Generation method and device of fully homomorphic calculation program

Through the partitioning and governance strategy and the minimum cutting algorithm, the generation of the full isomorphic computing program is solved, and the problems of long compilation time and low efficiency are achieved, and efficient full isomorphic computing program generation is achieved.

CN120335815APending Publication Date: 2025-07-18ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510387764.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, the fully homomorphic encryption compilation time is long and the generated fully homomorphic computing program has low execution efficiency and lacks efficient compilation solutions.

Method used

Using the partitioning and governance strategy and the minimum cutting algorithm, the value flow graph is constructed into multiple partitions, and the insertion position of the re-reduced operation and bootstrap operation is determined to optimize the generation process of the fully homomorphic calculation program.

Benefits of technology

It shortens the compilation time and improves the execution efficiency of fully homomorphic computing programs. The generated programs can be executed efficiently within a controlled time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120335815A_ABST
    Figure CN120335815A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a fully homomorphic calculation program generation method and device. The method comprises the following steps: constructing a value flow graph according to each homomorphic operation contained in a first fully homomorphic calculation program; the nodes correspond to homomorphic operation, and the directed edges correspond to transmission of data between the nodes; dividing the value flow graph into a plurality of partitions based on the multiplication depth corresponding to each node; traversing each partition according to the topological sequence to execute the following first operation: for a plurality of partition intervals which take the current partition as a source partition and take a plurality of partitions after the current partition as target partitions respectively, taking an added value of execution time of each homomorphic operation after insertion of the target operation as an edge weight, determining a candidate position for inserting the target operation by adopting a minimum cut algorithm; according to the candidate position, determining a target insertion position for stopping the target operation of each target partition; the target operation comprises a re-reduction operation and a bootstrap operation; and generating a second fully homomorphic calculation program according to the target insertion position obtained by traversal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of computers, and in particular, to a method and apparatus for generating fully homomorphic computing programs. Background Art

[0002] Fully homomorphic encryption (FHE) is a privacy computing technology. After encrypting plaintext data, homomorphic addition and homomorphic multiplication operations are performed and then decrypted, and the result is the same as the result of directly performing addition and multiplication operations on the plaintext. Since the calculation process is carried out in an encrypted state, the leakage of private data contained in the plaintext is avoided.

[0003] Fully homomorphic encryption ensures encryption security by adding noise to the original plaintext data. Homomorphic multiplication will significantly increase the noise level. After performing multiplication to a certain depth, the noise may overwhelm the plaintext message, resulting in decryption failure. By introducing a Rescale operation, the rate of noise increase is reduced, and the supported multiplication depth is increased. By introducing a Bootstrapping operation, a ciphertext containing a higher noise level is refreshed into a ciphertext containing a lower noise level, so that arbitrary-depth multiplication operations can be performed.

[0004] In some scenarios, the plaintext computing program is often determined first, and then the plaintext computing program is converted into a fully homomorphic computing program. This conversion process can be called compilation. During compilation, a Rescale operation needs to be inserted into the fully homomorphic computing program to reduce the rate of increase of the scale factor of the ciphertext, and a Bootstrapping operation needs to be inserted to support more multiplication operations. At the same time, the insertion positions of the Rescale operation and the Bootstrapping operation need to be optimized to optimize the execution efficiency of the encrypted calculation. In the prior art, there is a lack of a solution with a short compilation time and a high execution efficiency of the generated fully homomorphic computing program. Summary of the Invention

[0005] One or more embodiments of this specification describe a method and apparatus for generating a fully homomorphic computing program, which can shorten the compilation time and improve the execution efficiency of the fully homomorphic computing program.

[0006] In a first aspect, a method for generating a fully homomorphic computing program is provided. The method includes:

[0007] Converting a plaintext computing program into a first fully homomorphic computing program;

[0008] Constructing a value flow graph according to each homomorphic operation included in the first fully homomorphic computing program; the nodes in the value flow graph correspond to homomorphic operations, and the directed edges in the value flow graph correspond to the transfer of data between nodes;

[0009] Divide the value flow graph into multiple partitions based on the multiplication depth corresponding to each node in the value flow graph;

[0010] Traverse each partition in topological order and perform the following first operation: For several partition intervals with the current partition as the source partition and several subsequent partitions as the destination partitions respectively, use the minimum cut algorithm to determine the candidate positions for inserting the target operation with the increased execution time of each homomorphic operation after inserting the target operation as the edge weight; According to the candidate positions, determine the target insertion positions of the target operation up to each destination partition; The target operations include re - reduction operations and bootstrap operations;

[0011] Generate a second fully homomorphic computing program according to the obtained target insertion positions.

[0012] In a possible implementation manner, constructing a value flow graph according to each homomorphic operation included in the first fully homomorphic computing program includes:

[0013] For the loop of homomorphic multiplication operations included in the first fully homomorphic computing program, if the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop increases, expand the loop; if the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop remains unchanged, retain the loop;

[0014] Construct corresponding nodes for the homomorphic operations inside the loop and the homomorphic operations outside the loop respectively, and mark the execution times of the nodes; Among them, for the nodes inside the loop, the execution times are recorded as the number of loop iterations; for the nodes outside the loop, the execution times are 1.

[0015] In a possible implementation manner, dividing the value flow graph into multiple partitions based on the multiplication depth corresponding to each node in the value flow graph includes:

[0016] Traverse each node in the forward topological order of each node in the value flow graph, and calculate the initial multiplication depth of each node;

[0017] Traverse each node in the reverse topological order of each node in the value flow graph, and update the multiplication depth of each node to the maximum allowed value to obtain the optimized multiplication depth;

[0018] Divide the nodes with the same optimized multiplication depth into the same partition of the value flow graph.

[0019] Further, the traversing each node in the reverse topological order of each node in the value flow graph and updating the multiplication depth of each node to the maximum allowed value to obtain the optimized multiplication depth includes:

[0020] Traverse each node in reverse topological order according to the nodes in the value stream graph, and calculate the maximum multiplication depth allowed for the successor nodes of the current node in topological order;

[0021] If the current node is a multiplication node and its multiplication depth is less than the maximum multiplication depth allowed for its successor nodes, update the multiplication depth of the current node, and update the multiplication depths of all other nodes that depend on the current node within the current multiplication depth.

[0022] In a possible implementation manner, the determining the candidate positions for inserting the target operation by using the minimum cut algorithm includes:

[0023] Determine the first candidate position for inserting the bootstrap operation within the source partition based on the minimum cut algorithm;

[0024] For any partition interval, determine the first partition set that needs to insert the re-reduction operation among the partitions from the source partition to the destination partition, and determine the second candidate positions for inserting the re-reduction operation within each partition of the first partition set based on the minimum cut algorithm.

[0025] In a possible implementation manner, the determining the target insertion positions of the target operation up to each destination partition according to the candidate positions includes:

[0026] For any first partition interval with a first destination partition, based on its corresponding first candidate position and the previous insertion position determined with the previous partition as the source partition, determine the first target position up to the first destination partition according to the execution time of the involved homomorphic operation, and classify it into the target insertion positions.

[0027] Further, the previous insertion positions include the first insertion position from the first partition to the previous partition of the current partition, and the second insertion position from the first partition to the first destination partition;

[0028] Determining the first target position up to the first destination partition according to the execution time of the involved homomorphic operation includes:

[0029] According to the first candidate position, determine the section execution time for executing the homomorphic operation within the first partition interval;

[0030] Obtain the first execution time corresponding to the first insertion position and the second execution time corresponding to the second insertion position;

[0031] If the sum of the section execution time and the first execution time is less than the second execution time, determine the first insertion position and the first candidate position as the first target position; otherwise, determine the second insertion position as the first target position.

[0032] Further, the execution time of the section is the sum of the execution times of all homomorphic operations within the first partition interval; the execution time of any homomorphic operation is found from the execution times of each level of the homomorphic operation obtained from pre-tests according to its level.

[0033] In a possible implementation manner, the number of the several partitions corresponds to the maximum level of the bootstrapping operation.

[0034] Further, the determining the first candidate position for inserting a bootstrapping operation within the source partition based on the minimum cut algorithm includes:

[0035] Using the execution time of the bootstrapping operation after insertion and the increased value of the execution time of each homomorphic operation as the weights of each edge within the source partition;

[0036] Selecting the cut that minimizes the edge weights in the source partition and taking it as the first candidate position for inserting the bootstrapping operation within the source partition.

[0037] Further, the determining the first partition set that needs to insert a re-reduction operation among each partition from the source partition to the destination partition includes:

[0038] Forward traversing each partition from the source partition to the destination partition, and successively selecting the partition that reduces the magnification factor of the destination partition the most after inserting the re-reduction operation.

[0039] Further, the determining the second candidate position for inserting a re-reduction operation within each partition of the first partition set based on the minimum cut algorithm includes:

[0040] Using the execution time of the re-reduction operation after insertion and the increased value of the execution time of each homomorphic operation as the weights of each edge within a single partition;

[0041] Selecting the cut that minimizes the edge weights in a single partition and taking it as the second candidate position for inserting the re-reduction operation within a single partition.

[0042] Further, the minimum cut algorithm is calculated based on the weights of each edge and the set source node and sink node.

[0043] In a second aspect, a generating device for a fully homomorphic computing program is provided. The device includes:

[0044] A conversion unit, configured to convert a plaintext computing program into a first fully homomorphic computing program;

[0045] A construction unit, configured to construct a value flow graph according to each homomorphic operation included in the first fully homomorphic computing program obtained by the conversion unit; the nodes in the value flow graph correspond to homomorphic operations, and the directed edges in the value flow graph correspond to the transfer of data between nodes;

[0046] A partitioning unit, configured to partition the value flow graph into multiple partitions based on the multiplication depths respectively corresponding to the nodes in the value flow graph obtained from the construction unit;

[0047] A planning unit, configured to perform the following first operation by traversing the partitions obtained by the partitioning unit in topological order: for several partition intervals with the current partition as the source partition and several partitions after the current partition as the destination partitions respectively, using the increased value of the execution time of each homomorphic operation after inserting the target operation as the edge weight, determining the candidate positions for inserting the target operation by using the minimum cut algorithm; and determining the target insertion positions of the target operation up to each destination partition according to the candidate positions; the target operation includes a re-reduction operation and a bootstrap operation;

[0048] A generating unit, configured to generate a second fully homomorphic computing program according to the target insertion positions obtained by traversing by the planning unit.

