A homomorphic evaluation method and device of a symmetric cipher algorithm

CN121039998APending Publication Date: 2025-11-28HUAWEI TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380097023.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-08-22
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

In the existing hybrid homomorphic encryption framework, the greater multiplication depth of the AES symmetric cryptography algorithm results in a long calculation delay and is not suitable for homomorphic evaluation.

Method used

A homomorphic evaluation method for symmetric cryptographic algorithms is designed, and homomorphic evaluation of SNOW 3G and ZUC algorithms is realized by performing partial operations of LFSR and FSM in Level 0 and performing table lookup operations in Level 1.

Benefits of technology

While ensuring security, the multiplication depth is reduced, the computing efficiency is improved, and the resource consumption of homomorphic computing is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121039998A_ABST
    Figure CN121039998A_ABST
Patent Text Reader

Abstract

The application provides a homomorphic evaluation method and device of symmetric cipher algorithm, and belongs to the technical field of cryptography, to design a homomorphic evaluation scheme of symmetric stream cipher which meets a lower multiplication depth design standard and has high calculation efficiency and homomorphic friendliness under the condition of ensuring security. In the method, the homomorphic evaluation of SNOW 3G algorithm and ZUC algorithm can be respectively applied to a mixed homomorphic mode, such as performing the first part of operations of LFSR and FSM in a level 0 door bootstrap mode and performing a lookup table operation in a level 1 hierarchical homomorphic calculation mode, so as to realize the architecture and algorithm of homomorphic calculation of SNOW 3G algorithm and ZUC algorithm through fully homomorphic encryption, and further realize the homomorphic evaluation scheme of symmetric cipher algorithm which meets the lower multiplication depth design standard under the condition of ensuring security.
Need to check novelty before this filing date? Find Prior Art

Description

A homomorphic evaluation method and device for a symmetric cryptographic algorithm Technical Field

[0001] The present application relates to the technical field of cryptography, and in particular to a method and device for homomorphic evaluation of a symmetric cryptographic algorithm. Background Art

[0002] Homomorphic encryption is an encryption technique that allows arbitrary computational operations to be performed on ciphertext without decryption. The result of the homomorphic computation, after decryption, corresponds to the original plaintext. This means that data can still be processed and manipulated while encrypted without leaking the original data. Fully homomorphic encryption, a type of homomorphic encryption scheme, relies on bootstrapping, which refreshes the ciphertext to reduce noise levels and prevent errors from expanding during computation, leading to decryption failures. The ciphertext size of fully homomorphic encryption is typically thousands or even millions of times larger than the plaintext size, making it extremely unsuitable for terminals or other small devices with limited computing power and memory resources. The hybrid homomorphic framework combines homomorphic encryption with symmetric encryption schemes to reduce the computational burden and transmission bandwidth on clients using the hybrid homomorphic encryption framework. This framework provides an effective solution to the inherent ciphertext size and transmission bandwidth issues of fully homomorphic encryption.

[0003] Currently, some work on designing and optimizing fully homomorphic encryption schemes within the hybrid homomorphic encryption framework is benchmarked against the Advanced Encryption Standard (AES) symmetric cipher. However, AES's large multiplication depth results in very long computational latency, making the AES block cipher generally considered unsuitable for hybrid homomorphic encryption. Therefore, designing homomorphic evaluation schemes for symmetric ciphers that meet the design criteria of a lower multiplication depth while ensuring security is a hot topic of discussion.

[0004] Summary of the Invention

[0005] The embodiments of the present application provide a homomorphic evaluation method and device for a symmetric cryptographic algorithm, which are used to design a homomorphic evaluation scheme for a homomorphic-friendly symmetric stream cipher that meets the design standards of a low multiplication depth and has high computational efficiency while ensuring security.

[0006] To achieve the above objectives, this application adopts the following technical solutions:

[0007] In a first aspect, a homomorphic evaluation method for a symmetric cryptographic algorithm is provided, which is applied to a homomorphic computing entity, the method comprising: based on a first homomorphic ciphertext at level 0, executing a first part of operations of a linear feedback shift register LFSR and a finite state machine FSM in a gate bootstrap mode at level 0 to obtain a second homomorphic ciphertext at level 0; based on the second homomorphic ciphertext at level 0, executing a multi-valued function bootstrap from level 0 to level 2 and a privacy key switch from level 2 to level 1 to obtain a third homomorphic ciphertext at level 1; and based on the third homomorphic ciphertext at level 1, executing a table lookup operation in a hierarchical homomorphic computing mode at level 1 to obtain a fourth homomorphic ciphertext at level 1.

[0008] Based on the method described in the first aspect, it can be seen that the homomorphic evaluation scheme of the SNOW 3G algorithm and the ZUC algorithm can be designed based on the hybrid homomorphic mode, such as executing the first part of the LFSR and FSM operations in the gate bootstrapping mode at level 0, that is, implementing the operations corresponding to some basic operators of the LFSR and FSM in the SNOW 3G algorithm or the ZUC algorithm, and executing the table lookup operation in the hierarchical homomorphic computing mode at level 1, that is, implementing the operations corresponding to some advanced operators of the LFSR and FSM in the SNOW 3G algorithm or the ZUC algorithm, so that the SNOW 3G algorithm and the ZUC algorithm can be combined with homomorphic encryption respectively, that is, the encryption and decryption architecture and algorithm of the homomorphic computing SNOW 3G algorithm and the ZUC algorithm can be realized through fully homomorphic encryption, thereby achieving the design of a homomorphic evaluation scheme for a symmetric cryptographic algorithm that meets the design standards of a lower multiplication depth while ensuring security.

[0009] In one possible design, the first portion of operations includes at least one of the following: a bit extraction operation, a bit shift operation, an AND operation, an XOR operation, a modular addition operation, and a modular multiplication operation. In other words, the first portion of operations may correspond to operations corresponding to some basic operators of the LFSR and FSM in the SNOW 3G algorithm or the ZUC algorithm. This allows for flexible configuration of the first portion of operations.

[0010] Optionally, the modular addition operation includes an operation performed by a first full adder bootstrapped by one gate, or an operation performed by a second full adder bootstrapped by two gates. In this way, the modular addition operation can be implemented through homomorphic gate calculation.

[0011] Furthermore, the first full adder performs operations including a carry-out operation and a modular addition output operation via a three-input homomorphic AND gate. The carry-out operation and the modular addition output operation are performed iteratively. This allows for simpler and faster evaluation of the full adder using only a single gate bootstrap.

[0012] Furthermore, the second full adder performs operations including a modular addition output operation via a three-input homomorphic XOR gate and a carry output operation via a three-input homomorphic AND gate. The carry output operation and the modular addition output operation are performed iteratively. In this way, the modular addition operation can be implemented using the three-input homomorphic XOR gate and the three-input homomorphic AND gate, while ensuring the accuracy of the modular addition operation.

[0013] Optionally, the modular addition operation includes an operation performed using a tree-structured add-first-then-modulus modular addition strategy. The tree-structured add-first-then-modulus modular addition strategy first adds each data item, and then performs the modulus operation after all data items have been added. In this way, a 31-bit modular addition operation can be implemented more simply and quickly.

[0014] Furthermore, the operations performed by the modular addition strategy include: performing an addition operation on the first 31-bit number to the fourth bit number in the LFSR initialization phase of the ZUC algorithm based on two 31-bit adders to obtain a 32-bit first value and a 32-bit second value; performing an addition operation on the fifth bit number in the LFSR initialization phase of the ZUC algorithm based on one 31-bit adder to obtain a 32-bit third value; performing an addition operation on the first value and the second value based on one 32-bit adder to obtain a 33-bit fourth value; performing an addition operation on the third value and the fourth value based on one 33-bit adder to obtain a 34-bit fifth value; performing a modular (2 31 -1) modulo operation to obtain the shift value corresponding to the updated value of the LFSR register of the ZUC algorithm. In other words, by using the addition-first-modulo operation scheme, only 6 gates (modular addition), i.e., fewer The gate implements the modular addition strategy.

[0015] In one possible design, the table lookup operation involves selecting a target TRLWE ciphertext from two TRLWE ciphertexts using a CMUX gate based on the ciphertext corresponding to the most significant bit of the third homomorphic ciphertext; the two TRLWE ciphertexts are obtained by packing the first lookup table; and obtaining the fourth homomorphic ciphertext at level 1 using a blind rotation algorithm based on all ciphertexts except the ciphertext corresponding to the most significant bit of the third homomorphic ciphertext and the target TRLWE ciphertext. As can be seen, the above table lookup operation consists of eight CMUX gates, homomorphically evaluating an 8-bit input and 8-bit output table lookup operation. For the SNOW 3G and ZUC algorithms, the baseline uses a gate-bootstrapping model to homomorphically evaluate all operations. This approach builds on this by using a hierarchical homomorphic computation model, such as an S-box in a finite state machine, to homomorphically evaluate the table lookup operation. Compared to the baseline, this approach achieves speedups of 2.8x and 21x for the SNOW 3G and ZUC algorithms. That is, the above table lookup operation can improve the operation speed of the SNOW 3G algorithm and the ZUC algorithm.

[0016] In one possible design, the table lookup operation includes: selecting four first-target TRLWE ciphertexts from eight TRLWE ciphertexts using four CMUX gates based on the ciphertext corresponding to the sixth significant bit in the third homomorphic ciphertext; the eight TRLWE ciphertexts are obtained by packing the second lookup table; selecting two second-target TRLWE ciphertexts from the four first-target TRLWE ciphertexts using two CMUX gates based on the ciphertext corresponding to the seventh significant bit in the third homomorphic ciphertext; selecting one third-target TRLWE ciphertext from the two second-target TRLWE ciphertexts using one CMUX gate based on the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext; and obtaining the fourth homomorphic ciphertext at level 1 using a blind rotation algorithm based on all ciphertexts in the third homomorphic ciphertext except for the ciphertext corresponding to the sixth significant bit, the ciphertext corresponding to the seventh significant bit, and the ciphertext corresponding to the most significant bit, and the third target TRLWE ciphertext. It can be seen that the above table lookup operation consists of 12 CMUX gates, i.e., it homomorphically evaluates a table lookup operation with an 8-bit input and a 32-bit output. For the SNOW 3G algorithm, the S-box in the finite state machine and the MULα and DIVα functions in the linear shift register can be completed based on this table lookup operation. Compared with the baseline method of homomorphically evaluating all operations based on the gate bootstrapping mode, combining this table lookup operation with the baseline can accelerate the homomorphic evaluation of SNOW 3G by 40 times, thereby improving the calculation rate of the SNOW 3G algorithm.

[0017] In a possible design scheme, the method described in the first aspect may further include: extracting samples of the fourth homomorphic ciphertext of level 1 and switching the key from level 1 to level 0 to obtain the fifth homomorphic ciphertext of level 0.

[0018] Optionally, the method described in the first aspect may further include: receiving first information sent from a homomorphic key generator, the first information including at least one of the following: a homomorphic ciphertext of a symmetric key, a homomorphic ciphertext of an initial parameter of the symmetric key, a first bootstrap key in a gate bootstrap mode, a homomorphic encryption key for a lookup table operation, a homomorphic ciphertext of a lookup table in a lookup table operation, a second bootstrap key for multi-valued function bootstrapping, a first key switching key from level 2 to level 1, and a second key switching key from level 1 to level 0. In this way, the homomorphic encryption operation corresponding to the SNOW 3G algorithm or the ZUC algorithm can be successfully performed.

[0019] In one possible design, the parameters corresponding to each level of the hierarchical homomorphic computation mode include at least one of the following: ciphertext modulus, standard deviation of noise, TLWE dimension, ring polynomial dimension of TRLWE, gadget decomposition length of TRGSW, and basis of gadget decomposition of TRGSW.

[0020] In a second aspect, a security device is provided. The security device includes: a module for executing the method described in the first aspect, such as a processing module. For example, the processing module is configured to execute, based on a first homomorphic ciphertext at level 0, a first portion of operations of a linear feedback shift register (LFSR) and a finite state machine (FSM) in a gate bootstrap mode at level 0 to obtain a second homomorphic ciphertext at level 0; based on the second homomorphic ciphertext at level 0, execute a multi-valued function bootstrap from level 0 to level 2 and a privacy key switch from level 2 to level 1 to obtain a third homomorphic ciphertext at level 1; and based on the third homomorphic ciphertext at level 1, execute a table lookup operation in a hierarchical homomorphic computation mode at level 1 to obtain a fourth homomorphic ciphertext at level 1.

[0021] Optionally, the security device may further include a transceiver module for communicating with other devices.

