryption key and a randomizer, and %5. a noise value,the calculating thereby resulting in an element of the second non-cyclotomic ring.(xi) the encryption key is an element of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.(xii) the encrypting is based on:  EncryptedElementc0 = (PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.(xiii)the encrypting is based on: EncryptedElementc0 = (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. (xiv) the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * ) + (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue)) + Randomizer3)mod (ThirdNonCyclotomicRing / SecondIdeal)wherein the first ideal and second ideal are principal ideals,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. (xv) the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * SecondIdeal) + ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. (xvi) the encrypting is based on: EncryptedElementc0 = (PlaintextElement + (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. (xvii) the encryption key is an element of a module derivative of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm. (xviii) the encrypting is based on:  EncryptedElementc0 = (PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.(xix) the encrypting is based on: EncryptedElementc0 = (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.   (xx) the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * ) + (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue)) + Randomizer3)mod (ThirdNonCyclotomicRing / SecondIdeal)wherein the first ideal and second ideal are principal ideals,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. (xxi) the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * SecondIdeal) + ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. (xxii) the encrypting is based on: EncryptedElementc0 = (PlaintextElement + (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.According to another aspect of the presently disclosed subject matter there is provided a system of fully homomorphic encryption, the system comprising a processing circuitry (PC) configured to:encrypt an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xxii) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible. According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processing circuitry to perform a method of fully homomorphic encryption, the method comprising:encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xxii) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible. |According to another aspect of the presently disclosed subject matter there is a processing circuitry (PC)-based method of decrypting fully homomorphically encrypted data, the method comprising:decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.In addition to the above features, the method according to this aspect of the presently disclosed subject matter can comprise one or more of features (i) to (xvi) listed below, in any desired combination or permutation which is technically possible: (i) the irreducible non-cyclotomic polynomial is one of:f(x) = xn + x – b, or f(x) = xn - x + b; and the first ideal is:x-b wherein b is an integer. (ii) the method further comprising, subsequent to the decrypting: decoding the element of the first non-cyclotomic ring to a plaintext of a given plaintext space. (iii) the decoding is based on calculating:  felement(b)wherein felement() is a polynomial function corresponding to the element of the first non-cyclotomic ring. (iv) the first non-cyclotomic ring is a quotient ring based on a final ring of a series of successive rings extending a fourth non-cyclotomic ring, and wherein the decoding comprises:  a) determining one or more roots of a minimal polynomial associated with the first non-cyclotomic ring; b) for each determined root:calculating a result of substituting, in the element of the first non-cyclotomic ring, a respective extending algebraic element with the respective root,thereby generating one or more elements of a quotient ring derivative of a preceding ring of the series; c) responsive to the preceding ring being an extension ring of the fourth non-cyclotomic ring: for each generated element: repeating a) - b); and d) responsive to the preceding ring being the fourth non-cyclotomic ring:calculating, for each generated element felement();felement(b)thereby giving rise to one or more plaintexts. (v) the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring: a value based on a product of a decryption key and a randomizing element,the decryption key and the randomizing element being elements of the second non-cyclotomic ring,thereby resulting in an element of the first non-cyclotomic ring.(vi) the decrypting is based on: DecryptedElement = EncryptedElementc0 - (DecryptionKey * EncryptedElementc1) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementc1 denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key. (vii) the decryption key is a symmetric key.(viii) the decryption key is a private key.(ix) the randomizing element is derivative of at least one randomizer.(x) the randomizing element is further derivative of at least one constant value. (xi) the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring: a value based on a product of a decryption key and a randomizing element,the decryption key and the randomizing element being elements of a module derivative of the second non-cyclotomic ring,(xii) the decrypting is based on: DecryptedElement = EncryptedElementc0 - (DecryptionKey * EncryptedElementc1) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementc1 denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.(xiii) the decryption key is a symmetric key.(xiv) the decryption key is a private key.(xv) The randomizing element is derivative of at least one randomizer.(xvi) the randomizing element is further derivative of at least one constant value.According to another aspect of the presently disclosed subject matter there is provided a system of decrypting fully homomorphically encrypted data, the system comprising a processing circuitry (PC) configured to:decrypt an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xvi) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible. According to another aspect of the presently disclosed subject matter there is provided a computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processing circuitry to perform a method of fully homomorphic encryption, the method comprising:encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.This aspect of the disclosed subject matter can further optionally comprise one or more of features (i) to (xvi) listed above with respect to the method, mutatis mutandis, in any desired combination or permutation which is technically possible. BRIEF DESCRIPTION OF THE DRAWINGSIn order to understand the invention and to see how it can be carried out in practice, embodiments will be described, by way of non-limiting examples, with reference to the accompanying drawings, in which:Fig. 1 illustrates an example deployment of fully-homomorphic encryption / decryption, in accordance with some embodiments of the presently disclosed subject matter;Fig. 2A illustrates a logical block diagram of an example computer system enabled for performance of fully homomorphic encryption (FHE), in accordance with some embodiments of the presently disclosed subject matter;Fig. 2B illustrates a logical block diagram of an example deployment of a computer system enabled for decryption of data encrypted using FHE, in accordance with some embodiments of the presently disclosed subject matter;Fig. 3 illustrates a flow diagram of an example method of ring-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter;Fig. 4 illustrates a flow diagram of an example method of module-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter; andFig. 5 illustrates a flow diagram of an example method of decrypting data that was encrypted using ring-based or module-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.DETAILED DESCRIPTIONIn the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention.  However, it will be understood by those skilled in the art that the presently disclosed subject matter may be practiced without these specific details.  