[0049] In a third aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method of the first aspect.

[0050] In a fourth aspect, a computing device is provided, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method of the first aspect is implemented.

[0051] Through the method and device provided by the embodiments of this specification, first, the plaintext calculation program is converted into a first fully homomorphic calculation program; then, according to each homomorphic operation included in the first fully homomorphic calculation program, a value flow graph is constructed; the nodes in the value flow graph correspond to homomorphic operations, and the directed edges in the value flow graph correspond to the transfer of data between nodes; then, based on the multiplication depth corresponding to each node in the value flow graph, the value flow graph is divided into multiple partitions; then, traverse each partition in topological order to perform the following first operation: for several partition intervals with the current partition as the source partition and several subsequent partitions as the destination partitions respectively, using the increased value of the execution time of each homomorphic operation after inserting the target operation as the edge weight, the minimum cut algorithm is used to determine the candidate positions for inserting the target operation; according to the candidate positions, determine the target insertion positions of the target operation up to each destination partition; the target operations include re-reduction operations and bootstrapping operations; finally, according to the obtained target insertion positions through traversal, a second fully homomorphic calculation program is generated. As can be seen from the above, the embodiments of this specification adopt a divide-and-conquer strategy, analyze the insertion positions of re-reduction operations and bootstrapping operations based on partitioning and the minimum cut algorithm. Each time the minimum cut algorithm only needs to be applied to a single partition, which can ensure that the compilation time is controllable, and the insertion positions of re-reduction operations and bootstrapping operations within a single partition are relatively optimal. Combining the source partition and the destination partition to divide the partition intervals, and determining the target insertion positions of the target operation up to each destination partition according to the candidate positions in a single partition, thus ensuring that the overall execution efficiency is relatively optimal, being able to shorten the compilation time and improve the execution efficiency of the fully homomorphic calculation program. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0053] Figure 1 Schematic diagram of an implementation scenario of an embodiment disclosed in this specification;

[0054] Figure 2 Schematic diagram of an implementation scenario of another embodiment disclosed in this specification;

[0055] Figure 3 Flowchart showing a method for generating a fully homomorphic calculation program according to an embodiment;

[0056] Figure 4 Schematic diagram showing dividing a value flow graph into multiple partitions according to an embodiment;

[0057] Figure 5Schematic diagram of the planning process for the re - reduction operation and the bootstrap operation according to an embodiment;

[0058] Figure 6 Schematic diagram of the application of the minimum - cut algorithm according to an embodiment;

[0059] Figure 7 Schematic block diagram of a generating device for a fully - homomorphic computing program according to an embodiment. Detailed implementation manners

[0060] The solutions provided in this specification will be described below with reference to the accompanying drawings.

[0061] Figure 1 Schematic diagram of an implementation scenario of an embodiment disclosed in this specification. This implementation scenario is related to the generation of a fully - homomorphic computing program. It can be understood that the above process is specifically to convert a plain - text computing program into a fully - homomorphic computing program. Among them, the plain - text computing program can include various types of computations. For example, it can include linear operations composed of addition or multiplication, and can also include non - linear operations such as convolution operations and activation functions. In the embodiments of this specification, the operations included in the plain - text computing program itself and the overall implementation functions are not limited. Refer to Figure 1 , taking the plain - text computing program as a machine - learning model as an example, for a plain - text input, a plain - text result can be obtained through the machine - learning model. For example, the above - mentioned machine - learning model is a classification model for predicting the risk category of a user. The plain - text input is the feature data of the user, and the plain - text result is the risk category of the user. Since the feature data of the user usually belongs to private data, to prevent the leakage of private data, it can be encrypted to obtain a cipher - text input, the plain - text computing program of the machine - learning model is compiled into a fully - homomorphic computing program, the cipher - text input is used with the fully - homomorphic computing program to obtain a cipher - text result, and the cipher - text result is decrypted to obtain the plain - text result. In this way, the purpose of obtaining the plain - text result can be achieved, and the leakage of private data can be prevented.

[0062] The above - mentioned machine - learning model can be obtained through two stages: pre - training and fine - tuning. First, a pre - trained model is obtained through pre - training, and then the pre - trained model is fine - tuned to obtain the above - mentioned machine - learning model, which contains a large number of operations and can be used for inference and prediction for a target object.

[0063] Among them, pre - trained model: A pre - trained model is a machine - learning model that has been trained on a large - scale dataset and can be fine - tuned for a specific task. The pre - trained model contains the model structure, tensors, weights, and biases at the same time.

[0064] Inference: The process of using a trained and deployed machine learning model to make predictions on new real-world data.

[0065] Some basic concepts related to fully homomorphic encryption are described below.

[0066] CKKS Scheme: CKKS is a fully homomorphic encryption scheme, namely an approximate computing fully homomorphic encryption scheme for complex field fixed-point addition and multiplication operations proposed by four authors, Cheon, Kim, Kim, and Song, at ASIACRYPT ’17. The CKKS scheme does not pursue strict consistency between the decryption result and the plaintext calculation, but only retains a part of the significant digits. Compared with other homomorphic encryption schemes, the details of the CKKS scheme are greatly simplified and the computing efficiency is greatly improved, which is suitable for application scenarios such as machine learning inference.

[0067] Scaling Factor (scale): When encoding in the CKKS scheme, to ensure accuracy, the initial variable m to be encrypted is multiplied by the scaling factor Δ, such as mΔ. When performing the multiplication of two ciphertexts c1 and c2, the product corresponds to the plaintext m1m2Δ 2 , and the ciphertext scaling factor is Δ 2 , and the ciphertext scaling factor grows exponentially with the multiplication depth. If the ciphertext scaling factor exceeds the limit value, the encrypted data is damaged and cannot be decrypted.

[0068] Rescaling: To reduce the growth rate of the ciphertext scaling factor, after multiplication, the ciphertext can be divided by Δ, so that the corresponding plaintext changes from m1m2Δ 2 to m1m2Δ.

[0069] Ciphertext Modulus (Q L ): The CKKS format is implemented based on Ring Learning with Errors (RLWE). The ciphertext is represented as a polynomial with integer coefficients, and the polynomial coefficients take values within a finite range, and this range is the ciphertext modulus. The ciphertext modulus can only take values within a finite range, otherwise the security of the ciphertext is damaged. Each time the rescaling operation is performed, the ciphertext modulus is reduced by Δ, thus forming a sequence of gradually decreasing moduli: Q L , Q L-1 , …, Q0.

[0070] Level: Since the ciphertext modulus decreases after each rescaling, but the ciphertext modulus must be greater than Δ, otherwise the ciphertext cannot be decrypted. Therefore, although rescaling can reduce the growth rate of the ciphertext amplification factor, each ciphertext can only participate in a limited number of homomorphic multiplication operations. The level can be used to represent how many more homomorphic multiplications the ciphertext can participate in. After each rescaling, the ciphertext amplification factor decreases by Δ and the level decreases by 1. There is a basic characteristic in ciphertext calculation that the lower the ciphertext level, the higher the efficiency of homomorphic calculation.

[0071] Bootstrapping: The number of multiplications that a ciphertext can perform is limited. If it exceeds the limit, the encrypted data is corrupted and cannot be decrypted. In the ciphertext state, the multiplication depth that a machine learning model needs to perform is generally greater than the multiplication depth that the ciphertext can support. Fully homomorphic encryption (including the CKKS format) uses the bootstrapping technique to achieve infinite-depth multiplication operations. The bootstrapping operation can restore the ciphertext modulus and level, increasing them to the specified values so that the ciphertext can continue to participate in multiplication calculations. Since the ciphertext level increases after bootstrapping, the efficiency of related homomorphic calculations decreases.

[0072] Modswitch: In the CKKS scheme, addition and multiplication operations require the input ciphertexts to have the same level. If the levels are different, the level of the input ciphertext is reduced through the modswitch operation to balance the levels of the input ciphertexts. Addition also requires the input ciphertext amplification factors to be the same. If they are different, the ciphertext amplification factor can be reduced through the rescaling operation to balance the input ciphertexts. In the CKKS format, the execution time of the modswitch can be ignored and it can be inserted as needed without considering its own execution time.

[0073] Relinearization: In the CKKS scheme, homomorphic multiplication calculations support ciphertext-plaintext multiplication (MulCP) and also ciphertext-ciphertext multiplication (MulCC). The CKKS scheme is based on RLWE. The plaintext is represented by a polynomial, and the freshly encrypted ciphertext is represented by two polynomials. Multiplying a ciphertext containing m polynomials by a ciphertext or plaintext containing n polynomials results in a ciphertext containing (m + n - 1) polynomials. The increase in the number of polynomials will reduce the efficiency of subsequent homomorphic calculations. The relinearization operation is used to reduce the number of ciphertext polynomials back to 2.

[0074] Fully Homomorphic Encryption Compiler (FHEcompiler): A compiler that converts plaintext computations into fully homomorphic encryption computations. During the generation of encrypted computations, the compiler needs to insert rescaling operations to reduce the rate of increase of the ciphertext amplification factor and insert bootstrapping operations to support more multiplication operations. At the same time, the compiler needs to optimize the insertion positions of the rescaling operations and the bootstrapping operations to optimize the execution efficiency of the encrypted computations.

[0075] In the embodiments of this specification, Enc, Dec, Add, Mul, Rot, Relin, Rsc, Ms, and Bts are used to represent encryption (encrypt), decryption (decrypt), addition, multiplication, rotation, relinearization, rescaling, modswitch, and bootstrapping operations respectively. Homomorphic encryption computations can be represented by the following two sets of equations:

[0076] Dec(Add(Enc(x), Enc(y))) == Add(x, y);

[0077] Dec(Mul(Enc(x), Enc(y))) == Mul(x, y).