[0022] Furthermore, the transceiver module may include a sending module and a receiving module, wherein the sending module is used to implement the sending function of the safety device described in the second aspect, and the receiving module is used to implement the receiving function of the safety device described in the second aspect.

[0023] Optionally, the security device described in the second aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the security device may execute the method described in the first aspect.

[0024] It can be understood that the security device described in the second aspect can be a terminal, or a network device, or other device that can perform homomorphic tasks, or a chip (system) or other parts or components that can be set in the terminal, or network device, or other device that can perform homomorphic tasks, or a device that includes the terminal, or network device, or a device with homomorphic encryption capabilities.

[0025] In addition, the technical effects of the safety device described in the second aspect can refer to the technical effects of the method described in the first aspect, and will not be repeated here.

[0026] In a third aspect, a security device is provided, comprising: a processor configured to execute the method described in any possible implementation of the first aspect.

[0027] In one possible design solution, the security device described in the third aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used to enable the security device described in the third aspect to communicate with other devices.

[0028] In one possible design, the security device described in the third aspect may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the method described in any one of the implementations of the first aspect.

[0029] In an embodiment of the present application, the security device described in the third aspect may be a terminal, or a network device, or other device that can perform homomorphic tasks, or a chip (system) or other parts or components that can be set in the terminal, or the network device, or other device that can perform homomorphic tasks, or a device that includes the terminal, or the network device, or a device with homomorphic encryption capabilities.

[0030] In addition, the technical effects of the safety device described in the third aspect can refer to the technical effects of the method described in any implementation method of the first aspect, and will not be repeated here.

[0031] In a fourth aspect, a security device is provided, comprising: a processor coupled to a memory, the processor configured to execute a computer program stored in the memory, so that the security device executes the method described in any possible implementation of the first aspect.

[0032] In one possible design solution, the security device described in the fourth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used to enable the security device described in the fourth aspect to communicate with other devices.

[0033] In an embodiment of the present application, the security device described in the fourth aspect may be a terminal, or a network device, or other device that can perform homomorphic tasks, or a chip (system) or other parts or components that can be set in the terminal, or the network device, or other device that can perform homomorphic tasks, or a device that includes the terminal, or the network device, or a device with homomorphic encryption capabilities.

[0034] In addition, the technical effects of the safety device described in the fourth aspect can refer to the technical effects of the method described in any implementation method of the first aspect, and will not be repeated here.

[0035] In a fifth aspect, a security device is provided, comprising: a processor and a memory; the memory is used to store a computer program, and when the processor executes the computer program, the security device executes the method described in any one of the implementation methods of the first aspect.

[0036] In one possible design solution, the security device described in the fifth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used to enable the security device described in the fifth aspect to communicate with other devices.

[0037] In an embodiment of the present application, the security device described in the fifth aspect may be a terminal, or a network device, or other device that can perform homomorphic tasks, or a chip (system) or other parts or components that can be set in the terminal, or the network device, or other device that can perform homomorphic tasks, or a device that includes the terminal, or the network device, or a device with homomorphic encryption capabilities.

[0038] In addition, the technical effects of the safety device described in the fifth aspect can refer to the technical effects of the method described in any one of the implementation methods of the first aspect, and will not be repeated here.

[0039] In a sixth aspect, a chip is provided, in which instructions are stored, and when the chip runs on a security device, any possible implementation method of the first aspect is implemented.

[0040] In a seventh aspect, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are run on a computer, the computer is caused to execute the method described in any possible implementation manner in the first aspect.

[0041] In an eighth aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed on a computer, causes the computer to execute the method described in any possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] FIG1 is a schematic diagram of a homomorphic encryption architecture according to an embodiment of the present application;

[0043] FIG2 is a second schematic diagram of the homomorphic encryption architecture provided in an embodiment of the present application;

[0044] FIG3 is a schematic diagram of a first process of homomorphic encryption according to an embodiment of the present application;

[0045] FIG4 is a schematic diagram of a hierarchical homomorphic computing mode provided in an embodiment of the present application;

[0046] FIG5 is a schematic diagram of the architecture of hybrid homomorphic encryption provided in an embodiment of the present application;

[0047] FIG6 is a schematic diagram of the architecture of the SNOW 3G algorithm provided in an embodiment of the present application;

[0048] FIG7 is a schematic diagram of the architecture of the Zu Chongzhi ZUC algorithm provided in an embodiment of the present application;

[0049] FIG8 is a flow chart of a homomorphic evaluation method for a symmetric cryptographic algorithm provided in an embodiment of the present application;

[0050] FIG9 is a schematic diagram of the architecture of a homomorphic evaluation method for a symmetric cryptographic algorithm provided in an embodiment of the present application;

[0051] FIG10 is a schematic diagram of a pseudo code of an algorithm of a second full adder provided in an embodiment of the present application;

[0052] FIG11 is a schematic diagram of a modular addition strategy provided in an embodiment of the present application;

[0053] FIG12 is a schematic diagram of a pseudo code of an algorithm for a table lookup operation according to an embodiment of the present application;

[0054] FIG13 is a schematic diagram of a table lookup operation provided in an embodiment of the present application;

[0055] FIG14 is a second schematic diagram of a pseudo code of an algorithm for a table lookup operation provided in an embodiment of the present application;

[0056] FIG15 is a second schematic diagram of the homomorphic encryption process provided in an embodiment of the present application;

[0057] FIG16 is a first structural diagram of a safety device provided in an embodiment of the present application;

[0058] FIG17 is a second structural diagram of the safety device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0059] For ease of understanding, the technical terms involved in the embodiments of this application are first introduced below.

[0060] 1. Homomorphic encryption

[0061] As shown in Figure 1, homomorphic encryption (such as fully homomorphic encryption (FHE)) is an encryption technology that allows arbitrary technical operations to be performed on ciphertext without decryption. The results of the homomorphic computation, after decryption, correspond to the technical results of the original plaintext, that is, they are consistent with the plaintext computation results. This means that even in an encrypted state, data can still be processed and manipulated without leaking the original data. Homomorphic encryption generally consists of four algorithmic parts: key generation, homomorphic encryption, homomorphic evaluation, and homomorphic decryption, which are described below.

[0062] 1) Key Generation

[0063] As shown in Figure 2, the homomorphic key generation party can input the key material into the key generator to obtain the public key (pk), that is, the encryption key K enc (encryption key), private key (secret key, sk), that is, decryption key K dec (decryption key), homomorphic evaluation key (evk), that is, the calculation key K eval (evaluation key).

[0064] 2) Homomorphic encryption

[0065] As shown in Figure 2, homomorphic encryption uses the encryption key K enc Encrypt a single bit of plaintext data, such as m∈{0,1}, into ciphertext data, such as c=E pk (m). If there are multiple plaintext data, such as m1, m2, ..., m l , l is an integer greater than 1, and the homomorphic encryption party uses the encryption key K enc , encrypt multiple plaintext data into ciphertext data, such as c=E pk (m1,m2,…,m l ).

[0066] 3) Homomorphic decryption

[0067] As shown in Figure 2, the homomorphic decryption party uses the decryption key K dec , restore the ciphertext data to plaintext data, such as the ciphertext data is c=E pk(m), the homomorphic decryption party can restore c to the plaintext data m∈{0,1}; if the ciphertext data is c=E pk (m1,m2,…,m l ), the homomorphic decryption party can restore c to plaintext data m1,m2,…,m l .

[0068] 4) Homomorphic evaluation

[0069] As shown in Figure 2, homomorphic evaluation can also be called homomorphic computation, which is the operation of the homomorphic computation party. The homomorphic computation party uses the computation key K eval Calculate the ciphertext data (denoted as ciphertext data #1) to obtain the ciphertext data after homomorphic calculation (denoted as ciphertext data #2). If the homomorphic calculation function is f, and the ciphertext data #1 is c=E pk (m), then the ciphertext data #2 is c f =E pk (f(m)); the homomorphic calculation function is f, and the ciphertext data #1 is E pk (m1,m2,…,m l ), then the ciphertext data #2 is c f =E pk (f(m1,m2,…,m l )).

[0070] As you can understand, the above introduction to homomorphic encryption consists of four parts: key generation, homomorphic encryption, homomorphic evaluation, and homomorphic decryption. The following describes the overall process, combining these parts.

[0071] As shown in Figure 3, the homomorphic key generator generates the homomorphic encryption key K based on the key material. enc , homomorphic decryption key K dec and homomorphically evaluate the key K eval After that, the homomorphic encryption key K enc Send it to the homomorphic encryption party and send the homomorphic decryption key K dec Send to the homomorphic decryption party, and the homomorphic evaluation key K eval Sent to the homomorphic computing party.

[0072] The homomorphic encryption party receives the homomorphic encryption key K from the homomorphic key generator. enc After that, the homomorphic encryption key K can be used enc Perform homomorphic encryption on the plaintext data to obtain ciphertext data; and send the ciphertext data to the homomorphic computing party.

[0073] The homomorphic computing party receives the homomorphic evaluation key K from the homomorphic key generator. eval , and after receiving the ciphertext data from the homomorphic encryption party, the homomorphic evaluation key K can be used evalPerform homomorphic computation on the ciphertext data to obtain homomorphically computed ciphertext data; and send the homomorphically computed ciphertext data to a homomorphically decrypting party.

[0074] The homomorphic decryption party receives the decryption key K from the homomorphic key generator. dec , and after receiving the ciphertext data after homomorphic calculation from the homomorphic computing party, the homomorphic decryption key K can be used dec The ciphertext data after the homomorphic calculation is homomorphically decrypted to obtain the calculated plaintext data.

[0075] 2. Ciphertext

[0076] Homomorphic encryption uses various ciphertext forms, including learning with errors (LWE), the torus version of learning with errors (TLWE), ring learning with errors (RLWE), the torus version of the ring-LWE problem (TRLWE), RGSW (Gentry Sahai Water's ring version), and TRGSW. These are described below.

[0077] It should be understood that in the embodiments of the present application, lowercase bold letters are used to represent vectors, and uppercase bold letters are used to represent matrices. For example, a vector a of n elements is described as a=(a1,…,a n ).<a,b> is the inner product between two vectors. The set of integers is represented by As a set of real numbers. Represents the binary set {0,1}. Use Indicates a ring in The range is is the ciphertext modulus q. They are represented as floor, ceiling and round functions respectively.

[0078] use represents a 2N-th cyclotomic ring, modulo X N +1, where N is a power of 2. The coefficient is The quotient ring on the express A polynomial with binary coefficients in . Real torus is the set of real numbers modulo 1. is a torus polynomial Where N is a power of 2.

[0079] For polynomials The coefficient vector can be expressed as φ(m)=(m0,…,m N-1 ). Let x←D represent sampling x according to distribution D. For random variables Use Var(a) and stddev(a) to represent the variance and standard deviation of a. Then, for the vector Indicates the calculation of the 2-norm of a polynomial by its coefficient vector. In addition, a semicolon is used to indicate the vertical concatenation of vectors or matrices, such as [A; B].

[0080] 1)LWE

[0081] An LWE sample is a vector such as b=<a,s> +e mod q. Among them, is a uniformly random n-dimensional vector from uniform sampling in the key; the key s is an n-dimensional vector, and s can be sampled from the key distribution χ (such as Gaussian distribution); the error e←χ δ Sampling is done from an error distribution (e.g., Gaussian distribution); positive integers n and q are the vector dimension and ciphertext modulus, respectively.

[0082] The LWE ciphertext of the plaintext message m is: Δ=q / t, t is the plaintext modulus, and the dimensions of b, m, and e are 1.

[0083] 2) TLWE

[0084] The TLWE ciphertext is the Torus version of LWE and can be expressed as Specifically, b=<a,s> + m+e, where vector a is derived from uniformly sampled from B, the key s is n uniform sampling, is the plaintext message, and the error e is sampled from a Gaussian distribution with mean 0 and standard deviation σ.

[0085] 3)RLWE

[0086] RLWE is R qA valid RLWE sample is a pair of b=as+e mod Q, where the secret key s of the RLWE sample is sampled from the key distribution χ (such as Gaussian distribution), and a is in R q Uniformly random, error is sampled from the error distribution. (a,b) is equivalent to an RLWE ciphertext of message 0.

[0087] To simplify the description, the polynomial dimension N of RLWE is generally ignored.

[0088] Similar to the LWE sample, the RLWE ciphertext of the plaintext message m is Δ=Q / t, where t is the plaintext modulus.

[0089] The encryption of LWE is:

[0090] The encryption of RLWE is:

[0091] The decryption of LWE is:

[0092] The decryption of RLWE is:

[0093] 4)TRLWE

[0094] The TRLWE ciphertext is the Torus version of RLWE and can be expressed as Specifically, b=<a,s> +m+e, where a is from uniformly sampled from uniform sampling, is the plaintext message polynomial. Error is a polynomial with random coefficients, Sample from a Gaussian distribution with mean 0 and standard deviation σ.