In other instances, well-known methods, procedures, components and circuits have not been described in detail so as not to obscure the presently disclosed subject matter. Unless specifically stated otherwise, as apparent from the following discussions, it is appreciated that throughout the specification discussions utilizing terms such as "processing", "computing", "comparing", "encrypting", “decrypting”, "determining", "calculating", “receiving”, “providing”, “obtaining”, “emulating” or the like, refer to the action(s) and / or process(es) of a computer that manipulate and / or transform data into other data, said data represented as physical, such as electronic, quantities and / or said data representing the physical objects. The term “computer” should be expansively construed to cover any kind of hardware-based electronic device with data processing capabilities including, by way of non-limiting example, the processor, mitigation unit, and inspection unit therein disclosed in the present application. The terms "non-transitory memory" and “non-transitory storage medium” used herein should be expansively construed to cover any volatile or non-volatile computer memory suitable to the presently disclosed subject matter. The operations in accordance with the teachings herein may be performed by a computer specially constructed for the desired purposes or by a general-purpose computer specially configured for the desired purpose by a computer program stored in a non-transitory computer-readable storage medium. Embodiments of the presently disclosed subject matter are not described with reference to any particular programming language.  It will be appreciated that a variety of programming languages may be used to implement the teachings of the presently disclosed subject matter as described herein.Homomorphic encryption is a form of encryption that allows computations to be performed on encrypted data. When mathematical operations are performed on a homomorphically encrypted ciphertext, the result is a ciphertext that, when decrypted, matches the result of identical operations performed on the original plaintext. Certain homomorphic encryption schemes allow limited types of operations (e.g. addition or multiplication only). Fully Homomorphic Encryption (FHE) supports both addition and multiplication operations on ciphertexts, making it theoretically possible to perform any computation on encrypted data.In distributed computing, homomorphic encryption can be valuable because it allows data to be processed by untrusted third parties without exposing sensitive information. For example, in cloud computing environments, users can offload computations to a cloud server without revealing the underlying data. This is useful in privacy-preserving applications such as secure voting systems, confidential machine learning, and secure data outsourcing. By ensuring that the data remains encrypted throughout the process, homomorphic encryption enhances security and privacy while enabling distributed systems to perform necessary computations.Some embodiments of the presently disclosed subject matter are directed to methods of fully-homomorphic encryption and decryption based on non-cyclotomic rings. Some advantages of methods based on non-cyclotomic rings are presented in the additional disclosure section below.Fig. 1 illustrates an example deployment of fully-homomorphic encryption / decryption, in accordance with some embodiments of the presently disclosed subject matter.Encryption system 105 can be a computer system adapted to perform encryption in a manner which enables FHE decryption. An example encryption system 105 is described below, with reference to Fig. 2A.Communication network 110 can be any kind of suitable network for computer communications (Ethernet, Wi-Fi, 3G wireless network, 4G wireless network, 5G wireless network, Infiniband, etc.). In embodiments, communication network 110 includes a local area network (LAN), a wide area network (WAN), the Internet, and / or one or more Intranets. Communication network 110 can be operably attached to encryption system 105, encrypted calculation system 115, anddecryption system 120.Encryption calculation system 115 can be a computer system adapted to perform computation on FHE-encrypted data (i.e. without decrypting it first). Decryption system 120 can be a computer system adapted to perform FHE decryption. An example encryption system 105 is described below, with reference to Fig. 2B.In some examples, encryption system 105 can encrypt data using homomorphic encryption in combination with e.g. a public key that is associated with a private key held by decryption system 120. Encryption system 105 can e.g. transmit the encrypted data to encrypted calculations system 115, which performs mathematical operations based on the encrypted data. Encrypted calculations system 115 cantransmit the results of the mathematical operations to decryption system 120, which can then decrypt the encrypted results of the mathematical operations e.g. using its private key.Fig. 2A illustrates a logical block diagram of an example computer system enabled for performance of fully homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.Encryption system (processing circuitry) 200A can include processor 205A andmemory 210A.Processor 205A can be a suitable hardware-based electronic device with data processing capabilities, such as, for example, a general purpose processor, digital signal processor (DSP), a specialized Application Specific Integrated Circuit (ASIC), one or more cores in a multicore processor, etc. Processor 205A can also consist, for example, of multiple processors, multiple ASICs, virtual processors, combinations thereof etc. Memory 210A can be, for example, a suitable kind of volatile and / or non-volatile storage, and can include, for example, a single physical memory component or a plurality of physical memory components. Memory 210A can also include virtual memory. Memory 210A can be configured to, for example, store various data used in computation. Encryption system (processing circuitry) 200A can be configured to execute several functional modules in accordance with computer-readable instructions implemented on a non-transitory computer-readable storage medium. Such functional modules are referred to hereinafter as comprised in the processing circuitry. These modules can include, for example, communications unit 215A, optional ring-based encryption unit 220A,optionalmodule-based encryption unit 225A, and optional encoding unit 230A. The functional modules may include hardware modules, software modules, firmware modules, or combinations thereof. In some embodiments, the operations described with reference to one or more of the communications unit 215A, optional ring-based encryption unit 220A,optionalmodule-based encryption unit 225A, and optional encoding unit 230A may be combined into fewer units. In some embodiments, the operations described with reference to one or more of the communications unit 215A, optional ring-based encryption unit 220A,optionalmodule-based encryption unit 225A, and optional encoding unit 230A may be split up and handled by separate units.Communications unit 215A can be any suitable component usable for communicating via communication network 110 (ethernet controller, wi-fi controller etc.). Communications unit 215A can facilitate e.g. reception of data for encryption and / or transmission of encrypted data.Optional ring-based encryption unit 220A can encrypt data using a ring-based fully homomorphic encryption method as detailed herein. Some embodiments of the presently disclosed subject matter utilize a plaintext ring which is a quotient ring of a non-cyclotomic ring (termed R) and an Ideal (termed I). Such a plaintext ring (herein termed “P”) can be described formally as:P = R / Iwhere R is a ring such that:R=Z[x] / f()Where:- Z[x] denotes the set of all polynomials with integer coefficients (and for which the operations of addition and multiplication are defined as polynomial addition and multiplication), - f() is an irreducible non-cyclotomic polynomial and - the ideal I is a non-trivial ideal of the ring R (i.e. a proper subset of R satisfying additive closure and absorption, as known in the art).Some embodiments of the presently disclosed subject matter utilize a ciphertext ring which is a quotient ring of the non-cyclotomic ring R and a second ideal herein termed Q (which is distinct from I). Such a ciphertext ring (herein termed “C”) can be described formally as:C = R / QIn some embodiments, the plaintext ring and ciphertext ring are based on the following definitions:- The irreducible non-cyclotomic polynomial from which the non-cyclotomic ring R is derived is:f(x) = xn + x – bfor some degree n,and the Ideal of the non-cyclotomic ring is:x-bwhere b is an integer.In some other embodiments, the plaintext ring and ciphertext ring are based on the following definitions:- The irreducible non-cyclotomic polynomial from which the non-cyclotomic ring R is derived is:f(x) = xn + x + bfor some degree n,and the Ideal of the non-cyclotomic ring is:x-bwhere b is an integer.In some other embodiments, the plaintext ring and ciphertext ring are based on other specifications of f() and I.Some embodiments of the presently disclosed subject matter are directed to methods of encrypting an element of a non-cyclotomic plaintext ring to an element of a non-cyclotomic ciphertext ring.These methods can employ a e.g. symmetric encryption key or a public key / private key scheme. These methods can also employ one or more randomizers and / or constant values. These methods can also employ noise values.To facilitate subsequent homomorphic mathematical operations as well as decryption / reconstruction of plaintexts, some embodiments utilize a pair of ciphertext ring elements which can be transmitted together.In some examples herein, this pair of elements making up a ciphertext are described as two elements in parentheses, e.g.