[0078] Rsc, Ms, and Bts only change the amplification factor and level of the ciphertext and do not change the plaintext information:

[0079] Dec(Rsc(Enc(x))) == x;

[0080] Dec(Ms(Enc(x))) == x;

[0081] Dec(Bts(Enc(x))) == x.

[0082] Homomorphic encryption ensures encryption security by adding noise to the original plaintext data. Homomorphic multiplication will significantly increase the noise level. After performing a certain depth of multiplication, the noise may overwhelm the plaintext message, resulting in decryption failure. In the CKKS format, rescaling operations are introduced to reduce the rate of noise increase and increase the multiplication depth that can be supported. Fully homomorphic encryption (including the CKKS format) can perform multiplication operations of arbitrary depth by introducing bootstrapping operations to refresh a ciphertext with a high level of noise into a ciphertext with a low level of noise.

[0083] The fully homomorphic encryption technology enables the analysis and processing of data on the premise of ensuring that the data provider does not disclose the original data, ensuring that the data is "usable but invisible" during the process of circulation and fusion, and can be widely applied in various industries and scenarios that require privacy protection.

[0084] The general fully homomorphic encryption schemes are divided into two categories. One is the scheme for high-throughput batch computing on integer or floating-point vectors, which supports vector addition, multiplication, and rotation operations of vector elements, such as the BGV, BFV, and CKKS schemes; the other is the computing scheme on Boolean circuits, which supports comparison operations and efficient bootstrapping operations, but usually does not support batch processing, such as the GSW, FHEW, and TFHE schemes. The common fully homomorphic encryption schemes are introduced as follows:

[0085] CKKS scheme: A scheme that supports complex numbers (real numbers), batch processing, and bootstrapping. The basic operations include homomorphic addition, multiplication, rotation, and ciphertext bootstrapping.

[0086] BGV / BFV scheme: A scheme that supports integers and batch processing. The basic operations include homomorphic addition, multiplication, and rotation, and the bootstrapping operation is very expensive.

[0087] TFHE scheme: A scheme that supports Boolean circuits and fast bootstrapping. The basic operation is the Boolean circuit gate, and complex functions are realized by building a lookup table (LUT) through the gate circuit.

[0088] CKKS / TFHE hybrid scheme: Realize the mutual conversion of CKKS ciphertext and TFHE ciphertext through special bootstrapping operations.

[0089] Let ct.s represent the amplification factor (scale) of the ciphertext ct, ct.l represent the level (level) of the ciphertext, and l bts represent the ciphertext level after bootstrapping. The CKKS scheme supports batch processing, and the operation primitives of CKKS have different requirements and impacts on ct.s and ct.l. The semantics of each CKKS primitive are as follows:

[0090] Encryption: ct = Enc(a0, a1, …, a n-1 ).

[0091] Decryption: (c0, c1, …, c n-1 ) = Dec(ct) ≈ (a0, a1, …, a n-1 ).

[0092] Addition: ct1 = Enc(a0, a1, …, a n-1 );

[0093] ct2 = Enc(b0, b1, ..., b n-1 );

[0094] ct3 = Add(ct1, ct2);

[0095] (c0, c1, ..., c n-1) = Dec(ct3)

[0096] ≈(a0 + b0, a1 + b1, ..., a n-1 + b n-1 ).

[0097] Multiplication: ct1 = Enc(a0, a1, ..., a n-1 );

[0098] ct2 = Enc(b0, b1, ..., b n-1 );

[0099] ct3 = Mul(ct1, ct2);

[0100] (c0, c1, ..., c n-1 ) = Dec(ct3)

[0101] ≈(a0 * b0, a1 * b1, ..., a n-1 * b n-1 ).

[0102] Re-linearization: ct1 = Enc(a0, a1, ..., a n-1 );

[0103] ct2 = Enc(b0, b1, ..., b n-1 );

[0104] ct3 = Relin(Mul(ct1, ct2));

[0105] (c0, c1, ..., c n-1 ) = Dec(ct3)

[0106] ≈(a0 * b0, a1 * b1, ...a n-1 * b n-1 ).

[0107] Rotation: ct1 = Enc(a0, a1, ..., a n-1 );

[0108] ct2 = Rot(ct1, k);

[0109] (c0, c1, ..., c n-1 ) = Dec(ct2)

[0110] ≈(a k , a k+1 , ..., a n-1 , a0, a1, ..., a k-1 );

[0111] For each term: ci ≈a (i+k)%n where \(0\leq i\leq(n - 1)\).

[0112] Reduction again: \(ct1 = Enc(a0, a1,..., a n-1 );

[0113]

[0114] (c0, c1,..., c n-1 ) = Dec(ct2) \(\approx\) (a0, a1,..., a n-1 ).

[0115] Bootstrapping: \(ct1 = Enc(a0, a1,..., a n-1 );

[0116] ct2 = Bts(ct1) with ct2·s = \(\Delta\) and ct2.l = lb ts ;

[0117] (c0, c1,..., c n-1 ) = Dec(ct2) \(\approx\) (a0, a1,..., a n-1 ).

[0118] Modulus switching: \(ct1 = Enc(a0, a1,..., a n-1 );

[0119] ct2 = Ms(ct1) with ct2.s = ct1.s and ct2.l = ct1.l - 1;

[0120] (c0, c1,..., c n-1 ) = Dec(ct2) \(\approx\) (a0, a1,..., a n-1 ).

[0121] The constraints of ct.s and ct.l of the input ciphertext and the output ciphertext for each CKKS primitive are shown in Table 1 below: Table 1: Constraints of ct.s and ct.l of the input ciphertext and the output ciphertext for each CKKS primitive

[0122]

[0123] Referring to Table 1, the ciphertext calculation program directly generated from the plaintext calculation only contains Add, Mul, Rot, and Relin. At this time, the constraint conditions of Mul or Add on the input ciphertext are generally not satisfied. To meet the constraint conditions of each homomorphic operation on the input ciphertext and generate a correct, efficient, and executable homomorphic encryption program, the fully homomorphic encryption compiler needs to correctly insert operations such as rescaling, modulus switching, and bootstrapping into the fully homomorphic calculation program and optimize the insertion positions of related operations to improve the efficiency of fully homomorphic calculation. There are two basic laws for the calculation efficiency of homomorphic operations: one law is that the calculation efficiency of each operation increases as the level of the input ciphertext decreases; the other law is that there are significant differences in the calculation efficiency of different homomorphic operations, and the variation law of their time consumption is as follows:

[0124] Ms << Add < Mul < Rsc << Rot ≈ Relin << Bts.

[0125] Among them, the bootstrapping operation is the homomorphic calculation with the longest time consumption. Reducing the number of bootstrapping operations can effectively improve the efficiency of the homomorphic calculation program. However, usually, finding the optimal insertion position of the bootstrapping operation is a non-deterministic polynomial (NP) problem with too high time complexity and cannot be used in the compiler. Currently, the algorithm for finding the optimal management scheme of the amplification factor also cannot be used when compiling large machine learning models due to too high time complexity. For the CKKS fully homomorphic encryption scheme, the embodiments of this specification propose an efficient method for selecting and optimizing the insertion positions of the bootstrapping operation and the rescaling operation. Compared with the usual management methods of the bootstrapping operation and the amplification factor, both the execution time of the compiler and the execution efficiency of the generated code are significantly improved.

[0126] Figure 2 FIG. is a schematic diagram of an implementation scenario of another embodiment disclosed in this specification. This implementation scenario shows the generation process of the fully homomorphic calculation program, the goal of which is to generate an executable fully homomorphic calculation program with a short compilation time and high execution efficiency of the fully homomorphic calculation program. Referring to Figure 2 , the above generation process includes: Step 21, converting the plaintext calculation program into an initial fully homomorphic calculation program composed of homomorphic addition (Add), homomorphic multiplication (Mul), relinearization (Relin), and rotation (Rot); Step 22, constructing a data flow graph (DFG) based on the initial fully homomorphic calculation program; Step 23, dividing the data flow graph into multiple regions based on the multiplication depth of each node in the data flow graph; Step 24, determining a planning scheme for the insertion positions of the rescaling operation and the bootstrapping operation based on each region; Step 25, inserting the rescaling operation and the bootstrapping operation into the initial fully homomorphic calculation program according to the planning scheme to generate an executable fully homomorphic calculation program.

[0127] The embodiments of this specification can be management algorithms for ciphertext amplification factors and bootstrapping operations in fully homomorphic encryption schemes, and can simultaneously complete the analysis and optimization of the insertion positions of re-reduction operations and bootstrapping operations.

[0128] Among them, DFG: is a graph used to represent the flow process of data in a system and is widely used in compilers. Like other graphs, DFG contains two key elements, nodes and edges. The nodes of DFG are data operations, such as arithmetic operations, logical operations, or other data operations. Edges represent the transfer of data between nodes. Edges usually have directions. The starting point of an edge in DFG is the node that operates on the input data, and the end point of the edge is the corresponding data operation.

[0129] In the aforementioned step 24, a divide-and-conquer strategy can be adopted. First, use the minimum cut algorithm to determine the insertion positions of re-reduction operations or bootstrapping operations in a single partition, and then comprehensively determine the insertion positions of re-reduction operations and bootstrapping operations in the entire program.

[0130] Among them, the minimum cut algorithm: is an algorithm in graph theory used to find a cut that minimizes the sum of the edge weights in a graph. In an undirected graph, a cut is to divide the vertex set of the graph into two non-overlapping subsets, and the set of edges from one subset to the other subset is called a cut set. The goal of the minimum cut algorithm is to find a cut such that the sum of the weights of the edges in the cut set is minimized. In the embodiments of this specification, the increased execution time value within a single partition caused by inserting a re-reduction operation or a bootstrapping operation is used as the weight of the DFG edge. Therefore, the minimum cut is the insertion position of the re-reduction operation or the bootstrapping operation that optimizes the execution efficiency of fully homomorphic computation within the current partition.