[0095] 5)RGSW

[0096] An RGSW sample is a vector based on d RLWE samples, using Indicates. Given a gadget vector v=(v0,v1,…,v d-1 ), RLWE' represents the concept of gadget RLWE, which is defined as: RLWE′ sk (m) = (RLWE sk (v0·m),RLWE sk(v1·m),…,RLWE sk (v d-1 ·m)).

[0097] sk is the key, then the plaintext message m∈R q The RGSW ciphertext can be expressed as: RGSW sk (m) = (RLWE′ sk (sk·m),RLWE′ sk (m)). Parameters with the same dimension and ciphertext modulus are omitted.

[0098] 6)TRGSW

[0099] TRGSW is a torus version of RGSW that can convert plaintext messages Encrypted to ciphertext in It is a matrix, and each row of the matrix Z is the TRLWE ciphertext of the plaintext message 0 under the same key. -1 is the gadget decomposition matrix, which is used to control noise propagation.

[0100] Assume k = 1, TRGSW ciphertext It can be further expressed as follows:

[0101] Among them (a i (x),b i (x)), 1≤i≤2l is the TRLWE ciphertext of plaintext message 0 encrypted with the same key, B g represents the basis of gadget decomposition, and l is the length of gadget decomposition.

[0102] It can be understood that these ciphertext types can be converted to each other to cope with different computing tasks.

[0103] 3. Fully homomorphic encryption (FHE)

[0104] Fully homomorphic encryption schemes rely on a core operation called bootstrapping, a concept defined by Gentry in his first FHE solution proposed in 2009. The purpose of bootstrapping is to refresh the ciphertext, reduce its noise level, and prevent decryption failures caused by error expansion during computation. Bootstrapping can also be viewed as a decryption algorithm for homomorphic FHE computation. By decrypting the underlying ciphertext back to its original form, a new, low-noise FHE ciphertext is obtained.

[0105] The Fully Homomorphic Encryption scheme over the Torus (TFHE) is one of the most practical FHE schemes currently available. To enable homomorphic computation on circuits of arbitrary depth, TFHE introduces two bootstrapping operations to reduce noise and transform the ciphertext: gate bootstrapping and circuit bootstrapping. The following sections describe gate bootstrapping and circuit bootstrapping, respectively.

[0106] 1) Gate Bootstrap

[0107] Gate bootstrapping is a process in which a bootstrapping operation is performed on each binary gate during homomorphic computation. The core of gate bootstrapping is blind rotation, which involves rotating a polynomial using a ciphertext. This can be implemented using n CMUX gates, which are constructed using the outer product of the RLWE ciphertext and the RGSW ciphertext.

[0108] The input of the gate bootstrap is a homomorphically computed, noisy LWE / TLWE homomorphic ciphertext c = (b, a), whose corresponding homomorphic encryption and decryption keys are (pk, sk). The output of the gate bootstrap is a low-noise LWE / TLWE ciphertext, which reduces the noise to a relatively low range.

[0109] Specifically, we can first use the new homomorphic encryption key pk' to re-homomorphically encrypt b in the homomorphic ciphertext c, that is, RLWE.Enc(X -b ), recorded as the initial value of the blindly rotated accumulator ACC; then the initial value of ACC is input to the first CMUX gate, and a rotation component is rotated through the first CMUX gate to obtain the ACC output by the first CMUX gate, and the ACC output by the first CMUX gate is input to the second CMUX gate to form an iteration, and so on. After n CMUX gates are iteratively updated, the result output by the nth CMUX gate is RLWE.Enc(X -b+<a,s> ).

[0110] For ease of understanding, among n CMUX gates, the calculation process of the i-th CMUX gate can be expressed as follows: ACC=CMUX((ACC,X a[i] ACC), BK i )=ACC+(X a[i] -1) ACC⊙BK i

[0111] Among them, X a[i] is the i-th rotation component of the blind rotator operation, i is an integer from 1 to n, and n is the polynomial dimension of a. i is the i-th RLWEpk′ and RGSW pk′ The outer product of (sk[i]). ACC is the homomorphic ciphertext in RLWE form. BK i The homomorphic ciphertext in RGSW format can be specifically the ciphertext obtained by homomorphically encrypting the original homomorphic decryption key sk using the new homomorphic encryption key pk'. It can be understood that based on the characteristics of homomorphic computing, the bootstrapped high-noise homomorphic ciphertext (b, a) is multiplied by its corresponding decryption key (1, sk), that is, the high-noise homomorphic ciphertext is homomorphically decrypted, ultimately obtaining a low-noise homomorphic ciphertext, thus achieving noise suppression.

[0112] After n CMUX gate iterative updates and sample extraction, the bootstrapped low-noise homomorphic ciphertext can be obtained, which is denoted as LWE.Enc(m).

[0113] 2) Circuit bootstrap

[0114] TFHE provides a hierarchical homomorphic evaluation (LHE) scheme that efficiently computes multi-input lookup tables (LUTs), bit sequence representations (BSRs), and weighted finite automata (WFAs) using hierarchical circuits with a large number of layers or depth. The inputs and outputs of hierarchical homomorphic computations have different ciphertext forms. To achieve composability, circuit bootstrapping is required to transform the ciphertext form while implementing refresh noise.

[0115] As shown in Figure 4, to ensure security and operational correctness, TFHE's hierarchical homomorphic computing model spans three levels: level 0, level 1, and level 2. Each level sets different parameters, such as the homomorphic key.

[0116] The dimension n of level 0 is relatively low, such as n=635, and the ciphertext modulus q is relatively small, such as 32 bits, but the noise is relatively large, such as σ 2 ≈2 -30 , σ represents the noise of level 0.

[0117] Level 1 has a medium dimension n, such as n = 1024, and a relatively small ciphertext modulus q, such as 32 bits, but also relatively large noise, such as σ 2 ≈2 -50, σ represents the noise of level 1. Level 1 calculation is also relatively fast and can allow relatively high depth. For example, the above-mentioned LUT, BSR, WFA, etc. can all be executed at level 1.

[0118] The dimension n of level 2 is medium, such as n = 2048, the ciphertext modulus q is relatively large, such as 64 bits, but the noise is relatively small, such as Represents noise at level 1. Level 2 is slower to compute.

[0119] It can be understood that in the embodiments of the present application, variables at level 0 are represented by underscores, and variables at level 2 are represented by overscores.

[0120] The input of the circuit bootstrap is the noisy LWE / TLWE ciphertext, and the output is the noisy RGSW / TRGSW ciphertext. The circuit bootstrap spans three levels, such as the operation from level 0 to level 2 and from level 2 to level 1 (dashed arrows in the figure). The circuit bootstrap key includes: the key switching key from level 1 to level 0. The function bootstrap key from level 0 to level 2, such as sk i is the i-th item of the LWE key sk at level 0, i∈[1,n], where n is the polynomial dimension; and the circuit bootstrapping key also includes: 2 privacy key switching keys from level 2 to level 1, such as and RLWE′ sk (f 0,1 (1)). Here, function f0 is the identity function, function f1(x) = sk·x, sk is the RLWE key of level 1, Is a level 2 LWE key The jth term of , j∈[1,n], n is the polynomial dimension. Thus, the circuit bootstrap: CBS LWE→RGSW :LWE sk (m)→RGSW sk (m) may include the following three steps:

[0121] Step 1: Sample extraction and key switching (level 1 to level 0).

[0122] Taking a Level 1 RLWE sample with a large noise amplitude as input, we first use the Sample Extraction algorithm to extract the LWE ciphertext. Then, we use LWE-to-LWE key-switching to obtain the Level 0 LWE ciphertext.

[0123] Step 2: Function bootstrapping (level 0 to level 2).

[0124] This step calls 1 function bootstrap or 1 multi-value bootstrap (or PBSmanyLUT) to refresh the noise and perform function calculation.

[0125] Function bootstrapping can be expressed as follows:

[0126] Where v=(v0,v1,…,v l-1 ) is the gadget vector. Among them, the level 0 ciphertext is bootstrapped by the function to obtain the level 2 ciphertext sk is the key of level 0, is the level 2 key. l is equivalent to breaking a large number into smaller numbers, i.e., l LWE ciphertexts. testP is the test polynomial encoded by the LUT function f. Function bootstrapping can simultaneously compute a function f while simultaneously performing noise reduction and refreshing the ciphertext. Furthermore, in function bootstrapping, if a gate is computed, it is also called gate bootstrapping.

[0127] Step 3: Privacy key switching (such as level 2 to level 1).

[0128] This step calls PrivateKS 2l times. The privacy key switching can be expressed as follows: RGSW sk (m) = (RLWE′ sk (sk·m),RLWE′ sk (m));

[0129] Among them, the ciphertext of level 2 is converted into the ciphertext of level 1 after the privacy key is switched. The input of privacy key switching is LWE ciphertext, and the output is RGSW ciphertext. Specifically, privacy key switching involves: 1) changing the ciphertext form and computing the function f0 (identity function) and the function f1 (message m multiplied by the key sk); 2) concatenating one RLWE ciphertext into one RLWE' ciphertext, and then concatenating two RLWE's into one RGSW ciphertext.

[0130] 4. Hybrid Homomorphic Encryption

[0131] Hybrid homomorphic encryption combines homomorphic and symmetric encryption schemes to reduce client computational burden and transmission bandwidth. This framework addresses the inherent ciphertext size and transmission bandwidth issues inherent in fully homomorphic encryption.

[0132] As shown in Figure 5, rk in Figure 5 is a symmetric key, such as the round key of AES symmetric encryption; HE(rk) is the homomorphic ciphertext generated by the symmetric key after homomorphic encryption; m is the plaintext data to be encrypted; ε is the symmetric encryption operation under the plaintext; HE(ε(m)) is the mixed ciphertext after symmetric encryption and homomorphic encryption; Homomorphic evaluation ε -1 The symmetric decryption circuit is homomorphically computed under the ciphertext. In hybrid homomorphic encryption, the data sender (client) simply uses a symmetric encryption scheme to encrypt the original data (with a ciphertext expansion rate of 1) and transmits the symmetric ciphertext to the server. After receiving the symmetric ciphertext, the server first performs homomorphic encryption and then homomorphically computes the decryption circuit of the symmetric encryption scheme, thus converting the symmetric ciphertext into homomorphic ciphertext. Finally, the server performs homomorphic computation on the homomorphic ciphertext and sends the computed homomorphic ciphertext back to the client.

[0133] For clients (such as small terminal devices), hybrid homomorphic encryption can reduce the client's transmission bandwidth. That is, the client transmits the smaller symmetric ciphertext instead of the larger homomorphically encrypted ciphertext. Furthermore, hybrid homomorphic encryption can reduce the client's computational workload. In other words, the client only needs to perform symmetric encryption, without homomorphically encrypting the plaintext data m.

[0134] 5. Homomorphic Gate Computation

[0135] In gate bootstrapping, binary messages 0 and 1 are encoded as {(-1) / 8, 1 / 8} over the torus, respectively. Now, assuming two TLWE ciphertexts c1 and c2, some basic homomorphic gate operations are as follows:

[0136] HomoNOT(c)=(0,1 / 8)-c(no bootstrapping);

[0137] Homomorphism and: HomoAND(c1,c2)=(0,-1 / 8)+Bootstrap(c1+c2);

[0138] Homomorphic XOR: HomoXOR(c1,c2)=(0,1 / 4)+Bootstrap(2(c1±c2));

[0139] HomoOR(c1,c2)=(0,1 / 8)+Bootstrap(c1+c2);

[0140] 6. SNOW 3G

[0141] SNOW 3G is a word-oriented (32-bit) stream cipher with a key size of 128 bits and an initialization variable of 128 bits. 232 It consists of a 16-level linear feedback shift register (LFSR) and a finite state machine (FSM).

[0142] As shown in Figure 6, the algorithm flow of SNOW 3G is as follows:

[0143] Step 601, set the initial value s of 16 registers of LFSR i . Input 128-bit seed key (k0||k1||k2||k3) and initial vector IV (IV0||IV1||IV2||IV3).

[0144] Step 602, set three 32-bit registers, R1 = R2 = R3 = 0.

[0145] Step 603: iterate 32 rounds of the initialization mode process to update the LFSR.

[0146] Specifically, the FSM is clocked to generate a 32-bit word F. The LFSR is clocked in an initialization mode to consume F.

[0147] Step 604, execute the key stream generation mode to generate the key stream word z t .