(c0, c1)where c0 identifies a ciphertext ring element that is derivative of an encryption operation utilizing e.g. a plaintext element, an encryption key and other parameters, and where c1 is a ciphertext ring element that is derivative of e.g. randomizers and / or noise values and / or constant values and / or other parameters.In some examples herein, the pair of elements making up a ciphertext are described using the terms EncryptedElementc0 and EncryptedElementc1 to refer to the respective elements. In some cases herein, EncryptedElementc1 is referred to as a “randomizing element”.Ring-based encryption unit 220A can, for example, utilize methods such as the methods described below with reference to Fig. 3.Optional module-based encryption unit 225A can encrypt data using a module-based fully homomorphic encryption method. A module over a ring R is a generalization of a vector space, where the scalars come from a ring rather than a field.Some embodiments of the presently disclosed subject matter are directed to encryption / decryption methods which utilize modules as randomizing elements.In such embodiments, the second element (i.e. c1) of the (c0, c1) ciphertext (i.e. EncryptedElementc1) is a module. Module-based encryption can have desirable security properties, as detailed below.Module-based encryption unit 225A can, for example, utilize methods such as the methods described below with reference to Fig. 4.Optional encoding unit 230A can encode data (e.g. integers, binary data) to elements of a plaintext ring to facilitate encryption. Optional encoding unit 230A can utilize encoding methods as described below with reference to Fig. 3.It is noted that encryption system (processing circuitry) 200A can additionally implement some or all of the functions of encryption system (processing circuitry) 200B.Fig. 2B illustrates a logical block diagram of an example deployment of a computer system enabled for decryption of data encrypted using FHE, in accordance with some embodiments of the presently disclosed subject matter.Decryption system (processing circuitry) 200B can include processor 205B andmemory 210B.Processor 205B can be a suitable hardware-based electronic device with data processing capabilities, such as, for example, a general purpose processor, digital signal processor (DSP), a specialized Application Specific Integrated Circuit (ASIC), one or more cores in a multicore processor, etc. Processor 205B can also consist, for example, of multiple processors, multiple ASICs, virtual processors, combinations thereof etc. Memory 210B can be, for example, a suitable kind of volatile and / or non-volatile storage, and can include, for example, a single physical memory component or a plurality of physical memory components. Memory 210B can also include virtual memory. Memory 210B can be configured to, for example, store various data used in computation. Decryption system (processing circuitry) 200B can be configured to execute several functional modules in accordance with computer-readable instructions implemented on a non-transitory computer-readable storage medium. Such functional modules are referred to hereinafter as comprised in the processing circuitry. These modules can include, for example, communications unit 215B, decryption unit 220B, andoptional decoding unit 225B.Decryption unit 220B can receive ciphertexts (e.g. ring-based or module-based) and can decrypt them to e.g. plaintext ring elements unit 220B can do this, for example, utilizing methods such as the methods described below with reference to Fig. 5.Decoding unit 225B can then decode decrypted plaintext ring elements unit to e.g. integer or binary data. Decoding unit 225B can utilize, for example methods such as those described below with reference to Fig. 5.Attention is directed to Fig. 3, which illustrates a flow diagram of an example method of ring-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.Optionally: in some examples, it is desirable to perform fully homomorphic encryption (and possibly subsequent encrypted mathematical operations) upon plaintexts consisting of integers, binary data etc. To accomplish this, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode (305) such a plaintext. More specifically: encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can map the plaintext to an element of a plaintext ring (e.g. a plaintext ring in accordance with the plaintext ring definition provided above), so as to facilitate performing fully homomorphic encryption on the plaintext ring element. In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes a single plaintext to a single element of the plaintext ring. In some other examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes multiple plaintexts to a single plaintext ring element. In some examples, a plaintext consists of a series of binary digits of a plaintext space of given size. For example: a binary plaintext can be of length 8 (i.e. the plaintext size is 256). In such embodiments, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode the plaintext to a polynomial element of the plaintext ring (the ring being defined by a polynomial f() ) based on the formula:EncodedElement =   wherein m denotes the given plaintext, and wherein mi is based on:m =  and where f(b) is equivalent to the size of the plaintext space, and Logb() denotes the logarithm in base b.Accordingly, when the value of b is 2 (i.e. the first Ideal is x-2):EncodedElement =  where m denotes the given plaintext, and wherein mi is based on: m =  It is noted that in the formula above (i.e. with b = 2), the indexes of the polynomial terms are identical to the binary digits of the plaintext.In some embodiments, multiple plaintexts can be encoded in a single plaintext ring element for encryption.In such embodiments, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can utilize a special case of the non-cyclotomic ring R from which the plaintext ring and ciphertext ring are derived. Specifically, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can utilize a non-cyclotomic ring R that is an order of a field, the field in turn being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial.In some such embodiments, this ring can be a final ring of a recursive series of extension rings of the fourth non-cyclotomic ring for which:the irreducible non-cyclotomic polynomial f(x) is either xn + x – b or xn - x + b, and the first ideal (where the plaintext ring is derived by taking the quotient of the fourth non-cyclotomic ring R and the first ideal) is x-bwhere b is some integer. For example, the first extension ring of the fourth non-cyclotomic ring can be based on:FourthNonCyclotomicRing[t] / MinimalPolynomialwhere t is an algebraic element being added to the fourth non-cyclotomic ring, and where the minimal polynomial can be based on:  and wherein c(t) and d(t) are polynomials in FourthNonCyclotomicRing[t], and the minimal polynomial is irreducible in the fourth non-cyclotomic ring. In some embodiments, n is an integer greater than one that defines the degree of the minimal polynomial (and determines the number of plaintext slots that will be available). Each aj can be a unique element of a ring that is a quotient of the fourth non-cyclotomic ring and the first ideal.Similarly, subsequent extension rings can be based on:PredecessorNonCyclotomicRing[ti] / MinimalPolynomial wherein PredecessorNonCyclotomicRing denotes the immediately preceding extension ring of the series, and ti is a respective additional algebraic element being added in this extension.In this case, the minimal polynomial of the extension can again be based on: and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing [t], and the minimal polynomial is irreducible in the fourth non-cyclotomic ring. n is an integer greater than one that defines the degree of the minimal polynomial (and determines the number of plaintext slots that will be available). Each aj can be a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal. In some embodiments, n is an integer greater than one that defines the degree of this particular minimal polynomial.The series of recursive extensions of the fourth non-cyclotomic ring can have a particular series length (e.g. 5).The number of plaintext slots available in an element of the final extension ring of the series of extension rings can then be: wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring.In some embodiments, the minimal polynomial defining the final extension ring of the series of extension rings is one of:%2) tn2 + tn + x, or %2) tn2 - tn + x, or%2) tn2 + tn + x, or%2) tn2 - tn + x,wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings.In some embodiments, the minimal polynomial defining the final extension ring is one of:a) tn2 + tn + btn-1, orb) tn2 - tn + btn-1, orc) tn2 + tn - btn-1, ord) tn2 - tn - btn-1, wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, and wherein tn-1 denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring.Encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode a given number of plaintexts to a single ring element of the plaintext ring that is the quotient of the final extension ring and the first ideal.In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes a number of plaintexts that is equivalent to the number of plaintext slots available in each ring element (as given by the formula above). In some examples, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) encodes a number of plaintexts that is less than the number of plaintext slots available, and utilizes other values (e.g. 0) in the unused slots.Encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode the plurality of plaintexts based on the following steps:a) generating, for each plaintext of the given number of plaintexts, a respective per-plaintext ring element of the plaintext ring, the generating being based on: PerPlaintextRingElement = wherein PerPlaintextRingElement denotes the element of the plaintext ring, and wherein m denotes the given plaintext, and wherein mi is based on: m =  and wherein f(b) is equivalent to a size of the given plaintext space; andb) calculating an encoded element based on the formula:EncodedElementc0 =  wherein EncodedElementc0 denotes the element of the plaintext ring, n denotes the given number of plaintexts, PerPlaintextRingElementidenotes a respective per-plaintext ring element, and denotes a respective Lagrange coefficient.It is noted that this encoding method can be utilized to encode plaintexts to rings other than the rings defined herein. Similarly, it is noted that this encoding method can be utilized in the context of other applications (e.g. other encryption applications, non-encryption applications).Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can obtain (310) an encryption key. In some examples, the encryption key is received or derived from a secure key exchange mechanism. In some examples, the encryption key is an element of the ciphertext ring. . In some examples, the encryption key is an element of an algebraic structure (e.g. a module) that is derivative of the ciphertext ring.Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally obtain one or more randomizer. A randomizer can be a random value (with suitable distribution characteristics as described herein), that is used in the encryption to enhance security. In some examples, randomizers are obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use a randomizer.Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally obtain one or more noise values. Noise values can be a random value (with suitable distribution characteristics as described herein), that are used in homomorphic encryption to enhance security. In some examples, the noise values is obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use noise values.Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can next encrypt (315) an element of the plaintext ring to an element of the ciphertext ring.In some embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) performs the encryption by calculating a linear combination, over the ciphertext ring of, at least:the element of the plaintext ring to be encrypted, and a sum of, at least:(%5) a product of, at least, an encryption key and a randomizer, and (%5) a noise valuewhere the encryption key is an element of the ciphertext ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.In some such embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a symmetric encryption key, e.g. in accordance with the formula: EncryptedElementc0 = (PlaintextElement + (Randomizer * EncryptionKey + NoiseValue)) mod (ThirdNonCyclotomicRing / SecondIdeal) wherein ThirdNonCyclotomicRing denotes the plaintext ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the plaintext ring, EncryptionKey is the encryption key (i.e. an element of the ciphertext ring), NoiseValue is a noise value is sampled from the first ideal, and Randomizer is sampled from a distribution over a ring with a bounded expected norm.In this case the associated randomizing element (e.g. for use in decryption) can be defined in accordance with the formula:EncryptedElementc! = (Randomizer) mod (ThirdNonCyclotomicRing / SecondIdeal)It is noted that in this case EncryptedElementc0 is a linear combination of the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, e.g. in accordance with the formula: EncryptedElementc0 = (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal)where ConstantValue is a constant that is an element of the ciphertext ring, and Randomizer3 is sampled from distributions over respective rings with bounded expected norms. In this case the associated randomizing element can be defined in accordance with the formula:EncryptedElementC1 = ((Randomizer * ConstantValue)` + Randomizer2) mod (ThirdNonCyclotomicRing / SecondIdeal)where Randomizer2 is sampled from a distribution over a ring with a bounded expected norm.It is noted that here also EncryptedElementc0 is a linear combination of, at least, the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal and second ideal are principal ideals, in accordance the following formula: EncryptedElementc0 = ( (PlaintextElement * + ((Randomizer1 * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal)In this case the associated randomizing element can be defined in accordance with the formula:EncryptedElementc1 = ((Randomizer1 * ConstantValue)` + Randomizer2) mod (ThirdNonCyclotomicRing / SecondIdeal)In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal is not a principal ideal, and the second ideal is a principal ideal, in accordance the following formula: EncryptedElementc0 = ( (PlaintextElement * SecondIdeal) + ((Randomizer1 * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )In this case the associated randomizing element can be defined in accordance with the formula:EncryptedElementc1 = ((Randomizer1 * ConstantValue)` + Randomizer2) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the element of the plaintext ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, in accordance the following formula: EncryptedElementc0 = (PlaintextElement + ((Randomizer1 * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )In this case the associated randomizing element can be defined in accordance with the formula:EncryptedElementc1 = ((Randomizer1 * ConstantValue) + Randomizer2) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )Encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can optionally store (320) data derivative of the randomizer(s) and / or constant value, for use in decryption. For example: encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can compute EncryptedElementc1 according to formulas given above.Attention is directed to Fig. 4, which illustrates a flow diagram of an example method of module-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.As in the case of ring-based encryption, encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can encode (405) a plaintext to the plaintext ring. Encryption system (processing circuitry) 200A (e.g. encoding unit 230A) can optionally utilize encoding methods as described with reference to Fig. 3 above.Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can obtain (410) an encryption key. In some examples, the encryption key is received or derived from a secure key exchange mechanism. In some examples, the encryption key is an element of a module that is derivative of the ciphertext module.Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally obtain one or more randomizer. A randomizer can be a random value (with suitable distribution characteristics as described herein), that is used in the encryption to enhance security. In some examples, randomizers are obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use a randomizer.Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally obtain one or more noise values. Noise values can be a random value (with suitable distribution characteristics as described herein), that are used in homomorphic encryption to enhance security. In some examples, the noise values is obtained from a random number generator implemented hardware and / or software. It is noted that some encryption schemes do not use noise values.Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can then encrypt (415) an element of the plaintext ring to an element of the ciphertext ring, utilizing an encryption key that is an element of a module that is derivative of the ciphertext ring, as known in the art.In some embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) performs the encryption by calculating a linear combination, over the ciphertext ring of, at least:the element of the plaintext ring to be encrypted, and a sum of, at least:(i) a product of, at least, an encryption key and a randomizer, and (ii) a noise valuewhere the encryption key is an element of a module derived from the ciphertext ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm.In some such embodiments, encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can perform encryption using a symmetric encryption key, e.g. in accordance with the formula: EncryptedElementc0 = (PlaintextElement + (Randomizer * EncryptionKey + NoiseValue)) mod (ThirdNonCyclotomicRing / SecondIdeal) wherein ThirdNonCyclotomicRing denotes the plaintext ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the plaintext ring, EncryptionKey is the encryption key, NoiseValue is a noise value is sampled from the first ideal, and Randomizer is the randomizer.In this case the associated randomizing element (e.g. for use in decryption) can be defined in accordance with the formula:EncryptedElementc! = (Randomizer) mod (ThirdNonCyclotomicRing / SecondIdeal)It is noted that in this case EncryptedElementc0 is a linear combination of the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.In some other embodiments, encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can perform encryption using a public / private encryption key pair, e.g. in accordance with the formula: EncryptedElementc0 = (PlaintextElement + ((Randomizer1 * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal)where ConstantValue is a constant that is an element of a module derivative of the ciphertext ring, Randomizer1 and Randomizer2 are sampled from distributions over respective modules with bounded expected norms, and Randomizer3 is sampled from a distribution over a ring with a bounded expected normIn this case the associated randomizing element can be defined in accordance with the formula:EncryptedElementC1 = ((Randomizer1 * ConstantValue)` + Randomizer2) mod (ThirdNonCyclotomicRing / SecondIdeal)It is noted that here also EncryptedElementc0 is a linear combination of, at least, the element of the plaintext ring to be encrypted, and a sum of: the product of the encryption key and a randomizer, and the noise value.In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal and second ideal are principal ideals, in accordance the following formula: EncryptedElementc0 = ( (PlaintextElement * + ((Randomizer1 * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal)In this case the associated randomizing element can be defined in accordance with the formula:EncryptedElementc1 = ((Randomizer1 * ConstantValue)` + Randomizer2) mod (ThirdNonCyclotomicRing / SecondIdeal)In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the first ideal is not a principal ideal, and the second ideal is a principal ideal, in accordance the following formula: EncryptedElementc0 = ( (PlaintextElement * SecondIdeal) + ((Randomizer1 * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )In this case the associated randomizing element can be defined in accordance with the formula:EncryptedElementc1 = ((Randomizer1 * ConstantValue)` + Randomizer2) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )In some other embodiments, encryption system (processing circuitry) 200A (e.g. ring-based encryption unit 220A) can perform encryption using a public / private encryption key pair, where the element of the plaintext ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal, in accordance the following formula: EncryptedElementc0 = (PlaintextElement + ((Randomizer1 * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )In this case the associated randomizing element can be defined in accordance with the formula:EncryptedElementc1 = ((Randomizer1 * ConstantValue) + Randomizer2) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )Encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can optionally store (420) data derivative of the randomizer(s) and / or constant value, for use in decryption. For example: encryption system (processing circuitry) 200A (e.g. module-based encryption unit 225A) can compute EncryptedElementc1 according to formulas given above.Attention is directed to Fig. 5, which illustrates a flow diagram of an example method of decrypting data that was encrypted using ring-based or module-based fully-homomorphic encryption, in accordance with some embodiments of the presently disclosed subject matter.Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain (505) a decryption key corresponding to the encryption key used to encrypt the ciphertext ring element to be decrypted. A decryption key can be e.g. a symmetric key, or a private key of a public / private key pair. In some examples, the decryption key can be received or derived as part of a key distribution protocol. The ecryption key can be, for example a ciphertext ring element, or an element of an algebraic structure (e.g. a module or other algebraic structure) that is derivative of the ciphertext ring.Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain data derivative of any randomizers / constants used in encryption. In some examples, decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can simply obtain the randomizers and / or constants. In other examples, decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can obtain a randomizing element that is derivative of the randomizers and / or constants (as described above with reference to encryption methods). Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can utilize the randomizing elements in decryption, as described below. Decryption system (processing circuitry) 200B (e.g. decryption unit 220B) can decrypt (510) an element of the ciphertext ring to an element of the plaintext ring.In some embodiments, decryption system (processing circuitry) 200B (e.g. encryption unit 220B) performs the decryption by a method comprising: subtracting, from the element of the second non-cyclotomic ring, a value based on a product of a decryption key and a randomizing element.In some such embodiments, the decryption key and the randomizing element are elements of the ciphertext ring. In some other embodiments, the decryption key and the randomizing element are elements of the module derived from the ciphertext ring, as known in the art.More formally: considering a case where an encryption procedure generated the encrypted element (EncryptedElementc0, EncryptedElementc1), the decrypting can be performed based on the following formula:DecryptedElement = EncryptedElementc0 - (DecryptionKey * EncryptedElementc1) mod (ThirdNonCyclotomicRing / SecondIdeal)where ThirdNonCyclotomicRing denotes the non-cyclotomic ring R, SecondIdeal denotes the second ideal of R (termed Q), DecryptedElement denotes the resulting element of the plaintext ring, and DecryptionKey denotes the decryption key.In some embodiments, the decryption key is symmetric (i.e. is the same as the encryption key). In some other embodiments, the decryption key is a private key i.e. a non-public key that corresponds to a public key that was utilized in the encryption operation that generated the element of the ciphertext ring.In some embodiments, the randomizing element EncryptedElementc1 is identical with a randomizer that was multiplied by the encryption key in the encryption operation.In some embodiments, the randomizing element EncryptedElementc1 is derivative of a randomizer that was multiplied by the encryption key in the encryption operation, and is further derivative of – for example - one or more additional randomizers and / or constant values and / or other parameters.Decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can decode (515) the plaintext ring element to plaintext data (e.g. binary data). In some embodiments, when parameter b is 2, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can map an element of the plaintext ring to a plaintext by calculating:felement(2)where felement () is the plaintext ring element (i.e. a polynomial) resulting from the decoding. It is noted that this decoding method is the inverse of the encoding method which maps plaintext bits to coefficients of polynomial terms (as described above).As described in detail above, a single plaintext ring element can, in some examples, be an encoding of multiple plaintexts. Accordingly, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can perform decoding on the plaintext ring element, thereby generating multiple plaintexts.In some examples, the plaintext ring element is a quotient ring of: a final ring of a series of extension rings, and a non-trivial ideal of the final ring.It is noted that, as described in detail above each extension ring can be defined as:PredecessorNonCyclotomicRing[t] / MinimalPolynomialwhere t is an algebraic element being added to the predecessor ring (i.e. to extend it), and where the minimal polynomial can be:  To decode an element of a quotient ring derivative of an extended ring thus defined, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can generate, from the ring element, one or more ring elements of a quotient ring derivative of the immediately preceding extension ring in the series.To