[0131] Figure 3 Show a flowchart of a method for generating a fully homomorphic computation program according to an embodiment. This method can be based on Figure 1 and Figure 2 The shown implementation scenarios. As Figure 3As shown in the figure, the method for generating a fully homomorphic computing program in this embodiment includes the following steps: Step 31, converting a plaintext computing program into a first fully homomorphic computing program; Step 32, constructing a value flow graph according to each homomorphic operation included in the first fully homomorphic computing program; the nodes in the value flow graph correspond to homomorphic operations, and the directed edges in the value flow graph correspond to the transfer of data between nodes; Step 33, dividing the value flow graph into multiple partitions based on the multiplication depth corresponding to each node in the value flow graph; Step 34, traversing each partition in topological order to perform the following first operation: for several partition intervals with the current partition as the source partition and several subsequent partitions as the destination partitions respectively, using the increased value of the execution time of each homomorphic operation after inserting the target operation as the edge weight, and determining the candidate positions for inserting the target operation by using the minimum cut algorithm; according to the candidate positions, determining the target insertion positions of the target operation up to each destination partition; the target operation includes a re-reduction operation and a bootstrapping operation; Step 35, generating a second fully homomorphic computing program according to the obtained target insertion positions. The specific implementation methods of the above steps are described below.

[0132] First, in Step 31, the plaintext computing program is converted into a first fully homomorphic computing program. It can be understood that the first fully homomorphic computing program consists of a series of homomorphic operations, which implement the same arithmetic functions as the plaintext computing program. Among them, the first fully homomorphic computing program does not insert re-reduction operations and bootstrapping operations, and may not meet the constraint conditions of homomorphic addition and homomorphic multiplication on the input ciphertext, so it cannot be correctly executed.

[0133] For example, the plaintext computing program includes convolution operations and activation function arithmetic operations. Among them, the convolution operation can be converted into several Add, Mul, and Rot items, and the activation function arithmetic operation can be converted into several Add, Mul, and Relin items. It may occur that the amplification factor of the ciphertext exceeds the limit value and cannot be decrypted, or the amplification factors of two ciphertexts do not match and do not meet the constraint conditions of Add on the input data.

[0134] Then, in Step 32, a value flow graph is constructed according to each homomorphic operation included in the first fully homomorphic computing program; the nodes in the value flow graph correspond to homomorphic operations, and the directed edges in the value flow graph correspond to the transfer of data between nodes. It can be understood that when constructing the direct current graph, in order to reduce the scale of the graph, loops in the program can be retained under certain conditions, that is, the same operation executed multiple times in the loop can correspond to the same node in the value flow graph.

[0135] In one example, the constructing a value flow graph according to each homomorphic operation included in the first fully homomorphic computing program includes:

[0136] For the loop of the homomorphic multiplication operation included in the first fully homomorphic computing program, if the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop increases, expand the loop; if the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop remains unchanged, retain the loop.

[0137] Construct corresponding nodes for the homomorphic operations inside the loop and the homomorphic operations outside the loop respectively, and mark the execution times of the nodes; among them, for the nodes inside the loop, the execution times are recorded as the number of loop iterations; for the nodes outside the loop, the execution times are 1.

[0138] In this example, deciding whether to retain the loop according to whether the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop increases can effectively reduce the scale of the value flow graph and does not affect subsequent processing.

[0139] Then in step 33, divide the value flow graph into multiple partitions based on the multiplication depths respectively corresponding to each node in the value flow graph. It can be understood that the multiplication depth is the number of homomorphic multiplication operations passed by the node, and the amplification factor of the ciphertext grows exponentially with the multiplication depth.

[0140] In one example, the dividing the value flow graph into multiple partitions based on the multiplication depths respectively corresponding to each node in the value flow graph includes:

[0141] Traverse each node forward in the topological order of each node in the value flow graph to calculate the initial multiplication depth of each node;

[0142] Traverse each node backward in the reverse topological order of each node in the value flow graph, and update the multiplication depth of each node to the maximum allowed value to obtain the optimized multiplication depth;

[0143] Divide the nodes with the same optimized multiplication depth into the same partition of the value flow graph.

[0144] In this example, classifying the homomorphic operations that need to occur at the same multiplication depth into the same partition and allowing each homomorphic operation to occur at the required level results in better execution efficiency.

[0145] Further, the traversing each node backward in the reverse topological order of each node in the value flow graph and updating the multiplication depth of each node to the maximum allowed value to obtain the optimized multiplication depth includes:

[0146] Traverse each node backward in the reverse topological order of each node in the value flow graph to calculate the maximum allowed multiplication depth of the successor nodes of the current node in the topological order;

[0147] If the current node is a multiplication node and its multiplication depth is less than the maximum multiplication depth allowed for its successor nodes, update the multiplication depth of the current node and update the multiplication depths of all other nodes that depend on the current node within the current multiplication depth.

[0148] In this example, if there is a directed edge between node A and node B with the direction from node A to node B, then node B is a successor node of node A, and node A is a predecessor node of node B. This way of updating the multiplication depth facilitates classifying a node into a partition with a larger multiplication depth as much as possible.

[0149] Figure 4 A schematic diagram showing the partitioning of a value flow graph into multiple partitions according to an embodiment is shown. Refer to Figure 4 , the first fully homomorphic computing program is used to calculate a3x 3 +a1x, which can be decomposed into the following homomorphic operations: calculating the homomorphic multiplication of a1x, calculating the homomorphic multiplication of a3x, calculating the homomorphic multiplication of x 2 , calculating the homomorphic multiplication of a3x 3 , calculating the homomorphic multiplication of a3x 3 +a1x's homomorphic addition, and two relinearization operations. Correspondingly, the value flow graph includes an input node representing x and nodes corresponding to each homomorphic operation respectively. First, calculate the multiplication depth. In Figure 4 (a), starting from the input node, traverse the DFG forward in topological order, calculate the multiplication depth of each node, and record the nodes included in each multiplication depth. For example, the multiplication depth of the input node x is 0, denoted as Depth1; calculating the homomorphic multiplication MulCP of a1x, calculating the homomorphic multiplication MulCP of a3x, calculating the homomorphic multiplication MulCC of x 2 , the multiplication depths of the nodes corresponding to these operations are 1, denoted as Depth2; calculating the homomorphic multiplication MulCC of a3x 3 , the second relinearization operation Relin, calculating the homomorphic addition AddCC of a3x 3 +a1x, the multiplication depths of the nodes corresponding to these operations are 2, denoted as Depth3.

[0150] Then optimize the multiplication depth. Traverse the DFG in reverse starting from the return value of the program, and traverse the DFG nodes in descending order of multiplication depth, updating the multiplication depth of each node to the maximum allowed value. Specifically, it can be executed in two steps: First, traverse the nodes with the same multiplication depth in reverse topological order, and calculate the maximum allowed multiplication depth of the successor nodes of each node; Second, if the multiplication depth of a multiplication node is less than the maximum allowed multiplication depth of its successor nodes, then update the multiplication depth of the multiplication node, and update the multiplication depth of all other nodes that depend on this multiplication node within the current multiplication depth. For example, for the homomorphic multiplication MulCP that calculates a1x, the multiplication depth of this multiplication node is 1, and its successor nodes are the homomorphic addition AddCC that calculates a3x 3 +a1x, and the maximum allowed multiplication depth of this addition node is 2. Therefore, update the multiplication depth of this multiplication node to 2.

[0151] Finally, construct the DFG partition. In Figure 4 (b), split the DFG into different subgraphs according to the optimized multiplication depth, and hereafter refer to each subgraph as a partition (region). Denote the maximum multiplication depth of the homomorphic calculation program as max_depth, then this step will construct max_depth + 1 partitions, and the multiplication depth difference between adjacent two partitions is 1. For example, if max_depth is 2, the DFG is divided into 3 partitions. In topological order, they are the first partition, the second partition, and the third partition. The first partition is denoted as Region1, which contains the input node x; the second partition is denoted as Region2, which contains the homomorphic multiplication MulCP that calculates a3x, the homomorphic multiplication MulCC that calculates x 2 , and the first relinearization operation Relin; the third partition is denoted as Region3, which contains the homomorphic multiplication MulCP that calculates a1x, the homomorphic multiplication MulCC that calculates a3x 3 , the second relinearization operation Relin, and the homomorphic addition AddCC that calculates a3x 3 +a1x.

[0152] In the embodiments of this specification, the partitioning process of the partition can be represented by code. Among them, the input of the code is G, which represents the DFG, and the output of the code is R, which is the partition of G. The specific code is as follows:

[0153]

[0154] Among them, in the above code, lines 4 to 11 are used to calculate the multiplication depth, and lines 13 to 28 are used to optimize the multiplication depth. The following explains each variable involved in the code.

[0155] md represents the multiplication depth; input.md represents the multiplication depth of the input node; md2nodes represents the mapping from the multiplication depth to nodes. For example, let md2nodes = {0: [input, x, y], 1: [m, n]}, which means the nodes with multiplication depth 0 are input, x, and y; the nodes with multiplication depth 1 are m and n.

[0156] md2nodes[md] represents all the nodes corresponding to the multiplication depth md, and md2nodes[node.md].add(node) means adding node to the nodes corresponding to node.md. For example, assuming node.md = 1 and md2nodes = {0: [input, x, y], 1: [m, n]}, after executing md2nodes[node.md].add(node), md2nodes = {0: [input, x, y], 1: [m, n, node]}.

[0157] nodeList ← md2nodes[md], where nodeList represents all the nodes corresponding to md. For example, assuming md = 0, then nodeList = [input, x, y].

[0158] node.succMd represents the multiplication depths of all the successor nodes of node.

[0159] node.successors represents all the successor nodes of node.

[0160] UINT_MAX represents the maximum value of a 32 - bit unsigned integer.

[0161] R refers to all partitions, R[node.md] refers to the partition corresponding to the multiplication depth node.md, and R[node.md].add(node) means adding node to this partition.