[0148] Specifically, the FSM is clocked once and the output word of the FSM is discarded. The LFSR is clocked once in keystream mode. n 32-bit keystream words are generated as follows:

[0149] for t=1to n{

[0150] Clock the FSM and produce a 32-bit output word F.

[0151] The next key stream is calculated once:

[0152] The LFSR is clocked in keystream mode.

[0153] end

[0154] It can be understood that the initialization mode of LFSR (s i , i∈[0,15],32bits) includes: updating the LFSR according to the input 32-bit word F (i.e., the output of FSM), i.e. Among them, s i =si +1,0≤i≤14,s 15 =v.

[0155] The working mode of LFSR is: Among them, s i =s i +1,0≤i≤14,s 15 =v.

[0156] The FSM input is two 32-bit words s from the LFSR. 15 and s5, and three 32-bit registers R1, R2, R3; its output is a 32-bit word Among them, the median value is And the registers R1, R2, R3 can be updated through the two S-boxes S1 and S2: R3 = S2 (R2), R2 = S1 (R1), R1 = r.

[0157] The components used in LFSR include: MULx, MULxPOW, MUL α , and DIV α , each component is introduced below.

[0158] The MULx function takes two 8-bit data V and c as input and outputs one 8-bit data after conversion, i.e.

[0159] The input of the MULxPOW function is two 8-bit data V, c and a positive integer i. After conversion, the output is an 8-bit data, that is,

[0160] MUL α Function mapping 8 bits to 32 bits, namely MUL α (c)=(MULxPOW(c,23,0xa9)||MULxPOW(c,245,0xa9)||MULxPOW(c,48,0xa9)||MULxPOW(c,239,0xa9)).

[0161] DIV α Function mapping 8 bits to 32 bits, namely DIV α (c)=(MULxPOW(c,16,0xa9)||MULxPOW(c,39,0xa9)||MULxPOW(c,6,0xa9)||MULxPOW(c,64,0xa9)).

[0162] 32x32-bit S-Box (S1, S2) used by FSM: S-Box S1 maps 32-bit input to 32-bit output. Let w = w0||w1||w2||w3 be the 32-bit input, then S1(w) = r0||r1||r2||r3, where r0, r1, r2, r3 are defined as:

[0163] Among them, S R It is an 8-to-8-bit Rijndael S-Box. Similar to S1, S-Box S2 also maps 32-bit input to 32-bit output, but it uses another Rijndael S-Box S Q .

[0164] It can be seen that SNOW 3G includes bit shift, XOR Module 2 32 addition S-box (S-box) S1, S2 and other operations.

[0165] 7. Zu Chongzhi (ZUC) algorithm

[0166] ZUC is a word-oriented stream cipher that takes an initial key and initial vector (IV) as input and outputs a 32-bit keystream that can be used for encryption / decryption. ZUC is executed in two phases: an initialization phase and a working phase (i.e., keystream generation). In the first phase, the key / IV is initialized to update the LFSR, meaning the cipher is clocked without generating output. In the second phase, it generates a 32-bit word per clock cycle.

[0167] As shown in Figure 7, ZUC has three logic layers. The top layer is a linear feedback shift register (LFSR) with 16 stages. Unlike SNOW 3G, ZUC’s LFSR has 16 31-bit cells, each with s i , are taken from Galois Fields (GF) GF(2 31 -1), 0≤i≤15; the middle layer is used for bit-reorganization (BR); the bottom layer is the nonlinear function F.

[0168] The algorithm flow of ZUC is:

[0169] Step 701, set the LFSR initial value s i . Input 128-bit seed key k(k0||k1||…k 15 ), 128-bit initial vector iv (iv0||iv1||…iv 15 ) and a known constant d (16 15-bit d i ). Registers i =k i ||d i ||iv i , s i ∈GF(2 31 -1), 31 bits long, 0≤i≤15.

[0170] Step 702, set two 32-bit registers, R0=R1=0.

[0171] Step 703: iterate the initialization process 32 times. The specific iteration method is as follows:

[0172] Step 704: Iterate one round of key stream generation mode to output a 32-bit key word Z, where W is the output of the nonlinear function F and X3 is the output of the bit reorganization BR. The specific generation method is as follows:

[0173] –BitReconstruction(); / / bit reconstruct BR

[0174] –W=F(X0,X1,X2),diszard W; / / nonlinear function

[0175] –LFSRWithworkMode(); / / Linear feedback shift register working mode

[0176] / / Output key word

[0177] It can be understood that the initialization mode of LFSR in ZUC algorithm (s i ∈GF(2 31 -1)) is LFSRWithInitializationMode(u), that is, the output of the nonlinear function W>>1 in the initialization mode is used as the input of the LFSR. The specific steps are as follows:

[0178] v=2 15 ·s 15 +2 17 ·s 13 +2 21 ·s10 +2 20 s4+(1+2 8 )·s0mod(2 31 -1);s 16 =(v+u)mod(2 31 -1); if s 16 =0, then set s 16 =(2 31 -1);(s 16 ,s 15 ,…,s2,s1)→(s 15 ,s 14 ,…,s1,s0). Among them, s 16 is the update value of LFSR, and v is the shift value.

[0179] The working mode of LFSR is: 16 =2 15 ·s 15 +2 17 ·s 13 +2 21 ·s 10 +2 20 s4+(1+2 8 )·s0mod(2 31 -1); if s 16 =0, then set s 16 =(2 31 -1);(s 16 ,s 15 ,…,s2,s1)→(s 15 ,s 14 ,…,s1,s0).

[0180] The nonlinear function F (i.e., FSM) has two 32-bit registers R1 and R2. The inputs to F are X0, X1, and X2, which are the first three words output by the BR program. The output of F is a 32-bit word W.

[0181] Specifically, based on the input X0, X1, X2 of the nonlinear function F and the two registers R1 and R2, the XOR and modulo 2 32 The addition obtains the intermediate variables W1, W2, and the output W of the nonlinear function F.

[0182] Then, based on the intermediate variables W1, W2, two 32-bit linear transformations L1, L2 and four parallel S-boxes are used to update registers R1, R2, R1 = S (L1 (W 1L ||W 2H )), R2=S(L2(W 2L ||W1H )). Where S=(S0, S1, S0, S1) is 4 parallel S-boxes, L1 and L2 are two 32-bit linear transforms,

[0183] The bit reassembly extracts 128 bits from the LFSR word to form four 32-bit words, of which the first three words will be passed to the next layer, the nonlinear function F, and the last word will participate in the generation of the key stream. 15H ||s 14L , X1=s 11L ||s 9H , X2=s 7L ||s 5H , X3=s 2L ||s 0H . Where s iH It is the letter s i The high 16 bits of s jL It is the letter s j The lower 16 bits of the .

[0184] It can be seen that the ZUC algorithm includes bit shift, XOR Module 2 32 addition S-box, GF(2 31 - 1) Operations such as modular multiplication and modular addition.

[0185] Building on the aforementioned introduction to homomorphic encryption, Gentry et al. first proposed an AES evaluation scheme based on the BGV (Zvika Brakerski, Craig Gentry, and Vinod Vaikuntanathan) homomorphic encryption scheme. Since then, several related works on designing and optimizing fully homomorphic encryption schemes have been benchmarked against AES. However, the AES block cipher is generally considered unsuitable for hybrid homomorphic encryption frameworks due to its large multiplication depth, which results in very long computational latency. Therefore, designing homomorphic evaluation schemes for symmetric cryptographic algorithms that meet the design criteria of a lower multiplication depth while ensuring security is currently a hot topic of discussion.

[0186] In response to the above problems, the embodiments of the present application propose the following technical solutions, which will be described below in conjunction with the accompanying drawings.

[0187] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless network (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device to device (D2D) communication systems, Internet of Vehicles communication systems, 4G, such as long-term evolution (LTE) systems, world-wide interoperability for microwave access (WiMAX) communication systems, 5G, such as new radio (NR) systems, and future communication systems. The technical solutions of the embodiments of the present application can also be applied to other potential industries, such as genetics, health care, national security, education, social security, commercial financial analysis and other industries, for scenarios where privacy protection is required during computing, such as cloud computing, outsourced computing, machine learning, and privacy data processing.

[0188] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information (such as the first information, the second information, or the third information below) is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein the other information and the information to be indicated have an association relationship. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.

[0189] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0190] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. The sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.

[0191] "Pre-definition" or "pre-configuration" can be achieved by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a security device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a security device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.

[0192] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.

[0193] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.

[0194] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated with each other are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.

[0195] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0196] The homomorphic evaluation method of the symmetric cryptographic algorithm provided in the embodiment of the present application will be specifically described below with reference to FIG8 .

[0197] 8 is a flow chart of a homomorphic evaluation method for a symmetric cryptographic algorithm provided in an embodiment of the present application. The homomorphic evaluation method for a symmetric cryptographic algorithm can be executed by a homomorphic computing entity.

[0198] The homomorphic computing entity can specifically be a terminal, a network device, or other device with homomorphic capabilities, or it can also be a chip in a terminal, a network device, or other device with homomorphic capabilities, or it can also be an apparatus that includes a terminal, a network device, or other device with homomorphic capabilities.

[0199] The terminal may be a terminal with transceiver functions, or a chip or chip system that can be set in the terminal. The terminal may also be called user equipment (UE), access terminal, subscriber unit, user station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device. The terminal in the embodiments of the present application can be a mobile phone, a cellular phone, a smart phone, a tablet computer, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handset, a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle-mounted terminal, a road side unit (RSU) with terminal function, etc. The terminal of the present application may also be an on-board module, on-board module, on-board component, on-board chip or on-board unit built into the vehicle as one or more components or units.

[0200] The network device may be a device in an access network (AN), such as an access network device, or may be referred to as a radio access network device (RAN), which is used to provide network access services to a terminal. For example, the RAN device may include: a next-generation mobile communication system, such as a 6G access network device, such as a 6G base station, or in a next-generation mobile communication system, the network device may also have other naming methods, all of which are included in the protection scope of the embodiments of the present application, and the present application does not impose any restrictions on this. Alternatively, the RAN device may also include 5G, such as a gNB in ​​a new radio (NR) system, or one or a group of antenna panels (including multiple antenna panels) of a base station in 5G, or a network node constituting a gNB, a transmission and reception point (TRP or transmission point, TP) or a transmission measurement function (TMF), such as a baseband unit (BBU), a centralized unit (CU) or a distributed unit (DU), an RSU with base station functions, or a wired access gateway, or a 5G core network element. Alternatively, RAN devices may also include access points (APs) in wireless fidelity (WiFi) systems, wireless relay nodes, wireless backhaul nodes, various forms of macro base stations, micro base stations (also known as small stations), relay stations, access points, wearable devices, vehicle-mounted devices, and the like.

[0201] Alternatively, the network device may also be a device in the core network (CN), such as a user plane function (UPF) network element, an authentication server function (AUSF) network element, an access and mobility management function (AMF) network element, a session management function (SMF) network element, a policy control function (PCF) network element, a unified data management (UDM) network element, an application function (AF), etc., without specific limitation.

[0202] As shown in Figures 8 and 9, the homomorphic evaluation method of the symmetric cryptographic algorithm includes the following steps:

[0203] S801 , based on the first homomorphic ciphertext of level 0, executing the first part of the LFSR and FSM operations in the gate bootstrapping mode of level 0 to obtain the second homomorphic ciphertext of level 0.

[0204] For the hierarchical homomorphic computing mode, please refer to the relevant introduction of "4.2) Circuit Bootstrapping" above, which will not be repeated here.

[0205] The first homomorphic ciphertext can be a TLWE ciphertext. For details about TLWE ciphertext, refer to the previous section "2.2) TLWE" and are not further described here. The first homomorphic ciphertext can be obtained from a previous homomorphic evaluation based on the gate bootstrapping mode, or it can be obtained from the output of a hierarchical homomorphic computation circuit through sample extraction and key switching.

[0206] Gate bootstrapping mode means that during homomorphic computation, a bootstrapping operation can be performed at each binary gate. In other words, at level 0, partial operations of the LFSR and FSM, i.e., the first partial operations, can be performed based on gate bootstrapping.

[0207] The LFSR and FSM may be the LFSR and FSM in the SNOW 3G algorithm. For details, refer to the relevant introduction in "5. SNOW 3G" above and will not be repeated here. The LFSR and FSM may also be the LFSR and FSM in the ZUC algorithm. For details, refer to the relevant introduction in "6. Zu Chongzhi Algorithm" above and will not be repeated here.

[0208] The first portion of operations for the LFSR and FSM can be operations corresponding to the basic operators of the LFSR and FSM in the SNOW 3G algorithm, or operations corresponding to the basic operators of the LFSR and FSM in the ZUC algorithm. In other words, the first portion of operations can include at least one of the following: a bit extraction operation, a bit shift operation, an AND operation, an XOR operation, a modular addition operation, and a modular multiplication operation. Each operation is described below.