generate the one or more ring elements of the quotient ring based on the immediately preceding ring, decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can:a) determine the roots of the minimal polynomial associated with the ring of the encoded ring element. These can be identical with the aj values in the definition of the minimal polynomial. b) for each determined root aj:calculate a result of substituting, in the encoded ring element, the respective extending algebraic element (i.e. t) with the constant value aj,thereby generating one or more elements of a quotient ring based on the preceding ring of the series (i.e. generating a quotient ring element for each determined aj).If the preceding ring is also an extension ring, then decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can then repeat steps a) -b) on this next ring.If the preceding ring is a non-cyclotomic ring based on either xn + x – b or xn - x + b, with the ideal being x-b (for some integer b) - i.e. not an extension of such a ring, then decryption system (processing circuitry) 200B (e.g. decoding unit 225B) can calculate, for each generated element felement();felement(b)thereby resulting in one or more plaintexts.It is noted that this decoding method can be utilized to decode from rings other than the rings defined herein. It is similarly noted that this decoding method can be utilized in the context of other applications (e.g. other decryption applications, non-decryption applications).It is to be understood that the invention is not limited in its application to the details set forth in the description contained herein or illustrated in the drawings. The invention is capable of other embodiments and of being practiced and carried out in various ways. Hence, it is to be understood that the phraseology and terminology employed herein are for the purpose of description and should not be regarded as limiting. As such, those skilled in the art will appreciate that the conception upon which this disclosure is based may readily be utilized as a basis for designing other structures, methods, and systems for carrying out the several purposes of the presently disclosed subject matter.It will also be understood that the system according to the invention may be, at least partly, implemented on a suitably programmed computer. Likewise, the invention contemplates a computer program being readable by a computer for executing the method of the invention. The invention further contemplates a non-transitory computer-readable memory tangibly embodying a program of instructions executable by the computer for executing the method of the invention.Those skilled in the art will readily appreciate that various modifications and changes can be applied to the embodiments of the invention as hereinbefore described without departing from its scope, defined in and by the appended claims. CLAIMS1. A processing circuitry (PC)-based method of fully homomorphic encryption, the method comprising:encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:c. the third non-cyclotomic ring, and d. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. 2. The method of claim 1, wherein the irreducible non-cyclotomic polynomial is one of:f(x) = xn + x – b, or f(x) = xn - x + b; and wherein the first ideal is:x-b wherein b is an integer. 3. The method of claim 2, the method further comprising, prior to the encrypting: encoding a given plaintext, of a given plaintext space, to the element of the first non-cyclotomic ring, the encoding being based on:  EncodedElement =  wherein EncodedElement denotes the element of the first non-cyclotomic ring, FirstIdeal denotes the first ideal, and  wherein m denotes the given plaintext, and wherein mi is based on: m =  and wherein f(b) is equivalent to a size of the given plaintext space.  4. The method of claim 2, wherein the third non-cyclotomic ring is an order of a field, the field being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial. 5. The method of claim 4, wherein the third non-cyclotomic ring is a final extension ring of a series of extension rings, the series of extension rings successively extending the fourth non-cyclotomic ring, the series of extension rings being of a given series length,wherein each successive extension ring is based on an equation:CurrentNonCyclotomicExtensionRing = PredecessorNonCyclotomicRing[t] / MinimalPolynomialwherein PredecessorNonCyclotomicRing denotes a respective immediately preceding extension ring of the series, t is a respective additional algebraic element, and wherein MinimalPolynomial denotes a respective minimal polynomial, the respective minimal polynomial being based on an equation:MinimalPolynomial =  wherein FirstIdeal denotes the first ideal, and wherein each aj is a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal, n is a respective given integer greater than 1,and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing[t], and the minimal polynomial is irreducible in PredecessorNonCyclotomicRing. 6. The method of claim 5, wherein the given series length is 1, and wherein the final extension ring of the series of final extensions rings is based on: CurrentNonCyclotomicExtensionRing = FourthNonCyclotomicRing[t] / MinimalPolynomial where FourthNonCyclotomicRing denotes the fourth non-cyclotomic ring. 7. The method of claim 5, wherein the minimal polynomial defining the final extension ring is one of:%2) tn2 + tn + x, or %2) tn2 - tn + x, or%2) tn2 + tn + x, or%2) tn2 - tn + x,wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings.8. The method of claim 5, wherein the minimal polynomial defining the final extension ring is one of:%2) tn2 + tn + btn-1, or%2) tn2 - tn + btn-1, or%2) tn2 + tn - btn-1, or%2) tn2 - tn - btn-1,  wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, andwherein tn-1 denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring.  9. The method of claim 5, the method further comprising, prior to the encrypting, encoding a given number of plaintexts to an element of the first non-cyclotomic ring, wherein the encoding comprises: a) generating, for each plaintext of the given number of plaintexts, a respective per-plaintext ring element of the first non-cyclotomic ring, the generating being based on: PerPlaintextRingElement = wherein PerPlaintextRingElement denotes the element of the first non-cyclotomic ring, and wherein m denotes the given plaintext, and wherein mi is based on: m =  and wherein f(b) is equivalent to a size of the given plaintext space; andb) calculating an encoded element based on the formula:EncodedElementc0 =  wherein EncodedElementc0 denotes the element of the first non-cyclotomic ring, n denotes the given number of plaintexts, PerPlaintextRingElementidenotes a respective per-plaintext ring element, and denotes a respective Lagrange coefficient.10.The method of claim 9, wherein the given number of plaintexts is: wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring.11. The method of claim 1, wherein the encrypting the element of a first non-cyclotomic ring comprises:calculating a linear combination, over the second non-cyclotomic ring of, at least:%3. the element of the first non-cyclotomic ring, %3. a sum of, at least:(%5) a product of, at least, an encryption key and a randomizer, and (%5) a noise value,the calculating thereby resulting in an element of the second non-cyclotomic ring.12. The method of claim 11, wherein the encryption key is an element of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.13. The method of claim 12, wherein the encrypting is based on:  EncryptedElementc0 = (PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.14.The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. 15. The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * ) + (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue)) + Randomizer3)mod (ThirdNonCyclotomicRing / SecondIdeal)wherein the first ideal and second ideal are principal ideals,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. 16. The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * SecondIdeal) + ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. 17. The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. 18. The method of claim 11, wherein the encryption key is an element of a module derivative of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm. 19. The method of claim 18, wherein the encrypting is based on:  EncryptedElementc0 = (PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.20. The method of claim 18, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.   21. The method of claim 18, wherein the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * ) + (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue)) + Randomizer3)mod (ThirdNonCyclotomicRing / SecondIdeal)wherein the first ideal and second ideal are principal ideals,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. 22. The method of claim 18, wherein the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * SecondIdeal) + ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. 