[0162] Then in step 34, traverse each partition in topological order and perform the following first operation: for several partition intervals with the current partition as the source partition and several partitions after the current partition as the destination partitions respectively, using the increased value of the execution time of each homomorphism operation after inserting the target operation as the edge weight, determine the candidate positions for inserting the target operation by using the minimum - cut algorithm; according to the candidate positions, determine the target insertion positions of the target operation up to each destination partition; the target operations include the re - reduction operation and the bootstrap operation. It can be understood that this step determines both the insertion positions of the re - reduction operation and the bootstrap operation.

[0163] In the embodiment of this specification, in step 33 described above, a partition sequence consisting of max_depth + 1 partitions is constructed, and the multiplication depth of the partitions increases by 1 in sequence from 0 to max_depth. In step 34, taking the partitions as the analysis objects, the divide-and-conquer strategy is adopted to analyze the insertion positions of the reduction operation and the bootstrap operation. Traverse all partitions forward, first analyze the position of the bootstrap operation. Starting from the first partition, sequentially take it as the source partition src, and then sequentially take the partitions after the source partition as the destination partition dst. This traversal strategy can ensure that when analyzing from the source partition src to the destination partition dst, all solutions of the reduction operation and the bootstrap operation from the input node input to the source partition src have been analyzed. Assume that it is necessary to insert a bootstrap operation in the source partition src, and determine a better insertion position of the bootstrap operation within the source partition src based on the minimum cut algorithm. Then analyze the position of the reduction operation, analyze the partitions within the source partition src to the destination partition dst where the reduction operation needs to be inserted, and determine a better insertion position of the reduction operation within the partitions based on the minimum cut algorithm. Finally, perform performance analysis, determine a better solution from the input node input to the destination partition dst based on the insertion positions of the reduction operation and the bootstrap operation, and update the solutions of the reduction operation and the bootstrap operation corresponding to the destination partition dst accordingly. When analyzing the partitions with the multiplication depth of max_depth, all program nodes are analyzed, and a better solution of the reduction operation and the bootstrap operation for the entire program is obtained.

[0164] In one example, the determining the candidate positions for inserting the target operation by using the minimum cut algorithm includes:

[0165] Determining a first candidate position for inserting a bootstrap operation within the source partition based on the minimum cut algorithm;

[0166] For any partition interval, determining a first partition set that needs to insert a reduction operation from each partition between the source partition and the destination partition, and determining a second candidate position for inserting a reduction operation within each partition of the first partition set based on the minimum cut algorithm.

[0167] In this example, the divide-and-conquer strategy is adopted to analyze the insertion positions of the reduction operation and the bootstrap operation based on the partitions, so as to make the homomorphic computing program efficient and executable. Among them, each time the minimum cut algorithm only needs to be applied to a single partition, which can ensure that the compilation time is controllable, and the candidate positions of the reduction operation and the bootstrap operation within a single partition are optimal.

[0168] In one example, the determining the target insertion positions of the target operation up to each destination partition according to the candidate positions includes:

[0169] For any first partition interval having a first target partition, based on its corresponding first candidate position and the previous insertion position determined with the previous partition as the source partition, determine the first target position up to the first target partition according to the execution time of the involved homomorphic operation, and classify it into the target insertion position.

[0170] In this example, by comparing the execution times of the homomorphic computing program at different insertion positions, an insertion position with a shorter execution time can be selected, so that the generated fully homomorphic computing program is more efficient.

[0171] Further, the previous insertion position includes the first insertion position from the first partition to the previous partition of the current partition, and the second insertion position from the first partition to the first target partition;

[0172] Determining the first target position up to the first target partition according to the execution time of the involved homomorphic operation includes:

[0173] According to the first candidate position, determine the section execution time for executing the homomorphic operation within the first partition interval;

[0174] Obtain the first execution time corresponding to the first insertion position and the second execution time corresponding to the second insertion position;

[0175] If the sum of the section execution time and the first execution time is less than the second execution time, determine the first insertion position and the first candidate position as the first target position; otherwise, determine the second insertion position as the first target position.

[0176] In this example, based on the candidate positions of the re - reduction operation and the bootstrapping operation, calculate the section execution time corresponding to the source partition src to the target partition dst. Since all the re - reduction operation and bootstrapping operation schemes from the input node input to the source partition src have been analyzed, the minimum execution time minL AT[src] from the input node input to the source partition src is also known. For the scheme from the input node input to the target partition dst with a bootstrapping operation inserted at the source partition src, its new minimum execution time is If the new minimum execution time newLAT is smaller than the known minimum execution time minLAT[dst], then this scheme is considered to be a better scheme from the input node input to the target partition dst, and the re - reduction operation and bootstrapping operation schemes corresponding to the target partition dst are updated accordingly. When analyzing the partition with the maximum multiplication depth max_depth, all program nodes are analyzed, thus obtaining the better re - reduction operation and bootstrapping operation schemes for the entire program.

[0177] Further, the execution time of the section is the sum of the execution times of all the homomorphic operations within the first partition interval; the execution time of any homomorphic operation is found from the execution times of each level of this homomorphic operation obtained from pre-tests according to its level.

[0178] In this example, the execution time of the program is approximated by the sum of the execution times of each homomorphic operation, and the execution time of each homomorphic operation is the execution time of each operation at different levels obtained from pre-tests, so that the execution time of the homomorphic calculation program can be estimated.

[0179] Among them, the above homomorphic operations include the re-reduction operation and the bootstrapping operation to be inserted.

[0180] In one example, the number of the several partitions corresponds to the maximum level of the bootstrapping operation.

[0181] In this example, for the current partition as the source partition, it is not necessary to use any partition after the current partition as the destination partition, but only need to use the above maximum-level number of partitions after the current partition as the destination partition respectively.

[0182] Further, the determining the first candidate position for inserting the bootstrapping operation within the source partition based on the minimum cut algorithm includes:

[0183] Using the execution time of the bootstrapping operation after insertion and the increased value of the execution time of each homomorphic operation as the weights of each edge within the source partition;

[0184] Selecting the cut that minimizes the edge weight in the source partition and taking it as the first candidate position for inserting the bootstrapping operation within the source partition.

[0185] In this example, through the minimum cut algorithm, the insertion position of the bootstrapping operation that makes the execution efficiency of the fully homomorphic calculation better within the source partition can be selected.

[0186] Further, the determining the first partition set that needs to insert the re-reduction operation among the partitions from the source partition to the destination partition includes:

[0187] Traversing forward through the partitions from the source partition to the destination partition, and successively selecting the partitions that reduce the magnification factor of the destination partition the most after inserting the re-reduction operation.

[0188] In this example, it is used to select all the partitions that need to insert the re-reduction operation from the source partition to the destination partition.

[0189] Further, the determining the second candidate position for inserting the re-reduction operation within each partition of the first partition set based on the minimum cut algorithm includes:

[0190] Use the execution time of the re - reduction operation after the insertion - then - reduction operation and the increased values of the execution times of each homomorphic operation as the weights of each edge within a single partition.

[0191] Select the cut that minimizes the edge weights in a single partition and use it as the second candidate position for the insertion - then - reduction operation within the single partition.

[0192] In this example, through the minimum - cut algorithm, the insertion position of the re - reduction operation that can optimize the execution efficiency of the fully homomorphic calculation within a single partition can be selected.

[0193] Furthermore, the minimum - cut algorithm is calculated based on the weights of each edge and the set source node and sink node.

[0194] Finally, in step 35, according to the obtained target insertion position from the traversal, a second fully homomorphic calculation program is generated. It can be understood that at the target insertion position of the first fully homomorphic calculation program, the re - reduction operation and the bootstrapping operation are inserted to generate the second fully homomorphic calculation program.

[0195] In the embodiments of this specification, the second fully homomorphic calculation program is not only executable but also has high execution efficiency.

[0196] In the embodiments of this specification, the process of determining the target insertion position in step 34 can be represented by code. Among them, the input of the code is R, which is the partition of the DFG, and the output of the code is Plan, which is the scheme of the re - reduction operation and the bootstrapping operation, including the target insertion position of the re - reduction operation and the target insertion position of the bootstrapping operation. The specific code is as follows:

[0197]

[0198] Among them, in the above code, line 4 is used to sequentially take the first partition as the source partition starting from the first partition, line 5 is used to sequentially take the partitions after the source partition as the destination partitions, line 6 is used to analyze the partitions within the source partition to the destination partition where the re - reduction operation needs to be inserted, line 12 is used to determine the optimal insertion position of the re - reduction operation within the partition based on the minimum - cut algorithm, lines 10 to 15 are used to calculate the execution times of all homomorphic calculations within the source partition to the destination partition, line 16 is used to calculate the minimum execution time under the current scheme, and lines 17 to 19 are used to determine the optimal scheme from the input node to the destination partition. ScaleMGR, SMOPLC, and BtsPLC are the called sub - codes. The following explains each variable involved in the code.

[0199] R.first refers to the first partition, that is, the first partition in the DFG in topological order.

[0200] R.last refers to the last partition, that is, the last partition in the DFG in topological order.

[0201] minLAT represents the mapping from a partition to the minimum execution time (latency).

[0202] minLAT[r] represents the minimum execution time from the input node to partition r.

[0203] minLAT[R.first] represents the minimum execution time from the input node to the first partition.

[0204] DOUBLE_MAX represents the maximum value of a double-precision floating-point number.

[0205] l bts represents the level of the ciphertext after bootstrapping.

[0206] l max represents the maximum allowed level of the ciphertext after bootstrapping.

[0207] RescalingPlan represents the scheme for inserting rescaling operations.

[0208] BTSPlan represents the scheme for inserting bootstrapping operations.

[0209] Plan represents the mapping from a partition to the minimum execution time scheme.

[0210] Plan[dst]: The scheme with the minimum execution time from the input node to the destination partition.

[0211] In addition, in the above code, "||" represents finding the number of elements in a set; "\" represents except for...; "|RescalingRegions\{src}|" represents the partitions that need to insert rescaling operations except for src.

[0212] "RescalingRegions\{dst}" represents all the partitions that need to insert rescaling operations except for dst.