[0209] The bit extraction operation is an operation to extract the bit at a specified position from a binary operand. For example, the bit reorganization in the ZUC algorithm contains the bit extraction operation X0=s 15H ||s 14L , which means extracting register s 15 The upper 16 bits of register s 14 The lower 16 bits of X0 are concatenated to obtain 32 bits of X0.

[0210] A bit shift operation shifts a binary bit of an operand left or right by a specified number of bits. Unsigned bit shifts discard the shifted bits and fill the vacant bits with zeros. Circular shifts cyclically append the shifted bits to the vacant bits. For example, the SNOW 3G LFSR includes a circular shift operation V<<81, which indicates a leftward shift of 1 over an 8-bit length. This shifts the most significant bit out and places it in the vacant bit space left.

[0211] The AND operation multiplies the two data points involved in the operation. This means that if both data points are 1 at the same time, the result is 1; otherwise, the result is 0. This operation can be represented by the symbol "∧".

[0212] The XOR operation refers to the "exclusive OR" operation of the two data involved in the operation according to the binary system. That is, if the two data are different, the result is 1, otherwise it is 0. And the XOR operation can be performed by the symbol It can be seen that the XOR operation can perform modulo 2 addition on the two data involved in the operation, which is equivalent to binary addition without carry.

[0213] Modular multiplication is an operation that takes the modulus after multiplication. For example, the ZUC algorithm LFSR contains a modular multiplication operation (1+2 8 )·s0mod(2 31 -1).

[0214] Among them, the update operation of the 31-bit register of LFSR in the ZUC algorithm is included in GF(2 31 -1) Multiply the 31-bit string s by 2 k , GF(2 31 -1) can be realized by cyclic shifting k bits to the left, i.e. a·2 k mod(2 31 -1)=a<<< 31 k mod(2 31 -1).

[0215] Modular addition is an operation that takes the modulus after addition. For example, the ZUC algorithm FSM contains a modular addition operation. 32-bit length s 15 Add to R1 and perform 2 32 Modulo. Modulo addition can be performed by the symbol express.

[0216] In a first possible implementation, the modular addition includes an operation performed by a first full adder bootstrapped with one gate, or an operation performed by a second full adder bootstrapped with two gates.

[0217] To facilitate understanding of the first full adder and the second full adder, the modular addition operation in the prior art is first introduced below.

[0218] For example, given two 32-bit numbers X and Y, then calculate the 32-bit modular addition Sum = X + Y mod 2 32 This modular addition can be performed using a ripple-carry adder by discarding the most important bit of the result.

[0219] Specifically, a full adder can be constructed according to the following two formulas:

[0220] Where Carry0 = 0. Based on gate bootstrapping, the homomorphic gates HomoAND, HomoOR, and HomoXOR can be used to evaluate ∧, ∨ (or), and Therefore, we can use 32 (bits) * 5 (each bit requires 5 gates) - 3 = 157 gates to bootstrap and evaluate this modular addition circuit. HomoAND, HomoOR, and HomoXOR can be described in the previous section "5. Homomorphic Gate Computation" and will not be repeated here.

[0221] The operations performed by the first full adder and the operations performed by the second full adder are respectively described below.

[0222] 1. Operations performed by the first full adder

[0223] The operations performed by the first full adder include performing a carry output operation and a modular addition output operation through a three-input homomorphic AND gate, and the carry output operation and the modular addition output operation are performed iteratively.

[0224] Among them, each bit of the plaintext message {0,1} can be encoded as {-1 / 8,1 / 8} respectively. Set C add =X i +Y i +Carry i , the modular addition output result (HomoSum) of the i-th bit can be obtained based on the modular addition carry output (HomoCarry) of the i-th bit. The calculation for each bit is:

[0225] Step 1.1, use a 3-input HomoAND gate to calculate the carry output of the i-th bit and get HomoCarry(X i ,Y i,Carry i )=C add Among them, HomoAND contains a blind rotation.

[0226] Step 1.2, calculate the modular addition output result of the i-th bit according to the carry output HomoCarry of the i-th bit, that is, HomoSum(X i ,Y i ,Carry i )=C add -2·HomoCarry(X i ,Y i ,Carry i ). It can be seen that in this step, no blind rotation is involved.

[0227] It can be understood that the above steps 1.1-1.2 are for the calculation of one bit. When there are multiple bits, it is necessary to iterate steps 1.1 and 1.2, that is, the modular addition carry output HomoCarry(X i ,Y i ,Carry i ) as the input parameter Carry for the modular addition of the i+1th bit i+1 .

[0228] It can be seen that the first full adder includes one blind rotation, and therefore the first full adder can also be called a single blind rotation (1BR) full adder.

[0229] 2. Operations performed by the second full adder

[0230] The operations performed by the second full adder include performing a modular addition output operation through a three-input homomorphic XOR gate; performing a carry output operation through a three-input homomorphic AND gate; and the carry output operation and the modular addition output operation are performed iteratively.

[0231] Each bit of the plaintext message {0,1} can be encoded as {-1 / 8,1 / 8}, respectively. First, a 3-bit input XOR gate (3-input XOR) is constructed based on a 2-input XOR gate (2-input XOR, i.e., HomoXOR(c1,c2)), and a 3-bit input AND gate (3-input AND) is constructed based on a 2-input AND gate (2-input AND, i.e., HomoAND(c1,c2)). It can be understood that if the plaintext of the 3-input XOR is 1 / 8, then the plaintext of 2·(ca+cb+ccarryin) is 1 / 4, otherwise it is -1 / 4. The 2-input XOR gate and the 2-input AND gate can be referred to the relevant introduction of "5. Homomorphic Gate Computation" above, and will not be repeated here.

[0232] The formulas for 3-bit input XOR and 3-bit input AND are as follows: HomAND(c0,c1,c2)=(0,-1 / 8)+Bootstrap(c0+c1+c2); HomXOR(c0,c1,c2)=(0,1 / 4)+Bootstrap(2·(c0+c1+c2));

[0233] Setting C add =X i +Y i +Carry i , the operation performed by the second full adder is implemented by evaluating the 3-input XOR gate and AND gate in parallel. The calculation for each bit is:

[0234] Step 2.1, use a 3-input homomorphic XOR gate (HomoXOR) to calculate the modular addition output of the i-th bit, that is, HomoSum (X i ,Y i ,Carry i )=2·C add Among them, HomoXOR contains a blind rotation.

[0235] Step 2.2, use a 3-input homomorphic AND gate (HomoAND) to calculate the carry output of the i-th bit, namely HomoCarry(X i ,Y i ,Carry i )=C add Among them, HomoAND contains a blind rotation.

[0236] It can be understood that the above steps 2.1 and 2.2 are for the calculation of one bit. When there are multiple bits, steps 2.1 and 2.2 need to be iterated. That is, the carry output of the modular addition of the i-th bit HomoCarry(X i ,Y i ,Carry i ) as the input parameter Carry for the modular addition of the i+1th bit i+1 .

[0237] As can be seen, the second full adder includes two blind rotations, and therefore, the second full adder can also be called a two blind rotation (2BR) full adder. Please refer to FIG10 for the pseudo code of the algorithm of the second full adder.

[0238] It will also be understood that the above descriptions describe the operations performed by the first full adder and the second full adder. For the SNOW3G algorithm, the operations performed by the first full adder or the second full adder can be used to implement the modular addition operation in the FSM in the SNOW3G algorithm. For details about the modular addition operation in the FSM, refer to the aforementioned "6. SNOW3G" and will not be repeated here. For the ZUC algorithm, the operations performed by the first full adder or the second full adder can be used to implement the modular addition operation in the FSM in the ZUC algorithm. For details about the output operation of the FSM, refer to the aforementioned "7. Zu Chongzhi's Algorithm" and will not be repeated here.

[0239] In the second possible implementation, for the 31 -1) Addition of two elements a and b, modular addition c = a + b mod 2 31 The homomorphic evaluation of -1 can be calculated using the following two steps (step 3.1 - step 3.2).

[0240] Step 3.1, use 32-bit adder operation to calculate the modulo 2 of a and b 32 Addition, that is Where v is a 32-bit value.

[0241] Step 3.2, use a Gate implementation GF(2 31 -1) Upper die addition, i.e. Among them, (v&0x7FFFFFFF) is the lowest 31 bits of 32-bit v, and (v>>31) is the highest bit of 32-bit c.

[0242] Among them, steps 3.1 and 3.2 are both obtained by gate bootstrap mode calculation. It can be understood that for GF(2 31 -1) requires only two Door (Module 2 32 In the first two steps of the LFSR initialization phase of the ZUC algorithm, if each addition is followed by a modulo operation, then one LFSR update requires GF(2 31 -1) For the six modular additions above, if the above modular addition operation is used (i.e., the modular addition operation in the second possible implementation), each modular addition requires two There are 12 doors in total. Door.

[0243] It can also be understood that for the ZUC algorithm, the above modular addition operation can be used to perform the modular addition of the LFSR in the ZUC algorithm (2 31 -1) operation, the LFSR modulo (231 -1) can refer to the relevant introduction of "7. Zu Chongzhi's Algorithm" above, which will not be repeated here.

[0244] In a third possible implementation, the modular addition operation includes an operation performed by a tree-structured add-first-then-modulo modular addition strategy.

[0245] The operations performed by the modular addition strategy include: performing an addition operation on the first 31-bit number to the fourth bit number in the LFSR initialization phase of the ZUC algorithm based on two 31-bit adders to obtain a 32-bit first value and a 32-bit second value; performing an addition operation on the fifth bit number in the LFSR initialization phase of the ZUC algorithm based on a 31-bit adder to obtain a 32-bit third value; performing an addition operation on the first value and the second value based on a 32-bit adder to obtain a 33-bit fourth value; performing an addition operation on the third value and the fourth value based on a 33-bit adder to obtain a 34-bit fifth value; performing an addition operation on the fifth value (2 31 -1) to obtain the shift value corresponding to the updated value of the LFSR of the ZUC algorithm.

[0246] For example, the first two steps of the LFSR initialization phase in the ZUC algorithm are:

[0247] Step 4.1, v = 2 15 ·s 15 +2 17 ·s 13 +2 21 ·s 10 +2 20 s4+(1+2 8 )·s0mod(2 31 -1);

[0248] Step 4.2, s 16 =(v+u)mod(2 31 -1).

[0249] As shown in Figure 11, two 31-bit adders can be used to perform non-modular addition operations on the first four 31-bit numbers in the first step (step 4.1) of the LFSR initialization phase of the ZUC algorithm. For example: 15 ·s 15 and 2 17 ·s 13 Perform non-modular addition, i.e. tmp 0,32 =2 15 ·s 15+2 17 ·s 13 , for 2 21 ·s 10 and 2 20 s4 performs non-modular addition, tmp 1,32 =2 21 ·s 10 +2 20 s4, tmp 0,32 and tmp 1,32 It is a 32-bit number, and the last number (1+2 8 )·s0 also passes through a 31-bit adder to obtain a 32-bit number tmp 2,32 Then, tmp is calculated through a 32-bit adder. 0,32 and tmp 1,32 The result is a 33-bit number, namely tmp 0,33 =tmp 0,32 +tmp 1,32 . Then calculate tmp through a 33-bit adder 0,33 and tmp 2,32 The sum of the calculation result is a 34-bit number, namely tmp 34 =tmp 0,33 +tmp 2,32 Finally, through a Door to tmp 34 Calculation modulo (2 31 -1) operation, namely tmp 34 mod(2 31 -1), get the updated value of the LFSR of the ZUC algorithm (s in step 4.2 16 ) corresponding to the shift value (v in step 4.1).

[0250] It can be seen that the operation performed by the tree-structured modular addition strategy consumes a total of 6 Door.

[0251] It can be understood that the update of the first full adder mentioned above needs to add the carry output HomoCarry calculated previously, that is, only HomoCarry is calculated based on HomoAND using blind rotation. Since there is no blind rotation in HomoSum, it will cause noise accumulation. Therefore, in the operation performed by the modular addition strategy, the second full adder can be selected for Gate calculation.

[0252] S802 : Based on the second homomorphic ciphertext of level 0, perform multi-valued function bootstrapping from level 0 to level 2 and privacy key switching from level 2 to level 1 to obtain a third homomorphic ciphertext of level 1.

[0253] During the bootstrap process from level 0 to level 2, you can perform one function bootstrap call or one multi-valued function bootstrap call to refresh the noise and perform function calculations. For more information on function bootstrapping, refer to the previous section "3.2) Circuit Bootstrapping, Step 2" and will not be repeated here.