23. The method of claim 18, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. 24. A system of fully homomorphic encryption, the system comprising a processing circuitry (PC) configured to:encrypt an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. 25. A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processor to perform a method of fully homomorphic encryption, the method comprising: encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. 26. A processing circuitry (PC)-based method of decrypting fully homomorphically encrypted data, the method comprising: decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. 27. The method of claim 26, wherein the irreducible non-cyclotomic polynomial is one of:f(x) = xn + x – b, or f(x) = xn - x + b; and wherein the first ideal is:x-b wherein b is an integer.28. The method of claim 27, the method further comprising, subsequent to the decrypting: decoding the element of the first non-cyclotomic ring to a plaintext of a given plaintext space. 29. The method of claim 28 where the decoding is based on calculating:  felement(b)wherein felement() is a polynomial function corresponding to the element of the first non-cyclotomic ring.  30. The method of claim 28 wherein the first non-cyclotomic ring is a quotient ring based on a final ring of a series of successive rings extending a fourth non-cyclotomic ring, and wherein the decoding comprises:  a) determining one or more roots of a minimal polynomial associated with the first non-cyclotomic ring; b) for each determined root:calculating a result of substituting, in the element of the first non-cyclotomic ring, a respective extending algebraic element with the respective root,thereby generating one or more elements of a quotient ring derivative of a preceding ring of the series; c) responsive to the preceding ring being an extension ring of the fourth non-cyclotomic ring: for each generated element: repeating a) - b); and d) responsive to the preceding ring being the fourth non-cyclotomic ring:calculating, for each generated element felement();felement(b)thereby giving rise to one or more plaintexts. 31. The method of claim 26, wherein the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring: a value based on a product of a decryption key and a randomizing element,the decryption key and the randomizing element being elements of the second non-cyclotomic ring,thereby resulting in an element of the first non-cyclotomic ring.32. The method of claim 31, wherein the decrypting is based on: DecryptedElement = EncryptedElementc0 - (DecryptionKey * EncryptedElementc1) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementc1 denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key. 33. The method of claim 31, wherein the decryption key is a symmetric key.34. The method of claim 31, wherein the decryption key is a private key.35. The method of claim 31, wherein the randomizing element is derivative of at least one randomizer.36. The method of claim 35, wherein the randomizing element is further derivative of at least one constant value. 37. The method of claim 26, wherein the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring: a value based on a product of a decryption key and a randomizing element,the decryption key and the randomizing element being elements of a module derivative of the second non-cyclotomic ring,38. The method of claim 37, wherein the decrypting is based on: DecryptedElement = EncryptedElementc0 - (DecryptionKey * EncryptedElementc1) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementc1 denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.39. The method of claim 37, wherein the decryption key is a symmetric key.40. The method of claim 37, wherein the decryption key is a private key.41. The method of claim 37, wherein the randomizing element is derivative of at least one randomizer.42. The method of claim 41, wherein the randomizing element is further derivative of at least one constant value. 43. A system of decrypting fully homomorphically encrypted data, the system comprising a processing circuitry (PC) configured to: decrypt an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. 44. A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processor to perform a method of decrypting fully homomorphically encrypted data, the method comprising: decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. 

Claims

Claim 1.A processing circuitry (PC)-based method of fully homomorphic encryption, the method comprising:encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring,wherein the second ideal is not the first ideal. Claim 2. The method of claim 1, wherein the irreducible non-cyclotomic polynomial is one of:f(x) = xn + x – b, or f(x) = xn - x + b; and wherein the first ideal is: x-b wherein b is an integer.Claim 3. The method of claim 2, the method further comprising, prior to the encrypting:encoding a given plaintext, of a given plaintext space, to the element of the first non-cyclotomic ring, the encoding being based on:  EncodedElement =  wherein EncodedElement denotes the element of the first non-cyclotomic ring, FirstIdeal denotes the first ideal, and  wherein m denotes the given plaintext, and wherein mi is based on: m =  and wherein f(b) is equivalent to a size of the given plaintext space.Claim 4. The method of claim 2, wherein the third non-cyclotomic ring is an order of a field, the field being an extension of a fourth non-cyclotomic ring that is derivative of the irreducible non-cyclotomic polynomial. Claim 5. The method of claim 4, wherein the third non-cyclotomic ring is a final extension ring of a series of extension rings, the series of extension rings successively extending the fourth non-cyclotomic ring, the series of extension rings being of a given series length,wherein each successive extension ring is based on an equation:CurrentNonCyclotomicExtensionRing = PredecessorNonCyclotomicRing[t] / MinimalPolynomialwherein PredecessorNonCyclotomicRing denotes a respective immediately preceding extension ring of the series, t is a respective additional algebraic element, and wherein MinimalPolynomial denotes a respective minimal polynomial, the respective minimal polynomial being based on an equation:MinimalPolynomial =  wherein FirstIdeal denotes the first ideal, and wherein each aj is a unique element of a ring that is a quotient of PredecessorNonCyclotomicRing and the first ideal, n is a respective given integer greater than 1,and wherein c(t) and d(t) are polynomials in PredecessorNonCyclotomicRing[t], and the minimal polynomial is irreducible in PredecessorNonCyclotomicRing.Claim 6. The method of claim 5, wherein the given series length is 1, and wherein the final extension ring of the series of final extensions rings is based on:CurrentNonCyclotomicExtensionRing = FourthNonCyclotomicRing[t] / MinimalPolynomial where FourthNonCyclotomicRing denotes the fourth non-cyclotomic ring. Claim 7. The method of claim 5, wherein the minimal polynomial defining the final extension ring is one of:%2) tn2 + tn + x, or %2) tn2 - tn + x, or%2) tn2 + tn + x, or%2) tn2 - tn + x,wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings.Claim 8. The method of claim 5, wherein the minimal polynomial defining the final extension ring is one of:%2) tn2 + tn + btn-1, or%2) tn2 - tn + btn-1, or%2) tn2 + tn - btn-1, or%2) tn2 - tn - btn-1,  wherein tndenotes the additional algebraic element of the final extension ring of the series of extension rings, andwherein tn-1 denotes the additional algebraic element of the extension ring, of the series of extension rings, immediately preceding the final extension ring.Claim 9. The method of claim 5, the method further comprising, prior to the encrypting, encoding a given number of plaintexts to an element of the first non-cyclotomic ring, wherein the encoding comprises: a) generating, for each plaintext of the given number of plaintexts, a respective per-plaintext ring element of the first non-cyclotomic ring, the generating being based on: PerPlaintextRingElement = wherein PerPlaintextRingElement denotes the element of the first non-cyclotomic ring, and wherein m denotes the given plaintext, and wherein mi is based on: m =  and wherein f(b) is equivalent to a size of the given plaintext space; andb) calculating an encoded element based on the formula:EncodedElementc0 =  wherein EncodedElementc0 denotes the element of the first non-cyclotomic ring, n denotes the given number of plaintexts, PerPlaintextRingElementidenotes a respective per-plaintext ring element, and denotes a respective Lagrange coefficient.Claim 10. The method of claim 9, wherein the given number of plaintexts is: wherein SeriesLength is the given series length of the series of extension rings, and di is a respective degree of the respective minimal polynomial of the respective extension ring. Claim 11. The method of claim 1, wherein the encrypting the element of a first non-cyclotomic ring