[0213] represents the execution time (latency) of all operations within [src, dst) if bootstrapping operations are inserted at src and dst, and rescaling operations are inserted into RescalingRegions. The 15th line of the above code is successively accumulating the execution time of each partition, where r represents the partition being accumulated.

[0214] ScaleMGR is used to select all the partitions that need to be inserted and then reduced from the source partition to the destination partition. It traverses all the partitions from src to dst forward, and sequentially selects the partition that can reduce the magnification factor of the destination partition the most after the insert-and-reduce operation. Among them, the input of the code is [src, dst], where src represents the source partition and dst represents the destination partition. The bootstrap operation needs to be inserted into both of these partitions. The output of the code is RescalingRegions, which is a set of partitions. The specific code is as follows:

[0215]

[0216] The following explains each variable involved in the code.

[0217] RescalingRegions represents all the partitions that need to be inserted and then reduced.

[0218] INT_MAX represents the maximum value of a 32-bit integer.

[0219] q represents the magnification factor used during encryption.

[0220] SMORegion represents the partition to which the insert-and-reduce operation needs to be inserted. In line 11, SMORegion is added to RescalingRegions; CanRegion is a temporary variable during the execution of the loop, representing the partition that may need to be inserted with the insert-and-reduce operation and is currently being analyzed.

[0221] SMOPLC is used to select an optimal insertion position for the reduce operation within a single partition based on the minimum cut algorithm. The minimum cut algorithm is used to select the cut with the smallest weight in the weight graph. The execution time of the insert-and-reduce operation and the increased value of the execution time of each homomorphic operation after the insert-and-reduce operation are used as the weights of each edge within the partition. The cut selected by the minimum cut algorithm is the insertion position of the reduce operation that minimizes the execution time. Among them, the input of the code is G r =(N r , E r ), where G r represents the directed graph of partition r, N r represents the nodes, and E r represents the edges. The output of the code is minCut, which is the minimum cut in G r . The specific code is as follows:

[0222]

[0223] The following explains each variable involved in the code.

[0224] src / snk represents the source node and sink node of the partition respectively.

[0225] topoSort represents the sequence of nodes after topological sorting of all nodes in the partition. For example, in one partition, topoSort = [MulCP, MulCC, Relin], and in another partition, topoSort = [MulCP, MulCC, Relin, AddCC].

[0226] Indicates the execution time of the re - reduction operation on node n.

[0227] n.freq represents the execution times of node n.

[0228] Indicates the total execution time of executing node n with the ciphertext at level l as the input.

[0229] Indicates the execution time of the re - reduction operation with the ciphertext at level l as the input.

[0230] pred(n) represents all the predecessor nodes of node n.

[0231] succ(n) represents all the successor nodes of node n.

[0232] Indicates the increased execution time of all the predecessor nodes of node n in the partition for the re - reduction operation on node n.

[0233] w (n,m) represents the weight of the edge connecting nodes n and m.

[0234] BtsPLC is used to select a better insertion position of the bootstrapping operation within a single partition based on the minimum - cut algorithm. The execution time of inserting the bootstrapping operation and the increased execution time of each homomorphic operation after inserting the bootstrapping operation are used as the weights of each edge in the partition. The cut selected by the minimum - cut algorithm is the insertion position of the bootstrapping operation that minimizes the execution time. Among them, the input of the code is G r =(N r , E r ) and l bts , G r represents the directed graph of partition r, N r represents the nodes, E r represents the edges, l bts represents the level of the ciphertext after bootstrapping. The output of the code is minCut, which is the minimum cut in G r . The specific code is as follows:

[0235]

[0236] Among which G r only contains nodes with level 0, excluding the inserted re-reduction operations and their outgoing edges. The following explains each variable involved in the code. The code of BtsPLC and the code of SMOPLC both adopt the minimum cut algorithm, and their variables can refer to the variable description of SMOPLC above. In addition, represents the execution time of the bootstrap operation on node n.

[0237] Figure 5 shows a schematic diagram of the planning process of the re-reduction operation and the bootstrap operation according to an embodiment. Refer to Figure 5 , in this embodiment, taking 6 partitions as an example to show the planning process. These 6 partitions are denoted as Region1, Region2, Region3, Region4, Region5, and Region6 in sequence. Among them, x represents the input node, z represents the output node, Conv1 represents a convolution operation, ReLU represents an operation of an activation function, Conv2 represents another convolution operation, L0 represents level 0, L1 represents level 1, L2 represents level 2, L3 represents level 3. The final planning scheme is that bootstrap operations BTS are inserted in Region2 and Region5 respectively, and re-reduction operations RS are inserted in Region2, Region3, Region4, and Region5 respectively. Assume that the bootstrap operation can only restore the ciphertext level to 3, that is, the aforementioned l bts is at most 3. The planning process is a classic dynamic programming. If the optimal scheme from Region1 to Region4 is determined, the scheme from Region4 to Region6 has no impact on the scheme from Region1 to Region4, that is, the previous scheme does not need to be changed.

[0238] The complete traversal process is as follows:

[0239] In the first round of traversal, taking Region1 as the source partition, and Region2, Region3, and Region4 as the destination partitions respectively, determine the corresponding planning schemes for each destination partition.

[0240] First, determine Plan1. src = Region1, dst = Region2. Insert the re-reduction operation RS in Region2; src is the first partition, and the level of the ciphertext carried by itself has not been consumed, so there is no need to insert the bootstrap operation BTS. When traversing to Region2 for the first time, record it as the optimal scheme from the current Region1 to Region2, denoted as Plan[Region2].

[0241] Then determine Plan2. src = Region1, dst = Region3. Insert a re-reduction operation in Region2 and Region3; the level of the ciphertext is insufficient, and a bootstrap operation needs to be inserted at src to restore the ciphertext level to 2. When Region3 is traversed for the first time, it is recorded as the optimal solution for the current Region1->Region3, denoted as Plan[Region3].

[0242] Finally, determine Plan3. src = Region1, dst = Region4. Insert a re-reduction operation in Region2, Region3, and Region4; insert a bootstrap operation at src to restore the ciphertext level to 3. When Region4 is traversed for the first time, it is recorded as the optimal solution for the current Region1->Region4, denoted as Plan[Region4].

[0243] In the second round of traversal, using Region2 as the source partition and Region3, Region4, and Region5 as the destination partitions respectively, determine the planning solutions corresponding to each destination partition.

[0244] First, determine Plan4. src = Region2, dst = Region3. Insert a re-reduction operation in Region3; insert a bootstrap operation in Region2 to restore the ciphertext level to 1. When Region3 is traversed for the second time, compare Plan4 + Plan[Region2] with Plan[Region3]. If the execution time of the current solution is shorter, then update Plan[Region3].

[0245] Then determine Plan5. src = Region2, dst = Region4. Insert a re-reduction operation in Region3 and Region4; insert a bootstrap operation in Region2 to restore the ciphertext level to 2. When Region4 is traversed for the second time, compare Plan5 + Plan[Region2] with Plan[Region4]. If the execution time of the current solution is shorter, then update Plan[Region4].

[0246] Finally, determine Plan6. src = Region2, dst = Region5. Insert a re-reduction operation in Region3, Region4, and Region5; insert a bootstrap operation in Region2 to restore the ciphertext level to 3. When Region5 is traversed for the first time, it is recorded as the optimal solution for the current Region1->Region5, denoted as Plan[Region5].

[0247] In the third round of traversal, Region3 is used as the source partition, and Region4, Region5, and Region6 are used as the destination partitions respectively, and the corresponding planning schemes for each destination partition are determined respectively.

[0248] First, determine Plan7. src = Region3, dst = Region4. Insert a re-shrinking operation in Region4; insert a bootstrap operation in Region3 to restore the ciphertext level to 1. When traversing to Region4 for the third time, compare Plan7 + Plan[Region3] with Plan[Region4]. If the current scheme execution time is shorter, then update Plan[Region4].

[0249] Then, determine Plan8. src = Region3, dst = Region5. Insert re-shrinking operations in Region4 and Region5; insert a bootstrap operation in Region3 to restore the ciphertext level to 2. When traversing to Region5 for the second time, compare Plan8 + Plan[Region3] with Plan[Region5]. If the current scheme execution time is shorter, then update Plan[Region5].

[0250] Finally, determine Plan9. src = Region3, dst = Region6. Insert re-shrinking operations in Region4, Region5, and Region6; insert a bootstrap operation in Region3 to restore the ciphertext level to 3. When traversing to Region6 for the first time, record it as the current better scheme from Region1 to Region6, denoted as Plan[Region6].

[0251] In the fourth round of traversal, Region4 is used as the source partition, and Region5 and Region6 are used as the destination partitions respectively, and the corresponding planning schemes for each destination partition are determined respectively.

[0252] First, determine Plan10. src = Region4, dst = Region5. Insert a re-shrinking operation in Region5; insert a bootstrap operation in Region4 to restore the ciphertext level to 1. When traversing to Region5 for the third time, compare Plan10 + Plan[Region4] with Plan[Region5]. If the current scheme execution time is shorter, then update Plan[Region5].

[0253] Then determine Plan11. src = Region4, dst = Region6. Insert a re-reduction operation in Region5 and Region6; insert a bootstrap operation in Region4 to restore the ciphertext level to 2. When traversing Region6 for the second time, compare Plan11 + Plan[Region4] with Plan[Region6]. If the current plan has a shorter execution time, then update Plan[Region6].

[0254] In the fifth round of traversal, use Region5 as the source partition and Region6 as the destination partition to determine the planning scheme corresponding to the destination partition.

[0255] Determine Plan12. src = Region5, dst = Region6. Insert a re-reduction operation in Region6; insert a bootstrap operation in Region5 to restore the ciphertext level to 1. When traversing Region6 for the third time, compare Plan12 + Plan[Region5] with Plan[Region6]. If the current plan has a shorter execution time, then update Plan[Region6], which is the final planning scheme.