[0254] Multi-valued function bootstrapping supports evaluating multiple functions on the same input using a single blind rotation, i.e. starting with all functions (TVF i ) extracts a public function v0, then uses the input ciphertext to blindly rotate the test polynomial v0, and finally converts the TVF i / v0 (norm coefficient is smaller) are multiplied by the accumulator ACC to obtain the result. The multi-valued function bootstrapping can be implemented by reusing the existing technology method, and the embodiment of the present application does not limit it.

[0255] For privacy key switching, please refer to the above "3.2) Circuit Bootstrapping, Step 3" for related introduction, which will not be repeated here.

[0256] It can be understood that after performing a multi-valued function bootstrapping from level 0 to level 2 based on the second homomorphic ciphertext at level 0, a level 2 ciphertext, such as a TLWE ciphertext, can be obtained. After obtaining this ciphertext, a privacy key switch from level 2 to level 1 can be performed based on this ciphertext to obtain a third homomorphic ciphertext at level 1, which can be a TRGSW ciphertext.

[0257] S803 , based on the third homomorphic ciphertext of level 1, perform a table lookup operation in the hierarchical homomorphic computing mode of level 1 to obtain the fourth homomorphic ciphertext of level 1.

[0258] The table lookup operations can be partial operations of the LFSR and FSM, i.e., operations corresponding to high-level operators of the LFSR and FSM in the SNOW 3G algorithm, or operations corresponding to high-level operators of the LFSR and FSM in the ZUC algorithm. In other words, the table lookup operations can include S-box operations, MULα operations, DIVα function operations, etc.

[0259] In one possible implementation, the table lookup operation includes: based on the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext, using a CMUX gate to select a target TRLWE ciphertext from two TRLWE ciphertexts, where the two TRLWE ciphertexts are obtained by packaging the first lookup table; based on all other ciphertexts except the ciphertext with the most significant bit in the third homomorphic ciphertext and the target TRLWE ciphertext, using a blind rotation algorithm to obtain the fourth homomorphic ciphertext of level 1.

[0260] For example, as shown in FIG12 , the table lookup operation (denoted as table lookup operation #1) can be a homomorphic evaluation of an 8-to-8 bit table lookup. The input data of table lookup operation #1 can include data #1 and data #2. Data #1 is the third homomorphic ciphertext, i.e., the 8 input bits of the lookup table, corresponding to 8 TRGSW ciphertexts C i , 0≤i≤7, namely C0, C1, C2, C3, C4, C5, C6, C7. Data #2 is two TRLWE ciphertexts, such as T0 and T1. These two TRLWE ciphertexts can be used to find the first lookup table S R Use hybrid packaging technology to obtain, for example: the first lookup table S R There are 2 8 ×8 bits, that is, 2048 bits, are packed into 2 (8×2 8 / N) TRLWE ciphertexts, N is the dimension of the polynomial ring, and N is set to 1024. It can be understood that the hybrid packaging technology refers to the above 2 8 ×8 bits are set to 256 rows, each row has 8 bits, and the first 128 rows and the last 128 rows are packed into ciphertexts respectively. Each ciphertext contains row and column operations. The output data of table lookup operation #1 is the fourth homomorphic ciphertext, that is, 8 output bits, corresponding to 8 TRLWE ciphertexts c i , 0≤i≤7, that is, c0, c1, c2, c3, c4, c5, c6, c7. The specific process of table lookup operation #1 is as follows:

[0261] In step 5.1, according to the TRGSW ciphertext C7 of the most significant bit of the third homomorphic ciphertext, a target TRLWE ciphertext is selected from the two TRLWE ciphertexts using one CMUX gate. The target TRLWE ciphertext is T0 or T1.

[0262] In step 5.2, based on all other ciphertexts (C0, C1, C2, C3, C4, C5, C6) except C7 in the third homomorphic ciphertext, a blind rotation algorithm, such as 7 CMUX gates, is used to obtain the fourth homomorphic ciphertext from the target TRLWE ciphertext. That is, the results of the 8 expected outputs are moved to the first 8 coefficients of the plaintext polynomial through the blind rotation algorithm to obtain the fourth homomorphic ciphertext.

[0263] It can be understood that if all functional operations are evaluated using the gate bootstrap mode, using HomoMUX as an S-box S RThe algorithm's basic gates, an 8-to-8-bit homomorphic lookup table evaluation, consumes 8*(128+64+32+16+8+4+2+1)=2040 HomoMUX gates, equivalent to 4080 gate bootstrapping. As can be seen, the computational cost is high. The aforementioned table lookup operation requires a total of 8 CMUX gates, making it more efficient than the gate bootstrapping method.

[0264] In addition, the first lookup table S R The output of is 8 bits, so the second parameter set in the blind rotation algorithm contains a factor of 8, that is, the second input parameter (8*2 0 ,…,8*2 6 ,0). Furthermore, since the S-box is usually public, it can be used as a noiseless ciphertext for encryption. An efficient CMUX gate requires that the ciphertext of the select bit be a TRGSW ciphertext. Therefore, when evaluating the S-box, circuit bootstrapping is required to convert the ciphertext form of the input bits into a TRGSW ciphertext.

[0265] It can also be understood that, as shown in FIG13, the input bits are x0…x d-1 , d = 8, x0…x in Figure 13 d-1 The corresponding 256 rows of input bits are 8-bit data with different values. The output bits of the table are f0…f s-1 , s=8, The above table lookup operation can mix and pack the entire S-box lookup table into two TRLWE ciphertexts, such as T0 and T1, that is, the data of the two boxes in Figure 13 are T0 and T1 respectively, and then obtain the fourth homomorphic ciphertext from T0 or T1.

[0266] In another possible implementation, the table lookup operation includes: using 4 CMUX gates to select 4 first target TRLWE ciphertexts from 8 TRLWE ciphertexts according to the ciphertext corresponding to the 6th valid bit in the third homomorphic ciphertext; the 8 TRLWE ciphertexts are obtained by packaging the second lookup table; using 2 CMUX gates to select 2 second target TRLWE ciphertexts from 4 first target TRLWE ciphertexts according to the ciphertext corresponding to the 7th valid bit in the third homomorphic ciphertext; using one CMUX gate to select 1 third target TRLWE ciphertext from 2 second target TRLWE ciphertexts according to the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext; using a blind rotation algorithm to obtain the fourth homomorphic ciphertext of level 1 according to all ciphertexts except the ciphertext corresponding to the 6th valid bit, the ciphertext corresponding to the 7th valid bit, and the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext and the third target TRLWE ciphertext.

[0267] For example, as shown in FIG14 , the table lookup operation (denoted as table lookup operation #2) can be a homomorphic evaluation of an 8 to 32-bit table lookup. The input data of table lookup operation #2 can include data #11 and data #22. Data #11 is the third homomorphic ciphertext, i.e., the 8 input bits of the lookup table, corresponding to 8 TRGSW ciphertexts C i ,0≤i≤7, namely C0,C1,C2,C3,C4,C5,C6,C7. Data #22 is 8 TRLWE ciphertexts T i , 0≤i≤7, namely T0,T1,T2,T3,T4,T5,T6,T7, these 8 TRLWE ciphertexts can be obtained by using the hybrid packing technology on the second lookup table S1_T0, for example: the second lookup table S1_T0 has a total of 32×2 8 bits, that is, 8192 bits, are packed into 8 (32×2 8 / N) TRLWE ciphertexts, where N is the dimension of the polynomial ring and N is set to 1024, i.e., every 32 rows are packed into one ciphertext. The output data of table lookup operation #2 is the fourth homomorphic ciphertext, i.e., 32 output bits, corresponding to 32 TLWE ciphertexts c i , 0≤i≤31, i.e. c0 to c 31 The specific process of table lookup operation #2 is as follows:

[0268] In step 6.1, according to the TRGSW ciphertext C5 corresponding to the sixth significant bit of the third homomorphic ciphertext, four CMUX gates are used to select four first target TRLWE ciphertexts from the eight TRLWE ciphertexts. That is, one first target TRLWE ciphertext is selected from each of the four groups of TRLWE ciphertexts T0 / T1, T2 / T3, T4 / T5, and T6 / T7, namely Temp0, Temp1, Temp2, and Temp3.

[0269] In step 6.2, according to the TRGSW ciphertext C6 corresponding to the 7th significant bit of the third homomorphic ciphertext, two CMUX gates are used to select two second-target TRLWE ciphertexts from the four first-target TRLWE ciphertexts. That is, one second-target TRLWE ciphertext is selected from each of the two groups Temp0 / Temp1 and Temp2 / Temp3, namely Tmp0 and Tmp1.

[0270] In step 6.3, according to the TRGSW ciphertext C7 corresponding to the most significant bit in the third homomorphic ciphertext, use one CMUX gate to select a third target TRLWE ciphertext from the two second target TRLWE ciphertexts, that is, select a third target TRLWE ciphertext from Tmp0 / Tmp1.

[0271] In step 6.4, based on all other ciphertexts (C0, C1, C2, C3, C4) in the third homomorphic ciphertext except C5, C6, and C7, a blind rotation algorithm, such as 5 CMUX gates, is used to obtain the fourth homomorphic ciphertext from the third target TRLWE ciphertext. That is, the 32 expected output results are moved to the first 32 coefficients of the plaintext polynomial through the blind rotation algorithm.

[0272] It can be understood that the output of the second lookup table is 32 bits. Therefore, the second parameter set in the blind rotation algorithm contains a factor of 32, that is, the second parameter is adjusted to a multiple of 32. The second input parameter (32*2 0 ,…,32*2 4 ,0).

[0273] It can also be understood that for the 32-to-32-bit S-box S1 and S2 in the SNOW 3G algorithm, they can be obtained by an 8-to-8-bit lookup table S R , MULx functions and a large number of XOR gates. The above table lookup operation #2 can more efficiently calculate S1(w) and S2(w), where w=w0||w1||w2||w3, S1_T0, S1_T1, S1_T2, S1_T3, S2_T0, S2_T1, S2_T2, and S2_T3 are 8-to-32-bit tables. Furthermore, both the MULα and DIVα functions map 8-bit inputs to 32-bit outputs. Therefore, they can be efficiently evaluated using 8-to-32-bit table lookups. This avoids the need for recursive calls to the numerous MULx functions during the evaluation of the MULxPow function, which would result in high computational cost.

[0274] After performing a table lookup operation in level 1 based on the third homomorphic ciphertext, a fourth homomorphic ciphertext of level 1 can be obtained, and the fourth homomorphic ciphertext can be TRLWE. Sample extraction and key switching from level 1 to level 0 are performed on the fourth homomorphic ciphertext to obtain a fifth homomorphic ciphertext of level 0. Exemplarily, sample extraction is performed on the fourth homomorphic ciphertext of level 1 to obtain an extracted ciphertext of level 1, and the extracted ciphertext of level 1 can be in the form of TLWE ciphertext. Then, key switching from level 1 to level 0 is performed on the extracted ciphertext of level 1 to obtain a fifth homomorphic ciphertext of level 0, and the fifth homomorphic ciphertext is a new first homomorphic ciphertext of level 0, that is, the fifth homomorphic ciphertext can be in the form of TLWE ciphertext.

[0275] In summary, in the embodiments of the present application, the homomorphic evaluation of the SNOW 3G algorithm and the ZUC algorithm can be applied to the hybrid homomorphic evaluation mode based on the hierarchical homomorphic computing mode and the gate bootstrapping mode, respectively. For example, the first part of the operations of the LFSR and FSM of the gate bootstrapping mode is executed in level 0, that is, the operations corresponding to the basic operators of the LFSR and FSM in the SNOW 3G algorithm or the ZUC algorithm are implemented, and the table lookup operation is executed in level 1 of the hierarchical homomorphic computing mode, that is, the operations corresponding to the advanced operators of the LFSR and FSM in the SNOW 3G algorithm or the ZUC algorithm are implemented, so that the architecture and algorithm of the encryption and decryption of the homomorphic computing SNOW 3G algorithm and the ZUC algorithm can be realized through fully homomorphic encryption, and then a homomorphic evaluation scheme for the symmetric cryptographic algorithm that meets the design standards of a lower multiplication depth can be designed while ensuring security.

[0276] The above describes the overall process of the homomorphic evaluation method of the symmetric cryptographic algorithm in combination with Figures 8 to 14. The following describes the application of the homomorphic evaluation method of the symmetric cryptographic algorithm in a specific scenario in combination with Figure 15.