comprises:calculating a linear combination, over the second non-cyclotomic ring of, at least:%3. the element of the first non-cyclotomic ring, %3. a sum of, at least:(%5) a product of, at least, an encryption key and a randomizer, and (%5) a noise value,the calculating thereby resulting in an element of the second non-cyclotomic ring. Claim 12. The method of claim 11, wherein the encryption key is an element of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a ring with a bounded expected norm.Claim 13. The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.Claim 14. The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. Claim 15. The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * ) + (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue)) + Randomizer3)mod (ThirdNonCyclotomicRing / SecondIdeal)wherein the first ideal and second ideal are principal ideals,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. Claim 16. The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * SecondIdeal) + ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.Claim 17. The method of claim 12, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.Claim 18. The method of claim 11, wherein the encryption key is an element of a module derivative of the second non-cyclotomic ring, the noise value is sampled from the first ideal, and the randomizer is sampled from a distribution over a module with a bounded expected norm.Claim 19. The method of claim 18, wherein the encrypting is based on:  EncryptedElementc0 = (PlaintextElement + ((Randomizer * EncryptionKey) + NoiseValue) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer.Claim 20. The method of claim 18, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + ((Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)) mod (ThirdNonCyclotomicRing / SecondIdeal) wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm. Claim 21. The method of claim 18, wherein the encrypting is based on:EncryptedElementc0 = ((PlaintextElement * ) + (Randomizer * ((ConstantValue * EncryptionKey) + NoiseValue)) + Randomizer3)mod (ThirdNonCyclotomicRing / SecondIdeal)wherein the first ideal and second ideal are principal ideals,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.. Claim 22. The method of claim 18, wherein the encrypting is based on: EncryptedElementc0 = ((PlaintextElement * SecondIdeal) + ((Randomizer * (ConstantValue * EncryptionKey)) + NoiseValue) + Randomizer3) mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the first ideal is not a principal ideal, and the second ideal is a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.Claim 23. The method of claim 18, wherein the encrypting is based on: EncryptedElementc0 = (PlaintextElement + (Randomizer * (ConstantValue * EncryptionKey) + NoiseValue) + Randomizer3)mod (ThirdNonCyclotomicRing / (SecondIdeal * FirstIdeal) )wherein the element of the first non-cyclotomic ring is in the second ideal, the first ideal is a principal ideal, and the second ideal is not a principal ideal,wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, FirstIdeal denotes the first ideal, SecondIdeal denotes the second ideal, PlaintextElement denotes the element of the first non-cyclotomic ring, EncryptionKey denotes the encryption key, NoiseValue denotes the noise value, and Randomizer denotes the randomizer, andwherein ConstantValue is a constant value that is an element of a module that is derivative of the second non-cyclotomic ring, and wherein Randomizer3 is sampled from a distribution over a ring with a bounded expected norm.Claim 24. A system of fully homomorphic encryption, the system comprising a processing circuitry (PC) configured to:encrypt an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. Claim 25. A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processor to perform a method of fully homomorphic encryption, the method comprising:encrypting an element of a first non-cyclotomic ring to an element of a second non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. Claim 26. A processing circuitry (PC)-based method of decrypting fully homomorphically encrypted data, the method comprising: decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal. Claim 27. The method of claim 26, wherein the irreducible non-cyclotomic polynomial is one of:f(x) = xn + x – b, or f(x) = xn - x + b;  and wherein the first ideal is: x-b wherein b is an integer. Claim 28. The method of claim 27, the method further comprising, subsequent to the decrypting:decoding the element of the first non-cyclotomic ring to a plaintext of a given plaintext space. Claim 29. The method of claim 28 where the decoding is based on calculating: felement(b)wherein felement() is a polynomial function corresponding to the element of the first non-cyclotomic ring. Claim 30. The method of claim 28 wherein the first non-cyclotomic ring is a quotient ring based on a final ring of a series of successive rings extending a fourth non-cyclotomic ring, and wherein the decoding comprises:  a) determining one or more roots of a minimal polynomial associated with the first non-cyclotomic ring; b) for each determined root:calculating a result of substituting, in the element of the first non-cyclotomic ring, a respective extending algebraic element with the respective root,thereby generating one or more elements of a quotient ring derivative of a preceding ring of the series; c) responsive to the preceding ring being an extension ring of the fourth non-cyclotomic ring: for each generated element: repeating a) - b); and d) responsive to the preceding ring being the fourth non-cyclotomic ring:calculating, for each generated element felement(); felement(b)thereby giving rise to one or more plaintexts.Claim 31 The method of claim 26, wherein the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring:a value based on a product of a decryption key and a randomizing element,the decryption key and the randomizing element being elements of the second non-cyclotomic ring,thereby resulting in an element of the first non-cyclotomic ring. Claim 32. The method of claim 31, wherein the decrypting is based on: DecryptedElement = EncryptedElementc0 - (DecryptionKey * EncryptedElementc1) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementc1 denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key. Claim 33. The method of claim 31, wherein the decryption key is a symmetric key. Claim 34. The method of claim 31, wherein the decryption key is a private key. Claim 35. The method of claim 31, wherein the randomizing element is derivative of at least one randomizer. Claim 36. The method of claim 35, wherein the randomizing element is further derivative of at least one constant value. Claim 37. The method of claim 26, wherein the decrypting the element of a first non-cyclotomic ring comprises subtracting, from the element of the second non-cyclotomic ring:a value based on a product of a decryption key and a randomizing element,the decryption key and the randomizing element being elements of a module derivative of the second non-cyclotomic ring, Claim 38. The method of claim 37, wherein the decrypting is based on: DecryptedElement = EncryptedElementc0 - (DecryptionKey * EncryptedElementc1) mod (ThirdNonCyclotomicRing / SecondIdeal)wherein ThirdNonCyclotomicRing denotes the third non-cyclotomic ring, SecondIdeal denotes the second ideal, EncryptedElementc0 denotes the element of the second non-cyclotomic ring, EncryptedElementc1 denotes the randomizing element, DecryptedElement denotes the element of the first non-cyclotomic ring, and DecryptionKey denotes the decryption key.  Claim 39. The method of claim 37, wherein the decryption key is a symmetric key. Claim 40. The method of claim 37, wherein the decryption key is a private key. Claim 41. The method of claim 37, wherein the randomizing element is derivative of at least one randomizer. Claim 42. The method of claim 41, wherein the randomizing element is further derivative of at least one constant value. Claim 43. A system of decrypting fully homomorphically encrypted data, the system comprising a processing circuitry (PC) configured to: decrypt an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.Claim 44.  A computer program product comprising a computer readable non-transitory storage medium containing program instructions, which program instructions when read by a processor, cause the processor to perform a method of decrypting fully homomorphically encrypted data, the method comprising: decrypting an element of a second non-cyclotomic ring to an element of a first non-cyclotomic ring;wherein the first non-cyclotomic ring is a quotient of:a. a third non-cyclotomic ring that is derivative of an irreducible non-cyclotomic polynomial, and  b. a first non-trivial ideal of the third non-cyclotomic ring, and wherein the second non-cyclotomic ring is a quotient of:a. the third non-cyclotomic ring, and b. a second ideal of the third non-cyclotomic ring, wherein the second ideal is not the first ideal.