[0256] Figure 6 Show a schematic diagram of the application of the minimum cut algorithm according to an embodiment. Refer to Figure 6 , in the embodiments of the present specification, the minimum cut algorithm can be used to determine the insertion position of the bootstrap operation in the source partition and can also be used to determine the insertion position of the re-reduction operation in a single partition. First, based on the code corresponding to the aforementioned SMOPLC, calculate the weights of 9 edges E1, E2,..., E9, and use the minimum cut algorithm to solve the optimal insertion position of the re-reduction operation. In the minimum cut algorithm, the src nodes are: {MulCP_1; MulCP_2; MulCP_3; MulCP_4}; the snk node is: {MulCC}. Assume that the input ciphertext level l = 1, marked as L1. Perform a topological sort on the nodes within the partition to obtain the sequence {MulCP_1; MulCP_2; AddCC_1; Rot_1; MulCP_3; MulCP_4; AddCC_2; Rot_2; AddCC_3}.

[0257] Traverse all nodes in topological order in turn, calculate the weights of all edges, and the weights of each edge are as follows:

[0258]

[0259]

[0260] Among them, Represents the execution time of performing a re - reduction operation once at level 1; Represents the execution time of executing node AddCC_1 at level 1, Represents the execution time of executing node AddCC_1 at level 0; Similarly, Represents the execution time of executing node AddCC_2 at level 1, Represents the execution time of executing node AddCC_2 at level 0; Represents the execution time of executing node Rot_1 at level 1, Represents the execution time of executing node Rot_1 at level 0; Represents the execution time of executing node Rot_2 at level 1, Represents the execution time of executing node Rot_2 at level 0.

[0261] After calculating the weights of the 9 edges E1, E2, …, E9, calling the existing minimum - cut algorithm can obtain the optimal insertion position of the re - reduction operation.

[0262] Then, assume that a re - reduction operation is inserted after multiplications MulCP_1, MulCP_2, MulCP_3, MulCP_4, and denote the ciphertext level of the output of the bootstrapping operation as l bts . Based on the foregoing code corresponding to BTSPLC, calculate the weights of the 9 edges E1, E2, …, E9, and use the minimum - cut algorithm to solve the optimal insertion position of the bootstrapping operation. In the minimum - cut algorithm, the src nodes are: {MulCP_1; MulCP_2; MulCP_3; MulCP_4}; the snk node is: {MulCC}. Perform a reverse topological sort on the nodes within the partition to obtain the sequence: {MulCC; AddCC_3; Rot_1; AddCC_1; MulCP_1; MulCP_2; Rot_2; AddCC_2; MulCP_3; MulCP_4;}.

[0263] Traverse all nodes in reverse topological order in sequence, calculate the weights of all edges, and the weights of each edge are as follows:

[0264]

[0265]

[0266] Among them, Represents the execution time of the bootstrapping operation when the output ciphertext level is l bts ; Represents the execution time of executing node AddCC_3 at ciphertext level l bts ; Represents the execution time of the execution node AddCC_3 at the ciphertext level 0. Similarly, represents the execution time at the ciphertext level l bts for the execution node AddCC_2, represents the execution time of the execution node AddCC_2 at the ciphertext level 0; represents the execution time at the ciphertext level l bts for the execution node Rot_1, represents the execution time of the execution node Rot_1 at the ciphertext level 0; represents the execution time at the ciphertext level l bts for the execution node Rot_2, represents the execution time of the execution node Rot_2 at the ciphertext level 0.

[0267] After calculating the weights of the 9 edges E1, E2, …, E9, calling the existing minimum cut algorithm can obtain a better insertion position for the bootstrapping operation.

[0268] In the embodiments of this specification, on the one hand, an insertion scheme for the re-reduction operation and the bootstrapping operation can be quickly constructed. Based on the test results of multiple machine learning models, the compilation time for each model does not exceed 1 second. The fully homomorphic computing program generated based on this scheme has higher execution efficiency compared to the fully homomorphic computing program generated by the usual scheme.

[0269] Through the method provided by the embodiments of this specification, first convert the plaintext calculation program into a first fully homomorphic calculation program; then, based on each homomorphic operation included in the first fully homomorphic calculation program, construct a value flow graph; the nodes in the value flow graph correspond to homomorphic operations, and the directed edges in the value flow graph correspond to the transfer of data between nodes; then, based on the multiplication depth corresponding to each node in the value flow graph, divide the value flow graph into multiple partitions; then traverse each partition in topological order to perform the following first operation: for several partition intervals with the current partition as the source partition and several subsequent partitions as the destination partitions respectively, use the increase in the execution time of each homomorphic operation after inserting the target operation as the edge weight, and use the minimum cut algorithm to determine the candidate positions for inserting the target operation; according to the candidate positions, determine the target insertion positions of the target operation up to each destination partition; the target operation includes a re-reduction operation and a bootstrapping operation; finally, generate a second fully homomorphic calculation program according to the obtained target insertion positions during the traversal. As can be seen from the above, the embodiments of this specification adopt a divide-and-conquer strategy, analyze the insertion positions of the re-reduction operation and the bootstrapping operation based on partitioning and the minimum cut algorithm. Each time the minimum cut algorithm only needs to be applied to a single partition, which can ensure that the compilation time is controllable, and the insertion positions of the re-reduction operation and the bootstrapping operation within a single partition are relatively optimal. Combining the source partition and the destination partition to divide the partition intervals, and determining the target insertion positions of the target operation up to each destination partition according to the candidate positions in a single partition, thus ensuring that the overall execution efficiency is relatively optimal, being able to shorten the compilation time and improve the execution efficiency of the fully homomorphic calculation program.

[0270] According to an embodiment of another aspect, there is also provided a device for generating a fully homomorphic calculation program, which is used to execute the method provided by the embodiments of this specification. Figure 7 The schematic block diagram of a device for generating a fully homomorphic calculation program according to an embodiment is shown. As Figure 7 shown, the device 700 includes:

[0271] A conversion unit 71, configured to convert a plaintext calculation program into a first fully homomorphic calculation program;

[0272] A construction unit 72, configured to construct a value flow graph according to each homomorphic operation included in the first fully homomorphic calculation program obtained by the conversion unit 71; the nodes in the value flow graph correspond to homomorphic operations, and the directed edges in the value flow graph correspond to the transfer of data between nodes;

[0273] A partitioning unit 73, configured to divide the value flow graph into multiple partitions based on the multiplication depth corresponding to each node in the value flow graph obtained by the construction unit 72;

[0274] The planning unit 74 is configured to perform the following first operation on each partition obtained by traversing the partitioning unit 73 in topological order: for several partition intervals with the current partition as the source partition and several subsequent partitions as the destination partitions respectively, using the increased value of the execution time of each homomorphic operation after inserting the target operation as the edge weight, determining candidate positions for inserting the target operation by using the minimum cut algorithm; and determining the target insertion positions of the target operation up to each destination partition according to the candidate positions; the target operation includes a re-reduction operation and a bootstrap operation.

[0275] The generation unit 75 is configured to generate a second fully homomorphic computing program according to the target insertion positions obtained by traversing by the planning unit 74.

[0276] Optionally, as an embodiment, the construction unit 72 includes:

[0277] The loop processing subunit is configured to, for a loop of homomorphic multiplication operations included in the first fully homomorphic computing program, if the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop increases, expand the loop; if the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop remains unchanged, retain the loop.

[0278] The construction subunit is configured to respectively construct corresponding nodes for the homomorphic operations inside the loop and the homomorphic operations outside the loop obtained by the loop processing subunit, and mark the execution times of the nodes; wherein, for the nodes inside the loop, the execution times are recorded as the loop times; for the nodes outside the loop, the execution times are 1.

[0279] Optionally, as an embodiment, the partitioning unit 73 includes:

[0280] The calculation subunit is configured to traverse each node in forward order according to the topological order of each node in the value flow graph, and calculate the initial multiplication depth of each node.

[0281] The update subunit is configured to traverse each node in reverse order according to the reverse topological order of each node in the value flow graph, and update the multiplication depth of each node obtained by the calculation subunit to the maximum allowed value to obtain the optimized multiplication depth.

[0282] The partitioning subunit is configured to partition the nodes with the same optimized multiplication depth obtained by the update subunit into the same partition of the value flow graph.

[0283] Further, the update subunit is specifically configured to:

[0284] Traverse each node in reverse order according to the reverse topological order of each node in the value flow graph, and calculate the maximum allowed multiplication depth of the successor nodes of the current node in the topological order.

[0285] If the current node is a multiplication node and its multiplication depth is less than the maximum multiplication depth allowed by its successor nodes, update the multiplication depth of the current node and update the multiplication depths of all other nodes within the current multiplication depth that depend on the current node.

[0286] Optionally, as an embodiment, the planning unit 74 includes:

[0287] A first planning subunit, configured to determine a first candidate position for inserting a bootstrap operation within the source partition based on the minimum cut algorithm;

[0288] A second planning subunit, configured to, for any partition interval, determine a first set of partitions that require inserting a re-reduction operation among the partitions from the source partition to the destination partition, and determine a second candidate position for inserting the re-reduction operation within each partition of the first set of partitions based on the minimum cut algorithm.

[0289] Optionally, as an embodiment, the planning unit 74 is specifically configured to, for any first partition interval having a first destination partition, based on its corresponding first candidate position and the previous insertion position determined with the previous partition as the source partition, determine a first target position up to the first destination partition according to the execution time of the involved homomorphic operation, and classify it into the target insertion position.

[0290] Furthermore, the previous insertion position includes a first insertion position from the first partition to the previous partition of the current partition, and a second insertion position from the first partition to the first destination partition;

[0291] The planning unit 74 is specifically configured to:

[0292] Determine the section execution time for executing the homomorphic operation within the first partition interval according to the first candidate position;

[0293] Obtain a first execution time corresponding to the first insertion position and a second execution time corresponding to the second insertion position;

[0294] If the sum of the section execution time and the first execution time is less than the second execution time, determine the first insertion position and the first candidate position as the first target position; otherwise, determine the second insertion position as the first target position.