[0277] As shown in Figure 15, this scenario involves data party A, ciphertext data storage management (CDSM), homomorphic computing party, homomorphic decryption party, user B, and key management center (KMC). In this scenario, the key management center generates the parameters required for the homomorphic task and sends the parameters to data party A, homomorphic computing party, homomorphic decryption party, and user B as needed. Data party A can perform SNOW 3G symmetric encryption or ZUC symmetric encryption on the plaintext data m to obtain symmetric ciphertext, and send the symmetric ciphertext to the homomorphic computing party through ciphertext storage management. The homomorphic computing party performs homomorphic calculation based on the symmetric ciphertext and sends the homomorphic ciphertext of the calculation result (denoted as ciphertext #1) to the homomorphic decryption party. The homomorphic decryption party performs homomorphic decryption and symmetric encryption on the homomorphic ciphertext #1 to obtain ciphertext #2, and sends ciphertext #2 to user B. User B performs SNOW 3G symmetric decryption or ZUC symmetric decryption on ciphertext #2 to obtain the calculated plaintext data. The specific process is as follows:

[0278] 1) The key management center generates the parameters required for the homomorphic task and sends them to the data party A, the homomorphic computing party, the homomorphic decryption party, and the user party B. The parameters may include homomorphic keys and homomorphic parameters.

[0279] The homomorphic key includes at least one of the following: a symmetric key, such as the symmetric key of SNOW 3G or the symmetric key of ZUC, a homomorphic encryption key, a homomorphic decryption key, and a homomorphic computation key.

[0280] The homomorphic encryption key includes at least one of the following: the homomorphic encryption key of the symmetric ciphertext, and the homomorphic encryption key of the lookup table operation, that is, the key used when tabulating different S-boxes, MULα and DIVα functions in SNOW and ZUC in the level 1 lookup table operation.

[0281] The homomorphic computing key includes at least one of the following: the homomorphic ciphertext of the symmetric key, the first bootstrap key of the gate bootstrap mode, that is, the bootstrap key required for blind rotation in the homomorphic gate computing operation in the level 0 gate bootstrap mode, the second bootstrap key for multi-valued function bootstrapping from level 0 to level 2, the first key switching key from level 2 to level 1, and the second key switching key from level 1 to level 0.

[0282] Homomorphic parameters include at least one of the following: LWE dimensions of three levels, ciphertext modulus, basis of gadget decomposition during outer product operation in blind rotation, length of gadget decomposition during outer product operation, basis of gadget decomposition during key switching, and length of gadget decomposition during key switching. It can be understood that the parameters corresponding to each level of the hierarchical homomorphic computing mode include at least one of the following: ciphertext modulus, standard deviation of noise, TLWE dimension, ring polynomial dimension of TRLWE, gadget decomposition length of TRGSW, and basis of gadget decomposition of TRGSW. The recommended parameter sets for each level of the hierarchical homomorphic computing mode are shown in Table 1 below:

[0283] Table 1

[0284] It is understandable that other parameter values ​​can be set for each level of the hierarchical homomorphic computing mode, and this embodiment of the present application does not limit this.

[0285] It can also be understood that after generating the homomorphic encryption key for the lookup table operation, the key management center can also encrypt the entire output table to obtain homomorphic ciphertext, that is, the key management center can also generate the homomorphic ciphertext of the lookup table in the lookup table operation.

[0286] After the key management center generates the parameters, it can send the symmetric key to data party A and user party B, send the first information and homomorphic parameters to the homomorphic computing party, and send the homomorphic decryption key to the homomorphic decryption party. The first information includes at least one of the following: the homomorphic ciphertext of the symmetric key, the homomorphic ciphertext of the initial parameters of the symmetric key (such as the seed key and the initial vector), the first bootstrap key of the gate bootstrap mode, the homomorphic encryption key of the lookup table operation, the homomorphic ciphertext of the lookup table in the lookup table operation, the second bootstrap key of the multi-valued function bootstrap, the first key switching key from level 2 to level 1, and the second key switching key from level 1 to level 0.

[0287] 2) After receiving the symmetric key sent by the key management center, data party A can use the symmetric key to symmetrically encrypt the plaintext data m to generate symmetric ciphertext; and send the symmetric ciphertext to the ciphertext data storage management.

[0288] 3) Ciphertext Data Storage Management After receiving the symmetric ciphertext from data party A, the symmetric ciphertext can be sent to the homomorphic computing party.

[0289] 4) After receiving the symmetric ciphertext from the ciphertext data storage management, the homomorphic computing party can perform homomorphic computing in conjunction with the first information from the key management center. Specifically, the symmetric ciphertext can be first homomorphically encrypted to obtain a mixed ciphertext; then the mixed ciphertext can be symmetric decrypted by homomorphic computing to obtain a homomorphic ciphertext (denoted as ciphertext #A), and homomorphic computing can be performed based on ciphertext #A to obtain a homomorphic ciphertext (denoted as ciphertext #B). After obtaining ciphertext #B, the homomorphic computing party can send ciphertext #B to the homomorphic decryption party.

[0290] It can be understood that when the homomorphic computing party performs homomorphic computing symmetric decryption based on the mixed ciphertext, it can use the aforementioned homomorphic evaluation method for symmetric decryption. The homomorphic evaluation method for symmetric decryption can refer to the aforementioned content and will not be repeated here.

[0291] It is also understood that if the homomorphic encryption party does not receive the homomorphic ciphertext from the lookup table in the lookup table operation of the key management center, it can generate the homomorphic ciphertext on its own. The embodiment of the application does not limit the manner in which the homomorphic encryption party obtains the homomorphic ciphertext.

[0292] 5) After receiving the ciphertext #B from the homomorphic computing party, the homomorphic decryption party can combine the homomorphic decryption key and the symmetric key from the key management to perform homomorphic decryption and symmetric encryption on the ciphertext #B to obtain the ciphertext #C; and send the ciphertext #C to the user B.

[0293] 6) After receiving the ciphertext #C from the homomorphic decryption party, user B can use the symmetric key from the key management to symmetric decrypt the ciphertext #C to obtain the calculated plaintext.

[0294] It can be understood that if the homomorphic decryption party and the user B are the same entity, the homomorphic decryption party performs homomorphic decryption on the ciphertext #B to obtain the calculated plaintext.

[0295] The above describes in detail the homomorphic evaluation method of the symmetric cryptographic algorithm provided by the embodiment of the present application in conjunction with Figures 8 to 15. The following describes in detail the security device for executing the homomorphic evaluation method of the symmetric cryptographic algorithm provided by the embodiment of the present application in conjunction with Figures 16 and 17.

[0296] Figure 16 is a structural diagram of a safety device according to an embodiment of the present application. As shown in Figure 16 , the safety device 1600 includes a processing module 1601. For ease of illustration, Figure 16 only shows the main components of the safety device 1600.

[0297] In some embodiments, the security device 1600 can perform the functions of the homomorphic computing entity in the above method.

[0298] For example, processing module 1601 is used to execute the first part of the operation of the linear feedback shift register LFSR and the finite state machine FSM in the gate bootstrap mode at level 0 based on the first homomorphic ciphertext at level 0, to obtain the second homomorphic ciphertext at level 0; based on the second homomorphic ciphertext at level 0, execute the multi-valued function bootstrap from level 0 to level 2 and the privacy key switching from level 2 to level 1, to obtain the third homomorphic ciphertext at level 1; based on the third homomorphic ciphertext at level 1, execute the table lookup operation in the hierarchical homomorphic computing mode at level 1, to obtain the fourth homomorphic ciphertext at level 1.

[0299] In one possible design, the first part of operations includes at least one of the following: a bit extraction operation, a bit shift operation, an AND operation, an XOR operation, a modular addition operation, and a modular multiplication operation.

[0300] Optionally, the modular addition operation includes an operation performed by a first full adder bootstrapped with one gate, or an operation performed by a second full adder bootstrapped with two gates.

[0301] Furthermore, the operations performed by the first full adder include performing a carry output operation and a modular addition output operation through a three-input homomorphic AND gate, and the carry output operation and the modular addition output operation are performed iteratively.

[0302] Furthermore, the operations performed by the second full adder include performing a modular addition output operation through a three-input homomorphic XOR gate; performing a carry output operation through a three-input homomorphic AND gate; and the carry output operation and the modular addition output operation are performed iteratively.

[0303] Optionally, the modular addition operation includes an operation performed by a tree-structured add-first-then-modulo modular addition strategy.

[0304] Furthermore, the operations performed by the modular addition strategy include: performing an addition operation on the first 31-bit number to the fourth bit number in the LFSR initialization phase of the ZUC algorithm based on two 31-bit adders to obtain a 32-bit first value and a 32-bit second value; performing an addition operation on the fifth bit number in the LFSR initialization phase of the ZUC algorithm based on one 31-bit adder to obtain a 32-bit third value; performing an addition operation on the first value and the second value based on one 32-bit adder to obtain a 33-bit fourth value; performing an addition operation on the third value and the fourth value based on one 33-bit adder to obtain a 34-bit fifth value; performing a modular (2 31 -1) to obtain the shift value corresponding to the updated value of the LFSR of the ZUC algorithm.

[0305] In one possible design scheme, the table lookup operation includes: based on the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext, using a CMUX gate to select a target TRLWE ciphertext from two TRLWE ciphertexts; the two TRLWE ciphertexts are obtained by packaging the first lookup table; based on all other ciphertexts except the ciphertext with the most significant bit in the third homomorphic ciphertext and the target TRLWE ciphertext, using a blind rotation algorithm to obtain the fourth homomorphic ciphertext of level 1.

[0306] In one possible design scheme, the table lookup operation includes: using four CMUX gates to select four first-target TRLWE ciphertexts from eight TRLWE ciphertexts according to the ciphertext corresponding to the sixth valid bit in the third homomorphic ciphertext; the eight TRLWE ciphertexts are obtained by packaging the second lookup table; using two CMUX gates to select two second-target TRLWE ciphertexts from the four first-target TRLWE ciphertexts according to the ciphertext corresponding to the seventh valid bit in the third homomorphic ciphertext; using one CMUX gate to select one third-target TRLWE ciphertext from two second-target TRLWE ciphertexts according to the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext; and using a blind rotation algorithm to obtain a fourth homomorphic ciphertext of level 1 according to the third homomorphic ciphertext, except for the ciphertext corresponding to the sixth valid bit, the ciphertext corresponding to the seventh valid bit, and the ciphertext corresponding to the most significant bit, and the third target TRLWE ciphertext.

[0307] In one possible design, the processing module 1601 is further configured to extract samples of the fourth homomorphic ciphertext of level 1 and perform key switching from level 1 to level 0 to obtain the fifth homomorphic ciphertext of level 0.

[0308] Optionally, the processing module 1601 is also used to receive first information sent from the homomorphic key generator, the first information including at least one of the following: homomorphic ciphertext of the initial parameters of the symmetric key, the homomorphic ciphertext of the symmetric key, the first bootstrap key of the gate bootstrap mode, the homomorphic encryption key of the lookup table operation, the homomorphic ciphertext of the lookup table in the lookup table operation, the second bootstrap key bootstrapped by the multi-valued function, the first key switching key from level 2 to level 1, and the second key switching key from level 1 to level 0.

[0309] In one possible design, the parameters corresponding to each level of the hierarchical homomorphic computation mode include at least one of the following: ciphertext modulus, standard deviation of noise, TLWE dimension, ring polynomial dimension of TRLWE, gadget decomposition length of TRGSW, and basis of gadget decomposition of TRGSW.

[0310] Optionally, the security device 1600 may further include a transceiver module 1602 , which may be used for communication with other devices.

[0311] Furthermore, the transceiver module 1602 may include a sending module (not shown in FIG16 ) and a receiving module (not shown in FIG16 ). The sending module is used to implement the sending function of the security device 1600 , and the receiving module is used to implement the receiving function of the security device 1600 .

[0312] Optionally, the security device 1600 may further include a storage module (not shown in FIG. 16 ) storing a program or instruction. When the processing module 1601 executes the program or instruction, the security device 1600 may perform the functions of the above method.

[0313] It can be understood that the security device 1600 can be a terminal, a network device, or other device that can perform homomorphic tasks, or a chip (system) or other parts or components that can be set in a terminal, a network device, or other device that can perform homomorphic tasks, or a device that includes a terminal, a network device, or other device that can perform homomorphic tasks. This application does not limit this.

[0314] FIG17 is a second structural diagram of a security device provided in an embodiment of the present application. Exemplarily, the security device may be a network device, or a chip (system) or other component or assembly that can be provided in a network device. As shown in FIG17 , the security device 1700 may include a processor 1701. Optionally, the security device 1700 may further include a memory 1702 and / or a transceiver 1703. The processor 1701 is coupled to the memory 1702 and the transceiver 1703, for example, by a communication bus.

[0315] The following is a detailed introduction to the various components of the safety device 1700 with reference to FIG17 :

[0316] The processor 1701 is the control center of the security device 1700 and can be a single processor or a collective term for multiple processing elements. For example, the processor 1701 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0317] Optionally, the processor 1701 can execute various functions of the security device 1700 by running or executing software programs stored in the memory 1702 and calling data stored in the memory 1702, such as executing the homomorphic evaluation method of the symmetric cryptographic algorithm shown in Figures 8-14 above.

[0318] In a specific implementation, as an embodiment, the processor 1701 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG17 .

[0319] In a specific implementation, as an embodiment, the security device 1700 may also include multiple processors, such as processor 1701 and processor 1704 shown in Figure 17. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor here can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0320] Among them, the memory 1702 is used to store the software program for executing the solution of this application, and the execution is controlled by the processor 1701. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0321] Alternatively, the memory 1702 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1702 may be integrated with the processor 1701 or exist independently and be coupled to the processor 1701 via an interface circuit (not shown in FIG. 17 ) of the security device 1700, which is not specifically limited in this embodiment of the present application.

[0322] Transceiver 1703 is used for communication with other security devices. For example, if security device 1700 is a terminal, transceiver 1703 can be used to communicate with a network device or another terminal device. For another example, if security device 1700 is a network device, transceiver 1703 can be used to communicate with a terminal or another network device.

[0323] Optionally, the transceiver 1703 may include a receiver and a transmitter (not shown separately in FIG17 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a transmitting function.

[0324] Optionally, the transceiver 1703 can be integrated with the processor 1701, or can exist independently and be coupled to the processor 1701 through the interface circuit of the security device 1700 (not shown in Figure 17). This embodiment of the present application does not specifically limit this.

[0325] It is understandable that the structure of the safety device 1700 shown in FIG17 does not constitute a limitation on the safety device, and an actual safety device may include more or fewer components than shown, or a combination of certain components, or a different arrangement of components.

[0326] In addition, the technical effects of the safety device 1700 can refer to the technical effects of the methods described in the above method embodiments, and will not be repeated here.

[0327] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0328] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0329] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0330] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0331] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0332] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0333] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0334] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0335] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0336] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0337] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A homomorphic evaluation method for a symmetric cryptographic algorithm, characterized in that: Applied to a homomorphic computing entity, the method comprises: Based on the first homomorphic ciphertext of level 0, the first part of the operation of the linear feedback shift register LFSR and the finite state machine FSM is performed in the gate bootstrap mode of level 0 to obtain the second homomorphic ciphertext of level 0; Based on the second homomorphic ciphertext of level 0, performing multi-valued function bootstrapping from level 0 to level 2 and privacy key switching from level 2 to level 1, to obtain a third homomorphic ciphertext of level 1; Based on the third homomorphic ciphertext of level 1, a table lookup operation is performed in the hierarchical homomorphic computing mode of level 1 to obtain a fourth homomorphic ciphertext of level 1.

2. The method according to claim 1, characterized in that The first part of operations includes at least one of the following: a bit extraction operation, a bit shift operation, an AND operation, an XOR operation, a modular addition operation, and a modular multiplication operation.

3. The method according to claim 2, characterized in that The modular addition operation includes an operation performed by a first full adder bootstrapped with one gate, or an operation performed by a second full adder bootstrapped with two gates.

4. The method according to claim 3, characterized in that The operation performed by the first full adder includes performing a carry output operation and a modular addition output operation through a three-input homomorphic AND gate, and the carry output operation and the modular addition output operation are performed iteratively.

5. The method according to claim 3, characterized in that: The operations performed by the second full adder include performing a modular addition output operation through a three-input homomorphic XOR gate; performing a carry output operation through a three-input homomorphic AND gate; and the carry output operation and the modular addition output operation are performed iteratively.

6. The method according to claim 2, characterized in that The modular addition operation includes an operation performed by a tree-structured add-first-modulo-last modular addition strategy.

7. The method according to claim 6, characterized in that The operations performed by the modular addition strategy include: Based on two 31-bit adders, adding the first 31-bit number to the fourth bit number in the LFSR initialization phase of the ZUC algorithm is performed to obtain a 32-bit first value and a 32-bit second value; Based on a 31-bit adder, adding the fifth bit number in the LFSR initialization phase of the ZUC algorithm to obtain a 32-bit third value; Based on a 32-bit adder, adding the first value and the second value to obtain a 33-bit fourth value; Based on a 33-bit adder, adding the third value and the fourth value to obtain a 34-bit fifth value; Modulo (2 31 -1) to obtain the shift value corresponding to the updated value of the LFSR of the ZUC algorithm.

8. The method according to any one of claims 1 to 7, characterized in that The table lookup operation includes: Based on the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext, a target TRLWE ciphertext is selected from two TRLWE ciphertexts using a CMUX gate; the two TRLWE ciphertexts are obtained by packaging the first lookup table; According to all other ciphertexts except the ciphertext of the most significant bit in the third homomorphic ciphertext and the target TRLWE ciphertext, a blind rotation algorithm is used to obtain the fourth homomorphic ciphertext of level 1.

9. The method according to any one of claims 1 to 7, characterized in that: The table lookup operation includes: According to the ciphertext corresponding to the sixth effective bit in the third homomorphic ciphertext, four first target TRLWE ciphertexts are selected from eight TRLWE ciphertexts using four CMUX gates; the eight TRLWE ciphertexts are obtained by packaging the second lookup table; According to the ciphertext corresponding to the seventh valid bit in the third homomorphic ciphertext, using two CMUX gates to select two second target TRLWE ciphertexts from the four first target TRLWE ciphertexts; According to the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext, using a CMUX gate to select one third target TRLWE ciphertext from the two second target TRLWE ciphertexts; According to all other ciphertexts in the third homomorphic ciphertext except the ciphertext corresponding to the 6th valid bit, the ciphertext corresponding to the 7th valid bit, and the ciphertext corresponding to the most significant bit and the third target TRLWE ciphertext, a blind rotation algorithm is used to obtain the fourth homomorphic ciphertext of level 1.

10. The method according to any one of claims 1 to 9, characterized in that The method further comprises: Sample extraction and key switching from level 1 to level 0 are performed on the fourth homomorphic ciphertext of level 1 to obtain a fifth homomorphic ciphertext of level 0.

11. The method according to claim 10, characterized in that The method further comprises: Receive first information sent from a homomorphic key generator, the first information including at least one of the following: a homomorphic ciphertext of a symmetric key, a homomorphic ciphertext of an initial parameter of the symmetric key, a first bootstrap key of the gate bootstrap mode, a homomorphic encryption key of the lookup table operation, a homomorphic ciphertext of the lookup table in the lookup table operation, a second bootstrap key bootstrapped by the multi-valued function, a first key switching key from level 2 to level 1, and a second key switching key from level 1 to level 0.

12. The method according to any one of claims 1 to 11, characterized in that The parameters corresponding to each level of the hierarchical homomorphic computing mode include at least one of the following: ciphertext modulus, standard deviation of noise, TLWE dimension, ring polynomial dimension of TRLWE, gadget decomposition length of TRGSW, and basis of gadget decomposition of TRGSW.

13. A safety device, characterized in that: The device comprises: The processing module is used to perform the first part of the operation of the linear feedback shift register LFSR and the finite state machine FSM in the gate bootstrap mode in level 0 based on the first homomorphic ciphertext of level 0, so as to obtain the second homomorphic ciphertext of level 0; based on the second homomorphic ciphertext of level 0, perform multi-valued function bootstrapping from level 0 to level 2 and privacy key switching from level 2 to level 1, so as to obtain the third homomorphic ciphertext of level 1; based on the third homomorphic ciphertext of level 1, perform a table lookup operation in the hierarchical homomorphic computing mode in level 1, so as to obtain the fourth homomorphic ciphertext of level 1.

14. The device according to claim 13, characterized in that The first part of operations includes at least one of the following: a bit extraction operation, a bit shift operation, an AND operation, an XOR operation, a modular addition operation, and a modular multiplication operation.

15. The device according to claim 14, characterized in that The modular addition operation includes an operation performed by a first full adder bootstrapped with one gate, or an operation performed by a second full adder bootstrapped with two gates.

16. The device according to claim 15, characterized in that The operation performed by the first full adder includes performing a carry output operation and a modular addition output operation through a three-input homomorphic AND gate, and the carry output operation and the modular addition output operation are performed iteratively.

17. The device according to claim 15, characterized in that The operations performed by the second full adder include performing a modular addition output operation through a three-input homomorphic XOR gate; performing a carry output operation through a three-input homomorphic AND gate; and the carry output operation and the modular addition output operation are performed iteratively.

18. The device according to claim 14, characterized in that The modular addition operation includes an operation performed by a tree-structured add-first-modulo-last modular addition strategy.

19. The device according to claim 18, characterized in that The operations performed by the modular addition strategy include: Based on two 31-bit adders, adding the first 31-bit number to the fourth bit number in the LFSR initialization phase of the ZUC algorithm is performed to obtain a 32-bit first value and a 32-bit second value; Based on a 31-bit adder, adding the fifth bit number in the LFSR initialization phase of the ZUC algorithm to obtain a 32-bit third value; Based on a 32-bit adder, adding the first value and the second value to obtain a 33-bit fourth value; Based on a 33-bit adder, adding the third value and the fourth value to obtain a 34-bit fifth value; Modulo (2 31 -1) to obtain the shift value corresponding to the updated value of the LFSR of the ZUC algorithm.

20. The device according to any one of claims 13 to 19, characterized in that The table lookup operation includes: Based on the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext, a target TRLWE ciphertext is selected from two TRLWE ciphertexts using a CMUX gate; the two TRLWE ciphertexts are obtained by packaging the first lookup table; According to all other ciphertexts except the ciphertext of the most significant bit in the third homomorphic ciphertext and the target TRLWE ciphertext, a blind rotation algorithm is used to obtain the fourth homomorphic ciphertext of level 1.

21. The device according to any one of claims 13 to 19, characterized in that The table lookup operation includes: According to the ciphertext corresponding to the sixth effective bit in the third homomorphic ciphertext, four first target TRLWE ciphertexts are selected from eight TRLWE ciphertexts using four CMUX gates; the eight TRLWE ciphertexts are obtained by packaging the second lookup table; According to the ciphertext corresponding to the seventh valid bit in the third homomorphic ciphertext, using two CMUX gates to select two second target TRLWE ciphertexts from the four first target TRLWE ciphertexts; According to the ciphertext corresponding to the most significant bit in the third homomorphic ciphertext, using a CMUX gate to select one third target TRLWE ciphertext from the two second target TRLWE ciphertexts; According to all other ciphertexts in the third homomorphic ciphertext except the ciphertext corresponding to the 6th valid bit, the ciphertext corresponding to the 7th valid bit, and the ciphertext corresponding to the most significant bit and the third target TRLWE ciphertext, a blind rotation algorithm is used to obtain the fourth homomorphic ciphertext of level 1.

22. The device according to any one of claims 13 to 21, characterized in that The processing module is further used to extract samples of the fourth homomorphic ciphertext of level 1 and switch the key from level 1 to level 0 to obtain the fifth homomorphic ciphertext of level 0.

23. The device according to claim 22, characterized in that The processing module is also used to receive first information sent from a homomorphic key generator, the first information including at least one of the following: a homomorphic ciphertext of a symmetric key, a homomorphic ciphertext of an initial parameter of the symmetric key, a first bootstrap key of the gate bootstrap mode, a homomorphic encryption key of the lookup table operation, a homomorphic ciphertext of the lookup table in the lookup table operation, a second bootstrap key bootstrapped by the multi-valued function, a first key switching key from level 2 to level 1, and a second key switching key from level 1 to level 0.

24. The device according to any one of claims 13 to 23, characterized in that The parameters corresponding to each level of the hierarchical homomorphic computing mode include at least one of the following: ciphertext modulus, standard deviation of noise, TLWE dimension, ring polynomial dimension of TRLWE, gadget decomposition length of TRGSW, and basis of gadget decomposition of TRGSW.

25. A safety device, characterized in that: The security device comprises: a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the security device executes the method according to any one of claims 1-12.

26. A chip, characterized in that: Instructions are stored therein, and when the chip is run on a security device, the method according to any one of claims 1 to 12 is implemented.

27. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a computer program or instructions. When the computer program or instructions are executed on a computer, the computer is caused to perform the method according to any one of claims 1 to 12.

28. A computer program product, characterized in that The computer program product comprises: a computer program or instructions, and when the computer program or instructions are executed on a computer, the computer is caused to perform the method according to any one of claims 1 to 12.