[0295] Furthermore, the section execution time is the sum of the execution times of each homomorphic operation within the first partition interval; the execution time of any homomorphic operation is found from the execution times of each level of this homomorphic operation obtained from pre-tests according to its level.

[0296] Furthermore, the number of the several partitions corresponds to the maximum level of the bootstrap operation.

[0297] Furthermore, the first planning subunit is specifically configured to:

[0298] Use the execution time of the bootstrap operation after the insertion of the bootstrap operation and the increased values of the execution times of the respective homomorphic operations as the weights of the respective edges within the source partition;

[0299] Select the cut that minimizes the edge weights in the source partition and use it as the first candidate position for inserting the bootstrap operation within the source partition.

[0300] Furthermore, the second planning subunit is specifically configured to traverse forward through each partition between the source partition and the destination partition, and sequentially select the partition that maximally reduces the magnification factor of the destination partition after the insertion and reduction operation.

[0301] Furthermore, the second planning subunit is specifically configured to:

[0302] Use the execution time of the reduction operation after the insertion and reduction operation and the increased values of the execution times of the respective homomorphic operations as the weights of the respective edges within a single partition;

[0303] Select the cut that minimizes the edge weights in a single partition and use it as the second candidate position for inserting the reduction operation within the single partition.

[0304] Furthermore, the minimum cut algorithm is calculated based on the weights of the respective edges, as well as the set source node and sink node.

[0305] Through the device provided by the embodiments of this specification, first, the plaintext calculation program is converted into a first fully homomorphic calculation program by the conversion unit 71; then, the construction unit 72 constructs a value flow graph according to each homomorphic operation included in the first fully homomorphic calculation program; the nodes in the value flow graph correspond to homomorphic operations, and the directed edges in the value flow graph correspond to the transfer of data between nodes; next, the partitioning unit 73 divides the value flow graph into multiple partitions based on the multiplication depth corresponding to each node in the value flow graph; then, the planning unit 74 traverses each partition in topological order to perform the following first operation: for several partition intervals with the current partition as the source partition and several partitions after the current partition as the destination partitions respectively, using the increased value of the execution time of each homomorphic operation after inserting the target operation as the edge weight, the minimum cut algorithm is used to determine the candidate positions for inserting the target operation; according to the candidate positions, the target insertion positions of the target operation up to each destination partition are determined; the target operation includes a re-reduction operation and a bootstrapping operation; finally, the generation unit 75 generates a second fully homomorphic calculation program according to the obtained target insertion positions. As can be seen from the above, the embodiments of this specification adopt a divide-and-conquer strategy, analyze the insertion positions of the re-reduction operation and the bootstrapping operation based on partitioning and the minimum cut algorithm. Each time the minimum cut algorithm only needs to be applied to a single partition, which can ensure that the compilation time is controllable, and the insertion positions of the re-reduction operation and the bootstrapping operation within a single partition are relatively optimal. Combining the partitioning of the source partition and the destination partition, according to the candidate positions in a single partition, the target insertion positions of the target operation up to each destination partition are determined, so as to ensure that the overall execution efficiency is relatively optimal, the compilation time can be shortened, and the execution efficiency of the fully homomorphic calculation program can be improved.

[0306] According to an embodiment of another aspect, there is also provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method described in combination with Figure 3 what is described.

[0307] According to an embodiment of still another aspect, there is also provided a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method described in combination with Figure 3 what is described is implemented.

[0308] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0309] The specific embodiments described above further elaborate on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solution of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for generating a fully homomorphic computing program, the method comprising: Converting a plaintext computing program into a first fully homomorphic computing program; Constructing a value flow graph according to each homomorphic operation included in the first fully homomorphic computing program; Nodes in the value flow graph correspond to homomorphic operations, and directed edges in the value flow graph correspond to the transfer of data between nodes; Based on the multiplication depth corresponding to each node in the value flow graph, dividing the value flow graph into multiple partitions; Traverse each partition in topological order and perform the following first operation: for several partition intervals with the current partition as the source partition and several subsequent partitions as the destination partitions respectively, using the increased value of the execution time of each homomorphic operation after inserting the target operation as the edge weight, determine the candidate positions for inserting the target operation by using the minimum cut algorithm; according to the candidate positions, determine the target insertion positions of the target operation up to each destination partition; the target operations include re - reduction operations and bootstrapping operations; Generate a second fully homomorphic computing program according to the obtained target insertion positions through traversal.

2. The method according to claim 1, wherein The constructing a value flow graph according to each homomorphic operation included in the first fully homomorphic computing program includes: For a loop of homomorphic multiplication operations included in the first fully homomorphic computing program, if the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop increases, expand the loop; if the amplification factor of the ciphertext output by the homomorphic multiplication operation in the loop remains unchanged, retain the loop; Construct corresponding nodes for homomorphic operations inside the loop and homomorphic operations outside the loop respectively, and mark the execution times of the nodes; among them, for nodes inside the loop, the execution times are recorded as the loop times; for nodes outside the loop, the execution times are 1.

3. The method according to claim 1, wherein The dividing the value flow graph into multiple partitions based on the multiplication depth corresponding to each node in the value flow graph includes: Traverse each node in forward topological order in the value flow graph and calculate the initial multiplication depth of each node; Traverse each node in reverse topological order in the value flow graph and update the multiplication depth of each node to the maximum allowed value to obtain the optimized multiplication depth; Divide nodes with the same optimized multiplication depth into the same partition of the value flow graph.

4. The method according to claim 3, wherein, The traversing each node in reverse topological order in the value flow graph and updating the multiplication depth of each node to the maximum allowed value to obtain the optimized multiplication depth includes: Traverse each node in reverse topological order in the value flow graph and calculate the maximum allowed multiplication depth of the successor nodes of the current node in topological order; If the current node is a multiplication node and its multiplication depth is less than the maximum allowed multiplication depth of its successor nodes, update the multiplication depth of the current node, and update the multiplication depths of all other nodes that depend on the current node within the current multiplication depth.

5. The method according to claim 1, wherein, The determining the candidate positions for inserting the target operation by using the minimum cut algorithm includes: Determine the first candidate position for inserting a bootstrapping operation in the source partition based on the minimum cut algorithm; For any partition interval, determine a first set of partitions that require the insertion and reduction operation among the partitions from the source partition to the destination partition, and determine second candidate positions for inserting the insertion and reduction operation within each partition of the first set of partitions based on the minimum cut algorithm.

6. The method according to claim 1, wherein Determining the target insertion positions of the target operation up to each destination partition according to the candidate positions includes: For any first partition interval having a first destination partition, based on its corresponding first candidate position and the previous insertion position determined with the previous partition as the source partition, determine the first target position up to the first destination partition according to the execution time of the involved homomorphism operation, and classify it into the target insertion positions.

7. The method according to claim 6, wherein The previous insertion positions include the first insertion position from the first partition to the previous partition of the current partition, and the second insertion position from the first partition to the first destination partition; Determining the first target position up to the first destination partition according to the execution time of the involved homomorphism operation includes: According to the first candidate position, determine the section execution time of the homomorphism operation within the first partition interval; Obtain the first execution time corresponding to the first insertion position and the second execution time corresponding to the second insertion position; If the sum of the section execution time and the first execution time is less than the second execution time, determine the first insertion position and the first candidate position as the first target position; otherwise, determine the second insertion position as the first target position.

8. The method according to claim 7, wherein The section execution time is the sum of the execution times of each homomorphism operation within the first partition interval; the execution time of any homomorphism operation is found from the execution times of each level of this homomorphism operation obtained from pre-tests according to its level.

9. The method according to claim 1, wherein The number of the several partitions corresponds to the maximum level of the bootstrap operation.

10. The method according to claim 5, wherein Determining the first candidate position for inserting the bootstrap operation within the source partition based on the minimum cut algorithm includes: Use the execution time of the bootstrap operation after insertion and the increased value of the execution time of each homomorphism operation as the weights of each edge within the source partition; Select the cut that minimizes the edge weight in the source partition and use it as the first candidate position for inserting the bootstrap operation within the source partition.

11. The method according to claim 5, wherein, Determining the first set of partitions that require the insertion and reduction operation among the partitions from the source partition to the destination partition includes: Traverse forward through the partitions from the source partition to the destination partition, and sequentially select the partitions that reduce the magnification factor of the destination partition the most after inserting the insertion and reduction operation.

12. The method according to claim 5, wherein, Determining the second candidate positions for inserting the insertion and reduction operation within each partition of the first set of partitions based on the minimum cut algorithm includes: Use the execution time of the reduction operation after insertion and the increased value of the execution time of each homomorphism operation as the weights of each edge within a single partition; Select the cut that minimizes the edge weight in a single partition and use it as the second candidate position for inserting the insertion and reduction operation within a single partition.

13. The method according to claim 10, wherein, The minimum cut algorithm is calculated based on the weights of each edge and the set source node and sink node.

14. A generating device for a fully homomorphic computing program, the device includes: A conversion unit for converting a plaintext computing program into a first fully homomorphic computing program; A building unit is configured to build a value flow graph according to each homomorphic operation included in the first fully homomorphic computing program obtained by the conversion unit; Nodes in the value flow graph correspond to homomorphic operations, and directed edges in the value flow graph correspond to data transfer between nodes; A partitioning unit is configured to partition the value flow graph into multiple partitions based on the multiplication depth corresponding to each node in the value flow graph obtained by the building unit; A planning unit is configured to perform the following first operation by traversing each partition obtained by the partitioning unit in topological order: for several partition intervals with the current partition as the source partition and several subsequent partitions as the destination partitions respectively, using the increased value of the execution time of each homomorphic operation after inserting the target operation as the edge weight, determining candidate positions for inserting the target operation by using the minimum cut algorithm; and determining the target insertion positions of the target operation up to each destination partition according to the candidate positions; The target operations include a re-reduction operation and a bootstrap operation; A generating unit is configured to generate a second fully homomorphic computing program according to the target insertion positions obtained by the traversal of the planning unit.

15. A computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method according to any one of claims 1-13.

16. A computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method according to any one of claims 1-13 is implemented.